Full-Time

Information Security GRC Engineering Consultant

Visa

Visa

10,001+ employees

Global digital payments network processing transactions

No salary listed

London, UK

Hybrid

Hybrid role; days in office to be confirmed by hiring manager.

Category
IT & Security (1)
Required Skills
Vulnerability Analysis
SOC 2

Get referred to Visa

See people who can refer or advise you

Requirements
  • 3 or more years’ experience with ensuring information security compliance, preferably in highly regulated environments
  • Strong experience working with, building, and implementing successfully, a range of security control frameworks range such as SOC 2, ISO27000 and PCI, e.g. worked as SOC2 Lead Auditor/Implementer
  • Strong experience of ISMS, security risk management and associated practices
  • Experience of performing internal or third‑party security compliance assessments, including evidence review, control testing, and stakeholder engagement
  • Bachelor's degree preferred in information assurance, computer science, engineering, or related field
  • Demonstrated ability to multi-task, work calmly under pressure, think analytically, understand complex systems and communicate complexity effectively
  • Ability to communicate clearly with both technical and non-technical staff and stakeholders at different levels across the business
  • Excellent written and verbal communication as well as good presentation skills. Proficient English language skills are required
  • Be able to build relationships and influence actions from all areas of the business including senior leadership, engineering teams and auditors and regulators
  • Ability to adapt and stretch capabilities and skills to meet the business needs of a fast-growing technology firm
  • Ability to create repeatable and re-usable principles, processes and solutions
  • Broad knowledge / understanding of basic technical security controls / control frameworks including, but not limited to, areas such as cloud computing, network security, endpoint security and identity and access management, etc
  • Knowledge of common security vulnerabilities/risk factors in information processes, infrastructure and applications, e.g., Separation of Duties, CVEs, OWASP Top 10, etc
  • Technical proficiency in at least one programming language, and the ability to successfully complete a coding assessment as part of the selection process
Responsibilities
  • Lead the implementation and ongoing operation of Featurespace’s security controls framework, ensuring alignment with Visa Key Controls, PCI DSS, SOC 2, and other applicable regulatory or customer requirements, and ensuring controls are implemented in a manner appropriate to Featurespace products, services, and delivery models
  • Coordinate and lead Featurespace’s annual certification and assurance activities (e.g. PCI DSS, SOC 2), acting as the primary point of integration between Featurespace internal teams, external auditors, and Visa central control functions, and ensuring audit activities are delivered efficiently, accurately, and on time
  • Ensure all processes are operating effectively and are correctly evidenced, including the maintenance of appropriate documentation, dependency mapping, and traceability to responsible teams and subject matter experts
  • Translate regulatory, compliance, and control requirements into practical, product-aware implementations, working directly with engineering and platform teams to embed controls into architectures, CI/CD pipelines, cloud environments, and operating processes
  • Design, build, and maintain automation to support compliance activities where it adds demonstrable value, including:
  • control validation and continuous assurance
  • evidence collection, normalisation, and retention
  • workflow orchestration and exception handling
  • metrics, reporting, and compliance visibility
  • Apply engineering judgement to determine what should be automated in the short term, what requires process or architectural maturity or redesign to be effective, and what is not suitable for automation
  • Ensure Featurespace teams are effectively integrated with Visa’s centrally provided security and compliance capabilities, identifying when changes in Featurespace products, architectures, suppliers, customer requirements, or operating models introduce new or materially changed obligations, and ensuring the appropriate Visa processes and assessments are engaged, including:
  • policy and standards frameworks
  • third-party risk management processes
  • security architecture assessments
  • security awareness and training programmes
  • legal and commercial contracting
  • risk management and governance tooling
  • Act as a trusted advisor and subject matter expert to Featurespace engineering, product, commercial, and leadership teams, helping stakeholders understand information security and compliance expectations and how to meet them pragmatically
  • Drive a secure-by-design and shift-left mindset, ensuring compliance and assurance considerations are addressed early in delivery rather than deferred to audit windows, and facilitating the timely closure of gaps and findings identified through Visa vulnerability management and secure assessment processes
  • Develop and maintain repeatable patterns, reference implementations, standards, procedures, and guidance that reduce friction for delivery teams while maintaining strong assurance, consulting with and coordinating input from subject matter experts as required
  • Conduct security risk assessments and business impact analyses, and recommend appropriate control improvements to address identified risks or weaknesses
  • Provide oversight and assurance of corrective, preventative, or remediation activities, utilising Visa risk management tooling, working with identified application and service owners, and escalating issues at risk of missing deadlines in a timely and effective manner
  • Represent Information Security with customers, auditors, and internal stakeholders, particularly during assurance windows and customer security engagements
  • Coordinate and lead responses to customer RFP questions and security audits, ensuring responses are timely, accurate, repeatable, re-usable, traceable to responsible SMEs, and supported by appropriate evidence
  • Support incident response and recovery activities where compliance or control effectiveness is impacted, ensuring appropriate remediation actions are taken and evidenced
  • Travel periodically as required for customer, company, or relevant events
  • This is a hybrid position. Expectation of days in office will be confirmed by your hiring manager
Desired Qualifications
  • Preferably one or more of the following security qualifications - ISO270001 LI/LA, PCIP, ISA, CISA, CISM, CISSP or similar
  • History of applying a strong/deep understanding of information security controls, technologies, policies, processes, and best practices to applications, compute, networking, cloud, and containers
  • Experience / knowledge of Financial Services compliance such as PCI
  • Advanced software development experience

