At a Glance
- Tasks: Lead security risk programmes and enhance our security posture while supporting operational security.
- Company: Join Funding Circle, a game-changer in SME lending with a mission to support small businesses.
- Benefits: Enjoy hybrid working, private medical insurance, learning allowances, and subsidised lunches.
- Why this job: Make a real impact on cyber security and help small businesses thrive.
- Qualifications: 4+ years in Cyber Risk or Information Security with strong risk management skills.
- Other info: Diverse teams, flexible work culture, and excellent career development opportunities await you.
The predicted salary is between 36000 - 60000 ÂŁ per year.
We are seeking an experienced Security Engineer who thrives at the intersection of cyber risk and security operations. In this key role, you will be a major contributor to our security posture by leading and enhancing core risk programmes like Third-Party Risk Management and Security Awareness, while also providing crucial handsâon support to our operational security functions.
Who are we? We are Funding Circle. We back small businesses to succeed. At Funding Circle, we believe the world needs small businesses. Thatâs why weâve made it our mission to help them get the finance they need to grow. With more than a decade of expertise under our belt, weâve built a gameâchanger of a platform with cuttingâedge data and technology thatâs reshaping the landscape of SME lending.
The role:
- Lead and continue to evolve our thirdâparty risk management (TPRM) programme, performing security risk assessments for new and existing vendors to identify and mitigate potential risks.
- Manage and enhance our companyâwide security awareness programme, delivering engaging training and identifying new ways to foster a strong securityâconscious culture.
- Act as a key contributor during internal and external security audits, helping to gather evidence and formulate clear, concise responses for auditor and regulator inquiries.
- Analyse and report on key security metrics and risk indicators (KRIs), identifying trends to measure the effectiveness of our security programme and inform strategic decisions.
- Provide handsâon support on Security Operations, assisting with tasks such as incident triage, analysis, and other operational security duties.
- Support the incident response process by providing crucial risk context and ensuring activities align with our overall risk posture.
- Stay current with the evolving threat landscape, industry trends, and new regulations to proactively manage and mitigate emerging cyber risks.
What weâre looking for:
- Significant (4+ years) handsâon experience in a Cyber Risk, GRC, or Information Security role with a demonstrable focus on risk management and compliance.
- Deep, demonstrable expertise in operating within an Information Security Management System (ISMS) and applying security frameworks (e.g., ISO 27001, NIST CSF, SOC 2) to practical scenarios.
- Proven, handsâon experience conducting comprehensive risk assessments using established methodologies and managing risks throughout their lifecycle.
- Experience applying and advising on security policies and standards to ensure effective control implementation across the organisation.
- Experience managing or significantly contributing to a thirdâparty risk management (TPRM) program.
- Proven experience managing and responding to internal and external audits.
- Excellent communication and influencing skills, with the ability to articulate complex security and risk concepts clearly to both technical and nonâtechnical audiences.
- Ability to work collaboratively across multiple teams and build strong relationships with stakeholders in Procurement, Legal, and Compliance.
- A pragmatic and businessâfocused approach to risk management.
Nice to have:
- Relevant industry certifications (e.g., CISM, CRISC, CISA, CISSP).
- Experience with GRC and TPRM tooling.
- Familiarity with security operations tools, such as a SIEM and Endpoint Detection & Response (EDR) platforms.
- Experience in automating compliance evidence collection and reporting.
- Experience working in FinTech or other highly regulated environments.
At Funding Circle we are committed to building diverse teams so please apply even if your past experience doesnât align perfectly with the requirements.
Why join us? At Funding Circle, we celebrate and support the differences that make you, you. Weâre proud to be an equalâopportunity workplace and affirmativeâaction employer. We truly believe that diversity makes us better.
As a flexibleâfirst employer we offer hybrid working at Funding Circle, and weâve long believed in a 'best of both' approach to inâoffice collaboration and nonâoffice days. We expect our teams to be in our London office two times a week, where you can take advantage of our newly refurbished hybrid working space, barista made coffee and subsidised lunches every day!
We back our Circlers to build their own incredible career, making a difference to small businesses every day. Our Circler proposition is designed to support employees both in and out of work, and it is anchored around four pillars: Health, Wealth, Development & Lifestyle.
Health: Private Medical Insurance through Aviva, Dental Insurance through Bupa, MediCash, access to free online therapy sessions and exclusive discounts with Hertility for reproductive health support.
Wealth: Octopus Money Coach, free mortgage advisor partnership and discounts across numerous retailers through Perks at Work.
Development: Dedicated annual learning allowance and full access to internal learning platform.
Lifestyle: Wellhub (for fitness discounts), Electric Car Scheme and more!
And finally, we have awardâwinning parental leave policies supporting parents through enhanced maternity, partner and adoption leave, as well as additional leave for parental bereavement and for fertility treatments.
Ready to make a difference? Weâd love to hear from you.
Security Engineer in London employer: Funding Circle UK
Contact Detail:
Funding Circle UK Recruiting Team
StudySmarter Expert Advice đ¤Ť
We think this is how you could land Security Engineer in London
â¨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
â¨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their security posture and be ready to discuss how your experience aligns with their needs. We want to see that youâre genuinely interested in what we do!
â¨Tip Number 3
Show off your skills! If youâve got hands-on experience with security tools or frameworks, be ready to talk about specific projects or challenges youâve tackled. Real-world examples can make you stand out from the crowd.
â¨Tip Number 4
Donât forget to apply through our website! Itâs the best way to ensure your application gets seen. Plus, it shows us youâre serious about joining our team at Funding Circle.
We think you need these skills to ace Security Engineer in London
Some tips for your application đŤĄ
Tailor Your CV: Make sure your CV is tailored to the Security Engineer role. Highlight your experience in cyber risk and security operations, and donât forget to mention any relevant frameworks youâve worked with, like ISO 27001 or NIST CSF.
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why youâre passionate about helping small businesses succeed and how your skills align with our mission at Funding Circle. Keep it engaging and personal!
Showcase Your Achievements: When detailing your experience, focus on specific achievements rather than just responsibilities. Use metrics where possible to demonstrate the impact of your work, especially in risk management and compliance.
Apply Through Our Website: We encourage you to apply directly through our website. Itâs the best way for us to see your application and ensures youâre considered for the role. Plus, itâs super easy to do!
How to prepare for a job interview at Funding Circle UK
â¨Know Your Security Frameworks
Make sure you brush up on your knowledge of security frameworks like ISO 27001 and NIST CSF. Be ready to discuss how you've applied these in real-world scenarios, as this will show your hands-on experience and understanding of risk management.
â¨Prepare for Risk Assessment Questions
Expect questions about conducting risk assessments and managing risks throughout their lifecycle. Have specific examples ready that demonstrate your methodology and the outcomes of your assessments, as this will highlight your practical expertise.
â¨Showcase Your Communication Skills
Since you'll need to articulate complex security concepts to both technical and non-technical audiences, practice explaining your past projects in simple terms. This will help you stand out as someone who can bridge the gap between different teams.
â¨Stay Updated on Cyber Threats
Be prepared to discuss the latest trends in the cyber threat landscape. Showing that you're proactive about staying informed will demonstrate your commitment to security and your ability to manage emerging risks effectively.