At a Glance
- Tasks: Evaluate and enhance information security frameworks, ensuring compliance with industry standards.
- Company: Thredd is a trusted payments partner processing billions of transactions for innovators worldwide.
- Benefits: Enjoy a hybrid work environment and hands-on support in a secure setting.
- Why this job: Make a significant impact on security while fostering a culture of awareness across the company.
- Qualifications: Experience in InfoSec, especially with PCI DSS and ISO 27001; degree in Computer Science or related field.
- Other info: Candidates will undergo credit and background checks as permitted by law.
The predicted salary is between 36000 - 60000 £ per year.
Are you an InfoSec Auditor with experience in PCI DSS & ISO 27001, ready to drive our organisation\’s compliance?
What you\’ll be doing
Thredd is looking for an Information Security Auditor to join our Info Sec team based out of our London office. In this role, you will evaluate and enhance our information security frameworks and internal control systems, ensuring compliance with SOC 2, ISO 27001, ISO 22301, and PCI DSS requirements. You\’ll support audits, track security performance, manage supplier relationships, alongside handling day-to-day risk management. This position offers an opportunity to make a significant impact on our organisation\’s security landscape. You\’ll work closely with cross-functional teams and play a key role in fostering a culture of security awareness throughout the company.
Responsibilities
- Stay informed on emerging regulations and governance standards to maintain the organisation\’s forward-looking security posture.
- Conduct comprehensive risk assessments to identify, evaluate, and mitigate risks related to governance, data security, and compliance. Effectively respond to third-party requests for information, ensuring alignment with contractual and regulatory obligations.
- Perform thorough audits of security controls, processes, and systems to ensure compliance with organisational governance policies and industry standards such as ISO 27001, SOC 2, and PCI DSS.
- Assess the effectiveness of internal governance frameworks, identify areas for improvement, and propose actionable recommendations. Monitor adherence to governance frameworks, escalating non-compliance issues as necessary.
- Develop and deliver engaging training sessions to employees on internal governance standards and compliance best practices, enhancing overall security awareness.
- Address day-to-day risk management tasks and respond promptly to security alerts, ensuring swift and effective resolution of potential threats.
- Oversee supplier relationships and conduct thorough vendor/client onboarding reviews to maintain security standards across the organisation\’s network.
- Implement and maintain systems to track security performance and compliance posture over time, providing insights for continuous improvement.
- Assist in the preparation and execution of internal audits, and help coordinate external audit processes to ensure organisational readiness and compliance.
What you bring
- Proven experience in a similar role, ideally within financial services industry.
- Prior interaction with security frameworks – particularly PCI DSS and ISO 27001.
- Understanding of regulatory reporting and compliance.
- Bachelor\’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
- Basic knowledge of IT security controls.
- Prior experience and understanding of security audits, compliance assessments and internal security reviews.
- A natural problem solver with strong analytical skills.
- Collaborate effectively not only with immediate InfoSec team but cross-functionally on a global scale.
A bit about us …
Thredd is the trusted next-gen payments partner for innovators looking to modernise their payments offering. Certified by Mastercard, Visa and Diners & Discover, we process billions of debit, prepaid, and credit transactions annually, supporting consumer and corporate fintechs, digital banks, and embedded finance providers across the globe. Our unique offering is our client-centric approach, combining hands-on support with modern, reliable, and scalable technology. Our assured solution accelerates the development and delivery of consumer and corporate payments components embedded within digital banks, as well as for expense management, B2B payments, crypto, lending, credit, Buy Now Pay Later, FX, remittance, and open banking innovators.
Other
This role is a hybrid role based out of our London office. Thredd operates in a secure environment and all candidates will be Credit and Background checked to the extent permitted by law.
#J-18808-Ljbffr
Information Security Auditor employer: Thredd
Contact Detail:
Thredd Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Auditor
✨Tip Number 1
Familiarize yourself with the specific compliance frameworks mentioned in the job description, such as PCI DSS and ISO 27001. Understanding these standards deeply will not only help you in interviews but also demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals in the information security field, especially those who have experience in financial services. Engaging with industry peers can provide insights into the role and may even lead to referrals.
✨Tip Number 3
Stay updated on emerging regulations and governance standards relevant to information security. This knowledge will be crucial during discussions about maintaining a forward-looking security posture within the organization.
✨Tip Number 4
Prepare to discuss your experience with risk assessments and audits in detail. Be ready to share specific examples of how you've identified and mitigated risks in previous roles, as this will showcase your problem-solving skills and analytical abilities.
We think you need these skills to ace Information Security Auditor
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Information Security Auditor position at Thredd. Familiarize yourself with PCI DSS, ISO 27001, and other relevant standards mentioned in the job description.
Tailor Your CV: Customize your CV to highlight your experience with security frameworks, compliance assessments, and risk management. Use specific examples from your past roles that demonstrate your expertise in these areas.
Craft a Compelling Cover Letter: Write a cover letter that not only outlines your qualifications but also expresses your enthusiasm for the role and the company. Mention how your skills align with Thredd's mission and values, particularly in enhancing their information security landscape.
Highlight Relevant Experience: In your application, emphasize any previous roles where you conducted audits, managed supplier relationships, or developed training sessions on compliance best practices. This will showcase your ability to contribute effectively to Thredd's InfoSec team.
How to prepare for a job interview at Thredd
✨Showcase Your Compliance Knowledge
Be prepared to discuss your experience with PCI DSS and ISO 27001 in detail. Highlight specific instances where you've successfully implemented these frameworks or conducted audits, as this will demonstrate your expertise and relevance to the role.
✨Demonstrate Analytical Skills
Since the role requires strong analytical skills, be ready to provide examples of how you've identified and mitigated risks in previous positions. Use the STAR method (Situation, Task, Action, Result) to structure your responses effectively.
✨Engage with Cross-Functional Collaboration
Thredd values collaboration across teams. Prepare to discuss how you've worked with different departments to enhance security awareness and compliance. Share specific examples that illustrate your ability to communicate complex security concepts to non-technical stakeholders.
✨Stay Updated on Security Trends
Show your commitment to staying informed about emerging regulations and governance standards. Mention any recent developments in the InfoSec landscape that you find relevant, and be ready to discuss how they could impact Thredd's security posture.