Talent.com
AccessFintech
Security Operations & GRC ManagerAccessFintech • London, England, GB
Security Operations & GRC Manager

Security Operations & GRC Manager

AccessFintech • London, England, GB
6 days ago
Job type
  • Full-time
  • Quick Apply
Job description

AccessFintech is seeking a senior Information Security professional to join our Technology function. This is a broad remit spanning three areas — AFT's internal information security posture, our governance, risk and compliance programme, and the security relationship with AFT's client network.

As a capital markets technology provider handling sensitive financial data for over 250 institutions, client security confidence is as important as internal security rigour, and both rest on a well-run compliance and assurance programme. This role requires someone who can operate credibly across all three — running robust security operations, owning the certification and risk framework, and engaging directly with clients on security due diligence, assessments, and trust-building conversations.

You will report directly to the CTO and work closely with engineering, product, client operations, and solutions teams across all three jurisdictions.

Requirements

1. Internal Information Security

• Own and continuously improve AFT's information security posture across infrastructure, applications, cloud environments, and endpoints

• Lead the operation and evolution of AFT's security tooling — SIEM, EDR, vulnerability management, intrusion detection, and identity and access management (IAM)

• Own AFT's vulnerability management programme — regular assessments, remediation tracking, and risk reporting to the CTO and executive team

• Lead security incident response — identification, containment, investigation, remediation, and post-incident review

• Maintain and develop AFT's information security policies, standards, and procedures across all three jurisdictions

• Embed security into AFT's software development lifecycle (SDLC) — partnering with engineering and DevOps to shift security left

• Design and deliver security awareness training and communications across the global team

2. Client-Facing Security

• Act as AFT's primary point of contact for all client security enquiries, assessments, and due diligence requests

• Own the end-to-end response to client information security questionnaires — including standardised formats such as the Shared Assessments SIG and CSA CAIQ, as well as bespoke questionnaires issued by banks, custodians, and asset managers

• Build and maintain a central answer library so questionnaire responses are consistent, accurate, and efficient to produce — reducing turnaround times and removing reliance on ad hoc drafting

• Coordinate input from engineering, DevOps, legal, and compliance where questions fall outside the existing answer set, and quality-assure all responses before issue

• Manage annual reassessments and periodic client re-certification cycles, ensuring responses remain current as the platform and control environment evolve

• Represent AFT in client-facing security discussions, audits, and on-site or virtual security assessments — building confidence in AFT's security posture at senior level

• Support the client onboarding process from a security and compliance perspective — ensuring new clients can satisfy their own internal security requirements for onboarding AFT

• Partner with Client Operations and Solutions teams to proactively manage client security requirements as part of the commercial relationship

• Maintain AFT's security documentation suite — trust centre content, security overview decks, penetration test summaries, and compliance certificates — keeping them current and client-ready

• Track and manage client-raised security findings, ensuring remediation actions are progressed and communicated back to clients in a timely manner

• Contribute to new business conversations where security posture is a factor — working with Sales and Solutions on RFP responses and client presentations

3. Governance, Risk & Compliance (GRC)

• Own AFT's information security governance framework — policies, standards, and control documentation across all three jurisdictions

• Own and maintain AFT's information security risk register — identifying, assessing, and tracking risks across internal and client-facing dimensions, with defined risk appetite and escalation thresholds

• Own AFT's ISO 27001 and SOC 2 programmes end to end — control design, evidence collection, internal audit, gap remediation, and management of external auditors through certification and surveillance cycles

• Maintain regulatory compliance mapping across UK (FCA, UK GDPR), US (SEC), and Israel (Privacy Protection Law), ensuring controls are traceable to obligations

• Own the third-party and vendor security risk assessment programme — onboarding due diligence, ongoing monitoring, and contractual security requirements

• Own the control testing and assurance calendar, ensuring controls are evidenced continuously rather than reconstructed at audit

• Establish and run the security governance cadence — regular reporting to the CTO and executive team, translating technical risk into business-level insight

• Lead preparation for external security audits, regulatory examinations, and client-initiated security reviews

