About Lendable Lendable is on a mission to build the world's best technology to help people get credit and save money. We are building one of the world's leading fintech companies and are off to a strong start: a UK unicorn with a team of just over 700 people, one of the fastest-growing tech companies in the UK, profitable since 2017, backed by top investors including Balderton Capital and Goldman Sachs, and loved by customers with the best reviews in the market (4.9 across 10,000s of reviews on Trustpilot). We have rebuilt the Big Three consumer finance products from scratch: loans, credit cards and car finance, getting money into our customers' hands in minutes instead of days. About the Role We are looking for a proactive Security GRC Analyst to join our Information Security team. You will play a pivotal role in scaling our security posture in a fast paced, AI driven, cloud native environment and shape our security culture and operational resilience. What You'll Be Doing Framework & Regulatory Alignment: Help maintain, improve, and scale our security compliance programmes, ensuring ongoing alignment with standards such as SOC2, ISO27001, PCI DSS, UKGDPR and regulator expectations. Risk & Mitigation: Collaborate on identifying security risks across the business-including emerging risks from AI driven and agentic threats-and support the team in driving practical, risk first mitigation strategies. Compliance Automation: Utilize our security compliance platform (e.g., Vanta/Drata) to orchestrate automated evidence collection, reducing manual overhead and moving the company toward continuous audit readiness. Third Party Risk Management (TPRM): Conduct vendor and third party security risk assessments to evaluate the security posture of partners and critical outsourced service providers. Translating Risk & Governance: Work with the team to bridge the gap between engineering and business governance by turning technical security metrics into clear, risk based narratives for internal stakeholders and external auditors. Security Culture & Awareness: Support the delivery and promotion of security awareness initiatives to help drive a strong culture of shared security responsibility across the organisation. Technical Collaboration: Actively engage in conversations with engineers, developers, and IT teams-understanding their technical language and workflows to align security controls with engineering realities. Audit & Assessment Support: Participate in external audits and assessments by gathering evidence, preparing documentation, and ensuring a smooth, successful audit cycle. What You Will Bring Experience: 5+ years of experience in a related role, ideally within a regulated, cloud native business or FinTech. Compliance & Risk Expertise: A strong, foundational understanding of security risk management principles and hands on experience with compliance frameworks such as ISO27001, PCI DSS, or SOC2. Risk First & Pragmatic Mindset: A natural tendency to start with the "why" (the risk) rather than the checklist, balancing strict financial regulations with operational agility. Communication & Collaboration: Outstanding communication skills with a proven ability to converse with technical stakeholders, translate challenges into business risks, and influence decisions. Drive & Initiative: A highly proactive, self motivated mindset that actively seeks ways to improve security posture and drive change. Desirable Tooling: Direct, practical experience working with modern security compliance and automation platforms (e.g., Vanta or Drata). Programming and automation: Experience with Python or a similar scripting language, and/or using AI to improve productivity through automation. Interview Process Initial call with a recruiter. 15 minute cognitive assessment. 30 minute hiring manager call. 60 minute technical interview. 60 minute culture add interview. Life at Lendable Winning team: the opportunity to scale up one of the world's most successful fintech companies. Flexible working Flexible approach tailored to each role. Hybrid roles require three days in office weekly; fully remote roles include regular opportunities for in person connection through socials and off sites. Benefits Health coverage: support for physical and mental wellbeing, including private health cover. Retirement & savings: long term financial wellbeing through retirement savings plans. Employee referral programme: earn a competitive bonus when you refer successful new team members. Office meals & snacks: fully stocked kitchen and complimentary lunches on in office days at select locations. Sustainable commuting: cycle to work and electric vehicle salary sacrifice schemes available in select locations. Please note: The availability and details of specific benefits vary by location and role. For more information, please speak to your Talent Partner.
25/07/2026
Full time
About Lendable Lendable is on a mission to build the world's best technology to help people get credit and save money. We are building one of the world's leading fintech companies and are off to a strong start: a UK unicorn with a team of just over 700 people, one of the fastest-growing tech companies in the UK, profitable since 2017, backed by top investors including Balderton Capital and Goldman Sachs, and loved by customers with the best reviews in the market (4.9 across 10,000s of reviews on Trustpilot). We have rebuilt the Big Three consumer finance products from scratch: loans, credit cards and car finance, getting money into our customers' hands in minutes instead of days. About the Role We are looking for a proactive Security GRC Analyst to join our Information Security team. You will play a pivotal role in scaling our security posture in a fast paced, AI driven, cloud native environment and shape our security culture and operational resilience. What You'll Be Doing Framework & Regulatory Alignment: Help maintain, improve, and scale our security compliance programmes, ensuring ongoing alignment with standards such as SOC2, ISO27001, PCI DSS, UKGDPR and regulator expectations. Risk & Mitigation: Collaborate on identifying security risks across the business-including emerging risks from AI driven and agentic threats-and support the team in driving practical, risk first mitigation strategies. Compliance Automation: Utilize our security compliance platform (e.g., Vanta/Drata) to orchestrate automated evidence collection, reducing manual overhead and moving the company toward continuous audit readiness. Third Party Risk Management (TPRM): Conduct vendor and third party security risk assessments to evaluate the security posture of partners and critical outsourced service providers. Translating Risk & Governance: Work with the team to bridge the gap between engineering and business governance by turning technical security metrics into clear, risk based narratives for internal stakeholders and external auditors. Security Culture & Awareness: Support the delivery and promotion of security awareness initiatives to help drive a strong culture of shared security responsibility across the organisation. Technical Collaboration: Actively engage in conversations with engineers, developers, and IT teams-understanding their technical language and workflows to align security controls with engineering realities. Audit & Assessment Support: Participate in external audits and assessments by gathering evidence, preparing documentation, and ensuring a smooth, successful audit cycle. What You Will Bring Experience: 5+ years of experience in a related role, ideally within a regulated, cloud native business or FinTech. Compliance & Risk Expertise: A strong, foundational understanding of security risk management principles and hands on experience with compliance frameworks such as ISO27001, PCI DSS, or SOC2. Risk First & Pragmatic Mindset: A natural tendency to start with the "why" (the risk) rather than the checklist, balancing strict financial regulations with operational agility. Communication & Collaboration: Outstanding communication skills with a proven ability to converse with technical stakeholders, translate challenges into business risks, and influence decisions. Drive & Initiative: A highly proactive, self motivated mindset that actively seeks ways to improve security posture and drive change. Desirable Tooling: Direct, practical experience working with modern security compliance and automation platforms (e.g., Vanta or Drata). Programming and automation: Experience with Python or a similar scripting language, and/or using AI to improve productivity through automation. Interview Process Initial call with a recruiter. 15 minute cognitive assessment. 30 minute hiring manager call. 60 minute technical interview. 60 minute culture add interview. Life at Lendable Winning team: the opportunity to scale up one of the world's most successful fintech companies. Flexible working Flexible approach tailored to each role. Hybrid roles require three days in office weekly; fully remote roles include regular opportunities for in person connection through socials and off sites. Benefits Health coverage: support for physical and mental wellbeing, including private health cover. Retirement & savings: long term financial wellbeing through retirement savings plans. Employee referral programme: earn a competitive bonus when you refer successful new team members. Office meals & snacks: fully stocked kitchen and complimentary lunches on in office days at select locations. Sustainable commuting: cycle to work and electric vehicle salary sacrifice schemes available in select locations. Please note: The availability and details of specific benefits vary by location and role. For more information, please speak to your Talent Partner.
