Назад
Company hidden
8 часов назад

Security Governance, Risk, Compliance Lead (Fintech)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
UK/UAE
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Governance, Risk, Compliance Lead (Fintech): Building and operating an end-to-end security GRC function for a global payments platform with an accent on SOC 2, ISO 27001, PCI DSS, GDPR, and regional financial-services obligations. Focus on automating evidence and control mapping in Vanta, investigating cloud and CI/CD control failures, coordinating audits and penetration tests, and driving remediation across engineering and third-party risks.

Location: Hybrid in London or Dubai; candidates must have the right to work in the jurisdiction where they work.

Company

hirify.global is a B2B financial services provider delivering global payments and receivables, foreign exchange, treasury management, and finance reconciliation services.

What you will do

  • Own and mature the security compliance program across SOC 2, ISO 27001, PCI DSS, and GDPR, while addressing applicable DORA, FCA/PRA, MAS TRM, and UAE regulatory obligations.
  • Operate Vanta day to day, including control mapping, evidence review, remediation tracking, integration health, and custom automation or API connections.
  • Maintain the risk register, scoring methodology, policy library, and procedure documentation in Jira and Confluence.
  • Run vendor and third-party risk assessments for processors, banking partners, cloud providers, and subprocessors.
  • Lead external audits and penetration-test coordination, including scoping, evidence collection, auditor liaison, QSA engagement, and remediation.
  • Investigate control failures in AWS, GCP, Azure, IAM, CI/CD, logging, and GitHub; report risk posture and control health to the CISO and board.

Requirements

  • 4+ years of experience in GRC, information security, or compliance, ideally including hands-on security engineering or IT operations experience.
  • Direct experience running SOC 2 and/or ISO 27001 audits, including evidence collection and auditor management.
  • Technical literacy across IAM policies, SIEM alerts, GitHub CI/CD pipelines, cloud infrastructure, and engineering control implementation.
  • Hands-on experience with Vanta, Drata, Secureframe, or an equivalent GRC automation platform.
  • Daily working knowledge of Jira and Confluence, plus understanding of PCI DSS scoping, processor risk, and financial-services compliance.
  • Strong written communication for policies, board summaries, and customer-facing security questionnaires.

Nice to have

  • CISA, CISSP, or ISO 27001 Lead Auditor/Implementer certification.
  • Experience in regulated fintech or payments environments.
  • Experience with DORA, MAS TRM, or UAE CBUAE, VARA, or DFSA regulations.
  • Python or similar scripting experience for control automation and evidence pipelines.
  • Experience building or significantly maturing a GRC function.

Culture & Benefits

  • Direct access to the CISO and meaningful ownership of the security GRC function.
  • Modern tooling across Vanta, AWS, GCP, Azure, Jira, Confluence, and GitHub.
  • Agile and flexible working culture in a growing global startup.
  • Inclusive work environment with accommodations available during the recruitment process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →