Назад
Company hidden
6 дней назад

Security Assurance Manager

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
c1
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Assurance Manager (ISO 27001/GRC): Building and operating Abound’s security assurance function across third-party risk, inbound due diligence, control testing, vulnerability management, and regulatory evidence with an accent on ISO 27001 certification, supplier oversight, and financial-services compliance. Focus on coordinating audits and penetration tests, maintaining risk and exception registers, challenging technical findings, and producing trusted security reporting for senior stakeholders.

Location: London, United Kingdom; hybrid

Company

hirify.global is a UK fintech using AI and Open Banking data to provide fair, affordable personal finance and consumer lending.

What you will do

  • Run third-party security due diligence, supplier tiering, reassessments, outsourcing registers, concentration-risk reviews, and exit-plan tracking.
  • Own inbound security due diligence and maintain a reusable trust pack with certifications, penetration-test attestations, security documentation, and questionnaire responses.
  • Manage the annual security assurance calendar, including penetration tests, access reviews, disaster recovery tests, tabletop exercises, policy reviews, supplier reassessments, and awareness training.
  • Maintain the information security risk register, policy exceptions, risk acceptances, first-line control testing, and security management information for senior governance forums.
  • Consolidate and track vulnerabilities and security findings across endpoint, cloud, application-security, secrets-scanning, and penetration-testing sources.
  • Support the ISO 27001 ISMS, incident response, business continuity, secure development, data protection, and regulatory notifications.

Requirements

  • At least three years of experience in information security assurance, GRC, or security compliance, including experience in regulated financial services or an externally audited environment.
  • Hands-on experience operating or certifying an ISO 27001 ISMS.
  • Experience running third-party or vendor security assessments and responding to inbound security due diligence.
  • Ability to assess technical findings from endpoint, cloud, application-security, and penetration-testing reports and determine severity and exploitability.
  • Clear, concise written English and confidence challenging suppliers and coordinating remediation with engineering teams.

Nice to have

  • Experience in a cloud-native environment, ideally AWS.
  • Experience scaling control frameworks as organisations grow.
  • Familiarity with UK operational resilience and outsourcing requirements, including SYSC 15A and SYSC 8.
  • Certifications such as CISM, CISA, ISO 27001 Lead Implementer or Lead Auditor, CRISC, or CCSP.

Culture & Benefits

  • Work in a fast-growing fintech expanding into new markets and product lines.
  • Collaborate with Security, Engineering, Procurement, Legal, People, auditors, funders, banking partners, and regulators.
  • Own a function with direct impact on assurance, regulatory readiness, and customer trust.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →