At a Glance
- Tasks: Lead security governance, risk management, and assurance to protect our tech environment.
- Company: Join CLS, a key player in the global FX ecosystem, making currency transactions safer and smoother.
- Benefits: Enjoy 25+ holiday days, hybrid working, wellness support, and a generous pension plan.
- Why this job: Be part of a diverse team that values innovation and makes a real impact in finance.
- Qualifications: 5+ years in Info/Cyber Security with strong risk management skills; certifications preferred.
- Other info: Collaborate with top professionals and access extensive learning resources for career growth.
The predicted salary is between 72000 - 108000 £ per year.
About CLS: CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars' worth of currency flows through our systems each day. Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world's most actively traded currencies. We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use. CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle - whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market. Our ambition to make a positive difference starts with our people. Our values - Protect, Improve, Grow - underpin everything that we do at CLS and define and shape a supportive and inclusive working environment in which everyone is encouraged to be open and forward-thinking.
About the role: The individual will be part of the security function that is responsible for security governance, risk and assurance, to ensure the organisations security posture is robust, compliant against the security policy, standards and controls. The position will require close collaboration with technical, operational, compliance and audit teams to create a secure and compliant technology environment.
What you will be doing:
- Maintain security policy, standards, procedures and frameworks.
- Ensure alignment with security industry standards such as NIST CSF and NIST 800-53.
- Act as an advisor to colleagues across the organisation on best security practice.
- Conduct regular risk assessments and maintain risk register in RSA Archer.
- Identify assess and prioritize security risk across the organisation's information assets and environments.
- Understanding security gaps and provide evaluation and treatment options, consultation on remediation approaches to address gaps and continue ongoing monitoring of remediation, re-assess until reduced to an acceptable level.
- Supporting Cybersecurity Risk Management strategies based on security findings and observations.
- Profile and assign asset security criticality and prioritize risk assessments.
- Run lessons learned forums and recommend improvements to security controls.
- Represent security on audits and assessments, ensuring compliance with internal and external requirements.
- Provide assurance to stakeholders through detailed reporting and metrics.
What we're looking for:
- Minimum of 5 years' experience in Information and Cyber Security, with minimum of 2 years' experience in a security risk team.
- Highly organised with experience of planning and reporting data, information and updates.
- Ability to collaborate effectively with others to drive forward key security objectives.
- Expert in technical writing reports and documenting risk assessment findings and mitigation plans clearly and accurately.
- Attention to detail, Meticulous attention to detail to ensure data accuracy and integrity and ensure thorough and accurate risk assessment.
- Problem solving, ability to grasp security issues that impact multiple entities and troubleshoot with proposing and consulting with colleagues on effective solutions to mitigate risks.
- Excellent verbal and written communication skills to convey complex technical information clearly and effectively.
- Strong understanding of security risk management and taxonomy principles, to reduce risk to an acceptable level.
- Knowledge of vulnerability management and incident management practices.
- Experience with GRC tools and best practices. RSA Archer is preferred.
- Financial and/or Banking industry experience preferred.
Professional qualifications / certifications: Ideally qualified in MSc Information Security, CICA, CRISC, CISM and/or Data analysis beneficial but not essential if experience validates skills. Proficiency in security frameworks (e.g., NIST CSF, ISO 27001, SOC1,2). Prince 2, MSP, APMQ advantageous. A desire to continue learning and developing security skills and qualifications.
Our commitment to employees: At CLS, we celebrate diversity and consider this to be one of our strongest assets. We are committed to fostering an environment in which everyone feels comfortable to be who they are, and inclusion is valued. All employees have access to our inclusive benefits, including:
- Holiday - UK/Asia: 25 holiday days and 3 'life days' (in addition to bank holidays). US: 23 holiday days.
- 2 paid volunteer days so that you can actively support causes within your community that are important to you.
- Generous parental leave policies to ensure you can enjoy valuable time with your family.
- Wellbeing and mental health support resources to ensure you are looking after yourself, and able to support others.
- Hybrid working to promote a healthy work/life balance, enabling employees to work collaboratively in the office when needed and work from home when they don't.
- Active support of flexible working for all employees where possible.
- Monthly 'Heads Down Days' with no meetings across the whole company.
- Generous non-contributory pension provision for UK/Asia employees, and 401K match from CLS for US employees.
- Private medical insurance and dental coverage.
- Social events that give you opportunities to meet new people and broaden your network across the organisation.
- Annual flu vaccinations.
- Discounts and savings and cashback across a wide range of categories including health and retail for UK employees.
- All employees have access to Discover - our comprehensive learning platform with 1000+ courses from LinkedIn Learning.
- Access to frequent development sessions on a number of topics to help you be successful and develop your career at CLS.
Contact Detail:
CLS-Group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Vice President, Security Governance, Risk and Assurance
✨Tip Number 1
Familiarise yourself with the NIST CSF and NIST 800-53 frameworks, as these are crucial for the role. Understanding these standards will not only help you in interviews but also demonstrate your commitment to aligning with industry best practices.
✨Tip Number 2
Network with professionals in the cybersecurity field, especially those with experience in financial services. Attend relevant conferences or webinars to gain insights and make connections that could lead to referrals or recommendations.
✨Tip Number 3
Prepare to discuss specific examples of how you've conducted risk assessments and managed security policies in previous roles. Being able to articulate your hands-on experience will set you apart from other candidates.
✨Tip Number 4
Stay updated on the latest trends and threats in cybersecurity, particularly those affecting the financial sector. This knowledge will not only enhance your discussions during interviews but also show your proactive approach to security governance.
We think you need these skills to ace Vice President, Security Governance, Risk and Assurance
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in Information and Cyber Security, particularly focusing on your time in security risk teams. Use specific examples that demonstrate your ability to maintain security policies and conduct risk assessments.
Craft a Compelling Cover Letter: In your cover letter, express your passion for security governance and risk management. Mention how your values align with CLS's commitment to protecting and improving their security posture, and provide examples of how you've successfully collaborated with cross-functional teams.
Highlight Technical Writing Skills: Since the role requires expert technical writing, ensure you showcase your ability to document risk assessment findings and mitigation plans clearly. Include any relevant reports or documentation you've created in previous roles as evidence of your skills.
Showcase Continuous Learning: Mention any professional qualifications or certifications you hold, such as CISA, CRISC, or CISM, and express your desire to continue learning and developing your security skills. This shows your commitment to staying updated in the ever-evolving field of cybersecurity.
How to prepare for a job interview at CLS-Group
✨Understand the Security Frameworks
Familiarise yourself with security frameworks such as NIST CSF and ISO 27001. Be prepared to discuss how these frameworks can be applied to enhance security governance and risk management within the organisation.
✨Showcase Your Risk Assessment Skills
Be ready to explain your experience with conducting risk assessments and maintaining risk registers. Highlight specific examples where you identified security gaps and proposed effective remediation strategies.
✨Communicate Clearly and Effectively
Demonstrate your ability to convey complex technical information in a clear manner. Practice explaining your past projects or findings to non-technical stakeholders, as this will be crucial in your role.
✨Emphasise Collaboration Experience
Since the role requires close collaboration with various teams, share examples of how you've successfully worked with technical, operational, compliance, and audit teams in the past to achieve security objectives.