Vice President, Security Governance, Risk and Assurance Specialist

London, England, United Kingdom

CLS Group

CLS's innovative settlement, processing and data solutions reduce risk and deliver efficiency.

View all jobs at CLS Group

Apply now Apply later

About CLS:

CLS is the trusted party at the centre of the global FX ecosystem.  Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective.  Trillions of dollars’ worth of currency flows through our systems each day. 

Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies.  We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use.

CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market.

Our ambition to make a positive difference starts with our people.  Our values – Protect, Improve, Grow – underpin everything that we do at CLS and define and shape a supportive and inclusive working environment in which everyone is encouraged to be open and forward-thinking.

Job information:

  • Functional title - VP, IT Security Specialist 
  • Department - Security Governance and Risk Management 
  • Corporate level - Vice President 
  • Report to - Director of Security 
  • Location - London, onsite 2 days per week

 

About the role

The individual will be part of the security function that is responsible for security governance, risk and assurance, to ensure the organisations security posture is robust, compliant against the security policy, standards and controls. The position will require close collaboration with technical, operational, compliance and audit teams to create a secure and compliant technology environment.

 

What you will be doing:

  • Maintain security policy, standards, procedures and frameworks.
  • Ensure alignment with security industry standards such as NIST CSF and NIST 800-53.
  • Act as an advisor to colleagues across the organisation on best security practice.
  • Conduct regular risk assessments and maintain risk register in RSA Archer.
  • Identify assess and prioritize security risk across the organisation’s information assets and environments.
  • Understanding security gaps and provide evaluation and treatment options, consultation on remediation approaches to address gaps and continue ongoing monitoring of remediation, re-assess until reduced to an acceptable level.
  • Supporting Cybersecurity Risk Management strategies based on security findings and observations. Including informing improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all security functions
  • Profile and assign asset security criticality and prioritize risk assessments.
  • Where risk driven change is agreed across security functions, monitoring improvements against the baselined risk to evidence and report where security risk is being reduced to an acceptable level across security functions. Including Policy exceptions and dispensations.
  • Run lessons learned forums and recommend improvements to security controls.
  • Represent security on audits and assessments, ensuring compliance with internal and external requirements.
  • Provide assurance to stakeholders through detailed reporting and metrics.

 

What we’re looking for:

  • Minimum of 5 years’ experience in Information and Cyber Security, with minimum of 2 years’ experience in a security risk team.
  • Highly organised with experience of planning and reporting data, information and updates.
  • Ability to collaborate effectively with others to drive forward key security objectives.
  • Expert in technical writing reports and documenting risk assessment findings and mitigation plans clearly and accurately.
  • Attention to detail, Meticulous attention to detail to ensure data accuracy and integrity and ensure thorough and accurate risk assessment.
  • Problem solving, ability to grasp security issues that impact multiple entities and troubleshoot with proposing and consulting with colleagues on effective solutions to mitigate risks.
  • Excellent verbal and written communication skills to convey complex technical information clearly and effectively. Presenting data insights to non-technical stakeholders
  • Strong understanding of security risk management and taxonomy principles, to reduce risk to an acceptable level.
  • Knowledge of vulnerability management and incident management practices.
  • Experience with GRC tools and best practices. RSA Archer is preferred.
  • Financial and/or Banking industry experience preferred.

 

Professional qualifications / certifications

  • Ideally qualified in MSc Information Security, CICA, CRISC, CISM and/or Data analysis beneficial but not essential if experience validates skills.
  • Proficiency in security frameworks (e.g., NIST CSF, ISO 27001, SOC1,2).
  • Prince 2, MSP, APMQ advantageous.
  • A desire to continue learning and developing security skills and qualifications.

Our commitment to employees:

At CLS, we celebrate diversity and consider this to be one of our strongest assets. We are committed to fostering an environment in which everyone feels comfortable to be who they are, and inclusion is valued. All employees have access to our inclusive benefits, including:

  • Holiday - UK/Asia: 25 holiday days and 3 ‘life days’ (in addition to bank holidays). US: 23 holiday days.
  • 2 paid volunteer days so that you can actively support causes within your community that are important to you.
  • Generous parental leave policies to ensure you can enjoy valuable time with your family.
  • Parental transition coaching programmes and support services.
  • Wellbeing and mental health support resources to ensure you are looking after yourself, and able to support others.
  • Affinity Groups (including our Women’s Forum, Black Employee Network and Pride Network) in support of our organisational commitment to embrace and always be learning more about DE&I.
  • Hybrid working to promote a healthy work/life balance, enabling employees to work collaboratively in the office when needed and work from home when they don’t.
  • Active support of flexible working for all employees where possible.
  • Monthly ‘Heads Down Days’ with no meetings across the whole company.
  • Generous non-contributory pension provision for UK/Asia employees, and 401K match from CLS for US employees.
  • Private medical insurance and dental coverage.
  • Social events that give you opportunities to meet new people and broaden your network across the organisation.
  • Annual flu vaccinations.
  • Discounts and savings and cashback across a wide range of categories including health and retail for UK employees.
  • Discounted Gym membership – Complete Body Gym Discount/Sweat equity program for US employees.
  • All employees have access to Discover – our comprehensive learning platform with 1000+ courses from LinkedIn Learning.
  • Access to frequent development sessions on a number of topics to help you be successful and develop your career at CLS.
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: Audits Banking CISM Compliance CRISC Governance ISO 27001 Monitoring NIST NIST 800-53 Risk assessment Risk management RSA SOC 1 Vulnerability management

Perks/benefits: 401(k) matching Career development Fitness / gym Flex hours Health care Medical leave Parental leave Team events

Region: Europe
Country: United Kingdom

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.