Security Operations & GRC Manager
Operations
London, UK
Posted on Aug 4, 2026
AccessFintech is seeking a senior Information Security professional to join our Technology function. This is a broad remit spanning three areas — AFT's internal information security posture, our governance, risk and compliance programme, and the security relationship with AFT's client network.
As a capital markets technology provider handling sensitive financial data for over 250 institutions, client security confidence is as important as internal security rigour, and both rest on a well-run compliance and assurance programme. This role requires someone who can operate credibly across all three — running robust security operations, owning the certification and risk framework, and engaging directly with clients on security due diligence, assessments, and trust-building conversations.
You will report directly to the CTO and work closely with engineering, product, client operations, and solutions teams across all three jurisdictions.
Requirements
Skills & Experience
As a capital markets technology provider handling sensitive financial data for over 250 institutions, client security confidence is as important as internal security rigour, and both rest on a well-run compliance and assurance programme. This role requires someone who can operate credibly across all three — running robust security operations, owning the certification and risk framework, and engaging directly with clients on security due diligence, assessments, and trust-building conversations.
You will report directly to the CTO and work closely with engineering, product, client operations, and solutions teams across all three jurisdictions.
Requirements
- Internal Information Security
- Own and continuously improve AFT's information security posture across infrastructure, applications, cloud environments, and endpoints
- Lead the operation and evolution of AFT's security tooling — SIEM, EDR, vulnerability management, intrusion detection, and identity and access management (IAM)
- Own AFT's vulnerability management programme — regular assessments, remediation tracking, and risk reporting to the CTO and executive team
- Lead security incident response — identification, containment, investigation, remediation, and post-incident review
- Maintain and develop AFT's information security policies, standards, and procedures across all three jurisdictions
- Embed security into AFT's software development lifecycle (SDLC) — partnering with engineering and DevOps to shift security left
- Design and deliver security awareness training and communications across the global team
- Client-Facing Security
- Act as AFT's primary point of contact for all client security enquiries, assessments, and due diligence requests
- Own the end-to-end response to client information security questionnaires — including standardised formats such as the Shared Assessments SIG and CSA CAIQ, as well as bespoke questionnaires issued by banks, custodians, and asset managers
- Build and maintain a central answer library so questionnaire responses are consistent, accurate, and efficient to produce — reducing turnaround times and removing reliance on ad hoc drafting
- Coordinate input from engineering, DevOps, legal, and compliance where questions fall outside the existing answer set, and quality-assure all responses before issue
- Manage annual reassessments and periodic client re-certification cycles, ensuring responses remain current as the platform and control environment evolve
- Represent AFT in client-facing security discussions, audits, and on-site or virtual security assessments — building confidence in AFT's security posture at senior level
- Support the client onboarding process from a security and compliance perspective — ensuring new clients can satisfy their own internal security requirements for onboarding AFT
- Partner with Client Operations and Solutions teams to proactively manage client security requirements as part of the commercial relationship
- Maintain AFT's security documentation suite — trust centre content, security overview decks, penetration test summaries, and compliance certificates — keeping them current and client-ready
- Track and manage client-raised security findings, ensuring remediation actions are progressed and communicated back to clients in a timely manner
- Contribute to new business conversations where security posture is a factor — working with Sales and Solutions on RFP responses and client presentations
- Governance, Risk & Compliance (GRC)
- Own AFT's information security governance framework — policies, standards, and control documentation across all three jurisdictions
- Own and maintain AFT's information security risk register — identifying, assessing, and tracking risks across internal and client-facing dimensions, with defined risk appetite and escalation thresholds
- Own AFT's ISO 27001 and SOC 2 programmes end to end — control design, evidence collection, internal audit, gap remediation, and management of external auditors through certification and surveillance cycles
- Maintain regulatory compliance mapping across UK (FCA, UK GDPR), US (SEC), and Israel (Privacy Protection Law), ensuring controls are traceable to obligations
- Own the third-party and vendor security risk assessment programme — onboarding due diligence, ongoing monitoring, and contractual security requirements
- Own the control testing and assurance calendar, ensuring controls are evidenced continuously rather than reconstructed at audit
- Establish and run the security governance cadence — regular reporting to the CTO and executive team, translating technical risk into business-level insight
- Lead preparation for external security audits, regulatory examinations, and client-initiated security reviews
Skills & Experience
- 6-10 years of progressive experience in information security or cybersecurity, including at least 2 years in a client-facing or externally-engaged security role
- Proven experience owning client information security questionnaires at volume — including standardised formats (SIG, CAIQ) and bespoke bank or custodian questionnaires — with a track record of building an answer library rather than responding ad hoc
- Experience managing client-raised security findings through to remediation, and reporting outcomes back to client security teams
- Demonstrable experience owning a GRC programme — running an ISO 27001 or SOC 2 certification cycle end to end, including evidence management, internal audit, and managing external auditors
- Experience building and maintaining an information security risk register, with the ability to articulate risk appetite and escalate appropriately
- Experience managing third-party and vendor security risk assessment programmes
- Strong hands-on security operations experience — SIEM (e.g. Splunk, Microsoft Sentinel), EDR, vulnerability management (e.g. Tenable, Qualys), and IAM
- Deep working knowledge of information security frameworks — ISO 27001, SOC 2, NIST CSF — and experience maintaining or achieving certification
- Strong background in cloud-native applications and architectures, with cloud security expertise across IAM, network security, and cloud-native security monitoring
- Strong understanding of data privacy and regulatory obligations in financial services — GDPR, FCA, SEC, or equivalent — including mapping controls across multiple regimes
- Excellent communication skills — able to translate complex security concepts into clear, confident language for client security teams, legal and compliance functions, and non-technical business stakeholders
- Comfortable engaging at senior level with client security and technology teams — building trust and managing relationships through complex due diligence processes
- Relevant security certifications — CISSP, CISM, CRISC, CISA, CEH, or equivalent
- ISO 27001 Lead Implementer or Lead Auditor certification
- Experience in capital markets, fintech, or regulated financial services — familiarity with the security expectations of buy-side, sell-side, or custodian institutions
- Experience with DevSecOps practices — integrating security into CI/CD pipelines and engineering workflows
- Scripting or automation capability — Python, PowerShell, or Bash — for security tooling and reporting
- Experience building or maintaining a client trust centre or security documentation programme
- Experience with GRC tooling and compliance automation platforms
- AWS specifically is an advantage — hands-on experience securing containerised and serverless workloads, and using AWS-native security services such as GuardDuty, Security Hub, and Config