8 часов назад
Security Governance, Risk, Compliance Lead (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Governance, Risk, Compliance Lead (Fintech): Building and operating an end-to-end security GRC function for a global payments platform with an accent on SOC 2, ISO 27001, PCI DSS, GDPR, and regional financial-services obligations. Focus on automating evidence and control mapping in Vanta, investigating cloud and CI/CD control failures, coordinating audits and penetration tests, and driving remediation across engineering and third-party risks.
Location: Hybrid in London or Dubai; candidates must have the right to work in the jurisdiction where they work.
Company
is a B2B financial services provider delivering global payments and receivables, foreign exchange, treasury management, and finance reconciliation services.
What you will do
- Own and mature the security compliance program across SOC 2, ISO 27001, PCI DSS, and GDPR, while addressing applicable DORA, FCA/PRA, MAS TRM, and UAE regulatory obligations.
- Operate Vanta day to day, including control mapping, evidence review, remediation tracking, integration health, and custom automation or API connections.
- Maintain the risk register, scoring methodology, policy library, and procedure documentation in Jira and Confluence.
- Run vendor and third-party risk assessments for processors, banking partners, cloud providers, and subprocessors.
- Lead external audits and penetration-test coordination, including scoping, evidence collection, auditor liaison, QSA engagement, and remediation.
- Investigate control failures in AWS, GCP, Azure, IAM, CI/CD, logging, and GitHub; report risk posture and control health to the CISO and board.
Requirements
- 4+ years of experience in GRC, information security, or compliance, ideally including hands-on security engineering or IT operations experience.
- Direct experience running SOC 2 and/or ISO 27001 audits, including evidence collection and auditor management.
- Technical literacy across IAM policies, SIEM alerts, GitHub CI/CD pipelines, cloud infrastructure, and engineering control implementation.
- Hands-on experience with Vanta, Drata, Secureframe, or an equivalent GRC automation platform.
- Daily working knowledge of Jira and Confluence, plus understanding of PCI DSS scoping, processor risk, and financial-services compliance.
- Strong written communication for policies, board summaries, and customer-facing security questionnaires.
Nice to have
- CISA, CISSP, or ISO 27001 Lead Auditor/Implementer certification.
- Experience in regulated fintech or payments environments.
- Experience with DORA, MAS TRM, or UAE CBUAE, VARA, or DFSA regulations.
- Python or similar scripting experience for control automation and evidence pipelines.
- Experience building or significantly maturing a GRC function.
Culture & Benefits
- Direct access to the CISO and meaningful ownership of the security GRC function.
- Modern tooling across Vanta, AWS, GCP, Azure, Jira, Confluence, and GitHub.
- Agile and flexible working culture in a growing global startup.
- Inclusive work environment with accommodations available during the recruitment process.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →