Business Information Security Manager Apply now
Business Information Security Manager

Business Information Security Manager

London Full-Time 54000 - 84000 £ / year (est.)
Apply now
L

At a Glance

  • Tasks: Lead security oversight for Regulatory Reporting, ensuring data protection and effective cyber controls.
  • Company: Join LSEG, a trusted global financial markets infrastructure and data provider.
  • Benefits: Enjoy a dynamic work environment with opportunities for growth and development.
  • Why this job: Make a real impact in cybersecurity while collaborating with diverse teams and stakeholders.
  • Qualifications: 10+ years in senior InfoSec roles, with expertise in FS or FMI industries required.
  • Other info: Must have CISSP certification; additional certifications are a plus.

The predicted salary is between 54000 - 84000 £ per year.

LSEG

LSEG is your trusted global financial markets infrastructure and data provider. Discover how we deliver value for our customers.

The purpose of this role is to assist the Director of Business Information Security (BISO) in all security matters relating to the oversight of Information Security, Cyber Security and Data Privacy within the Regulatory Reporting business line of LSEG’s Post Trade division. The successful candidate will be charged with ensuring that the critical business systems and data assets of Regulatory Reporting are adequately protected, and that all related information security and cyber controls remain effective and within risk appetite and/or have appropriate risk treatment plans in place to bring them back into risk appetite.

The role will best suit an experienced Information Security Manager with extensive experience gained from having previously operated within Senior Management level InfoSec/Cyber roles within the FS or FMI industries.

The successful candidate must be a subject matter expert in Information Security, as the role demands a very strong knowledge in all areas of information security and cyber security, as well as in-depth knowledge of legacy, existing, and emerging technologies including cloud and security technologies/controls. In addition to a solid foundationary Security Governance Risk and Compliance (Security-GRC) skillset, a prior background in information security engineering, security architecture, and security operations will be advantageous in this role given the various levels of stakeholders as well as the tech/cyber projects that the successful candidate will engage with daily.

Key responsibilities include:

Assisting in the oversight of Information Security by:

  • Reviewing and assessing the information security and cyber controls that enable Regulatory Reporting to conduct its business in a secure manner, and gap analysis of the same.
  • The oversight of InfoSec/Cyber related control gap/risk remediation activities.
  • Monitoring and analysing the information security roadmaps, strategies, programmes, and projects within Regulatory Reporting, and identifying and reporting risks, trends and future opportunities for improvement and enhancement.
  • Proactively engaging and working closely with the technology and cyber teams that are delivering technology and cyber services to the firm.
  • Attending risk and governance meetings to provide updates to the Regulatory Reporting stakeholders from the three lines of defence regarding the delivery and progress of the various strategic cyber initiatives and broader cyber programme within LSEG.
  • Working with colleagues from the three lines of defence to define the current risk posture of Regulatory Reporting and collaborating with those stakeholders to remediate identified risks/issues.
  • Engaging with external third parties who provide services to Regulatory Reporting and working closely with the established internal third-party oversight functions to ensure appropriate and contracted levels of security are met.
  • Establish and maintain a Cyber Risk Profile of Regulatory Reporting in line with other areas of LSEG.
  • Assisting with the establishment and maintenance of a Risk Control Assessment (RCA) that focuses on InfoSec/Cyber risks and associated controls, etc.
  • Maintaining the established key performance and key risk indicators and ensuring that all management information (MI) is an accurate reflection of the current control’s estate.
  • Maintaining an accurate set of executive level presentation materials that clearly and accurately present the current state of security control within Regulatory Reporting.
  • Assessing the security architecture solution designs and risk position of projects and initiatives undertaken by Regulatory Reporting and working closely with associated SMEs and design authorities to ensure projects are delivered in compliance with Policies and Standards, and with security design principles considered/implemented as key success deliverables.

