• Stakeholder Communication and Reporting: respond to customer security questionnaires and produce management reports on security compliance and metrics for relevant committees.
• Contribute to and Improve Compliance Programmes: contribute to internal control evaluations and testing to ensure adherence. Ensure compliance with industry standards such as DORA, ISO 27001, and SOC 2. Coordinate responses to internal and external audits, and support security assessments, including third-party penetration tests.
• Risk Management and Issue Resolution: contribute to the maintenance of the risk assessment process to identify, evaluate, and mitigate potential risks. Triage security issues and provide recommended solutions.
• To be successful in this role, we require:
• 4+ years of experience in security compliance, GRC, or infosec roles
• Experience answering complex compliance questionnaires, ideally from Banks or highly regulated organisations
• Experience in developing and implementing information security policies, standards and procedures
• Experience leading ISO27001 and SOC 2 certification processes
• Familiarity with security standards and frameworks such as ISO 27001, SOC 2, NIST CSF, DORA, and GDPR