Information Security Governance Manager
Information Security Governance Manager

Information Security Governance Manager

Full-Time 48000 - 72000 £ / year (est.) No home office possible
Modulr

At a Glance

  • Tasks: Lead information security governance and manage risks in a dynamic fintech environment.
  • Company: Join Modulr, a forward-thinking company revolutionising embedded payments.
  • Benefits: Enjoy share options, flexible benefits, and 33 days of annual leave.
  • Why this job: Make a real impact on security governance while working with cutting-edge technology.
  • Qualifications: Experience in information security governance and strong communication skills required.
  • Other info: Be part of a diverse and inclusive culture that values your unique perspective.

The predicted salary is between 48000 - 72000 £ per year.

Our vision is a world where all businesses are powered by embedded payments. Modulr enables businesses, from SMEs to Enterprise, to grow their revenue, drive efficiencies and deliver fantastic customer experiences, by embedding payments into their products and operating systems. We do this by providing products and services which allow our clients to efficiently collect, reconcile and disburse funds instantly via a range of payment schemes, accounts, and card products, fully controllable via API.

What You'll Do

  • Own and operate the information security risk register, ensuring risks are clearly articulated, consistently assessed, actively managed, and accurately reflected in governance and executive reporting.
  • Work with technology, product, and platform teams to identify, assess, and track information security risks, providing constructive challenge where risk assessments or remediation plans are weak, incomplete, or misaligned with risk appetite.
  • Ensure security incidents, near misses, and material control failures result in appropriate updates to risk posture, governance reporting, and follow-up actions, rather than being treated as isolated operational issues.
  • Own the lifecycle of information security policies and standards, ensuring they remain relevant, proportionate, and aligned with how the organisation builds and operates technology.
  • Operate and govern the policy exception process, ensuring exceptions are risk assessed, time bound, and approved at the appropriate level, with clear visibility of residual risk.
  • Develop and maintain clear, decision focused information security reporting for technical risk forums, executive committees, and board level audiences, including content for the CTO's board pack.
  • Define, maintain, and continuously improve security management information, metrics, and KPIs, focusing on insight and decision support rather than volume or vanity measures.
  • Translate complex or technical security issues into concise, business focused risk narratives that support informed decision making by senior and non-technical stakeholders.
  • Prepare and support governance forums, including agenda setting, paper authorship, action tracking, and follow up to ensure decisions are implemented and risks are actively managed.
  • Evolve the organisation's approach to information security governance and reporting as the business scales, technology changes, and regulatory expectations develop.
  • Act as a trusted advisor on information security risk and governance matters, partnering closely with security engineering functions while remaining independent from delivery ownership.
  • Work closely with risk, compliance, legal, and internal audit teams to ensure alignment, consistency, and effective use of governance effort.

Who You Are

What you'll need

  • Significant experience in an information security governance, risk, or assurance role within fintech, financial services, or a similarly regulated environment.
  • Demonstrable ownership of an information security risk register, including risk articulation, assessment, treatment tracking, and senior management reporting.
  • Experience owning information security policies and standards end to end, including review, approval, exception handling, and ongoing relevance.
  • Regular exposure to executive committees and board level reporting, with accountability for the quality, clarity, and narrative of content presented.
  • Strong understanding of information security risk management principles and how they are applied in practice, not just defined in frameworks.
  • Ability to distinguish between theoretical, perceived, and material security risk, and reflect that accurately in governance discussions and reporting.
  • Confidence to challenge engineering and senior stakeholders constructively, using evidence and risk-based reasoning rather than policy citation.
  • Excellent written communication skills, with the ability to translate technical security issues into clear, business focused risk narratives.
  • Strong judgement and prioritisation skills, balancing regulatory expectations, security risk, and delivery realities.
  • Ability to operate independently, manage multiple governance cycles in parallel, and take accountability for outcomes rather than activity.

Nice to haves

  • Experience supporting regulatory interactions, supervisory reviews, or significant audit activity in a regulated environment.
  • Professional certifications in information security, risk, or governance.
  • Experience working in organisations undergoing rapid growth, technology change, or increasing regulatory scrutiny.
  • Familiarity with modern, cloud-based technology environments and contemporary software delivery practices from a governance perspective.
  • Experience improving or evolving governance, risk, or reporting models rather than simply operating established processes.

