Point your AI agent at freehire and let it find you a job.

Get the CLI →

Finera

New

Senior GRC and Security Specialist

Posted 3 views
Discussion

Summary

Owns the governance, risk, and compliance function end to end at a payments company: building and maintaining the security control framework (PCI DSS, SOC 2, GDPR), managing audits and the risk register, vendor security due diligence, and security policies and training for merchants, partners, and regulators.

The Senior GRC and Security Specialist owns our governance, risk, and compliance function end to end building and maintaining the control framework, driving audit readiness, and providing the security assurance our merchants, partners, and regulators expect.

Responsibilities

  • Own and maintain the security control framework across PCI DSS, SOC 2, GDPR, and applicable payment-industry and regulatory obligations, keeping controls documented, evidenced, and audit-ready year-round
  • Plan and manage internal and external audits and assessments end to end -scoping, evidence collection, auditor liaison, and remediation tracking to closure.
  • Run the enterprise risk management process: maintain the risk register, conduct and document risk assessments, and report risk posture clearly to CISO.
  • Develop, maintain, and enforce security policies, standards, and procedures, and lead the security awareness and training programme across the company.
  • Lead third-party and vendor security due diligence, including assessments, contractual security requirements, and ongoing monitoring of key suppliers
  • Respond to customer and prospect security questionnaires and due-diligence requests, enabling enterprise sales by providing timely, credible assurance.
  • Partner with Engineering and Product to embed security and compliance requirements into the platform, SDLC, and change-management processes.
  • Support incident response and business-continuity planning from a governance and regulatory-reporting perspective.
  • Monitor the evolving regulatory and threat landscape and translate changes into actionable updates to controls, policies, and priorities

Requirements

  • BSc/MSc. Cyber Security, or Network Security
  • Experience in fintech, payments, or another highly regulated financial-services domain.
  • Familiarity with ISO 27001, PCI-DSS, NIST frameworks, and emerging payment regulations.
  • Experience implementing or managing a GRC tooling platform.
  • Exposure to vendor risk management and security assurance for enterprise sales cycles.
  • 5+ years in GRC, information security, or IT audit, with demonstrable ownership of a compliance framework in a regulated environment.
  • Strong working knowledge of PCI DSS, SOC 2, and GDPR, and experience preparing for and managing audits against them.
  • Proven experience running risk assessments and maintaining a risk register, with the ability to communicate risk to both technical and executive audiences.
  • Solid grounding in security controls, cloud security concepts (AWS/GCP), and secure software development practices.
  • Excellent written communication and documentation skills — able to produce audit-grade evidence and clear policies.
  • Ability to work independently and manage multiple compliance workstreams to deadline.

Nice to Have/ Preferred:
  • Experience in fintech, payments, or another highly regulated financial-services domain.
  • Familiarity with ISO 27001, NIST CSF / 800-53, and emerging payment regulations (e.g. PSD2/SCA, card-scheme mandates).
  • Track record supporting enterprise sales through security questionnaires, due-diligence calls, and trust/assurance documentation
  • Experience with vendor and third-party risk management programmes at scale.
  • Exposure to cloud security posture management and control automation

Benefits

  • Competitive salary package aligned with experience and market standards.
  • Medical Insurance starting from day 1.
  • Access to training resources and development opportunities that support your professional growth.
  • Well-stocked office with snacks, drinks, and refreshments available daily.
  • A multinational organisation that promotes a strong, collaborative culture
  • Regular team-building events and company activities that strengthen collaboration across teams.
  • Employee Recognition Program celebrating our "Employee of the Month" with special perks.

Skills

What Senior Security jobs ask for — and how much of it you have →
Apply

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available