Job type: Full-time

Loading ...

Job content

Cybersecurity Risk Officer (Technology Management)

Job Number:

3202837

POSTING DATE: Feb 24, 2022
PRIMARY LOCATION: Europe, Middle East, Africa-United Kingdom-United Kingdom-Glasgow
EDUCATION LEVEL: Bachelor’s Degree
JOB: Risk Management
EMPLOYMENT TYPE: Full Time
JOB LEVEL: Associate

DESCRIPTION

Overview

Enterprise Technology Services (ETS) delivers firm-wide services and platforms including network infrastructure (ENS), core computing (EC), mainframe (MF), end user technologies (EUT), application infrastructure (AI) and workplace support services (WSS).

The EC Security and Cybersecurity Risk Officer is responsible for facilitating security and cybersecurity risk management practices across the EC Compute and Storage (CASE) fleet. The role will champion the security and cybersecurity risk agenda across multiple teams and ensures that risks are identified, controlled, managed, and reported. This role will have colleagues and stakeholders across the globe and be required to liaise with risk governance functions, senior technology leaders and executive management.

This is position will report to the Head of Risk Management for EC in New York.

Primary responsibilities

  • Engagement with EC engineers, operations staff, product owners and security architecture reviewers as equal stakeholder for the security and cybersecurity risk agenda. Participate in agile design phases to deliver security and cybersecurity requirements.
  • Pro-active security and cybersecurity risk identification for both new and legacy EC systems.
  • Engagement with Firm wide risk and control groups, including first, second and third line of defense risk functions as appropriate.
  • Establish technology wide view of prioritized key security and cybersecurity threats.
  • Establish security and cybersecurity best practices and coordinate implementation across multiple squads.
  • Serve as key stakeholder and sponsor for a portfolio of risk remediation activities, including driving requirements and priorities to delivery teams.
  • Facilitates cross-disciplinary coordination for risk analysis, remediation scoping and reporting / engagement with stakeholders.

QUALIFICATIONS

Skills Required:

  • Detailed knowledge of NIST or other security control frameworks
  • Detailed knowledge of security and cybersecurity threats and vulnerabilities
  • Previous experience in security and cybersecurity risk consulting in technology Infrastructure (in particular, unix/linux operating systems and storage) at an enterprise scale
  • Previous experience with technology controls programs and risk domains, (e.g. change management, SDLC, information security practices, risk management frameworks (e.g. COBT, ITIL)
  • Working knowledge of agile methodologies and organizational principles
  • Excellent verbal and written communication skills, including the ability to translate requirements effectively and lead group discussion
  • Must be extremely detail oriented, very organized and value the integrity of the data
  • Strong analytical and problem-solving ability and capability to switch context quickly and work on multiple streams of work concurrently
  • High proficiency with MS Office and related applications (Word, Excel, PowerPoint, Access, Visio, Project) with advanced skill in data manipulation using Excel.
  • Ability to build and sustain relationships with individuals at all levels of the organization and leverage this to achieve work-related objectives

Skills Desired

  • Experience working in an Investment Banking environment
  • Experience of auditing within a technical environment
  • Working knowledge of OpenPages
  • Project Management experience (e.g. PMP)
  • Have industry recognized risk related qualifications (e.g. SOC, CISSP, CISM, CISA)
Loading ...
Loading ...

Deadline: 16-07-2024

Click to apply for free candidate

Apply

Loading ...
Loading ...

SIMILAR JOBS

Loading ...
Loading ...