it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

5 jobs found

Email me jobs like this
Refine Search
Current Search
security auditor risk assessor
Technical Operations Manager
De Fontenay LTD
We're looking for someone to take ownership of the operational backbone behind our development and support teams. Not a coder. Not a CTO. Someone who makes the machinery run - the people, the processes, the infrastructure, the compliance - so our talented developers can focus on what they do best: building brilliant work for our clients. This is a new role for Laser Red, and it's a big one. You'll sit in our Management Team, line manage our development and support teams, and be directly responsible for how our technical function operates day to day. If you're the kind of person who bridges the gap between technical teams and the wider business - someone who's equally comfortable in a 1:1 with a developer and a strategy meeting with directors - we want to hear from you. Full time, permanent position (35 hours a week) Location Hybrid - work from our Lincoln or Grimsby offices, or from home. (Must be a UK resident with a valid driving licence) Why This Role Exists As Laser Red has grown, our Lead Developers have taken on more and more management responsibility alongside their technical work. It's meant less time coding, less time mentoring, and less time doing the things they're genuinely brilliant at. This role fixes that. You'll take on the people management, operational oversight, and cross department coordination so our technical leads can get back to leading technically - setting standards, reviewing code, mentoring the team, and building great solutions. You don't need to be a web developer. You need to be a strong manager with a technical operations background who can earn the trust of a skilled team, bring structure without bureaucracy, and make things run better. What You'll Be Responsible For People management and team development. You'll line manage our development team of around 10 people (including our Lead Backend and Lead Frontend Developers) plus our Support Manager and their team. That means regular 1:1s, performance reviews, career development conversations, recruitment, onboarding, and being the person who handles the day to day people stuff - workload concerns, conflict resolution, wellbeing. You'll be their voice in the Management Team. Capacity planning and resource allocation. Making sure the right people are working on the right things at the right time. You'll own our internal scheduling and capacity tools, coordinate with Project Managers on project handovers, and keep an eye on utilisation - flagging burnout risks or gaps before they become problems. Infrastructure and hosting. We manage hosting across multiple providers for 150+ client websites. You'll own the hosting estate - performance, uptime, cost optimisation - and drive migration projects as we improve our infrastructure. You'll work alongside our senior developers on technical architecture decisions; they own the direction, you own the operations and execution. Security, compliance and governance. Cyber Essentials certification, GDPR compliance, accessibility standards, AI usage policy governance, and regular security reviews. You'll own the compliance posture for the business and liaise with external assessors and auditors as needed. R&D, innovation and continuous improvement. This is where it gets interesting. We want someone who's naturally curious about better ways of working - someone who'll research new tools, trial AI applications, evaluate emerging technologies, and then actually implement them across the team. Not just ideas, but execution. Training, rollout, adoption. You'll champion our innovation time and make sure it delivers real value back to the business. Tooling, systems and technical debt. We have internal tools for estimation, scheduling, and time tracking that need day to day management and adoption. You'll also own the technical debt backlog - the housekeeping that keeps our infrastructure clean and our projects maintainable. Documentation standards, staging site hygiene, repository management, backup cleanup. Reporting and data. Build and maintain operational dashboards that give leadership clear visibility on infrastructure costs, team utilisation, hosting profitability, and technical health. Not vanity metrics - useful data that drives decisions. Client facing technical advisory. Where the opportunity arises, you'll support our Account Managers on client conversations that involve digital systems, process improvement, or operational efficiency. Particularly with manufacturing, engineering, and industrial clients, your operational and systems expertise adds genuine commercial value. How This Role Works We want to be transparent about how this fits into the team. Our Lead Developers retain all technical authority. They own code standards, architecture decisions, code review, technical mentoring, and tooling choices. They're the people who decide how things are built and whether the quality is right. You own the operational layer around them. People management, resource planning, processes, infrastructure, compliance, reporting. You decide what gets worked on and when. You make sure the team has what they need. You handle the management overhead so the technical leads don't have to. The relationship works when both sides trust each other. You don't need to evaluate code quality - you need to listen to the people who can, champion their recommendations, and translate technical needs into business decisions. The absolute must haves: Proven experience managing technical teams. - doesn't have to be web or agency. Manufacturing, engineering, IT operations backgrounds are equally valid. What matters is you've managed skilled people and done it well. Strong IT operations and infrastructure knowledge. - server management, hosting, networking fundamentals. You understand the systems side of technology. Compliance experience. - GDPR, Cyber Essentials, ISO, accessibility standards, or equivalent. You've worked within compliance frameworks and ideally led a business through certification. Project management discipline. - you can take something from business case to delivery without losing the thread. You plan, you track, you deliver. Data literacy. - comfortable building reports and dashboards, making sense of operational metrics, and using data to drive decisions rather than gut feel. Genuinely good with people. - you build trust, you handle difficult conversations, you develop people. You can earn the respect of a team who know more about their craft than you do. Process improvement mindset. - Lean, continuous improvement, operational efficiency. You spot waste and fix it without creating bureaucracy. Curious about technology. - you actively research, trial, and implement better ways of working. AI, automation, new tools - you're the person who makes innovation actually happen. Comfortable in a small business. - we're a team of 33. You'll roll your sleeves up. There's no one to delegate everything to. Nice to have (but honestly, we can teach you): Agency, SaaS, or digital environment experience - even tangentially. If you've worked adjacent to web development, that helps. Linux server familiarity - command line, SSH, server administration. CI/CD and deployment pipeline understanding - even conceptually. Knowing what a release process looks like matters. ERP, MES, or scheduling tool experience - production planning, resource management, capacity systems. These skills transfer directly. Budget and CAPEX management - experience managing technology budgets and making the financial case for investment. Client advisory experience - advising businesses on digital transformation, systems implementation, or operational improvement. Manufacturing, engineering, or industrial sector background - our core client base is in these sectors. If you speak their language, that's a genuine advantage. Experience & Qualifications 3+ years managing technical teams in any sector Degree or equivalent experience in a relevant field (IT, business, engineering, operations) Any formal management training or qualifications are a bonus, but real world experience matters more Full UK driving licence What You'll Achieve in Your First 90 Days Month 1 - Meet every member of the dev and support teams. Understand our tools, systems, and how work flows through the business. Build relationships with the team leads and the wider Management Team. Month 2 - Start delivering quick wins: documentation gaps, hosting cost optimisation, process improvements. Take over 1:1s with the dev team. Establish a regular security review cadence. Begin building the operational dashboards leadership needs. Month 3 - Present a 6 month roadmap covering infrastructure, compliance, R&D priorities, and process improvements. Have at least one visible win the team can point to and say "that made my life easier." Establish a working rhythm where the Lead Developers feel empowered and supported. Here's what's in it for you! A seat at the table: You'll be part of the Management Team with direct input into how the business operates and grows. This isn't a middle management role that gets told what to do - you'll shape the direction of the technical function. Real autonomy: We'll give you the scope to make this role your own. We've told you what we need - how you deliver it is up to you. . click apply for full job details
