Skip to main content

Security Operations & GRC Manager

AccessFintechTel Aviv-Yafo, Tel Aviv District, IsraelNot specifiedFull-timeSeniority: Not specified

Posted yesterday · 0 applicants

Salary not listed for this role

Saving, applying or scoring takes a few seconds to set up your free account.

Willbi insight

The role in plain words

Must-have
  • 6-10 years of progressive experience in information security or cybersecurity, including 2+ years in a client-facing role
  • Experience owning client information security questionnaires (SIG, CAIQ, bespoke bank questionnaires) and building answer libraries
  • Experience owning a GRC programme and running ISO 27001 or SOC 2 certification cycles end-to-end
  • Experience building and maintaining an information security risk register and managing third-party vendor risk
  • Hands-on security operations experience across SIEM, EDR, vulnerability management, and IAM
Nice-to-have
  • Security certifications such as CISSP, CISM, CRISC, CISA, CEH, or equivalent
  • ISO 27001 Lead Implementer or Lead Auditor certification
  • Experience with DevSecOps practices and integrating security into CI/CD pipelines
  • Scripting or automation capability in Python, PowerShell, or Bash
  • AWS hands-on experience and native security services (GuardDuty, Security Hub, Config)

Extracted from the job description · kept up to date automatically

Who this suits

Full job description

Original listing · kept for reference

AccessFintech is seeking a senior Information Security professional to join our Technology function. This is a broad remit spanning three areas — AFT's internal information security posture, our governance, risk and compliance programme, and the security relationship with AFT's client network.

As a capital markets technology provider handling sensitive financial data for over 250 institutions, client security confidence is as important as internal security rigour, and both rest on a well-run compliance and assurance programme. This role requires someone who can operate credibly across all three — running robust security operations, owning the certification and risk framework, and engaging directly with clients on security due diligence, assessments, and trust-building conversations.

You will report directly to the CTO and work closely with engineering, product, client operations, and solutions teams across all three jurisdictions.

Requirements

• Internal Information Security

• Own and continuously improve AFT's information security posture across infrastructure, applications, cloud environments, and endpoints

• Lead the operation and evolution of AFT's security tooling — SIEM, EDR, vulnerability management, intrusion detection, and identity and access management (IAM)

• Own AFT's vulnerability management programme — regular assessments, remediation tracking, and risk reporting to the CTO and executive team

• Lead security incident response — identification, containment, investigation, remediation, and post-incident review

• Maintain and develop AFT's information security policies, standards, and procedures across all three jurisdictions

• Embed security into AFT's software development lifecycle (SDLC) — partnering with engineering and DevOps to shift security left

• Design and deliver security awareness training and communications across the global team

• Client-Facing Security

• Act as AFT's primary point of contact for all client security enquiries, assessments, and due diligence requests

• Own the end-to-end response to client information security questionnaires — including standardised formats such as the Shared Assessments SIG and CSA CAIQ, as well as bespoke questionnaires issued by banks, custodians, and asset managers

• Build and maintain a central answer library so questionnaire responses are consistent, accurate, and efficient to produce — reducing turnaround times and removing reliance on ad hoc drafting

• Coordinate input from engineering, DevOps, legal, and compliance where questions fall outside the existing answer set, and quality-assure all responses before issue

• Manage annual reassessments and periodic client re-certification cycles, ensuring responses remain current as the platform and control environment evolve

• Represent AFT in client-facing security discussions, audits, and on-site or virtual security assessments — building confidence in AFT's security posture at senior level

• Support the client onboarding process from a security and compliance perspective — ensuring new clients can satisfy their own internal security requirements for onboarding AFT

• Partner with Client Operations and Solutions teams to proactively manage client security requirements as part of the commercial relationship

• Maintain AFT's security documentation suite — trust centre content, security overview decks, penetration test summaries, and compliance certificates — keeping them current and client-ready

• Track and manage client-raised security findings, ensuring remediation actions are progressed and communicated back to clients in a timely manner

• Contribute to new business conversations where security posture is a factor — working with Sales and Solutions on RFP responses and client presentations

• Governance, Risk & Compliance (GRC)

• Own AFT's information security governance framework — policies, standards, and control documentation across all three jurisdictions

• Own and maintain AFT's information security risk register — identifying, assessing, and tracking risks across internal and client-facing dimensions, with defined risk appetite and escalation thresholds

• Own AFT's ISO 27001 and SOC 2 programmes end to end — control design, evidence collection, internal audit, gap remediation, and management of external auditors through certification and surveillance cycles

• Maintain regulatory compliance mapping across UK (FCA, UK GDPR), US (SEC), and Israel (Privacy Protection Law), ensuring controls are traceable to obligations

• Own the third-party and vendor security risk assessment programme — onboarding due diligence, ongoing monitoring, and contractual security requirements

• Own the control testing and assurance calendar, ensuring controls are evidenced continuously rather than reconstructed at audit

• Establish and run the security governance cadence — regular reporting to the CTO and executive team, translating technical risk into business-level insight

• Lead preparation for external security audits, regulatory examinations, and client-initiated security reviews

Essential

Skills & Experience

• 6-10 years of progressive experience in information security or cybersecurity, including at least 2 years in a client-facing or externally-engaged security role

• Proven experience owning client information security questionnaires at volume — including standardised formats (SIG, CAIQ) and bespoke bank or custodian questionnaires — with a track record of building an answer library rather than responding ad hoc

• Experience managing client-raised security findings through to remediation, and reporting outcomes back to client security teams

• Demonstrable experience owning a GRC programme — running an ISO 27001 or SOC 2 certification cycle end to end, including evidence management, internal audit, and managing external auditors

• Experience building and maintaining an information security risk register, with the ability to articulate risk appetite and escalate appropriately

• Experience managing third-party and vendor security risk assessment programmes

• Strong hands-on security operations experience — SIEM (e.g. Splunk, Microsoft Sentinel), EDR, vulnerability management (e.g. Tenable, Qualys), and IAM

• Deep working knowledge of information security frameworks — ISO 27001, SOC 2, NIST CSF — and experience maintaining or achieving certification

• Strong background in cloud-native applications and architectures, with cloud security expertise across IAM, network security, and cloud-native security monitoring

• Strong understanding of data privacy and regulatory obligations in financial services — GDPR, FCA, SEC, or equivalent — including mapping controls across multiple regimes

• Excellent communication skills — able to translate complex security concepts into clear, confident language for client security teams, legal and compliance functions, and non-technical business stakeholders

• Comfortable engaging at senior level with client security and technology teams — building trust and managing relationships through complex due diligence processes

Desirable

• Relevant security certifications — CISSP, CISM, CRISC, CISA, CEH, or equivalent

• ISO 27001 Lead Implementer or Lead Auditor certification

• Experience in capital markets, fintech, or regulated financial services — familiarity with the security expectations of buy-side, sell-side, or custodian institutions

• Experience with DevSecOps practices — integrating security into CI/CD pipelines and engineering workflows

• Scripting or automation capability — Python, PowerShell, or Bash — for security tooling and reporting

• Experience building or maintaining a client trust centre or security documentation programme

• Experience with GRC tooling and compliance automation platforms

• AWS specifically is an advantage — hands-on experience securing containerised and serverless workloads, and using AWS-native security services such as GuardDuty, Security Hub, and Config

About AccessFintech
Company profile · coming soon

Employee reviews · coming soonMore roles at AccessFintech

Questions about this role

  • This listing did not state a salary. We only show pay when the employer publishes it.
Similar & related
AccessFintech
Posted yesterday · 0 applicants
See how you match