At a Glance
- Tasks: Lead and enhance our Information Security practices while managing a growing team.
- Company: Join Engine by Starling, a tech-driven company transforming banking with innovative solutions.
- Benefits: Enjoy 33 days of holiday, private medical insurance, and perks like discounts and wellness programs.
- Why this job: Be part of a mission to revolutionize banking globally while working in a collaborative environment.
- Qualifications: Experience in cyber security roles with strong leadership skills and a deep understanding of security standards.
- Other info: Hybrid work model with flexibility in office attendance and potential for international travel.
The predicted salary is between 43200 - 72000 £ per year.
Business Information Security Officer (BISO) – Engine by Starling
Starling Bank
Transform the way you manage your money with Starling Bank. Enjoy personal and business banking online and at your fingertips, always. Apply in minutes.
At Engine by Starling, we are on a mission to find and work with leading banks all around the world who have the ambition to build rapid growth businesses, on our technology.
Engine is Starling’s software-as-a-service (SaaS) business, the technology that was built to power Starling Bank, and two years ago we split out as a separate business.
Starling Bank has seen exceptional growth and success, and a large part of that is down to the fact that we have built our own modern technology from the ground up. This SaaS technology platform is now available to banks and financial institutions all around the world, enabling them to benefit from the innovative digital features, and efficient back-office processes that has helped achieve Starling’s success.
As a company, everyone is expected to roll up their sleeves to help deliver great outcomes for our clients. We are an engineering led company and we’re looking for someone who will be excited by the potential for Engine’s technology to transform banking in different markets around the world.
Hybrid Working
We have a Hybrid approach to working here at Engine – our preference is that you’re located within a commutable distance of one of our offices so that we’re able to interact and collaborate in person. We don’t like to mandate how much you visit the office and work from home, that’s to be agreed upon between you and your manager.
Some travel (including international) may be necessary depending on the client and nature of the engagement.
About the Role
This role will shape our Security objectives, practices and associated policies and processes within Engine as well as lead the continuous improvement of our Information Security capabilities whilst managing a growing Information Security Team.
The successful candidate will act as the liaison between Starling Banks Information Security Team and Engine’s Information Security team whilst also ensuring that they are the point of contact for all Information security related questions raised by Engine clients and our auditors.
We’re looking for a curious, versatile, adaptable and experienced information security or cyber specialist with executive presence and strong leadership skills who enjoys the challenge of a varied and collaborative role.
You’ll enjoy problem solving, working with a wide variety of stakeholders, and enabling us to be creative in continuing to provide innovative products and services to support our clients, and stay at the forefront of all things Information Security.
What you’ll get to do
- Manage and maintain the Information Security Policy and Information Security Management System to ensure it meets the needs of Engine, its clients, employees and other stakeholders and compliance with the relevant industry standards, regulatory and certification requirements such as ISO 27001.
- Oversee Engine’s Information Security governance documents (processes, standards and procedures) and optimise reporting of identified threats and vulnerabilities.
- Oversee the process for obtaining and maintaining compliance certifications and accreditations including but not limited to ISO 27001, SOC 2 and PCI DSS/3DS through engagement with internal teams and our external auditors.
- Maintain the Information Security Risk Register; identifying, assessing and mitigating information security risks (including security risks related to third-parties and partners) and ensuring coherence with Engine’s Risk Management framework.
- Act as a point of contact for all Information Security related client queries and issues; providing expert opinion and communication during initial client conversations, RFPs, RFIs, delivery and throughout the client lifecycle.
- Act as an Information Security point of contact for Business Continuity Planning and Disaster Recovery; this includes responsibility for initiation and execution of cyber business impact analysis.
- Advise the wider organisation on compliance and governance requirements.
- Oversee Incident Response related to Information Security and ensure coherence and collaboration with the broader Technology response capability.
- Liaise with external bodies and organisations to keep abreast of the threat landscape, emerging trends, technologies and legislation that have an impact on Information Security.
- Assist as necessary to investigate security breaches and pursue associated disciplinary and legal matters.
- Lead and manage a team of subject matter experts to ensure Information Security is managed effectively throughout the IT service delivery lifecycle, addressing client needs.
- Promote security awareness by collaborating with the relevant teams to provide training and awareness to the wider Engine organisation.
Requirements
- Deep understanding and knowledge of cyber security principles, security standards and regulatory compliance and its application in a wide variety of organisations with a strong risk culture.
- Experience in a business facing security role, ideally in an Information Security Director, BISO, CISO or similar capacity.
