- Company Name
- Funding Circle UK
- Job Title
- Security Engineer
- Job Description
-
**Job Title:** Security Engineer
**Role Summary:**
Lead and evolve the third‑party risk management program and company‑wide security awareness initiatives while providing hands‑on support to security operations. Act as a primary contributor to internal and external audits, analyze security metrics, and support incident response with risk context. Maintain up‑to‑date knowledge of threats, regulations, and industry standards to strengthen the organization’s security posture.
**Expectations:**
- 4+ years of hands‑on experience in cyber risk, GRC, or information security.
- Proven ability to conduct risk assessments, manage audit processes, and influence stakeholders across procurement, legal, and compliance.
- Strong communication skills for translating technical risk concepts to non‑technical audiences.
- Pragmatic, business‑focused approach to risk management and continuous improvement.
**Key Responsibilities:**
- Design, implement, and maintain the Third‑Party Risk Management (TPRM) program, including vendor risk assessments.
- Develop, deliver, and continuously improve the security awareness training program.
- Support security operations tasks such as incident triage, analysis, and day‑to‑day duties.
- Contribute to internal and external audit preparation, evidence gathering, and response formulation.
- Track, analyze, and report on security metrics and key risk indicators (KRIs) to guide strategic decisions.
- Provide risk context for incident response activities and ensure alignment with overall risk posture.
- Stay current on emerging threats, regulatory changes, and industry best practices.
**Required Skills:**
- Deep knowledge of ISMS and security frameworks (ISO 27001, NIST CSF, SOC 2).
- Expertise in risk assessment methodologies and risk lifecycle management.
- Experience applying security policies, standards, and controls across an organization.
- Proven experience managing or contributing to a TPRM program.
- Strong audit management skills (internal and external).
- Excellent written and verbal communication; ability to influence cross‑functional teams.
- Collaborative mindset with ability to build relationships with procurement, legal, and compliance stakeholders.
- Familiarity with security operations tools (SIEM, EDR) and GRC/TPRM platforms is a plus.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Preferred certifications: CISM, CRISC, CISA, CISSP.
- Additional certifications or experience with GRC tools, automation of compliance evidence, or FinTech/regulatory environments are advantageous.