16/07/2026
Full time
We're looking for someone to take ownership of the operational backbone behind our development and support teams. Not a coder. Not a CTO. Someone who makes the machinery run - the people, the processes, the infrastructure, the compliance - so our talented developers can focus on what they do best: building brilliant work for our clients. This is a new role for Laser Red, and it's a big one. You'll sit in our Management Team, line manage our development and support teams, and be directly responsible for how our technical function operates day to day. If you're the kind of person who bridges the gap between technical teams and the wider business - someone who's equally comfortable in a 1:1 with a developer and a strategy meeting with directors - we want to hear from you. Full time, permanent position (35 hours a week) Location Hybrid - work from our Lincoln or Grimsby offices, or from home. (Must be a UK resident with a valid driving licence) Why This Role Exists As Laser Red has grown, our Lead Developers have taken on more and more management responsibility alongside their technical work. It's meant less time coding, less time mentoring, and less time doing the things they're genuinely brilliant at. This role fixes that. You'll take on the people management, operational oversight, and cross department coordination so our technical leads can get back to leading technically - setting standards, reviewing code, mentoring the team, and building great solutions. You don't need to be a web developer. You need to be a strong manager with a technical operations background who can earn the trust of a skilled team, bring structure without bureaucracy, and make things run better. What You'll Be Responsible For People management and team development. You'll line manage our development team of around 10 people (including our Lead Backend and Lead Frontend Developers) plus our Support Manager and their team. That means regular 1:1s, performance reviews, career development conversations, recruitment, onboarding, and being the person who handles the day to day people stuff - workload concerns, conflict resolution, wellbeing. You'll be their voice in the Management Team. Capacity planning and resource allocation. Making sure the right people are working on the right things at the right time. You'll own our internal scheduling and capacity tools, coordinate with Project Managers on project handovers, and keep an eye on utilisation - flagging burnout risks or gaps before they become problems. Infrastructure and hosting. We manage hosting across multiple providers for 150+ client websites. You'll own the hosting estate - performance, uptime, cost optimisation - and drive migration projects as we improve our infrastructure. You'll work alongside our senior developers on technical architecture decisions; they own the direction, you own the operations and execution. Security, compliance and governance. Cyber Essentials certification, GDPR compliance, accessibility standards, AI usage policy governance, and regular security reviews. You'll own the compliance posture for the business and liaise with external assessors and auditors as needed. R&D, innovation and continuous improvement. This is where it gets interesting. We want someone who's naturally curious about better ways of working - someone who'll research new tools, trial AI applications, evaluate emerging technologies, and then actually implement them across the team. Not just ideas, but execution. Training, rollout, adoption. You'll champion our innovation time and make sure it delivers real value back to the business. Tooling, systems and technical debt. We have internal tools for estimation, scheduling, and time tracking that need day to day management and adoption. You'll also own the technical debt backlog - the housekeeping that keeps our infrastructure clean and our projects maintainable. Documentation standards, staging site hygiene, repository management, backup cleanup. Reporting and data. Build and maintain operational dashboards that give leadership clear visibility on infrastructure costs, team utilisation, hosting profitability, and technical health. Not vanity metrics - useful data that drives decisions. Client facing technical advisory. Where the opportunity arises, you'll support our Account Managers on client conversations that involve digital systems, process improvement, or operational efficiency. Particularly with manufacturing, engineering, and industrial clients, your operational and systems expertise adds genuine commercial value. How This Role Works We want to be transparent about how this fits into the team. Our Lead Developers retain all technical authority. They own code standards, architecture decisions, code review, technical mentoring, and tooling choices. They're the people who decide how things are built and whether the quality is right. You own the operational layer around them. People management, resource planning, processes, infrastructure, compliance, reporting. You decide what gets worked on and when. You make sure the team has what they need. You handle the management overhead so the technical leads don't have to. The relationship works when both sides trust each other. You don't need to evaluate code quality - you need to listen to the people who can, champion their recommendations, and translate technical needs into business decisions. The absolute must haves: Proven experience managing technical teams. - doesn't have to be web or agency. Manufacturing, engineering, IT operations backgrounds are equally valid. What matters is you've managed skilled people and done it well. Strong IT operations and infrastructure knowledge. - server management, hosting, networking fundamentals. You understand the systems side of technology. Compliance experience. - GDPR, Cyber Essentials, ISO, accessibility standards, or equivalent. You've worked within compliance frameworks and ideally led a business through certification. Project management discipline. - you can take something from business case to delivery without losing the thread. You plan, you track, you deliver. Data literacy. - comfortable building reports and dashboards, making sense of operational metrics, and using data to drive decisions rather than gut feel. Genuinely good with people. - you build trust, you handle difficult conversations, you develop people. You can earn the respect of a team who know more about their craft than you do. Process improvement mindset. - Lean, continuous improvement, operational efficiency. You spot waste and fix it without creating bureaucracy. Curious about technology. - you actively research, trial, and implement better ways of working. AI, automation, new tools - you're the person who makes innovation actually happen. Comfortable in a small business. - we're a team of 33. You'll roll your sleeves up. There's no one to delegate everything to. Nice to have (but honestly, we can teach you): Agency, SaaS, or digital environment experience - even tangentially. If you've worked adjacent to web development, that helps. Linux server familiarity - command line, SSH, server administration. CI/CD and deployment pipeline understanding - even conceptually. Knowing what a release process looks like matters. ERP, MES, or scheduling tool experience - production planning, resource management, capacity systems. These skills transfer directly. Budget and CAPEX management - experience managing technology budgets and making the financial case for investment. Client advisory experience - advising businesses on digital transformation, systems implementation, or operational improvement. Manufacturing, engineering, or industrial sector background - our core client base is in these sectors. If you speak their language, that's a genuine advantage. Experience & Qualifications 3+ years managing technical teams in any sector Degree or equivalent experience in a relevant field (IT, business, engineering, operations) Any formal management training or qualifications are a bonus, but real world experience matters more Full UK driving licence What You'll Achieve in Your First 90 Days Month 1 - Meet every member of the dev and support teams. Understand our tools, systems, and how work flows through the business. Build relationships with the team leads and the wider Management Team. Month 2 - Start delivering quick wins: documentation gaps, hosting cost optimisation, process improvements. Take over 1:1s with the dev team. Establish a regular security review cadence. Begin building the operational dashboards leadership needs. Month 3 - Present a 6 month roadmap covering infrastructure, compliance, R&D priorities, and process improvements. Have at least one visible win the team can point to and say "that made my life easier." Establish a working rhythm where the Lead Developers feel empowered and supported. Here's what's in it for you! A seat at the table: You'll be part of the Management Team with direct input into how the business operates and grows. This isn't a middle management role that gets told what to do - you'll shape the direction of the technical function. Real autonomy: We'll give you the scope to make this role your own. We've told you what we need - how you deliver it is up to you. . click apply for full job details
