jobify_logo ×
  • מִשׁתַמֵשׁ
  • התחברות/הרשמה
  • עמוד הבית
  • מי אנחנו
  • מעסיקים מובילים
  • פרסום משרה חינם
  • צרו קשר
  • תנאי שימוש
  • מדיניות פרטיות
  • הצהרת נגישות
קרן עזריאלי טקסט בעברית עם סמל אינסוף social_security the_israeli_employment_service work_office המקום
jobify_logo
  • מי אנחנו
  • מעסיקים מובילים
  • פרסום משרה חינם
  • צרו קשר
דילוג לתוכן

עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!

במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.

מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.

Security Operations & GRC Manager

AccessFintech

AccessFintech

  • תל אביב - יפו
  • Indeed
Indeed

Security Operations & GRC Manager

AccessFintech

AccessFintech

  • תל אביב - יפו
  • bag_icon מלאה
  • coins_icon 28,000-40,000 ₪ הערכה מבוססת AI ולא שכר שהתקבל מהמעסיק
    הערכה מבוססת AI ולא שכר של המעסיק
  • Indeed
Indeed

AccessFintech is seeking a senior Information Security professional to join our Technology function. This is a broad remit spanning three areas — AFT's internal information security posture, our governance, risk and compliance programme, and the security relationship with AFT's client network.

As a capital markets technology provider handling sensitive financial data for over 250 institutions, client security confidence is as important as internal security rigour, and both rest on a well-run compliance and assurance programme. This role requires someone who can operate credibly across all three — running robust security operations, owning the certification and risk framework, and engaging directly with clients on security due diligence, assessments, and trust-building conversations.

You will report directly to the CTO and work closely with engineering, product, client operations, and solutions teams across all three jurisdictions.

Requirements

1. Internal Information Security

• Own and continuously improve AFT's information security posture across infrastructure, applications, cloud environments, and endpoints

• Lead the operation and evolution of AFT's security tooling — SIEM, EDR, vulnerability management, intrusion detection, and identity and access management (IAM)

• Own AFT's vulnerability management programme — regular assessments, remediation tracking, and risk reporting to the CTO and executive team

• Lead security incident response — identification, containment, investigation, remediation, and post-incident review

• Maintain and develop AFT's information security policies, standards, and procedures across all three jurisdictions

• Embed security into AFT's software development lifecycle (SDLC) — partnering with engineering and DevOps to shift security left

• Design and deliver security awareness training and communications across the global team

2. Client-Facing Security

• Act as AFT's primary point of contact for all client security enquiries, assessments, and due diligence requests

• Own the end-to-end response to client information security questionnaires — including standardised formats such as the Shared Assessments SIG and CSA CAIQ, as well as bespoke questionnaires issued by banks, custodians, and asset managers

• Build and maintain a central answer library so questionnaire responses are consistent, accurate, and efficient to produce — reducing turnaround times and removing reliance on ad hoc drafting

• Coordinate input from engineering, DevOps, legal, and compliance where questions fall outside the existing answer set, and quality-assure all responses before issue

• Manage annual reassessments and periodic client re-certification cycles, ensuring responses remain current as the platform and control environment evolve

• Represent AFT in client-facing security discussions, audits, and on-site or virtual security assessments — building confidence in AFT's security posture at senior level

• Support the client onboarding process from a security and compliance perspective — ensuring new clients can satisfy their own internal security requirements for onboarding AFT

• Partner with Client Operations and Solutions teams to proactively manage client security requirements as part of the commercial relationship

• Maintain AFT's security documentation suite — trust centre content, security overview decks, penetration test summaries, and compliance certificates — keeping them current and client-ready

• Track and manage client-raised security findings, ensuring remediation actions are progressed and communicated back to clients in a timely manner

• Contribute to new business conversations where security posture is a factor — working with Sales and Solutions on RFP responses and client presentations

3. Governance, Risk & Compliance (GRC)

• Own AFT's information security governance framework — policies, standards, and control documentation across all three jurisdictions

• Own and maintain AFT's information security risk register — identifying, assessing, and tracking risks across internal and client-facing dimensions, with defined risk appetite and escalation thresholds

• Own AFT's ISO 27001 and SOC 2 programmes end to end — control design, evidence collection, internal audit, gap remediation, and management of external auditors through certification and surveillance cycles

• Maintain regulatory compliance mapping across UK (FCA, UK GDPR), US (SEC), and Israel (Privacy Protection Law), ensuring controls are traceable to obligations

