CareerPlanSign in

GRC Security Specialist

London💼 Full-time🗓 2026-09-25 → 2026-09-26

Core

Own the end-to-end security assurance cycle, managing third-party security programs, inbound due diligence, and the ISO 27001 ISMS implementation for a UK fintech.

Role type

GRC Security Specialist (Information Security Assurance)

Builds

Security assurance programs, supplier risk registers, trust packs for due diligence, and ISO 27001 evidence.

Domain

Fintech / Consumer Lending / Information Security

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Third-party security assessment, ISO 27001 ISMS management, security due diligence, risk register administration, control testing, vulnerability management, security awareness training, incident response support, policy drafting, regulatory reporting (FCA/ICO).

Preferred skills

Cloud-native environment experience (AWS), scaling control frameworks, UK operational resilience (SYSC 15A) and outsourcing (SYSC 8) knowledge.

Technologies

EDR, SAST/DAST/SCA, SIG, CAIQ, AWS

Responsibilities

Run security due diligence on new suppliers and maintain tiering models; manage the annual security assurance calendar including penetration tests and tabletop exercises; consolidate and triage vulnerability findings across multiple sources; draft and maintain security policies and the Statement of Applicability for ISO 27001; produce security MI for executive committees.

Seniority

Mid-Senior, hands-on IC

Sourced via ashby · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.