6 дней назад
Security Assurance Manager
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Assurance Manager (ISO 27001/GRC): Building and operating Abound’s security assurance function across third-party risk, inbound due diligence, control testing, vulnerability management, and regulatory evidence with an accent on ISO 27001 certification, supplier oversight, and financial-services compliance. Focus on coordinating audits and penetration tests, maintaining risk and exception registers, challenging technical findings, and producing trusted security reporting for senior stakeholders.
Location: London, United Kingdom; hybrid
Company
is a UK fintech using AI and Open Banking data to provide fair, affordable personal finance and consumer lending.
What you will do
- Run third-party security due diligence, supplier tiering, reassessments, outsourcing registers, concentration-risk reviews, and exit-plan tracking.
- Own inbound security due diligence and maintain a reusable trust pack with certifications, penetration-test attestations, security documentation, and questionnaire responses.
- Manage the annual security assurance calendar, including penetration tests, access reviews, disaster recovery tests, tabletop exercises, policy reviews, supplier reassessments, and awareness training.
- Maintain the information security risk register, policy exceptions, risk acceptances, first-line control testing, and security management information for senior governance forums.
- Consolidate and track vulnerabilities and security findings across endpoint, cloud, application-security, secrets-scanning, and penetration-testing sources.
- Support the ISO 27001 ISMS, incident response, business continuity, secure development, data protection, and regulatory notifications.
Requirements
- At least three years of experience in information security assurance, GRC, or security compliance, including experience in regulated financial services or an externally audited environment.
- Hands-on experience operating or certifying an ISO 27001 ISMS.
- Experience running third-party or vendor security assessments and responding to inbound security due diligence.
- Ability to assess technical findings from endpoint, cloud, application-security, and penetration-testing reports and determine severity and exploitability.
- Clear, concise written English and confidence challenging suppliers and coordinating remediation with engineering teams.
Nice to have
- Experience in a cloud-native environment, ideally AWS.
- Experience scaling control frameworks as organisations grow.
- Familiarity with UK operational resilience and outsourcing requirements, including SYSC 15A and SYSC 8.
- Certifications such as CISM, CISA, ISO 27001 Lead Implementer or Lead Auditor, CRISC, or CCSP.
Culture & Benefits
- Work in a fast-growing fintech expanding into new markets and product lines.
- Collaborate with Security, Engineering, Procurement, Legal, People, auditors, funders, banking partners, and regulators.
- Own a function with direct impact on assurance, regulatory readiness, and customer trust.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Ping Identity
9 дней назад
Risk Manager (Cybersecurity)
8 дней назад
Senior Security Engineer (Cloud Security)
110 000 - 130 000€
7 дней назад
Security Assurance Lead
8 дней назад
GRC Cyber Security Consultant
10 дней назад
Cloud Security Engineer (AI)
Writer
9 дней назад