
Lendable · London
ABOUT LENDABLE Lendable is on a mission to build the world's best technology to help people get credit and save money. We're building one of the world’s leadin...
Lendable is on a mission to build the world's best technology to help people get credit and save money. We're building one of the
world’s leading fintech companies and are off to a strong start:
So far, we’ve rebuilt the Big Three consumer finance products from scratch: loans, credit cards and car finance. We get money into
our customers’ hands in minutes instead of days.
We’re growing fast, and there’s a lot more to do: we’re going after the two biggest Western markets (UK and US) where trillions
worth of financial products are held by big banks with dated systems and painful processes.
1. Take ownership across a broad remit. You are trusted to make decisions that drive a material impact on the direction and
success of Lendable from day 1
2. Work in small teams of exceptional people, who are relentlessly resourceful to solve problems and find smarter solutions than
the status quo
3. Build the best technology in-house, using new data sources, machine learning and AI to make machines do the heavy lifting
We are looking for a proactive Security GRC Analyst to join our Information Security team. You will play a pivotal role in scaling
our security posture in a fast-paced, AI driven, cloud-native environment. You will be part of a growing team, where your voice
will be heard, and your ability to take ownership and drive initiative will directly shape our security culture and operational
resilience.
Your approach to GRC starts with the risk, not the checklist. Rather than chasing compliance for its own sake, you will identify
and assess the risks first, then collaborate with stakeholders to design pragmatic mitigations. You understand that compliance
doesn't drive the business; rather, it is the natural outcome of a mature security posture that actively works for the
organisation.
alignment with standards such as SOC 2, ISO 27001, and PCI-DSS, as well as regulator expectations and UK GDPR.
agentic threats - and support the team in driving practical, risk-first mitigation strategies.
collection, reducing manual overhead and moving the company toward a state of continuous audit readiness.
of partners and critical outsourced service providers.
technical security metrics into clear, risk-based narratives for internal stakeholders and external auditors.
culture of shared security responsibility across the organisation.
technical language and workflows to help align security controls with engineering realities.
helping to ensure a smooth, successful audit cycle.
experience working with compliance frameworks (e.g. ISO 27001, PCI-DSS, or SOC 2).
the ability to balance strict financial regulations with the operational agility of a fast-paced FinTech, ensuring security
controls protect the business without slowing it down.
stakeholders, understand their challenges, and translate them into business risks.
posture and drive change.
Drata).
productivity through automation.
1. Initial Chat all with a Recruiter
2. 15 minute Cognitive Assessment
3. 30 minute Hiring Manager call
4. 60 minute Technical Interview
5. 60 Culture-Add Interview
include regular opportunities for in-person connection through socials and off-sites
at select locations
Please note: The availability and details of specific benefits vary by location and role. For more information, please speak to
your Talent Partner.
Check out our blog!
Third Party Risk Analyst - London, 12 Months FTC Pay.UK maintains and develops the UK retail payment systems and standards that are core to the economy. From Bacs to Faster Payments and cheques, we act as the single operator for UK retail payments, working in the public interest to ensure safe, open, innovative and resilient systems. Pay.UK maintains and develops the UK retail payment systems and standards that keep the economy moving, processing over 11 billion transactions worth more than £10 trillion each year. In this role, you will build practical third party risk experience by working end to end on supplier assurance across systems that millions of people and businesses rely on every day. We are seeking a Third Party Risk Analyst to join our Procurement team on a 12 month fixed term basis, reporting to the Senior Third Party Risk Manager and supporting effective risk oversight across critical supplier relationships. ACCOUNTABILITIES The role incorporates the following key responsibilities. * Support end to end execution of supplier assurance reviews, including criticality assessment, supplier tiering and gap analysis. * Issue, manage and assess Third Party Assurance Questionnaires across key risk domains including cyber security, data protection, operational resilience and business continuity. * Evaluate supplier responses and evidence to assess control design and effectiveness, documenting findings and residual risk. * Produce clear Third Party Assurance Reports, including issues, remediation actions and timelines. * Act as Pay.UK’s operational point of contact with suppliers during assurance activity, including evidence collection and scheduling. * Engage internal subject matter experts to validate evidence, challenge responses and escalate issues where required. * Maintain accurate supplier and risk data within the GRC tool and provide first line support to suppliers. * Monitor the supplier threat landscape using external intelligence and data sources. * Support commercial managers by ensuring identified risks are addressed, tracked and closed. * Prepare regular functional risk reports that summarise supplier assurance results, key risk themes, and remediation progress, and present clear insights to governance forums to support informed decisions. QUALIFICATIONS, SKILLS AND EXPERIENCE To perform well in this role you will demonstrate the following experience and capabilities. * Degree or equivalent experience in a relevant field such as risk management, business, information security, procurement or law. * Understanding of third party risk management and UK regulatory expectations relating to outsourcing and supplier assurance. * Solid analytical skills with experience performing gap analysis and