Information Security Analyst

Summary

FundApps is hiring an Information Security Analyst in London to run the day-to-day of its ISO 27001 and SOC 2 programmes — access reviews, vulnerability management, vendor assessments, pen testing, incident response and security awareness — across a growing fintech SaaS business. Mindset and curiosity matter more than experience with specific security tools.

We are looking for a curious and hands-on Information Security Analyst to help keep FundApps secure, resilient and trustworthy as we continue to grow.

This role has a broad scope, as you will work across security operations, access reviews, vulnerability management, supplier assurance, security awareness, audits, incident response, risk management and the day-to-day running of our Information Security Management System.

As an Information Security Analyst, you will help operate and improve the controls that support our ISO 27001 and SOC 2 programmes, while also getting involved in the real security work that happens across a growing SaaS business. You will not be expected to know everything on Day 1, but you will be expected to learn quickly, ask good questions, follow through on details and help make security easier for everyone at FundApps.
  • Working with Engineering, IT, Legal, Finance and People to make security a helpful, trusted partner in the way FundApps builds, buys and operates technology.
  • Taking full, end-to-end ownership of FundApps’ ISO 27001 and SOC 2 controls operation, managing every stage from initial evidence collection and control checks through to remediation tracking and comprehensive audit preparation.
  • Organising and chairing monthly review meetings.
  • Partnering with Legal and Revenue to address security questionnaires and RFPs, ensuring our clients and prospects receive accurate, transparent, and timely answers about our security posture.
  • Directing the end-to-end planning and execution of penetration testing campaigns.
  • Managing and facilitating annual business continuity planning (BCP) exercises.
  • Assessing our vendors to ensure we accurately identify, evaluate, and mitigate any security risks brought in by outside partners.
  • Supporting vulnerability management across our estate, helping teams understand, prioritise and remediate issues rather than just logging them.
  • Monitoring security alerts, incidents and internal security events, escalating where needed and helping ensure issues are properly investigated, understood and closed out.
  • Supporting security awareness activities, including onboarding, refresher training, phishing reporting and practical guidance for colleagues.
  • Helping improve security documentation and processes so that our controls are easy to follow, repeatable and genuinely useful.
  • Recurring access reviews across key business systems, checking that permissions are correct and following up when something looks off.
  • Helping maintain FundApps’ Information Security Management System, including security objectives, risk registers, management review inputs and follow-up actions.
This role has a lot of freedom to solve problems in ways that achieve our outcomes and align with our values. You will be expected to take ownership of your work from Day 1, while being supported by experienced members of the Information Security team. To thrive at FundApps, you will need to be comfortable with uncertainty and embrace change as it comes. We value people who take charge of their destiny and help make things better for everyone around them

Background: You don't need deep experience with any particular security tool. We care far more about how you think and work than what you've used before. What matters is that you're genuinely curious: when something doesn't look right, you dig into it rather than accepting the first explanation. You ask questions until you actually understand a situation, rather than settling for a surface-level answer because it's quicker or easier. You’re comfortable saying "I don't know, let me find out" and you’re comfortable learning new ways of doing things.

Hands-on and thorough: You don't settle for the easy or convenient answer. If an access review throws up something odd, or a vulnerability report doesn't quite add up, you'll get into the detail, ask the awkward questions and follow the thread until you genuinely understand what's going on.

Work-with-purpose: You can articulate the value of your own work in the bigger picture. You understand that a third party review isn't just a task, it’s a way to surface risks and it's part of keeping FundApps and its clients safe. You're comfortable with ambiguity and evolving requirements.

Have-courage: You're comfortable asking for and giving feedback, and you're not afraid to say "I don't understand this, can you explain it" in front of others. You participate in debates, brainstorms and team conversations, and you build strong relationships with colleagues across the wider company.

Be-transparent: As a company, we value and aspire to transparency at all levels; you'll provide work updates to communicate regularly about progress and blockers and reach out for help when needed.

Raise-the-bar: You seek out opportunities to improve our workflows, processes and practices; 1% improvements over time improve things for everyone. You're the type of person who asks "why do we do it this way?" rather than just following a checklist.

Do-more-with-less: You identify and help implement improvements to processes and standards within the team, seek to optimise our workflows, and share ideas for how to automate manual tasks. As a company, we try to minimise meetings (we have meeting-free Wednesdays) and default to asynchronous written communication over long, multiple-person meetings.
Work Eligibility

We require candidates to have permission to work in the UK without visa sponsorship.

We work hybrid and ask that new FundAppers spend 3 days per week at our shiny London office during their first 6 months, to make the most of getting to know the business and other FundAppers.

After that, our policy is at least 2 days per week in the office to collaborate, connect and enjoy our shared space and team activities.


Life at FundApps

🕐 Work/life balance with flexible hybrid working
💚 Wellbeing benefits such as private health insurance, life insurance, a flexible stipend and mental health coaching
💰 Matched pension contribution up to 10%
💰 Peer micro-bonuses through Bonusly
🎓 £1,000 learning budget each year and unlimited professional development leave
💡 Peer-led ‘Brown-bag lunch’ learning sessions and an annual Learning Festival
🚢 25 days holiday leave + an extra day next year if you use it all + an extra day after 3 & 5 years
🧳 5 Years @ FundApps - additional 4 weeks paid holiday leave during your 5th year as a FundApper
👶 26 weeks leave for all new parents regardless of gender, location or family structure
❤️ Volunteering leave
🎁 Birthday off


👩🏾🌈👦🏼🌏👵🏼👳🏽👽

We are proud of the diversity of all FundAppers - it makes us strong. We provide flexibility around religious observances and embrace a variety of cultural celebrations! If you’re looking for a workplace where you can just be yourself, you’re in the right place.


Your Privacy

Any information you submit through our job application process will be used for the purposes of assessing your fit for a role at FundApps. We may also retrieve and store information from your public social media profiles for the same purpose. By applying for this position, you consent to your data being processed in accordance with the FundApps privacy policy.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available