- Own and drive the end-to-end certification roadmap for ISO 27001, SOC 2 Type II, GDPR accountability framework, and PCI DSS Level 1, sequencing each programme to minimise organisational disruption and maximise control reuse across frameworks.
- Conduct thorough gap assessments for each framework — identifying missing controls, policies, and technical measures — and lead remediation to closure before each audit cycle.
- Build and maintain a living evidence library, risk register, and control mapping documentation aligned to each framework's requirements.
- Select, engage, and manage Qualified Security Assessors (QSAs) for PCI DSS, and external auditors and certification bodies for ISO 27001 and SOC 2.
- Act as the primary liaison between the organisation and all external auditors, certification bodies, and regulatory contacts throughout each certification cycle.
- Embed a culture of continuous compliance — establishing automated evidence collection, policy-as-code where appropriate, and recurring control validation cycles rather than point-in-time audit preparation.
- Maintain organisational awareness of framework updates (e.g. PCI DSS 4.0 requirements, ISO 27001:2022 controls) and adapt the programme accordingly.
2. Network, Infrastructure & API Security
- Develop and maintain physical and logical network diagrams, server topologies, and high-availability / disaster recovery solutions.
- Design and maintain a secure, segmented corporate network architecture aligned with zero-trust principles — including firewall rule-sets, VPN configurations, VLAN segmentation, and perimeter security controls.
- Liaise with the CTO on infrastructure dependencies between corporate IT and cloud environments.
- Own and govern the security standards for all API integrations with the card issuing partner and other payment infrastructure vendors, including authentication (OAuth 2.0 / mTLS), rate limiting, logging, and webhook validation.
- Ensure all payment-related API flows are logged, monitored, and covered by anomaly detection — in compliance with PCI DSS 4.0 API security requirements.
- Maintain the organisation's card program scope documentation — defining what cardholder data flows through internal systems and ensuring appropriate controls are applied.
- Verify that the card issuing partner's (e.g. Rain) PCI DSS attestation of compliance is current, documented, and reviewed on a defined schedule as part of the vendor assurance programme.
3. Observability & Monitoring
- Implement and maintain a SIEM (Security Information and Event Management) platform to provide centralised log aggregation, anomaly detection, and audit trail management — a core PCI DSS and ISO 27001 control.
- Define alerting thresholds, on-call escalation paths, and incident response runbooks for corporate IT systems.
- Ensure log retention meets the requirements of each certification framework (e.g. 12-month retention, 3 months immediately accessible for PCI DSS).
4. Endpoint Security & Device Management
- Deploy, configure, and maintain a Mobile Device Management (MDM) platform covering both Apple (iOS, macOS) and non-Apple (Windows, Android) devices using tools such as Jamf and Microsoft Intune.
- Enforce device compliance policies, remote wipe capabilities, app deployment, and OS update management.
- Own the full device lifecycle: procurement standards, enrolment, ongoing compliance monitoring, and decommissioning.
- Deploy and manage an Endpoint Detection & Response (EDR) solution across all endpoints — reviewing alerts, driving threat remediation, and maintaining coverage reporting as audit evidence for PCI DSS and ISO 27001.
- Ensure device security posture is documented and evidenced as a control within the ISO 27001 and PCI DSS certification programmes.
5. Identity, Access & Credential Management
- Administer the organisation's IAM platform (e.g. Okta or Microsoft Entra ID), including SSO, SCIM provisioning, and access workflow automation.
- Own automated joiner-mover-leaver (JML) workflows to ensure timely and evidenced onboarding and offboarding.
- Conduct semi-annual access reviews and enforce least-privilege principles — a mandatory control under ISO 27001, SOC 2, and PCI DSS.
- Enforce MFA across all users and integrate all SaaS applications via SSO/SCIM.
- Administer the organisation's password manager (Bitwarden) — including vault structure, collection permissions, user provisioning, and emergency access procedures — and enforce strong credential hygiene policies across all teams.
- Own the annual IT software budget — including forecasting, optimisation, and reporting to leadership.
- Manage the full SaaS licence lifecycle: procurement, renewal, consolidation, and cancellation across all business tools.
- Lead vendor evaluation, RFP processes, and contract negotiations to drive value and minimise risk.
