VP/SVP - Cyber Risk
Gurugram
Applications have closed
OakNorth
OakNorth can fund your growth with business finance starting from £1million. Unlock your savings goals with our range of savings accounts.Job Responsibilities
- Working with the Director of Technology and Cyber Risk and the wider Risk Team:
- Provide expert risk advice, oversight and challenge of the management of technology risk across the development, architecture, testing or our internal and external technology estate.
- Provide risk advice, oversight and challenge and guidance of cyber security risk across cloud platforms, network infrastructure, desktop environments, servers, and mobile devices.
- Collaborate with development teams to review code, ensuring best practices are integrated throughout the software development lifecycle (SDLC).
- Review the implementation and enforcement of robust information technology and security policies across all IT functions, ensuring alignment with industry best practices and frameworks.
- Deliver the risk assurance monitoring plan for technology and cyber risk including independent risk assessments of critical systems and applications, ensuring timely resolution of vulnerabilities ensuring effective corrective and preventive actions are implemented to address findings.
- Ensure organisational compliance with relevant UK, EU, and global regulations (e.g., GDPR and Prudential Regulation Authority (PRA) requirements and leading security frameworks, such as NIST and ISO 27001
- Review risk mitigation strategies, ensuring appropriate treatment of identified risks and providing oversight on residual risks.
- Serve as a bridge between the technical risk team, senior management, and the broader technology and cybersecurity community to ensure a holistic approach to risk management.
- Identify, assess, and effectively communicate complex technology and cyber risks, translating them into actions for cross-functional technical teams.
Skills, Competencies and Preferred Qualifications
- Proven experience in a technology focused Second Line of Defense or similar risk management role, with an emphasis on information security, technology risk, and cybersecurity.
- Deep technical expertise in IT infrastructure security, with hands-on experience in network security, cloud platforms (e.g., AWS), servers, mobile devices, and desktop environments.
- In-depth understanding of security frameworks and best practices such as NIST, ISO 27001, and MITRE ATT&CK, along with regulatory requirements like GDPR and PRA requirements
- Strong ability to independently audit complex IT systems, identify vulnerabilities, and implement effective security solutions.
- Hands-on experience with secure coding practices and security assessments within an SDLC environment.
- Experience with security testing tools, such as static code analysis tools, dynamic application security testing (DAST), and automated vulnerability scanning tools.
- Excellent communication skills with the ability to translate highly technical cyber risks and audit findings into business-friendly language for executive leadership and non-technical teams.
- Demonstrated ability to lead thematic reviews through collaboration with internal and external stakeholders.
- Relevant risk management, security certifications and cloud security certifications.
For more information regarding our Privacy Policy and practices, please visit: https://oaknorth.co.uk/legal/privacy-notice/employees-and-visitors/
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Analytics Application security AWS Banking Cloud Code analysis Compliance DAST Data Analytics Finance GDPR ISO 27001 IT infrastructure MITRE ATT&CK Monitoring Network security NIST Privacy Risk assessment Risk management SDLC Security assessment Vulnerabilities
Perks/benefits: Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.