Security GRC Manager
Security GRC Manager

Security GRC Manager

London Full-Time 43200 - 72000 £ / year (est.) No home office possible
B

At a Glance

  • Tasks: Lead and enhance our Information Security Governance, Risk, and Compliance programme.
  • Company: Join Boku Inc., a global leader in mobile-first payment solutions for top brands.
  • Benefits: Enjoy a diverse workplace with opportunities for remote work and professional growth.
  • Why this job: Make a real impact on security while working with innovative technology and global teams.
  • Qualifications: 5+ years in Information Security or GRC roles; strong knowledge of regulatory frameworks required.
  • Other info: Be part of a company that values diversity and offers a supportive environment.

The predicted salary is between 43200 - 72000 £ per year.

Boku Inc. (BOKU.L) is the leading global provider of local mobile-first payments solutions. Global brands including Amazon, DAZN, Meta, Google, Microsoft, Netflix, Sony, Spotify, and Tencent rely on Boku to reach millions of new paying consumers who do not use credit cards with our purpose-built payment network of more than 300 local payment methods across 70+ countries. Every year, Boku processes over $10 billion in value for our customers. Incorporated in 2008, Boku is headquartered in London and San Francisco and has employees in over 39 countries around the world, including Brazil, China, Estonia, Germany, Ireland, Japan, Singapore, and the UAE. Boku is a truly global company that takes pride in its diversity and thriving equal opportunity workplace.

Role Purpose

We are seeking a highly motivated and detail-oriented Security Governance, Risk, and Compliance (GRC) Manager to drive the maturity of our information security program across governance, risk management, regulatory compliance, and control assurance. This role plays a critical part in safeguarding the firm’s information assets, ensuring ongoing alignment with ISO 27001, SOC 2, PCI DSS, GDPR, and region-specific regulatory frameworks (e.g., RBI, DORA, MAS). You will act as the central point of coordination for risk reporting, policy governance, audit support, and cross-functional control implementation, working closely with internal stakeholders, regulators, and third-party partners.

Key Responsibilities

  • Lead the design, implementation, and continuous improvement of the firm’s Information Security Governance, Risk, and Compliance program.
  • Own and maintain information security policies, standards, and procedures aligned to ISO 27001 and other regulatory frameworks.
  • Coordinate internal and external audits, including evidence gathering, control walkthroughs, findings management, and follow-up remediation.
  • Conduct and manage IT/security risk assessments and support enterprise risk reporting cycles.
  • Oversee the implementation and monitoring of key controls across technology, cloud platforms, and business processes.
  • Maintain the ISMS and support ongoing ISO 27001 certification and surveillance activities.
  • Work with Legal, Engineering, IT, and Compliance teams to support data protection (e.g., GDPR), supplier risk, and contractual security requirements.
  • Build and track risk registers, control testing results, and remediation plans.
  • Identify suitable GRC tooling to support enterprise activities and work to implement.
  • Lead periodic governance forums including Security Council and Risk Review Board meetings.
  • Monitor changes in regulations and industry standards to ensure timely updates to internal programs.
  • Develop training and awareness programs to foster a security-first culture across the organization.

Qualifications

  • 5+ years of experience in Information Security, GRC, Risk Management, or Compliance roles within a regulated industry (e.g., payments, fintech, healthcare).
  • Strong understanding of frameworks such as ISO 27001, SOC 2, PCI DSS, GDPR, and/or NIST CSF.
  • Experience managing or supporting external audits, certifications, or regulatory inspections.
  • Knowledge of risk assessment methodologies, control design, and assurance testing.
  • Ability to interpret complex security requirements and translate them into practical internal controls.
  • Familiarity with GRC tools and platforms.
  • Excellent project management, stakeholder engagement, and written communication skills.
  • Highly organized, self-directed, and able to manage multiple priorities with attention to detail.
  • Experience working in regulated entities is essential.

Security GRC Manager employer: Boku

Boku Inc. is an exceptional employer that champions a diverse and inclusive work culture, offering employees the opportunity to engage with global brands while contributing to innovative mobile payment solutions. With a strong focus on professional development, Boku provides ample growth opportunities in the rapidly evolving fintech landscape, alongside competitive benefits and a commitment to maintaining a security-first environment. Located in London, employees enjoy the vibrant city life while being part of a forward-thinking company that values collaboration and excellence.
B

Contact Detail:

Boku Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Security GRC Manager

✨Tip Number 1

Familiarise yourself with the specific regulatory frameworks mentioned in the job description, such as ISO 27001 and GDPR. Understanding these standards will not only help you in interviews but also demonstrate your commitment to the role.

✨Tip Number 2

Network with professionals in the GRC field, especially those who have experience in the payments or fintech sectors. Engaging with industry peers can provide valuable insights and potentially lead to referrals.

✨Tip Number 3

Stay updated on the latest trends and changes in information security regulations. Being knowledgeable about current events in the industry will show your proactive approach and readiness to adapt to new challenges.

✨Tip Number 4

Prepare to discuss your experience with risk assessments and audits in detail. Be ready to share specific examples of how you've successfully managed compliance and governance in previous roles, as this will highlight your suitability for the position.

We think you need these skills to ace Security GRC Manager

Information Security Management
Governance, Risk, and Compliance (GRC)
ISO 27001
SOC 2
PCI DSS
GDPR
Risk Assessment Methodologies
Control Design
Audit Coordination
Stakeholder Engagement
Project Management
Regulatory Compliance
Attention to Detail
Training and Awareness Program Development
GRC Tools Familiarity
Strong Written Communication Skills

Some tips for your application 🫡

Understand the Role: Before applying, make sure you fully understand the responsibilities and qualifications required for the Security GRC Manager position at Boku Inc. Familiarise yourself with key frameworks like ISO 27001, SOC 2, and GDPR.

Tailor Your CV: Customise your CV to highlight relevant experience in Information Security, GRC, Risk Management, or Compliance. Emphasise your familiarity with regulatory frameworks and any experience with audits or certifications.

Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for information security and your understanding of Boku's mission. Mention specific experiences that demonstrate your ability to lead GRC initiatives and manage compliance effectively.

Proofread Your Application: Before submitting, carefully proofread your application materials. Check for spelling and grammatical errors, and ensure that all information is clear and concise. A polished application reflects your attention to detail.

How to prepare for a job interview at Boku

✨Understand the Regulatory Landscape

Familiarise yourself with key regulations such as ISO 27001, SOC 2, PCI DSS, and GDPR. Be prepared to discuss how these frameworks impact Boku's operations and how you can contribute to maintaining compliance.

✨Showcase Your Risk Management Skills

Prepare examples of past experiences where you've successfully conducted risk assessments or managed compliance projects. Highlight your ability to identify risks and implement effective controls.

✨Demonstrate Stakeholder Engagement

Boku values collaboration across teams. Be ready to share instances where you've worked with cross-functional teams, particularly in legal, IT, or engineering, to achieve security goals.

✨Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Think about how you would handle specific compliance challenges or audit situations relevant to Boku's industry.

Security GRC Manager
Boku
B
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>