- Maintain a tiered vendor risk register — with critical payment infrastructure vendors (e.g. card issuing partner, stablecoin settlement provider) subject to enhanced due diligence, ongoing SLA oversight, and annual compliance attestation reviews.
- Coordinate legal and finance teams on IT contract reviews and procurement approvals, ensuring all SaaS applications are integrated with SSO/SCIM for consistent access governance.
- Maintain awareness of the stablecoin and digital asset regulatory landscape (e.g. MiCA, FinCEN guidance) as it relates to vendor obligations and the card programme's compliance posture.
7. IT Operations, Planning & Administration
- Formulate the corporate IT and compliance certification roadmap, aligned to cost constraints, certification timelines, and business objectives.
- Own the IT cost centre — tracking spend, identifying savings, and presenting monthly reporting to leadership; define IT KPIs and report on infrastructure health, security posture, and certification progress.
- Day-to-day IT administration including user onboarding/offboarding, helpdesk escalation, hardware inventory management, and software licence tracking.
- Own and operate AV and conference room technology across office locations.
- Create and maintain detailed technical documentation covering infrastructure, runbooks, network diagrams, security policies, vendor contracts, and certification evidence artefacts.
Education
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field — or equivalent practical experience in lieu of a formal qualification.
Years of Experience
- 5–8 years of progressive experience in IT, cybersecurity, or information security roles.
- At least 2–3 years in a compliance, security management, or audit-facing capacity — ideally within a regulated industry (fintech, payments, financial services, or similar).
- Demonstrable experience owning or materially contributing to at least one compliance certification project (ISO 27001, SOC 2, PCI DSS, or equivalent).
Certifications (Desirable — not mandatory)
- CISM — Certified Information Security Manager (most directly relevant to this role).
- ISO 27001 Lead Implementer or Lead Auditor.
- PCI ISA — Internal Security Assessor (payments-specific; strong signal for PCI DSS ownership).
- CISSP — Certified Information Systems Security Professional.
- CISA — Certified Information Systems Auditor.
Candidates who have delivered compliance certifications without holding formal credentials are equally welcomed. Practical track record takes precedence over certification.
Skills & Experience Required
Compliance Certification Leadership
- Demonstrable track record leading or significantly contributing to ISO 27001, SOC 2, GDPR, and/or PCI DSS Level 1 certification programmes — ideally from gap assessment through to successful certification.
- Ability to run pre-audit readiness assessments, map controls across multiple frameworks, and manage auditor and QSA relationships.
- Familiarity with control overlap across frameworks (e.g. ISO 27001 SOC 2 PCI DSS) to deliver an efficient, integrated certification programme.
Network, Infrastructure & API Security
- Hands-on experience with network architecture design (physical, logical, HA/DR, zero-trust segmentation) and firewall, VPN, DNS, and VLAN management.
- Working knowledge of API security best practices (OAuth 2.0, mTLS, rate limiting, webhook signing, audit logging) and PCI DSS 4.0 API security requirements.
- SIEM platform experience (e.g. Splunk, Microsoft Sentinel, Datadog, or equivalent) — deployment, tuning, and alert management.
Endpoint Security & Device Management
- Hands-on MDM administration for Apple devices (Jamf Pro / Apple Business Manager or equivalent) and non-Apple devices (Microsoft Intune or equivalent).
- Experience with EDR solutions, endpoint compliance policies, conditional access, and zero-touch device provisioning.
Identity, Access & Credential Management
- Practical experience administering Okta, Microsoft Entra ID, or equivalent IAM platform — SSO, SCIM, MFA, and automated JML workflows.
- Experience conducting access reviews and enforcing least-privilege governance as an auditable compliance control.
- Experience administering Bitwarden or comparable enterprise password manager at organisational scale.
- Experience owning an IT or software budget — forecasting, optimisation, and executive reporting.
- Track record managing SaaS licence lifecycles, vendor contract negotiations, and a tiered vendor risk framework with heightened oversight for critical or regulated third parties.
- Experience reviewing PCI DSS attestations and managing compliance obligations for third-party payment infrastructure vendors.
Crypto / Stablecoin Awareness (Desirable)
- Familiarity with stablecoin or blockchain-based payment infrastructure and awareness of emerging regulatory requirements (e.g. MiCA, FinCEN, FCA digital asset frameworks)