Security GRC Analyst in London

Security GRC Analyst in London

London Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
Doist

At a Glance

  • Tasks: Join our team to enhance security compliance and manage risks in a fast-paced fintech environment.
  • Company: Lendable, a leading UK fintech unicorn focused on innovative credit solutions.
  • Benefits: Flexible working, health coverage, retirement plans, and office perks like free meals.
  • Other info: Dynamic team with opportunities for growth and collaboration in a thriving tech environment.
  • Why this job: Make a real impact on security culture while working with cutting-edge technology.
  • Qualifications: 5+ years in security roles, strong understanding of compliance frameworks, and excellent communication skills.

The predicted salary is between 63000 - 77000 £ per year.

About Lendable

Lendable is on a mission to build the world's best technology to help people get credit and save money. We are building one of the world’s leading fintech companies and are off to a strong start: a UK unicorn with a team of just over 700 people, one of the fastest-growing tech companies in the UK, profitable since 2017, backed by top investors including Balderton Capital and Goldman Sachs, and loved by customers with the best reviews in the market (4.9 across 10,000s of reviews on Trustpilot). We have rebuilt the Big Three consumer finance products from scratch: loans, credit cards and car finance, getting money into our customers’ hands in minutes instead of days.

About the Role

We are looking for a proactive Security GRC Analyst to join our Information Security team. You will play a pivotal role in scaling our security posture in a fast‑paced, AI‑driven, cloud‑native environment and shape our security culture and operational resilience.

What You’ll Be Doing

  • Framework & Regulatory Alignment: Help maintain, improve, and scale our security compliance programmes, ensuring ongoing alignment with standards such as SOC2, ISO27001, PCI‑DSS, UKGDPR and regulator expectations.
  • Risk & Mitigation: Collaborate on identifying security risks across the business—including emerging risks from AI‑driven and agentic threats—and support the team in driving practical, risk‑first mitigation strategies.
  • Compliance Automation: Utilize our security compliance platform (e.g., Vanta/Drata) to orchestrate automated evidence collection, reducing manual overhead and moving the company toward continuous audit readiness.
  • Third‑Party Risk Management (TPRM): Conduct vendor and third‑party security risk assessments to evaluate the security posture of partners and critical outsourced service providers.
  • Translating Risk & Governance: Work with the team to bridge the gap between engineering and business governance by turning technical security metrics into clear, risk‑based narratives for internal stakeholders and external auditors.
  • Security Culture & Awareness: Support the delivery and promotion of security awareness initiatives to help drive a strong culture of shared security responsibility across the organisation.
  • Technical Collaboration: Actively engage in conversations with engineers, developers, and IT teams—understanding their technical language and workflows to align security controls with engineering realities.
  • Audit & Assessment Support: Participate in external audits and assessments by gathering evidence, preparing documentation, and ensuring a smooth, successful audit cycle.

What You Will Bring

  • Experience: 5+ years of experience in a related role, ideally within a regulated, cloud‑native business or FinTech.
  • Compliance & Risk Expertise: A strong, foundational understanding of security risk management principles and hands‑on experience with compliance frameworks such as ISO27001, PCI‑DSS, or SOC2.
  • Risk‑First & Pragmatic Mindset: A natural tendency to start with the “why” (the risk) rather than the checklist, balancing strict financial regulations with operational agility.
  • Communication & Collaboration: Outstanding communication skills with a proven ability to converse with technical stakeholders, translate challenges into business risks, and influence decisions.
  • Drive & Initiative: A highly proactive, self‑motivated mindset that actively seeks ways to improve security posture and drive change.
  • Desirable Tooling: Direct, practical experience working with modern security compliance and automation platforms (e.g., Vanta or Drata).
  • Programming and automation: Experience with Python or a similar scripting language, and/or using AI to improve productivity through automation.

Interview Process

  • Initial call with a recruiter.
  • 15‑minute cognitive assessment.
  • 30‑minute hiring manager call.
  • 60‑minute technical interview.
  • 60‑minute culture‑add interview.

Life at Lendable

  • Winning team: the opportunity to scale up one of the world’s most successful fintech companies.
  • Flexible working: Flexible approach tailored to each role. Hybrid roles require three days in‑office weekly; fully remote roles include regular opportunities for in‑person connection through socials and off‑sites.
  • Benefits: Health coverage: support for physical and mental wellbeing, including private health cover. Retirement & savings: long‑term financial wellbeing through retirement savings plans. Employee referral programme: earn a competitive bonus when you refer successful new team members. Office meals & snacks: fully stocked kitchen and complimentary lunches on in‑office days at select locations. Sustainable commuting: cycle‑to‑work and electric vehicle salary sacrifice schemes available in select locations.

Please note: The availability and details of specific benefits vary by location and role. For more information, please speak to your Talent Partner.

Security GRC Analyst in London employer: Doist

Brink's is an exceptional employer that fosters a collaborative and innovative work culture, empowering employees to drive global commercial strategies in the ATM lifecycle solutions sector. With a strong focus on professional development and growth opportunities, employees are encouraged to expand their skills while contributing to sustainable growth and operational excellence. Located in a dynamic environment, Brink's offers unique advantages such as a diverse team and the chance to build long-term partnerships with global customers, making it a rewarding place to advance your career.

Doist

Contact Details:

Doist Recruitment Team

We think you need these skills to ace Security GRC Analyst in London

Security Compliance Programmes
SOC2
ISO27001
PCI-DSS
UKGDPR
Risk Management
Compliance Automation