

Founded: 2017
Product: Lineage-first metadata management and data lineage tooling
Core customers: Regulated enterprises, notably financial services
Offices: UK, US, Singapore
Notable investors: AlbionVC, Citi, HSBC
Data governance, metadata management and data lineage for regulated industries.
2017
Enterprise software / Data management
Strategic investment announced by Citi on 18 August 2020.
USD 19.2M
Series A reported with participation from Citi and HSBC.
“Participation from strategic investors including Citi and HSBC; Series A led by AlbionVC”
| Company |
|---|
We are seeking a proactive and detail-oriented Information Security Engineer to own and operate our information security program. This is a critical hybrid role responsible for maintaining our security and compliance posture across multiple frameworks (ISO 27001, ISO 27017, SOC 2) while also managing and implementing the technical security controls that protect our business and customers.
You will be the central point of contact for all things security, working closely with stakeholders across Engineering, Product, and Operations to ensure our systems are secure, our controls are effective, and we are always prepared for audits.
Key Responsibilities
Compliance & Governance:
Own, maintain, and continually improve our Information Security Management System (ISMS) to ensure compliance with ISO 27001, ISO 27017, and SOC 2 standards.
Manage the annual audit cycle, liaising with external auditors and internal teams to ensure a smooth and successful outcome.
Maintain key security artefacts, including the risk register, asset inventory, and access control records, by collaborating with stakeholders across the business.
Respond to customer and prospect security questionnaires (RFIs/RFPs), effectively communicating our security posture.
Security Operations & Engineering:
Implement, configure, and manage key security systems, including email filtering, Microsoft 365 Defender, endpoint protection, and vulnerability scanning tools.
Coordinate and manage third-party penetration testing, and track remediation of identified vulnerabilities with the engineering teams.
Assess and drive the implementation of technical security controls and best practices (e.g., DKIM/DMARC, MFA, secure configuration).
Risk & Awareness:
Identify, assess, and document new information security risks, and propose effective mitigation strategies.
Promote a culture of security awareness throughout the company by running phishing simulations and managing our security training program via our Learning Management System (LMS).
Act as the subject matter expert on information security, providing guidance and support to all employees.
What We're Looking For
Why Join Us?
Build your career at Solidatus:
If you love solving complex data lineage challenges, thrive on technical ownership, and want to make your mark in a growing company understanding data flows, we want to hear from you!
Your next opportunity is in here somewhere. Sign up to explore 52,000+ startups and their open roles. No spam. No gamification. Just jobs.
52,000+
Startups
58,000+
Open Roles
2,300+
New This Week
Essential Experience:
Proven experience in a security role with direct responsibility for managing or contributing to an ISMS under ISO 27001 and/or SOC 2 frameworks.
Hands-on experience implementing and managing security tools and technologies.
Strong understanding of risk assessment methodologies and experience maintaining a risk register.
Excellent communication and stakeholder management skills, with the ability to translate technical concepts for non-technical audiences.
Experience coordinating security audits and interacting with external auditors.
A solid grasp of core security domains: network security, application security, cloud security (AWS/Azure/GCP), and identity & access management.
Desirable Skills:
Relevant industry certifications (e.g., CISSP, CISM, ISO 27001 Lead Implementer/Auditor).
Experience with security in a cloud-native environment.
Familiarity with data protection regulations such as GDPR.