Skills & Experience

Essential

• 6–10 years of progressive experience in information security or cybersecurity, including at least 2 years in a client-facing or externally-engaged security role

• Proven experience owning client information security questionnaires at volume — including standardised formats (SIG, CAIQ) and bespoke bank or custodian questionnaires — with a track record of building an answer library rather than responding ad hoc

• Experience managing client-raised security findings through to remediation, and reporting outcomes back to client security teams

• Demonstrable experience owning a GRC programme — running an ISO 27001 or SOC 2 certification cycle end to end, including evidence management, internal audit, and managing external auditors

• Experience building and maintaining an information security risk register, with the ability to articulate risk appetite and escalate appropriately

• Experience managing third-party and vendor security risk assessment programmes

• Strong hands-on security operations experience — SIEM (e.g. Splunk, Microsoft Sentinel), EDR, vulnerability management (e.g. Tenable, Qualys), and IAM

• Deep working knowledge of information security frameworks — ISO 27001, SOC 2, NIST CSF — and experience maintaining or achieving certification

• Strong background in cloud-native applications and architectures, with cloud security expertise across IAM, network security, and cloud-native security monitoring

• Strong understanding of data privacy and regulatory obligations in financial services — GDPR, FCA, SEC, or equivalent — including mapping controls across multiple regimes

• Excellent communication skills — able to translate complex security concepts into clear, confident language for client security teams, legal and compliance functions, and non-technical business stakeholders

• Comfortable engaging at senior level with client security and technology teams — building trust and managing relationships through complex due diligence processes

Desirable

• Relevant security certifications — CISSP, CISM, CRISC, CISA, CEH, or equivalent

• ISO 27001 Lead Implementer or Lead Auditor certification

• Experience in capital markets, fintech, or regulated financial services — familiarity with the security expectations of buy-side, sell-side, or custodian institutions

• Experience with DevSecOps practices — integrating security into CI/CD pipelines and engineering workflows

• Scripting or automation capability — Python, PowerShell, or Bash — for security tooling and reporting

• Experience building or maintaining a client trust centre or security documentation programme

• Experience with GRC tooling and compliance automation platforms

• AWS specifically is an advantage — hands-on experience securing containerised and serverless workloads, and using AWS-native security services such as GuardDuty, Security Hub, and Config

Create a job alert for this search

Security Operations & GRC Manager • London, England, GB

Similar jobs

Group Security Manager

SSR PersonnelGreater London, England, GB
Full-time

We are pleased to be partnering with a leading and well-established security services provider to appoint an experienced Operations Manager – Security.This is a senior appointment offering the succ... Show more

 • Promoted

Datacenter Site Security Leader - 24/7 Ops & Team Growth

Securitas UKGreater London, England, GB
Full-time

A leading security services provider in Greater London seeks a Site Security Manager to oversee on-site operations and lead a 24/7 security team.Responsible for managing personnel and ensuring comp... Show more

 • Promoted

Hospitality IT Operations & Security Lead

Virgin Hotels EdinburghGreater London, England, GB
Full-time

Virgin Hotels London is seeking an IT Manager to lead the technology landscape for the hotel, focusing on stability, security, and compliance across on‑prem and cloud platforms.You will manage vend... Show more

 • Promoted

Infrastructure Security Operations Manager

Sumitomo Mitsui Financial Group, Inc.Greater London, England, GB
Full-time

SMBC Group is a universal banking platform in EMEA delivering corporate finance products, investment banking, and capital market solutions.We are committed to an inclusive culture and supporting su... Show more

 • Promoted

Security Operations Lead (SC Cleared)

SR2City Of London, England, GB
Full-time

SR2 is seeking an experienced Information & Cyber Security Manager to support a high profile secure programme in City of London.You will work within the Security Operations function to assure secur... Show more

 • Promoted

Global Security Operations Lead (Associate Director)

IcebergGreater London, England, GB
Full-time

A leading global financial institution is seeking an Associate Director of Security Operations to join their world-class security team in London.In this pivotal role, you will support the Global He... Show more

