
Humaans · London
ABOUT US Humaans is building the next generation of infrastructure for the workplace; software designed for companies that are scaling fast, operating globally...
Humaans is building the next generation of infrastructure for the workplace; software designed for companies that are scaling
fast, operating globally, and pushing into new boundaries.
What started as a system of record has evolved into a broader platform for operating people globally. With Athena, our agentic AI
layer, Humaans moves beyond data management into intelligent orchestration, connecting workflows across HR, IT, Finance, and
Operations so organisations can act faster and with greater confidence, redefining how work gets done.
We work with ambitious teams across Europe and the US, from AI-native companies like Lovable, Poolside, Fyxer AI, and Tandem
Health, to established, high-growth organisations scaling internationally and through acquisition, including Quantexa, Sellpy,
Manychat, Gigs, Croud, and Threecolts. These teams don’t buy software for features,they buy leverage. The ability to run faster,
cleaner, and with more control as complexity compounds.
To date, we’ve raised $20m in venture funding from some of the most respected founders, operators, and funds in technology: Lachy
Groom (Physical Intelligence), Stewart Butterfield (Slack), Tobias Lütke (Shopify), Dylan Field (Figma), Jeff Weiner (LinkedIn),
Claire Johnson (Stripe), Oliver Jay (OpenAI), Jay Simmons (Bond) as well as Y Combinator, Moonfire, Frontline Ventures, Pathlight
Ventures, and Exor.
If you have massive ambition and want to work on a hard problem, with a small team that moves fast, at a moment when the category
is genuinely up for grabs - this is it.
We're looking for a Security GRC Manager to own the systems, processes, audits, and customer-facing trust work that help Humaans
scale into more demanding markets.
This is a hands-on ownership role, built around AI. You'll run our security compliance programme throughout the year, not just
during audit season. AI is how the work gets done here. It drafts policies, speeds up questionnaire responses, and keeps evidence
current. You already use these tools daily and know how to get real leverage from them.
You'll own the operating rhythm for frameworks like ISO 27001, SOC 1, SOC 2, HIPAA and future standards that matter to our
customers. You'll keep evidence organised, controls running, policies up to date, vendors reviewed, risks visible, and audits
moving smoothly.
Own the commercial trust layer. Security questionnaires, enterprise diligence, vendor reviews; fast, accurate, reusable. You'll be
in the room with enterprise buyers; on calls, in reviews and procurement threads, ensuring security won't be the reason a deal
slows down.
This role sits at the intersection of Security, Legal, Product, Engineering, Revenue, and Operations. You don't need to be the
person configuring every system yourself, but you do need to understand how modern SaaS companies operate, ask sharp questions,
drive action across teams, and keep the bar high.
Humaans has a trust function that helps us win. In this role, you'll ensure evidence is stronger, controls are cleaner,
questionnaire turnaround is faster, ownership is clear. Security compliance is a commercial asset and enabler to growth.
pursue.
Finance and Operations.
incident response documentation that support our certifications and customer commitments. AI drafts and updates these artefacts
and keeps evidence current year-round, not only at audit time.
DPAs, subprocessors, data protection questions, and enterprise diligence.
Trust collateral stays current. A review process holds quality as volume scales.
the company down unnecessarily.
related role.
questionnaire responses, reviewing vendor documentation.
security questions clearly, and give buyers confidence.
read.
product development, customer data and enterprise sales.
This is an in-person role. Our team comes together in the office Monday through Thursday, while most of the team collaborates in
person on Mondays, Tuesdays, and Thursdays.
Early stage startups can be messy – we know that. We're putting effort in providing you with the best employee experience and a
quality driven environment in exchange for trusting us.
HR tech is having its AI moment and we’re positioned to own it. Humaans started as a next-gen HRIS taking on large incumbents in a
massive market. We’ve since evolved into something even bigger: an AI platform that sits across workforce data and automates the
operational layer of HR entirely; the natural progression of what we’ve been building toward.
The product is highly differentiated. It’s built around a structured workforce data model that makes AI reliable in an HR context,
something no one else has gotten right. Customers notice the difference immediately.
We’re backed by Y Combinator, Lachy Groom, Moonfire, Frontline Ventures, and operators who’ve built some of the most consequential
software companies of the last decade: the founders of Slack, Figma, and Shopify, and Asana’s former CRO and Head of OpenAI
International.
