Senior Information Security Analyst Information security London

Senior Information Security Analyst Information security London

London Full-Time 66150 - 80850 £ / year (est.) Home office (partial)
Checkout Ltd

At a Glance

  • Tasks: Lead Checkout's governance, risk, and compliance programme while ensuring security across the business.
  • Company: Join Checkout.com, a key player in fintech powering major brands like eBay and Spotify.
  • Benefits: Enjoy a flexible hybrid work model, competitive salary, and opportunities for personal growth.
  • Other info: Be part of a dynamic team that values diversity and supports your career development.
  • Why this job: Make a real impact in shaping security culture and compliance strategies at a global scale.
  • Qualifications: 5+ years in GRC or information security with deep knowledge of PCI DSS, ISO 27001, and SOC 2.

The predicted salary is between 66150 - 80850 £ per year.

Company Description

We're Checkout. com.

You might not know our name, but companies like e Bay, Spotify, Klarna, Uber, and Sony do, because we’re behind many of the digital experiences you use every day.

We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers.

Whether you want to book a holiday, order food, renew a subscription, or check out online, there’s a good chance our tech powers the payments behind the scenes.

Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale.

If you want to do career-defining work, you’ve come to the right place.

We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact.

With 20 offices across six continents and London as our HQ, we’re shaping the future of fintech – and we’re just getting started.

The Role

As a Senior Information Security Analyst within the GRC team, you will lead the strategic and technical execution of Checkout’s governance, risk and compliance programme.

This is a role for a seasoned GRC professional who brings deep expertise across regulatory compliance, enterprise risk management, and security governance – and who can operate with full autonomy while shaping how the function evolves.

You will take ownership of Checkout’s most complex and high‑stakes compliance programmes – PCI DSS v4.0.1, ISO 27001, SOC 2, DORA, and emerging obligations across our global licensed entities – while providing expert guidance to engineering, product, legal, and compliance teams on the security requirements that underpin our ability to operate and grow in regulated markets worldwide.

At L4, you are a trusted advisor.

You do not just manage compliance – you set the direction for it.

You define how risk is identified, assessed, and treated.

You advise on product and infrastructure decisions from a risk perspective.

You mentor and develop junior and mid‑level analysts.

And you work closely with security leadership to ensure the GRC programme is aligned to the business’s strategic objectives and risk appetite.

Your influence extends well beyond the GRC team.

You help shape the security culture at Checkout, driving a risk‑aware mindset across the business through clear communication, pragmatic guidance, and expert leadership.

  • How You’ll Make An Impact
  • GRC Programme Leadership
  • Lead defined sub‑areas of Checkout’s GRC programme end‑to‑end, including PCI DSS v4.0.1, ISO 27001, SOC 2, and regulatory obligations across Europe, MENA, APAC, and the Americas.
  • Define how control evidence is collected and maintained, moving the function toward continuous audit readiness and away from point‑in‑time preparation.
  • Own and drive improvements to GRC documentation including policies, standards, procedures, and control matrices – ensuring they reflect Checkout’s evolving risk profile and regulatory obligations.
  • Lead gap analyses against new and evolving requirements, including DORA ICT risk obligations and the EU AI Act, producing prioritised remediation roadmaps with clear business impact framing.
  • Own the risk register for your sub‑area, managing risk treatment through to closure and escalating to leadership where risk appetite may be exceeded.
  • Define and refine Checkout’s third‑party risk management approach for high‑risk and critical vendors, setting assessment standards and overseeing their consistent application.
  • Drive continual improvement of the GRC programme itself – regularly assessing programme maturity, identifying process inefficiencies, and implementing improvements to how risk is identified, assessed, treated, and reported across the business.
  • Audit and Assessment Leadership
  • Serve as the primary point of contact for external auditors, QSAs, and regulatory assessors across PCI DSS, ISO 27001, SOC 2, and ITGC audit cycles.
  • Demonstrated experience implementing ISO management system standards end‑to‑end, covering initial scoping and gap assessment through control design, policy development, internal audit programme, and certification – ideally across more than one standard.
  • Lead end‑to‑end audit delivery – scoping, evidence preparation, walkthrough facilitation, finding management, and formal closure.
  • Own the end‑to‑end response process for complex merchant assurance and regulatory due diligence requests, ensuring Checkout’s compliance posture is presented accurately and persuasively.
  • Lead quarterly and annual compliance activities including vulnerability scanning coordination, penetration testing programmes, access reviews, and firewall configuration assurance.
  • Policy, Controls and Regulatory Strategy
  • Apply expert knowledge of PCI DSS v4.0.1, ISO 27001/27002, SOC 2, DORA, NIST CSF, and related frameworks to drive control design, policy development, and compliance strategy.
  • Advise product and engineering teams on compliance requirements at the point of design, embedding regulatory obligations into architecture decisions and development workflows.
  • Lead Checkout’s regulatory change management activities – monitoring the evolving landscape across financial services, data protection, and AI regulation, assessing business impact, and driving remediation programmes.
  • Identify and drive systemic improvements to GRC processes, including automation opportunities that improve programme efficiency and evidence quality.
  • Contribute to the design and development of GRC tooling, dashboards, and risk reporting to improve leadership visibility of Checkout’s compliance and risk posture.
  • Stakeholder Influence and Team Development
  • Act as a senior trusted advisor to Engineering, Product, Legal, Finance, Procurement, and Compliance on all GRC matters, communicating risk in business terms that drive informed decisions.
  • Represent the GRC function in cross‑functional forums, governance committees, and regulatory discussions, influencing decisions that affect Checkout’s risk posture.
  • Mentor and develop junior and mid‑level GRC analysts (L1–L3), raising the capability of the team through structured knowledge sharing, review, and coaching.
  • Promote a security‑first culture across Checkout through proactive engagement, executive‑level reporting, and accessible guidance that empowers non‑security teams to make good risk decisions.
  • What We’re Looking For

