Security Compliance Specialist
Full Description
Location: Remote First; office location Moorgate, London (flexible remote working locations within UK/Europe)
Employment type: Permanent (open to contract as well)
Working Hours: Full-time (UK 9-6)
Salary: dependent on experience up to £75,000 + Shares + Benefits
We are hiring to enhance our Security and Compliance efforts. In this role, you will work closely with Security Compliance, Senior Leadership, and Site Reliability Engineering to support our GRC initiatives.
We provide a low-latency, high-throughput distributed messaging system to the e-trading Fixed-income markets. We are, foremost, a technology service provider and support for part of our customers’ trading infrastructure.
You will help maintain positive customer relationships by handling compliance questions and ensuring our security practices are effective and up to date.
Here’s what you’ll be doing:
Stakeholder Communication and Reporting: respond to customer security questionnaires and produce management reports on security compliance and metrics for relevant committees.
Contribute to and Improve Compliance Programmes: contribute to internal control evaluations and testing to ensure adherence. Ensure compliance with industry standards such as GDPR, DORA, NIS2, ISO 27001, and SOC 2. Coordinate responses to internal and external audits, and support security assessments, including third-party penetration tests.
Risk Management and Issue Resolution: contribute to the maintenance of the risk assessment process to identify, evaluate, and mitigate potential risks. Triage security issues and provide recommended solutions.
To be successful in this role, we require:
4+ years of experience in security compliance, GRC, or infosec roles
Experience answering complex compliance questionnaires, ideally from Banks or highly regulated organisations
Experience in developing and implementing information security policies, standards and procedures
Experience leading ISO27001 and SOC 2 certification processes
Familiarity with standards and frameworks such as ISO 27001, SOC 2, NIST CSF, as well as legal frameworks such as DORA, NIS2, and GDPR
Bonus points if you:
Have experience working with Vanta or similar GRC automation tools
Can comprehend penetration test and vulnerability scan results
Have startup experience or experience working in a fast-moving environment
Are comfortable using technical tools, CLIs, or basic scripting to improve compliance workflows
Find Jobs in United Kingdom on Arbeitnow