FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in information security governance, risk management, and compliance with regulatory standards such as ISO 27001, DORA, and GDPR. Proficient in managing audits, vendor risk assessments, and GRC platforms to ensure operational resilience and adherence to industry regulations.
Highest-signal resume keywords
ISO/IEC 27001GRC Platform AdministrationRisk ManagementIT Audit CoordinationCompliance Automation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Information Security PoliciesRisk IdentificationRisk AssessmentAudit ManagementPolicy DraftingEvidence CollectionControl MonitoringAutomated Evidence CollectionWorkflow AutomationGap Analysis
Soft Skills
Strong Written EnglishTime Management
Tools & Technologies
GRC PlatformsVantaServiceNow GRCOneTrustAI Tools
Certifications & Qualifications
CISACRISCCISMCIPP/EISO 27001 Lead Auditor
Industry Keywords
DORAGDPRPCI DSSFCA Operational ResilienceRegulated Financial Services
Tech Stack
Tools & technologiesAssemblyServiceNow
About the role
Key responsibilities & impact- Develop, maintain and continuously improve information security policies, standards and procedures aligned with ISO 27001 and applicable regulatory requirements
- Manage the full policy lifecycle, including approval workflows, periodic reviews, ownership and version control
- Maintain the information security risk register, including risk identification, assessment, treatment tracking and formal risk acceptance
- Prepare risk reporting for management and governance committees and track remediation actions through closure
- Support compliance activities under DORA, including the Register of Information, PSD2/EBA ICT guidelines, GDPR and PCI DSS across licensed entities
- Contribute to operational resilience activities for the UK entity in line with FCA requirements
- Manage the third-party risk management lifecycle, including due diligence, security questionnaires, risk rating, onboarding gates and periodic reassessments
- Maintain the vendor register and contractual security requirements with the Legal team
- Coordinate internal and external audits, including Big Four ICT audits, regulator requests and PCI QSA cycles, and manage the audit calendar
- Own evidence collection and maintain an evidence library for audits, certifications and client questionnaires
- Administer and develop the GRC platform, including control monitoring, automated evidence collection, framework mapping and reporting
- Apply AI tools to GRC activities such as policy drafting, gap analysis, evidence assembly and questionnaire responses, and automate recurring processes
- Contribute to the AI governance programme, including AI vendor assessment, support of the AI system register and alignment with emerging requirements such as the EU AI Act
- Report to the Head of Information Security
Requirements
What you’ll need- 3+ years of similar experience in GRC, information security governance, IT audit or IT risk management
- Working knowledge of ISO/IEC 27001
- Exposure to DORA, GDPR or PCI DSS
- Experience in regulated financial services (payments, e-money, banking, fintech) or advisory work for such companies
- Hands-on experience with audits, including coordinating audits, preparing evidence and remediating findings
- Familiarity with GRC platforms or a strong interest in compliance automation
- Strong written English
- Ability to manage multiple workstreams against fixed deadlines
- Certifications such as CISA, CRISC, CISM, CIPP/E or ISO 27001 Lead Auditor / Lead Implementer are nice to have
- Direct experience with DORA implementation, EBA outsourcing guidelines or FCA operational resilience is nice to have
- Experience implementing or administering a GRC platform such as Vanta, ServiceNow GRC, OneTrust or similar is nice to have
- Familiarity with ISO 42001, the EU AI Act or AI risk management is nice to have
- Light scripting or workflow automation skills using low-code tools are nice to have
Benefits
Comp & perks- Annual Learning Budget for professional development (eligible after probation)
- Company celebrations bringing colleagues from all offices together
- Opportunities to participate in international company events and initiatives
- Global collaboration with colleagues from all regions