We’re a small team with an unapologetically high bar. It shows up in the product, in how we communicate, and in the standards we
hold each other to.
At Humaans we’re looking for genuinely good people that are transparent and emphatic. We’re committed to providing equal
opportunities, a diverse and inclusive work environment, and ensuring a fair interview process for everyone. You’re welcome to
apply no matter your gender, ethnicity, sexual orientation, religion, civil or family status, age, disability, or race.
We care about your privacy. When you apply for a role at Humaans, we’ll collect and process your personal data as part of our
recruitment process. This includes things like your CV, contact details, and any other information you choose to share. We may
also contact you about future opportunities. You can ask us to delete your data at any time. For more details, see our Privacy
Policy.
ABOUT LENDABLE Lendable is on a mission to build the world's best technology to help people get credit and save money. We're building one of the world’s leading fintech companies and are off to a strong start: * One of the UK’s newest unicorns with a team of just over 700 people * Among the fastest-growing tech companies in the UK * Profitable since 2017 * Backed by top investors including Balderton Capital and Goldman Sachs * Loved by customers with the best reviews in the market (4.9 across 10,000s of reviews on Trustpilot) So far, we’ve rebuilt the Big Three consumer finance products from scratch: loans, credit cards and car finance. We get money into our customers’ hands in minutes instead of days. We’re growing fast, and there’s a lot more to do: we’re going after the two biggest Western markets (UK and US) where trillions worth of financial products are held by big banks with dated systems and painful processes. JOIN US IF YOU WANT TO 1. Take ownership across a broad remit. You are trusted to make decisions that drive a material impact on the direction and success of Lendable from day 1 2. Work in small teams of exceptional people, who are relentlessly resourceful to solve problems and find smarter solutions than the status quo 3. Build the best technology in-house, using new data sources, machine learning and AI to make machines do the heavy lifting ABOUT THE ROLE We are looking for a proactive Security GRC Analyst to join our Information Security team. You will play a pivotal role in scaling our security posture in a fast-paced, AI driven, cloud-native environment. You will be part of a growing team, where your voice will be heard, and your ability to take ownership and drive initiative will directly shape our security culture and operational resilience. Your approach to GRC starts with the risk, not the checklist. Rather than chasing compliance for its own sake, you will identify and assess the risks first, then collaborate with stakeholders to design pragmatic mitigations. You understand that compliance doesn't drive the business; rather, it is the natural outcome of a mature security posture that actively works for the organisation. WHAT YOU’LL BE DOING * Framework & Regulatory Alignment: Help maintain, improve, and scale our security compliance programmes, ensuring ongoing alignment with standards such as SOC 2, ISO 27001, and PCI-DSS, as well as regulator expectations and UK GDPR. * Risk & Mitigation: Collaborate on identifying security risks across the business - including emerging risks from AI-driven and agentic threats - and support the team in driving practical, risk-first mitigation strategies. * Compliance Automation: Utilise our security compliance platform (e.g., Vanta/Drata) to orchestrate automated evidence collection, reducing manual overhead and moving the company toward a state of continuous audit readiness. * Third-Party Risk Management (TPRM): Conduct vendor and third-party security risk assessments to evaluate the security posture of partners and critical outsourced service providers. * Translating Risk & Governance: Work with the team to bridge the gap between engineering and business governance by turning technical security metrics into clear, risk-based narratives for internal stakeholders and external auditors. * Security Culture & Awareness: Support the delivery and promotion of security awareness initiatives to help drive a strong culture of shared security responsibility across the organisation. * Technical Collaboration: Actively engage in conversations with engineers, developers, and IT teams - understanding their technical language and workflows to help align security controls with engineering realities. * Audit & Assessment Support: Participate in external audits and assessments by gathering evidence, preparing documentation, and helping to ensure a smooth, successful audit cycle. WHAT YOU WILL BRING Essential: * Experience: 5+ years of experience in a related role (ideally within a regulated, cloud-native business or FinTech). * Compliance & Risk Expertise: A strong, foundational understanding of security risk management principles and hands-on experience working with compliance frameworks (e.g. ISO 27001, PCI-DSS, or SOC 2). * Risk-First & Pragmatic Mindset: A natural tendency to start with the "why" (the risk) rather than the checklist. You possess the ability to balance strict financial regulations with the operational agility of a fast-paced FinTech, ensuring security controls protect the business without slowing it down. * Communication & Collaboration: Outstanding communication skills with a proven ability to comfortably converse with technical stakeholders, understand their challenges, and translate them into business risks. * Drive & Initiative: A highly proactive and self-motivated mindset - someone who actively looks for ways to improve our security posture and drive change. Deisrable: * Tooling: Direct, practical experience working with modern security compliance and automation platforms (such as Vanta or Drata). * Programming and automation: Experience with Python or a similar programming/scripting language, and/or using AI to improve productivity through automation. INTERVIEW PROCESS 1. Initial Chat all with a Recruiter 2. 