InfoSec Manager (Hiring Immediately)

First Circle
London

First Circle is a fast-growing, profitable, credit-led SME NeoBank in the Philippines whose shareholders include the World Bank Group (IFC). Today, our Business Credit Line and Business Bank Accounts are used by thousands of SMEs to grow and run their business. Our product velocity has accelerated — in the next few months we’ll release SME Corporate Cards, Payroll, Invoices, and Solar Financing — redefining the SME NeoBank category through software, financial products, and exceptional risk models.

Our culture emphasises building, problem solving, ownership / responsibility, and personal & professional growth. We balance a collegiate atmosphere with free & direct communication which enables us to move very quickly and avoid politics or toxicity. Our team continues to level up quickly, necessary for business to compound more than 100% per year, which we achieve through individual growth and bar-raiser hiring

Requirements

This is a unique opportunity for a high growth individual to become the first dedicated security professional at a high-growth, regulated bank whose market leadership position lies in its technology.

You will define strategy, priorities, and our security operating model aligned to business goals – reporting to the VP Engineering and supported in your development by our world-class CISO Board advisor.

As the company continues to grow you’ll have unparalleled opportunities for career growth and to build out our infosec team around you.

Your first year is about building foundations, addressing primary risks, and ensuring the bar you set is consistently upheld by the wider technology organisation:

  1. ISO 27001 certified. You own the certification from scoping to audit pass.
  2. Implement external pen test & remediation. Every finding closed or formally risk-accepted.
  3. MSSP/SOC live and producing alerts we act on. SLAs measured monthly. Escalation path drilled at least twice.
  4. Engineering development processes aligned with security. Embed secure-by-design principles into technology and product development, working closely with engineering and DevOps teams. Full audit trail.
  5. Regulatory compliance. Design, implement, and maintain security policies, standards, and procedures aligned to global standards and local regulations: BSP circulars, EPFS and PPMI (payments) requirements, and PCI DSS scope.
  6. Mitigate user & device threats. Define, assess, and upgrade the law of least privilege across users & devices. No unmanaged device touches production.
  7. A risk register used monthly by the exec team and Board. Internal and external (eg. vendor, supply chain) risks. Tied to mitigation owners and dates.
  8. Develop a strong culture & training practice. Phishing simulation, secure-coding standards, IR runbook drilled live at least once.
  9. Tooling. Evaluate and implement security tools and technologies, optimising for a lean, scalable security stack. Oversee vulnerability management and remediation, ensuring regular scanning, prioritisation, and tracking of fixes.

What you own steady-state

The strategy and roadmap with the exec team and Board Risk Committee. The MSSP relationship. Incident response. Vulnerability management. Third-party risk — particularly card processors, payment rails, KYC providers. BSP cybersecurity engagement and PCI DSS scope where it applies. Security culture — making it easier to do the right thing than the wrong thing.

About You

  • You've built a security function before, hands-on. Not advised — built. At a regulated fintech, payments business or bank. Be ready to walk us through what was there when you arrived and what was there when you left.
  • You've led a Sev-1 from page to post-mortem. Tell us about one.
  • You've taken an organisation through ISO 27001 as the responsible owner, not a consultant on the sidelines.
  • You've stood up an MSSP — chosen the vendor, defined the use cases, tuned the alerts, fired one when it underperformed.
  • You've written IAM policy that survived contact with real engineers. Azure-native (that's our stack).
  • You're hands-on enough to read Terraform, open a PR, and debug events. If your last line of code was 5+ years ago, this isn't your role.
  • Certifications — CISSP, CISM, CRISC, or ISO 27001 Lead Implementer/Auditor are useful signals. They're a tiebreaker, not the bar.

What this role is not

  • Not a CISO inheriting a team — you'll build it. Year 1 you may have one or two hires.
  • Not a paper-driven compliance role — we expect you in the codebase, in the cloud console, on the on-call rotation when it matters.
  • Not for someone who needs a clean SOC 2 starting point. We're earlier than that, by design, and moving fast.

Benefits

  • No fixed budget for this]]>
Posted 2026-05-06

Recommended Jobs

Junior Digital Merchandise Planner

Pentland Brands
London

We’re Pentland Brands: a global family business behind some of the world’s most iconic active and lifestyle brands. We bring integrity, energy and ambition to our work, setting high standards and st…

View Details
Posted 2026-04-28

PRIMARY TEACHER - FOREST GATE, EAST LONDON

Marchant Recruitment
Waltham Forest, Greater London

Location: Forest Gate, East London Job Title: Primary School Teacher (KS1 or KS2) Contract Type: Full-Time, Long-Term / Permanent Opportunity Salary: MPS1–MPS6 (Inner London) – dependent …

View Details
Posted 2026-01-22

Part-time Housekeeper in Wandsworth, Job ID J203BE

Little Ones UK Ltd
Wandsworth, Greater London

A lovely family from London is looking for a reliable and proactive Part-time Housekeeper to help them maintain the cleanliness of their property. The role involves high-standard cleaning and floor c…

View Details
Posted 2026-03-12

Global Equities - Futures & Derivatives Clearing Risk Manager - Analyst or Associate (Hiring Immediately)

jpmc
London

Are you ready to make an impact in the world’s leading Futures & Derivatives Clearing business? As part of our London team, you will gain unique exposure to a diverse client portfolio and product set…

View Details
Posted 2026-05-06

Associate Delivery Manager - UK 2026

Suade
London

Suade Labs delivers intelligent, data-driven and scalable SaaS solutions across the financial industry. Our platform enables clients to ensure regulatory reporting compliance gain deeper business ins…

View Details
Posted 2026-01-17

Programmatic Senior Account Manager

Croud
London

LONDON, UK (Hybrid Working - 3 days in the office per week)  A benchmarked salary between £48,000-£54,500 . Your salary level is determined by skills and experience within our progression framework…

View Details
Posted 2026-04-30

Targeted Support Officer (SC6) - Admin & Clerical

Lewisham Council
Lewisham, Greater London

Job Category: Admin & Clerical Job location:  Lewisham Council Hours per week: 35 Start date: Immediate start Salary: £19.50 per hour MAIN PURPOSE This is a new role being created to…

View Details
Posted 2025-07-30

Credit Controller - Finchley

Fusion Consulting Limited
London

Credit Controller   Due to extensive growth and multiple acquisitions, Fusion Consulting Group are looking to recruit an experienced Credit Controller to join our internal finance team based out of …

View Details
Posted 2026-04-03

Office Manager - Independent School - Westminster (London)

Marchant Recruitment
London

A highly regarded independent school in Westminster is seeking an experienced, organised and proactive Office Manager to lead the day-to-day running of a busy school office. This is an excellent …

View Details
Posted 2026-03-07

Analyst, QE, Software Engineering (London, GB)

EBRD
London

Analyst, QE, Software Engineering (London, GB) Requisition ID 36588 Office Country United Kingdom Office City London Division Information Technology Contract T…

View Details
Posted 2026-04-03