What We Offer You

  • Share Options - We offer a Company Share Option Plan (CSOP), giving you the opportunity to benefit from any increase in share value in the event of a sale, merger, or flotation.
  • Bonus - Our annual discretionary bonus, paid in May for the previous year, is based on both company and individual performance.
  • Flexible benefits - £1000 to spend on benefits to suit you, including private medical insurance, gym membership, dental etc.
  • Wellbeing app - confidential, on-demand access to therapy, coaching, counselling, management training or mindfulness sessions with accredited professionals, with company-funded hours and top-up options available.
  • Holidays - 33 days annual leave (including bank holidays) plus your birthday off. In the UK, Christmas Day, Boxing Day, and New Year's Day are fixed holidays. You can choose the remaining days to suit your personal schedule.
  • Learning opportunities - Our two-day onboarding program, ModStart, helps equip you for success. Learning doesn't stop there; we'll continue to support your development through various channels.
  • Company-Wide Events - Participate in collaborative and engaging events with colleagues across the business.
  • Bike to work / E-bike scheme.

At Modulr, we're committed to building a diverse, equitable and inclusive culture where everyone feels they belong and can bring their whole self to work. We welcome applications from candidates of all backgrounds as we believe it's the right thing for our people, our business, and the community we operate in.

Information Security Governance Manager employer: Modulr

Modulr is an exceptional employer that fosters a dynamic and inclusive work culture, offering employees the chance to thrive in a rapidly growing fintech environment. With generous benefits such as share options, flexible spending on personal needs, and a strong focus on employee wellbeing and development, Modulr empowers its team members to grow both personally and professionally while contributing to innovative payment solutions in London.
Modulr

Contact Detail:

Modulr Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Governance Manager

✨Tip Number 1

Network like a pro! Reach out to people in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their products and services, especially how they handle information security. This will help you tailor your answers and show you're genuinely interested.

✨Tip Number 3

Practice your storytelling skills! Be ready to share specific examples of how you've managed risks or improved governance in past roles. This will help you stand out and demonstrate your expertise.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining our team at Modulr.

We think you need these skills to ace Information Security Governance Manager

Information Security Governance
Risk Management
Policy Development
Executive Reporting
Risk Assessment
Stakeholder Engagement
Written Communication
Judgement and Prioritisation
Regulatory Compliance
Technical Risk Analysis
Governance Frameworks
Problem-Solving
Adaptability to Change
Collaboration with Cross-Functional Teams

Some tips for your application 🫡

Tailor Your CV: Make sure your CV speaks directly to the role of Information Security Governance Manager. Highlight your experience in risk management and governance, and don’t forget to mention any relevant certifications or projects that showcase your skills.

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to tell us why you’re passionate about information security and how your background makes you the perfect fit for our team. Keep it concise but impactful!

Showcase Your Communication Skills: Since this role involves translating complex security issues into business-focused narratives, make sure your application reflects your excellent written communication skills. Use clear and straightforward language throughout your CV and cover letter.

Apply Through Our Website: We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you get all the updates directly from us. Plus, it’s super easy!

How to prepare for a job interview at Modulr

✨Know Your Stuff

Make sure you have a solid understanding of information security governance and risk management principles. Brush up on the specific frameworks and regulations relevant to the fintech sector, as this will help you articulate your experience and how it aligns with the company's needs.

✨Prepare Real-World Examples

Think of specific instances where you've owned an information security risk register or developed policies. Be ready to discuss how you assessed risks, managed incidents, and communicated with senior stakeholders. This will show that you can translate complex issues into business-focused narratives.

✨Show Your Collaborative Side

Highlight your experience working with cross-functional teams, especially in technology and compliance. Be prepared to discuss how you've partnered with engineering functions while maintaining independence, as this is crucial for the role.

✨Ask Insightful Questions

Prepare thoughtful questions about the company's approach to information security governance and how they handle evolving regulatory expectations. This not only shows your interest but also demonstrates your strategic thinking and understanding of the industry.

Information Security Governance Manager
Modulr

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>