- Strong business acumen and commercial awareness with previous experience in a senior client-facing role or similar.
- Be a self starter / self motivated with the ability to lead, inspire and drive change through an organisation.
- Have the ability to be pragmatic while balancing the needs of Engine against security.
- Ability to work with a variety of stakeholders across all levels and can adapt communication style to different stakeholders.
- Have an ability to think and plan strategically and systematically while recognising the need to deliver to the business requirements.
- Have previous experience working in a complex IT organisation encompassing service delivery, application development and IT infrastructure.
- An understanding of best practice within Information Security and risk management including standards such as ISO 27001, NIST, Cyber Essentials and COBIT.
- An understanding of legislation and regulations that impact information Security. E.g. Data Protection Act and GDPR, Freedom of Information Act, PCI DSS.
- Have previous experience in leading, developing and motivating a team of subject matter experts.
- An understanding of current and emerging threats and countermeasures and the organisational challenges to addressing these threats.
- A good practical knowledge of security technologies and wider business solutions including Identity and access management, SIEM, remote working and cloud technologies.
- Experience of working in a banking or financial services environment would be beneficial.
- ISC2 CISSP or ISACA CISM, ISACA CRISC, CISA or Open FAIR qualifications would be beneficial.
This role for applications will close on Mon 21st October.
Benefits
- 33 days holiday (including public holidays, which you can take when it works best for you).
- An extra day’s holiday for your birthday.
- Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off.
- 16 hours paid volunteering time a year.
- Salary sacrifice, company enhanced pension scheme.
- Life insurance at 4x your salary & group income protection.
- Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton.
- Generous family-friendly policies.
- Incentives refer a friend scheme.
- Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks.
- Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing.
Engine by Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Engine by Starling are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.
#J-18808-Ljbffr
Business Information Security Officer (BISO) - Engine by Starling employer: Starling Bank
Contact Detail:
Starling Bank Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Business Information Security Officer (BISO) - Engine by Starling
✨Tip Number 1
Familiarize yourself with the specific security standards and regulatory compliance requirements mentioned in the job description, such as ISO 27001 and PCI DSS. This knowledge will not only help you understand the role better but also demonstrate your commitment to the field during discussions.
✨Tip Number 2
Network with professionals in the banking and financial services sector, especially those who have experience in information security roles. Engaging with them can provide insights into the industry and may even lead to referrals or recommendations for the position.
✨Tip Number 3
Prepare to discuss your leadership experience and how you've successfully managed teams in previous roles. Highlight specific examples where you drove change or improved security practices, as this aligns with the expectations for the BISO role.
✨Tip Number 4
Stay updated on current trends and emerging threats in information security. Being able to speak knowledgeably about recent developments will show your proactive approach and passion for the field, making you a more attractive candidate.
We think you need these skills to ace Business Information Security Officer (BISO) - Engine by Starling
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Business Information Security Officer position. Tailor your application to highlight relevant experiences and skills that align with the job description.
Highlight Relevant Experience: In your CV and cover letter, emphasize your experience in information security, particularly in roles like BISO or CISO. Provide specific examples of how you've managed security policies, compliance certifications, and risk assessments in previous positions.
Showcase Leadership Skills: Since this role involves leading a team, be sure to include examples of your leadership experience. Discuss how you've motivated teams, driven change, and collaborated with various stakeholders to achieve security objectives.
Tailor Your Application: Customize your cover letter to reflect your enthusiasm for Engine by Starling and its mission. Mention how your values align with their approach to innovation and client service in the banking sector.
How to prepare for a job interview at Starling Bank
✨Understand the Role and Responsibilities
Make sure you have a clear understanding of the Business Information Security Officer role. Familiarize yourself with the key responsibilities, such as managing the Information Security Policy and overseeing compliance certifications like ISO 27001. This will help you articulate how your experience aligns with their needs.
✨Showcase Your Leadership Skills
Since this position involves leading a growing Information Security Team, be prepared to discuss your leadership style and past experiences. Highlight instances where you've successfully motivated a team or driven change within an organization, especially in a security context.
✨Demonstrate Your Knowledge of Cyber Security Standards
Be ready to discuss your understanding of cyber security principles and relevant standards such as NIST, Cyber Essentials, and PCI DSS. Providing examples of how you've applied these standards in previous roles will demonstrate your expertise and suitability for the position.
✨Prepare for Client-Facing Scenarios
As this role involves acting as a point of contact for client queries, prepare for questions that assess your communication skills and ability to handle client relationships. Think of examples where you've successfully navigated complex client interactions or resolved security-related issues.