About the Role
We are looking for a proactive Security GRC Analyst to join our Information Security team. You will play a pivotal role in scaling our security posture in a fast-paced, AI driven, cloud-native environment. Your approach to GRC starts with the risk, not the checklist. You will identify and assess risks first, then collaborate with stakeholders to design pragmatic mitigations.
Responsibilities
- Help maintain, improve, and scale security compliance programmes, ensuring alignment with standards such as SOC 2, ISO 27001, and PCI-DSS, regulator expectations, and UK GDPR.
- Collaborate on identifying security risks, including emerging risks from AI-driven and agentic threats, and support the team in driving practical, risk-first mitigation strategies.
- Utilise security compliance platforms to orchestrate automated evidence collection, reducing manual overhead and moving toward continuous audit readiness.
- Conduct vendor and third-party security risk assessments to evaluate the security posture of partners and critical outsourced service providers.
- Turn technical security metrics into clear, risk-based narratives for internal stakeholders and external auditors.
- Support the delivery and promotion of security awareness initiatives to help drive a strong culture of shared security responsibility.
- Engage in conversations with engineers, developers, and IT teams to align security controls with engineering realities.
- Participate in external audits and assessments by gathering evidence and preparing documentation.
Requirements
- 5+ years of experience in a related role (ideally within a regulated, cloud-native business or FinTech).
- Strong, foundational understanding of security risk management principles.
- Hands-on experience working with compliance frameworks (e.g. ISO 27001, PCI-DSS, or SOC 2).
- Ability to balance strict financial regulations with the operational agility of a fast-paced FinTech.
- Outstanding communication skills with a proven ability to converse with technical stakeholders, understand their challenges, and translate them into business risks.
- Highly proactive and self-motivated mindset.
- Direct, practical experience working with modern security compliance and automation platforms (such as Vanta or Drata) is desirable.
- Experience with Python or a similar programming/scripting language, and/or using AI to improve productivity through automation is desirable.
Skills
- Security Risk Management
- Compliance Frameworks (ISO 27001, PCI-DSS, SOC 2)
- Third-Party Risk Management (TPRM)
- Security Compliance Platforms (Vanta, Drata)
- Python
- AI Automation
Location
- Remote
- Hybrid
Work Type
- Hybrid
- Remote
- Full-time
Experience Level
- 5+ years
Benefits
- Flexible working
- Private health cover
- Retirement savings plans
- Employee referral programme
- Complimentary lunches
- Cycle-to-work schemes
- Electric vehicle salary sacrifice schemes
About the Company
- Lendable is on a mission to build the world's best technology to help people get credit and save money.
- One of the UK’s newest unicorns with a team of just over 700 people.
- Among the fastest-growing tech companies in the UK.
- Profitable since 2017.
- Backed by top investors including Balderton Capital and Goldman Sachs.
- Loved by customers with the best reviews in the market (4.9 across 10,000s of reviews on Trustpilot).
- Rebuilt the Big Three consumer finance products from scratch: loans, credit cards and car finance.
- Get money into customers’ hands in minutes instead of days.
- Going after the two biggest Western markets (UK and US) where trillions worth of financial products are held by big banks with dated systems and painful processes.
