Information Security GRC Engineering Consultant (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Information Security GRC Engineering Consultant (Cybersecurity): Building and operating security control frameworks and compliance automation for Featurespace with an accent on continuous assurance, evidence collection, and secure-by-design delivery. Focus on translating PCI DSS, SOC 2, and Key Controls into practical implementations across cloud environments, CI/CD pipelines, and product teams while leading audits and risk remediation.
Location: Hybrid in London, United Kingdom; office attendance requirements will be confirmed by the hiring manager. Periodic travel may be required.
Company
is a global payments technology company facilitating transactions between consumers, merchants, financial institutions, and governments.
What you will do
- Own and operate Featurespace’s security controls framework aligned with Key Controls, PCI DSS, SOC 2, and applicable regulatory requirements.
- Lead annual certification and assurance activities, coordinating internal teams, control functions, and external auditors.
- Translate security and compliance requirements into controls embedded in product architectures, CI/CD pipelines, cloud environments, and operating processes.
- Design automation for control validation, evidence collection, workflow orchestration, exception handling, metrics, and compliance reporting.
- Advise engineering, product, commercial, and leadership teams on secure-by-design practices, risk management, and remediation.
- Coordinate customer RFP responses, security audits, risk assessments, business impact analyses, and control-related incident recovery activities.
Requirements
- At least 3 years of experience ensuring information security compliance, preferably in highly regulated environments.
- Strong experience implementing and operating security control frameworks such as SOC 2, ISO 27001, and PCI DSS.
- Experience with ISMS, security risk management, compliance assessments, evidence review, control testing, and stakeholder engagement.
- Knowledge of technical security controls across cloud, networks, endpoints, identity and access management, infrastructure, and applications.
- Technical proficiency in at least one programming language and the ability to complete a coding assessment.
- Proficient English language skills are required. Clear communication with technical and non-technical stakeholders is essential.
Nice to have
- ISO 27001 Lead Implementer or Lead Auditor, PCIP, ISA, CISA, CISM, CISSP, or similar certification.
- Financial services compliance experience, particularly PCI.
- Advanced software development experience.
- Deep understanding of security controls, technologies, policies, processes, and best practices across applications, compute, networking, cloud, and containers.
Culture & Benefits
- Work on payments technology operating at global scale and impacting customers worldwide.
- Collaborate across Featurespace engineering and product teams, Cyber, Risk, and Legal functions, auditors, regulators, and customers.
- Operate in a role that values ownership, adaptability, analytical thinking, and influence without direct line management.
- Develop repeatable principles, processes, reference implementations, and solutions that reduce delivery friction while maintaining strong assurance.
Hiring process
- The selection process includes a coding assessment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →