Skip to main content
AfterDuty

Security Operations & GRC Manager

AccessFintech · London, Greater London

Type
Full-time
Posted
Today

Overview

This role directly leverages your operational command and incident response experience from policing. You have run major incidents, managed risk under pressure, and coordinated multi-agency responses — all of which translate into leading security operations, incident response, and client-facing security assurance. Your experience with evidence handling and compliance frameworks (PACE, RIPA) gives you a strong foundation for governance, risk, and compliance work, and your ability to engage confidently with senior stakeholders mirrors the client trust-building conversations this role demands.

About this role

AccessFintech is seeking a senior Information Security professional to join our Technology function. This is a broad remit spanning three areas — AFT's internal information security posture, our governance, risk and compliance programme, and the security relationship with AFT's client network.

As a capital markets technology provider handling sensitive financial data for over 250 institutions, client security confidence is as important as internal security rigour, and both rest on a well-run compliance and assurance programme. This role requires someone who can operate credibly across all three — running robust security operations, owning the certification and risk framework, and engaging directly with clients on security due diligence, assessments, and trust-building conversations.

You will report directly to the CTO and work closely with engineering, product, client operations, and solutions teams across all three jurisdictions.

Requirements*

1. Internal Information Security

  • Own and continuously improve AFT's information security posture across infrastructure, applications, cloud environments, and endpoints
  • Lead the operation and evolution of AFT's security tooling — SIEM, EDR, vulnerability management, intrusion detection, and identity and access management (IAM)
  • Own AFT's vulnerability management programme — regular assessments, remediation tracking, and risk reporting to the CTO and executive team
  • Lead security incident response — identification, containment, investigation, remediation, and post-incident review
  • Maintain and develop AFT's information security policies, standards, and procedures across all three jurisdictions
  • Embed security into AFT's software development lifecycle (SDLC) — partnering with engineering and DevOps to shift security left
  • Design and deliver security awareness training and communications across the global team

2. Client-Facing Security

  • Act as AFT's primary point of contact for all client security enquiries, assessments, and due diligence requests
  • Own the end-to-end response to client information security questionnaires — including standardised formats such as the Shared Assessments SIG and CSA CAIQ, as well as bespoke questionnaires issued by banks, custodians, and asset managers
  • Build and maintain a central answer library so questionnaire responses are consistent, accurate, and efficient to produce — reducing turnaround times and removing reliance on ad hoc drafting
  • Coordinate input from engineering, DevOps, legal, and compliance where questions fall outside the existing answer set, and quality-assure all responses before issue
  • Manage annual reassessments and periodic client re-certification cycles, ensuring responses remain current as the platform and control environment evolve
  • Represent AFT in client-facing security discussions, audits, and on-site or virtual security assessments — building confidence in AFT's security posture at senior level
  • Support the client onboarding process from a security and compliance perspective — ensuring new clients can satisfy their own internal security requirements for onboarding AFT
  • Partner with Client Operations and Solutions teams to proactively manage client security requirements as part of the commercial relationship
  • Maintain AFT's security documentation suite — trust centre content, security overview decks, penetration test summaries, and compliance certificates — keeping them current and client-ready
  • Track and manage client-raised security findings, ensuring remediation actions are progressed and communicated back to clients in a timely manner
  • Contribute to new business conversations where security posture is a factor — working with Sales and Solutions on RFP responses and client presentations

3. Governance, Risk & Compliance (GRC)

  • Own AFT's information security governance framework — policies, standards, and control documentation across all three jurisdictions
  • Own and maintain AFT's information security risk register — identifying, assessing, and tracking risks across internal and client-facing dimensions, with defined risk appetite and escalation thresholds
  • Own AFT's ISO 27001 and SOC 2 programmes end to end — control design, evidence collection, internal audit, gap remediation, and management of external auditors through certification and surveillance cycles
  • Maintain regulatory compliance mapping across UK (FCA, UK GDPR), US (SEC), and Israel (Privacy Protection Law), ensuring controls are traceable to obligations
  • Own the third-party and vendor security risk assessment programme — onboarding due diligence, ongoing monitoring, and contractual security requirements
  • Own the control testing and assurance calendar, ensuring controls are evidenced continuously rather than reconstructed at audit
  • Establish and run the security governance cadence — regular reporting to the CTO and executive team, translating technical risk into business-level insight
  • Lead preparation for external security audits, regulatory examinations, and client-initiated security reviews

Skills & Experience**Essential

  • 6–10 years of progressive experience in information security or cybersecurity, including at least 2 years in a client-facing or externally-engaged security role
  • Proven experience owning client information security questionnaires at volume — including standardised formats (SIG, CAIQ) and bespoke bank or custodian questionnaires — with a track record of building an answer library rather than responding ad hoc
  • Experience managing client-raised security findings through to remediation, and reporting outcomes back to client security teams
  • Demonstrable experience owning a GRC programme — running an ISO 27001 or SOC 2 certification cycle end to end, including evidence management, internal audit, and managing external auditors
  • Experience building and maintaining an information security risk register, with the ability to articulate risk appetite and escalate appropriately
  • Experience managing third-party and vendor security risk assessment programmes
  • Strong hands-on security operations experience — SIEM (e.g. Splunk, Microsoft Sentinel), EDR, vulnerability management (e.g.

About security roles for ex-police

Security management, operations and consultancy roles. Years of operational policing — command, incident response, public order — translate directly into corporate security, and employers in this sector actively rate police experience.

See all security jobs in London

Why this fits a police background — match score 85/100

  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Surveillance & covert work
  • Risk & threat assessment

What security roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Security officer (SIA)£24,000–£29,000
Security supervisor / team leader£28,000–£34,000
Site / security manager£38,000–£52,000
Regional / operations security manager£50,000–£65,000
Full security salary guide →

More security jobs for ex-police

  • Full-time

    Your operational policing background gives you exactly the composure and protocol discipline this role demands. Handling inbound calls, triaging incidents, and managing case files are second nature after years on response and control rooms, and your experience with multi-agency coordination and clear communication under pressure means you can step straight into this fast-paced environment without a lengthy re-training curve.

    Posted Yesterday

  • Your operational policing background gives you direct credibility in physical, personnel, and information security assurance, especially with government standards like HMG SPF and GovS007. You are used to managing risk, conducting audits, and writing clear reports, which are core to this role. Your experience in multi-agency coordination and incident response will help you build strong relationships with the Defence Security and Justice Account and advise practitioners effectively.

    Posted Yesterday

  • Security Officer

    ISS Facility Services · London

    Full-time

    Your policing background has given you a sharp eye for suspicious activity, the discipline to follow security protocols to the letter, and the composure to handle incidents calmly. You are already practised at managing access, conducting patrols, and interacting with the public in a professional, reassuring manner — all of which are central to this role.

    Posted Yesterday

  • SECURITY OFFICER

    Atos · London

    Full-time

    Your operational policing background gives you a natural command of risk assessment, incident response, and enforcing compliance with strict policies—exactly what this role demands. Coordinating security operations across business lines mirrors the multi-agency collaboration and incident management you handled on the job, and your ability to monitor and report KPIs aligns with your experience of objective-driven performance in high-pressure environments.

    Posted Yesterday