Sr Manager, Technology and Security Oversight

PayPal PayPal · Fintech · London, United Kingdom +1 · Cybersecurity Risk

This role is for a Sr. Manager, Technology and Security Oversight at PayPal in London, GB. The primary focus is on leading independent oversight of technology and cybersecurity risk for PayPal's UK regulated entity, acting as a Second Line of Defense. The role requires providing effective challenge to risk management practices and ensuring regulatory compliance, with a need for strong communication skills at board and executive levels, and deep technical risk knowledge within a regulated financial services environment.

What you'd actually do

  1. Recognized as a security governance, risk, and compliance expert, independently addressing the most complex security risks and providing strategic direction on risk mitigation and governance practices across the security domain.
  2. Define methods and procedures for new or special assignments, collaborating with cross-functional teams to drive security risk and governance initiatives that align with business needs and objectives.
  3. Lead complex, high-impact security governance and risk management initiatives, leveraging a deep understanding of business trends and security challenges to develop innovative risk mitigation strategies and solutions.
  4. Possess a keen awareness of the broader impact of decisions, with initiatives driving enterprise-wide improvements in risk management and security governance, enhancing overall security practices and operational efficiency.
  5. Lead a security risk and governance team; set clear priorities and define actionable plans, ensuring alignment with organizational goals.

Skills

Required

  • 8+ years relevant experience
  • Bachelor’s degree or equivalent combination of education and experience
  • Strong background in technology and cybersecurity risk management
  • Experience in independent oversight, second line of defense, or audit within a regulated financial services organization
  • Proven ability to engage at executive and board level
  • Direct interaction with regulators such as the FCA and PRA
  • Excellent written and verbal communication skills
  • Ability to explain complex security and technology risk topics to both technical and non-technical audiences
  • Strong influencing, negotiation, and relationship-building skills
  • Comfortable operating across organizational boundaries to drive outcomes
  • Solid understanding of UK regulatory frameworks, including PS21/3, the FCA Handbook, and the Senior Managers and Certification Regime

Nice to have

  • Familiarity with EU frameworks such as DORA and PSD2
  • Professional certifications such as CISSP, CISM, or CRISC
  • Working knowledge of COBIT, NIST CSF, PCI DSS, or ISO 27001

What the JD emphasized

  • independent oversight
  • technology and cybersecurity risk
  • regulated entity
  • Second Line of Defense
  • regulatory obligations
  • FCA and PRA
  • UK regulatory frameworks
  • PS21/3
  • FCA Handbook
  • Senior Managers and Certification Regime