Information Security Lead

Information Security Lead

Full-Time 48000 - 72000 ÂŁ / year (est.) No home office possible
Go Premium
V

At a Glance

  • Tasks: Lead security governance, manage incidents, and oversee data protection strategies.
  • Company: VFX Financial, a leader in secure global payments and treasury management.
  • Benefits: Profit share plan, equity options, flexible learning budget, and annual incentive trips.
  • Why this job: Join a dynamic team and make a real impact in cybersecurity.
  • Qualifications: 5+ years in IT Security with strong Azure and SIEM experience.
  • Other info: Work remotely or from our offices in the UK or Portugal.

The predicted salary is between 48000 - 72000 ÂŁ per year.

Join to apply for the Information Security Lead role at VFX Financial

VFX is a fast‑growing FinTech simplifying global trading and cash management for businesses worldwide. We remove complexity so clients can transact globally with confidence. Our tailored, secure, and efficient solutions span FX and international payments, multi‑currency accounts, and integrations that make global operations effortless.

With six offices, five regulatory licences, and an 83% CAGR over the past three years, we’re scaling fast and earning industry recognition – including CNBC UK’s Top Fintech Companies for 2025, Wealth & Finance FinTech Awards 2025, and the Business Growth Award from Business Awards UK. Behind it all is a team of ambitious VFXers who think like founders, never stop learning, and go the extra mile to help our clients succeed.

About the Role

The Information Security Lead will take ownership of VFX’s security governance, risk management, and operational resilience, ensuring compliance with frameworks such as DORA/Ops Res. You’ll oversee vulnerability management, SOC operations (whether internal or outsourced), vendor security, and regulatory readiness.

A key part of the role will be implementing Microsoft Sentinel as the SIEM platform and managing SOC operations day to day. You’ll also support data security, resilience planning, secure development practices, and provide board‑level infosec reporting. Experience with ISO 27001 and SOC 2 is highly desirable.

Location

This role can be based in either the UK or Portugal. We’re open to fully remote candidates in both locations, though you’re also welcome to work from our offices in London or Portimão.

Key Responsibilities

Governance & Risk Oversight

  • Define and enforce security governance policies across Azure and enterprise systems.
  • Maintain and update the IT risk register, ensuring risks are tracked, prioritized, and mitigated.
  • Drive compliance with DORA, GDPR, and fintech regulatory obligations.
  • Contribute to initiatives for ISO 27001 and SOC 2 readiness.
  • Provide regular reporting to leadership and the board on security posture, KPIs, and risk trends.

Security Operations & Incident Response

  • Implement and configure Microsoft Sentinel as the company’s SIEM.
  • Manage the SOC function (whether internal or delivered by a vendor), ensuring SLA compliance and effective detection/response.
  • Act as the internal escalation point for SOC alerts and incidents.
  • Lead incident response planning, post‑mortems, and resilience testing.
  • Collaborate with the Infrastructure team on business continuity and disaster recovery (BCP/DR) from a security perspective.

Vulnerability & Attack Surface Management

  • Lead the vulnerability management lifecycle, coordinating remediation with Infra/Dev teams.
  • Oversee attack surface monitoring, penetration testing, and red team activities.
  • Ensure vulnerabilities are prioritized based on business risk.

Data Security & Privacy

  • Oversee data security strategy, including classification, encryption, retention, and privacy‑by‑design.
  • Ensure compliance with data protection laws (GDPR) and industry standards (PCI DSS).

Vendor & Third‑Party Security

  • Manage relationships with SOC providers, penetration testers, and auditors.
  • Conduct third‑party risk assessments and due diligence on critical vendors.

Security Awareness & Culture

  • Champion DevSecOps practices, including code scanning, pipeline security, and secure design reviews.
  • Run security awareness programs and phishing simulations across the company.
  • Act as the security point of contact for regulators, auditors, investors, and key clients.

Candidate Profile

Qualifications & Experience

  • 5+ years in IT Security, Cybersecurity, or Risk Management roles.
  • Strong knowledge of Azure security governance and controls (in partnership with Cloud Architect).
  • Hands‑on experience with SIEM implementation (Microsoft Sentinel preferred).
  • Experience with SOC operations (internal or vendor‑managed).
  • Knowledge of vulnerability management, incident response, and risk frameworks.
  • Familiarity with DORA, GDPR, and fintech regulatory frameworks.
  • ISO 27001 and SOC 2 experience preferable (certification, audit prep, or implementation).