Senior IT & Security Manager
PLP Group
Senior IT & Security ManagerJob detailsBusiness OperationsSydenhamFull-timeSharks have spent 400 million years perfecting low-drag travel. We're putting that to work on aircraft and we need someone to keep the systems behind it secure. Your Mission MAKO's mission is to improve the efficiency of the global aviation fleet, saving billions in fuel and megatonnes of CO2 every year. We need a Senior IT & Security Manager to own and operate MAKO's Information Security Management System (ISMS), ensuring alignment with regulatory and certification obligations, while developing and strengthening MAKO's overall IT and security posture. You will report to the COO. What You Will Do Develop and execute a multi-year IT and security roadmap that scales with MAKO's growth and supports the secure handling of sensitive and regulated data Own and operate MAKO's Information Security Management System (ISMS), aligned with recognised information security and aviation standards Maintain the security plans, risk registers and supporting documentation that underpin MAKO's customer, regulatory and supply-chain security obligations Implement, uplift and maintain technical security controls aligned with recognised cyber security baselines, while supporting the evolution of MAKO's security infrastructure as operations grow Act as the primary owner of certification, compliance, and audit workstreams, preparing for and supporting audits, assessments and regulator engagements Own MAKO's IT environment, including strategy, governance and day-to-day management of hardware, software, identity and access management, device lifecycle management, end-user support, documentation, and related systems and services What Success Looks Like First Month: You understand MAKO's IT and security environment, have built strong working relationships across the team, and have begun shaping a multi-year IT and security plan First Six Months: You are confidently operating MAKO's ISMS and security controls, have delivered meaningful improvements in line with your roadmap, and are effectively managing our certification and compliance workstreams First Year: You own a mature, well-documented security program and have materially strengthened MAKO's IT and security posture. You have deep knowledge of MAKO's environment and communicate technical information effectively to the executive team, customers and regulators as the internal owner of our certification program About You Tertiary qualifications in information technology, cybersecurity or a related field; or equivalent practical experience Relevant industry certifications are well regarded, such as CISSP, CISM, or ISO/IEC 27001 Lead Implementer / Lead Auditor (preferred, not essential) 5+ years in IT and/or information security, ideally including a role with broad ownership spanning IT operations, security and compliance Experience implementing or operating against recognised security frameworks (e.g. ISO/IEC 27001, ASD Essential 8) Experience producing documentation to the standard expected by external assessors, including policies, standards, procedures, SSPs, POA&Ms, risk registers and audit evidence Experience developing and executing a multi-year IT and security strategy Comfortable coordinating specialist consultants, auditors, and external assessors to deliver outcomes across a broad range of technical and compliance domains Enthusiasm for the pace and breadth of a startup environment Why You Should Join MAKO Impact: Aviation is one of the hardest to abate industries, and its share of global emissions is only growing. Join our mission to improve the efficiency of the global fleet and save millions of tonnes of CO2 every year. Technology: Our technology leverages the drag-reducing properties of shark skin to make aircraft more efficient. You'll be exposed to expertise and developments in materials, photolithography, fluid dynamics, and scale manufacturing. Team: Our team focuses on achieving our mission. We live our values of lift over drag, active transparency, and changing the boundary conditions, and we welcome new team members who want to do the same. Corporate Jet: We have (most of) a corporate jet. It won't fly, but it sure does look cool.This is a rare chance to shape the entire IT and security function of a fast-moving startup at the frontier of materials science and aviation, with real ownership and real impact from day one. Bring your expertise, your curiosity, and your appetite for breadth, and help us change the boundary conditions. Apply today.
13/07/2026
Full time
Senior IT & Security ManagerJob detailsBusiness OperationsSydenhamFull-timeSharks have spent 400 million years perfecting low-drag travel. We're putting that to work on aircraft and we need someone to keep the systems behind it secure. Your Mission MAKO's mission is to improve the efficiency of the global aviation fleet, saving billions in fuel and megatonnes of CO2 every year. We need a Senior IT & Security Manager to own and operate MAKO's Information Security Management System (ISMS), ensuring alignment with regulatory and certification obligations, while developing and strengthening MAKO's overall IT and security posture. You will report to the COO. What You Will Do Develop and execute a multi-year IT and security roadmap that scales with MAKO's growth and supports the secure handling of sensitive and regulated data Own and operate MAKO's Information Security Management System (ISMS), aligned with recognised information security and aviation standards Maintain the security plans, risk registers and supporting documentation that underpin MAKO's customer, regulatory and supply-chain security obligations Implement, uplift and maintain technical security controls aligned with recognised cyber security baselines, while supporting the evolution of MAKO's security infrastructure as operations grow Act as the primary owner of certification, compliance, and audit workstreams, preparing for and supporting audits, assessments and regulator engagements Own MAKO's IT environment, including strategy, governance and day-to-day management of hardware, software, identity and access management, device lifecycle management, end-user support, documentation, and related systems and services What Success Looks Like First Month: You understand MAKO's IT and security environment, have built strong working relationships across the team, and have begun shaping a multi-year IT and security plan First Six Months: You are confidently operating MAKO's ISMS and security controls, have delivered meaningful improvements in line with your roadmap, and are effectively managing our certification and compliance workstreams First Year: You own a mature, well-documented security program and have materially strengthened MAKO's IT and security posture. You have deep knowledge of MAKO's environment and communicate technical information effectively to the executive team, customers and regulators as the internal owner of our certification program About You Tertiary qualifications in information technology, cybersecurity or a related field; or equivalent practical experience Relevant industry certifications are well regarded, such as CISSP, CISM, or ISO/IEC 27001 Lead Implementer / Lead Auditor (preferred, not essential) 5+ years in IT and/or information security, ideally including a role with broad ownership spanning IT operations, security and compliance Experience implementing or operating against recognised security frameworks (e.g. ISO/IEC 27001, ASD Essential 8) Experience producing documentation to the standard expected by external assessors, including policies, standards, procedures, SSPs, POA&Ms, risk registers and audit evidence Experience developing and executing a multi-year IT and security strategy Comfortable coordinating specialist consultants, auditors, and external assessors to deliver outcomes across a broad range of technical and compliance domains Enthusiasm for the pace and breadth of a startup environment Why You Should Join MAKO Impact: Aviation is one of the hardest to abate industries, and its share of global emissions is only growing. Join our mission to improve the efficiency of the global fleet and save millions of tonnes of CO2 every year. Technology: Our technology leverages the drag-reducing properties of shark skin to make aircraft more efficient. You'll be exposed to expertise and developments in materials, photolithography, fluid dynamics, and scale manufacturing. Team: Our team focuses on achieving our mission. We live our values of lift over drag, active transparency, and changing the boundary conditions, and we welcome new team members who want to do the same. Corporate Jet: We have (most of) a corporate jet. It won't fly, but it sure does look cool.This is a rare chance to shape the entire IT and security function of a fast-moving startup at the frontier of materials science and aviation, with real ownership and real impact from day one. Bring your expertise, your curiosity, and your appetite for breadth, and help us change the boundary conditions. Apply today.
