Information Security Manager - Fintech - Hybrid Calling highly motivated, bright candidates who are looking for a career at an exciting award winning FinTech firm! Company: Wealth Dynamix Role: Information Security Manag…
Skills: ISO 27001, SOC 2, Information security governance, Risk management, Incident response
Senior Technical Project Manager - French Speaking - Hybrid
City of London, England, United Kingdom · Hybrid
Senior+
Senior Technical Project Manager – SDLC - French Speaking Calling highly motivated, bright candidates who are looking for a career at an exciting award winning FinTech firm! Company: Wealth Dynamix Role: Senior Technical…
Pre Sales Consultant – Fintech – Private Banking Pre Sales Consultant wanted as our team is growing fast! Calling highly motivated, bright candidates who are looking for a career at an exciting award winning FinTech firm…
Senior Technical Project Manager – SDLC - Fintech Calling highly motivated, bright candidates who are looking for a career at an exciting award winning FinTech firm! Company: Wealth Dynamix Role: Senior Technical Project…
Senior Technical Project Manager - French Speaking - Hybrid
City of London, England, United Kingdom · Hybrid
Senior+
Senior Technical Project Manager – SDLC - French Speaking Senior Technical Project Manager - SDLC - French Speaking Calling highly motivated, bright candidates who are looking for a career at an exciting award winning Fi…
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Full-time
bachelor degree, professional certificate
Career progression, Learning and development, WDX Academy
Posted 8d ago
~40 hrs/week
Responsibilities
The Information Security Manager is responsible for defining and operating the company's information security governance, risk, and compliance framework. This includes managing the ISMS, overseeing client security assurance, and coordinating security incident response across the organization.
Requirements
Candidates should have demonstrable experience operating an ISO 27001-aligned ISMS and supporting SOC 2 or external audit processes. A strong background in information security risk management and experience within a SaaS, fintech, or regulated technology environment is essential.
Full job description
Information Security Manager - Fintech - Hybrid
Calling highly motivated, bright candidates who are looking for a career at an exciting award winning FinTech firm!
Company: Wealth Dynamix
Role: Information Security Manager
Location: London
Start Date: August 2026
Would you like to join one of the fastest growing FinTech firms in Europe? We are looking for an analytical self starter with experience in product focussed software delivery. If you are passionate about digital transformation and keen to learn about delivering the market leading Client Lifecycle Managing solution to the Wealth Management industry,? apply now!
Who are we?
Wealth Dynamix helps to relieve the burden client management issues for wealth management and private banking firms with innovative technology.
We provide Relationship Managers with a multi-award winning digital Client Lifecycle Management (CLM) platform, offering 360-degree access to their client.
We are a global leader in end-to-end CLM, Wealth Dynamix has offices and clients in three continents with headquarters in the UK.
What is the role?
The role is accountable for defining, operating and evidencing the information security governance framework. Technology and Engineering teams remain responsible for implementing and operating technical controls, subject to oversight, assurance and challenge from the Information Security function.
Purpose of Role
The Information Security Manager owns the company’s information security governance, risk and compliance programme, including the ISMS, client security assurance, security policy framework, incident governance, supplier security assurance, and security reporting. The role works closely with Technology, Product, Operations, Legal and senior leadership to ensure the company’s products, services and operations meet internal, regulatory, contractual and client security expectations.
The role provides security input into privacy compliance activities and works with the DPO on UK GDPR and EU GDPR obligations, DPIAs, data protection by design and incident response. The role is not the statutory DPO unless separately appointed.
The role reports to the COO and ultimately to the WDX Board.
Responsibilities
ISMS & IS Programme
Maintain and continuously improve the Information Security Management System, firmwide information security programme, security policies, certifications and control framework, aligned to ISO 27001, SOC 2, DORA-related customer obligations, applicable financial services expectations and Crédit Agricole Group requirements.
Partner with Product, Engineering and Technology teams to embed security into the software development lifecycle, including secure design reviews, threat modelling, secure coding standards, dependency scanning, SAST/DAST tooling, secrets management, application/API penetration testing, vulnerability remediation tracking and release security governance.
Support DORA-related client and contractual obligations for EU financial services customers, including ICT risk management evidence, incident response and notification processes, resilience testing, ICT third-party risk controls, subcontractor oversight, exit planning and audit evidence.
Provide security governance over cloud and SaaS environments, including identity and access management, logging and monitoring, encryption, key management, backup, tenant segregation, environment segregation, secure configuration and cloud security posture management.
Own and test the security incident response framework, including severity classification, escalation, communications, evidence preservation, lessons learned and remediation tracking.
Support Legal and Sales teams in reviewing client and supplier contract clauses relating to information security, privacy, audit rights, incident notification, resilience, subcontracting and data protection.
Audit & Budgets
Coordinate internal, external, client and certification audits, including audit planning, evidence collection, stakeholder coordination, finding remediation and management reporting.
Manage the information security budget, including security tooling, external assurance, certifications, training and specialist advisory support, in line with agreed financial controls.
Own the client security assurance process, including security questionnaires, RFP/RFI responses, client audits, evidence packs, ISO 27001/SOC 2 artefacts, penetration test summaries, contractual security schedules and remediation tracking.
Security Awareness & Planning
Plan and maintain the annual security roadmap for the company.
Determine whether emerging technology or market trends pose a security risk to the company.
Provide quarterly security updates to the Board, including risk posture, material vulnerabilities, incident trends, control maturity and alignment to risk appetite.