Experience

  • 5 or more years of experience in GRC, information security compliance, IT audit, or a closely related function, ideally within payments, financial services, or fintech.
  • Deep working knowledge of PCI DSS (v4.0.1 required), ISO 27001, and SOC 2. Practical experience with DORA, NIST CSF, the EU AI Act, or FCA/PRA obligations is strongly preferred.
  • Demonstrated track record of leading external audits and regulatory assessments end‑to‑end, including managing assessor relationships and driving findings to closure.
  • Proven ability to own and deliver complex GRC programme workstreams independently, including gap analyses, risk treatment programmes, and regulatory change initiatives.
  • Experience advising engineering and product teams on compliance requirements, with the ability to translate regulatory obligations into practical, proportionate controls.
  • Track record of developing and mentoring less experienced colleagues.

Skills and Approach

  • Expert written and verbal communication.

You can frame complex regulatory and risk issues for a technical audience, a business stakeholder, and executive leadership – and adapt your style to drive the right outcome in each context.

  • Strategic and analytical thinker.

You see beyond individual findings and controls to understand systemic risk patterns, root causes, and the broader implications for the business.

  • Decisive under ambiguity. You can set direction and make sound judgement calls on prioritisation and risk treatment without waiting for perfect information.
  • Highly collaborative and influential.

You understand that compliance must be embedded across the business, and you build the relationships and credibility needed to make that happen.

  • Pragmatic and outcome‑focused. You design controls and processes that are proportionate to risk and workable in practice, not just theoretically sound.
  • Preferred
  • CISA, CISM, CISSP, PCIP, ISO 27001 Lead Implementer or Lead Auditor, or equivalent advanced certification.
  • Familiarity with cloud environments (AWS, Azure, GCP) at an architecture or control level.
  • Experience with AI governance frameworks such as ISO 42001, the EU AI Act, or NIST AI RMF.
  • Experience designing or implementing GRC tooling, risk platforms, or compliance automation solutions.
  • Background in a Big Four advisory, payments scheme, or regulatory environment is advantageous.
  • Additional Information

Bring all of you to work. We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one.

Here, you’ll move fast, take on meaningful challenges, and be recognized for the impact you deliver.

It’s a place where ambition gets met with opportunity, and where your growth is in your hands.

We work as one team, and we back each other to succeed. So whatever your background or identity, if you’re ready to grow and make a difference, you’ll be right at home here.

It’s important we set you up for success and make our process as accessible as possible.

So let us know in your application, or tell your recruiter directly, if you need anything to make your experience or working environment more comfortable.

Life at Checkout. com

We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.

Curious about what it’s like to be part of our team? Visit our Careers Page to learn more about our culture, open roles, and what drives us.

For a closer look at daily life at Checkout. com, follow us on Linked In and Instagram.

#J-18808-Ljbffr

Senior Information Security Analyst Information security London employer: Checkout Ltd

Checkout Ltd is an exceptional employer that fosters a dynamic and inclusive work culture, where collaboration and innovation thrive. With a strong focus on employee growth, the company offers ample opportunities for professional development while embracing a hybrid working model that promotes flexibility. Located in London, employees benefit from a vibrant city atmosphere, making it an ideal place for those seeking meaningful and rewarding careers in the legal field.

Checkout Ltd

Contact Details:

Checkout Ltd Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Information Security Analyst Information security London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Checkout Ltd, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Checkout Ltd

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Checkout Ltd. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Senior Information Security Analyst Information security London

Governance, Risk and Compliance (GRC)
PCI DSS v4.0.1
ISO 27001
SOC 2
Regulatory Compliance
Enterprise Risk Management
Security Governance

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Checkout Ltd insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Checkout Ltd that you’re committed to staying ahead in the game.

How to prepare for a job interview at Checkout Ltd

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Checkout Ltd to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Checkout Ltd.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.