Stand out for this role — generate a tailored resume and cover letter in about a minute.
Abound is formalising its security assurance function in London with a governance layer for auditors, funders and regulators. You will own the recurring assurance cycle end to end, manage third-party security programmes, and turn evidence into concise audit-ready material.
Essential experience includes 3+ years in information security assurance and hands-on ISO 27001. The role requires clear written English, collaboration with Procurement and Legal, and accountability for the assurance calendar
About Abound
We’re redefining consumer lending in the UK, and beyond. Using advanced AI and Open Banking data, we make fair, affordable personal finance available to more people. While traditional lenders rely almost entirely on credit scores, we look at the full financial picture - how much you spend, and what you can afford to repay to build a deeper, more accurate understanding of each customer's unique financial situation.
And we've shown it works at scale. We’ve issued over £1.3bn in loans directly to customers while delivering market-leading credit performance - for every 10 defaults the industry expects, we see only 3. We also reached profitability just 2.5 years after launch.
Backed by £2bn+ of funding from top-tier investors including Citi, GSR Ventures, and Deutsche Bank, we’re recognised as one of Europe’s fastest-growing fintechs (Sifted, CNBC). Now, we’re expanding into new markets and product lines - and we’re looking for ambitious people who want to learn fast, take ownership, and grow with us.
We are formalising our security assurance function. We have technical controls and the engineering culture; what we need now is the governance layer that proves it - to our auditors, to our funders, and to our regulator.
You will be the delivery engine behind that. You will own the recurring assurance cycle end to end, run our third-party security programme, and be the person who turns evidence into something a due diligence team or a certification auditor can be satisfied by.
You will be responsible for building controls, gathering evidence, and challenging suppliers.
The ISO 27001 ISMS, which we are building towards certification. You will draft and maintain control documentation, populate the Statement of Applicability, gather evidence, coordinate the internal audit programme and be a primary point of contact for our external auditor. The Head of Security owns the framework, scope, and risk appetite.
Policies and standards: you will draft, review and shepherd policies through approval, and track the review cycle.
Incident response: you will maintain the IR plan and playbooks, facilitate post‑incident reviews, track remediation actions, and support regulatory notification (ICO personal data breach reporting within 72 hours; FCA notification under Principle 11 / SUP 15.3).
Business continuity and DR: you will maintain the documentation and the testing evidence.
Secure development: you will help embed security requirements into the SDLC and support threat modelling sessions.
Data protection: you will support RoPA maintenance, DPIA completion and DSAR handling alongside Legal.
First 90 days: you know our supplier estate and have tiered it; the assurance calendar for the next 12 months is published and owned; inbound due diligence requests come to you and go out without the Head of Security rewriting them.
Six months: the trust pack exists and is being used; the risk register is live with owned treatment plans; ISO 27001 evidence collection is systematic rather than a scramble; the exception register exists.
Twelve months: supplier re‑assessment runs on a cadence without prompting; the material third party register is ready ahead of the March 2027 deadline; MI to the Risk Committee is trusted.