Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
FundApps is seeking an Information Security Analyst to help operate and improve controls supporting our ISO 27001 and SOC 2 programs. You will work across security operations, risk management, audits, and incident response while learning quickly in a growing SaaS business.
You will lead end-to-end control operation, collaborate with Legal and Revenue on security questionnaires, and support vulnerability management and security awareness activities.
Department: Operations
Employment Type: Full Time
Location: London, UK
Compensation: GBP 60,000 - GBP 65,000 / year
We are looking for a curious and hands-on Information Security Analyst to help keep FundApps secure, resilient and trustworthy as we continue to grow.
This role has a broad scope, as you will work across security operations, access reviews, vulnerability management, supplier assurance, security awareness, audits, incident response, risk management and the day-to-day running of our Information Security Management System.
As an Information Security Analyst, you will help operate and improve the controls that support our ISO 27001 and SOC 2 programmes, while also getting involved in the real security work that happens across a growing SaaS business. You will not be expected to know everything on Day 1, but you will be expected to learn quickly, ask good questions, follow through on details and help make security easier for everyone at FundApps.
This role has a lot of freedom to solve problems in ways that achieve our outcomes and align with our values. You will be expected to take ownership of your work from Day 1, while being supported by experienced members of the Information Security team. To thrive at FundApps, you will need to be comfortable with uncertainty and embrace change as it comes. We value people who take charge of their destiny and help make things better for everyone around them
You don't need deep experience with any particular security tool. We care far more about how you think and work than what you've used before. What matters is that you're genuinely curious: when something doesn't look right, you dig into it rather than accepting the first explanation. You ask questions until you actually understand a situation, rather than settling for a surface-level answer because it's quicker or easier. You're comfortable saying "I don't know, let me find out" and you're comfortable learning new ways of doing things.
You don't settle for the easy or convenient answer. If an access review throws up something odd, or a vulnerability report doesn't quite add up, you'll get into the detail, ask the awkward questions and follow the thread until you genuinely understand what's going on.
You can articulate the value of your own work in the bigger picture. You understand that a third party review isn't just a task, it's a way to surface risks and it's part of keeping FundApps and its clients safe. You're comfortable with ambiguity and evolving requirements.
You're comfortable asking for and giving feedback, and you're not afraid to say "I don't understand this, can you explain it" in front of others. You participate in debates, brainstorms and team conversations, and you build strong relationships with colleagues across the wider company.
As a company, we value and aspire to transparency at all levels; you'll provide work updates to communicate regularly about progress and blockers and reach out for help when needed.
You seek out opportunities to improve our workflows, processes and practices; 1% improvements over time improve things for everyone. You're the type of person who asks "why do we do it this way?" rather than just following a checklist.
You identify and help implement improvements to processes and standards within the team, seek to optimise our workflows, and share ideas for how to automate manual tasks. As a company, we try to minimise meetings (we have meeting-free Wednesdays) and default to asynchronous written communication over long, multiple-person meetings.
We require candidates to have permission to work in the UK without visa sponsorship.
We work hybrid and ask that new FundAppers spend 3 days per week at our shiny London office during their first 6 months, to make the most of getting to know the business and other FundAppers.
After that, our policy is at least 2 days per week in the office to collaborate, connect and enjoy our shared space and team activities.
We are proud of the diversity of all FundAppers - it makes us strong. We provide flexibility around religious observances and embrace a variety of cultural celebrations! If you're looking for a workplace where you can just be yourself, you're in the right place.
Any information you submit through our job application process will be used for the purposes of assessing your fit for a role at FundApps. We may also retrieve and store information from your public social media profiles for the same purpose. By applying for this position, you consent to your data being processed in accordance with the FundApps privacy policy.