
How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About Lendable
Lendable is on a mission to build the world's best technology to help people get credit and save money. We're building one of the world’s leading fintech companies and are off to a strong start:
- One of the UK’s newest unicorns with a team of just over 700 people
- Among the fastest-growing tech companies in the UK
- Profitable since 2017
- Backed by top investors including Balderton Capital and Goldman Sachs
- Loved by customers with the best reviews in the market (4.9 across 10,000s of reviews on Trustpilot)
So far, we’ve rebuilt the Big Three consumer finance products from scratch: loans, credit cards and car finance. We get money into our customers’ hands in minutes instead of days.
We’re growing fast, and there’s a lot more to do: we’re going after the two biggest Western markets (UK and US) where trillions worth of financial products are held by big banks with dated systems and painful processes.
Join us if you want to
- Take ownership across a broad remit. You are trusted to make decisions that drive a material impact on the direction and success of Lendable from day 1
- Work in small teams of exceptional people, who are relentlessly resourceful to solve problems and find smarter solutions than the status quo
- Build the best technology in-house, using new data sources, machine learning and AI to make machines do the heavy lifting
About The Role
We are looking for a proactive Security GRC Analyst to join our Information Security team. You will play a pivotal role in scaling our security posture in a fast-paced, AI driven, cloud-native environment. You will be part of a growing team, where your voice will be heard, and your ability to take ownership and drive initiative will directly shape our security culture and operational resilience.
Your approach to GRC starts with the risk, not the checklist. Rather than chasing compliance for its own sake, you will identify and assess the risks first, then collaborate with stakeholders to design pragmatic mitigations. You understand that compliance doesn't drive the business; rather, it is the natural outcome of a mature security posture that actively works for the organisation.
What You’ll Be Doing
- Framework & Regulatory Alignment: Help maintain, improve, and scale our security compliance programmes, ensuring ongoing alignment with standards such as SOC 2, ISO 27001, and PCI-DSS, as well as regulator expectations and UK GDPR.
- Risk & Mitigation: Collaborate on identifying security risks across the business - including emerging risks from AI-driven and agentic threats - and support the team in driving practical, risk-first mitigation strategies.
- Compliance Automation: Utilise our security compliance platform (e.g., Vanta/Drata) to orchestrate automated evidence collection, reducing manual overhead and moving the company toward a state of continuous audit readiness.
- Third-Party Risk Management (TPRM): Conduct vendor and third-party security risk assessments to evaluate the security posture of partners and critical outsourced service providers.
- Translating Risk & Governance: Work with the team to bridge the gap between engineering and business governance by turning technical security metrics into clear, risk-based narratives for internal stakeholders and external auditors.
- Security Culture & Awareness: Support the delivery and promotion of security awareness initiatives to help drive a strong culture of shared security responsibility across the organisation.
- Technical Collaboration: Actively engage in conversations with engineers, developers, and IT teams - understanding their technical language and workflows to help align security controls with engineering realities.
- Audit & Assessment Support: Participate in external audits and assessments by gathering evidence, preparing documentation, and helping to ensure a smooth, successful audit cycle.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What You Will Bring
Essential:
- Experience: 5+ years of experience in a related role (ideally within a regulated, cloud-native business or FinTech).
- Compliance & Risk Expertise: A strong, foundational understanding of security risk management principles and hands-on experience working with compliance frameworks (e.g. ISO 27001, PCI-DSS, or SOC 2).
- Risk-First & Pragmatic Mindset: A natural tendency to start with the "why" (the risk) rather than the checklist. You possess the ability to balance strict financial regulations with the operational agility of a fast-paced FinTech, ensuring security controls protect the business without slowing it down.
- Communication & Collaboration: Outstanding communication skills with a proven ability to comfortably converse with technical stakeholders, understand their challenges, and translate them into business risks.
- Drive & Initiative: A highly proactive and self-motivated mindset - someone who actively looks for ways to improve our security posture and drive change.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable:
- Tooling: Direct, practical experience working with modern security compliance and automation platforms (such as Vanta or Drata).
- Programming and automation: Experience with Python or a similar programming/scripting language, and/or using AI to improve productivity through automation.
Interview Process
- Initial Chat all with a Recruiter
- 15 minute Cognitive Assessment
- 30 minute Hiring Manager call
- 60 minute Technical Interview
- 60 Culture-Add Interview
Life at Lendable
- Winning team: the opportunity to scale up one of the world’s most successful fintech companies
- Flexible working: flexible approach tailored to each role. Hybrid roles require three days in-office weekly; fully remote roles include regular opportunities for in-person connection through socials and off-sites
- Socials & connection: opportunities and events to come together, socialise, and get to know each other beyond the office walls
- Health coverage: support for your physical and mental wellbeing, including private health cover
- Retirement & savings: long-term financial wellbeing through retirement savings plans
- Employee referral programme: earn a competitive bonus when you refer successful new team members
- Office meals & snacks: enjoy a fully stocked kitchen, plus complimentary lunches prepared by in-house chefs on in-office days at select locations
- Sustainable commuting: cycle-to-work and electric vehicle salary sacrifice schemes available in select locations
Please note: The availability and details of specific benefits vary by location and role. For more information, please speak to your Talent Partner.
Check out our blog!
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location