FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Tech Stack
Tools & technologiesAWSCloudSDLC
About the role
Key responsibilities & impact- Own the recurring security assurance cycle end to end
- Run third-party security due diligence, supplier tiering, reassessments, registers, concentration-risk tracking, and exit plans
- Own responses to inbound security due diligence from funders, banking partners, investors, commercial partners, and prospects
- Build and maintain a reusable security trust pack and standard questionnaire pre-fills
- Maintain the annual security assurance calendar and ensure activities produce evidence and close actions
- Coordinate external penetration tests from scoping through remediation and retesting
- Facilitate tabletop exercises and track post-exercise actions
- Maintain the information security risk register and administer policy exceptions and risk acceptances
- Perform first-line control testing and retain evidence
- Produce security management information for the Head of Security, ExCo, and Risk Committee
- Consolidate and manage vulnerabilities and security findings from EDR, cloud security posture, SAST/DAST/SCA, secrets scanning, and penetration tests
- Triage findings, coordinate remediation with engineering teams, escalate ageing findings, and report remediation performance
- Run security awareness activities, phishing simulations, role-based training, and completion tracking
- Coordinate pre-employment screening with People
- Contribute to the ISO 27001 ISMS, including control documentation, Statement of Applicability, evidence collection, internal audits, and external auditor liaison
- Draft, review, approve, and maintain security policies and standards
- Maintain incident response plans and playbooks, facilitate post-incident reviews, track remediation, and support regulatory notifications
- Maintain business continuity and disaster recovery documentation and testing evidence
- Embed security requirements into the SDLC and support threat modelling
- Support RoPA maintenance, DPIA completion, and DSAR handling with Legal
Requirements
What you’ll need- Three or more years in an information security assurance, GRC or security compliance role
- At least some experience in a regulated financial services environment or another environment with real external audit pressure
- Hands-on experience of ISO 27001, whether operating an ISMS or taking one through certification
- Demonstrable experience running third-party or vendor security assessments
- Demonstrable experience responding to inbound security due diligence
- Ability to read technical findings, including EDR vulnerability reports, penetration test findings, and cloud misconfigurations, and assess severity and real-world exploitability
- Clear, concise written English
- Confidence to challenge engineers and suppliers and identify inadequate answers
- Experience of a cloud-native environment, ideally AWS (desirable)
- Experience of scaling a control framework as an organisation grows (desirable)
- Familiarity with UK operational resilience expectations (SYSC 15A) and outsourcing requirements (SYSC 8) (desirable)
- Certifications such as CISM, CISA, ISO 27001 Lead Implementer or Lead Auditor, CRISC or CCSP (desirable)
- Willingness to come to the office three times a week
- Visa eligibility for the location where the job is based is addressed in the application form
Benefits
Comp & perks- No benefits, perks, or compensation extras are specified in the posting.