Senior Information Security Analyst Information security London
Checkout Ltd
Company Description We're You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we're behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there's a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you've come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we're shaping the future of fintech - and we're just getting started. The Role As a Senior Information Security Analyst within the GRC team, you will lead the strategic and technical execution of Checkout's governance, risk and compliance programme. This is a role for a seasoned GRC professional who brings deep expertise across regulatory compliance, enterprise risk management, and security governance - and who can operate with full autonomy while shaping how the function evolves. You will take ownership of Checkout's most complex and high stakes compliance programmes - PCI DSS v4.0.1, ISO 27001, SOC 2, DORA, and emerging obligations across our global licensed entities - while providing expert guidance to engineering, product, legal, and compliance teams on the security requirements that underpin our ability to operate and grow in regulated markets worldwide. At L4, you are a trusted advisor. You do not just manage compliance - you set the direction for it. You define how risk is identified, assessed, and treated. You advise on product and infrastructure decisions from a risk perspective. You mentor and develop junior and mid level analysts. And you work closely with security leadership to ensure the GRC programme is aligned to the business's strategic objectives and risk appetite. Your influence extends well beyond the GRC team. You help shape the security culture at Checkout, driving a risk aware mindset across the business through clear communication, pragmatic guidance, and expert leadership. How You'll Make An Impact GRC Programme Leadership Lead defined sub areas of Checkout's GRC programme end to end, including PCI DSS v4.0.1, ISO 27001, SOC 2, and regulatory obligations across Europe, MENA, APAC, and the Americas. Define how control evidence is collected and maintained, moving the function toward continuous audit readiness and away from point in time preparation. Own and drive improvements to GRC documentation including policies, standards, procedures, and control matrices - ensuring they reflect Checkout's evolving risk profile and regulatory obligations. Lead gap analyses against new and evolving requirements, including DORA ICT risk obligations and the EU AI Act, producing prioritised remediation roadmaps with clear business impact framing. Own the risk register for your sub area, managing risk treatment through to closure and escalating to leadership where risk appetite may be exceeded. Define and refine Checkout's third party risk management approach for high risk and critical vendors, setting assessment standards and overseeing their consistent application. Drive continual improvement of the GRC programme itself - regularly assessing programme maturity, identifying process inefficiencies, and implementing improvements to how risk is identified, assessed, treated, and reported across the business. Audit and Assessment Leadership Serve as the primary point of contact for external auditors, QSAs, and regulatory assessors across PCI DSS, ISO 27001, SOC 2, and ITGC audit cycles. Demonstrated experience implementing ISO management system standards end to end, covering initial scoping and gap assessment through control design, policy development, internal audit programme, and certification - ideally across more than one standard. Lead end to end audit delivery - scoping, evidence preparation, walkthrough facilitation, finding management, and formal closure. Own the end to end response process for complex merchant assurance and regulatory due diligence requests, ensuring Checkout's compliance posture is presented accurately and persuasively. Lead quarterly and annual compliance activities including vulnerability scanning coordination, penetration testing programmes, access reviews, and firewall configuration assurance. Policy, Controls and Regulatory Strategy Apply expert knowledge of PCI DSS v4.0.1, ISO 27001/27002, SOC 2, DORA, NIST CSF, and related frameworks to drive control design, policy development, and compliance strategy. Advise product and engineering teams on compliance requirements at the point of design, embedding regulatory obligations into architecture decisions and development workflows. Lead Checkout's regulatory change management activities - monitoring the evolving landscape across financial services, data protection, and AI regulation, assessing business impact, and driving remediation programmes. Identify and drive systemic improvements to GRC processes, including automation opportunities that improve programme efficiency and evidence quality. Contribute to the design and development of GRC tooling, dashboards, and risk reporting to improve leadership visibility of Checkout's compliance and risk posture. Stakeholder Influence and Team Development Act as a senior trusted advisor to Engineering, Product, Legal, Finance, Procurement, and Compliance on all GRC matters, communicating risk in business terms that drive informed decisions. Represent the GRC function in cross functional forums, governance committees, and regulatory discussions, influencing decisions that affect Checkout's risk posture. Mentor and develop junior and mid level GRC analysts (L1-L3), raising the capability of the team through structured knowledge sharing, review, and coaching. Promote a security first culture across Checkout through proactive engagement, executive level reporting, and accessible guidance that empowers non security teams to make good risk decisions. What We're Looking For Experience 5 or more years of experience in GRC, information security compliance, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Deep working knowledge of PCI DSS (v4.0.1 required), ISO 27001, and SOC 2. Practical experience with DORA, NIST CSF, the EU AI Act, or FCA/PRA obligations is strongly preferred. Demonstrated track record of leading external audits and regulatory assessments end to end, including managing assessor relationships and driving findings to closure. Proven ability to own and deliver complex GRC programme workstreams independently, including gap analyses, risk treatment programmes, and regulatory change initiatives. Experience advising engineering and product teams on compliance requirements, with the ability to translate regulatory obligations into practical, proportionate controls. Track record of developing and mentoring less experienced colleagues. Skills and Approach Expert written and verbal communication. You can frame complex regulatory and risk issues for a technical audience, a business stakeholder, and executive leadership - and adapt your style to drive the right outcome in each context. Strategic and analytical thinker. You see beyond individual findings and controls to understand systemic risk patterns, root causes, and the broader implications for the business. Decisive under ambiguity. You can set direction and make sound judgement calls on prioritisation and risk treatment without waiting for perfect information. Highly collaborative and influential. You understand that compliance must be embedded across the business, and you build the relationships and credibility needed to make that happen. Pragmatic and outcome focused. You design controls and processes that are proportionate to risk and workable in practice, not just theoretically sound. Preferred CISA, CISM, CISSP, PCIP, ISO 27001 Lead Implementer or Lead Auditor, or equivalent advanced certification. Familiarity with cloud environments (AWS, Azure, GCP) at an architecture or control level. Experience with AI governance frameworks such as ISO 42001, the EU AI Act, or NIST AI RMF. Experience designing or implementing GRC tooling, risk platforms, or compliance automation solutions. Background in a Big Four advisory, payments scheme, or regulatory environment is advantageous. Additional Information Bring all of you to work. We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one. Here, you'll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It's a place where ambition gets met with opportunity, and where your growth is in your hands. We work as one team, and we back each other to succeed. So whatever your background or identity, if you're ready to grow and make a difference, you'll be right at home here. It's important we set you up for success and make our process as accessible as possible. So let us know in your application . click apply for full job details
