InfoSec Analyst II (GRC) Information security London

InfoSec Analyst II (GRC) Information security London

Full-Time 55000 - 65000 £ / year (est.) Home office (partial)
Checkout Ltd

At a Glance

  • Tasks: Own and manage GRC programmes, ensuring compliance and risk management across global operations.
  • Company: Join a leading fintech company focused on innovation and security.
  • Benefits: Enjoy a hybrid working model, competitive salary, and professional development opportunities.
  • Other info: Dynamic work environment with a focus on mentorship and career growth.
  • Why this job: Make a real impact in information security while collaborating with diverse teams worldwide.
  • Qualifications: 2-4 years in GRC or information security, with knowledge of PCI DSS and ISO 27001.

The predicted salary is between 55000 - 65000 £ per year.

As an Information Security Analyst II within the GRC team, you will take meaningful ownership of Checkout.com's governance, risk, and compliance programmes. This is a role for someone who has moved beyond task execution and is ready to drive workstreams, lead compliance activities, and act as a trusted point of contact for internal teams and external assessors. You will work across Checkout's core compliance frameworks including PCI DSS v4.0.1, ISO 27001, SOC 2, and emerging regulatory obligations such as DORA and the EU AI Act, supporting our global footprint across Europe, MENA, APAC, and the Americas.

You will coordinate audit evidence activities, conduct risk assessments, improve GRC processes, and support the development of junior colleagues. This role sits at the heart of how Checkout manages risk. We don't just audit and report. We own the risk narrative, drive the control environment, and ensure the business can grow with confidence in regulated markets worldwide.

  • Governance, Risk and Compliance Programme Management
    • Own and manage defined workstreams within Checkout's GRC programme, including PCI DSS v4.0.1, ISO 27001, SOC 2, and relevant regulatory obligations across our global licensed entities.
    • Coordinate control evidence collection activities across internal teams, ensuring continuous audit readiness rather than point-in-time preparation.
    • Maintain and improve GRC documentation including policies, standards, procedures, and control matrices, ensuring they stay current and proportionate to Checkout's evolving risk profile.
    • Perform gap analyses against new or evolving requirements including DORA and the EU AI Act, translating findings into prioritised remediation plans.
    • Support monitoring of the risk register, track remediation activity against agreed timelines, and elevate issues where commitments are at risk.
    • Conduct third-party risk assessments, evaluating supplier security controls and compliance posture in line with Checkout's TPRM framework.
  • Audit and Assessment Support
    • Act as a key liaison between internal teams and external auditors, QSAs, and assessors across PCI DSS, ISO 27001, IT General Controls (ITGCs) and SOC 2 certification cycles.
    • Prepare and deliver evidence packages, coordinate walkthroughs, and manage audit findings through to closure.
    • Support end-to-end response process for merchant assurance questionnaires and due diligence inquiries, ensuring all technical and regulatory queries are addressed with accuracy and within agreed SLAs.
    • Support quarterly and annual compliance activities including vulnerability scanning, penetration testing coordination, access reviews, and firewall configuration reviews.
  • Policy, Controls and Regulatory Coverage
    • Apply working knowledge of PCI DSS v4.0.1, ISO 27001/27002, SOC 2, DORA, NIST CSF, and other applicable frameworks to day-to-day GRC work.
    • Support meeting regulatory change across Checkout's operating markets including FCA/PRA requirements and payment scheme obligations, flagging gaps and supporting impact assessments.
    • Proactively identify inefficiencies in GRC processes and propose practical improvements, including automation where viable.
    • Contribute to the development and refinement of GRC tooling, dashboards, and reporting to improve visibility of risk and compliance posture across the business.
  • Stakeholder Engagement and Mentoring
    • Work closely with Engineering, Product, Legal, Procurement, and Finance to embed security and compliance requirements into processes, systems, and projects.
    • Respond to PCI DSS, ISO 27001, and broader security-related due diligence requests from merchants, partners, and regulators.
    • Provide guidance and day-to-day support to junior analysts (L1 and L2), contributing to their development through knowledge sharing and review.
    • Promote a security-first culture across Checkout through proactive engagement, awareness sessions, and accessible guidance for non-security teams.

What We're Looking For

  • Experience
    • 2 to 4 years of experience in GRC, information security compliance, IT audit, or a closely related function, ideally within payments, financial services, or fintech.
    • Practical working knowledge of PCI DSS (v4.0.1 preferred), ISO 27001, and SOC 2.
    • Familiarity with DORA, NIST CSF, or the EU AI Act is a plus.
    • Experience supporting or directly managing external audits and assessments, including evidence collation and assessor liaison.
    • Demonstrated ability to own a programme workstream independently, from planning through to delivery.
    • Well-versed in risk management processes including risk identification, third-party risk management and merchant due diligence.
  • Skills and Approach
    • Clear written and verbal communication.
    • Analytical and process-oriented mindset.
    • Comfortable operating with ambiguity.
    • Methodical and well-organised, with strong attention to detail.
    • Collaborative and pragmatic.
  • Preferred
    • CISA, CISM, PCIP, ISO 27001 Lead Implementer or Auditor, or equivalent certification.
    • Familiarity with cloud environments (AWS, Azure, GCP) in a GRC or compliance context.
    • Experience with GRC tooling, risk platforms, or compliance automation.
    • Exposure to AI governance frameworks such as ISO 42001, EU AI Act, or NIST AI RMF.

Hybrid Working Model
All of our offices globally are onsite three times per week (Tuesday, Wednesday, and Thursday). We work collaboratively in the same space while also merging with colleagues globally. During your days at the office, we offer snacks, breakfast, and lunch options in all of our locations.

InfoSec Analyst II (GRC) Information security London employer: Checkout Ltd

Checkout.com is an exceptional employer that fosters a dynamic work culture where innovation and collaboration thrive. As an InfoSec Analyst II, you will not only take ownership of critical governance, risk, and compliance programmes but also benefit from continuous professional development opportunities and a supportive environment that encourages mentorship and knowledge sharing. With a hybrid working model and a focus on employee well-being, including complimentary meals and snacks, Checkout.com ensures that you can grow your career while enjoying a balanced work-life experience in the vibrant city of London.

Checkout Ltd

Contact Details:

Checkout Ltd Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land InfoSec Analyst II (GRC) Information security London

Join Compliance Communities

Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!

Attend Industry Conferences

Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.

Leverage Your University Career Services

If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.

Showcase Your Knowledge Online

Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Checkout Ltd looking for candidates who are engaged and informed.

We think you need these skills to ace InfoSec Analyst II (GRC) Information security London

Governance, Risk and Compliance (GRC)
PCI DSS v4.0.1
ISO 27001
SOC 2
DORA
EU AI Act
Risk Assessment

Some tips for your application 🫡

Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!

Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.

Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!

Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Checkout Ltd. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!

How to prepare for a job interview at Checkout Ltd

Master the Regulations

Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!

Show Your Analytical Skills

Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!

Know Your Tools

Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!

Align with Company Culture

Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Checkout Ltd’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!