NewPublic feed

GRC Security Specialist

Abound

London · United Kingdom

Published : Sep 27, 2026

Visa sponsorship mentioned

Every opportunity links to its original source. No employment guarantee.

About this opportunity

About Abound We’re redefining consumer lending in the UK, and beyond. Using advanced AI and Open Banking data, we make fair, affordable personal finance available to more people. While traditional lenders rely almost entirely on credit scores, we look at the full financial picture - how much you spend, and what you can afford to repay to build a deeper,…

Read the full description

About Abound We’re redefining consumer lending in the UK, and beyond. Using advanced AI and Open Banking data, we make fair, affordable personal finance available to more people. While traditional lenders rely almost entirely on credit scores, we look at the full financial picture - how much you spend, and what you can afford to repay to build a deeper, more accurate understanding of each customer's unique financial situation. And we've shown it works at scale.

We’ve issued over £1.3bn in loans directly to customers while delivering market-leading credit performance - for every 10 defaults the industry expects, we see only 3. We also reached profitability just 2.5 years after launch. Backed by £2bn+ of funding from top-tier investors including Citi, GSR Ventures, and Deutsche Bank, we’re recognised as one of Europe’s fastest-growing fintechs (Sifted, CNBC).

Now, we’re expanding into new markets and product lines - and we’re looking for ambitious people who want to learn fast, take ownership, and grow with us. The role We are formalising our security assurance function. We have technical controls and the engineering culture; what we need now is the governance layer that proves it - to our auditors, to our funders, and to our regulator. You will be the delivery engine behind that.

You will own the recurring assurance cycle end to end, run our third-party security programme, and be the person who turns evidence into something a due diligence team or a certification auditor can be satisfied by. You will be responsible for building controls, gathering evidence, and challenging suppliers. What you will own: 1.

Third-party security assurance - Run security due diligence on new suppliers, maintain initial questionnaire to risk sign-off, working with Procurement and Legal on security and data protection schedules. - Maintain a supplier tiering model based on criticality and run the periodic re-assessment cycle for tiered suppliers: certification expiry, subprocessor changes, breach notifications, SLA performance. - Maintain the supplier and outsourcing registers, including preparation for the FCA's material third party register under PS26/2 (rules in force 18 March 2027). - Track concentration risk and exit plans for critical suppliers. 2.

Inbound due diligence and customer assurance - Own our response to security due diligence from funders, banking partners, institutional investors, commercial partners and prospects. - Build and maintain a reusable trust pack: ans