Engagement with the business to:

  • Develop an understanding of business goals and operational risks.
  • Identifying key areas for improvement.
  • Support the risk management decision processes and risk forums/committees.
  • Assisting with the identification of emerging information and cyber security threats to the business, and the subsequent analysis to realise and oversee risk mitigation plans.
  • Build strong relationships within the business to gain an understanding of security-related business risks.
  • Work closely with governance stakeholders in the 1st, 2nd, and 3rd lines of defence on all matters relating to information security, cyber risk, data privacy, including all regulatory and legislative considerations.

Embedding Cyber across the firm by:

  • Working closely with all necessary stakeholders in the business and technology areas to ensure compliance with established LSEG policies, standards, and procedures.
  • Constructively and pragmatically challenging established controls to ensure, recommend, and accommodate continuous improvement.
  • Ensuring Regulatory Reporting stakeholders understand their responsibilities in relation to security risk mitigation and remediation.
  • Monitoring industry information security trends and keeping business leadership informed about information security-related issues and activities potentially affecting the organisation and specific business functions.

Security Governance, Technical, and Risk Review:

  • The review and documenting of technologies and security controls across the firm, including areas such as office spaces, data centres and cloud.
  • Executing and concluding security controls maturity assessments against industry standards such as the NIST Cyber Security Framework, ISO27001/2, SOC2, etc.
  • Working closely with stakeholders to review all projects and initiatives, assessing them for appropriate/correct levels of security design and controls.
  • Identification of technology and security risks across the firm and the assessment and appropriate risk scoring and presentation of the same.
  • Produce appropriate risk remediation action plans and ability to present and take ownership of risk treatment proposals and action plans.
  • Review and appropriate response to regulatory and legislative matters.
  • Produce and present risks and risk postures/cyber maturity to senior/executive bodies.
  • Able to clearly and precisely present complex cyber risk matters to clients and regulators.

Partnering with the different business control functions:

  • Build knowledge of business units by assisting them with their security workloads, agendas, and difficulties.
  • Maintaining a balanced relationship with risk, compliance, legal, human resources, and internal and external audit functions.

Knowledge of technology, security, and threat landscapes:

  • Staying abreast of emerging technologies, including all security technologies.
  • Sustaining a deep and in-depth knowledge of the cyber threat landscape.
  • Maintain and constantly enriching knowledge of information security and cyber risks as they develop.
  • Being able to propose and explain appropriate cyber risk counter measures clearly and concisely.
  • Remaining informed and knowledgeable on primary global data protection regulations and legislation.

Experience and core skill requirements:

  • 10 years minimum experience in senior InfoSec management roles.
  • Extensive previous exposure to FS or FMI industry organisations.
  • High performance in problem solving, innovating and critical thinking.
  • Excellent written/verbal communication and stakeholder management skills.
  • Ability to articulate ideas to both technical and non-technical audiences.
  • Must be capable of working pragmatically and efficiently in both a team and alone.
  • Able to prioritise workloads efficiently and appropriately with minimal supervision.
  • Able to work in fast paced, high-volume workload environment, prioritising accordingly.

Must Have Security Certifications:

  • CISSP

Desirable & Advantageous Certifications:

  • CISSP-ISSAP, CISSP-ISSEP, CISM, CCSP, CCSK, CEH

Working knowledge of Security Standards / Frameworks:

  • ISO27K, ISF SOGP, NIST CSF, CIS, CSA STAR, CBEST, TIBER-EU, SOC2

#J-18808-Ljbffr

Business Information Security Manager employer: LSEG

At LSEG, we pride ourselves on being a leading global financial markets infrastructure and data provider, offering a dynamic work environment that fosters innovation and collaboration. As a Business Information Security Manager, you will benefit from our commitment to employee growth through continuous learning opportunities and a supportive culture that values diverse perspectives. Located in a vibrant city, our team enjoys a flexible work-life balance, competitive compensation, and the chance to make a meaningful impact in the ever-evolving field of information security.
L

Contact Detail:

LSEG Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Business Information Security Manager

✨Tip Number 1

Familiarize yourself with the specific security frameworks and standards mentioned in the job description, such as NIST CSF and ISO27001. This knowledge will not only help you understand the role better but also demonstrate your commitment to the field during discussions.