15 minute Cognitive Assessment 3. 30 minute Hiring Manager call 4. 60 minute Technical Interview 5. 60 Culture-Add Interview LIFE AT LENDABLE * Winning team: the opportunity to scale up one of the world’s most successful fintech companies * Flexible working: flexible approach tailored to each role. Hybrid roles require three days in-office weekly; fully remote roles include regular opportunities for in-person connection through socials and off-sites * Socials & connection: opportunities and events to come together, socialise, and get to know each other beyond the office walls * Health coverage: support for your physical and mental wellbeing, including private health cover * Retirement & savings: long-term financial wellbeing through retirement savings plans * Employee referral programme: earn a competitive bonus when you refer successful new team members * Office meals & snacks: enjoy a fully stocked kitchen, plus complimentary lunches prepared by in-house chefs on in-office days at select locations * Sustainable commuting: cycle-to-work and electric vehicle salary sacrifice schemes available in select locations Please note: The availability and details of specific benefits vary by location and role. For more information, please speak to your Talent Partner. Check out our blog!
ABOUT LENDABLE Lendable is on a mission to build the world's best technology to help people get credit and save money. We're building one of the world’s leading fintech companies and are off to a strong start: * One of the UK’s newest unicorns with a team of just over 700 people * Among the fastest-growing tech companies in the UK * Profitable since 2017 * Backed by top investors including Balderton Capital and Goldman Sachs * Loved by customers with the best reviews in the market (4.9 across 10,000s of reviews on Trustpilot) So far, we’ve rebuilt the Big Three consumer finance products from scratch: loans, credit cards and car finance. We get money into our customers’ hands in minutes instead of days. We’re growing fast, and there’s a lot more to do: we’re going after the two biggest Western markets (UK and US) where trillions worth of financial products are held by big banks with dated systems and painful processes. JOIN US IF YOU WANT TO 1. Take ownership across a broad remit. You are trusted to make decisions that drive a material impact on the direction and success of Lendable from day 1 2. Work in small teams of exceptional people, who are relentlessly resourceful to solve problems and find smarter solutions than the status quo 3. Build the best technology in-house, using new data sources, machine learning and AI to make machines do the heavy lifting About the Role At Lendable, we don’t do box-ticking security. We’re building automated guardrails and high-leverage tooling integrations to keep our business moving fast and safely. We are looking for a practical, execution-focused Security Engineer to manage the configuration, integration, and engineering lifecycle of our internal security tools. This is a highly versatile engineering role for someone who loves to solve security problems with code and automation. You will act as the engineering engine room for the InfoSec team - collaborating closely with our SecOps, AppSec, Architecture, Security GRC and IT Systems leads to translate security requirements into working configurations, automated pipelines, and custom data integrations. Whether it's writing Terraform to roll out a new edge security rule, stitching together SaaS APIs via Python to pull data into a centralised reporting app, or jumping into a web UI for some quick "click-ops" configuration, your focus is entirely on efficiency, posture improvement, and eliminating manual toil. What You’ll Be Doing * Configuration as Code: Drive security configurations across our stack utilising a Terraform and GitOps workflow. * Tooling Optimisation: Get the most out of our InfoSec tooling through proactive setup, tuning, and configuration, ensuring we maximise our defensive utility and continuously improve our security posture. * Platform Integrations: Build and maintain high-leverage integrations between cloud providers, SaaS platforms, and our core security tooling - for example, engineering log pipelines into our SIEM or automating evidence feeds into our compliance platform. * Automation Engineering: Architect and deploy agentic workflows and lean automation scripts to eliminate manual toil, driving productivity and scalability for the InfoSec team. * Frictionless Control Implementation: Design and deploy practical guardrails, CASB, and data loss prevention (DLP) policies across network boundaries and collaboration tools – for example, Google Workspace. Your focus is on safeguarding data and enabling safe tooling usage without creating engineering bottlenecks. What We’re Looking For * Practical Engineering Capabilities: Solid hands-on experience using Python (or