GRC Security Specialist
Core
Own the end-to-end security assurance cycle, managing third-party security programs, inbound due diligence, and the ISO 27001 ISMS implementation for a UK fintech.
Role type
GRC Security Specialist (Information Security Assurance)
Builds
Security assurance programs, supplier risk registers, trust packs for due diligence, and ISO 27001 evidence.
Domain
Fintech / Consumer Lending / Information Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Third-party security assessment, ISO 27001 ISMS management, security due diligence, risk register administration, control testing, vulnerability management, security awareness training, incident response support, policy drafting, regulatory reporting (FCA/ICO).
Preferred skills
Cloud-native environment experience (AWS), scaling control frameworks, UK operational resilience (SYSC 15A) and outsourcing (SYSC 8) knowledge.
Technologies
EDR, SAST/DAST/SCA, SIG, CAIQ, AWS
Responsibilities
Run security due diligence on new suppliers and maintain tiering models; manage the annual security assurance calendar including penetration tests and tabletop exercises; consolidate and triage vulnerability findings across multiple sources; draft and maintain security policies and the Statement of Applicability for ISO 27001; produce security MI for executive committees.
Seniority
Mid-Senior, hands-on IC
