InfoSec Analyst - L3
Curve
InfoSec Analyst - L3
- SecOps
- London
- L3 (Mid)
- Permanent
Description
Curve was founded with a rebellious spirit, and a lofty vision; to truly simplify your finances, so you can focus on what matters most in life.
That’s why Curve puts your finances simply at your fingertips, so you can make smart choices on how to spend, send, see and save your money. We help you control your financial life, so you can go out and live the life you want to live.
With Curve you can spend from all your accounts, track spend behaviour and provide insights, and security to protect you from fraud. For the first time giving you bright insights and control of all your money in one beautiful place.
We’re developing a ground-breaking product with our customers at the core. Our user base is growing rapidly and we have exceptional metrics. We have funding from the leading names in tech investment, and a visionary leadership team who wants everyone who joins this remarkable adventure, to have the autonomy to masterfully develop their expertise.
Welcome to Curve. On a mission to help you live inspired.
💡 Role Purpose:
The mission for this role is to be responsible for all security compliance monitoring and assurance activities within Curve. The role reports to the Senior Security Engineer and will be key in leading regulatory, audit and supplier-based assessments and their remediation actions. The role will also be required to provide ongoing compliance reporting to senior management.
You will create, deliver, and operate a framework and supporting processes that will enable Curve to deliver continuous compliance for all InfoSec audit and risk-related matters.
This role requires someone who has previously worked within a global team and has prior experience of working in a PCI/GDPR/DPA regulated environment.
🔑 What you’ll be doing:
- Develop, maintain, review, and update information security policies.
- Lead audit, attestation, and assurance activities, ensuring all reviews are scoped accordingly and resulting actions are managed to resolution.
- Develop reporting and measurements to demonstrate adherence to regulatory requirements.
- Support the supplier onboarding and due diligence program by conducting 3rd party security risk assessments.
- Assist with development and ongoing management of the security awareness program and InfoSec training.
- Maintain the Information Security Risk Register and Information Security Context Register.
- Report regularly to management on the status of assigned activities including issues, risks, and remediation actions.
🧠 What you’ll bring:
- 2+ years experience in information security governance, risk, and compliance (GRC) or security auditing.
- Experience in establishing and operating a proactive and continual compliance programme, including PCI, ISO 27001 and SOC2 (as a bonus).
- Control mapping and gap analysis experience.
- Experience with controls and compliance in cloud / SaaS environments.
- Professional security certification preferred (e.g., CISA, CRISC, CISM).
🎯 What success looks like here:
- Applies 2+ years of information security governance, risk, and compliance (GRC) experience to proactively manage audits and regulatory obligations.
- Demonstrates firm technical and practical understanding of information security frameworks (e.g., NIST, ISO 27001, OWASP) to improve processes and mitigate risks.
- Identifies, triages, and drives timely resolution of vulnerabilities, ensuring environments remain secure and compliant.
- Contributes to the development, implementation, and ongoing management of the security awareness program, increasing team-wide knowledge and adherence to InfoSec best practices.
🎈 Benefits:
- 25 days plus bank holidays
- Bonus days off for Learning & Development, Mental Wellbeing, Birthday, Moving House & Christmas
- Working abroad policy (up to 60 calendar days per year)
- Bupa Health Insurance (YuLife)
- Life insurance powered by AIG (5x Annual Salary)
- Pension Scheme powered by “People’s Pension”
- EAP (Mental health & wellbeing support, Life coach, Career coach)
- 24/7 GP access (Smart Health via YuLife)
- Annual subscriptions to Meditopia & FIIT for your mind and body (via YuLife)
- Discounted shopping vouchers (via YuLife)
- Enhanced parental leave
- Ride to work scheme & Season ticket loan
- Six nights of Night Nanny for new parents
- Free Curve subscription for you and your +1
📝 A note from us:
- We know that great candidates don’t always tick every single box. If this role excites you and you think you’d be a great fit, we want to hear from you.
- We design our hiring process to be fair, inclusive, and practical. If you ever need adjustments or feel there’s a way we can improve - we’re all ears.
Requirements
- This role will be required to attend our London (Paddington) office, 3 days per week (minimum)
- The successful candidate will require full working rights in the United Kingdom without the need for visa sponsorship