Deerfoot Recruitment Solutions Limited
City, London
Senior ServiceNow Engineer - GRC/IRM (TPRM, OpsRes & BCM) London (Hybrid - 3 days onsite per week) Banking - Up to 120,000 + Bonus + Benefits This is a brand-new, strategically created Vice President position - not a backfill - giving you the chance to shape a global GRC product suite from the ground up. Do you want to own the product roadmap for TPRM, OpsRes and BCM at a major financial services organisation, with the mandate to take these capabilities from a single-region platform to a genuinely global offering across EMEA, APAC and the US? If you're a ServiceNow professional who can move fluently between the boardroom and the sprint room, this could be the role you've been waiting for. You'll join as the product-level owner for TPRM, OpsRes and BCM, engaging senior stakeholders up to MD and Board level, and translating what the business needs into clear technical stories for the development team to build. This is a highly mature ServiceNow environment, built on the Common Services Data Model (CSDM) and moving toward fully out-of-the-box, AI-enabled versions of these products within the next 3-6 months. This is a rare opportunity to combine strong technical credibility with real influence over strategy, adoption and where the platform goes next. What you'll be doing: Owning the product roadmap for TPRM, OpsRes and BCM, translating business requirements into clear, technical user stories for the development team to deliver Acting as the go-to voice for the GRC suite, engaging senior stakeholders - up to MD and Board level - to understand where the business is heading and guide it toward the ServiceNow way of working Building the case for, and supporting delivery of, a global rollout as EMEA, APAC and the US converge onto a single platform Providing technical governance and change approval, and overseeing testing and preparation for platform upgrades and releases Producing and maintaining documentation, training materials and process guides, while mentoring junior and off-shore team members Building strong relationships with stakeholders across the region and globally to share best practice and drive continuous improvement What you'll bring: Strong technical grounding in ServiceNow, ideally with hands-on GRC/IRM experience (TPRM, OpsRes and/or BCM), but equally comfortable operating at product/strategy level rather than day-to-day scripting A track record of engaging senior/executive stakeholders and translating business requirements into technical user stories for development teams Strong understanding of risk management, GRC and ServiceNow best practice, with sharp problem-solving skills Proven experience in a regulated environment (financial services, insurance or critical infrastructure), with the credibility to manage audit and IT security requirements Excellent communication and leadership skills, with a structured, detail-focused approach Desirable: current ServiceNow certifications, familiarity with ITIL/COBIT, and exposure to DORA compliance The package: Up to 120,000 plus bonus and benefits, based in London with hybrid working (3 days in the office per week). If this sounds like the platform-defining role you've been looking for, apply now or get in touch for a confidential conversation about the opportunity. If you've held any of these roles or used these technologies/skills, this role could be a great fit: ServiceNow Engineer, ServiceNow Developer, ServiceNow Consultant, ServiceNow Technical Lead, ServiceNow Product Manager, GRC Engineer, GRC Analyst, GRC Product Owner, IRM Engineer, IRM Consultant, Integrated Risk Management Engineer, Operational Resilience (OpsRes) Specialist, Business Continuity Management (BCM) Specialist, Third-Party Risk Management (TPRM) Consultant, Risk & Compliance Technology Engineer, ServiceNow Platform Engineer, ServiceNow Administrator, ITIL, COBIT, DORA compliance. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate 1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
24/07/2026
Full time
Senior ServiceNow Engineer - GRC/IRM (TPRM, OpsRes & BCM) London (Hybrid - 3 days onsite per week) Banking - Up to 120,000 + Bonus + Benefits This is a brand-new, strategically created Vice President position - not a backfill - giving you the chance to shape a global GRC product suite from the ground up. Do you want to own the product roadmap for TPRM, OpsRes and BCM at a major financial services organisation, with the mandate to take these capabilities from a single-region platform to a genuinely global offering across EMEA, APAC and the US? If you're a ServiceNow professional who can move fluently between the boardroom and the sprint room, this could be the role you've been waiting for. You'll join as the product-level owner for TPRM, OpsRes and BCM, engaging senior stakeholders up to MD and Board level, and translating what the business needs into clear technical stories for the development team to build. This is a highly mature ServiceNow environment, built on the Common Services Data Model (CSDM) and moving toward fully out-of-the-box, AI-enabled versions of these products within the next 3-6 months. This is a rare opportunity to combine strong technical credibility with real influence over strategy, adoption and where the platform goes next. What you'll be doing: Owning the product roadmap for TPRM, OpsRes and BCM, translating business requirements into clear, technical user stories for the development team to deliver Acting as the go-to voice for the GRC suite, engaging senior stakeholders - up to MD and Board level - to understand where the business is heading and guide it toward the ServiceNow way of working Building the case for, and supporting delivery of, a global rollout as EMEA, APAC and the US converge onto a single platform Providing technical governance and change approval, and overseeing testing and preparation for platform upgrades and releases Producing and maintaining documentation, training materials and process guides, while mentoring junior and off-shore team members Building strong relationships with stakeholders across the region and globally to share best practice and drive continuous improvement What you'll bring: Strong technical grounding in ServiceNow, ideally with hands-on GRC/IRM experience (TPRM, OpsRes and/or BCM), but equally comfortable operating at product/strategy level rather than day-to-day scripting A track record of engaging senior/executive stakeholders and translating business requirements into technical user stories for development teams Strong understanding of risk management, GRC and ServiceNow best practice, with sharp problem-solving skills Proven experience in a regulated environment (financial services, insurance or critical infrastructure), with the credibility to manage audit and IT security requirements Excellent communication and leadership skills, with a structured, detail-focused approach Desirable: current ServiceNow certifications, familiarity with ITIL/COBIT, and exposure to DORA compliance The package: Up to 120,000 plus bonus and benefits, based in London with hybrid working (3 days in the office per week). If this sounds like the platform-defining role you've been looking for, apply now or get in touch for a confidential conversation about the opportunity. If you've held any of these roles or used these technologies/skills, this role could be a great fit: ServiceNow Engineer, ServiceNow Developer, ServiceNow Consultant, ServiceNow Technical Lead, ServiceNow Product Manager, GRC Engineer, GRC Analyst, GRC Product Owner, IRM Engineer, IRM Consultant, Integrated Risk Management Engineer, Operational Resilience (OpsRes) Specialist, Business Continuity Management (BCM) Specialist, Third-Party Risk Management (TPRM) Consultant, Risk & Compliance Technology Engineer, ServiceNow Platform Engineer, ServiceNow Administrator, ITIL, COBIT, DORA compliance. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate 1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
Deerfoot Recruitment Solutions Limited
City, London
Senior ServiceNow Engineer - GRC/IRM (TPRM, OpsRes & BCM) London (Hybrid - 3 days onsite per week) Banking - Up to £120,000 + Bonus + Benefits This is a brand-new, strategically created Vice President position - not a backfill - giving you the chance to shape a global GRC product suite from the ground up. Do you want to own the product roadmap for TPRM, OpsRes and BCM at a major financial services organisation, with the mandate to take these capabilities from a single-region platform to a genuinely global offering across EMEA, APAC and the US? If you're a ServiceNow professional who can move fluently between the boardroom and the sprint room, this could be the role you've been waiting for. You'll join as the product-level owner for TPRM, OpsRes and BCM, engaging senior stakeholders up to MD and Board level, and translating what the business needs into clear technical stories for the development team to build. This is a highly mature ServiceNow environment, built on the Common Services Data Model (CSDM) and moving toward fully out-of-the-box, AI-enabled versions of these products within the next 3-6 months. This is a rare opportunity to combine strong technical credibility with real influence over strategy, adoption and where the platform goes next. What you'll be doing: Owning the product roadmap for TPRM, OpsRes and BCM, translating business requirements into clear, technical user stories for the development team to deliver Acting as the go-to voice for the GRC suite, engaging senior stakeholders - up to MD and Board level - to understand where the business is heading and guide it toward the ServiceNow way of working Building the case for, and supporting delivery of, a global rollout as EMEA, APAC and the US converge onto a single platform Providing technical governance and change approval, and overseeing testing and preparation for platform upgrades and releases Producing and maintaining documentation, training materials and process guides, while mentoring junior and off-shore team members Building strong relationships with stakeholders across the region and globally to share best practice and drive continuous improvement What you'll bring: Strong technical grounding in ServiceNow, ideally with hands-on GRC/IRM experience (TPRM, OpsRes and/or BCM), but equally comfortable operating at product/strategy level rather than day-to-day Scripting A track record of engaging senior/executive stakeholders and translating business requirements into technical user stories for development teams Strong understanding of risk management, GRC and ServiceNow best practice, with sharp problem-solving skills Proven experience in a regulated environment (financial services, insurance or critical infrastructure), with the credibility to manage audit and IT security requirements Excellent communication and leadership skills, with a structured, detail-focused approach Desirable: current ServiceNow certifications, familiarity with ITIL/COBIT, and exposure to DORA compliance The package: Up to £120,000 plus bonus and benefits, based in London with hybrid working (3 days in the office per week). If this sounds like the platform-defining role you've been looking for, apply now or get in touch for a confidential conversation about the opportunity. If you've held any of these roles or used these technologies/skills, this role could be a great fit: ServiceNow Engineer, ServiceNow Developer, ServiceNow Consultant, ServiceNow Technical Lead, ServiceNow Product Manager, GRC Engineer, GRC Analyst, GRC Product Owner, IRM Engineer, IRM Consultant, Integrated Risk Management Engineer, Operational Resilience (OpsRes) Specialist, Business Continuity Management (BCM) Specialist, Third-Party Risk Management (TPRM) Consultant, Risk & Compliance Technology Engineer, ServiceNow Platform Engineer, ServiceNow Administrator, ITIL, COBIT, DORA compliance. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate £1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
24/07/2026
Full time
Senior ServiceNow Engineer - GRC/IRM (TPRM, OpsRes & BCM) London (Hybrid - 3 days onsite per week) Banking - Up to £120,000 + Bonus + Benefits This is a brand-new, strategically created Vice President position - not a backfill - giving you the chance to shape a global GRC product suite from the ground up. Do you want to own the product roadmap for TPRM, OpsRes and BCM at a major financial services organisation, with the mandate to take these capabilities from a single-region platform to a genuinely global offering across EMEA, APAC and the US? If you're a ServiceNow professional who can move fluently between the boardroom and the sprint room, this could be the role you've been waiting for. You'll join as the product-level owner for TPRM, OpsRes and BCM, engaging senior stakeholders up to MD and Board level, and translating what the business needs into clear technical stories for the development team to build. This is a highly mature ServiceNow environment, built on the Common Services Data Model (CSDM) and moving toward fully out-of-the-box, AI-enabled versions of these products within the next 3-6 months. This is a rare opportunity to combine strong technical credibility with real influence over strategy, adoption and where the platform goes next. What you'll be doing: Owning the product roadmap for TPRM, OpsRes and BCM, translating business requirements into clear, technical user stories for the development team to deliver Acting as the go-to voice for the GRC suite, engaging senior stakeholders - up to MD and Board level - to understand where the business is heading and guide it toward the ServiceNow way of working Building the case for, and supporting delivery of, a global rollout as EMEA, APAC and the US converge onto a single platform Providing technical governance and change approval, and overseeing testing and preparation for platform upgrades and releases Producing and maintaining documentation, training materials and process guides, while mentoring junior and off-shore team members Building strong relationships with stakeholders across the region and globally to share best practice and drive continuous improvement What you'll bring: Strong technical grounding in ServiceNow, ideally with hands-on GRC/IRM experience (TPRM, OpsRes and/or BCM), but equally comfortable operating at product/strategy level rather than day-to-day Scripting A track record of engaging senior/executive stakeholders and translating business requirements into technical user stories for development teams Strong understanding of risk management, GRC and ServiceNow best practice, with sharp problem-solving skills Proven experience in a regulated environment (financial services, insurance or critical infrastructure), with the credibility to manage audit and IT security requirements Excellent communication and leadership skills, with a structured, detail-focused approach Desirable: current ServiceNow certifications, familiarity with ITIL/COBIT, and exposure to DORA compliance The package: Up to £120,000 plus bonus and benefits, based in London with hybrid working (3 days in the office per week). If this sounds like the platform-defining role you've been looking for, apply now or get in touch for a confidential conversation about the opportunity. If you've held any of these roles or used these technologies/skills, this role could be a great fit: ServiceNow Engineer, ServiceNow Developer, ServiceNow Consultant, ServiceNow Technical Lead, ServiceNow Product Manager, GRC Engineer, GRC Analyst, GRC Product Owner, IRM Engineer, IRM Consultant, Integrated Risk Management Engineer, Operational Resilience (OpsRes) Specialist, Business Continuity Management (BCM) Specialist, Third-Party Risk Management (TPRM) Consultant, Risk & Compliance Technology Engineer, ServiceNow Platform Engineer, ServiceNow Administrator, ITIL, COBIT, DORA compliance. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate £1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
