checkout.com - Senior Information Security Analyst (GRC)
Requirements
• 5 or more years of experience in GRC, information security compliance, IT audit, or a closely related function, ideally within payments, financial services, or fintech. • Deep working knowledge of PCI DSS (v4.0.1 required), ISO 27001, and SOC 2. Practical experience with DORA, NIST CSF, the EU AI Act, or FCA/PRA obligations is strongly preferred. • Demonstrated track record of leading external audits and regulatory assessments end-to-end, including managing assessor relationships and driving findings to closure. • Proven ability to own and deliver complex GRC programme workstreams independently, including gap analyses, risk treatment programmes, and regulatory change initiatives. • Experience advising engineering and product teams on compliance requirements, with the ability to translate regulatory obligations into practical, proportionate controls. • Track record of developing and mentoring less experienced colleagues. • Expert written and verbal communication. You can frame complex regulatory and risk issues for a technical audience, a business stakeholder, and executive leadership — and adapt your style to drive the right outcome in each context. • Strategic and analytical thinker. You see beyond individual findings and controls to understand systemic risk patterns, root causes, and the broader implications for the business. • Decisive under ambiguity. You can set direction and make sound judgement calls on prioritisation and risk treatment without waiting for perfect information. • Highly collaborative and influential. You understand that compliance must be embedded across the business, and you build the relationships and credibility needed to make that happen. • Pragmatic and outcome-focused. You design controls and processes that are proportionate to risk and workable in practice, not just theoretically sound. • CISA, CISM, CISSP, PCIP, ISO 27001 Lead Implementer or Lead Auditor, or equivalent advanced certification. • Familiarity with cloud environments (AWS, Azure, GCP) at an architecture or control level. • Experience with AI governance frameworks such as ISO 42001, the EU AI Act, or NIST AI RMF. • Experience designing or implementing GRC tooling, risk platforms, or compliance automation solutions. • Background in a Big Four advisory, payments scheme, or regulatory environment is advantageous. • It’s important we set you up for success and make our process as accessible as possible. So let us know in your application, or tell your recruiter directly, if you need anything to make your experience or working environment more comfortable. • Life at Checkout.com http://Checkout.com • We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection. • Curious about what it’s like to be part of our team? Visit our Careers Page https://www.checkout.com/careers to learn more about our culture, open roles, and what drives us. • For a closer look at daily life at Checkout.com http://Checkout.com, follow us on LinkedIn https://www.linkedin.com/company/checkout/life/ and Instagram https://www.instagram.com/checkout_com/
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT