At a Glance
- Tasks: Lead governance, risk, and compliance programmes while driving impactful workstreams.
- Company: Join a dynamic fintech company focused on security and compliance.
- Benefits: Enjoy hybrid working, competitive salary, and great office perks like snacks and meals.
- Other info: Collaborative culture with opportunities for mentoring and professional growth.
- Why this job: Make a real difference in global compliance and risk management across diverse markets.
- Qualifications: 2-4 years in GRC or information security with strong communication skills.
The predicted salary is between 50000 - 60000 £ per year.
As an Information Security Analyst II within the GRC team, you will take meaningful ownership of Checkout.com's governance, risk and compliance programmes. This is a role for someone who has moved beyond task execution and is ready to drive workstreams, lead compliance activities, and act as a trusted point of contact for internal teams and external assessors. You will work across Checkout's core compliance frameworks including PCI DSS v4.0.1, ISO 27001, SOC 2, and emerging regulatory obligations such as DORA and the EU AI Act, supporting our global footprint across Europe, MENA, APAC, and the Americas. You will coordinate audit evidence activities, conduct risk assessments, improve GRC processes, and support the development of junior colleagues. This role sits at the heart of how Checkout manages risk. We don't just audit and report. We own the risk narrative, drive the control environment, and ensure the business can grow with confidence in regulated markets worldwide.
How You'll Make an Impact
- Governance, Risk and Compliance Programme Management
- Own and manage defined workstreams within Checkout's GRC programme, including PCI DSS v4.0.1, ISO 27001, SOC 2, and relevant regulatory obligations across our global licensed entities.
- Coordinate control evidence collection activities across internal teams, ensuring continuous audit readiness rather than point-in-time preparation.
- Maintain and improve GRC documentation including policies, standards, procedures, and control matrices, ensuring they stay current and proportionate to Checkout's evolving risk profile.
- Perform gap analyses against new or evolving requirements including DORA and the EU AI Act, translating findings into prioritised remediation plans.
- Support monitoring of the risk register, track remediation activity against agreed timelines, and elevate issues where commitments are at risk.
- Conduct third-party risk assessments, evaluating supplier security controls and compliance posture in line with Checkout's TPRM framework.
- Audit and Assessment Support
- Act as a key liaison between internal teams and external auditors, QSAs, and assessors across PCI DSS, ISO 27001, ITGCs and SOC 2 certification cycles.
- Prepare and deliver evidence packages, coordinate walkthroughs, and manage audit findings through to closure.
- Support end-to-end response process for merchant assurance questionnaires and due diligence inquiries, ensuring all technical and regulatory queries are addressed with accuracy and within agreed SLAs.
- Support quarterly and annual compliance activities including vulnerability scanning, penetration testing coordination, access reviews, and firewall configuration reviews.
- Policy, Controls and Regulatory Coverage
- Apply working knowledge of PCI DSS v4.0.1, ISO 27001/27002, SOC 2, DORA, NIST CSF, and other applicable frameworks to day‑to‑day GRC work.
- Support meeting regulatory change across Checkout's operating markets including FCA/PRA requirements and payment scheme obligations, flagging gaps and supporting impact assessments.
- Proactively identify inefficiencies in GRC processes and propose practical improvements, including automation where viable.
- Contribute to the development and refinement of GRC tooling, dashboards, and reporting to improve visibility of risk and compliance posture across the business.
- Stakeholder Engagement and Mentoring
- Work closely with Engineering, Product, Legal, Procurement, and Finance to embed security and compliance requirements into processes, systems, and projects.
- Respond to PCI DSS, ISO 27001, and broader security-related due diligence requests from merchants, partners, and regulators.
- Provide guidance and day‑to‑day support to junior analysts (L1 and L2), contributing to their development through knowledge sharing and review.
- Promote a security‑first culture across Checkout through proactive engagement, awareness sessions, and accessible guidance for non‑security teams.
What We're Looking For
- Experience
- 2 to 4 years of experience in GRC, information security compliance, IT audit, or a closely related function, ideally within payments, financial services, or fintech.
- Practical working knowledge of PCI DSS (v4.0.1 preferred), ISO 27001, and SOC 2.
- Familiarity with DORA, NIST CSF, or the EU AI Act is a plus.
- Experience supporting or directly managing external audits and assessments, including evidence collation and assessor liaison.
- Demonstrated ability to own a programme workstream independently, from planning through to delivery.
- Well‑versed in risk management processes including risk identification, third‑party risk management and merchant due diligence.
- Skills and Approach
- Clear written and verbal communication. You can translate a compliance requirement or risk finding for a technical team and a business stakeholder with equal clarity.
- Analytical and process‑oriented mindset. You look for root causes, not just point‑in‑time fixes.
- Comfortable operating with ambiguity. You can prioritise and structure your work without every requirement being fully defined upfront.
- Methodical and well‑organised, with strong attention to detail and a consistent track record of delivering on commitments.
- Collaborative and pragmatic. You understand that security and compliance must work with the business, not against it.
- Preferred
- CISA, CISM, PCIP, ISO 27001 Lead Implementer or Auditor, or equivalent certification.
- Familiarity with cloud environments (AWS, Azure, GCP) in a GRC or compliance context.
- Experience with GRC tooling, risk platforms, or compliance automation.
- Exposure to AI governance frameworks such as ISO 42001, EU AI Act, or NIST AI RMF.
Hybrid Working Model
All of our offices globally are onsite three times per week (Tuesday, Wednesday, and Thursday). During your days at the office, we offer great snacks, breakfast, and lunch options in all of our locations.
Information Security Analyst II (GRC) employer: Checkout.com
Checkout.com is an exceptional employer that fosters a dynamic work culture where innovation and collaboration thrive. As an Information Security Analyst II, you will not only take ownership of critical governance, risk, and compliance programmes but also benefit from a supportive environment that prioritises employee growth through mentorship and continuous learning. With a hybrid working model and a focus on maintaining a healthy work-life balance, Checkout.com ensures that its employees are well-equipped to drive impactful change across the globe.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security Analyst II (GRC)
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Checkout.com, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Checkout.com
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Checkout.com. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Information Security Analyst II (GRC)
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Checkout.com insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Checkout.com that you’re committed to staying ahead in the game.
How to prepare for a job interview at Checkout.com
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Checkout.com to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Checkout.com.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.