793,143open jobs
50,545companies
124,108added this week
Browse all
Salary
≈ $60k – $144k per year (Estimated)
Location
Hybrid (London, United Kingdom)
Seniority
Middle · 3+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 25, 2026. First seen by Alion on Sep 25, 2026. Abound scores A on the Alion truth index.

Overview
Company
Impact
Profile match
We look at the full picture to design a loan that works for you, at a fair rate.

About Abound

We’re redefining consumer lending in the UK, and beyond. Using advanced AI and Open Banking data, we make fair, affordable personal finance available to more people. While traditional lenders rely almost entirely on credit scores, we look at the full financial picture - how much you spend, and what you can afford to repay to build a deeper, more accurate understanding of each customer's unique financial situation.

And we've shown it works at scale. We’ve issued over £1.3bn in loans directly to customers while delivering market-leading credit performance - for every 10 defaults the industry expects, we see only 3. We also reached profitability just 2.5 years after launch.

Backed by £2bn+ of funding from top-tier investors including Citi, GSR Ventures, and Deutsche Bank, we’re recognised as one of Europe’s fastest-growing fintechs (Sifted, CNBC). Now, we’re expanding into new markets and product lines - and we’re looking for ambitious people who want to learn fast, take ownership, and grow with us.

The role

We are formalising our security assurance function. We have technical controls and the engineering culture; what we need now is the governance layer that proves it - to our auditors, to our funders, and to our regulator.

You will be the delivery engine behind that. You will own the recurring assurance cycle end to end, run our third-party security programme, and be the person who turns evidence into something a due diligence team or a certification auditor can be satisfied by.

You will be responsible for building controls, gathering evidence, and challenging suppliers.

What you will own:

1. Third-party security assurance

- Run security due diligence on new suppliers, maintain initial questionnaire to risk sign-off, working with Procurement and Legal on security and data protection schedules.

- Maintain a supplier tiering model based on criticality and run the periodic re-assessment cycle for tiered suppliers: certification expiry, subprocessor changes, breach notifications, SLA performance.

- Maintain the supplier and outsourcing registers, including preparation for the FCA's material third party register under PS26/2 (rules in force 18 March 2027).

- Track concentration risk and exit plans for critical suppliers.

2. Inbound due diligence and customer assurance

- Own our response to security due diligence from funders, banking partners, institutional investors, commercial partners and prospects.

- Build and maintain a reusable trust pack: answer library, security whitepaper, current certifications, pen test attestations, standard questionnaire pre-fills (SIG, CAIQ).

- Turn a 40-hour bespoke questionnaire response into a 4-hour one.

3. The assurance calendar

- Maintain the annual calendar of security activities and make sure each one happens, produces evidence, and closes its actions: penetration tests, access reviews, disaster recovery tests, tabletop exercises, policy reviews, supplier re-assessments, awareness training.

- Coordinate external penetration tests: scoping, vendor selection, scheduling, findings triage, remediation tracking, retest.

- Facilitate tabletop exercises, including scenario design and post-exercise action tracking.

4. Risk and control administration

- Maintain the information security risk register: run the assessment cycle, record treatment plans with named owners and dates, chase closure.

- Administer the policy exception and risk acceptance process, ensuring every exception is owned, time-bound and reviewed on expiry.

- Perform first-line control testing: sample-test where key controls operate as designed and retain the evidence.

- Produce security MI for the Head of Security to take to ExCo and the Risk Committee.

5. Vulnerability and findings management

- Consolidate findings across sources - EDR, cloud security posture, SAST/DAST/SCA, secrets scanning, penetration tests - into a single view with agreed severity definitions and remediation SLAs.

- Triage, route and chase remediation with engineering teams; escalate ageing findings.

- Own the reporting on remediation performance.

6. Security awareness

- Run the awareness programme: induction, annual refresher, phishing simulation, role-based training for engineers, completion tracking.

- Coordinate pre-employment screening with People.

What you will contribute to:

- The ISO 27001 ISMS, which we are building towards certification. You will draft and maintain control documentation, populate the Statement of Applicability, gather evidence, coordinate the internal audit programme and be a primary point of contact for our external auditor. The Head of Security owns the framework, scope, and risk appetite.

- Policies and standards: you will draft, review and shepherd policies through approval, and track the review cycle.

- Incident response: you will maintain the IR plan and playbooks, facilitate post-incident reviews, track remediation actions, and support regulatory notification (ICO personal data breach reporting within 72 hours; FCA notification under Principle 11 / SUP 15.3).

- Business continuity and DR: you will maintain the documentation and the testing evidence.

- Secure development: you will help embed security requirements into the SDLC and support threat modelling sessions.

- Data protection: you will support RoPA maintenance, DPIA completion and DSAR handling alongside Legal.

What success looks like:

First 90 days: you know our supplier estate and have tiered it; the assurance calendar for the next 12 months is published and owned; inbound due diligence requests come to you and go out without the Head of Security rewriting them.

Six months: the trust pack exists and is being used; the risk register is live with owned treatment plans; ISO 27001 evidence collection is systematic rather than a scramble; the exception register exists.

Twelve months: supplier re-assessment runs on a cadence without prompting; the material third party register is ready ahead of the March 2027 deadline; MI to the Risk Committee is trusted.

Essential experience:

- Three or more years in an information security assurance, GRC or security compliance role, at least some of it in a regulated financial services environment or another environment with real external audit pressure.

- Hands-on experience of ISO 27001, whether operating an ISMS or taking one through certification.

- Demonstrable experience running third-party or vendor security assessments, and of responding to inbound security due diligence.

- Comfortable reading technical findings - an EDR vulnerability report, a penetration test finding, a cloud misconfiguration - and forming your own view on severity and real-world exploitability rather than passing the vendor's rating through unchanged.

