At a Glance
- Tasks: Lead compliance initiatives and develop scalable programmes for PCI and SOC 2.
- Company: NMI powers innovative tech for SMBs and fintech start-ups, making payments easy.
- Benefits: Enjoy remote work, flexible hours, annual bonuses, and a generous holiday allowance.
- Why this job: Join a proactive culture focused on compliance and risk management while making a real impact.
- Qualifications: 5+ years in information security or compliance, with expertise in PCI DSS and SOC 2.
- Other info: Remote-first role with occasional in-person responsibilities; strong commitment to employee wellbeing.
The predicted salary is between 49500 - 58500 ÂŁ per year.
Senior Information Security Compliance Specialist
Join to apply for the Senior Information Security Compliance Specialist role at NMI
Senior Information Security Compliance Specialist
Join to apply for the Senior Information Security Compliance Specialist role at NMI
Get AI-powered advice on this job and more exclusive features.
We are seeking a strategic and execution-driven Senior Information Security Compliance Specialist to champion enterprise-level compliance initiatives and embed regulatory excellence across our operations. In this role, you will lead the development and execution of scalable compliance programs that align with business goals, regulatory obligations, and audit requirements. You\’ll play a critical role in supporting PCI (DSS, PIN, P2PE, MPoC), and SOC 2 initiatives while cultivating a culture of proactive compliance and risk management.
This is primarily a remote position, with occasional in-person responsibilities for cryptographic ceremonies held at our Bristol, UK office.
The Ideal Candidate Is a Seasoned Compliance Specialist Who
- Converts complex regulatory standards into pragmatic, scalable programs, policies, and procedures
- Brings deep familiarity with PCI (DSS, PIN, P2PE, MPoC), and SOC 2
- Partners cross-functionally to drive governance, automation, and continuous improvement
- Leverages GRC tooling to enhance documentation, management, and reporting on compliance initiatives, risk, and controls
- Communicates effectively across technical and non-technical stakeholders
- Champions a proactive compliance culture organization-wide
Key Responsibilities
Compliance Program Development & Execution:
- Develop and evolve compliance programs for PCI (DSS, PIN, P2PE), and SOC 2 across their full lifecycle
- Establish and maintain audit-ready compliance processes that support year-round readiness
- Define internal roadmaps to achieve and sustain certification status
- Own the full policy lifecycle, including control mapping, documentation governance, and change management
Risk Management & Control Validation
- Conduct risk assessments and controls testing to identify and remediate gaps
- Collaborate with engineering, infrastructure, and operations teams to ensure effective design and implementation of controls
- Lead NMI’s Business Continuity and Disaster Recovery planning, management, and testing programs
- Provide compliance-focused input on new systems and service implementations
Audit Preparation & Oversight
- Serve as a primary point of contact for external auditors and assessors
- Lead audit prep activities including walkthroughs, documentation reviews, and technical evidence collection
- Ensure timely resolution of audit findings and communicate progress to stakeholders
Cross-Functional Collaboration & Enablement
- Engage with stakeholders across Engineering, Product, Legal, and HR to support compliance-by-design
- Educate internal teams on compliance responsibilities, procedures, and controls
- Support vendor risk and third-party security assessment activities
Required
Skills & Experience:
- 5+ years of experience in information security, IT risk, or compliance roles
- In-depth experience with PCI DSS and at least two of: PCI PIN, PCI P2PE, SOC 2
- Proven ability to manage end-to-end compliance projects including successful third-party audits
- Familiarity with common security documentation, audit evidence gathering, and security documentation management practices
- Strong organizational, project management, and stakeholder communication skills
Preferred
- Experience with compliance oversight for secure key management ceremonies and cryptographic key exchanges
- Industry certifications such as CISA, CISM, CRISC, or ISO 27001 Lead Implementer
- Background in SaaS or fintech environments
- Exposure to secure development practices, risk assessments, and vendor risk management programs
- Familiarity with common GRC tools such as Tugboat, Drata, or Vanta
- Understanding of privacy regulations (e.g., GDPR, CCPA) as they relate to operational compliance
As well as being a part of something exciting everyday, you will also receive the following benefits:
- Annual bonus scheme dependent on individual and company performance
- Annual salary of £57,500 – £67,500
- 25 days holiday each year (+ bank holidays + 1 day after each year of service with up to a max. of 30 days)
- Workplace pension scheme
- Private medical insurance (upon 30 days of employment)
- 7 hours per day, 35 hours per week
- A remote first culture
- Great work-life balance with our Flexi-time policy
- Family Friendly policies (Enhanced Maternity and Paternity Pay and Shared Parental Leave).
- A chance to develop with an allocated company training budget
- Bike2Work Scheme
- Lifeworks, an Employee Assistance Programme which offers wellbeing, family and financial support services, such as assessments, resources and even 1:1 counselling sessions. It also offers interesting perks such as discounts on gyms, restaurants, high street retailers and cinema tickets
- A strong commitment to employee wellbeing including mental health first aiders
- Employee referral scheme with generous financial reward
- Bonusly colleague reward scheme
We’re looking for creative and passionate people who share our vision of making payments easy. If that sounds like you and you meet the requirements above, then please click on \’Apply for this job\’!
