Location: Remote First; office location Moorgate, London (flexible remote working locations within UK/Europe)
Employment type: Permanent (open to contract as well)
Working Hours: Full-time (UK 9-6)
Salary: dependent on experience up to £75,000 + Shares + Benefits
We are hiring to enhance our Security and Compliance efforts. In this role, you will work closely with Security Compliance, Senior Leadership, and Site Reliability Engineering to support our GRC initiatives.
We provide a low-latency, high-throughput distributed messaging system to the e-trading Fixed-income markets. We are, foremost, a technology service provider and support for part of our customers’ trading infrastructure.
You will help maintain positive customer relationships by handling compliance questions and ensuring our security practices are effective and up to date.
Here’s what you’ll be doing:
Stakeholder Communication and Reporting: respond to customer security questionnaires and produce management reports on security compliance and metrics for relevant committees.
Contribute to and Improve Compliance Programmes: contribute to internal control evaluations and testing to ensure adherence. Ensure compliance with industry standards such as GDPR, DORA, NIS2, ISO 27001, and SOC 2. Coordinate responses to internal and external audits, and support security assessments, including third-party penetration tests.
Risk Management and Issue Resolution: contribute to the maintenance of the risk assessment process to identify, evaluate, and mitigate potential risks. Triage security issues and provide recommended solutions.
To be successful in this role, we require:
4+ years of experience in security compliance, GRC, or infosec roles
Experience answering complex compliance questionnaires, ideally from Banks or highly regulated organisations
Experience in developing and implementing information security policies, standards and procedures
Experience leading ISO27001 and SOC 2 certification processes
Familiarity with standards and frameworks such as ISO 27001, SOC 2, NIST CSF, as well as legal frameworks such as DORA, NIS2, and GDPR
Bonus points if you:
Have experience working with Vanta or similar GRC automation tools
Can comprehend penetration test and vulnerability scan results
Have startup experience or experience working in a fast-moving environment
Are comfortable using technical tools, CLIs, or basic scripting to improve compliance workflows
Skills Required
- 4+ years of experience in security compliance, GRC, or information security roles
- Experience answering complex compliance questionnaires, ideally for banks or highly regulated organizations
- Experience developing and implementing information security policies, standards, and procedures
- Experience leading ISO 27001 and SOC 2 certification processes
- Familiarity with ISO 27001, SOC 2, NIST CSF, DORA, NIS2, and GDPR
- Experience with Vanta or similar GRC automation tools
- Ability to comprehend penetration test and vulnerability scan results
- Startup or fast-moving environment experience
- Comfort using technical tools, command-line interfaces, or basic scripting to improve compliance workflows
What We Do
TransFICC is an e-trading technology company, providing connectivity and workflow solutions for banks and asset managers operating in the Fixed Income and Derivatives markets. Its "One API for eTrading" product provides clients with an alternative to maintaining connectivity with multiple e-trading venues. By delivering low-latency, scalable and secure connectivity, TransFICC resolves the issues of market fragmentation, market data throughput, and increased regulation. TransFICC does three things: - It translates Execution Venue API’s to a single API. Clients connect once to TransFICC's unified API, and TransFICC manages connectivity with the electronic venues from that point. - It uses low-latency, scalable and secure technology, essential to keep pace with price updates and not get beaten to a trade by high frequency trading firms. - It provides timestamps for price and order messages. Measured in microseconds, timestamps record when data arrives at the bank or asset manager, helping to provide an audit trail, which supports Best Execution.









