At a Glance
- Tasks: Lead and enhance global security governance, risk, and compliance programs.
- Company: Join Crown Agents Bank, a growing UK bank transforming payments in emerging markets.
- Benefits: Enjoy hybrid working, competitive annual leave, and a contributory pension plan.
- Why this job: Make a real impact in a collaborative team while driving innovation in security.
- Qualifications: 5+ years in GRC with expertise in ISO 27001 and cybersecurity regulations.
- Other info: Opportunity to work with cutting-edge technology in a supportive environment.
The predicted salary is between 43200 - 72000 £ per year.
Crown Agents Bank is a vastly growing and regulated UK bank that connects emerging and frontier markets to the rest of the world, using FX and payments technology. We are transforming the way payments and FX move through emerging markets, reducing friction so that more money gets to those who need it.
The Security GRC (Governance, Risk & Compliance) Manager will take the lead in developing, implementing, and continuously improving our global security governance, risk, and compliance programs. You will play a critical role in maintaining and achieving key security certifications, driving regulatory compliance across multiple regions, and enabling a strong security culture across the business.
Responsibilities:
- Security Frameworks: Lead the management and continuous improvement of security frameworks such as ISO/IEC 27001, NIST CSF, and others as required.
- Certifications & Audits: Oversee and drive certification and re-certification efforts for Cyber Essentials Plus, SOC 2 Type 2, and other relevant regional or industry-specific standards across EMEA, Americas and Asia.
- Compliance & Regulation: Analyse global laws and regulatory requirements to ensure the business meets applicable security compliance obligations (e.g., EU GDPR, DORA, etc.).
- Risk Management: Own and manage the security risk management program, including advanced risk assessments, vendor risk reviews, and mitigation planning.
- Security Incidents: Collaborate with cross-functional teams on security incident coordination, response, root cause analysis, and continuous improvement efforts.
- Stakeholder Reporting: Provide clear, data-driven reporting to senior stakeholders on GRC metrics, risks, controls, and compliance posture.
- Awareness & Training: Design and deliver user training programs and security awareness initiatives to foster a strong security-first culture.
- Customer Trust: Respond to customer assurance questionnaires, support sales and legal teams with RFPs and security-related queries.
Qualifications:
- 5+ years of hands-on experience in information security governance, risk, and compliance.
- Deep experience leading and maintaining ISO 27001, NIST CSF, and SOC 2 Type 2 programs.
- Proven track record with certification efforts like Cyber Essentials Plus and local/regional compliance standards across EMEA, Americas and Asia.
- Strong understanding of international laws and regulations related to cybersecurity and data protection.
- Expertise in ISMS management, internal/external audits, policy lifecycle management, and compliance monitoring.
- Confident in conducting risk assessments, vendor reviews, and third-party due diligence.
- Comfortable presenting to and influencing executive leadership.
- Experience working in tech startups or global technology corporations is highly desirable.
- A hands-on, innovative, and analytical mindset - you enjoy rolling up your sleeves and solving complex problems.
- Excellent communication skills - written and verbal - with the ability to translate security language for different audiences.
Certifications required: CISSP (Certified Information Systems Security Professional), ISO 27001 Lead Implementer and/or Auditor certification.
Nice to have: Experience with security tools such as GRC platforms (e.g., Vanta, Drata, OneTrust), familiarity with regulatory frameworks like EU GDPR and DORA, background in customer trust, sales enablement, or due diligence support.
Additional Information:
- Hybrid working
- Contributory personal pension plan: Minimum: Employee 2% and Employer 7%. Employer matches contributions in 1% increments to a maximum of: Employee 5% and Employer 10%
- Life Assurance - 4 times annual salary
- Group Income Protection
- Private Medical Insurance - this may include cover for partner and or children at company cost. Cover includes Optical, Dental and Audiology
- Discretionary Bonus
- Competitive Annual Leave
- 2 Volunteering Days
- Benefit Hub
Security GRC Manager employer: Crown Agents Bank
Contact Detail:
Crown Agents Bank Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security GRC Manager
✨Tip Number 1
Familiarise yourself with the specific security frameworks mentioned in the job description, such as ISO/IEC 27001 and NIST CSF. Understanding these frameworks will not only help you in interviews but also demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals in the GRC field, especially those who have experience in tech environments. Engaging with industry peers can provide insights into the latest trends and challenges, which you can discuss during your interview.
✨Tip Number 3
Prepare to discuss your hands-on experience with compliance certifications like Cyber Essentials Plus and SOC 2 Type 2. Be ready to share specific examples of how you've successfully led certification efforts in previous roles.
✨Tip Number 4
Showcase your analytical mindset by preparing to discuss how you've approached risk assessments and vendor reviews in the past. Highlighting your problem-solving skills will resonate well with the hiring team at Crown Agents Bank.
We think you need these skills to ace Security GRC Manager
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your experience in information security governance, risk, and compliance. Focus on your hands-on experience with ISO 27001, NIST CSF, and SOC 2 Type 2 programs, as well as any relevant certifications.
Craft a Compelling Cover Letter: In your cover letter, express your passion for innovation and your data-driven approach. Mention specific examples of how you've contributed to security frameworks and compliance efforts in previous roles.
Highlight Relevant Skills: Emphasise your expertise in conducting risk assessments, vendor reviews, and your understanding of international laws related to cybersecurity. Make sure to mention your communication skills and ability to present to executive leadership.
Showcase Your Problem-Solving Abilities: Provide examples in your application that demonstrate your hands-on, innovative mindset. Discuss complex problems you've solved in tech environments and how your contributions made a real impact.
How to prepare for a job interview at Crown Agents Bank
✨Understand the Security Frameworks
Familiarise yourself with key security frameworks like ISO/IEC 27001 and NIST CSF. Be prepared to discuss how you've implemented or improved these frameworks in your previous roles, as this will demonstrate your hands-on experience.
✨Showcase Your Compliance Knowledge
Brush up on global laws and regulations related to cybersecurity, such as EU GDPR and DORA. During the interview, highlight your experience in ensuring compliance and how you’ve navigated complex regulatory environments.
✨Prepare for Risk Management Discussions
Be ready to talk about your approach to risk management, including how you've conducted risk assessments and vendor reviews. Providing specific examples of past challenges and how you mitigated risks will showcase your analytical mindset.
✨Communicate Effectively
Since you'll be presenting to senior stakeholders, practice translating technical security language into layman's terms. Strong communication skills are essential, so consider preparing a few key points that illustrate your ability to convey complex information clearly.