Edenpeople logo

Information Security Compliance Analyst

Salary
Up to £45K
Hiring from
United Kingdom
Work type
Hybrid
Posted
Is this job info correct?
Show job description

Take a step forward and let Edenred surprise you.

Every day, we deliver innovative solutions to improve the life of millions of people, connecting employees, companies, and merchants all around the world.

We know there are hundred ways for you to grow. With us, you will expand your skills in a multicultural, challenging, and dynamic environment.

Dare to join Edenred and get ready to thrive in a global company that will offer you endless opportunities.

Edenred is all about meritocracy. You come as you are, and you contribute. Indeed, the Edenred Group recognizes, recruits and develops all talents and singularities.

We are committed to preventing all forms of discrimination and to providing all our candidates with equal opportunities regardless of their gender and gender expression, disability, origin, religious belief and sexual orientation or any other criteria.

Information Security Compliance Analyst

Salary: Up to £45,000 per annum + Bonus

Swindon/London – Hybrid

Objective:

You will support the Information Security function across PayTech by coordinating and improving compliance activities, helping ensure that security controls remain effective, evidenced, and aligned to regulatory, client, and internal requirements. The role partners with business, technology, audit, and group stakeholders to drive practical compliance outcomes across PCI DSS, DORA, and other regulatory and risk frameworks, internal control assurance, security awareness compliance, and client due diligence activity.

Crucial to this role is helping maintain PayTech's ability to demonstrate that security controls operate in practice, not only on paper, and that identified gaps are tracked, escalated, and supported through to closure. The role also helps improve confidence in PayTech's security posture by supporting internal audit requirements and responding to client security questionnaires and audits in a structured, repeatable way.

Responsible for:

The Compliance Analyst is responsible for supporting the day-to-day operation of PayTech's security compliance activities. This includes maintaining evidence and documentation, assisting with PCI DSS readiness, coordinating responses to internal audit and client assurance requests, owning the security awareness programme and activities, liaising with our learning teams and wider group functions to maintain the content and ensure it’s delivery, and helping track remediation actions across the business. The role works closely with the rest of the PayTech information security team, technology teams, and group functions to ensure that compliance activity leads to measurable risk reduction and operational improvement.

Promote the use of standard frameworks and consistent evidence practices so that PayTech can meet immediate PCI DSS and audit obligations while improving compatibility with wider regulatory, group, and client assurance expectations. This includes maintaining clear records and minutes, repeatable processes, and practical reporting that supports internal governance and external assurance activity.

What you will be doing:

  • Support and coordinate PCI DSS compliance activity, including evidence collection, control tracking, action follow-up, and audit readiness reviews.
  • Assist with internal audit requirements by gathering evidence, coordinating with control owners, tracking findings, and supporting timely remediation closure.
  • Support responses to client security questionnaires, due diligence requests, and client-led audits by coordinating inputs, maintaining standard response packs, and improving consistency of answers.
  • Maintain and improve compliance documentation, including policies, procedures, standards, evidence libraries, control descriptions, and meeting records.
  • Track security awareness compliance activities, including completion reporting, support for awareness campaigns, policy attestations, and follow-up of non-compliance.
  • Conduct scheduled compliance checks and sample reviews to help confirm that required controls and processes are operating as expected.
  • Support risk and exception management by ensuring issues are logged, documented accurately, escalated where required, and reviewed through the proper governance forums.
  • Work with technology, engineering, operations, legal, compliance, finance, and group teams to provide clear guidance on evidence expectations and policy requirements.
  • Produce reporting and dashboards on compliance status, audit actions, awareness completion, and outstanding remediation items.
  • Contribute to continuous improvement of compliance processes so that audit and assurance activity becomes more efficient, repeatable, and less dependent on manual chasing.

Key Result Areas:

  • PCI DSS and Control Assurance: Help ensure PCI DSS obligations are supported through well-maintained evidence, control tracking, and readiness for formal assessment activity. The role supports the reduction of audit-visible process gaps by improving documentation quality and follow-through on actions.
  • Internal Audit Support: Ensure that internal audit requests are handled in a timely, organised, and professional manner, with clear ownership, accurate evidence, and tracked remediation.
  • Client Assurance and Trust: Improve PayTech's ability to respond consistently and credibly to client security questionnaires, assurance requests, and audit queries by maintaining reusable information packs and accurate records.
  • Security Awareness Compliance: Support the monitoring and improvement of staff compliance with mandatory security training, awareness activities, and policy acknowledgement requirements.
  • Policy and Documentation Quality: Maintain clear, current, and usable compliance documentation aligned with PayTech requirements and Edenred group direction.
  • Issue Tracking and Closure: Help ensure audit actions, compliance gaps, and exceptions are visible, correctly recorded, and driven to closure within agreed timescales.
  • Regulatory Landscape and Best Practice: Maintain awareness of relevant standards and obligations affecting the role, including PCI DSS, audit expectations, and broader control assurance good practice, and apply these appropriately in daily work.

