Above analytics are generated algorithmically based on job titles and may not always be the same as the company's job classification. You can also check detailed occupation eligibility, and salary criteria on our UK Visa Eligible Occupations & Salary Thresholds page.
Disclaimer: Hunt UK Visa Sponsors aggregates job listings from publicly available sources, such as search engines, to assist with your job hunting. We do not claim affiliation with Narwhal Labs. For the most up-to-date job details, please visit the official website by clicking "Apply Now."
Security Operations (SecOps) & Compliance Engineer
Company: Narwhal Labs (Narwhal Group Limited)
Location: Bristol, UK (must be within commutable distance to Bristol)
Employment Type: Contract
Reports to: Head of Platform
Salary: £40,000 - £50,000
About Us
Narwhal Labs is the company behind DeepBlue OS — an autonomous revenue infrastructure platform that enables any business to answer every call, follow up every lead, and log every interaction across Voice, SMS, Email and WhatsApp. As an NVIDIA Inception Program Member and Google Partner, we are a 38-person team with our platform launching in May 2026. We build the infrastructure layer for serious businesses that want enterprise-grade revenue operations at a fraction of traditional cost.
Role Overview
You'll be the person who owns security and compliance end-to-end — not as a checkbox exercise, but as an operational discipline that runs through everything the platform does. DeepBlue OS handles live customer conversations in regulated verticals (financial services, healthcare, energy), stores PII across a multi-tenant architecture, processes payments through Stripe, and integrates with third-party telephony and AI providers. The security and compliance posture of this platform is not a background concern — it's a commercial requirement that directly affects whether enterprise customers will buy.
The foundations are in place: a security audit log built to SOC 2 CC6.1 and ISO 27001 A.12.4, a compliance incident model with automated action sets, RBAC with tenant-scoped permissions, MFA enforcement for platform users, encrypted secrets management, Semgrep and dependency audit in CI, rate limiting with Redis-backed middleware, and a compliance reference document covering PCI DSS, UK GDPR, HIPAA, and FCA. What's missing is the person who takes ownership of this — who maintains it, extends it, drives the certifications, responds to incidents, and makes sure security doesn't become the thing that only gets attention after something goes wrong.
Key Responsibilities
Security operations — platform and infrastructure
Compliance frameworks — certification and maintenance
Data protection and privacy
Internal security culture
Who We’re Looking For
You've done this before — not in theory, but in a company where you were the person responsible for getting and keeping a compliance certification, responding when something went wrong, and explaining the security posture to a customer who was deciding whether to buy.
What sets you apart
What You Won't Be Doing
Diversity and Inclusion
We're building something global at Narwhal, and we mean that in every sense. The work we do requires different ways of thinking — and different ways of thinking come from different people.
At Narwhal, we're committed to building a diverse and inclusive team. We welcome applications from people of all backgrounds, identities, and experiences, and we actively work to ensure our hiring process is fair and accessible for everyone. Reasonable adjustments are available at every stage, just reach out and we'll make it happen.