interpreting technical risk information. * Experience working in a controls driven environment with governance, audit and evidence based assessments. * Professional certifications are beneficial but not mandatory, including CTPRP, IRM, CRISC, CISSP, ISO 27001, CIPP/E or CIPS. PAY.UK BEHAVIOURS At Pay.UK, our behaviours are central to who we are and how we operate. They bring our values to life, shape our culture, and guide how we make decisions, collaborate, and respond to challenges across the payments ecosystem. All interview processes will assess the following behaviours: * Listen to Find Win-Wins - Empathy, Listening and Understanding * Influence with Courage - Influence, Courage * Go Horizontal First - Cross Boundary Collaboration * Take Ownership - Self Development * Opportunity Mindset - Initiative * Simplify - Achievement Orientation ---------------------------------------------------------------------------------------------------------------------------------- INCLUSIVITY At Pay.UK, we value diversity and inclusivity. Research has shown that candidates from underrepresented groups may hesitate to apply unless they meet all the requirements listed. We encourage all qualified candidates to apply, regardless of how closely their skills and experience match the requirements. We are committed to supporting accessibility needs and creating a welcoming environment for all employees. Become part of our team and contribute to the creation of an inclusive work environment that values everyone's unique input. ---------------------------------------------------------------------------------------------------------------------------------- WHO WE ARE Pay.UK maintains and develops the UK retail payment systems and standards that are core to the economy being able to function on a day-to-day basis. From Bacs to Faster Payments and cheques – we act as the single operator for all UK retail payments. We put the needs of consumers and businesses at the heart of everything we do, working in the public interest to ensure that the systems the country relies on for its banking transactions are safe, open, innovative and resilient. Our payment systems underpin the services that enable funds to be transferred between people and institutions. In 2024, the UK's retail payment systems processed 11 billion transactions worth over £10 trillion through Bacs Direct Credit, Direct Debit, Faster Payments, and cheques, and our Current Account Switch Service has facilitated over 9 million switches since it’s launch in 2013. Every day, individuals and businesses use the services we provide to get their salaries, pay their bills and make online and mobile banking payments. Our vision for the future is to enable a vibrant economy, with Pay.UK delivering robust payment infrastructure and standards for the benefit of consumers and businesses nationwide. Learn more about life at Pay.UK by hearing what employees have to say, click here to view videos. ---------------------------------------------------------------------------------------------------------------------------------- BENEFITS & ADDITIONAL INFORMATION * 12% Non-contributory pension * Discretionary annual bonus * 30 days annual leave (excluding bank holidays) * Private medical insurance, life assurance, income protection, health cash plan, dental insurance, Bupa medicals etc * Employee assistance programme * Cycle to Work Scheme * Season ticket loan * Annual fitness subsidy of up to £500 per annum * Working from home policy - minimum 40% in the office (eg. 2 days in the office over a 5 day working week) Please note: * Some of our benefits are only available to colleagues after meeting the requirements of the probationary period. * Pay.UK employee benefits are not available to contractors and are only available to permanent and fixed-term employees.
ABOUT US Humaans is building the next generation of infrastructure for the workplace; software designed for companies that are scaling fast, operating globally, and pushing into new boundaries. What started as a system of record has evolved into a broader platform for operating people globally. With Athena, our agentic AI layer, Humaans moves beyond data management into intelligent orchestration, connecting workflows across HR, IT, Finance, and Operations so organisations can act faster and with greater confidence, redefining how work gets done. We work with ambitious teams across Europe and the US, from AI-native companies like Lovable, Poolside, Fyxer AI, and Tandem Health, to established, high-growth organisations scaling internationally and through acquisition, including Quantexa, Sellpy, Manychat, Gigs, Croud, and Threecolts. These teams don’t buy software for features,they buy leverage. The ability to run faster, cleaner, and with more control as complexity compounds. To date, we’ve raised $20m in venture funding from some of the most respected founders, operators, and funds in technology: Lachy Groom (Physical Intelligence), Stewart Butterfield (Slack), Tobias Lütke (Shopify), Dylan Field (Figma), Jeff Weiner (LinkedIn), Claire Johnson (Stripe), Oliver Jay (OpenAI), Jay Simmons (Bond) as well as Y Combinator, Moonfire, Frontline Ventures, Pathlight Ventures, and Exor. If you have massive ambition and want to work on a hard problem, with a small team that moves fast, at a moment when the category is genuinely up for grabs - this is it. GRC AT HUMAANS We're looking for a Security GRC Manager to own the systems, processes, audits, and customer-facing trust work that help Humaans scale into more demanding markets. This is a hands-on ownership role, built around AI. You'll run our security compliance programme throughout the year, not just during audit season. AI is how the work gets done here. It drafts policies, speeds up questionnaire responses, and keeps evidence current. You already use these tools daily and know how to get real leverage from them. You'll own the operating rhythm for frameworks like ISO 27001, SOC 1, SOC 2, HIPAA and future standards that matter to our customers. You'll keep evidence organised, controls running, policies up to date, vendors reviewed, risks visible, and audits moving smoothly. Own the commercial trust layer. Security questionnaires, enterprise diligence, vendor