Measuring Success:

Perform against agreed metrics detailed in objectives such as:

  • PCI evidence readiness: percentage of key PCI evidence items current, complete, and available for review at agreed checkpoints.
  • Audit action closure rate: percentage of internal and external audit actions closed within agreed target dates.
  • Questionnaire turnaround time: average time to coordinate and complete client security questionnaire responses.
  • Response quality and reuse: percentage of client assurance responses delivered using approved standard content packs, reducing inconsistency and rework.
  • Awareness compliance rate: percentage of staff completing mandatory security awareness training and attestations within target timescales.
  • Policy review completion: percentage of in-scope compliance documents reviewed and updated to schedule.
  • Open exception age: average age of open compliance exceptions or overdue evidence requests.
  • Governance reporting timeliness: percentage of required compliance and audit reports delivered on schedule.

What you will bring:

Qualifications & Experience

Required Experience:

  • Strong experience in information security compliance, IT audit, risk, governance, or a related control assurance role.
  • Practical experience supporting compliance or assurance activity against at least one recognised framework such as PCI DSS, ISO 27001, SOC 2, or similar.
  • Experience coordinating evidence collection and working with control owners, auditors, or business stakeholders.
  • Experience maintaining structured documentation, trackers, and records to support audit or compliance requirements.
  • Ability to work across multiple teams to follow up actions, clarify requirements, and keep activity moving.
  • Strong written communication skills for drafting policies, procedures, evidence summaries, and questionnaire responses.

Preferred Experience:

  • Experience in financial services, FinTech, payments, or another regulated environment.
  • Exposure to internal audit processes, client due diligence questionnaires, or external client assurance reviews.
  • Experience supporting security awareness campaigns, training compliance, or policy attestation processes.
  • Familiarity with Jira, Confluence, Excel, ticketing systems, and evidence repositories.

Skills & Certifications

Certifications (desirable, not mandatory):

  • PCI-related training or assessor/audit exposure.
  • ISO 27001 Foundation, Internal Auditor, or Lead Implementer.
  • CISA, CRISC, or equivalent governance / audit certification pathway.
  • Security+, ISC2 CC, or similar entry-level security certification.

Skills:

  • Strong organisation and attention to detail, with the ability to keep documentation accurate, current, and audit ready.
  • Good stakeholder coordination skills and the confidence to follow up actions with teams across business and technology functions.
  • Ability to explain compliance requirements in clear, practical language and translate requests from auditors or clients into actionable asks.
  • Solid reporting capability, including maintenance of dashboards, metrics, evidence trackers, and status updates.
  • Ability to handle sensitive information professionally and maintain confidentiality in client, audit, and internal matters.
  • Continuous improvement mindset, helping standardise recurring compliance tasks and reduce manual overhead.

Why Edenred PayTech?

We are a subsidiary of the Edenred group and leaders in prepaid solutions including banking, virtual cards, debit, credit, and prepaid processing.

As an Edenred PayTech employee you will get the support and structure that you need to enjoy your work and develop your career while doing what you love and making a difference in a fast-paced and innovative business.

What you will get:

  • 25 days annual leave plus Bank Holidays
  • Hybrid working environment (min. 3 days per week in the office)
  • Pension Scheme – employer 6% with minimum employee contribution 3%
  • Discretionary bonus scheme based on company and personal performance
  • Medical & international travel cover (leisure and action sports)
  • Life insurance (4x salary)
  • Wellbeing Employee Assistance Program (extended access to family members)
  • Holiday trading scheme
  • Season ticket loan
  • Cycle to Work scheme
  • Employee discount shopping platform
  • Employee referral bonus scheme
  • Digital learning platform
  • Complimentary fruit and other ‘in office’ snacks & refreshments
  • Volunteering programme
  • Social events

Diversity:

Edenred PayTech are proud to be an equal opportunity employer. We will not discriminate against any applicant or employee based on age, race, colour, creed, religion, sex, sexual orientation, gender, gender identity or expression, national origin, citizenship, marital status or civil partnership/union status, disability, pregnancy, genetic information, or any other basis prohibited by applicable country or local laws.

Apply now and Vibe with Us!

About Us

The Edenred State of mind - We are a unique company.

We are looking for new employees who will embrace the Edenred adventure with the same intensity and passion as we do. They will feel right at ease at Edenred because they like to push back the boundaries, try new things, constantly improve, win and grow. We need women and men who share our ambition, who are looking to perform, challenge us and themselves to move forward every day. We are looking for women and men who want to vibe with us.

Similar jobs

Apply for this job