 • Promoted

Senior Operations Leader – Intelligence & Security Delivery

PrevailGreater London, England, GB
Full-time

Prevail is looking for an experienced Senior Operations Manager based in Greater London to lead operational delivery for their projects.You will oversee multiple engagements, ensuring they are deli... Show more

 • Promoted

Senior Operations Leader - Intelligence & Security Delivery

PREVAILCity of Westminster, England, GB
Full-time

Prevail Partners is seeking an experienced Senior Operations Manager to lead the delivery of client work and strengthen governance across engagements.You will supervise multiple concurrent engageme... Show more

 • Promoted

Security Manager

LexisNexis Risk SolutionsGreater London, England, GB
Full-time

Get AI-powered advice on this job and more exclusive features.Direct message the job poster from LexisNexis Risk Solutions.Join Us as a Security Manager and Safeguard Our Systems.Are you able to op... Show more

 • Promoted

SAP Security & GRC Lead

PRIMA PartnersGreater London, England, GB
Full-time

ESSENTIAL SKILLS | SAP Security & GRC Lead.Fluent English language skills (Written & Verbal).Proven expertise in SAP Security architecture and GRC solutions (SAP Access Control, Identity Access Gov... Show more

 • Promoted

Security Operations Leader – Multi-Site & Licensing Expert

Soho House & Co.Greater London, England, GB
Full-time

Soho House is seeking a senior security and safety professional to oversee licensing, safety and security across London sites, with occasional support for Brighton and Manchester.You will lead inve... Show more

 • Promoted

Security GRC Manager

HumaansGreater London, England, GB
Full-time

Humaans is building the next generation of infrastructure for the workplace; software designed for companies that are scaling fast, operating globally, and pushing into new boundaries.What started ... Show more

 • Promoted

OT Cyber Security Senior Manager - Critical Infrastructure

WeAreTechWomenGreater London, England, GB
Full-time

WeAreTechWomen is seeking an experienced OT Cyber Security Senior Manager to lead security programmes across critical infrastructure sectors.You will manage client projects, ensuring seamless execu... Show more

 • Promoted

Senior Operations Leader – Intelligence & Security Delivery

Prevail Partners LimitedGreater London, England, GB
Full-time

Prevail Partners Limited is seeking a Senior Operations Manager to lead the delivery of client projects while strengthening operational processes.The role involves managing several simultaneous eng... Show more

 • Promoted

Cyber Security Operations Manager

jobr.proGreater London, England, GB
Full-time

We are seeking a Security Operations Manager to lead and strengthen Frasers Group’s internal Security Operations Center (SOC), ensuring robust monitoring, detection, and response capabilities acros... Show more

 • Promoted

Chief Cyber Defence Centre | Lead Security Operations

Lloyds Banking GroupGreater London, England, United Kingdom
Full-time

Lloyds Banking Group is seeking a Head of Cyber Defence Centre to lead an engineering‑first Cyber Defence Lab responsible for designing, building and operating resilient security capabilities acros... Show more

 • Promoted

Security & Compliance Lead - GRC, ISO 27001 & TPRM

PEI GroupGreater London, England, GB
Full-time

PEI Group is seeking an Information Security & Compliance Officer based in Greater London.This role is pivotal in coordinating security activities, supporting compliance initiatives, and managing t... Show more

 • Promoted

Security Operations Lead — Player-Coach for Global Growth

ME+EMGreater London, England, GB
Full-time

ME+EM is looking for an Information Security Operations Manager to lead its security team in West London.This role requires a strong leader who can bridge high-level risk management with technical ... Show more

 • Promoted

Group Tech Strategy & Security Leader

Billion Dollar BoyGreater London, England, United Kingdom
Full-time

Billion Dollar Boy is seeking a Group Head of Tech to drive secure, efficient and innovative technology across its London-based teams and global operations.You will align IT with business goals, ov... Show more

 • Promoted

Offensive Security Manager

Barlowe LLPGreater London, England, GB
Full-time

We tackle the most complex problems in quantitative finance, by bringing scientific clarity to financial complexity.From our London HQ, we unite world‑class researchers and engineers in an environm... Show more