reviews; fast, accurate, reusable. You'll be in the room with enterprise buyers; on calls, in reviews and procurement threads, ensuring security won't be the reason a deal slows down. This role sits at the intersection of Security, Legal, Product, Engineering, Revenue, and Operations. You don't need to be the person configuring every system yourself, but you do need to understand how modern SaaS companies operate, ask sharp questions, drive action across teams, and keep the bar high. Humaans has a trust function that helps us win. In this role, you'll ensure evidence is stronger, controls are cleaner, questionnaire turnaround is faster, ownership is clear. Security compliance is a commercial asset and enabler to growth. FOCUS / OWNERSHIP * Own Humaans' security compliance programme end-to-end, including ISO, SOC 1, SOC 2, HIPAA and future frameworks we choose to pursue. * Run audit cycles throughout the year, coordinating with external auditors, internal control owners, Engineering, People, Legal, Finance and Operations. * Maintain the controls, evidence, policies, risk register, access reviews, vendor reviews, business continuity processes, and incident response documentation that support our certifications and customer commitments. AI drafts and updates these artefacts and keeps evidence current year-round, not only at audit time. * Lead customer-facing trust work, including sales calls, security reviews, procurement processes, vendor questionnaires, RFPs, DPAs, subprocessors, data protection questions, and enterprise diligence. * Build AI-assisted systems for answering repeated security questions quickly and accurately. The answer bank drafts responses. Trust collateral stays current. A review process holds quality as volume scales. * Partner with Product and Engineering to translate compliance requirements into practical operational controls without slowing the company down unnecessarily. * Help the company make clear, risk-based decisions, escalating when something matters and cutting through noise when it doesn't. * Raise the maturity of how Humaans thinks about security, privacy, risk, and customer trust as we move upmarket. REQUIREMENTS * 4+ years of experience in security compliance, GRC, trust, audit, information security, privacy operations, or a closely related role. * Hands-on experience running or supporting audits across SOC 2, ISO 27001, SOC 1, HIPAA, GDPR, or similar frameworks. * AI is already part of how you work. You can point to what you built and what it changed; drafting policies, accelerating questionnaire responses, reviewing vendor documentation. * Direct experience supporting enterprise sales, procurement, RFPs, or security reviews. You can lead sales calls, answer security questions clearly, and give buyers confidence. * Strong written communicator. Crisp policies, questionnaire responses, audit narratives, internal guidance that people actually read. * Deep understanding of how modern B2B SaaS companies operate; cloud infrastructure, access management, vendor management, product development, customer data and enterprise sales. * Organised and detail-oriented. Evidence, control owners, audit timelines and customer commitments. * You know the difference between meaningful risk reduction and compliance theatre. * Able to work across teams and hold a high bar without becoming a blocker. * Energised by a high-growth, high-ownership environment where the playbook is still being written. * Built or owned a trust centre, customer-facing security portal, or security questionnaire answer library. This is an in-person role. Our team comes together in the office Monday through Thursday, while most of the team collaborates in person on Mondays, Tuesdays, and Thursdays. PACKAGE & BENEFITS Early stage startups can be messy – we know that. We're putting effort in providing you with the best employee experience and a quality driven environment in exchange for trusting us. * Market-leading compensation that reflects your value * 25 days paid time off each year plus public holidays * Share Options with 5-year exercise window so you don’t feel pressure to exercise if you leave * Free Thursday lunches at HQ, quarterly team events, and company offsites. * Top tier private coverage for health, vision and dental care * A new MacBook and tools you need to do your best work * Enhanced parental leave with up to 16 weeks for primary and 4 weeks for secondary * Learning & development budget WHY JOIN HUMAANS TODAY? HR tech is having its AI moment and we’re positioned to own it. Humaans started as a next-gen HRIS taking on large incumbents in a massive market. We’ve since evolved into something even bigger: an AI platform that sits across workforce data and automates the operational layer of HR entirely; the natural progression of what we’ve been building toward. The product is highly differentiated. It’s built around a structured workforce data model that makes AI reliable in an HR context, something no one else has gotten right. Customers notice the difference immediately. We’re backed by Y Combinator, Lachy Groom, Moonfire, Frontline Ventures, and operators who’ve built some of the most consequential software companies of the last decade: the founders of Slack, Figma, and Shopify, and Asana’s former CRO and Head of OpenAI International. We’re a small team with an unapologetically high bar. It shows up in the product, in how we communicate, and in the standards we hold each other to. OUR COMMITMENT TO DIVERSITY At Humaans we’re looking for genuinely good people that are transparent and emphatic. We’re committed to providing equal opportunities, a diverse and inclusive work environment, and ensuring a fair interview process for everyone. You’re welcome to apply no matter your gender, ethnicity, sexual orientation, religion, civil or family status, age, disability, or race. PRIVACY NOTICE We care about your privacy. When you apply for a role at Humaans, we’ll collect and process your personal data as part of our recruitment process. This includes things like your CV, contact details, and any other information you choose to share. We may also contact you about future opportunities. You can ask us to delete your data at any time. For more details, see our Privacy Policy.