The Role As an Information Security Analyst II at you will work across the full breadth of the information security function, spanning Governance, Risk and Compliance (GRC), AI Governance, Application Security (AppSec), Technology Risk, and Data Governance. This is a role for someone who has built solid foundational expertise and is ready to take independent ownership of security initiatives across multiple domains. Security at Checkout operates at scale and at pace. We are a global payments business, regulated across multiple jurisdictions, building infrastructure that processes billions of transactions. Our security function needs analysts who can think across domains, communicate with engineers and executives alike, and contribute to a security programme that is genuinely embedded in how the business operates. At L3 you will manage security programmes, lead assessments, drive policy improvements, and mentor junior colleagues. Your primary focus is independent execution with growing influence. You know your domains well enough to spot gaps, propose solutions, and take them through to completion. Governance, Risk and Compliance Support workstreams within Checkout's GRC programme, including ISO 27001, SOC 2, and relevant regulatory obligations across our global licensed entities. Coordinate control evidence collection activities across internal teams, ensuring continuous audit readiness rather than point in time preparation. Maintain and improve GRC documentation including policies, standards, procedures, and control matrices, ensuring they stay current and proportionate to Checkout's evolving risk profile. Monitor the risk register, track remediation activity against agreed timelines, and elevate issues where commitments are at risk. Conduct third party risk assessments, evaluating supplier security controls and compliance posture in line with Checkout's TPRM framework. Track regulatory change across Checkout's operating markets including DORA, FCA/PRA requirements, and payment scheme obligations, flagging gaps and supporting impact assessments. AI Governance Support the development and operationalisation of Checkout's AI governance framework, aligned to ISO 42001, the EU AI Act, and NIST AI RMF. Conduct AI risk assessments for internal AI and ML systems and third party AI tools, evaluating bias, transparency, data lineage, and control adequacy. Maintain an inventory of AI use cases and associated risk classifications, working with product and engineering teams to embed governance requirements at the point of design. Monitor the evolving regulatory landscape for AI in financial services and contribute to policy and control development that keeps Checkout ahead of emerging obligations. Support Checkout's AI Security programme including threat modelling for agentic and LLM based systems, and controls mapping against the OWASP LLM Top 10 and related frameworks. Technology Risk Conduct technology risk assessments across infrastructure, cloud environments, and third party systems, producing clear outputs with actionable treatment recommendations. Support third party risk management activities, evaluating supplier security controls and compliance posture in line with Checkout's vendor risk framework. Contribute to control assurance activities including vulnerability scanning coordination, firewall and configuration reviews, and access control assessments. Monitor Checkout's technology risk landscape, identifying emerging threats and translating them into actionable risk items for the register and leadership reporting. Support DORA related ICT risk management obligations, contributing to resilience testing coordination and critical third party risk assessments. Data Governance Support Checkout's data governance programme, including data classification, data flow mapping, and enforcement of data handling standards across the business. Contribute to data loss prevention (DLP) controls and tooling, working with engineering and product teams to ensure sensitive data is protected throughout its lifecycle. Assist in maintaining records of processing activities (RoPA) and supporting data protection impact assessments (DPIAs) for new systems and processing activities. Work with the privacy and legal functions to ensure data governance controls meet GDPR, UK GDPR, and applicable regional data protection requirements. Promote data governance awareness and good data handling practices across the business, contributing to training and guidance materials for non technical teams. Cross domain Collaboration and Mentoring Work closely with Engineering, Product, Legal, Procurement, Finance, and Compliance teams to embed security requirements into processes, systems, and projects across all five domains. Respond to security due diligence requests from merchants, partners, and regulators, drawing on multi domain expertise to provide accurate and comprehensive responses. Provide guidance and day to day support to junior analysts (L1 and L2), contributing to their development through knowledge sharing and review. Contribute to the continuous improvement of Checkout's security processes, identifying inefficiencies and proposing practical solutions including automation where viable. What We're Looking For Experience 2 to 4 years of experience in information security, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Demonstrated working knowledge across more than one of the following domains: GRC, AI governance, AppSec, technology risk, or data governance. Depth in one or two with credible breadth across the others is the target profile. Practical experience with one or more major compliance frameworks: PCI DSS (v4.0.1 preferred), ISO 27001, SOC 2, DORA, NIST CSF, or equivalent. Experience supporting or managing external audits, assessments, or regulatory engagements including evidence collation and assessor liaison. Demonstrated ability to own a workstream independently, from scoping through to delivery, without requiring constant direction. Skills and Approach Strong analytical and process oriented mindset. You look for root causes and systemic fixes, not just point in time remediation. Clear written and verbal communication. You can translate security concepts for technical teams and business stakeholders with equal clarity. Comfortable operating with ambiguity across a complex domain landscape. You can prioritise without perfect information. Collaborative and pragmatic. You understand that security must work with the business and that influence matters as much as expertise. Methodical and well organised, with a track record of delivering on commitments across concurrent workstreams. Preferred Relevant certification in one or more domains: CISA, CISM, CISSP, PCIP, ISO 27001 Lead Implementer or Auditor, Certified AppSec Practitioner (CAP), or equivalent. Familiarity with cloud environments (AWS, Azure, GCP) from a security or compliance perspective. Exposure to AI and ML systems from a risk, governance, or security perspective. Experience with security or GRC tooling such as Wiz, Qualys, Microsoft Sentinel, ServiceNow GRC, or similar. Understanding of agentic AI and LLM security risks including OWASP LLM Top 10, prompt injection, and data exfiltration vectors. Hybrid Working Model All of our offices globally are onsite three times per week (Tuesday, Wednesday, and Thursday). We work collaboratively in the same space while also being able to partner with colleagues globally. During your days at the office, we offer great snacks, breakfast, and lunch options in all of our locations. We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.
