Cyber Security Specialist (Security control testing)
Cyber Security Specialist (Security control testing)

Cyber Security Specialist (Security control testing)

London Full-Time 64000 - 76000 £ / year (est.) No home office possible
S

At a Glance

  • Tasks: Join us as a Cyber Security Specialist, testing and improving security controls daily.
  • Company: Be part of a leading financial services organisation in the heart of London.
  • Benefits: Enjoy a hybrid work model with competitive salary and annual bonuses.
  • Why this job: Make a real impact on cybersecurity while collaborating with talented professionals.
  • Qualifications: 5+ years in Cyber Security, ideally within finance; strong problem-solving and communication skills required.
  • Other info: Must be within commuting distance to London HQ for 2 days a week.

The predicted salary is between 64000 - 76000 £ per year.

Docklands, London - Hybrid £80,000 - £90,000 per annum + annual discretionary bonus

On behalf of a leading financial services organisation, I am seeking an experienced Cyber Security Specialist at AVP level. The individual will play a critical role in strengthening the organisation's security posture with hands-on testing of security controls. The Specialist applies their expertise to recommend corrective actions, improvements to security controls and runs lessons learned forums. You will also conduct regular risk assessments and maintain the risk register in RSA Archer.

The company operates a hybrid work policy and therefore you must be willing to commit to 2 days per week and must be within commutable distance of their London HQ.

Responsibilities:
  • Maintain security policy, standards, procedures and frameworks.
  • Ensure alignment with security industry standards such as NIST CSF and NIST 800-53.
  • Hands-on testing of security controls.
  • Conduct regular risk assessments and maintain the risk register in RSA Archer.
  • Represent security on audits and assessments, ensuring compliance with internal and external requirements.
  • Identify, assess and prioritise security risk across the organisation's information assets and environments.
  • Understand security gaps and provide evaluation and treatment options, consultation on remediation approaches to address gaps and continue ongoing monitoring of remediation, re-assess until reduced to an acceptable level.
  • Support Cybersecurity Risk Management strategies based on security findings and observations.
  • Profile and assign asset security criticality and prioritise risk assessments.
  • Monitor improvements against the baselined risk to evidence and report where security risk is being reduced to an acceptable level across security functions.
  • Run lessons learned forums and recommend improvements to security controls.
  • Provide assurance to stakeholders through detailed reporting and metrics.
Skills/Experience required:
  • Minimum of 5 years' experience in Information and Cyber Security with demonstrable hands-on testing of security controls.
  • You will ideally hold experience in a Cyber Security capacity within a Financial and/or Banking environment.
  • Highly organised with experience of planning and reporting data, information and updates.
  • Ability to collaborate effectively with others to drive forward key security objectives.
  • Good level of technical writing reports and documenting risk assessment findings and mitigation plans clearly and accurately.
  • Attention to detail, meticulous attention to detail to ensure data accuracy and integrity and ensure thorough and accurate risk assessment.
  • Problem solving, ability to grasp security issues that impact multiple entities and troubleshoot with proposing and consulting with colleagues on effective solutions to mitigate risks.
  • Good verbal and written communication skills to convey complex technical information clearly and effectively.
  • Base level understanding of security risk management and taxonomy principles, to reduce risk to an acceptable level.
  • Knowledge of vulnerability management and incident management practices.
  • Ability to learn GRC tools and best practices. RSA Archer is preferred (alternatives considered).
Professional Certifications:
  • Ideally qualified in MSc Information Security, CICA, CRISC, CISM and/or Data analysis beneficial but not essential if experience validates skills.
  • Knowledge of security frameworks (e.g., NIST CSF, ISO 27001, SOC1,2).

Cyber Security Specialist (Security control testing) employer: Spencer Rose

As a leading financial services organisation based in Docklands, London, we pride ourselves on being an excellent employer that values innovation and security. Our hybrid work policy promotes a healthy work-life balance, while our commitment to employee growth through continuous learning and professional development ensures that you will thrive in your career as a Cyber Security Specialist. Join us to be part of a collaborative culture that prioritises security excellence and offers competitive compensation, including an annual discretionary bonus.
S

Contact Detail:

Spencer Rose Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Cyber Security Specialist (Security control testing)

✨Tip Number 1

Familiarise yourself with the specific security frameworks mentioned in the job description, such as NIST CSF and NIST 800-53. Being able to discuss these frameworks in detail during your interview will demonstrate your expertise and alignment with the company's standards.

✨Tip Number 2

Prepare to showcase your hands-on experience with security control testing. Think of specific examples where you've identified vulnerabilities and implemented corrective actions, as this will highlight your practical skills and problem-solving abilities.

✨Tip Number 3

Brush up on your knowledge of RSA Archer or similar GRC tools. If you can speak confidently about how you've used these tools in past roles, it will set you apart from other candidates who may not have that experience.

✨Tip Number 4

Be ready to discuss your approach to risk assessments and how you prioritise security risks. Having a clear methodology will show your analytical skills and your ability to contribute to the organisation's cybersecurity risk management strategies.

We think you need these skills to ace Cyber Security Specialist (Security control testing)

Hands-on Security Control Testing
Risk Assessment and Management
Knowledge of NIST CSF and NIST 800-53
Experience with RSA Archer
Technical Writing Skills
Attention to Detail
Problem-Solving Skills
Collaboration and Teamwork
Communication Skills
Understanding of Vulnerability Management
Incident Management Practices
Knowledge of Security Frameworks (e.g., ISO 27001, SOC 1,2)
Ability to Learn GRC Tools
Organisational Skills
Reporting and Data Analysis

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in Cyber Security, particularly hands-on testing of security controls. Emphasise any experience you have in financial services or banking environments, as this is crucial for the role.

Craft a Strong Cover Letter: In your cover letter, explain why you're passionate about Cyber Security and how your skills align with the responsibilities outlined in the job description. Mention specific frameworks like NIST CSF and your experience with risk assessments to demonstrate your fit for the role.

Showcase Technical Writing Skills: Since the role requires good technical writing skills, include examples of reports or documentation you've created in previous roles. This could be risk assessment findings or security control evaluations that showcase your ability to communicate complex information clearly.

Highlight Problem-Solving Abilities: Use your application to illustrate your problem-solving skills. Provide examples of how you've identified security gaps and proposed effective solutions in past roles. This will show your proactive approach to Cyber Security challenges.

How to prepare for a job interview at Spencer Rose

✨Showcase Your Hands-On Experience

Make sure to highlight your practical experience in testing security controls. Be prepared to discuss specific examples of how you've identified and mitigated security risks in previous roles, especially within a financial or banking environment.

✨Demonstrate Knowledge of Security Frameworks

Familiarise yourself with key security frameworks such as NIST CSF and NIST 800-53. During the interview, be ready to explain how these frameworks influence your approach to maintaining security policies and conducting risk assessments.

✨Prepare for Technical Questions

Expect technical questions related to vulnerability management and incident management practices. Brush up on your knowledge of GRC tools, particularly RSA Archer, and be ready to discuss how you would use them in your role.

✨Communicate Clearly and Effectively

Since you'll need to present complex technical information to non-technical stakeholders, practice explaining your past projects and findings in simple terms. Good verbal and written communication skills are crucial for this position.

Cyber Security Specialist (Security control testing)
Spencer Rose
S
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>