Soft Skills

  • Strong communicator, able to govern SOC vendors or lead internal SOC teams.
  • Pragmatic, risk‑based decision maker with business alignment.
  • Calm, structured, and decisive in incident response situations.
  • Ability to engage business leaders, regulators, and external partners effectively.

Benefits at VFX

We offer more than just perks — we offer ownership.

Our benefits include:

  • Generous Profit Share Plan (PSP)
  • Equity via the Company Share Option Plan (CSOP)
  • Annual all‑expenses paid company incentive trip abroad
  • Flexible learning & development budget

Through our Profit Share Scheme (PSP) and Company Share Option Plan (CSOP), every team member has a chance to own a stake in the business and share in the profits. In 2024, PSP participants received over $1,000,000 USD. From those distributions, more than 80% of eligible VFXers chose to become shareholders — a powerful reflection of the belief and commitment that drives VFX forward.

If you care about building something meaningful, take pride in your work, and are motivated by impact — you’ll thrive here.

#J-18808-Ljbffr

Information Security Lead employer: VFX Financial

VFX Financial is an exceptional employer that fosters a culture of ownership and ambition, where every team member is encouraged to think like a founder. With flexible working options in the UK or Portugal, generous profit-sharing plans, and a commitment to continuous learning and development, VFX offers a rewarding environment for those passionate about making a meaningful impact in the world of global payments and treasury management.
V

Contact Detail:

VFX Financial Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Lead

✨Tip Number 1

Network like a pro! Reach out to current employees at VFX Financial on LinkedIn. A friendly message can go a long way in getting insider info and maybe even a referral.

✨Tip Number 2

Prepare for the interview by diving deep into VFX's services and values. Show us you understand how our tailored solutions work and how your skills can enhance our mission.

✨Tip Number 3

Practice your responses to common security scenarios. We love candidates who can think on their feet, especially when it comes to incident response and risk management.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take that extra step.

We think you need these skills to ace Information Security Lead

Azure Security Governance
IT Risk Management
DORA Compliance
GDPR Compliance
ISO 27001
SOC 2
SIEM Implementation
Microsoft Sentinel
SOC Operations
Vulnerability Management
Incident Response
Data Security Strategy
Third-Party Risk Assessments
DevSecOps Practices
Strong Communication Skills

Some tips for your application 🫡

Tailor Your CV: Make sure your CV speaks directly to the Information Security Lead role. Highlight your experience with Azure security governance, SIEM implementation, and any relevant certifications like ISO 27001 or SOC 2. We want to see how your skills align with what we’re looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to tell us why you’re passionate about cybersecurity and how your previous roles have prepared you for this position. Don’t forget to mention your experience in risk management and incident response — we love a good story!

Show Off Your Soft Skills: While technical skills are crucial, we also value strong communication and decision-making abilities. In your application, give examples of how you've effectively engaged with business leaders or managed SOC teams. We want to know how you handle pressure and lead in tough situations!

Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to showcase your application in the best light. Plus, it helps us keep track of all the amazing candidates like you!

How to prepare for a job interview at VFX Financial

✨Know Your Stuff

Make sure you brush up on your knowledge of Azure security governance and controls. Familiarise yourself with DORA, GDPR, and the relevant fintech regulations. Being able to discuss these topics confidently will show that you're serious about the role.

✨Showcase Your Experience

Prepare specific examples from your past roles that highlight your experience in IT Security, Cybersecurity, or Risk Management. Think about times when you successfully managed incidents or led vulnerability management initiatives. This will help demonstrate your hands-on expertise.

✨Communicate Clearly

As a potential Information Security Lead, strong communication skills are key. Practice explaining complex security concepts in simple terms. You might need to engage with business leaders or external partners, so being clear and concise is crucial.

✨Be Ready for Scenario Questions

Expect scenario-based questions that test your incident response skills. Think through how you would handle various security incidents or compliance challenges. Showing a calm and structured approach will impress the interviewers and reflect your decision-making abilities.

Information Security Lead
VFX Financial
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

V
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>