Information Security Analyst II (GRC)
Job in
London, Greater London, W1B, England, UK
Listed on 2026-08-10
Listing for:
Checkout.com
Full Time
position Listed on 2026-08-10
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Our platform helps the most ambitious businesses deliver effortless digital experiences, you want to do career-defining work, you’ve come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we’re shaping the future of fintech – and we’re just getting started.
The Role As an Information Security Analyst II within the GRC team, you will take meaningful ownership of 's governance, risk and compliance programmes. This is a role for someone who has moved beyond task execution and is ready to drive work streams, lead compliance activities, and act as a trusted point of contact for internal teams and external assessors.
You will work across Checkout's core compliance frameworks including PCI DSS v4.0.1, ISO 27001, SOC 2, and emerging regulatory obligations such as DORA and the EU AI Act, supporting our global footprint across Europe, MENA, APAC, and the Americas. You will coordinate audit evidence activities, conduct risk assessments, improve GRC processes, and support the development of junior colleagues.
This role sits at the heart of how Checkout manages risk. We don't just audit and report. We own the risk narrative, drive the control environment, and ensure the business can grow with confidence in regulated markets worldwide.
How You'll Make an Impact Governance, Risk and Compliance Programme Management Own and manage defined work streams within Checkout's GRC programme, including PCI DSS v4.0.1, ISO 27001, SOC 2, and relevant regulatory obligations across our global licensed entities.
Coordinate control evidence collection activities across internal teams, ensuring continuous audit readiness rather than point-in-time preparation.
Maintain and improve GRC documentation including policies, standards, procedures, and control matrices, ensuring they stay current and proportionate to Checkout's evolving risk profile.
Perform gap analyses against new or evolving requirements including DORA and the EU AI Act, translating findings into prioritised remediation plans.
Support monitoring of the risk register, track remediation activity against agreed timelines, and escalate issues where commitments are duct third-party risk assessments, evaluating supplier security controls and compliance posture in line with Checkout's TPRM framework.
Audit and Assessment Support Act as a key liaison between internal teams and external auditors, QSAs, and assessors across PCI DSS, ISO 27001, IT General Controls (ITGCs) and SOC 2 certification cycles.
Prepare and deliver evidence packages, coordinate walkthroughs, and manage audit findings through to closure.
Support end-to-end response process for merchant assurance questionnaires and due diligence inquiries, ensuring all technical and regulatory queries are addressed with accuracy and within agreed SLAs.Support quarterly and annual compliance activities including vulnerability scanning, penetration testing coordination, access reviews, and firewall configuration reviews.
Policy, Controls and Regulatory Coverage Apply working knowledge of PCI DSS v4.0.1, ISO 27001/27002, SOC 2, DORA, NIST CSF, and other applicable frameworks to day-to-day GRC work.
Support meeting regulatory change across Checkout's operating markets including FCA/PRA requirements and payment scheme obligations, flagging gaps and supporting impact assessments.
Proactively identify inefficiencies in GRC processes and propose practical improvements, including automation where viable.
Contribute to the development and refinement of GRC tooling, dashboards, and reporting to…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×