Information Security Governance Specialist in London

Information Security Governance Specialist in London

London Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
Frontify

At a Glance

  • Tasks: Drive security governance and transform compliance with automation and AI.
  • Company: Join Frontify, a vibrant tech company empowering brands like Uber and Microsoft.
  • Benefits: Enjoy private health benefits, 25+ days leave, and workation opportunities.
  • Other info: Hybrid work model with a supportive and inclusive culture.
  • Why this job: Make a real impact in security governance while working with cutting-edge technology.
  • Qualifications: 5+ years in information security governance and experience with SOC 2 or ISO 27001 audits.

The predicted salary is between 60000 - 80000 £ per year.

We're all about helping brands turn ideas into impact.

Frontify’s brand platform transforms how teams organize digital assets, collaborate on projects, and create engaging campaigns.

Our people empower thousands of marketers and designers — including teams at Uber, Microsoft, Volkswagen, and Telefónica — to build engaging brands.

With headquarters in St.

Gallen, Switzerland, and offices in London and New York City, we share a vibrant culture built on creativity, collaboration, inclusion, and joy.

And we’re on the lookout for new team members to share our vision.

If you’re ready for a brand-new adventure, keep reading!

Our Information Security Office never misses a chance to be the trusted partner for internal and external stakeholders.

Security, pragmatism and user friendliness are our guiding principles.

Outside of work, we’re gamers, avid bookworms and kickboxers.

Your mission

Trust is what enables the world's leading brands to build on Frontify.

Behind that trust is our Security Governance team, ensuring our security is not only effective, but also measurable, demonstrable, and easy for customers and auditors to verify.

Our work spans compliance, regulatory oversight, customer security assurance, vendor risk management, security policy management, awareness, and enterprise risk management.

A key focus of the role is driving the next stage of our security governance maturity.

Today, too many governance activities still rely on collecting evidence, chasing screenshots, and preparing spreadsheets for audits.

You'll help transform that by introducing automation and AI into our governance processes, enabling continuous evidence collection, automated control monitoring, and more efficient audit readiness.

This creates more space for the team to focus on the areas where human expertise, critical thinking, and sound judgment create the greatest value.

  • Your responsibilities
  • You'll own customer security assurance, ensuring enterprise security questionnaires, due diligence requests, and audit inquiries are handled accurately, consistently, and efficiently, helping customers make informed decisions while supporting commercial success.
  • You'll drive the day‑to‑day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements.
  • You'll serve as the subject matter expert during audits and ensure our control environment remains effective and audit‑ready.
  • You'll help transform compliance from a point‑in‑time activity into a continuous process by introducing automation and AI into our Vanta‑based GRC program.

This includes improving evidence collection, control monitoring, and access review processes.

  • You'll design and improve AI‑enabled GRC workflows, leveraging LLMs to streamline policy management, documentation, risk assessments, and other governance activities while ensuring appropriate governance and human oversight.
  • You'll strengthen Frontify's vendor risk management program by scaling security assessments through automation while ensuring higher‑risk vendors receive appropriate human review.
  • You'll contribute to the continuous improvement of Frontify's security awareness program by helping employees build practical security knowledge rather than simply completing mandatory training.
  • Your story
  • You're comfortable working in a hybrid format, with the ability to come to our London office once per week.
  • You have 5+ years of experience in information security governance, GRC, or technology risk within a Saa S or cloud environment.
  • You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors.

Experience with additional frameworks such as TISAX or Microsoft SSPA is a plus.

  • You're hands‑on with modern GRC platforms (we run Vanta and Conveyor), and you instinctively reach for automation over manual effort.
  • You think entrepreneurially, embrace new technologies, and challenge the status quo to drive meaningful improvements.
  • You're genuinely excited about applying AI to compliance work, and you can tell the difference between where it accelerates you and where human judgment still matters.
  • You communicate risk clearly to both technical and business audiences, and you enjoy helping those around you do their best work.
  • A relevant certification (CISA, CISM, CISSP, CIPP, or similar) is a plus.
  • You speak English fluently. German is a plus.

What we offer

  • Private health benefits and health cash plan
  • Pension scheme: 5% matched
  • A minimum of 25 days of annual leave per year
  • Paid educational and wellbeing days off
  • Wellbeing, learning and development, and commuter allowance
  • Home office setup budget- Weekly free office lunch
  • Localized benefits
  • Workation: Work from inspiring locations around the world (45 days annually)
  • Invite to our summer company meet‑up

We understand that every candidate’s experience is different. If you’re interested in this role but don’t tick all the boxes, we still encourage you to apply.

Important to us

Frontify is a place where authenticity and inclusion thrive, empowering every voice to help shape our future.

We’re committed to providing a fair and accessible recruitment process.

If you have a disability and require reasonable adjustments at any stage, please speak with your Talent Partner.

Any information you share will remain confidential.

#J-18808-Ljbffr

Information Security Governance Specialist in London employer: Frontify

At Frontify, we pride ourselves on being an exceptional employer that champions creativity, collaboration, and inclusion. Our vibrant culture, combined with flexible working arrangements and a commitment to employee growth, ensures that you can thrive while making a meaningful impact in the tech recruitment space. With generous benefits like extensive holiday, educational days off, and a supportive team environment, you'll find yourself part of a community that values your contributions and encourages your professional journey.

Frontify

Contact Details:

Frontify Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Governance Specialist in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Frontify, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Frontify

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Frontify. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Information Security Governance Specialist in London

Information Security Governance
GRC (Governance, Risk Management, and Compliance)
ISO 27001
SOC 2
TISAX
Vendor Risk Management
Audit Management

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Frontify insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Frontify that you’re committed to staying ahead in the game.

How to prepare for a job interview at Frontify

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Frontify to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Frontify.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.