Visa operates a global digital payments network that connects consumers, businesses, banks, and governments to enable electronic card payments. Its system moves money through a card-based flow: a merchant request, card authorization via Visa, funds settlement between banks, and data processing, with fees earned on transactions and services. The company differentiates itself with its worldwide network, large client base, and partnerships that expand access to digital payments while supporting sustainable commerce. Its goal is to widen financial inclusion and provide convenient, secure electronic payments for a growing share of global commerce.

Company Size

10,001+

Company Stage

N/A

Total Funding

$9.6M

Headquarters

San Francisco, California

Founded

1958

Get referred to Visa

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Agentic commerce expands Visa’s relevance in AI-driven checkout flows.[1]
  • VisaNet’s scale supports deeper monetization through value-added services and risk tools.[3][8]
  • Tokenization and digital-click payments strengthen secure growth in mobile commerce.[5]

What critics are saying

  • Agentic-payment startups can bypass Visa-controlled checkout and routing economics.[1]
  • Domestic real-time payment rails reduce Visa’s volume in key transaction categories.[4][6]
  • A major fraud or outage event would damage trust and accelerate rail substitution.[2][3]

What makes Visa unique

  • VisaNet processes secure, reliable payments across 200 countries and territories.[4]
  • VisaNet +AI enables smarter authorization, clearing, and settlement in milliseconds.[8]
  • Visa Ventures backed Nekuda’s agentic-payments infrastructure alongside Madrona and Amex Ventures.[1]

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance.

Life Insurance.

Dental Insurance.

Disability Insurance.

Accidental Death & Dismemberment Insurance.

Company News

TechCabal
Aug 12th, 2025
HoneyCoin raises $4.9M for expansion

Kenyan fintech HoneyCoin raised $4.9 million in seed funding to expand its stablecoin cross-border payment services into Africa, Latin America, and Asia. Led by Flourish Ventures, the round included TLcom Capital, Stellar Development Foundation, and Visa Ventures. HoneyCoin processes $150 million monthly, serving 350 enterprise clients. The funds will be used to hire executives, secure licenses, and expand into new markets, with plans for new products by Q3 2025.

Business Wire
May 15th, 2025
Nekuda Raises $5M Led by Madrona, Together with Amex Ventures and Visa Ventures, to Power Agentic Payments

Nekuda raises $5M led by Madrona, Amex Ventures & Visa Ventures to power agentic aayments. For the infrastructure of the future of online commerce.

Forbes
May 6th, 2025
Visa Invests in BVNK, $50M Funding

Visa Ventures has invested in stablecoin infrastructure platform BVNK, marking Visa's first direct investment in a stablecoin payments player. This move supports the future of stablecoins in payments, enhancing BVNK's credibility and penetration with Visa's partners. BVNK, which raised $50 million in a Series B round in December 2024, processes $12 billion in annualized volume and offers solutions for B2B and B2C payments using stablecoins.