About Bridewell
One of the most exciting prospects in the cyber security sector today, Bridewell is a leading cyber security services company specializing in protecting and transforming critical business functions for some of the world's most trusted organizations. We are the trusted partner for operators of essential services and provide end-to-end cyber security capabilities that help our clients overcome their security challenges, allowing them to operate safely and securely.
Having expanded into North America in 2022, Bridewell is quickly increasing its presence across the United States, showing our commitment to becoming a major player in the US cyber security market. Our US operations are focused on delivering cyber security solutions in the critical infrastructure sector, providing critical support to organisations navigating security challenges.
Overview
We are looking for a Data Center Compliance Auditor to support the delivery of Bridewell services to one of our most strategic clients. You will support our client's Security & Compliance team across critical business operations, compliance and data protection activities within its infrastructure data centers.
The role will focus on ensuring that data center environments remain audit-ready, while supporting additional audit and compliance requirements as they arise. You will work closely with a broad range of cross-functional stakeholders, including facilities, engineering, physical security and infrastructure finance teams.
Requirements
The Role - here's what you will do:
As a Data Center Compliance Auditor, you will have a primary focus on regulatory and certification audit support across SOX, SOC 2, ISO 27001, PCI and additional data center audits as required. You will help ensure that the client's data center infrastructure is audit-ready and compliant with applicable standards, coordinating with internal teams and external auditors while driving continuous improvement across the control environment.
You will play a critical role in maintaining certifications by planning and executing audit activities, owning evidence gathering, conducting site walkthroughs, performing readiness assessments and enabling data center teams to understand and meet their compliance obligations.
Further Breakdown of key responsibilities
Regulatory & Certification Audit Support
- Plan, coordinate and facilitate external audits, both remote and on-site, across the client's owned and leased data center portfolio.
- Support audits covering SOX, SOC 2, ISO 27001, PCI and other emerging audit requirements.
- Manage audit schedules, scope definition and logistics with external auditors.
- Act as a primary liaison between external auditors and internal cross-functional teams throughout audit engagements.
Evidence Collection & Auditor Inquiry Response
- Own end-to-end evidence gathering across facilities, engineering, physical security and infrastructure finance teams to satisfy auditor requests for information (RFIs).
- Respond to auditor inquiries with accurate, timely and well-documented evidence.
- Maintain organized evidence repositories and ensure completeness of audit documentation.
- Interpret evidence requirements and guide control owners on the standard of evidence expected.
Walkthrough Facilitation
- Attend and support on-site security walkthroughs with external auditors at data center facilities.
- Conduct virtual and on-site walkthroughs of data center security environments in support of SOC 2, ISO 27001 and SOX assessments.
- Prepare site teams for auditor walkthroughs through pre-audit briefings and rehearsals.
- Document walkthrough findings and coordinate any required follow-up actions.
Audit Readiness & Control Testing
- Conduct control testing covering design effectiveness and advisory activities across physical and environmental security, logical access, change management and availability controls.
- Evaluate control design within a Three Lines of Defense (3LOD) framework and provide advisory input on control adequacy.
- Conduct mock audits and tabletop exercises to prepare sites for external assessments.
- Develop and deliver compliance training to data center teams on control requirements and audit expectations.
Impact Assessments & Compliance Enablement
- Support compliance impact assessments for new processes, system changes and site launches.
- Advise cross-functional teams on the compliance implications of operational changes.
- Maintain documentation of control descriptions, policies and procedures relevant to audit scope.
Experience
- You will have strong, demonstrable experience in several of the following areas:
- 5+ years of experience in IT audit, compliance or information security, with demonstrable experience across SOC 2, ISO 27001, SOX and/or PCI.
- Proven experience managing compliance programmes within a Three Lines of Defense (3LOD) governance framework.
- Experience with the AICPA Trust Services Criteria and SOC 2 reporting framework, including Type I and Type II.
- Strong understanding of control design through to control testing, including evaluating both design and operating effectiveness.
- Demonstrable ability to interpret evidence and assess whether it satisfies control objectives and auditor expectations.
- Experience planning and executing compliance audits in data center or critical infrastructure environments.
- Familiarity with physical and environmental security controls, logical access controls and change management processes.
- Strong stakeholder management skills, with the ability to build relationships and influence cross-functional teams at all levels.
Preferred Qualifications
- Professional certification such as CISA, ISO 27001 Lead Auditor, CISSP or CRISC.
Eligibility: Due to requirements from clients this role will support, applicants must be authorized to work in the United States.
Benefits
Why join us?
Our vision is to create a safe, inclusive digital world where people and organization can thrive. Our values of Do the Right Thing, One Team and Above and Beyond emphasize the importance of the part we play in society, and our commitment to our people and clients. Our story to-date has been phenomenal, but success doesn't end here and as we continue to grow and scale, we want to keep the same culture, passion and commitment to high quality that has enabled us to get this far. Bridewell will provide a great career opportunity with continual development as well as the following:
- 15 Days Vacation - Plus buy and sell options
- Flexible Working (around core office hours)
- 401(k)
- Personal Day & Birthday Off - After 1 year of service
- Family Leave - After 1 year of service
- Life Assurance
- Private Healthcare
Location: Bridewell operates a hybrid and flexible working policy; however, you will be required to travel to different data center sites for audit activities on occasion. Travel for this role is estimated at 25%.
Bridewell values diversity in the workplace and is a fair and equal opportunity employer. We are committed to creating an equal and inclusive working environment, with the aim that our employees will be truly representative of all sections of society and each person feels respected and able to give their best.
Skills Required
- 5+ years of experience in IT audit, compliance, or information security
- Demonstrable experience with SOC 2, ISO 27001, SOX, and/or PCI
- Experience managing compliance programs within a Three Lines of Defense governance framework
- Experience with the AICPA Trust Services Criteria and SOC 2 Type I and Type II reporting frameworks
- Strong understanding of control design, control testing, and evaluating design and operating effectiveness
- Ability to interpret evidence and assess whether it satisfies control objectives and auditor expectations
- Experience planning and executing compliance audits in data center or critical infrastructure environments
- Familiarity with physical and environmental security, logical access, and change management controls
- Strong stakeholder management, relationship-building, and cross-functional influencing skills
- Professional certification such as CISA, ISO 27001 Lead Auditor, CISSP, or CRISC
- Must be authorized to work in the United States
What We Do
Bridewell is a leading cyber security services company that specialises in protecting and transforming critical business functions for some of the world’s most trusted organisations. Its teams of security experts work alongside clients to deliver end-to-end services that solve key business challenges. Bridewell's specialists are highly accredited by major industry bodies and have extensive experience delivering services across cyber security, managed security, penetration testing, and data privacy. Bridewell is headquartered in the UK where they run a 24/7 Security Operations Centre (SOC) and has expanded into the US to further support global clients. Since being founded in 2013, Bridewell has grown rapidly and is now one of the largest cyber security providers.

.jpeg)





