Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
The role involves strengthening and maturing our information security governance, risk, and compliance function. Reporting to the Head of Information Security, you will develop and operate frameworks, registers, and processes to ensure compliance and audit readiness across ISO 27001, DORA, GDPR, PCI DSS, and operational resilience requirements. This hands-on senior position requires building and managing programs, working with a modern GRC platform, and leveraging AI and automation to streamline workflows.
Key Responsibilities:
- Developing, maintaining, and continuously improving information security policies, standards, and procedures aligned with ISO 27001 and applicable regulatory requirements.
- Managing the full policy lifecycle, including approval workflows, periodic reviews, ownership, and version control across the document estate.
- Maintaining the information security risk register, including risk identification, assessment, treatment tracking, and formal risk acceptance.
- Preparing risk reporting for management and governance committees, and tracking remediation actions through to closure.
- Supporting compliance activities under DORA, including the Register of Information, as well as PSD2/EBA ICT guidelines, GDPR, and PCI DSS across licensed entities.
- Contributing to operational resilience activities for the UK entity in line with FCA requirements.
- Managing the third-party risk management lifecycle, including due diligence, security questionnaires, risk rating, onboarding gates, and periodic reassessments.
- Maintaining the vendor register and contractual security requirements in collaboration with the Legal team.
- Coordinating internal and external audits, including Big Four ICT audits, regulator requests, and PCI QSA cycles, and managing the audit calendar.
- Owning evidence collection and maintaining an evidence library for reuse across audits, certifications, and client questionnaires.
- Administering and developing our GRC platform, including control monitoring, automated evidence collection, framework mapping, and reporting.
- Applying AI tools to day-to-day GRC activities, including policy drafting, gap analysis, evidence assembly, and questionnaire responses, while helping to automate recurring processes.
- Contributing to our AI governance program, including the assessment of AI vendors, support of the AI system register, and alignment with emerging regulatory requirements such as the EU AI Act.
Requirements:
- 3+ years of experience in GRC, information security governance, IT audit, or IT risk management.
- Working knowledge of ISO/IEC 27001; exposure to DORA, GDPR, or PCI DSS.
- Experience in regulated financial services (payments, e-money, banking, fintech) or advisory work for such companies.
- Hands-on experience with audits — coordinating them, preparing evidence, and remediating findings.
- Familiarity with GRC platforms or a strong interest in compliance automation.
- Strong written English — your output goes to auditors, regulators, and senior stakeholders.
- Ability to manage multiple workstreams against fixed deadlines.
- Nice to have:
- Certifications such as CISA, CRISC, CISM, CIPP/E, or ISO 27001 Lead Auditor/Lead Implementer.
- Direct experience with DORA implementation, EBA outsourcing guidelines, or FCA operational resilience.
- Experience implementing or administering a GRC platform (e.g., Vanta, ServiceNow GRC, OneTrust, or similar).
- Familiarity with ISO 42001, the EU AI Act, or AI risk management.
- Light scripting or workflow automation skills (low-code tools).
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
Senior Employee Relations Specialist (Western Europe) - Remote
Oyster
Spain
AustriaSenior Global Mobility Specialist
Remotepass
Philippines
PolandGlobal Entity Operations Associate (Internal Title: Global Entity Infrastructure Associate)
Workmotion
Bulgaria
HungaryGlobal Entity Operations Associate (Internal Title: Global Entity Infrastructure Associate)
Workmotion
Albania
CroatiaMore Openings at Payabl
Explore Top Companies in this Space
AppZen
FinTech & Autonomous Finance / Agentic AI & AP Automation / Corporate Expense Auditing / Enterprise Software SaaS
M+R Strategic Services
Public Relations and Communications Services / Non-Profit & Charitable Organizations / Fundraising / Advocacy
BlueFlag Security
Enterprise Software / Cybersecurity / Developer Tools / AI Governance
Northramp
IT Services / Government Technology / Enterprise Software / Cybersecurity
Payabl
View Company ProfilePayabl (operating at payabl.com) is a financial services platform engineered for streamlining and automating payment processes within the business-to-business (B2B) sector. Founded in an unspecified year, the company appears to specialize in providing a modern solution to the complexities of invoice management, payment tracking, and cash flow optimization. Under the hood, Payabl likely leverages cloud-based technology and integration APIs to connect with accounting systems, payment gateways, and enterprise resource planning (ERP) tools, ensuring seamless workflows. This allows businesses to reduce manual errors, accelerate payment cycles, and gain real-time visibility into their financial operations. While specific details about funding, investors, or founders remain undisclosed, the platform’s focus on operational efficiency suggests it targets mid-sized to large enterprises seeking to digitize their payment processes.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.