24/07/2026
Full time
The Role As an Information Security Analyst II at you will work across the full breadth of the information security function, spanning Governance, Risk and Compliance (GRC), AI Governance, Application Security (AppSec), Technology Risk, and Data Governance. This is a role for someone who has built solid foundational expertise and is ready to take independent ownership of security initiatives across multiple domains. Security at Checkout operates at scale and at pace. We are a global payments business, regulated across multiple jurisdictions, building infrastructure that processes billions of transactions. Our security function needs analysts who can think across domains, communicate with engineers and executives alike, and contribute to a security programme that is genuinely embedded in how the business operates. At L3 you will manage security programmes, lead assessments, drive policy improvements, and mentor junior colleagues. Your primary focus is independent execution with growing influence. You know your domains well enough to spot gaps, propose solutions, and take them through to completion. Governance, Risk and Compliance Support workstreams within Checkout's GRC programme, including ISO 27001, SOC 2, and relevant regulatory obligations across our global licensed entities. Coordinate control evidence collection activities across internal teams, ensuring continuous audit readiness rather than point in time preparation. Maintain and improve GRC documentation including policies, standards, procedures, and control matrices, ensuring they stay current and proportionate to Checkout's evolving risk profile. Monitor the risk register, track remediation activity against agreed timelines, and elevate issues where commitments are at risk. Conduct third party risk assessments, evaluating supplier security controls and compliance posture in line with Checkout's TPRM framework. Track regulatory change across Checkout's operating markets including DORA, FCA/PRA requirements, and payment scheme obligations, flagging gaps and supporting impact assessments. AI Governance Support the development and operationalisation of Checkout's AI governance framework, aligned to ISO 42001, the EU AI Act, and NIST AI RMF. Conduct AI risk assessments for internal AI and ML systems and third party AI tools, evaluating bias, transparency, data lineage, and control adequacy. Maintain an inventory of AI use cases and associated risk classifications, working with product and engineering teams to embed governance requirements at the point of design. Monitor the evolving regulatory landscape for AI in financial services and contribute to policy and control development that keeps Checkout ahead of emerging obligations. Support Checkout's AI Security programme including threat modelling for agentic and LLM based systems, and controls mapping against the OWASP LLM Top 10 and related frameworks. Technology Risk Conduct technology risk assessments across infrastructure, cloud environments, and third party systems, producing clear outputs with actionable treatment recommendations. Support third party risk management activities, evaluating supplier security controls and compliance posture in line with Checkout's vendor risk framework. Contribute to control assurance activities including vulnerability scanning coordination, firewall and configuration reviews, and access control assessments. Monitor Checkout's technology risk landscape, identifying emerging threats and translating them into actionable risk items for the register and leadership reporting. Support DORA related ICT risk management obligations, contributing to resilience testing coordination and critical third party risk assessments. Data Governance Support Checkout's data governance programme, including data classification, data flow mapping, and enforcement of data handling standards across the business. Contribute to data loss prevention (DLP) controls and tooling, working with engineering and product teams to ensure sensitive data is protected throughout its lifecycle. Assist in maintaining records of processing activities (RoPA) and supporting data protection impact assessments (DPIAs) for new systems and processing activities. Work with the privacy and legal functions to ensure data governance controls meet GDPR, UK GDPR, and applicable regional data protection requirements. Promote data governance awareness and good data handling practices across the business, contributing to training and guidance materials for non technical teams. Cross domain Collaboration and Mentoring Work closely with Engineering, Product, Legal, Procurement, Finance, and Compliance teams to embed security requirements into processes, systems, and projects across all five domains. Respond to security due diligence requests from merchants, partners, and regulators, drawing on multi domain expertise to provide accurate and comprehensive responses. Provide guidance and day to day support to junior analysts (L1 and L2), contributing to their development through knowledge sharing and review. Contribute to the continuous improvement of Checkout's security processes, identifying inefficiencies and proposing practical solutions including automation where viable. What We're Looking For Experience 2 to 4 years of experience in information security, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Demonstrated working knowledge across more than one of the following domains: GRC, AI governance, AppSec, technology risk, or data governance. Depth in one or two with credible breadth across the others is the target profile. Practical experience with one or more major compliance frameworks: PCI DSS (v4.0.1 preferred), ISO 27001, SOC 2, DORA, NIST CSF, or equivalent. Experience supporting or managing external audits, assessments, or regulatory engagements including evidence collation and assessor liaison. Demonstrated ability to own a workstream independently, from scoping through to delivery, without requiring constant direction. Skills and Approach Strong analytical and process oriented mindset. You look for root causes and systemic fixes, not just point in time remediation. Clear written and verbal communication. You can translate security concepts for technical teams and business stakeholders with equal clarity. Comfortable operating with ambiguity across a complex domain landscape. You can prioritise without perfect information. Collaborative and pragmatic. You understand that security must work with the business and that influence matters as much as expertise. Methodical and well organised, with a track record of delivering on commitments across concurrent workstreams. Preferred Relevant certification in one or more domains: CISA, CISM, CISSP, PCIP, ISO 27001 Lead Implementer or Auditor, Certified AppSec Practitioner (CAP), or equivalent. Familiarity with cloud environments (AWS, Azure, GCP) from a security or compliance perspective. Exposure to AI and ML systems from a risk, governance, or security perspective. Experience with security or GRC tooling such as Wiz, Qualys, Microsoft Sentinel, ServiceNow GRC, or similar. Understanding of agentic AI and LLM security risks including OWASP LLM Top 10, prompt injection, and data exfiltration vectors. Hybrid Working Model All of our offices globally are onsite three times per week (Tuesday, Wednesday, and Thursday). We work collaboratively in the same space while also being able to partner with colleagues globally. During your days at the office, we offer great snacks, breakfast, and lunch options in all of our locations. We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.
Goldman Sachs Group, Inc.
Birmingham, Staffordshire
OUR IMPACT Corporate Planning & Management (CPM) unifies Finance & Planning, Global Procurement, Product & Reporting, CPM Engineering and CPM Management teams to deliver business planning and analytics, expense management, third party risk management, sustainability strategy for our operations and supply chain, and governance strategies across the firm. Global Procurement enables the firm to work strategically with third parties, ensuring strong commercial and compliance controls while promoting sustainability. It drives value, encourages innovation, and reduces risks throughout the supply chain for services and non compensation spending. Key teams include Strategic Sourcing, which works with business units to source and contract third party products and services, optimize value, and digitize commercial commitments. They monitor the firm's main relationships to support ongoing improvement and consistent value delivery. Third Party Risk Management (TPRM) identifies, assesses, manages, and monitors third party risks for all relationships, including vendors and contingent workers, helping to prevent issues like cybersecurity threats and operational disruptions. Procure to Pay (P2P) oversees the payment process, from vendor onboarding and invoice handling to travel expense processing and compliance, ensuring efficiency. The Travel team manages travel services and policy for cost effectiveness and compliance. Sustainable Operations lead emission reduction strategies and ESG risk management in the supply chain, supporting environmental and social goals. Product & Reporting manages product lifecycle and reporting for vendor supplied and internal solutions. The Product team maintains technology platforms like FP&A systems, Spend Management, and Third Party Risk Management tools, focusing on user experience and digital workflows for vendor management and compliance. The Reporting team creates reports, dashboards, and analytics to show spending patterns, risk metrics, and performance, helping stakeholders monitor KPIs, find cost savings, and make informed decisions while ensuring data accuracy and compliance. Finance & Planning manages planning and reporting to support the firm's strategic goals, integrating revenue, expense, liquidity, and capital planning in collaboration with Controllers, Treasury, and Risk. This pillar includes divisional CFOs who advise on financial opportunities and manage zero based budgeting. Product Finance oversees governance and accounting for non compensation expenses, ensuring efficient