10/07/2026
Full time
Company Description We're You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we're behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there's a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you've come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we're shaping the future of fintech - and we're just getting started. The Role As a Senior Information Security Analyst within the GRC team, you will lead the strategic and technical execution of Checkout's governance, risk and compliance programme. This is a role for a seasoned GRC professional who brings deep expertise across regulatory compliance, enterprise risk management, and security governance - and who can operate with full autonomy while shaping how the function evolves. You will take ownership of Checkout's most complex and high stakes compliance programmes - PCI DSS v4.0.1, ISO 27001, SOC 2, DORA, and emerging obligations across our global licensed entities - while providing expert guidance to engineering, product, legal, and compliance teams on the security requirements that underpin our ability to operate and grow in regulated markets worldwide. At L4, you are a trusted advisor. You do not just manage compliance - you set the direction for it. You define how risk is identified, assessed, and treated. You advise on product and infrastructure decisions from a risk perspective. You mentor and develop junior and mid level analysts. And you work closely with security leadership to ensure the GRC programme is aligned to the business's strategic objectives and risk appetite. Your influence extends well beyond the GRC team. You help shape the security culture at Checkout, driving a risk aware mindset across the business through clear communication, pragmatic guidance, and expert leadership. How You'll Make An Impact GRC Programme Leadership Lead defined sub areas of Checkout's GRC programme end to end, including PCI DSS v4.0.1, ISO 27001, SOC 2, and regulatory obligations across Europe, MENA, APAC, and the Americas. Define how control evidence is collected and maintained, moving the function toward continuous audit readiness and away from point in time preparation. Own and drive improvements to GRC documentation including policies, standards, procedures, and control matrices - ensuring they reflect Checkout's evolving risk profile and regulatory obligations. Lead gap analyses against new and evolving requirements, including DORA ICT risk obligations and the EU AI Act, producing prioritised remediation roadmaps with clear business impact framing. Own the risk register for your sub area, managing risk treatment through to closure and escalating to leadership where risk appetite may be exceeded. Define and refine Checkout's third party risk management approach for high risk and critical vendors, setting assessment standards and overseeing their consistent application. Drive continual improvement of the GRC programme itself - regularly assessing programme maturity, identifying process inefficiencies, and implementing improvements to how risk is identified, assessed, treated, and reported across the business. Audit and Assessment Leadership Serve as the primary point of contact for external auditors, QSAs, and regulatory assessors across PCI DSS, ISO 27001, SOC 2, and ITGC audit cycles. Demonstrated experience implementing ISO management system standards end to end, covering initial scoping and gap assessment through control design, policy development, internal audit programme, and certification - ideally across more than one standard. Lead end to end audit delivery - scoping, evidence preparation, walkthrough facilitation, finding management, and formal closure. Own the end to end response process for complex merchant assurance and regulatory due diligence requests, ensuring Checkout's compliance posture is presented accurately and persuasively. Lead quarterly and annual compliance activities including vulnerability scanning coordination, penetration testing programmes, access reviews, and firewall configuration assurance. Policy, Controls and Regulatory Strategy Apply expert knowledge of PCI DSS v4.0.1, ISO 27001/27002, SOC 2, DORA, NIST CSF, and related frameworks to drive control design, policy development, and compliance strategy. Advise product and engineering teams on compliance requirements at the point of design, embedding regulatory obligations into architecture decisions and development workflows. Lead Checkout's regulatory change management activities - monitoring the evolving landscape across financial services, data protection, and AI regulation, assessing business impact, and driving remediation programmes. Identify and drive systemic improvements to GRC processes, including automation opportunities that improve programme efficiency and evidence quality. Contribute to the design and development of GRC tooling, dashboards, and risk reporting to improve leadership visibility of Checkout's compliance and risk posture. Stakeholder Influence and Team Development Act as a senior trusted advisor to Engineering, Product, Legal, Finance, Procurement, and Compliance on all GRC matters, communicating risk in business terms that drive informed decisions. Represent the GRC function in cross functional forums, governance committees, and regulatory discussions, influencing decisions that affect Checkout's risk posture. Mentor and develop junior and mid level GRC analysts (L1-L3), raising the capability of the team through structured knowledge sharing, review, and coaching. Promote a security first culture across Checkout through proactive engagement, executive level reporting, and accessible guidance that empowers non security teams to make good risk decisions. What We're Looking For Experience 5 or more years of experience in GRC, information security compliance, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Deep working knowledge of PCI DSS (v4.0.1 required), ISO 27001, and SOC 2. Practical experience with DORA, NIST CSF, the EU AI Act, or FCA/PRA obligations is strongly preferred. Demonstrated track record of leading external audits and regulatory assessments end to end, including managing assessor relationships and driving findings to closure. Proven ability to own and deliver complex GRC programme workstreams independently, including gap analyses, risk treatment programmes, and regulatory change initiatives. Experience advising engineering and product teams on compliance requirements, with the ability to translate regulatory obligations into practical, proportionate controls. Track record of developing and mentoring less experienced colleagues. Skills and Approach Expert written and verbal communication. You can frame complex regulatory and risk issues for a technical audience, a business stakeholder, and executive leadership - and adapt your style to drive the right outcome in each context. Strategic and analytical thinker. You see beyond individual findings and controls to understand systemic risk patterns, root causes, and the broader implications for the business. Decisive under ambiguity. You can set direction and make sound judgement calls on prioritisation and risk treatment without waiting for perfect information. Highly collaborative and influential. You understand that compliance must be embedded across the business, and you build the relationships and credibility needed to make that happen. Pragmatic and outcome focused. You design controls and processes that are proportionate to risk and workable in practice, not just theoretically sound. Preferred CISA, CISM, CISSP, PCIP, ISO 27001 Lead Implementer or Lead Auditor, or equivalent advanced certification. Familiarity with cloud environments (AWS, Azure, GCP) at an architecture or control level. Experience with AI governance frameworks such as ISO 42001, the EU AI Act, or NIST AI RMF. Experience designing or implementing GRC tooling, risk platforms, or compliance automation solutions. Background in a Big Four advisory, payments scheme, or regulatory environment is advantageous. Additional Information Bring all of you to work. We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one. Here, you'll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It's a place where ambition gets met with opportunity, and where your growth is in your hands. We work as one team, and we back each other to succeed. So whatever your background or identity, if you're ready to grow and make a difference, you'll be right at home here. It's important we set you up for success and make our process as accessible as possible. So let us know in your application . click apply for full job details