• Own the third-party and vendor security risk assessment programme — onboarding due diligence, ongoing monitoring, and contractual security requirements

• Own the control testing and assurance calendar, ensuring controls are evidenced continuously rather than reconstructed at audit

• Establish and run the security governance cadence — regular reporting to the CTO and executive team, translating technical risk into business-level insight

• Lead preparation for external security audits, regulatory examinations, and client-initiated security reviews

Skills & ExperienceEssential

• 6–10 years of progressive experience in information security or cybersecurity, including at least 2 years in a client-facing or externally-engaged security role

• Proven experience owning client information security questionnaires at volume — including standardised formats (SIG, CAIQ) and bespoke bank or custodian questionnaires — with a track record of building an answer library rather than responding ad hoc

• Experience managing client-raised security findings through to remediation, and reporting outcomes back to client security teams

• Demonstrable experience owning a GRC programme — running an ISO 27001 or SOC 2 certification cycle end to end, including evidence management, internal audit, and managing external auditors

• Experience building and maintaining an information security risk register, with the ability to articulate risk appetite and escalate appropriately

• Experience managing third-party and vendor security risk assessment programmes

• Strong hands-on security operations experience — SIEM (e.g. Splunk, Microsoft Sentinel), EDR, vulnerability management (e.g. Tenable, Qualys), and IAM

• Deep working knowledge of information security frameworks — ISO 27001, SOC 2, NIST CSF — and experience maintaining or achieving certification

• Strong background in cloud-native applications and architectures, with cloud security expertise across IAM, network security, and cloud-native security monitoring

• Strong understanding of data privacy and regulatory obligations in financial services — GDPR, FCA, SEC, or equivalent — including mapping controls across multiple regimes

• Excellent communication skills — able to translate complex security concepts into clear, confident language for client security teams, legal and compliance functions, and non-technical business stakeholders

• Comfortable engaging at senior level with client security and technology teams — building trust and managing relationships through complex due diligence processes

Desirable

• Relevant security certifications — CISSP, CISM, CRISC, CISA, CEH, or equivalent

• ISO 27001 Lead Implementer or Lead Auditor certification

• Experience in capital markets, fintech, or regulated financial services — familiarity with the security expectations of buy-side, sell-side, or custodian institutions

• Experience with DevSecOps practices — integrating security into CI/CD pipelines and engineering workflows

• Scripting or automation capability — Python, PowerShell, or Bash — for security tooling and reporting

• Experience building or maintaining a client trust centre or security documentation programme

• Experience with GRC tooling and compliance automation platforms

• AWS specifically is an advantage — hands-on experience securing containerised and serverless workloads, and using AWS-native security services such as GuardDuty, Security Hub, and Config


במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.

מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.

שאלות ותשובות עבור משרת Security Operations & GRC Manager

התפקיד של מנהל/ת אבטחת תפעול ו-GRC ב-AccessFintech כולל שלושה תחומים עיקריים: אבטחת המידע הפנימית של החברה, תוכנית הממשל, סיכונים ותאימות (GRC), וניהול קשרי האבטחה עם רשת הלקוחות של AccessFintech. זהו תפקיד רחב הדורש יכולת פעולה אמינה בכל אחד מהתחומים הללו, כולל ניהול פעולות אבטחה חזקות, בעלות על מסגרת ההסמכה והסיכונים, ומעורבות ישירה עם לקוחות בנושאי בדיקות נאותות אבטחתיות ובניית אמון.

כספקית טכנולוגיה לשוק ההון המטפלת בנתונים פיננסיים רגישים עבור למעלה מ-250 מוסדות, אמון הלקוחות באבטחה חשוב לא פחות מקפדנות האבטחה הפנימית. מנהל/ת אבטחת תפעול ו-GRC משמש/ת כנקודת הקשר העיקרית לכל פניות האבטחה של הלקוחות, הערכות ובקשות בדיקת נאותות, מנהל/ת את המענה לשאלונים אבטחתיים, ובונה ומקיים/ת ספריית תשובות מרכזית. בנוסף, התפקיד כולל ייצוג AccessFintech בדיוני אבטחה מול לקוחות, ביקורות והערכות אבטחה, ובכך בונה אמון ביכולות האבטחה של החברה ברמה בכירה.

לתפקיד מנהל/ת אבטחת תפעול ו-GRC ב-AccessFintech נדרש ניסיון של 6-10 שנים באבטחת מידע או סייבר, כולל שנתיים לפחות בתפקיד מול לקוחות. נדרש ניסיון מוכח בניהול תוכנית GRC, כולל ניהול מחזור הסמכת ISO 27001 או SOC 2 מקצה לקצה, וכן ניסיון בבנייה ותחזוקה של רישום סיכוני אבטחת מידע. הבנה עמוקה של מסגרות אבטחת מידע כמו ISO 27001, SOC 2, NIST CSF, וידע חזק בתאימות לרגולציות פרטיות נתונים בשירותים פיננסיים (כגון GDPR, FCA, SEC) הם חיוניים, כולל היכולת למפות בקרות לדרישות רגולטוריות מרובות.

משרות נוספות מומלצות עבורך
  • רשימת משאלות

    מב"ט אבטחת מידע

    • map_icon יקנעם עילית
    אלביט מערכות

    אלביט מערכות

  • רשימת משאלות

    Security Operations & GRC Manager

    • map_icon תל אביב - יפו
    AccessFintech

    AccessFintech

  • רשימת משאלות

    לחברת אינטגרציה ענן דרוש/ה CISO

    • map_icon פתח תקווה
    אי.די.פי

    אי.די.פי

  • רשימת משאלות

    Cyber security Consultant / CISO ( Chief Information Security Officer )

    • map_icon הרצליה
    ריקרוטיקס בע"מ

    ריקרוטיקס בע"מ

  • רשימת משאלות

    מב"ט אבטחת מידע

    • map_icon יקנעם עילית
    Elbit Systems

    Elbit Systems

  • רשימת משאלות

    GRC Lead

    • map_icon תל אביב - יפו
    Dream

    Dream

לכל המשרות של מנהל אבטחת מידע

הכשרות רלוונטיות

הטכניון -  מכון טכנולוגי לישראל

הטכניון - מכון טכנולוגי לישראל

מנהלי אבטחת מידע CISO

  • map_icon ירושלים
  • ערב
  • clk_icon 10 חודשים
Real Time College

Real Time College

קורס CISO - ניהול אבטחת מידע וסייבר

  • map_icon תל אביב - יפו
  • בוקר
  • clk_icon 10 חודשים
  • תעודה ממשלתית תעודה ממשלתית
  • סיבסוד סבסוד
  • השמה השמה
הטכניון -  מכון טכנולוגי לישראל

הטכניון - מכון טכנולוגי לישראל

מנהלי אבטחת מידע CISO

  • map_icon אונליין
  • אונליין
  • clk_icon 7 חודשים
הטכניון -  מכון טכנולוגי לישראל

הטכניון - מכון טכנולוגי לישראל

מנהלי אבטחת מידע CISO

  • map_icon תל אביב - יפו
  • ערב
  • clk_icon 7 חודשים

ניתן לצפות במשרות שסימנת בכל שלב תחת התפריט הראשי בקטגוריית 'משרות שאהבתי'

המקום קרן עזריאלי טקסט בעברית עם סמל אינסוף
  • מי אנחנו
  • מעסיקים מובילים
  • צרו קשר
  • תנאי שימוש
  • מדיניות פרטיות
  • הצהרת נגישות

2026 Ⓒ ג'וביפיי - כל הזכויות שמורות

קרן עזריאלי טקסט בעברית עם סמל אינסוף social_security the_israeli_employment_service israel_innovation_authority work_office המקום
המערכת בונה את הפרופיל התעסוקתי שלך

עוד רגע...

המערכת זיהתה ששינית את הנתונים באזור האישי ומעדכנת את ההמלצות על תפקידים ומשרות בהתאם.

מצטערים, לא הצלחנו לנתח בהצלחה את הנתונים שהזנת.
אתם מוזמנים לנסות להזין שוב או להעלות קובץ קורות חיים במידה ויש לכם.
בהצלחה

הגעת להגבלה היומית של שלושה עדכונים בפרופיל האישי ביום

loader

הבקשה שלך נשלחה בהצלחה!

יש באפשרותך לשלוח בקשה לקבלת ייעוץ אישי ללא עלות מיועצת קריירה.

באפשרותך לשלוח בקשה לקבלת ייעוץ אישי ללא עלות

  • בעיה טכנית

  • סיוע בכתיבת קורות חיים או בהכנה לראיון עבודה

  • התאמה של משרות

  • אחר:

פנייתך נשלחה בהצלחה. נציג מטעם ארגון נכי צהל ייצור איתך קשר בהקדם