Lead, Information Security
Your mission
As an Information Security Expert, you are a senior individual contributor who sets direction and solves the hardest GRC problems in a regulated fintech environment. You shape our security governance strategy, ensure our control framework remains effective as the business scales, and act as a key advisor to security leadership and senior business stakeholders on risk and compliance decisions. You’ll lead complex, high-impact initiatives (multi-entity, multi-region, regulator/customer-facing), influence across the organisation, and raise the bar for how we design, test, and evidence security controls.
What you’ll do
GRC strategy & roadmap: Define multi-year GRC roadmap aligned to business strategy, risk appetite, and regulatory expectations (e.g., DORA readiness, audit strategy, control maturity targets). Drive control framework evolution: rationalize controls, reduce duplication, and ensure proportionality based on criticality, data sensitivity, and business impact. Establish “north star” principles for governance (e.g., minimum control baselines, exception governance, evidence-by-design).
Executive advisory & decision support: Advise leadership on material risk decisions: risk acceptance, remediation prioritisation, control investments, and scope decisions. Produce executive-grade outputs: risk narratives, board/committee materials, and regulator/customer responses with defensible rationale. Facilitate senior stakeholder alignment when priorities conflict (delivery speed vs control rigor; cost vs assurance depth).
Regulatory, audit & assurance leadership (complex scope): Own strategy and approach for major audits/assurance activities (ISO 27001, SOC 2, regulatory examinations, key client due diligence), including scope, positioning, and negotiation. Lead responses to complex audit/regulatory issues: root-cause analysis, corrective action programs, and sustained effectiveness verification.
Domain SME ownership (one or more, depending on needs): You may be the SME for one or more of: ISMS/ISO 27001 at scale (multi-entity scope, continuous compliance); DORA / operational resilience governance (control mapping, ICT risk integration, testing oversight); Third-party risk for critical ICT providers (oversight model, ongoing monitoring, exit/continuity governance); Security control assurance (testing program design, evidence standards, control health metrics).
Enablement, standards & mentorship: Set standards and reusable artifacts: control narratives, evidence templates, testing methodologies, and playbooks. Mentor specialists and associates; raise organisation-wide capability through coaching and review. Partner with Security Engineering/IT/Compliance to embed controls into workflows (policy-to-automation where possible).
Who you are
Typically 7–10+ years of experience in information security GRC, audit/assurance, security risk, compliance, software engineering and/ or financial services risk roles.
Demonstrated ownership of complex, multi-stakeholder GRC programs and successful navigation of audits/regulatory scrutiny.
Deep working knowledge of ISO 27001, DORA and strong familiarity with adjacent frameworks (SOC 2, NIST CSF, BaIT, COBIT), including how to test and evidence controls.
Strong technology risk understanding across cloud, IAM, SDLC governance, incident management, vulnerability management, logging/monitoring, crypto/fintech operational processes (as relevant).
You are able to influence across the organisation and resolve conflicts with a risk-based, outcome-oriented approach.