Hasthin Gateru
Information Security Manager @ Monzo Bank
About
I am a risk and security executive specialising in owning enterprise risk outcomes in regulated, high-growth environments. Across 11+ years in financial services, government, consulting, and fintech, I’ve built trusted relationships with regulators, boards, senior executives, and engineering leadership to enable growth under regulatory scrutiny — not block it. My work sits between regulation, technology, and commercial decision-making. I lead risk ownership across third party risk, enterprise and product risk, market expansion, and regulatory readiness - translating ambiguity into clear, defensible decisions that allow businesses to move faster securely. Currently at Monzo Bank, I lead security and risk outcomes supporting European market expansion, embedding regulatory risk management into product launches, infrastructure, and third-party relationships. I act as a primary security and risk interface for internal audit, regulators, and senior stakeholders, ensuring security is an enabler of scale rather than a cost centre. Previously, I’ve led cyber and GRC functions across critical national infrastructure, defence, finance, and public sector, including senior consulting roles advising C-suite leaders on regulatory compliance, operating models, and enterprise risk decisions. I’m particularly effective in roles that require: - Judgement under ambiguity - Clear ownership of risk outcomes - Credibility with regulators and boards - Balancing growth, innovation, and control I’m motivated by roles where accountability matters - where decisions have real commercial, regulatory, and reputational consequences.
United Kingdom
Gloucester
Information Technology & Services
Systemic Cyber Risk & National Resilience, Financial Services Cyber Security, Regulatory & Government Cyber Advisory, Sector-Level Security Strategy & Policy, Critical Infrastructure & Economic Security, Cyber Risk Assessment & Prioritisation, Governance, Risk & Compliance (GRC) Leadership, Enterprise & Technology Risk Advisory, Executive & Board-Level Security Advisory, Regulatory Compliance Program Delivery, Security Frameworks & Standards (ISO 27001, SOC 2, PCI-DSS, NIS), vCISO / vISM Advisory, Risk-Based Security Operating Models, Defensible Risk Decision-Making, Incident Response Planning & Executive Exercises, Multi-Sector Regulated Environments (FS, Public Sector), Cyber & Information Security Strategy, Enterprise & Information Risk Management, Executive Security Leadership & Governance, Regulated & High-Assurance Environments (Defence, Health, CNI)
Experience

Information Security Manager
London Area, United Kingdom
- Own enterprise security and technology risk outcomes supporting Monzo’s European banking expansion, operating at the intersection of regulation, product, and infrastructure. - Act as a risk owner and senior security representative across market entry, regulatory engagement, and material business decisions — providing clear, defensible risk positions to senior leadership. - Lead security strategy and execution across third-party risk, governance, vulnerability management, and regulatory compliance, ensuring Monzo can scale internationally while meeting supervisory expectations. - Embed security and risk management into product and infrastructure launches, enabling speed to market without compromising regulatory trust. - Partner closely with engineering leadership, internal audit, legal, and risk teams to ensure controls are effective, measurable, and proportionate to business risk. - Identify and plan for emerging threats, regulatory changes, and systemic risks, translating uncertainty into actionable decisions.

Head of Cyber & Information Security
City Of Bristol, England, United Kingdom
- Owned cyber and information risk strategy across regulated and high-assurance sectors including defence, health, space, and critical national infrastructure. - Acted as the senior risk and security authority in audit committees, project reviews, and executive decision-making forums, balancing commercial delivery with regulatory and contractual obligations. - Embedded secure-by-design and risk-based decision-making into engineering and delivery teams, aligning ISO, NIST, MOD, and HMG frameworks with real operational outcomes. - Led organisational risk maturity uplift across cloud, AI, and emerging technologies, enabling innovation while maintaining regulator and client confidence. - Positioned security as a growth enabler, improving client acquisition and trust in highly regulated markets.

Senior Governance Risk and Compliance Information Security Consultant
Remote
- Advised C-suite leaders and boards on enterprise risk, regulatory compliance, and security operating models across financial services, public sector, and regulated industries. - Led and delivered GRC programmes at scale, including ISO 27001, SOC 2, PCI-DSS, NIS, and emerging regulatory requirements. - Acted as a trusted advisor and vCISO/vISM, helping organisations make defensible risk decisions under regulatory and commercial pressure. - Designed and delivered risk assessments, operating models, and incident response exercises aligned to business strategy rather than checklist compliance.

Senior Information Security Consultant in GRC
United Kingdom
- Advised C-suite leaders and boards on enterprise risk, regulatory compliance, and security operating models across financial services, public sector, and regulated industries. - Led and delivered GRC programmes at scale, including ISO 27001, SOC 2, PCI-DSS, NIS, and emerging regulatory requirements. - Acted as a trusted advisor and vCISO/vISM, helping organisations make defensible risk decisions under regulatory and commercial pressure. - Designed and delivered risk assessments, operating models, and incident response exercises aligned to business strategy rather than checklist compliance.

Cyber Security Consultant in Finance
- Worked at the heart of the UK’s national cyber ecosystem, advising financial institutions, regulators, and government stakeholders on systemic cyber and information risk. - Led and contributed to sector-level security and resilience strategy, shaping how financial services manage cyber risk at scale. - Operated with trusted, regulated entities by providing clear, proportionate, and outcome-focused risk guidance aligned with national priorities.

Systems Analyst and Administrator
Gloucestershire, England, United Kingdom
Worked as a Systems Analyst and Workday Administrator supporting business operations across the organisation. Owned user access, role design, and privilege management to ensure staff had appropriate, least-privilege access aligned to their responsibilities. Acted as a central point of expertise for Workday’s capabilities, supporting HR, operational, and system changes while maintaining control, auditability, and operational continuity. This role provided early exposure to identity, access governance, and the importance of system controls in enabling business outcomes.

Service Development Analyst
Gloucester, England, United Kingdom
Early-career role working across service development and IT operations within a managed services environment. Supported service transition, security operations, customer issue management, networking and hosting, and early cloud security initiatives. Gained a strong foundation in IT Service Management (ITSM), including change management, service transition, and service decommissioning, while working closely with technical and operational teams to maintain service reliability and customer outcomes. This role established a broad understanding of how technology services are delivered, operated, and governed at scale.

Senior Outbound Wine Advisor
Gloucester, England, United Kingdom
Managed a portfolio of approximately 1,000 customers, providing personalised wine recommendations, bespoke offers, and hosted tastings to build long-term customer relationships. Operated as a trusted advisor, understanding individual preferences and occasions to deliver tailored solutions while consistently exceeding monthly sales targets. Developed strong communication, persuasion, and conflict-resolution skills through regular customer engagement, objection handling, and service recovery. This role built early confidence in advisory-style engagement and outcome-driven conversations that later translated into senior stakeholder interaction in technology and security leadership roles.
Hasthin Gateru's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.


