About this role
Salary: £31,500 - 58,000 per year
Requirements: 2 to 4 years of experience in GRC, information security compliance, IT audit, or a closely related function, ideally within payments, financial services, or fintech.Practical working knowledge of PCI DSS v4.0.1, ISO 27001, and SOC 2.Familiarity with DORA, NIST CSF, or the EU AI Act is a plus.Experience supporting or directly managing external audits and assessments, including evidence collation and assessor liaison.Demonstrated ability to own a programme workstream independently, from planning through to delivery.Well-versed in risk management processes including risk identification, third-party risk management, and merchant due diligence.Clear written and verbal communication skills.Analytical and process-oriented mindset.Comfortable operating with ambiguity.Methodical and well-organised, with strong attention to detail and a consistent track record of delivering on commitments.Collaborative and pragmatic.Preferred certifications include CISA, CISM, PCIP, ISO 27001 Lead Implementer or Auditor, or equivalent.Familiarity with cloud environments (AWS, Azure, GCP) in a GRC or compliance context.Experience with GRC tooling, risk platforms, or compliance automation.Exposure to AI governance frameworks such as ISO 42001, EU AI Act, or NIST AI RMF. Responsibilities: Own and manage defined workstreams within our GRC programme, including PCI DSS v4.0.1, ISO 27001, SOC 2, and relevant regulatory obligations across our global licensed entities.Coordinate control evidence collection activities across internal teams, ensuring continuous audit readiness rather than point-in-time preparation.Maintain and improve GRC documentation including policies, standards, procedures, and control matrices.Perform gap analyses against new or evolving requirements including DORA and the EU AI Act, translating findings into prioritised remediation plans.Support monitoring of the risk register, track remediation activity against agreed timelines, and escalate issues where commitments are at risk.Conduct third-party risk assessments, evaluating supplier security controls and compliance posture in line with our TPRM framework.Act as a key liaison between internal teams and external auditors, QSAs, and assessors across PCI DSS, ISO 27001, IT General Controls (ITGCs), and SOC 2 certification cycles.Prepare and deliver evidence packages, coordinate walkthroughs, and manage audit findings through to closure.Support end-to-end response process for merchant assurance questionnaires and due diligence inquiries.Support quarterly and annual compliance activities including vulnerability scanning, penetration testing coordination, access reviews, and firewall configuration reviews.Apply working knowledge of PCI DSS v4.0.1, ISO 27001/27002, SOC 2, DORA, NIST CSF, and other applicable frameworks to day-to-day GRC work.Support meeting regulatory change across our operating markets including FCA/PRA requirements and payment scheme obligations.Proactively identify inefficiencies in GRC processes and propose practical improvements, including automation where viable.Contribute to the development and refinement of GRC tooling, dashboards, and reporting.Work closely with Engineering, Product, Legal, Procurement, and Finance to embed security and compliance requirements into processes, systems, and projects.Respond to PCI DSS, ISO 27001, and broader security-related due diligence requests from merchants, partners, and regulators.Provide guidance and day-to-day support to junior analysts (L1 and L2).Promote a security-first culture across our company through proactive engagement, awareness sessions, and accessible guidance for non-security teams. Technologies: AIAWSAzureCloudFirewallGCPSupportSecurity More:
Were Checkout.com, a global fintech company powering the digital payments behind experiences used by companies like eBay, Spotify, Klarna, Uber, and Sony. We process over 10 billion transactions a year for more than one billion shoppers, helping ambitious businesses deliver effortless digital experiences at scale. We have 20 offices across six continents, with our HQ in London, and this role is based in London in an onsite, full-time position. Our hybrid working model includes three days in the office each week: Tuesday, Wednesday, and Thursday, and we provide snacks, breakfast, and lunch in our locations on office days. We value high performers, real ownership, and meaningful work, and we aim to create a collaborative environment where people can grow and make an impact.
last updated 36 week of 2026