FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Security Governance, Risk, and Compliance (GRC) with a strong focus on automating compliance processes and integrating security frameworks. Proficient in translating compliance requirements into technical specifications while collaborating across teams to ensure effective implementation.
Highest-signal resume keywords
Security GRC ExperienceCloud Architecture UnderstandingAI and Automation ImplementationRegulatory Compliance FamiliarityCISM, CISSP, or CISA Certification
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Governance, Risk, and Compliance AutomationControl Testing AutomationEvidence Collection AutomationReporting Automation for GRC ProgramsMapping Infrastructure to Security ControlsAuditing ProcessesTechnical Specification TranslationDashboards and KPI ReportingPolicy as Code DevelopmentThird-Party Vendor Assessment Automation
Soft Skills
InitiativeCollaborationCommunication with Non-Technical StakeholdersIndependent Work
Tools & Technologies
AWSCloud PlatformsTicketing SystemsAsset Management Systems
Certifications & Qualifications
CISMCISSPCISAPCI-Related Credentials
Industry Keywords
FintechPayments IndustryCybersecurityCompliance FrameworksISO 27001PCI-DSSDORAUK Cyber EssentialsFinancial Services Regulations
Tech Stack
Tools & technologiesAWSCloudCyber Security
About the role
Key responsibilities & impact- Automate legacy systems related to governance, risk, and compliance frameworks, including ISO 27001, PCI-DSS, DORA, UK Cyber Essentials, and relevant financial services regulations
- Engineer GRC workflows integrating ticketing, asset management, identity, and cloud platforms to support compliance by design
- Design and build scalable GRC architectures and automation for evidence collection, control testing, and compliance reporting
- Draft, review, and maintain Pleo security policies and map them to relevant control standards
- Automate incoming security requests from customers and prospects, including questionnaires, one-off questions, review calls, and documentation
- Automate third-party vendor assessments and track resolution of identified gaps
- Automate compliance metrics and KPI reporting for leadership
- Translate compliance requirements into technical specifications for engineering teams and explain them to non-technical stakeholders
- Coordinate complex, multi-team workstreams and keep dependencies, priorities, and delivery on track
- Contribute to broader Cybersecurity team initiatives and shared security goals
- Report to the VP of Fraud & Security and collaborate with Risk and Compliance, Procurement, Legal, Finance, Engineering, and other teams
- During the first six months, learn Pleo's security landscape, build evidence-collection and control-testing automation, develop policy as code, and integrate with Cybersecurity workflows and tooling
Requirements
What you’ll need- Significant experience in Security GRC
- Understanding of auditing processes
- Direct experience in both internal and external audit cycles
- Demonstrated experience using AI and/or coding automation to build, implement, and operate controls
- Strong understanding of cloud architectures, such as AWS or equivalent
- Experience mapping infrastructure decisions to security controls and audit evidence
- Experience automating reporting for GRC programs, including dashboards and executive-level summaries
- Fintech, payments industry, or IT audit background
- Familiarity with regulatory expectations and payment platform architectures
- Certifications such as CISM, CISSP, CISA, or PCI-related credentials
- A degree in Cybersecurity, Engineering, Computer Science, or Mathematics, or equivalent experience, is a plus
- Ability to work closely with colleagues without engineering backgrounds
- Ability to work independently and take initiative
- Valid right to work in the selected country; Pleo cannot offer visa sponsorship
- Application must be submitted in English
Benefits
Comp & perks- Your own Pleo card
- Catered meals or a lunch allowance for work days
- Comprehensive private healthcare, depending on location (Vitality, Alan or Médis)
- 25–28 days of holiday depending on location, plus public holidays
- Hybrid and fully remote working options
- Option to purchase 5 additional days of holiday through salary sacrifice
- Free mental health and well-being support through MyndUp
- Paid parental leave
- Career development opportunities, including bigger projects, leadership, and acquiring new skills