use and transparency for senior leadership. Corporate Insurance & Advisory manages insurance needs, connects risk to insurance solutions, and provides advisory support for firm activities and claims. CPM Engineering develops solutions for managing third party spend, data, automation, budgeting, forecasting, and expense allocation to support decision making aligned with strategic objectives. CPM Management includes senior leaders and teams that give strategic oversight and operational support across The Core. This pillar covers the Chief of Staff function and Communications and User Engagement team, which manage change initiatives and people strategies for CPM. It also leads operational risk programs, ensures compliance with risk and resilience policies, and manages CPM specific risks with proper controls. YOUR IMPACT This role sits within Product & Reporting. The Product & Reporting team is a global team who enable Goldman Sachs to manage our vendor contracts and third party risk actively and effectively, deliver supply chain effectiveness, travel & expense processing & enable Source to Pay activity through the platforms we maintain within our architecture. Through excellent functional, project, program, and change management skills, along with a bias for becoming the subject matter or technical expert and driving our strategic architectural vision, this team seeks to fulfil the vision of our clients and partners with employees across platforms like Ariba, S4, Concur, KY3P & Fieldglass. The Product & Reporting Team work closely with senior leadership, process owners, CPM Engineering and our vendors to drive supply chain value and achieve Corporate Planning & Management's objectives & key results. This role, positioned within the EMEA Product Team, will support the delivery of our Customer Journey through our ProcurementHub Process Orchestration Platform (Powered by ORO Labs). The role requires regular collaboration with various functions across the firm, independent work capability, and interaction with senior professionals. The ideal candidate will be a skilled Product Owner experienced across Procurement Platforms and Processes. This role requires a blend of analytical skills, business process expertise, product design capabilities, and low code/no code system configuration & testing experience to ensure the seamless implementation of the ProcurementHub platform. JOB RESPONSIBILITIES Work with business stakeholders to gather and document requirements for ProcurementHub and convert them into detailed user stories. Partner with Strategic Sourcing and Third-Party Risk Management (TPRM) teams to automate manual policies into user friendly processes. Architect and configure end to end procurement orchestration workflows using ORO Labs AI to automate complex intake, risk, and compliance processes. Identify opportunities to improve the procurement experience through automation and AI capabilities. Lead workshops, meetings, and demonstrations to align stakeholders, collect feedback and deliver user training. Define testing strategies and lead User Acceptance Testing (UAT) to ensure new features meet business objectives and GS security standards. Monitor platform adoption and usage metrics to identify friction points in the procurement journey. Leverage data driven insights to propose iterative improvements to the user experience. Communicate product updates, release notes, and roadmap progress to senior leadership and cross divisional partners. Assist with post go live validations and ensure smooth, defect free production rollouts. QUALIFICATIONS Bachelor's degree in Business Administration, Computer Science, Information Systems, or related field, or equivalent experience. Over 5 years' experience as a Business Analyst or Product Lead, preferably with understanding of the "Intake-to-Pay" lifecycle, including supplier onboarding, risk tiering, and contract management. Ability to build complex logic and workflows in orchestration platforms (e.g., ORO Labs, ServiceNow, or similar BPM tools) preferred. Understanding of Large Language Model (LLM) capabilities and the ability to write structured, effective instructions/prompts for AI agents to execute business tasks. Familiarity with data structures and the ability to map fields between disparate systems is preferred. Familiarity with Ariba Invoicing, Ariba SLP, S4 HANA, or similar Invoice to Pay and Vendor Management applications is preferred. Experience participating in at least one medium-to-large-scale platform deployment project within Professional Services. Understanding of Agile change management and platforms such as JIRA and Confluence or comparable tools. Excellent analytical skills, with a preference for using data to guide decisions and direction. Outstanding communication skills and ability to work effectively with cross functional teams and present to senior leadership. Ability to collaborate across hierarchies and regions, with a flexible working style. Comfort working in a fast paced, evolving environment where requirements may shift based on regulatory or strategic changes. Experience in the Financial Services industry is advantageous, though not required. Proactive, enthusiastic, and team oriented attitude. We're committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veteran status, disability, or any other characteristic protected by applicable law.
13/07/2026
Full time
OUR IMPACT Corporate Planning & Management (CPM) unifies Finance & Planning, Global Procurement, Product & Reporting, CPM Engineering and CPM Management teams to deliver business planning and analytics, expense management, third party risk management, sustainability strategy for our operations and supply chain, and governance strategies across the firm. Global Procurement enables the firm to work strategically with third parties, ensuring strong commercial and compliance controls while promoting sustainability. It drives value, encourages innovation, and reduces risks throughout the supply chain for services and non compensation spending. Key teams include Strategic Sourcing, which works with business units to source and contract third party products and services, optimize value, and digitize commercial commitments. They monitor the firm's main relationships to support ongoing improvement and consistent value delivery. Third Party Risk Management (TPRM) identifies, assesses, manages, and monitors third party risks for all relationships, including vendors and contingent workers, helping to prevent issues like cybersecurity threats and operational disruptions. Procure to Pay (P2P) oversees the payment process, from vendor onboarding and invoice handling to travel expense processing and compliance, ensuring efficiency. The Travel team manages travel services and policy for cost effectiveness and compliance. Sustainable Operations lead emission reduction strategies and ESG risk management in the supply chain, supporting environmental and social goals. Product & Reporting manages product lifecycle and reporting for vendor supplied and internal solutions. The Product team maintains technology platforms like FP&A systems, Spend Management, and Third Party Risk Management tools, focusing on user experience and digital workflows for vendor management and compliance. The Reporting team creates reports, dashboards, and analytics to show spending patterns, risk metrics, and performance, helping stakeholders monitor KPIs, find cost savings, and make informed decisions while ensuring data accuracy and compliance. Finance & Planning manages planning and reporting to support the firm's strategic goals, integrating revenue, expense, liquidity, and capital planning in collaboration with Controllers, Treasury, and Risk. This pillar includes divisional CFOs who advise on financial opportunities and manage zero based budgeting. Product Finance oversees governance and accounting for non compensation expenses, ensuring efficient use and transparency for senior leadership. Corporate Insurance & Advisory manages insurance needs, connects risk to insurance solutions, and provides advisory support for firm activities and claims. CPM Engineering develops solutions for managing third party spend, data, automation, budgeting, forecasting, and expense allocation to support decision making aligned with strategic objectives. CPM Management includes senior leaders and teams that give strategic oversight and operational support across The Core. This pillar covers the Chief of Staff function and Communications and User Engagement team, which manage change initiatives and people strategies for CPM. It also leads operational risk programs, ensures compliance with risk and resilience policies, and manages CPM specific risks with proper controls. YOUR IMPACT This role sits within Product & Reporting. The Product & Reporting team is a global team who enable Goldman Sachs to manage our vendor contracts and third party risk actively and effectively, deliver supply chain effectiveness, travel & expense processing & enable Source to Pay activity through the platforms we maintain within our architecture. Through excellent functional, project, program, and change management skills, along with a bias for becoming the subject matter or technical expert and driving our strategic architectural vision, this team seeks to fulfil the vision of our clients and partners with employees across platforms like Ariba, S4, Concur, KY3P & Fieldglass. The Product & Reporting Team work closely with senior leadership, process owners, CPM Engineering and our vendors to drive supply chain value and achieve Corporate Planning & Management's objectives & key results. This role, positioned within the EMEA Product Team, will support the delivery of our Customer Journey through our ProcurementHub Process Orchestration Platform (Powered by ORO Labs). The role requires regular collaboration with various functions across the firm, independent work capability, and interaction with senior professionals. The ideal candidate will be a skilled Product Owner experienced across Procurement Platforms and Processes. This role requires a blend of analytical skills, business process expertise, product design capabilities, and low code/no