Security Operations & GRC Manager
פורסם אתמול · 0 מועמדים
התפקיד במילים פשוטות
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןAccessFintech is seeking a senior Information Security professional to join our Technology function. This is a broad remit spanning three areas — AFT's internal information security posture, our governance, risk and compliance programme, and the security relationship with AFT's client network.
As a capital markets technology provider handling sensitive financial data for over 250 institutions, client security confidence is as important as internal security rigour, and both rest on a well-run compliance and assurance programme. This role requires someone who can operate credibly across all three — running robust security operations, owning the certification and risk framework, and engaging directly with clients on security due diligence, assessments, and trust-building conversations.
You will report directly to the CTO and work closely with engineering, product, client operations, and solutions teams across all three jurisdictions.
Requirements
• Internal Information Security
• Own and continuously improve AFT's information security posture across infrastructure, applications, cloud environments, and endpoints
• Lead the operation and evolution of AFT's security tooling — SIEM, EDR, vulnerability management, intrusion detection, and identity and access management (IAM)
• Own AFT's vulnerability management programme — regular assessments, remediation tracking, and risk reporting to the CTO and executive team
• Lead security incident response — identification, containment, investigation, remediation, and post-incident review
• Maintain and develop AFT's information security policies, standards, and procedures across all three jurisdictions
• Embed security into AFT's software development lifecycle (SDLC) — partnering with engineering and DevOps to shift security left
• Design and deliver security awareness training and communications across the global team
• Client-Facing Security
• Act as AFT's primary point of contact for all client security enquiries, assessments, and due diligence requests
• Own the end-to-end response to client information security questionnaires — including standardised formats such as the Shared Assessments SIG and CSA CAIQ, as well as bespoke questionnaires issued by banks, custodians, and asset managers
• Build and maintain a central answer library so questionnaire responses are consistent, accurate, and efficient to produce — reducing turnaround times and removing reliance on ad hoc drafting
• Coordinate input from engineering, DevOps, legal, and compliance where questions fall outside the existing answer set, and quality-assure all responses before issue
• Manage annual reassessments and periodic client re-certification cycles, ensuring responses remain current as the platform and control environment evolve
• Represent AFT in client-facing security discussions, audits, and on-site or virtual security assessments — building confidence in AFT's security posture at senior level
• Support the client onboarding process from a security and compliance perspective — ensuring new clients can satisfy their own internal security requirements for onboarding AFT
• Partner with Client Operations and Solutions teams to proactively manage client security requirements as part of the commercial relationship
• Maintain AFT's security documentation suite — trust centre content, security overview decks, penetration test summaries, and compliance certificates — keeping them current and client-ready
• Track and manage client-raised security findings, ensuring remediation actions are progressed and communicated back to clients in a timely manner
• Contribute to new business conversations where security posture is a factor — working with Sales and Solutions on RFP responses and client presentations
• Governance, Risk & Compliance (GRC)
• Own AFT's information security governance framework — policies, standards, and control documentation across all three jurisdictions
• Own and maintain AFT's information security risk register — identifying, assessing, and tracking risks across internal and client-facing dimensions, with defined risk appetite and escalation thresholds
• Own AFT's ISO 27001 and SOC 2 programmes end to end — control design, evidence collection, internal audit, gap remediation, and management of external auditors through certification and surveillance cycles
• Maintain regulatory compliance mapping across UK (FCA, UK GDPR), US (SEC), and Israel (Privacy Protection Law), ensuring controls are traceable to obligations
• Own the third-party and vendor security risk assessment programme — onboarding due diligence, ongoing monitoring, and contractual security requirements
• Own the control testing and assurance calendar, ensuring controls are evidenced continuously rather than reconstructed at audit
• Establish and run the security governance cadence — regular reporting to the CTO and executive team, translating technical risk into business-level insight
• Lead preparation for external security audits, regulatory examinations, and client-initiated security reviews
Essential
Skills & Experience
• 6-10 years of progressive experience in information security or cybersecurity, including at least 2 years in a client-facing or externally-engaged security role
• Proven experience owning client information security questionnaires at volume — including standardised formats (SIG, CAIQ) and bespoke bank or custodian questionnaires — with a track record of building an answer library rather than responding ad hoc
• Experience managing client-raised security findings through to remediation, and reporting outcomes back to client security teams
• Demonstrable experience owning a GRC programme — running an ISO 27001 or SOC 2 certification cycle end to end, including evidence management, internal audit, and managing external auditors
• Experience building and maintaining an information security risk register, with the ability to articulate risk appetite and escalate appropriately
• Experience managing third-party and vendor security risk assessment programmes
• Strong hands-on security operations experience — SIEM (e.g. Splunk, Microsoft Sentinel), EDR, vulnerability management (e.g. Tenable, Qualys), and IAM
• Deep working knowledge of information security frameworks — ISO 27001, SOC 2, NIST CSF — and experience maintaining or achieving certification
• Strong background in cloud-native applications and architectures, with cloud security expertise across IAM, network security, and cloud-native security monitoring
• Strong understanding of data privacy and regulatory obligations in financial services — GDPR, FCA, SEC, or equivalent — including mapping controls across multiple regimes
• Excellent communication skills — able to translate complex security concepts into clear, confident language for client security teams, legal and compliance functions, and non-technical business stakeholders
• Comfortable engaging at senior level with client security and technology teams — building trust and managing relationships through complex due diligence processes
Desirable
• Relevant security certifications — CISSP, CISM, CRISC, CISA, CEH, or equivalent
• ISO 27001 Lead Implementer or Lead Auditor certification
• Experience in capital markets, fintech, or regulated financial services — familiarity with the security expectations of buy-side, sell-side, or custodian institutions
• Experience with DevSecOps practices — integrating security into CI/CD pipelines and engineering workflows
• Scripting or automation capability — Python, PowerShell, or Bash — for security tooling and reporting
• Experience building or maintaining a client trust centre or security documentation programme
• Experience with GRC tooling and compliance automation platforms
• AWS specifically is an advantage — hands-on experience securing containerised and serverless workloads, and using AWS-native security services such as GuardDuty, Security Hub, and Config
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.