At a Glance
- Tasks: Lead and enhance our Information Security Governance, Risk, and Compliance programme.
- Company: Boku is a global leader in mobile-first payment solutions, trusted by top brands worldwide.
- Benefits: Enjoy a diverse workplace with opportunities for remote work and professional growth.
- Why this job: Join a dynamic team making a real impact in the fintech industry while ensuring data security.
- Qualifications: 5+ years in Information Security or GRC roles; familiarity with ISO 27001 and GDPR is essential.
- Other info: This role offers a chance to work with global teams and develop a security-first culture.
The predicted salary is between 36000 - 60000 £ per year.
Boku Inc. (BOKU.L) is the leading global provider of local mobile-first payments solutions. Global brands including Amazon, DAZN, Meta, Google, Microsoft, Netflix, Sony, Spotify, and Tencent rely on Boku to reach millions of new paying consumers who do not use credit cards with our purpose-built payment network of more than 300 local payment methods across 70+ countries. Every year, Boku processes over $10 billion in value for our customers. Incorporated in 2008, Boku is headquartered in London and San Francisco and has employees in over 39 countries around the world.
Role Purpose: We are seeking a highly motivated and detail-oriented Security Governance, Risk, and Compliance (GRC) Manager to drive the maturity of our information security program across governance, risk management, regulatory compliance, and control assurance. This role plays a critical part in safeguarding the firm’s information assets, ensuring ongoing alignment with ISO 27001, SOC 2, PCI DSS, GDPR, and region-specific regulatory frameworks (e.g., RBI, DORA, MAS). You will act as the central point of coordination for risk reporting, policy governance, audit support, and cross-functional control implementation, working closely with internal stakeholders, regulators, and third-party partners.
Key Responsibilities:
- Lead the design, implementation, and continuous improvement of the firm’s Information Security Governance, Risk, and Compliance program.
- Own and maintain information security policies, standards, and procedures aligned to ISO 27001 and other regulatory frameworks.
- Coordinate internal and external audits, including evidence gathering, control walkthroughs, findings management, and follow-up remediation.
- Conduct and manage IT/security risk assessments and support enterprise risk reporting cycles.
- Oversee the implementation and monitoring of key controls across technology, cloud platforms, and business processes.
- Maintain the ISMS and support ongoing ISO 27001 certification and surveillance activities.
- Work with Legal, Engineering, IT, and Compliance teams to support data protection (e.g., GDPR), supplier risk, and contractual security requirements.
- Build and track risk registers, control testing results, and remediation plans.
- Identify suitable GRC tooling to support enterprise activities and work to implement.
- Lead periodic governance forums including Security Council and Risk Review Board meetings.
- Monitor changes in regulations and industry standards to ensure timely updates to internal programs.
- Develop training and awareness programs to foster a security-first culture across the organization.
Qualifications:
- 5+ years of experience in Information Security, GRC, Risk Management, or Compliance roles within a regulated industry (e.g., payments, fintech, healthcare).
- Strong understanding of frameworks such as ISO 27001, SOC 2, PCI DSS, GDPR, and/or NIST CSF.
- Experience managing or supporting external audits, certifications, or regulatory inspections.
- Knowledge of risk assessment methodologies, control design, and assurance testing.
- Ability to interpret complex security requirements and translate them into practical internal controls.
- Familiarity with GRC tools and platforms.
- Excellent project management, stakeholder engagement, and written communication skills.
- Highly organized, self-directed, and able to manage multiple priorities with attention to detail.
- Experience working in regulated entities is essential.
Security GRC Manager employer: Boku
Contact Detail:
Boku Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security GRC Manager
✨Tip Number 1
Familiarise yourself with the specific regulatory frameworks mentioned in the job description, such as ISO 27001 and GDPR. Being able to discuss these frameworks in detail during your interview will demonstrate your expertise and commitment to the role.
✨Tip Number 2
Network with professionals in the information security and GRC fields. Attend relevant industry events or webinars where you can meet people who work at Boku or similar companies. This can provide you with insider knowledge and potentially a referral.
✨Tip Number 3
Prepare to discuss your experience with audits and compliance in detail. Think of specific examples where you've successfully managed audits or implemented compliance measures, as this is a key responsibility of the role.
✨Tip Number 4
Showcase your project management skills by preparing examples of how you've led initiatives in previous roles. Highlight your ability to manage multiple priorities and engage stakeholders effectively, as these are crucial for the Security GRC Manager position.
We think you need these skills to ace Security GRC Manager
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in Information Security, GRC, Risk Management, or Compliance. Use keywords from the job description, such as ISO 27001, SOC 2, and GDPR, to demonstrate your fit for the role.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for security governance and compliance. Mention specific achievements in previous roles that align with the responsibilities listed in the job description, such as leading audits or managing risk assessments.
Showcase Your Skills: In your application, emphasise your project management and stakeholder engagement skills. Provide examples of how you've successfully communicated complex security requirements to various teams or stakeholders.
Highlight Continuous Learning: Mention any relevant certifications or ongoing education related to information security and compliance. This shows your commitment to staying updated with industry standards and regulations, which is crucial for the role.
How to prepare for a job interview at Boku
✨Know Your Frameworks
Familiarise yourself with ISO 27001, SOC 2, PCI DSS, and GDPR. Be prepared to discuss how these frameworks apply to the role and your previous experiences in managing compliance.
✨Demonstrate Risk Management Skills
Prepare examples of how you've conducted risk assessments and managed risk registers in past roles. Highlight your ability to translate complex security requirements into practical controls.
✨Showcase Your Project Management Experience
Be ready to talk about your project management skills, especially in coordinating audits and implementing security policies. Use specific examples to illustrate your organisational abilities.
✨Engage with Stakeholders
Discuss your experience working with cross-functional teams, such as Legal, IT, and Compliance. Emphasise your communication skills and how you’ve built relationships to foster a security-first culture.