Security Operations & GRC Manager

Security Operations & GRC Manager

Full-Time 63000 - 77000 £ / year (est.) No working from home possible
AccessFintech

At a Glance

  • Tasks: Lead security operations and manage client security relationships in a dynamic fintech environment.
  • Company: Join AccessFintech, a leading capital markets technology provider focused on security and compliance.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Be part of a forward-thinking company that values security and client trust.
  • Why this job: Make a real impact on security in the financial sector while collaborating with innovative teams.
  • Qualifications: 6-10 years in information security, with strong client-facing experience and GRC expertise.

The predicted salary is between 63000 - 77000 £ per year.

Access Fintech is seeking a senior Information Security professional to join our Technology function.

This is a broad remit spanning three areas — AFT's internal information security posture, our governance, risk and compliance programme, and the security relationship with AFT's client network.

As a capital markets technology provider handling sensitive financial data for over 250 institutions, client security confidence is as important as internal security rigour, and both rest on a well-run compliance and assurance programme.

This role requires someone who can operate credibly across all three — running robust security operations, owning the certification and risk framework, and engaging directly with clients on security due diligence, assessments, and trust-building conversations.

You will report directly to the CTO and work closely with engineering, product, client operations, and solutions teams across all three jurisdictions.

Requirements

  • Internal Information Security
  • Own and continuously improve AFT's information security posture across infrastructure, applications, cloud environments, and endpoints
  • Lead the operation and evolution of AFT's security tooling — SIEM, EDR, vulnerability management, intrusion detection, and identity and access management (IAM)
  • Own AFT's vulnerability management programme — regular assessments, remediation tracking, and risk reporting to the CTO and executive team
  • Lead security incident response — identification, containment, investigation, remediation, and post-incident review
  • Maintain and develop AFT's information security policies, standards, and procedures across all three jurisdictions
  • Embed security into AFT's software development lifecycle (SDLC) — partnering with engineering and Dev Ops to shift security left
  • Design and deliver security awareness training and communications across the global team
  • Client-Facing Security
  • Act as AFT's primary point of contact for all client security enquiries, assessments, and due diligence requests
  • Own the end-to-end response to client information security questionnaires — including standardised formats such as the Shared Assessments SIG and CSA CAIQ, as well as bespoke questionnaires issued by banks, custodians, and asset managers
  • Build and maintain a central answer library so questionnaire responses are consistent, accurate, and efficient to produce — reducing turnaround times and removing reliance on ad hoc drafting
  • Coordinate input from engineering, Dev Ops, legal, and compliance where questions fall outside the existing answer set, and quality-assure all responses before issue
  • Manage annual reassessments and periodic client re-certification cycles, ensuring responses remain current as the platform and control environment evolve
  • Represent AFT in client-facing security discussions, audits, and on-site or virtual security assessments — building confidence in AFT's security posture at senior level
  • Support the client onboarding process from a security and compliance perspective — ensuring new clients can satisfy their own internal security requirements for onboarding AFT
  • Partner with Client Operations and Solutions teams to proactively manage client security requirements as part of the commercial relationship
  • Maintain AFT's security documentation suite — trust centre content, security overview decks, penetration test summaries, and compliance certificates — keeping them current and client-ready
  • Track and manage client-raised security findings, ensuring remediation actions are progressed and communicated back to clients in a timely manner
  • Contribute to new business conversations where security posture is a factor — working with Sales and Solutions on RFP responses and client presentations
  • Governance, Risk & Compliance (GRC)
  • Own AFT's information security governance framework — policies, standards, and control documentation across all three jurisdictions
  • Own and maintain AFT's information security risk register — identifying, assessing, and tracking risks across internal and client-facing dimensions, with defined risk appetite and escalation thresholds
  • Own AFT's ISO 27001 and SOC 2 programmes end to end — control design, evidence collection, internal audit, gap remediation, and management of external auditors through certification and surveillance cycles
  • Maintain regulatory compliance mapping across UK (FCA, UK GDPR), US (SEC), and Israel (Privacy Protection Law), ensuring controls are traceable to obligations
  • Own the third-party and vendor security risk assessment programme — onboarding due diligence, ongoing monitoring, and contractual security requirements
  • Own the control testing and assurance calendar, ensuring controls are evidenced continuously rather than reconstructed at audit
  • Establish and run the security governance cadence — regular reporting to the CTO and executive team, translating technical risk into business-level insight
  • Lead preparation for external security audits, regulatory examinations, and client-initiated security reviews

