lendable - Security GRC Analyst
Responsibilities
• Framework & Regulatory Alignment: Help maintain, improve, and scale our security compliance programmes, ensuring ongoing alignment with standards such as SOC 2, ISO 27001, and PCI-DSS, as well as regulator expectations and UK GDPR. • Risk & Mitigation: Collaborate on identifying security risks across the business - including emerging risks from AI-driven and agentic threats - and support the team in driving practical, risk-first mitigation strategies. • Compliance Automation: Utilise our security compliance platform (e.g., Vanta/Drata) to orchestrate automated evidence collection, reducing manual overhead and moving the company toward a state of continuous audit readiness. • Third-Party Risk Management (TPRM): Conduct vendor and third-party security risk assessments to evaluate the security posture of partners and critical outsourced service providers. • Translating Risk & Governance: Work with the team to bridge the gap between engineering and business governance by turning technical security metrics into clear, risk-based narratives for internal stakeholders and external auditors. • Security Culture & Awareness: Support the delivery and promotion of security awareness initiatives to help drive a strong culture of shared security responsibility across the organisation. • Technical Collaboration: Actively engage in conversations with engineers, developers, and IT teams - understanding their technical language and workflows to help align security controls with engineering realities. • Audit & Assessment Support: Participate in external audits and assessments by gathering evidence, preparing documentation, and helping to ensure a smooth, successful audit cycle. • Experience: 5+ years of experience in a related role (ideally within a regulated, cloud-native business or FinTech). • Compliance & Risk Expertise: A strong, foundational understanding of security risk management principles and hands-on experience working with compliance frameworks (e.g. ISO 27001, PCI-DSS, or SOC 2). • Risk-First & Pragmatic Mindset: A natural tendency to start with the "why" (the risk) rather than the checklist. You possess the ability to balance strict financial regulations with the operational agility of a fast-paced FinTech, ensuring security controls protect the business without slowing it down. • Communication & Collaboration: Outstanding communication skills with a proven ability to comfortably converse with technical stakeholders, understand their challenges, and translate them into business risks. • Drive & Initiative: A highly proactive and self-motivated mindset - someone who actively looks for ways to improve our security posture and drive change. • Tooling: Direct, practical experience working with modern security compliance and automation platforms (such as Vanta or Drata). • Programming and automation: Experience with Python or a similar programming/scripting language, and/or using AI to improve productivity through automation.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT