LHV Bank, a fully licensed UK bank, specialises in Banking Services for global fintechs and SME Lending solutions for UK businesses. The SME Lending division offers commercial real estate investment loans and trading loans from £0.5m to small and medium-sized businesses in the UK.

As a leading Banking Services provider, LHV Bank delivers a wide range of services, including real-time multi-currency payments, accounts, acquiring, indirect scheme access, open banking, and FX solutions. Over 200 renowned fintech companies, such as Airwallex, Currencycloud, Truelayer, and Wise, utilise LHV Bank to serve more than 10 million end customers and access a pool of 500 million potential customers across the UK and Europe.


LHV Bank gained its UK banking licence in May 2023 and launched into the retail savings market through deposit aggregators in August 2023. It is in the process of developing its direct to customer retail banking proposition for launch in 2024. More information: lhv.com

We are currently looking for an Information Security GRC Analyst who will help shape our cybersecurity posture. You will be central to identifying and mitigating security risks, ensuring compliance with regulatory requirements, and developing robust security frameworks.

You will also be tasked with managing data privacy, crafting business continuity plans, and leading our security awareness initiatives. This position offers a unique opportunity to safeguard our digital infrastructure and contribute significantly to our overall security strategy.

Please note that we are asking the successful candidate to be in our London Office 2-3 days a week

Duties and responsibilities:

Third party security (clients, partners and suppliers)

  • Manage and maintain client due diligence questionnaires on behalf of InfoSec and IT to include maintaining repository of responses and ensuring timely responses to requesting team
  • Support with onboarding new suppliers as part of Project Management and Supplier Risk Management maintaining and reviewing third party questionnaires, collating responses, identifying gaps within baselines controls and proposing recommendations where appropriate
  • Respond to due diligence questionnaires to assist with client onboarding

Information Risk Management

  • Work closely with ERM and Audit and other teams where required to ensure risks are managed within risk appetite and audit findings are closed within an agreed timeframe.
  • Demonstrated expertise in implementing risk frameworks and applying risk management principles.

 Maintain Policies and standards

  • Maintain ISMS related policies, guidance, and procedures to include document management, version control.
  • Support the design and execution of the Information Security Governance, Risk and Compliance roadmap.

Consulting with the business to identify risks and implement mitigations and actions

  • Work with IT Security Operations and IT in general to ensure that baseline security processes are documented and followed in line with ISO27001 and regulatory requirements
  • Information security incident management liaising with Security Operations Team to include reporting, advising, response and escalation to management
  • Advise IT with managing technical risks & issues through vulnerability management oversight, gap analysis and ensure that findings are documented and assigned for remediation
  • Manage DLP related incidents and support with policy changes of DLP tool

 Data Privacy

  • Develop the Personal Information Management System (PIMS) in line with ISO 27701
  • Conduct DPIA’s, Article 30 (record of processing activity), data privacy notice, data privacy policy, data retention audits
  • Consult with DPO
  • Develop and test procedures for breach notification and escalation

 Business Continuity and Disaster Recovery

  • Implement the Business Continuity and Disaster Recovery Framework in line with ISO 22301
  • Conduct risk assessment, Business Impact Analysis and guide DR plans with business owners

 Training and Awareness

  • Support with Information Security Education and Awareness strategy to include delivery of training using various methods, simulation exercises, communication, reporting and trend analysis

Compliance

  • Support in establishing Information Security governance forum.
  • Support team with various ISO27001 related project to include planning internal and external audits, risk treatment and improvement plans, maintenance of information security risk register, and support with implementation of control objectives.
  • Generate monthly security metrics, dashboards and reporting for management review
  • Work closely with the staff across firm to gather information on working practices to identify security risk and exposure and recommend steps to improve security posture and processes
  • Keeping abreast of latest IT security measures and controls
  • Support alignment and reviews of our maturity against security frameworks as agreed with the CISO, such as NIST CSF.

 Skills and Experience:

  • Prior experience in Information Security with a focus on governance, risk, and compliance (Financial Services or Consulting background is preferable)
  • An information security related qualification or certificates such as CISM, CISA, CISSP; CRISC, ISO27001 Lead Implementer or Lead Auditor is preferable
  • Experience and knowledge of IT systems, networking principles and associated technology-based security controls
  • Experience in facilitating and supporting internal and/or external audit activities.
  • Experience in applying and implementing ISO related controls both technical and operational.
  • Understanding of general information security management principles and data protection.
  • Knowledge and experience of logical access control management and administration.
  • Experience working within Information Security or IT Security, Data Protection.
  • Experience in working Information Security training and awareness tools.
  • Excellent written and verbal communication skills.
  • Strong MS and Atlassian skills using MS Word, Excel, PowerPoint, SharePoint and Outlook and Confluence.

Some of our benefits

•    Competitive salary & progression
•    Open and inclusive culture 
•    Hybrid working 
•    Fantastic offices and great working environment
•    Vitality Health Plan (includes private health insurance, travel insurance, gym discounts)
•    Medicash health plan (Level 3)
•    5% employer pension contribution
•    Life assurance
•    Income protection insurance
•    28 days holiday plus 3 additional days, bank holidays & further days for various key life events
•    Team socials

Apply for this Job

* Required
resume chosen  
(File types: pdf, doc, docx, txt, rtf)
cover_letter chosen  
(File types: pdf, doc, docx, txt, rtf)


Our system has flagged this application as potentially being associated with bot traffic. Please turn off any VPNs, clear your browser cache and cookies, or try submitting your application in a different browser. If this issue persists, please reach out to our support team via our help center.
Please complete the reCAPTCHA above.