SOC Coordinator
Advantage Resourcing UK Ltd Stevenage, Hertfordshire
World Class Defence Organisation based in Stevenage, Hertfordshire is currently looking to recruit a SOC Coordinator subcontractor on an initial 6 month contract. Suitable backgrounds may include: SOC Leadership, SOC Manager, Cyber Security governance and assurance, Information Security Management, Defence or National Security Operations. Military Leadership appointments with responsibility for people, operations and governance. Rate: £80.00 per hour Location: Stevenage Hybrid / Remote working: 3-4 days a week on site min, 1-2 remote. Contract: 37 Hours per week Overtime: Hours worked over 37 hours per week will be calculated at 'time and a quarter' Duration: 12 Months (initially and then ongoing and long-term thereafter) IR35 status: Inside IR35 (Umbrella) SOC Coordinator Job Description The SOC is undergoing a period of growth and maturity, with a focus on strengthening governance, improving operational resilience, enhancing monitoring capability in accordance with defence specific compliance requirements such as the DCC. The successful applicant will act as the deputy to the SOC Manager and serve as a key operational and governance lead within the team. Whilst SOC Operations contains technical analysts, engineers and security specialists, this role is primarily focussed on leadership, governance, stakeholder engagement and operational effectiveness. Responsibilities demands of countering the Cyber Threat. Support for the operational functions of the UK SOC. To work with other UK SOC members, including the UK InfoSec Team and the IM Domains. The successful candidate will help coordinate the day-to-day operation of the SOC whilst ensuring governance activities, audits, working groups, recruitment, onboarding, documentation and security improvement activities continue to progress effectively. Coordinate the implementation and maturity of Cyber security capability within DEx UK (Digital Excellence is the IT department) Deputise for the SOC Manager as required Deliver the SOC Security Working Groups across DEx and effectively track remediation and actions Responsible for the effective delivery and resilience of the 24x7 SOC shift rota Support the SOC Manager in the recruitment and onboarding process for all SOC resourcing Work in close collaboration with the Cyber Security Capability Manager Responsible for the responses and support to external requests and auditing of DEx within a cyber security context, such as ISO27001 audits, DCC and CE+ requests, GDPR requests, contractual questionnaires from customer or suppliers Coordinate vetting and access requests within the SOC in collaboration with the Cyber Security Capability Manager Responsible for attending the DEx CAB and ensuring that cyber security and compliance due diligence has taken place as well as reporting into SOC any impacting changes Take responsibility for the implementation of the Group cyber security (SOC) strategy within DEx UK, ensuring gaps and development areas are given assigned action owners To be the official interface of DEx cyber security for UK InfoSec, PCSO, GIMS, Personnel Security and National Cyber Procurement Coordinator Responsible for ensuring that DEx projects are informed of ITHC and pentest requirements prior to acceptance into service in line with policies Responsible for the coordination of any CHECK test or ITHC scoping activity which may impact the SOC Responsible for the creation, review and update of UK SOC documentation and support the delivery of Group policy and frameworks To advise and support the SOC and Vulnerability Management teams on flow management policy, incident response plans and playbooks Work in collaboration with CSC DEx in other Natcos (International Group Companies - France, Italy, Germany, Spain etc) Skillset/experience required Ideally ISO 27001/CE+ Lead/Auditor DCC Assessor would be ideal if possible Suitable backgrounds may include SOC Leadership, Cyber Security governance and assurance, Information Security Management, Defence or National Security Operations. Military Leadership appointments with responsibility for people, operations and governance. Knowledge of SOC functions and operating models. Knowledge of Vulnerability management principles Risk management and risk treatment process Audit preparation and evidence gathering Awareness of Incident response processes. Security Policy development and implementation Audit preparation and evidence gathering Stakeholder management Security awareness of modern cyber threats and defensive practices JSPs and defence security policies / Defence assurance Frameworks (DCC)
02/07/2026
Full time
World Class Defence Organisation based in Stevenage, Hertfordshire is currently looking to recruit a SOC Coordinator subcontractor on an initial 6 month contract. Suitable backgrounds may include: SOC Leadership, SOC Manager, Cyber Security governance and assurance, Information Security Management, Defence or National Security Operations. Military Leadership appointments with responsibility for people, operations and governance. Rate: £80.00 per hour Location: Stevenage Hybrid / Remote working: 3-4 days a week on site min, 1-2 remote. Contract: 37 Hours per week Overtime: Hours worked over 37 hours per week will be calculated at 'time and a quarter' Duration: 12 Months (initially and then ongoing and long-term thereafter) IR35 status: Inside IR35 (Umbrella) SOC Coordinator Job Description The SOC is undergoing a period of growth and maturity, with a focus on strengthening governance, improving operational resilience, enhancing monitoring capability in accordance with defence specific compliance requirements such as the DCC. The successful applicant will act as the deputy to the SOC Manager and serve as a key operational and governance lead within the team. Whilst SOC Operations contains technical analysts, engineers and security specialists, this role is primarily focussed on leadership, governance, stakeholder engagement and operational effectiveness. Responsibilities demands of countering the Cyber Threat. Support for the operational functions of the UK SOC. To work with other UK SOC members, including the UK InfoSec Team and the IM Domains. The successful candidate will help coordinate the day-to-day operation of the SOC whilst ensuring governance activities, audits, working groups, recruitment, onboarding, documentation and security improvement activities continue to progress effectively. Coordinate the implementation and maturity of Cyber security capability within DEx UK (Digital Excellence is the IT department) Deputise for the SOC Manager as required Deliver the SOC Security Working Groups across DEx and effectively track remediation and actions Responsible for the effective delivery and resilience of the 24x7 SOC shift rota Support the SOC Manager in the recruitment and onboarding process for all SOC resourcing Work in close collaboration with the Cyber Security Capability Manager Responsible for the responses and support to external requests and auditing of DEx within a cyber security context, such as ISO27001 audits, DCC and CE+ requests, GDPR requests, contractual questionnaires from customer or suppliers Coordinate vetting and access requests within the SOC in collaboration with the Cyber Security Capability Manager Responsible for attending the DEx CAB and ensuring that cyber security and compliance due diligence has taken place as well as reporting into SOC any impacting changes Take responsibility for the implementation of the Group cyber security (SOC) strategy within DEx UK, ensuring gaps and development areas are given assigned action owners To be the official interface of DEx cyber security for UK InfoSec, PCSO, GIMS, Personnel Security and National Cyber Procurement Coordinator Responsible for ensuring that DEx projects are informed of ITHC and pentest requirements prior to acceptance into service in line with policies Responsible for the coordination of any CHECK test or ITHC scoping activity which may impact the SOC Responsible for the creation, review and update of UK SOC documentation and support the delivery of Group policy and frameworks To advise and support the SOC and Vulnerability Management teams on flow management policy, incident response plans and playbooks Work in collaboration with CSC DEx in other Natcos (International Group Companies - France, Italy, Germany, Spain etc) Skillset/experience required Ideally ISO 27001/CE+ Lead/Auditor DCC Assessor would be ideal if possible Suitable backgrounds may include SOC Leadership, Cyber Security governance and assurance, Information Security Management, Defence or National Security Operations. Military Leadership appointments with responsibility for people, operations and governance. Knowledge of SOC functions and operating models. Knowledge of Vulnerability management principles Risk management and risk treatment process Audit preparation and evidence gathering Awareness of Incident response processes. Security Policy development and implementation Audit preparation and evidence gathering Stakeholder management Security awareness of modern cyber threats and defensive practices JSPs and defence security policies / Defence assurance Frameworks (DCC)
