Lead IT Security Manager
London
CFC
CFC’s broad range of commercial insurance products are purpose-built for today’s risks, and we aim to give our customers everything they need in one, easy-to-understand policy. We specialize in cyber insurance, professional liability,...
Lead IT Security Manager
As the Security Manager, you will liaise with security incident response experts, working with our infrastructure and development teams to ensure that our systems are appropriately secure, compliant and resilient while keeping up to date with industry changes. . You will also be expected to continuously educate people across the business in security matters and threats.
You will be responsible for the following:
We show up each day ready to take on the world. Our passion and intensity set us apart and makes the difference to our colleagues, customers, brokers and carriers.
Challenge everything:
We’re never afraid to question the way that things are done and we constantly challenge ourselves and others to makes things better.
Have fun, be good:
Insurance is a serious business, but we don’t take ourselves too seriously. We make it fun to work at CFC, we welcome all viewpoints, and we treat everyone how we would expect to be treated.
Department: IT Operations
Employment Type: Permanent - Full Time
Location: London
Reporting To: Dax Grant
Description
As CFC’s IT Security Manager you will be part of the technology team, the engine room of the business, providing bespoke systems that give CFC its competitive advantage in this dynamic marketing place.As the Security Manager, you will liaise with security incident response experts, working with our infrastructure and development teams to ensure that our systems are appropriately secure, compliant and resilient while keeping up to date with industry changes. . You will also be expected to continuously educate people across the business in security matters and threats.
About the role
As the Security Manager you will be accountable for setting standards , ensuring that all people across the business understand their own responsibilities in relation to IT security. You will have a clear understanding of how to navigate the inevitable tension between security concerns and business delivery drivers.You will be responsible for the following:
- Accountability for creating and maintaining standards and their implementation
- Work with stakeholders and staff to nurture a culture where security is always in mind and seen as a critical part of everyone’s responsibility
- Creation of training materials and assisting with the continual upskilling of the whole company in relation to security matters relevant to their roles
- Provide day to day advice in security matters across the business
- Carry out business impact analysis activities relating to new changes and capabilities
- Working with our SOC to ensure that their incident detection models and alert response processes are kept appropriate and up to date
- Coordinating with our MSSP for the scoping and execution of vulnerability scanning and penetration testing
- Curation of security standards for development and infrastructure delivery and operations
- Facilitate internal / external IT security audits.
- Working with development teams during the design phase of architectural changes to ensure that security is considered
- Running tabletop security exercises to test our response plans and capabilities
- Satisfying security related compliance and due diligence requests from capacity providers and auditors
- Scheduling and coordination of DR test exercises
About you
You will be someone that has an exposure to environment where infrastructure management is heavily automated. You will have experience in working with suppliers to negotiate and manage the service they provide. Insurance experience would be advantageous, but not essential. You will be someone that has experience with:- Defining and implementing IT security policies within a financial services organisation and with a demonstrable understanding of associated risk management
- Knowledge of security in a cloud hosted environment, especially using cloud native technologies in Azure
- Knowledge of secure development practices and relevant tooling
- Experience training others in security matters at all levels
- Great communication skills and the ability to influence others
- Experience running security testing processes such as tabletop exercises, phishing campaigns etc.
- Knowledge of security audit requirements in financial services organisations and a proven track record working with auditors on such matters
Core Values
Love what you do:We show up each day ready to take on the world. Our passion and intensity set us apart and makes the difference to our colleagues, customers, brokers and carriers.
Challenge everything:
We’re never afraid to question the way that things are done and we constantly challenge ourselves and others to makes things better.
Have fun, be good:
Insurance is a serious business, but we don’t take ourselves too seriously. We make it fun to work at CFC, we welcome all viewpoints, and we treat everyone how we would expect to be treated.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
0
0
0
Category:
Leadership Jobs
Tags: Audits Azure Cloud Compliance Incident response Pentesting Risk management SOC
Region:
Europe
Country:
United Kingdom
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Systems Security Officer jobsSenior Cloud Security Engineer jobsInformation System Security Officer jobsInformation Security Specialist jobsSenior Cybersecurity Engineer jobsInformation Security Manager jobsSenior Network Security Engineer jobsSecurity Consultant jobsIT Security Engineer jobsCyber Security Specialist jobsSenior Information Security Analyst jobsSenior Penetration Tester jobsSecurity Specialist jobsSenior Cyber Security Engineer jobsSystems Engineer jobsChief Information Security Officer jobsSystems Administrator jobsPrincipal Security Engineer jobsInformation System Security Officer (ISSO) jobsIT Security Analyst jobsSenior Product Security Engineer jobsStaff Security Engineer jobsCloud Security Architect jobsSecurity Operations Analyst jobsInformation Systems Security Engineer jobs
Kubernetes jobsDevSecOps jobsCI/CD jobsPowerShell jobsIDS jobsSaaS jobsEDR jobsSplunk jobsIPS jobsTop Secret jobsRMF jobsSQL jobsSDLC jobsIntrusion detection jobsBash jobsITIL jobsActive Directory jobsThreat detection jobsCompTIA jobsCRISC jobsDoDD 8570 jobsFinance jobsBanking jobsDocker jobsOWASP jobs
TCP/IP jobsClearance Required jobsUNIX jobsVPN jobsGIAC jobsHIPAA jobsSANS jobsCISO jobsIT infrastructure jobsTerraform jobsIndustrial jobsOSCP jobsSOC 2 jobsSOX jobsJavaScript jobsCCSP jobsPolygraph jobsData Analytics jobsDNS jobsSOAR jobsNIST 800-53 jobsGCIH jobsJira jobsMITRE ATT&CK jobsSecurity strategy jobs