At a Glance
- Tasks: Join us as a Risk & Control Advisor, focusing on security control frameworks and compliance.
- Company: Euroclear is a global leader in financial market infrastructure, prioritising IT risk management and security.
- Benefits: Enjoy flexible working options, competitive perks, and a dynamic work environment.
- Why this job: Be part of a transformative team that enhances IT security culture and drives impactful change.
- Qualifications: Master’s degree or equivalent experience, with 5+ years in security risk and control environments.
- Other info: Ideal for motivated self-starters eager to influence and collaborate across diverse teams.
The predicted salary is between 43200 - 72000 £ per year.
Euroclear is a global critical financial market infrastructure company. Strong IT Risk Management and Security are at the core of the company’s services, firmly embedded in their management systems and processes. The Regulatory Watch, Policies and Controls team is part of the Cyber Information Security Office Division and is in charge of driving the definition and implementation of the policy and control framework addressing the key IT and Security risks and ensuring compliance to all regulations and external requirements applicable to the Technology organization of the group.
This role focuses on the security control framework, covering all key security domains including Identity & Access Management, Vulnerability Management, Security Monitoring and Incident Management, Platform, Network and Application Security among others. The Euroclear security control framework is built upon the ISO 27001/2 and CIS industry standards and is currently being implemented within the ServiceNow GRC platform.
Your active role will encompass both defining and implementing controls during the change phase, as well as managing the control framework as it transitions to live operation for continuous monitoring, evidencing, and ongoing improvement during the run phase. You will contribute to design, co-create and roll out effective controls addressing key risks and regulatory requirements across all security domains, advising and challenging control owners. By promoting and implementing controls you will help to improve the risk culture and control maturity in IT.
You will work closely with security process owners, control owners and performers across IT divisions and locations, as well as liaise with second and third lines of defence (Risk Management and Internal Audit). You have a strong risk mind-set, are a good relationship builder and want to play a critical role in the IT and Security Risk transformation and change roadmap. Proficient (oral and written) communication as well as influencing are part of your main skills.
Requirements
- University Master’s degree or equivalent experience (education in computer science, engineering or cybersecurity is a plus)
- 5+ years field experience in the security risk and control environment, preferably in controls design/implementation area in large/enterprise multi-platform-based IT environments
- Good knowledge of the key principles of the Information Security Management Systems and various Security Technology Domains such as Identity and Access Management, Network Security, Vulnerability Management, Endpoint Security, Data Protection, Security Incident Management
- Certifications in security such as CISSP, CISM, GIAC is a key advantage
- A good understanding and experience with ServiceNow GRC or equivalent solution is a strong asset
- Proficient knowledge of English (verbal, writing, presentation)
- You possess a strong risk and control attitude; your thoroughness ensures consistently high-quality work.
- You have good communication skills, whether on the field, in the team or with management: you are a great teammate and coordinate work amongst people from different areas or divisions.
- A good relationship builder with diplomacy skills.
- You are a highly motivated self-starter and quick learner, and you can work proactively in an environment with challenging priorities.
- You are analytical and risk oriented. You know how to break down complex situations to address logical links and dependencies.
- You can distinguish essential information and summarize it accordingly.
- You have the ability to challenge and influence IT and Security experts.
- You acquire approval of others with good arguments, appropriate influencing methods and personal assertiveness (persuasion), constructively challenging and negotiating at levels up to middle management.
Risk & Control Advisor employer: Euroclear
Contact Detail:
Euroclear Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Risk & Control Advisor
✨Tip Number 1
Familiarise yourself with the ISO 27001/2 and CIS industry standards, as these are crucial for the role. Understanding these frameworks will not only help you in interviews but also demonstrate your commitment to the security control framework.
✨Tip Number 2
Network with professionals in the cybersecurity field, especially those who have experience with ServiceNow GRC or similar platforms. Engaging with them can provide insights into the role and may even lead to referrals.
✨Tip Number 3
Prepare to discuss real-world scenarios where you've successfully implemented security controls or managed risks. Use the STAR method (Situation, Task, Action, Result) to structure your responses effectively during interviews.
✨Tip Number 4
Showcase your communication and relationship-building skills by preparing examples of how you've influenced stakeholders in previous roles. This is key for a position that requires collaboration across various IT divisions.
We think you need these skills to ace Risk & Control Advisor
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in IT risk management and security. Emphasise your familiarity with security control frameworks, particularly ISO 27001/2 and CIS standards, as well as any certifications like CISSP or CISM.
Craft a Compelling Cover Letter: In your cover letter, express your passion for IT security and risk management. Discuss specific experiences where you've successfully implemented controls or improved risk culture, and how these relate to the role at Euroclear.
Showcase Communication Skills: Since proficient communication is key for this role, provide examples in your application that demonstrate your ability to influence and build relationships across different teams. Highlight any experience in presenting complex information clearly.
Highlight Analytical Abilities: Illustrate your analytical skills by detailing instances where you've broken down complex security issues or challenges. Show how you identified essential information and made logical connections to resolve problems effectively.
How to prepare for a job interview at Euroclear
✨Understand the Security Control Framework
Familiarise yourself with the ISO 27001/2 and CIS industry standards, as these are central to the role. Be prepared to discuss how you have implemented or managed security controls in previous positions.
✨Showcase Your Risk Mindset
Demonstrate your strong risk and control attitude by providing examples of how you've identified and mitigated risks in past roles. Highlight your analytical skills and ability to break down complex situations.
✨Communicate Effectively
Since proficient communication is key, practice articulating your thoughts clearly and concisely. Prepare to discuss how you've influenced stakeholders and built relationships in previous roles.
✨Prepare for Technical Questions
Expect questions related to Identity & Access Management, Vulnerability Management, and other security domains. Brush up on your technical knowledge and be ready to explain how you've applied it in real-world scenarios.