InfoSec Analyst II Information security London
Checkout Ltd
The Role As an Information Security Analyst II at you will work across the full breadth of the information security function, spanning Governance, Risk and Compliance (GRC), AI Governance, Application Security (AppSec), Technology Risk, and Data Governance. This is a role for someone who has built solid foundational expertise and is ready to take independent ownership of security initiatives across multiple domains. Security at Checkout operates at scale and at pace. We are a global payments business, regulated across multiple jurisdictions, building infrastructure that processes billions of transactions. Our security function needs analysts who can think across domains, communicate with engineers and executives alike, and contribute to a security programme that is genuinely embedded in how the business operates. At L3 you will manage security programmes, lead assessments, drive policy improvements, and mentor junior colleagues. Your primary focus is independent execution with growing influence. You know your domains well enough to spot gaps, propose solutions, and take them through to completion. Governance, Risk and Compliance Support workstreams within Checkout's GRC programme, including ISO 27001, SOC 2, and relevant regulatory obligations across our global licensed entities. Coordinate control evidence collection activities across internal teams, ensuring continuous audit readiness rather than point in time preparation. Maintain and improve GRC documentation including policies, standards, procedures, and control matrices, ensuring they stay current and proportionate to Checkout's evolving risk profile. Monitor the risk register, track remediation activity against agreed timelines, and elevate issues where commitments are at risk. Conduct third party risk assessments, evaluating supplier security controls and compliance posture in line with Checkout's TPRM framework. Track regulatory change across Checkout's operating markets including DORA, FCA/PRA requirements, and payment scheme obligations, flagging gaps and supporting impact assessments. AI Governance Support the development and operationalisation of Checkout's AI governance framework, aligned to ISO 42001, the EU AI Act, and NIST AI RMF. Conduct AI risk assessments for internal AI and ML systems and third party AI tools, evaluating bias, transparency, data lineage, and control adequacy. Maintain an inventory of AI use cases and associated risk classifications, working with product and engineering teams to embed governance requirements at the point of design. Monitor the evolving regulatory landscape for AI in financial services and contribute to policy and control development that keeps Checkout ahead of emerging obligations. Support Checkout's AI Security programme including threat modelling for agentic and LLM based systems, and controls mapping against the OWASP LLM Top 10 and related frameworks. Technology Risk Conduct technology risk assessments across infrastructure, cloud environments, and third party systems, producing clear outputs with actionable treatment recommendations. Support third party risk management activities, evaluating supplier security controls and compliance posture in line with Checkout's vendor risk framework. Contribute to control assurance activities including vulnerability scanning coordination, firewall and configuration reviews, and access control assessments. Monitor Checkout's technology risk landscape, identifying emerging threats and translating them into actionable risk items for the register and leadership reporting. Support DORA related ICT risk management obligations, contributing to resilience testing coordination and critical third party risk assessments. Data Governance Support Checkout's data governance programme, including data classification, data flow mapping, and enforcement of data handling standards across the business. Contribute to data loss prevention (DLP) controls and tooling, working with engineering and product teams to ensure sensitive data is protected throughout its lifecycle. Assist in maintaining records of processing activities (RoPA) and supporting data protection impact assessments (DPIAs) for new systems and processing activities. Work with the privacy and legal functions to ensure data governance controls meet GDPR, UK GDPR, and applicable regional data protection requirements. Promote data governance awareness and good data handling practices across the business, contributing to training and guidance materials for non technical teams. Cross domain Collaboration and Mentoring Work closely with Engineering, Product, Legal, Procurement, Finance, and Compliance teams to embed security requirements into processes, systems, and projects across all five domains. Respond to security due diligence requests from merchants, partners, and regulators, drawing on multi domain expertise to provide accurate and comprehensive responses. Provide guidance and day to day support to junior analysts (L1 and L2), contributing to their development through knowledge sharing and review. Contribute to the continuous improvement of Checkout's security processes, identifying inefficiencies and proposing practical solutions including automation where viable. What We're Looking For Experience 2 to 4 years of experience in information security, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Demonstrated working knowledge across more than one of the following domains: GRC, AI governance, AppSec, technology risk, or data governance. Depth in one or two with credible breadth across the others is the target profile. Practical experience with one or more major compliance frameworks: PCI DSS (v4.0.1 preferred), ISO 27001, SOC 2, DORA, NIST CSF, or equivalent. Experience supporting or managing external audits, assessments, or regulatory engagements including evidence collation and assessor liaison. Demonstrated ability to own a workstream independently, from scoping through to delivery, without requiring constant direction. Skills and Approach Strong analytical and process oriented mindset. You look for root causes and systemic fixes, not just point in time remediation. Clear written and verbal communication. You can translate security concepts for technical teams and business stakeholders with equal clarity. Comfortable operating with ambiguity across a complex domain landscape. You can prioritise without perfect information. Collaborative and pragmatic. You understand that security must work with the business and that influence matters as much as expertise. Methodical and well organised, with a track record of delivering on commitments across concurrent workstreams. Preferred Relevant certification in one or more domains: CISA, CISM, CISSP, PCIP, ISO 27001 Lead Implementer or Auditor, Certified AppSec Practitioner (CAP), or equivalent. Familiarity with cloud environments (AWS, Azure, GCP) from a security or compliance perspective. Exposure to AI and ML systems from a risk, governance, or security perspective. Experience with security or GRC tooling such as Wiz, Qualys, Microsoft Sentinel, ServiceNow GRC, or similar. Understanding of agentic AI and LLM security risks including OWASP LLM Top 10, prompt injection, and data exfiltration vectors. Hybrid Working Model All of our offices globally are onsite three times per week (Tuesday, Wednesday, and Thursday). We work collaboratively in the same space while also being able to partner with colleagues globally. During your days at the office, we offer great snacks, breakfast, and lunch options in all of our locations. We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.
