Location
London
Hours
Full Time
Salary
Competitive, commensurate with experience
About the Role
AccessFintech is seeking a senior Information Security professional to join our Technology function. This role spans three critical areas: managing AFT's internal information security posture, leading the governance, risk and compliance (GRC) programme, and overseeing the security relationship with AFT's client network. As a capital markets technology provider handling sensitive financial data for over 250 institutions, maintaining client security confidence alongside internal security rigour is paramount. You will be responsible for running robust security operations, owning the certification and risk framework, and engaging directly with clients on security due diligence, assessments, and trust-building conversations. Reporting directly to the CTO, you will collaborate closely with engineering, product, client operations, and solutions teams across multiple jurisdictions to ensure a well-run compliance and assurance programme.
Experience
- 6–10 years of progressive experience in information security or cybersecurity, including at least 2 years in a client-facing or externally-engaged security role
- Proven experience managing client information security questionnaires at volume, including standardised formats (SIG, CAIQ) and bespoke questionnaires from banks or custodians, with a track record of building and maintaining an answer library
- Experience managing client-raised security findings through to remediation and reporting outcomes back to client security teams
- Demonstrable experience owning a GRC programme, including running ISO 27001 or SOC 2 certification cycles end to end, evidence management, internal audits, and managing external auditors
- Experience building and maintaining an information security risk register, articulating risk appetite and escalating appropriately
- Experience managing third-party and vendor security risk assessment programmes
- Strong hands-on security operations experience with SIEM (e.g. Splunk, Microsoft Sentinel), EDR, vulnerability management (e.g. Tenable, Qualys), and IAM
- Deep working knowledge of information security frameworks such as ISO 27001, SOC 2, NIST CSF, and experience maintaining or achieving certification
- Strong background in cloud-native applications and architectures, with expertise in cloud security across IAM, network security, and cloud-native security monitoring
- Strong understanding of data privacy and regulatory obligations in financial services including GDPR, FCA, SEC, or equivalent, with ability to map controls across multiple regimes
- Excellent communication skills, able to translate complex security concepts into clear, confident language for client security teams, legal and compliance functions, and non-technical business stakeholders
- Comfortable engaging at senior level with client security and technology teams, building trust and managing relationships through complex due diligence processes
About you
You are a highly motivated and experienced information security professional with a strong client focus and the ability to manage complex security programmes across multiple jurisdictions. You thrive in a dynamic fintech environment, possess excellent interpersonal and communication skills, and can effectively collaborate with technical and non-technical stakeholders. You are proactive, detail-oriented, and capable of leading security operations, GRC initiatives, and client engagements with confidence and professionalism.
Qualifications
- Relevant security certifications such as CISSP, CISM, CRISC, CISA, CEH, or equivalent are desirable
- ISO 27001 Lead Implementer or Lead Auditor certification is advantageous
- Experience in capital markets, fintech, or regulated financial services, with familiarity of security expectations for buy-side, sell-side, or custodian institutions
- Experience with DevSecOps practices, integrating security into CI/CD pipelines and engineering workflows
- Scripting or automation skills (Python, PowerShell, Bash) for security tooling and reporting
- Experience building or maintaining a client trust centre or security documentation programme
- Experience with GRC tooling and compliance automation platforms
- Hands-on AWS security experience, including securing containerised and serverless workloads and using AWS-native security services such as GuardDuty, Security Hub, and Config