code system configuration & testing experience to ensure the seamless implementation of the ProcurementHub platform. JOB RESPONSIBILITIES Work with business stakeholders to gather and document requirements for ProcurementHub and convert them into detailed user stories. Partner with Strategic Sourcing and Third-Party Risk Management (TPRM) teams to automate manual policies into user friendly processes. Architect and configure end to end procurement orchestration workflows using ORO Labs AI to automate complex intake, risk, and compliance processes. Identify opportunities to improve the procurement experience through automation and AI capabilities. Lead workshops, meetings, and demonstrations to align stakeholders, collect feedback and deliver user training. Define testing strategies and lead User Acceptance Testing (UAT) to ensure new features meet business objectives and GS security standards. Monitor platform adoption and usage metrics to identify friction points in the procurement journey. Leverage data driven insights to propose iterative improvements to the user experience. Communicate product updates, release notes, and roadmap progress to senior leadership and cross divisional partners. Assist with post go live validations and ensure smooth, defect free production rollouts. QUALIFICATIONS Bachelor's degree in Business Administration, Computer Science, Information Systems, or related field, or equivalent experience. Over 5 years' experience as a Business Analyst or Product Lead, preferably with understanding of the "Intake-to-Pay" lifecycle, including supplier onboarding, risk tiering, and contract management. Ability to build complex logic and workflows in orchestration platforms (e.g., ORO Labs, ServiceNow, or similar BPM tools) preferred. Understanding of Large Language Model (LLM) capabilities and the ability to write structured, effective instructions/prompts for AI agents to execute business tasks. Familiarity with data structures and the ability to map fields between disparate systems is preferred. Familiarity with Ariba Invoicing, Ariba SLP, S4 HANA, or similar Invoice to Pay and Vendor Management applications is preferred. Experience participating in at least one medium-to-large-scale platform deployment project within Professional Services. Understanding of Agile change management and platforms such as JIRA and Confluence or comparable tools. Excellent analytical skills, with a preference for using data to guide decisions and direction. Outstanding communication skills and ability to work effectively with cross functional teams and present to senior leadership. Ability to collaborate across hierarchies and regions, with a flexible working style. Comfort working in a fast paced, evolving environment where requirements may shift based on regulatory or strategic changes. Experience in the Financial Services industry is advantageous, though not required. Proactive, enthusiastic, and team oriented attitude. We're committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veteran status, disability, or any other characteristic protected by applicable law.
Company Description We're You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we're behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there's a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you've come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we're shaping the future of fintech - and we're just getting started. The Role As an Information Security Analyst at you will work across the full breadth of the information security function, spanning Governance, Risk and Compliance (GRC), AI Governance, Application Security (AppSec), Technology Risk, and Data Governance. This is a role for someone who has built a solid foundation in information security and is ready to move from guided execution to genuine ownership of tasks and smaller workstreams. Security at Checkout operates at scale and at pace. We are a global payments business, regulated across multiple jurisdictions, building infrastructure that processes billions of transactions. Our security function needs analysts who understand how different domains fit together, communicate clearly with technical and non-technical colleagues, and take accountability for the quality of their work. At L2 you will implement security controls, respond to security incidents, identify risks, and support compliance activities across multiple domains. You work independently for extended periods and are developing the cross-domain knowledge and stakeholder skills that will prepare you for programme ownership at L3 and beyond. How You'll Make Impact Governance, Risk and Compliance Support workstreams within Checkout's GRC programme, including ISO 27001, SOC 2, PCI DSS, and applicable regulatory obligations across our global licensed entities. Assist with control evidence collection activities, coordinating with internal teams to gather accurate and timely evidence in support of audit readiness. Maintain GRC documentation including policies, standards, procedures, and control matrices under the guidance of senior colleagues. Support monitoring of the risk register, tracking remediation activity against agreed timelines and escalating where commitments are at risk. Assist in conducting third party risk assessments, evaluating supplier security controls in line with Checkout's TPRM framework. Develop working knowledge of regulatory obligations across Checkout's operating markets, including FCA/PRA requirements, payment scheme rules, and DORA. AI Governance Support the operationalisation of Checkout's AI governance framework, aligned to ISO 42001, the EU AI Act, and NIST AI RMF. Assist in conducting AI risk assessments for internal AI and ML systems and third party AI tools, under the guidance of more senior analysts. Help maintain an inventory of AI use cases and associated risk classifications, working with product and engineering teams as directed. Develop awareness of the evolving regulatory landscape for AI in financial services and contribute to policy and control documentation. Contribute to the development and communication of responsible AI usage guidance for staff, helping teams across the business understand acceptable use boundaries, data handling expectations, and the risks associated with AI tools in a regulated environment. Application Security Contribute to Checkout's application security programme, including support for secure code review processes, SDLC integration, and developer security guidance. Support threat modelling activities for new and existing products, identifying security requirements under the guidance of senior colleagues. Assist in managing vulnerability findings from penetration tests, bug bounty programmes, and automated tooling, tracking remediation and validating fixes. Apply knowledge of the OWASP Top 10 and secure development frameworks to practical security reviews and guidance activities. Technology Risk Support technology risk assessments across infrastructure, cloud environments, and third party systems, contributing to outputs with actionable treatment recommendations. Assist with control assurance activities including vulnerability scanning coordination, access control assessments, and firewall and configuration reviews. Develop an understanding of Checkout's technology risk landscape, identifying emerging threats and contributing inputs to the risk register. Support DORA related ICT risk management activities under the direction of senior analysts. Data Governance Support Checkout's data governance programme, including data classification activities, data flow mapping, and enforcement of data handling standards. Assist with data loss prevention (DLP) controls and tooling, contributing to activities that ensure sensitive data is protected throughout its lifecycle. Help maintain records of processing activities (RoPA) and support data protection impact assessments (DPIAs) for new systems. Develop working knowledge of GDPR, UK GDPR, and applicable regional data protection requirements as they affect Checkout's operations. Cross domain Collaboration Work with Engineering, Product, Legal, Procurement, Finance, and Compliance teams to support the embedding of security requirements into processes, systems, and projects. Respond to security due diligence requests from merchants, partners, and regulators with accuracy and within agreed SLAs, escalating complex queries appropriately. Communicate clearly with internal stakeholders on security requirements, keeping teams updated on changes and project progress. Contribute to security awareness initiatives, promoting a security conscious culture across Checkout. What We're Looking for Experience 1 to 2 years of experience in information security, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Working knowledge of at least one of the following domains: GRC, AppSec, technology risk, or data governance. Practical familiarity with at least one compliance framework: PCI DSS, ISO 27001, SOC 2, NIST CSF, or equivalent. Some exposure to external audits, risk assessments, or security assurance activities. Ability to manage tasks independently and deliver on commitments reliably. Skills and Approach Clear written and verbal communication. You can translate security concepts for technical and non technical audiences. Detail oriented and methodical. You approach your work carefully and follow through consistently. Curious and proactive. You ask questions, flag issues early, and look for root causes rather than surface fixes. Collaborative and adaptable. You work effectively across teams and adjust your approach as priorities shift. Receptive to feedback and committed to developing your information security skills across multiple domains. Preferred Pursuing or holding a relevant certification: CompTIA Security+, CISA (in progress), ISO 27001 Foundation, or equivalent. Familiarity with cloud environments (AWS, Azure, GCP) from a security or compliance perspective. Exposure to security or GRC tooling such as Wiz, Qualys, Microsoft Sentinel, ServiceNow GRC, or similar. Awareness of AI governance frameworks or the OWASP LLM Top 10. Some scripting or automation experience (Python, etc.) is a plus.