Provide monthly updates to the Executive Committee on security roadmap delivery, key risks, incidents, audit actions, supplier risks and control performance.
Provide security awareness training to employees to help them identify potential threats and understand how to protect themselves from harm.
Support the Board and Executive Committee in understanding cyber risk, regulatory expectations, risk appetite, material control gaps and their governance responsibilities.
Others
Undertake any such duties required to continuously improve the Company Information Security Management System and set high standards and levels of compliance related to Information Security.
Develop and report security KPIs/KRIs, including vulnerability remediation, patch compliance, access review completion, audit action closure, supplier assurance status, incident trends, phishing performance, training completion and control exceptions.
Partner with Technology and Operations to maintain and evidence business continuity, disaster recovery and digital operational resilience controls, including dependency mapping, backup/restore testing, RTO/RPO validation, and remediation tracking.
Why should you apply?
This is a fantastic opportunity to work in a growing FinTech environment with excellent career progression available.
With a global client base the role offers an opportunity to experience a wide variety of digital transformation projects – each with their own unique requirements and opportunities.
We take career progression seriously, with investment into the WDX Academy for new and existing employee learning and development.
You will learn a lot with exposure to multiple complex client needs.
Who is best suited to this role?
Essential
Demonstrable experience owning or materially operating an ISO 27001-aligned or certified ISMS
Strong understanding of information security risk management, control assessment, risk treatment and governance reporting.
Experience coordinating security incident response governance, including escalation, communications and remediation tracking.
Experience operating or improving supplier security assurance and third-party risk processes.
Ability to report security risks, control performance and remediation priorities to senior stakeholders, including ExCo or Board-level audiences.
Experience in a SaaS, fintech, financial services, regulated technology or B2B enterprise software environment.
Desirable
Exposure to DORA, FCA operational resilience, outsourcing/third-party risk or financial services client assurance requirements.
Experience with Microsoft Dynamics, Azure security, SaaS platforms or Microsoft cloud security controls.
Working knowledge of UK GDPR/EU GDPR and privacy-by-design principles.
Familiarity with secure SDLC, application security testing, DevSecOps or product security governance.
Qualifications
Relevant professional certification such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Lead Auditor or equivalent experience.
Degree in cybersecurity, computer science, risk management or a related discipline, or equivalent practical experience.
We believe we offer career defining opportunities and are on a journey that will build awesome memories in a diverse and inclusive culture. If you are looking for more than just a job, get in touch.
Related keywords
Information SecurityFintechISO 27001SOC 2ISMSRisk ManagementComplianceDORAGDPRSaaSCloud SecurityAzureMicrosoft DynamicsDevSecOpsIncident ResponseThird-party Risk
We provide wealth management firms and private banks across the globe with the ability to proactively prospect, onboard and manage the broadest range of clients. We do this via a holistic digital-first platform designed to help wealth management firms grow AuM, streamline operational processes, remain compliant and deliver innovative service.
We create modular CLM solutions capable of much more than just client relationship management. Our solutions can be configured to connect clients across the entire lifecycle from the very first touchpoint, through onboarding and account opening to management and the ongoing transfer of wealth to the next generation.
We work with existing technology architectures – or develop new ones – to support the broadest range of firms, from 10-person boutique investment managers and multi-family offices to global wealth managers and private banks. Our industry experts’ partner with your staff – from technology to the front office, from compliance to operations – to ensure the right fit for your business.
Established in 2012, we are now part of Indosuez Wealth Management within the Crédit Agricole Group, providing us with scale and stability. We operate globally from our UK Headquarters, with offices in France, Switzerland, Singapore and Lithuania.
Offices: Broadwalk House, 5 Appold Street, London, Shoreditch EC2A 2DA, GB · Uraniastrasse 28, Zurich, Zurich 8001, CH · Route de Saint-Julien 7, Carouge, Geneva 1227, CH · 44, Rue de Lisbonne, Paris, Île-de-France 75008, FR · Konstitucijos prospektas, 7, Vilinius, Vilniaus 09307, LT
We provide wealth management firms and private banks across the globe with the ability to proactively prospect, onboard and manage the broadest range of clients. We do this via a holistic digital-first platform designed to help wealth management firms grow AuM, streamline operational processes, remain compliant and deliver innovative service.
We create modular CLM solutions capable of much more than just client relationship management. Our solutions can be configured to connect clients across the entire lifecycle from the very first touchpoint, through onboarding and account opening to management and the ongoing transfer of wealth to the next generation.
We work with existing technology architectures – or develop new ones – to support the broadest range of firms, from 10-person boutique investment managers and multi-family offices to global wealth managers and private banks. Our industry experts’ partner with your staff – from technology to the front office, from compliance to operations – to ensure the right fit for your business.
Established in 2012, we are now part of Indosuez Wealth Management within the Crédit Agricole Group, providing us with scale and stability. We operate globally from our UK Headquarters, with offices in France, Switzerland, Singapore and Lithuania.
Offices: Broadwalk House, 5 Appold Street, London, Shoreditch EC2A 2DA, GB · Uraniastrasse 28, Zurich, Zurich 8001, CH · Route de Saint-Julien 7, Carouge, Geneva 1227, CH · 44, Rue de Lisbonne, Paris, Île-de-France 75008, FR · Konstitucijos prospektas, 7, Vilinius, Vilniaus 09307, LT