Location: London, UK Weekly office requirement: Hybrid – 2 days per week Employment type: Permanent Seniority level: Mid-Senior At GWI we're always looking for extraordinary people who thrive on making an extraordinary impact. Right now we're looking for an Information Security GRC Specialist to play a key role in our Legal team in London. If that's you, and making a difference gets you out of bed in the morning, keep reading. It could be the start of something, well, extraordinary. SOUNDS GREAT, WHAT WILL I BE DOING? 🤔 As our Information Security GRC Specialist you'll play a pivotal role in shaping the future of security compliance at GWI. Reporting into our General Counsel and working closely with our Information Security, Product, and Technology teams, you'll own our compliance posture across security frameworks, vendor risk, and client-facing security requirements — while building a security-conscious culture across the business. A few things you'll be responsible for: 👉 Own and maintain GWI's ISO 27001 certification and compliance across relevant security frameworks, keeping our posture sharp as the threat landscape evolves. 👉 Develop, implement, and maintain information security policies and procedures aligned with industry best practices. 👉 Lead vendor risk management and client security assessments — including responding to client security questionnaires and onboarding requirements. 👉 Build and maintain GWI's security trust portal, showcasing our credentials to clients and stakeholders using tools such as Drata or Vanta. 👉 Drive security awareness across the business through training programmes and internal communications that promote a strong GRC culture. It's also fun; shaking things up is what working for GWI is all about. You'll need to be flexible, comfortable with continuous change, and working in a high-tempo environment. WHAT DO I NEED TO BRING WITH ME? 🧳 You'll need to be able to demonstrate the core skills this role requires. You don't have to tick all the boxes right away; the important thing is that you're willing to learn. Here's what the team will be looking for in you: 👉 In-depth, practical experience obtaining and maintaining ISO 27001 certification, with solid knowledge of frameworks such as NIST — typically 3–5 years in an information security compliance role, though other experience levels will be considered. 👉 Proven ability to develop and maintain security policies and procedures that align with industry best practice. 👉 Experience conducting vendor security assessments and managing client security onboarding requirements, balancing risk against commercial objectives. 👉 Hands-on experience building or maintaining a security trust portal; familiarity with tools such as Drata or Vanta is a plus. 👉 Knowledge of SaaS and AI environments, with experience implementing and managing cloud security best practices. 👉 Strong communication skills — able to translate complex GRC topics into clear internal guidance and keep the wider business informed and engaged on security matters. Equally important is attitude. We want people who think big (to make an impact), ask why (to find a better way), and show respect (to everyone, at every level, all the time). Those are our values, and they're a big part of what we're looking for in you. WHAT WE OFFER 🧘 At GWI, you’ll find meaningful work, visible impact, and a culture that empowers you to do your best. Our package includes: * Time to recharge – 25 days’ annual leave, plus office closures over the holidays. * Health & wellbeing – Health cash plan, enhanced family benefits, carer days, and mental health support. * Financial benefits – Competitive salary, 4% pension matching, and recognition programs that celebrate success. * Flexibility & balance – Flexitime, early Friday finishes, hybrid and remote options, plus a “work from home” budget. * Career growth – Accredited learning, leadership development, and global career mobility. * Community & impact – DE&I initiatives, volunteering opportunities, donation matching, and payroll giving. Put all that together and GWI is the friendliest, most fulfilling place any of us has ever worked. DIVERSITY, EQUITY & INCLUSION 🫶 Diversity is fundamental to who we are—both as a data company and as a workplace. Our data reflects global realities, and so must our teams. We strive to ensure our workforce is as diverse and inclusive as the insights we provide to our clients. As a Disability Confident employer, we welcome applications from disabled candidates and are committed to providing all necessary adjustments during the hiring process. We also actively encourage applications from underrepresented and marginalized communities. At GWI, you will find a place where you can contribute meaningfully, grow professionally, and belong fully. #li-hybrid #LI-NIKOSSS1