similar) to automate tasks, Terraform to manage infrastructure, connect APIs, and manage infrastructure state, balanced with the judgement to use UI configurations when code isn't viable. * Cloud & Infrastructure Literacy: Proven experience configuring or hardening security controls within cloud (AWS/GCP) environments (e.g. IAM and network/identity boundaries) and handling data formats like JSON to parse logs. * AI-First Execution: Enthusiastic about actively leveraging advanced AI coding tools (such as Claude Code, Codex) to exponentially increase your engineering output, script generation, and delivery speed. * Pragmatic Security Mindset: A builder who views security as a business enabler. You focus on building practical defensive posture rather than filling out compliance checklists, with the instinct to identify actual systemic risk based on context. * Bias for Action: An execution-focused operator. When a security control drifts or a peer needs a detection mechanism, you write the script, open the PR, or modify the control to get it done. * Communication & Collaboration: The ability to debate technical IAM architecture details with a Platform Engineer and seamlessly explain to non-technical risk stakeholders why a specific control change matters. Interview Process 1. TA Screening Call 2. Hiring Manager Call 3. Technical Interview 4. Culture Interview LIFE AT LENDABLE * Winning team: the opportunity to scale up one of the world’s most successful fintech companies * Flexible working: flexible approach tailored to each role. Hybrid roles require three days in-office weekly; fully remote roles include regular opportunities for in-person connection through socials and off-sites * Socials & connection: opportunities and events to come together, socialise, and get to know each other beyond the office walls * Health coverage: support for your physical and mental wellbeing, including private health cover * Retirement & savings: long-term financial wellbeing through retirement savings plans * Employee referral programme: earn a competitive bonus when you refer successful new team members * Office meals & snacks: enjoy a fully stocked kitchen, plus complimentary lunches prepared by in-house chefs on in-office days at select locations * Sustainable commuting: cycle-to-work and electric vehicle salary sacrifice schemes available in select locations Please note: The availability and details of specific benefits vary by location and role. For more information, please speak to your Talent Partner. Check out our blog!
Qube Research & Technologies (QRT) is a global quantitative and systematic investment manager, operating in all liquid asset classes across the world. We are a technology- and data-driven group implementing a scientific approach to investing. Combining data, research, technology, and trading expertise has shaped our collaborative mindset, which enables us to solve the most complex challenges. QRT’s culture of innovation continuously drives our ambition to deliver high-quality returns for our investors. You will work within the Cyber Security function, supporting the delivery of security initiatives across the organisation. The team partners with Technology, Engineering, and Infrastructure teams, as well as senior stakeholders, to ensure security programmes are delivered effectively and aligned with business priorities. Your Future Role within QRT You will: * Lead end-to-end delivery of cyber security projects within a broader programme framework * Manage multiple concurrent workstreams, including identity and access management, cloud security, risk remediation, and compliance initiatives * Develop and maintain project plans, timelines, and resource allocation * Ensure programme governance, including management of risks, assumptions, issues, and dependencies * Drive stakeholder engagement across technical teams and senior leadership * Translate cyber security concepts into clear, business-facing updates * Build and maintain programme dashboards using Power BI or Tableau to improve reporting automation * Track objectives, milestones, and programme performance metrics * Identify delivery risks and implement mitigation actions * Collaborate with Cyber Security, Infrastructure, and Engineering teams to align on technical requirements * Ensure alignment with internal standards, security frameworks, and regulatory requirement Your Present Skillset * Experience delivering IT or cyber security projects in complex environments * Strong understanding of IT infrastructure, cloud environments, and security principles * Experience using Power BI or Tableau for reporting and dashboard creation * Experience automating reporting and working with structured data sources * Knowledge of project management methodologies (Agile, Waterfall, or hybrid) * Strong stakeholder management and communication skills * Experience managing timelines, dependencies, and cross-functional delivery * Familiarity with cyber security frameworks such as NIST, ISO 27001, or CIS * Experience delivering cyber security or transformation programmes * Certifications such as PMP, PRINCE2, or Agile (Scrum) * Exposure to GRC tools or security platforms * Experience working in regulated environments QRT is an equal opportunity employer. We welcome diversity as essential to our success. QRT empowers employees to work openly and respectfully to achieve collective success. In addition to professional achievement, we are offering initiatives and programs to enable employees achieve a healthy work-life balance.