Security Operations & GRC Manager in Glasgow

Security Operations & GRC Manager in Glasgow

Glasgow Full-Time No working from home possible
AccessFintech
Description

AccessFintech is seeking a senior Information Security professional to join our Technology function. This is a broad remit spanning three areas β€” AFT's internal information security posture, our governance, risk and compliance programme, and the security relationship with AFT's client network.

As a capital markets technology provider handling sensitive financial data for over 250 institutions, client security confidence is as important as internal security rigour, and both rest on a well-run compliance and assurance programme. This role requires someone who can operate credibly across all three β€” running robust security operations, owning the certification and risk framework, and engaging directly with clients on security due diligence, assessments, and trust-building conversations.

You will report directly to the CTO and work closely with engineering, product, client operations, and solutions teams across all three jurisdictions.


Requirements

1. Internal Information Security

β€’ Own and continuously improve AFT's information security posture across infrastructure, applications, cloud environments, and endpoints

β€’ Lead the operation and evolution of AFT's security tooling β€” SIEM, EDR, vulnerability management, intrusion detection, and identity and access management (IAM)

β€’ Own AFT's vulnerability management programme β€” regular assessments, remediation tracking, and risk reporting to the CTO and executive team

β€’ Lead security incident response β€” identification, containment, investigation, remediation, and post-incident review

β€’ Maintain and develop AFT's information security policies, standards, and procedures across all three jurisdictions

β€’ Embed security into AFT's software development lifecycle (SDLC) β€” partnering with engineering and DevOps to shift security left

β€’ Design and deliver security awareness training and communications across the global team

2. Client-Facing Security

β€’ Act as AFT's primary point of contact for all client security enquiries, assessments, and due diligence requests

β€’ Own the end-to-end response to client information security questionnaires β€” including standardised formats such as the Shared Assessments SIG and CSA CAIQ, as well as bespoke questionnaires issued by banks, custodians, and asset managers

β€’ Build and maintain a central answer library so questionnaire responses are consistent, accurate, and efficient to produce β€” reducing turnaround times and removing reliance on ad hoc drafting

β€’ Coordinate input from engineering, DevOps, legal, and compliance where questions fall outside the existing answer set, and quality-assure all responses before issue

β€’ Manage annual reassessments and periodic client re-certification cycles, ensuring responses remain current as the platform and control environment evolve

β€’ Represent AFT in client-facing security discussions, audits, and on-site or virtual security assessments β€” building confidence in AFT's security posture at senior level

β€’ Support the client onboarding process from a security and compliance perspective β€” ensuring new clients can satisfy their own internal security requirements for onboarding AFT

β€’ Partner with Client Operations and Solutions teams to proactively manage client security requirements as part of the commercial relationship

β€’ Maintain AFT's security documentation suite β€” trust centre content, security overview decks, penetration test summaries, and compliance certificates β€” keeping them current and client-ready

β€’ Track and manage client-raised security findings, ensuring remediation actions are progressed and communicated back to clients in a timely manner

β€’ Contribute to new business conversations where security posture is a factor β€” working with Sales and Solutions on RFP responses and client presentations

3. Governance, Risk & Compliance (GRC)

β€’ Own AFT's information security governance framework β€” policies, standards, and control documentation across all three jurisdictions

β€’ Own and maintain AFT's information security risk register β€” identifying, assessing, and tracking risks across internal and client-facing dimensions, with defined risk appetite and escalation thresholds

β€’ Own AFT's ISO 27001 and SOC 2 programmes end to end β€” control design, evidence collection, internal audit, gap remediation, and management of external auditors through certification and surveillance cycles

β€’ Maintain regulatory compliance mapping across UK (FCA, UK GDPR), US (SEC), and Israel (Privacy Protection Law), ensuring controls are traceable to obligations

β€’ Own the third-party and vendor security risk assessment programme β€” onboarding due diligence, ongoing monitoring, and contractual security requirements

β€’ Own the control testing and assurance calendar, ensuring controls are evidenced continuously rather than reconstructed at audit

β€’ Establish and run the security governance cadence β€” regular reporting to the CTO and executive team, translating technical risk into business-level insight

β€’ Lead preparation for external security audits, regulatory examinations, and client-initiated security reviews

Skills & Experience

Essential

β€’ 6–10 years of progressive experience in information security or cybersecurity, including at least 2 years in a client-facing or externally-engaged security role

β€’ Proven experience owning client information security questionnaires at volume β€” including standardised formats (SIG, CAIQ) and bespoke bank or custodian questionnaires β€” with a track record of building an answer library rather than responding ad hoc

β€’ Experience managing client-raised security findings through to remediation, and reporting outcomes back to client security teams

β€’ Demonstrable experience owning a GRC programme β€” running an ISO 27001 or SOC 2 certification cycle end to end, including evidence management, internal audit, and managing external auditors

β€’ Experience building and maintaining an information security risk register, with the ability to articulate risk appetite and escalate appropriately

β€’ Experience managing third-party and vendor security risk assessment programmes

β€’ Strong hands-on security operations experience β€” SIEM (e.g. Splunk, Microsoft Sentinel), EDR, vulnerability management (e.g. Tenable, Qualys), and IAM

β€’ Deep working knowledge of information security frameworks β€” ISO 27001, SOC 2, NIST CSF β€” and experience maintaining or achieving certification

β€’ Strong background in cloud-native applications and architectures, with cloud security expertise across IAM, network security, and cloud-native security monitoring

β€’ Strong understanding of data privacy and regulatory obligations in financial services β€” GDPR, FCA, SEC, or equivalent β€” including mapping controls across multiple regimes

β€’ Excellent communication skills β€” able to translate complex security concepts into clear, confident language for client security teams, legal and compliance functions, and non-technical business stakeholders

β€’ Comfortable engaging at senior level with client security and technology teams β€” building trust and managing relationships through complex due diligence processes

Desirable

β€’ Relevant security certifications β€” CISSP, CISM, CRISC, CISA, CEH, or equivalent

β€’ ISO 27001 Lead Implementer or Lead Auditor certification

β€’ Experience in capital markets, fintech, or regulated financial services β€” familiarity with the security expectations of buy-side, sell-side, or custodian institutions

β€’ Experience with DevSecOps practices β€” integrating security into CI/CD pipelines and engineering workflows

β€’ Scripting or automation capability β€” Python, PowerShell, or Bash β€” for security tooling and reporting

β€’ Experience building or maintaining a client trust centre or security documentation programme

β€’ Experience with GRC tooling and compliance automation platforms

β€’ AWS specifically is an advantage β€” hands-on experience securing containerised and serverless workloads, and using AWS-native security services such as GuardDuty, Security Hub, and Config

Security Operations & GRC Manager in Glasgow employer: AccessFintech

AccessFintech is an exceptional employer that fosters a collaborative and innovative work culture, particularly for Project Managers looking to make a significant impact in the financial services sector. With a focus on employee growth and development, the company offers comprehensive training and opportunities to engage with cutting-edge technologies, all while working in a dynamic environment that values teamwork and client relationships. Located in a vibrant area, AccessFintech provides a unique chance to be part of a forward-thinking team that is reshaping post-trade workflows across the industry.

AccessFintech

Contact Details:

AccessFintech Recruitment Team