We are an Equal Opportunities employer and will provide reasonable support throughout the recruitment process to applicants who have a disability. Please let us know in advance so that any support, aids or adaptations can be put in place to assist you.
Please be aware that all offers of employment are made subject to receipt of satisfactory background and financial checks.
About Us
NMI enables our partners with choice, and challenges the one-size-fits-all approach to payments. You\’ve probably used NMI in the last 24 hours without even realising it. We’re the platform that powers success for innovative tech created by SMBs, entrepreneurs and fintech start-ups. We’re creative problem solvers who help visionaries smash through boundaries and think beyond what’s possible so they can think about what’s next. But we’re not just built for the tech savvy. We democratise the latest payments technology so that everyone can realise the benefits of easy payments across the full spectrum of commerce. We’re all about enabling more payments in more ways and more places.
Please note that in compliance with the data protection regulations within your jurisdiction, any personal information submitted with your job application may be collected and used by NMI for the purpose of recruitment and employment-related activities. By submitting your application, you acknowledge and provide explicit consent to the processing of your personal information as described in our privacy policy found on our website. For more information on how we process your information, please read our privacy policy here: https://www.nmi.com/legal/privacy-policy/
Salary Range, Depending On Experience
£57,500—£67,500 GBP
Seniority level
-
Seniority level
Mid-Senior level
Employment type
-
Employment type
Full-time
Job function
-
Job function
Information Technology
Referrals increase your chances of interviewing at NMI by 2x
Sign in to set job alerts for “Senior Information Security Specialist” roles.
Remote Information Security & Compliance Manager (m/f/d)
London, England, United Kingdom 1 month ago
Information Security Assurance Specialist
Chandler\’s Ford, England, United Kingdom 1 week ago
Lead_Analyst Information Security Governance Risk Compliance
Senior Director Analyst, Security Architecture and Cloud Security (Remote Canada and EMEA)
London, England, United Kingdom 2 weeks ago
Sr Director Analyst – National Defense and Security – EMEA remote
London, England, United Kingdom 1 week ago
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-Ljbffr
Senior Information Security Compliance Specialist employer: NMI
Contact Detail:
NMI Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Information Security Compliance Specialist
✨Tip Number 1
Familiarise yourself with the specific compliance frameworks mentioned in the job description, such as PCI DSS and SOC 2. Understanding these standards deeply will not only help you in interviews but also demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals in the information security compliance field, especially those who have experience with NMI or similar companies. Engaging in conversations can provide insights into the company culture and expectations, which can be invaluable during the interview process.
✨Tip Number 3
Prepare to discuss your experience with cross-functional collaboration. Since the role requires working with various teams, think of examples where you've successfully partnered with different departments to achieve compliance goals.
✨Tip Number 4
Stay updated on the latest trends and changes in compliance regulations, particularly those affecting the fintech industry. Being knowledgeable about current events can set you apart and show that you're proactive about your professional development.
We think you need these skills to ace Senior Information Security Compliance Specialist
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in information security and compliance, particularly with PCI DSS and SOC 2. Use specific examples that demonstrate your ability to manage compliance projects and collaborate cross-functionally.
Craft a Compelling Cover Letter: In your cover letter, express your passion for compliance and risk management. Mention how your skills align with the responsibilities outlined in the job description, such as developing compliance programs and engaging with stakeholders.
Showcase Relevant Certifications: If you have industry certifications like CISA, CISM, or ISO 27001 Lead Implementer, be sure to include them prominently in your application. This will demonstrate your commitment to professional development and expertise in the field.
Highlight Soft Skills: The role requires effective communication across technical and non-technical teams. Make sure to highlight your soft skills, such as project management and stakeholder engagement, in both your CV and cover letter.
How to prepare for a job interview at NMI
✨Understand Compliance Frameworks
Make sure you have a solid grasp of the compliance frameworks relevant to the role, particularly PCI DSS and SOC 2. Be prepared to discuss how you've implemented these standards in previous roles and how they can be adapted to meet NMI's needs.
✨Showcase Your Project Management Skills
Highlight your experience managing end-to-end compliance projects. Discuss specific examples where you successfully led audits or developed compliance programmes, focusing on your organisational skills and ability to collaborate with cross-functional teams.
✨Communicate Effectively
Since the role involves liaising with both technical and non-technical stakeholders, practice explaining complex compliance concepts in simple terms. This will demonstrate your ability to bridge the gap between different departments and ensure everyone is on the same page.
✨Prepare for Scenario-Based Questions
Expect scenario-based questions that assess your problem-solving abilities in compliance situations. Think of past challenges you've faced and how you resolved them, especially in relation to risk management and audit preparation.