28/06/2026
Full time
The Role As an Information Security Analyst II at you will work across the full breadth of the information security function, spanning Governance, Risk and Compliance (GRC), AI Governance, Application Security (AppSec), Technology Risk, and Data Governance. This is a role for someone who has built solid foundational expertise and is ready to take independent ownership of security initiatives across multiple domains. Security at Checkout operates at scale and at pace. We are a global payments business, regulated across multiple jurisdictions, building infrastructure that processes billions of transactions. Our security function needs analysts who can think across domains, communicate with engineers and executives alike, and contribute to a security programme that is genuinely embedded in how the business operates. At L3 you will manage security programmes, lead assessments, drive policy improvements, and mentor junior colleagues. Your primary focus is independent execution with growing influence. You know your domains well enough to spot gaps, propose solutions, and take them through to completion. Governance, Risk and Compliance Support workstreams within Checkout's GRC programme, including ISO 27001, SOC 2, and relevant regulatory obligations across our global licensed entities. Coordinate control evidence collection activities across internal teams, ensuring continuous audit readiness rather than point in time preparation. Maintain and improve GRC documentation including policies, standards, procedures, and control matrices, ensuring they stay current and proportionate to Checkout's evolving risk profile. Monitor the risk register, track remediation activity against agreed timelines, and elevate issues where commitments are at risk. Conduct third party risk assessments, evaluating supplier security controls and compliance posture in line with Checkout's TPRM framework. Track regulatory change across Checkout's operating markets including DORA, FCA/PRA requirements, and payment scheme obligations, flagging gaps and supporting impact assessments. AI Governance Support the development and operationalisation of Checkout's AI governance framework, aligned to ISO 42001, the EU AI Act, and NIST AI RMF. Conduct AI risk assessments for internal AI and ML systems and third party AI tools, evaluating bias, transparency, data lineage, and control adequacy. Maintain an inventory of AI use cases and associated risk classifications, working with product and engineering teams to embed governance requirements at the point of design. Monitor the evolving regulatory landscape for AI in financial services and contribute to policy and control development that keeps Checkout ahead of emerging obligations. Support Checkout's AI Security programme including threat modelling for agentic and LLM based systems, and controls mapping against the OWASP LLM Top 10 and related frameworks. Technology Risk Conduct technology risk assessments across infrastructure, cloud environments, and third party systems, producing clear outputs with actionable treatment recommendations. Support third party risk management activities, evaluating supplier security controls and compliance posture in line with Checkout's vendor risk framework. Contribute to control assurance activities including vulnerability scanning coordination, firewall and configuration reviews, and access control assessments. Monitor Checkout's technology risk landscape, identifying emerging threats and translating them into actionable risk items for the register and leadership reporting. Support DORA related ICT risk management obligations, contributing to resilience testing coordination and critical third party risk assessments. Data Governance Support Checkout's data governance programme, including data classification, data flow mapping, and enforcement of data handling standards across the business. Contribute to data loss prevention (DLP) controls and tooling, working with engineering and product teams to ensure sensitive data is protected throughout its lifecycle. Assist in maintaining records of processing activities (RoPA) and supporting data protection impact assessments (DPIAs) for new systems and processing activities. Work with the privacy and legal functions to ensure data governance controls meet GDPR, UK GDPR, and applicable regional data protection requirements. Promote data governance awareness and good data handling practices across the business, contributing to training and guidance materials for non technical teams. Cross domain Collaboration and Mentoring Work closely with Engineering, Product, Legal, Procurement, Finance, and Compliance teams to embed security requirements into processes, systems, and projects across all five domains. Respond to security due diligence requests from merchants, partners, and regulators, drawing on multi domain expertise to provide accurate and comprehensive responses. Provide guidance and day to day support to junior analysts (L1 and L2), contributing to their development through knowledge sharing and review. Contribute to the continuous improvement of Checkout's security processes, identifying inefficiencies and proposing practical solutions including automation where viable. What We're Looking For Experience 2 to 4 years of experience in information security, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Demonstrated working knowledge across more than one of the following domains: GRC, AI governance, AppSec, technology risk, or data governance. Depth in one or two with credible breadth across the others is the target profile. Practical experience with one or more major compliance frameworks: PCI DSS (v4.0.1 preferred), ISO 27001, SOC 2, DORA, NIST CSF, or equivalent. Experience supporting or managing external audits, assessments, or regulatory engagements including evidence collation and assessor liaison. Demonstrated ability to own a workstream independently, from scoping through to delivery, without requiring constant direction. Skills and Approach Strong analytical and process oriented mindset. You look for root causes and systemic fixes, not just point in time remediation. Clear written and verbal communication. You can translate security concepts for technical teams and business stakeholders with equal clarity. Comfortable operating with ambiguity across a complex domain landscape. You can prioritise without perfect information. Collaborative and pragmatic. You understand that security must work with the business and that influence matters as much as expertise. Methodical and well organised, with a track record of delivering on commitments across concurrent workstreams. Preferred Relevant certification in one or more domains: CISA, CISM, CISSP, PCIP, ISO 27001 Lead Implementer or Auditor, Certified AppSec Practitioner (CAP), or equivalent. Familiarity with cloud environments (AWS, Azure, GCP) from a security or compliance perspective. Exposure to AI and ML systems from a risk, governance, or security perspective. Experience with security or GRC tooling such as Wiz, Qualys, Microsoft Sentinel, ServiceNow GRC, or similar. Understanding of agentic AI and LLM security risks including OWASP LLM Top 10, prompt injection, and data exfiltration vectors. Hybrid Working Model All of our offices globally are onsite three times per week (Tuesday, Wednesday, and Thursday). We work collaboratively in the same space while also being able to partner with colleagues globally. During your days at the office, we offer great snacks, breakfast, and lunch options in all of our locations. We understand that work is just one part of your life. Our hybrid working model offers flexibility, with three days per week in the office to support collaboration and connection.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board