Essential

Skills & Experience

  • 6-10 years of progressive experience in information security or cybersecurity, including at least 2 years in a client-facing or externally-engaged security role
  • Proven experience owning client information security questionnaires at volume — including standardised formats (SIG, CAIQ) and bespoke bank or custodian questionnaires — with a track record of building an answer library rather than responding ad hoc
  • Experience managing client-raised security findings through to remediation, and reporting outcomes back to client security teams
  • Demonstrable experience owning a GRC programme — running an ISO 27001 or SOC 2 certification cycle end to end, including evidence management, internal audit, and managing external auditors
  • Experience building and maintaining an information security risk register, with the ability to articulate risk appetite and elevate appropriately
  • Experience managing third-party and vendor security risk assessment programmes
  • Strong hands-on security operations experience — SIEM (e. g. Splunk, Microsoft Sentinel), EDR, vulnerability management (e. g. Tenable, Qualys), and IAM
  • Deep working knowledge of information security frameworks — ISO 27001, SOC 2, NIST CSF — and experience maintaining or achieving certification
  • Strong background in cloud-native applications and architectures, with cloud security expertise across IAM, network security, and cloud-native security monitoring
  • Strong understanding of data privacy and regulatory obligations in financial services — GDPR, FCA, SEC, or equivalent — including mapping controls across multiple regimes
  • Excellent communication skills — able to translate complex security concepts into clear, confident language for client security teams, legal and compliance functions, and non-technical business stakeholders
  • Comfortable engaging at senior level with client security and technology teams — building trust and managing relationships through complex due diligence processes

Desirable

  • Relevant security certifications — CISSP, CISM, CRISC, CISA, CEH, or equivalent
  • ISO 27001 Lead Implementer or Lead Auditor certification
  • Experience in capital markets, fintech, or regulated financial services — familiarity with the security expectations of buy-side, sell-side, or custodian institutions
  • Experience with Dev Sec Ops practices — integrating security into CI/CD pipelines and engineering workflows
  • Scripting or automation capability — Python, Power Shell, or Bash — for security tooling and reporting
  • Experience building or maintaining a client trust centre or security documentation programme
  • Experience with GRC tooling and compliance automation platforms
  • AWS specifically is an advantage — hands-on experience securing containerised and serverless workloads, and using AWS-native security services such as Guard Duty, Security Hub, and Config
  • #J-18808-Ljbffr

Security Operations & GRC Manager employer: AccessFintech

AccessFintech is an exceptional employer that fosters a collaborative and innovative work culture, particularly for Project Managers looking to make a significant impact in the financial services sector. With a focus on employee growth and development, the company offers comprehensive training and opportunities to engage with cutting-edge technologies, all while working in a dynamic environment that values teamwork and client relationships. Located in a vibrant area, AccessFintech provides a unique chance to be part of a forward-thinking team that is reshaping post-trade workflows across the industry.

AccessFintech

Contact Details:

AccessFintech Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Operations & GRC Manager

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including AccessFintech, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through AccessFintech

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at AccessFintech. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security Operations & GRC Manager

Information Security
Governance, Risk and Compliance (GRC)
Client-Facing Security
ISO 27001
SOC 2
Security Incident Response
Vulnerability Management

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at AccessFintech insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to AccessFintech that you’re committed to staying ahead in the game.

How to prepare for a job interview at AccessFintech

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at AccessFintech to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at AccessFintech.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.