At a Glance
- Tasks: Lead information security assurance activities and collaborate with auditors and regulators.
- Company: Join Modulr, a fintech innovator transforming embedded payments for businesses.
- Benefits: Enjoy share options, flexible benefits, 33 days leave, and ongoing learning opportunities.
- Why this job: Make a real impact in a fast-paced environment while ensuring security compliance.
- Qualifications: Experience in information security assurance and strong communication skills required.
- Other info: Be part of a diverse and inclusive culture that values your unique contributions.
The predicted salary is between 43200 - 72000 £ per year.
Our vision is a world where all businesses are powered by embedded payments. Modulr enables businesses, from SMEs to Enterprise, to grow their revenue, drive efficiencies and deliver fantastic customer experiences, by embedding payments into their products and operating systems. We do this by providing products and services which allow our clients to efficiently collect, reconcile and disburse funds instantly via a range of payment schemes, accounts, and card products, fully controllable via API.
What You'll Do
- Lead and complete information security assurance activities in support of internal audits, external audits, certifications, and regulatory reviews.
- Act as the primary information security point of contact for internal audit, external auditors, and regulators.
- Plan information security audit scope, timelines, and evidence requirements in collaboration with governance and delivery teams.
- Coordinate and run information security control walkthroughs, interviews, and technical deep dives with engineering, platform, and operations teams.
- Review, validate, and challenge information security control evidence to ensure it is accurate, complete, and auditable.
- Independently assess the design and operating effectiveness of information security controls against governance owned policies, standards, and regulatory expectations.
- Produce clear and information security assurance findings and audit reports for technical, executive, and regulatory audiences.
- Identify and communicate information security control observations and assurance outcomes to the security governance to inform governance led risk assessment and decision making.
- Track information security audit findings through to closure, validating remediation implementation without owning delivery.
- Identify recurring or systemic information security control observations and escalate them through agreed governance forums.
- Act as a pragmatic but independent assurance partner, ensuring information security assurance activity enables compliant, well controlled delivery.
Who You Are
What you'll need
- Significant experience in information security assurance, audit, or second line security roles within a regulated environment.
- Proven experience leading internal and external information security audits end to end, including direct interaction with auditors and regulators.
- Strong understanding of information security control design and operating effectiveness, particularly across cloud, SaaS, identity, and modern application environments.
- Experience assessing security controls against regulatory requirements and recognised frameworks such as PCI-DSS, ISO 27001, SOC 2, or equivalent.
- Ability to critically assess audit evidence, identify gaps or weaknesses, and challenge findings constructively using facts and documentation.
- Clear understanding of the separation between assurance, governance, and delivery, and the discipline to maintain independence.
- Strong written and verbal communication skills, with the ability to explain assurance findings clearly to both technical teams and senior stakeholders.
- Confidence operating autonomously, managing multiple audits or assurance activities in parallel without loss of quality.
Nice to haves
- Experience working in fintech, financial services, or similarly regulated environments.
- Direct experience supporting regulatory reviews, supervisory visits, or thematic inspections.
- Prior exposure to internal audit functions or working as a second line assurance partner to internal audit.
- Familiarity with multiple security and risk frameworks and how auditors interpret them in practice.
- Experience pushing back on auditors with evidence while maintaining constructive relationships.
- Professional certifications in information security, assurance, or audit (e.g. CISM, CISSP, CISA), without being framework driven.
- Experience operating in fast moving technology environments where assurance must be risk based and pragmatic, not checkbox led.
What We Offer You
- Share Options – We offer a Company Share Option Plan (CSOP), giving you the opportunity to benefit from any increase in share value in the event of a sale, merger, or flotation.
- Bonus – Our annual discretionary bonus, paid in May for the previous year, is based on both company and individual performance.
- Flexible benefits - £1000 to spend on benefits to suit you, including private medical insurance, gym membership, dental etc.
- Wellbeing app – confidential, on-demand access to therapy, coaching, counselling, management training or mindfulness sessions with accredited professionals, with company-funded hours and top-up options available.
- Holidays - 33 days annual leave (including bank holidays) plus your birthday off. In the UK, Christmas Day, Boxing Day, and New Year's Day are fixed holidays. You can choose the remaining days to suit your personal schedule.
- Learning opportunities- Our two-day onboarding program, ModStart, helps equip you for success. Learning doesn’t stop there; we’ll continue to support your development through various channels.
- Company-Wide Events - Participate in collaborative and engaging events with colleagues across the business.
- Bike to work / E-bike scheme.
At Modulr, we’re committed to building a diverse, equitable and inclusive culture where everyone feels they belong and can bring their whole self to work. We welcome applications from candidates of all backgrounds as we believe it’s the right thing for our people, our business, and the community we operate in.
By submitting your CV, you consent to us using your personal data to assess your application, contact you, or share your CV with relevant hiring managers. You can request removal of your data at any time by emailing - though this will withdraw you from consideration for the role.
Information Security Assurance Manager in London employer: Modulr
Contact Detail:
Modulr Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Assurance Manager in London
✨Tip Number 1
Network like a pro! Reach out to people in the industry, attend events, and connect with potential colleagues on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their products and services, especially how they handle information security. This will help you tailor your answers and show that you're genuinely interested in the role.
✨Tip Number 3
Practice your interview skills! Get a friend to throw some common questions your way, or even better, find someone in the field to give you feedback. The more comfortable you are, the better you'll perform when it counts.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining our team at Modulr.
We think you need these skills to ace Information Security Assurance Manager in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Information Security Assurance Manager role. Highlight your relevant experience in information security assurance and any specific audits you've led. We want to see how your skills match what we're looking for!
Showcase Your Achievements: Don’t just list your responsibilities; showcase your achievements! Use metrics or examples to demonstrate how you’ve improved security processes or successfully managed audits. This helps us see the impact you've made in previous roles.
Craft a Compelling Cover Letter: Your cover letter is your chance to tell your story. Explain why you're passionate about information security and how your background makes you a great fit for our team. Keep it engaging and relevant to the role!
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s straightforward, and we’ll be able to track your application easily. Plus, you’ll get to explore more about us while you’re at it!
How to prepare for a job interview at Modulr
✨Know Your Stuff
Make sure you brush up on your knowledge of information security frameworks like PCI-DSS, ISO 27001, and SOC 2. Be ready to discuss how you've applied these in past roles, especially in regulated environments. This will show that you’re not just familiar with the theory but can also implement it practically.
✨Prepare for Technical Deep Dives
Since the role involves coordinating technical walkthroughs and interviews, practice explaining complex security concepts in simple terms. Think about how you would communicate findings to both technical teams and senior stakeholders. Clear communication is key!
✨Show Your Independence
Demonstrate your ability to act as an independent assurance partner. Prepare examples where you’ve maintained objectivity while still being a constructive team player. This will highlight your understanding of the separation between assurance, governance, and delivery.
✨Be Ready to Challenge Findings
Think of instances where you’ve had to critically assess audit evidence and push back on auditors. Prepare to discuss how you did this while maintaining positive relationships. This shows you can stand your ground while still being collaborative.