InterviewHack.ai
Empezar gratis
Vacantes / Abound

GRC Security Specialist

Abound·Londonmid

En corto

  • →Especialista en seguridad y cumplimiento (GRC) que gestiona auditorías y pruebas de control para proveedores y clientes.
  • →Lidera ciclos recurrentes de aseguranzas, gestión de riesgos, certificaciones y respuesta a due diligence externa.
  • →Destacado: ser el conductor del cumplimiento regulatorio con el FCA (PS26/2) y asegurar la confianza de inversores y bancos.

Proficiency in English required for due diligence and documentation

Postularme en la empresa ↗Compartir por WhatsApp

En ~1 minuto te damos: quién te entrevista, las preguntas probables con respuestas desde tu CV, y tu CV adaptado a esta vacante. Gratis, sin tarjeta.

🎧¿Llegás a la entrevista? Llevá el copiloto. Nuestra extensión escucha la entrevista en vivo y te muestra anclas de 3-4 palabras desde tu CV y tu preparación — mirás, conectás, hablás. Gratis. Ver la extensión →

¿Qué piden?

  • ✓Experiencia en gestión de terceros y due diligence de seguridad.
  • ✓Capacidad para gestionar múltiples auditorías y certificaciones (ISO 27001, SOC 2, etc.).
  • ✓Conocimiento del marco regulatorio financiero (FCA, PS26/2).
  • ✓Habilidad para estructurar y automatizar respuestas a preguntas de seguridad (trust pack).
  • ✓Experiencia con pruebas de penetración y gestión de vulnerabilidades.
  • ✓Aptitud para trabajar con equipos de ingeniería, legal y compras.

¿No cumplís todo? Es lo normal — tu dossier gratis te dice qué gaps tenés y cómo cubrirlos en la entrevista.

ISO 27001SOC 2SIGCAIQEDRCloud Security PostureSASTDASTSCAPenetration Testing

¿A quién escribirle en Abound?

Tu dossier gratis identifica a las personas que te entrevistarían — con su background, qué valoran y cómo escribirles para destacar antes de aplicar.

About Abound We’re redefining consumer lending in the UK, and beyond. Using advanced AI and Open Banking data, we make fair, affordable personal finance available to more people. While traditional lenders rely almost entirely on credit scores, we look at the full financial picture - how much you spend, and what you can afford to repay to build a deeper, more accurate understanding of each customer's unique financial situation. And we've shown it works at scale. We’ve issued over £1.3bn in loans directly to customers while delivering market-leading credit performance - for every 10 defaults the industry expects, we see only 3. We also reached profitability just 2.5 years after launch. Backed by £2bn+ of funding from top-tier investors including Citi, GSR Ventures, and Deutsche Bank, we’re recognised as one of Europe’s fastest-growing fintechs (Sifted, CNBC). Now, we’re expanding into new markets and product lines - and we’re looking for ambitious people who want to learn fast, take ownership, and grow with us. The role We are formalising our security assurance function. We have technical controls and the engineering culture; what we need now is the governance layer that proves it - to our auditors, to our funders, and to our regulator. You will be the delivery engine behind that. You will own the recurring assurance cycle end to end, run our third-party security programme, and be the person who turns evidence into something a due diligence team or a certification auditor can be satisfied by. You will be responsible for building controls, gathering evidence, and challenging suppliers. What you will own: 1. Third-party security assurance - Run security due diligence on new suppliers, maintain initial questionnaire to risk sign-off, working with Procurement and Legal on security and data protection schedules. - Maintain a supplier tiering model based on criticality and run the periodic re-assessment cycle for tiered suppliers: certification expiry, subprocessor changes, breach notifications, SLA performance. - Maintain the supplier and outsourcing registers, including preparation for the FCA's material third party register under PS26/2 (rules in force 18 March 2027). - Track concentration risk and exit plans for critical suppliers. 2. Inbound due diligence and customer assurance - Own our response to security due diligence from funders, banking partners, institutional investors, commercial partners and prospects. - Build and maintain a reusable trust pack: answer library, security whitepaper, current certifications, pen test attestations, standard questionnaire pre-fills (SIG, CAIQ). - Turn a 40-hour bespoke questionnaire response into a 4-hour one. 3. The assurance calendar - Maintain the annual calendar of security activities and make sure each one happens, produces evidence, and closes its actions: penetration tests, access reviews, disaster recovery tests, tabletop exercises, policy reviews, supplier re-assessments, awareness training. - Coordinate external penetration tests: scoping, vendor selection, scheduling, findings triage, remediation tracking, retest. - Facilitate tabletop exercises, including scenario design and post-exercise action tracking. 4. Risk and control administration - Maintain the information security risk register: run the assessment cycle, record treatment plans with named owners and dates, chase closure. - Administer the policy exception and risk acceptance process, ensuring every exception is owned, time-bound and reviewed on expiry. - Perform first-line control testing: sample-test where key controls operate as designed and retain the evidence. - Produce security MI for the Head of Security to take to ExCo and the Risk Committee. 5. Vulnerability and findings management - Consolidate findings across sources — EDR, cloud security posture, SAST/DAST/SCA, secrets scanning, penetration tests — into a single view with agreed severity definitions and remediation SLAs.

¿Buscando algo parecido?

Dejá tu email y te avisamos cuando salgan vacantes que coincidan con tu perfil.

No apliques sin prepararte

Investigamos quién te entrevista, adaptamos tu CV y te ensayamos en vivo — gratis la primera.

InterviewHack.ai

Preparate para la entrevista exacta: quién te entrevista, tu CV a medida y coach real.

Producto

VacantesEmpresas contratandoRevisar CV (ATS) gratis¿Cómo suena tu inglés?¿Te pagan bien?Reporte de sueldos LATAMCursos gratisBlogCV a medidaPráctica habladaEs gratis

Empleos remotos

ReactPythonFull-StackLATAMArgentinaMéxicoVer todas →

Preparate

Práctica habladaFrontendBackendAI EngineerPor empresaVendete con tu CV

Empresa

Buscás talentoAcerca deContactoPrivacidadTérminos

© 2026 InterviewHack.ai · Tu CV es tuyo. Nunca se usa para entrenar nada. · Un producto de IA-PTY

Vacantes similares activas

Collections Administrator

Abound · Milton Keynes

→

Senior Frontend Engineer

Abound · London

→

Collections Adviser

Abound · Milton Keynes

→