✨Tip Number 2

Network with professionals in the financial services or financial market infrastructure sectors. Engaging with industry peers can provide insights into current trends and challenges, which you can leverage in your conversations with us.

✨Tip Number 3

Stay updated on emerging cyber threats and security technologies. Being able to discuss recent developments in the cybersecurity landscape will showcase your proactive approach and expertise in the field.

✨Tip Number 4

Prepare to articulate your experience in managing information security risks and controls effectively. Use specific examples from your past roles to illustrate how you've successfully navigated similar challenges, as this will resonate well with our team.

We think you need these skills to ace Business Information Security Manager

Information Security Management
Cyber Security Expertise
Data Privacy Knowledge
Risk Management
Security Governance Risk and Compliance (Security-GRC)
Security Architecture
Security Operations
Cloud Security Technologies
Stakeholder Management
Regulatory Compliance
Technical Communication Skills
Problem Solving
Critical Thinking
Project Management
Emerging Technology Awareness
Security Standards Knowledge (ISO27001, NIST CSF, etc.)
Risk Assessment and Mitigation
Executive Presentation Skills
Collaboration with Cross-Functional Teams
Ability to Work Independently

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights your extensive experience in Information Security, particularly within the FS or FMI industries. Emphasize your senior management roles and any relevant certifications like CISSP.

Craft a Strong Cover Letter: In your cover letter, clearly articulate your understanding of the role's responsibilities and how your background aligns with them. Mention specific experiences that demonstrate your expertise in cyber security and risk management.

Showcase Relevant Skills: Highlight your problem-solving abilities, communication skills, and experience with security standards/frameworks such as ISO27K and NIST CSF. Provide examples of how you've successfully managed security risks in previous roles.

Research LSEG: Familiarize yourself with LSEG’s business model and recent developments in their Regulatory Reporting division. This knowledge will help you tailor your application and demonstrate your genuine interest in the company.

How to prepare for a job interview at LSEG

✨Showcase Your Expertise

Make sure to highlight your extensive experience in Information Security, especially within the Financial Services or Financial Market Infrastructure sectors. Be prepared to discuss specific projects or challenges you've faced and how you addressed them.

✨Understand the Regulatory Landscape

Familiarize yourself with the regulatory requirements relevant to the role, such as data privacy laws and security standards like ISO27001 or NIST. Demonstrating your knowledge of these regulations will show that you are well-prepared for the responsibilities of the position.

✨Engage with Stakeholders

Prepare to discuss how you would build relationships with various stakeholders across the organization. Share examples of how you've successfully collaborated with different teams to enhance security measures and address risks.

✨Communicate Clearly

Since the role requires articulating complex cyber risk matters to both technical and non-technical audiences, practice explaining intricate concepts in simple terms. This will demonstrate your ability to communicate effectively with diverse groups.

Business Information Security Manager
LSEG Apply now
L
  • Business Information Security Manager

    London
    Full-Time
    54000 - 84000 £ / year (est.)
    Apply now

    Application deadline: 2027-01-08

  • L

    LSEG

  • Other open positions at LSEG

    L
    Senior Manager, Business Information Security

    LSEG

    London Full-Time 54000 - 84000 £ / year (est.)
    L
    Group Cyber Security Senior Project Manager

    LSEG

    London Full-Time 60000 - 84000 £ / year (est.)
Similar positions in other companies
L
Business Information Security Manager

London Stock Exchange Group

London Full-Time 54000 - 84000 £ / year (est.)
L
Senior Manager, Business Information Security

London Stock Exchange Group

London Full-Time 43200 - 72000 £ / year (est.)
Europas größte Jobbörse für Gen-Z
discover-jobs-cta
Discover now
>