Information Security Grc Engineering Consultant

Visa Visa · Fintech · London, United Kingdom, United Kingdom

Information Security GRC Engineering Consultant at Visa, focusing on building and automating compliance systems (PCI DSS, SOC 2, Visa Key Controls) within the Featurespace product and cloud environments. The role involves translating regulatory requirements into practical controls, leading assurance activities, and advising product and engineering teams on security and compliance.

What you'd actually do

  1. Lead the implementation and ongoing operation of Featurespace’s security controls framework, ensuring alignment with Visa Key Controls, PCI DSS, SOC 2, and other applicable regulatory or customer requirements, and ensuring controls are implemented in a manner appropriate to Featurespace products, services, and delivery models.
  2. Translate regulatory, compliance, and control requirements into practical, product-aware implementations, working directly with engineering and platform teams to embed controls into architectures, CI/CD pipelines, cloud environments, and operating processes.
  3. Design, build, and maintain automation to support compliance activities where it adds demonstrable value, including: - control validation and continuous assurance - evidence collection, normalisation, and retention - workflow orchestration and exception handling - metrics, reporting, and compliance visibility
  4. Act as a trusted advisor and subject matter expert to Featurespace engineering, product, commercial, and leadership teams, helping stakeholders understand information security and compliance expectations and how to meet them pragmatically.
  5. Conduct security risk assessments and business impact analyses, and recommend appropriate control improvements to address identified risks or weaknesses.

Skills

Required

  • Information Security
  • GRC (Governance, Risk, Compliance)
  • Engineering
  • Automation
  • Cloud environments (AWS/GCP/Azure)
  • CI/CD pipelines
  • Risk assessment
  • Compliance frameworks (PCI DSS, SOC 2)
  • Visa Key Controls

Nice to have

  • Security architecture
  • Third-party risk management
  • Security awareness training
  • Vulnerability management

What the JD emphasized

  • PCI DSS
  • SOC 2
  • Visa Key Controls
  • automation