10/07/2026
Full time
Company Description We're You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we're behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there's a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you've come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we're shaping the future of fintech - and we're just getting started. The Role As an Information Security Analyst at you will work across the full breadth of the information security function, spanning Governance, Risk and Compliance (GRC), AI Governance, Application Security (AppSec), Technology Risk, and Data Governance. This is a role for someone who has built a solid foundation in information security and is ready to move from guided execution to genuine ownership of tasks and smaller workstreams. Security at Checkout operates at scale and at pace. We are a global payments business, regulated across multiple jurisdictions, building infrastructure that processes billions of transactions. Our security function needs analysts who understand how different domains fit together, communicate clearly with technical and non-technical colleagues, and take accountability for the quality of their work. At L2 you will implement security controls, respond to security incidents, identify risks, and support compliance activities across multiple domains. You work independently for extended periods and are developing the cross-domain knowledge and stakeholder skills that will prepare you for programme ownership at L3 and beyond. How You'll Make Impact Governance, Risk and Compliance Support workstreams within Checkout's GRC programme, including ISO 27001, SOC 2, PCI DSS, and applicable regulatory obligations across our global licensed entities. Assist with control evidence collection activities, coordinating with internal teams to gather accurate and timely evidence in support of audit readiness. Maintain GRC documentation including policies, standards, procedures, and control matrices under the guidance of senior colleagues. Support monitoring of the risk register, tracking remediation activity against agreed timelines and escalating where commitments are at risk. Assist in conducting third party risk assessments, evaluating supplier security controls in line with Checkout's TPRM framework. Develop working knowledge of regulatory obligations across Checkout's operating markets, including FCA/PRA requirements, payment scheme rules, and DORA. AI Governance Support the operationalisation of Checkout's AI governance framework, aligned to ISO 42001, the EU AI Act, and NIST AI RMF. Assist in conducting AI risk assessments for internal AI and ML systems and third party AI tools, under the guidance of more senior analysts. Help maintain an inventory of AI use cases and associated risk classifications, working with product and engineering teams as directed. Develop awareness of the evolving regulatory landscape for AI in financial services and contribute to policy and control documentation. Contribute to the development and communication of responsible AI usage guidance for staff, helping teams across the business understand acceptable use boundaries, data handling expectations, and the risks associated with AI tools in a regulated environment. Application Security Contribute to Checkout's application security programme, including support for secure code review processes, SDLC integration, and developer security guidance. Support threat modelling activities for new and existing products, identifying security requirements under the guidance of senior colleagues. Assist in managing vulnerability findings from penetration tests, bug bounty programmes, and automated tooling, tracking remediation and validating fixes. Apply knowledge of the OWASP Top 10 and secure development frameworks to practical security reviews and guidance activities. Technology Risk Support technology risk assessments across infrastructure, cloud environments, and third party systems, contributing to outputs with actionable treatment recommendations. Assist with control assurance activities including vulnerability scanning coordination, access control assessments, and firewall and configuration reviews. Develop an understanding of Checkout's technology risk landscape, identifying emerging threats and contributing inputs to the risk register. Support DORA related ICT risk management activities under the direction of senior analysts. Data Governance Support Checkout's data governance programme, including data classification activities, data flow mapping, and enforcement of data handling standards. Assist with data loss prevention (DLP) controls and tooling, contributing to activities that ensure sensitive data is protected throughout its lifecycle. Help maintain records of processing activities (RoPA) and support data protection impact assessments (DPIAs) for new systems. Develop working knowledge of GDPR, UK GDPR, and applicable regional data protection requirements as they affect Checkout's operations. Cross domain Collaboration Work with Engineering, Product, Legal, Procurement, Finance, and Compliance teams to support the embedding of security requirements into processes, systems, and projects. Respond to security due diligence requests from merchants, partners, and regulators with accuracy and within agreed SLAs, escalating complex queries appropriately. Communicate clearly with internal stakeholders on security requirements, keeping teams updated on changes and project progress. Contribute to security awareness initiatives, promoting a security conscious culture across Checkout. What We're Looking for Experience 1 to 2 years of experience in information security, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Working knowledge of at least one of the following domains: GRC, AppSec, technology risk, or data governance. Practical familiarity with at least one compliance framework: PCI DSS, ISO 27001, SOC 2, NIST CSF, or equivalent. Some exposure to external audits, risk assessments, or security assurance activities. Ability to manage tasks independently and deliver on commitments reliably. Skills and Approach Clear written and verbal communication. You can translate security concepts for technical and non technical audiences. Detail oriented and methodical. You approach your work carefully and follow through consistently. Curious and proactive. You ask questions, flag issues early, and look for root causes rather than surface fixes. Collaborative and adaptable. You work effectively across teams and adjust your approach as priorities shift. Receptive to feedback and committed to developing your information security skills across multiple domains. Preferred Pursuing or holding a relevant certification: CompTIA Security+, CISA (in progress), ISO 27001 Foundation, or equivalent. Familiarity with cloud environments (AWS, Azure, GCP) from a security or compliance perspective. Exposure to security or GRC tooling such as Wiz, Qualys, Microsoft Sentinel, ServiceNow GRC, or similar. Awareness of AI governance frameworks or the OWASP LLM Top 10. Some scripting or automation experience (Python, etc.) is a plus.
Position: Security Risk Analyst Location: Remote Rate: Outside IR35 - 450 a day Role We are seeking an experienced Security Risk Analyst to support the delivery of a large-scale Third-Party Risk Management (TPRM) programme. The successful candidate will be responsible for conducting security risk assessments for up to 570 third-party vendors, ensuring supplier security risks are identified, assessed, documented, and managed in accordance with organisational policies and industry best practice. INDIT Planet Recruitment is acting as an Employment Business in relation to this vacancy.
09/07/2026
Contractor
Position: Security Risk Analyst Location: Remote Rate: Outside IR35 - 450 a day Role We are seeking an experienced Security Risk Analyst to support the delivery of a large-scale Third-Party Risk Management (TPRM) programme. The successful candidate will be responsible for conducting security risk assessments for up to 570 third-party vendors, ensuring supplier security risks are identified, assessed, documented, and managed in accordance with organisational policies and industry best practice. INDIT Planet Recruitment is acting as an Employment Business in relation to this vacancy.