At a Glance
- Tasks: Help build secure systems and frameworks that ensure compliance and protect customer data.
- Company: Join Visa, a global leader in payments technology with a mission to uplift everyone, everywhere.
- Benefits: Enjoy competitive pay, flexible work options, and opportunities for professional growth.
- Other info: Hybrid role with excellent career advancement opportunities in a dynamic team.
- Why this job: Make a real impact on security and compliance in a fast-paced tech environment.
- Qualifications: 3+ years in information security compliance and strong communication skills required.
The predicted salary is between 60000 - 80000 £ per year.
About Us
Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid. At Visa, you'll have the opportunity to create impact at scale — tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world. Join Visa and do work that matters – to you, to your community, and to the world. Progress starts with you.
Job Description
In your role as Information Security GRC Engineering Consultant - Featurespace, you will help us achieve our goals and deliver success on behalf of our customers by:
- Building systems and frameworks, in line with industry standards, Visa Key Controls and customer expectations, that make compliance continuous, measurable, and low‑friction.
- Acting as a hands‑on, solutions‑driven GRC engineering consultant, translating regulatory and control requirements (PCI DSS, SOC 2, Visa KCX) into practical, implementable controls within our products, teams and cloud environments.
- Designing and implementing automation where it adds genuine value, including control validation, evidence collection, workflow orchestration, and compliance telemetry.
- Leading compliance outcomes through expertise and influence, working cross‑functionally with the product, engineering and platform teams in Featurespace, and the central Visa Cyber, Risk and Legal teams.
- Helping Featurespace integrate effectively into Visa’s security and compliance ecosystem.
- Providing assurance to our customers by providing appropriate responses to customer RFP questions and customer audits on topics such as cybersecurity, technology operations, and compliance with standards (e.g., PCI DSS, SOC 2).
Responsibilities
As a company we hire people with a willingness to adapt to a variable role, so along with the key responsibilities below, we ask for ownership of any other duties as required.
- Control Framework Ownership & Assurance: Lead the implementation and ongoing operation of Featurespace’s security controls framework, ensuring alignment with Visa Key Controls, PCI DSS, SOC 2, and other applicable regulatory or customer requirements.
- GRC Engineering, Integration & Automation: Translate regulatory, compliance, and control requirements into practical, product-aware implementations.
- Advisory, Enablement & Secure-by-Design: Act as a trusted advisor and subject matter expert to Featurespace engineering, product, commercial, and leadership teams.
- Risk Management, Audit & External Engagement: Conduct security risk assessments and business impact analyses, and recommend appropriate control improvements.
Qualifications
Basic Qualifications:
- 3 or more years’ experience with ensuring information security compliance, preferably in highly regulated environments.
- Strong experience working with, building, and implementing successfully, a range of security control frameworks such as SOC 2, ISO27000 and PCI.
- Bachelors degree preferred in information assurance, computer science, engineering, or related field.
- Demonstrated ability to multi-task, work calmly under pressure, think analytically, understand complex systems and communicate complexity effectively.
- Excellent written and verbal communication as well as good presentation skills.
- Proficient English language skills are required.
Preferred Qualifications:
- Preferably one or more of the following security qualifications - ISO270001 LI/LA, PCIP, ISA, CISA, CISM, CISSP or similar.
- History of applying a strong/deep understanding of information security controls, technologies, policies, processes, and best practices.
This is a hybrid position. Expectation of days in office will be confirmed by your hiring manager.
Information Security GRC Engineering Consultant employer: Tink
Visa in Basingstoke is an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation. Employees benefit from comprehensive growth opportunities, including training in cutting-edge technologies like Kubernetes and automation, while enjoying a supportive environment that values work-life balance with flexible office arrangements. Joining Visa means being part of a global leader in payment technology, where your contributions directly impact service stability and customer satisfaction.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security GRC Engineering Consultant
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching Visa's culture and values. Understand their approach to information security and compliance, and think about how your skills align with their needs. This will help you stand out as a candidate who truly gets what they're about.
✨Tip Number 3
Practice your responses to common interview questions, especially those related to GRC engineering and compliance frameworks. Use the STAR method (Situation, Task, Action, Result) to structure your answers and showcase your experience effectively.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining the Visa team.
We think you need these skills to ace Information Security GRC Engineering Consultant
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience with information security compliance and frameworks like PCI DSS and SOC 2. We want to see how your skills align with the role, so don’t hold back on showcasing your relevant achievements!
Showcase Your Technical Skills:Since this role involves a bit of technical know-how, be sure to mention any programming languages you’re proficient in and your experience with security controls. We love seeing candidates who can bridge the gap between technical and non-technical teams!
Be Clear and Concise:When writing your application, keep it straightforward and to the point. Use clear language to explain your past experiences and how they relate to the job. We appreciate applicants who can communicate complex ideas simply and effectively.
Apply Through Our Website:We encourage you to submit your application through our website for the best chance of being noticed. It’s the easiest way for us to track your application and get back to you quickly. Don’t miss out on the opportunity to join our team!
How to prepare for a job interview at Tink
✨Know Your Frameworks
Make sure you’re well-versed in security control frameworks like PCI DSS and SOC 2. Brush up on how these frameworks apply to the role and be ready to discuss how you've implemented them in past experiences.
✨Showcase Your Technical Skills
Be prepared to demonstrate your technical proficiency, especially in programming languages relevant to the role. You might face a coding assessment, so practice common coding challenges that relate to security automation and compliance.
✨Communicate Clearly
Since you'll be working with both technical and non-technical teams, practice explaining complex security concepts in simple terms. This will show your ability to bridge gaps between different stakeholders effectively.
✨Prepare for Scenario Questions
Expect scenario-based questions where you’ll need to apply your knowledge to real-world situations. Think about past projects where you’ve had to lead compliance efforts or integrate security controls, and be ready to share those experiences.