- Clear, concise written English. Much of this role is writing things that external parties will judge us on.

- The confidence to chase a busy engineer, challenge a supplier's assertion, and tell us when an answer is not good enough.

Desirable:

- Experience of a cloud-native environment, ideally AWS.

- Experience of scaling a control framework as an organisation grows.

- Familiarity with UK operational resilience expectations (SYSC 15A) and outsourcing requirements (SYSC 8).

- Certifications such as CISM, CISA, ISO 27001 Lead Implementer or Lead Auditor, CRISC or CCSP. We care more about what you have done than what you hold.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
793,143 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
London
≈ $48k – $116k per year (Estimated) • In office • Full-Time • 2+ years exp • Mansfield
Cybersecurity
MITRE ATT&CK
CVSS
Apply
≈ $92k – $180k per year (Estimated) • In office • Full-Time • 5+ years exp • London
Apply
$63k – $81k per year • In office • Full-Time • Huntingdon
Python
PowerShell
AI/ML
Machine Learning
DevOps
Rest API
Terraform
Ansible
GitHub Actions
Istio
Rancher
GitLab CI
CI/CD
Jenkins
Git
Kubernetes
Service Mesh
IAM
Cybersecurity
SonarQube
Trivy
CIS Benchmarks
OWASP Top 10
SIEM
Cryptography
Vault
Apply
SOC Reporter 2 days ago
≈ $45k – $98k per year (Estimated) • In office • Full-Time • Warrington
Apply
≈ $45k – $98k per year (Estimated) • In office • Full-Time • Warrington
Apply
≈ $136k – $265k per year (Estimated) • Equity • In office • Full-Time • 5+ years exp • United States
SQL
Databases
Snowflake
Google BigQuery
BigQuery
AI/ML
Claude
Claude Code
Model Context Protocol
Prompt Engineering
AI Agents
DevOps
SLI/SLO/SLA
Robotics
Apollo
Management
n8n
Apply
$200k – $265k per year • Equity 0.1–0.2% • In office • Full-Time • 6+ years exp • Bachelor's Degree • New York
Python
TypeScript
Python
Django
Databases
MySQL
PostgreSQL
RabbitMQ
Apache Kafka
AI/ML
Fine-tuning
DevOps
Terraform
GCP
GitHub Actions
Azure
CI/CD
ArgoCD
Jenkins
AWS
Kubernetes
Amazon EKS
Google GKE
Azure AKS
Cybersecurity
ISO 27001
SOC 2
GDPR
Apply
≈ $60k – $170k per year (Estimated) • In office • Full-Time • 11+ years exp • Associate's Degree • Brussels
Python
JavaScript
DevOps
Rest API
Terraform
Ansible
Red Hat
CI/CD
Jenkins
Docker
Bitbucket
SLI/SLO/SLA
Linux
DNS
DHCP
Cybersecurity
Wireshark
PKI
Management
Agile
Apply
$21k – $28k per year • Remote (EAEU) • Moscow
PHP
PHP
Bitrix
AI/ML
Cursor
AI Agents
DevOps
SLI/SLO/SLA
Management
n8n
Apply
≈ $55k – $141k per year (Estimated) • Hybrid • Melbourne
DevOps
SLI/SLO/SLA
Apply
≈ $84k – $166k per year (Estimated) • Hybrid • Full-Time • London
Python
Java
Databases
Amazon Aurora
DevOps
Terraform
GCP
AWS CDK
GitLab CI
CI/CD
AWS
Shift-Left
AWS Fargate
AWS Lambda
Incident Management
GitLab
Amazon S3
IAM
Amazon ECS
Cybersecurity
Microsoft Sentinel
Zero Trust
Shift-Left Security
SIEM
Apply
≈ $131k – $246k per year (Estimated) • Hybrid • Full-Time • London
DevOps
FinOps
Apply
≈ $27k – $72k per year (Estimated) • Hybrid • Full-Time • 7+ years exp • Shenzhen
Python
Java
SQL
Python
SQLAlchemy
FastAPI
Uvicorn
Java
Liquibase
Databases
MySQL
PostgreSQL
DevOps
GCP
OpenTelemetry
Azure
Git
AWS
Docker
Platform Engineering
Apply
≈ $80k – $191k per year (Estimated) • Hybrid • Full-Time • London
Python
Python
Django
Pydantic
Databases
PostgreSQL
Frontend
GraphQL
Mobile
Clean Architecture
DevOps
GCP
Apply
≈ $39k – $63k per year (Estimated) • Hybrid • Full-Time • London
DevOps
GitHub
Marketing
LinkedIn
Apply
$106k – $199k per year • Equity 0.2–0.8% • In office • Full-Time • 1+ year exp • London
TypeScript
Databases
PostgreSQL
AI/ML
Red Teaming
Edge AI
Browser Agents
DevOps
Linux
Windows
Cybersecurity
Okta
ISO 27001
OWASP Top 10
SOC 2
Zero Trust
Microsoft Entra ID
Apply
≈ $66k – $156k per year (Estimated) • In office • Full-Time • Manchester • London • Cardiff • Edinburgh • Belfast
AI/ML
Recommender Systems
Apply
≈ $101k – $166k per year (Estimated) • Remote (United Kingdom, GMT hours) • Full-Time • London
AI/ML
Model Context Protocol
AI Agents
Ray
Cybersecurity
DLP
Management
Agile
Apply
≈ $13k – $32k per year (Estimated) • In office • 7+ years exp • London • Kuala Lumpur
Apply
Equity • In office • London
Apply
See all jobs
This is one of many
793,143 more open roles from verified company boards, updated every day.