At a Glance
- Tasks: Lead the design and implementation of enterprise security architecture to protect our systems.
- Company: CLS is a key player in the global FX ecosystem, making currency transactions safer and more efficient.
- Benefits: Enjoy hybrid working, generous leave, private medical cover, and access to extensive learning resources.
- Why this job: Join a purpose-driven team where your contributions directly impact the financial market's stability.
- Qualifications: 8+ years in information security with expertise in security architecture and risk management frameworks.
- Other info: Be part of an inclusive culture that prioritises employee well-being and career development.
The predicted salary is between 72000 - 100000 £ per year.
About CLS: CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars’ worth of currency flows through our systems each day. Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies. We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use. CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market.
Our ambition to make a positive difference starts with our people. Our values – Protect, Improve, Grow – underpin everything that we do at CLS and define and shape a supportive and inclusive working environment in which everyone is encouraged to be open and forward-thinking.
Job purpose: We are seeking a highly skilled and strategic Enterprise Security Architect reporting to the Enterprise Security Architecture Manager, to lead the design, implementation, and continuous improvement of Security Architecture across the enterprise. In this role, you will collaborate with senior leadership, key stakeholders, and cross-functional teams to define and align security strategies with business objectives, ensuring security alignment to business objectives, evolving threat landscapes, and industry standards across the enterprise to mitigate risks and address emerging threats.
The Enterprise Security Architect will play a pivotal role in developing and enforcing the enterprise security architecture strategy and roadmap, developing patterns and conducting capability gap assessments whilst maintaining integration into the company's business and technology landscape. You will be responsible for maturing the security architecture practice, defining principles and input into policies and standards that span multiple business domains and technical environments, including cloud, infrastructure, and applications. This position requires deep expertise in security architecture, a strong understanding of risk management, and the ability to influence and guide key decisions at the enterprise level.
Key responsibilities include:
- Lead the development and execution of the enterprise security architecture strategy and roadmaps, working closely with senior leadership, Enterprise Architecture, and technical teams to align security initiatives with broader business goals.
- Drive the integration of security across the enterprise.
- Champion security across multiple divisions, ensuring security is embedded into the design and implementation of products, services, and technology solutions.
- Provide thought leadership and guidance on security risks, policies, and controls to senior management and stakeholders, influencing key business decisions.
- Collaborate with internal and external stakeholders to ensure the security architecture supports business objectives, ensuring scalability, compliance, and future state.
- Develop and enforce security architecture frameworks, policies, and standards to guide the secure implementation of IT solutions across the enterprise, with particular emphasis on Cloud Security, SaaS, and IaaS models, ensuring alignment with industry best practices and evolving regulatory requirements.
- Familiarity with SABSA framework and its six layers, particularly in risk management and security strategy development.
- Lead efforts to assess and mature security practices across the enterprise.
- Stay abreast of industry trends, frameworks, and regulations (e.g., GDPR, ISO 27001/2, SANS Top 20 Critical Security Controls, NIST CSF, SP 800-53, PFMI, CPMI ISOCO and FFIEC handbook, SABSA) to ensure the organization is proactive in addressing emerging security threats and compliance challenges.
- Foster relationships with key functional teams such as IT, Compliance, Operations, Finance, HR, Internal Audit, and Enterprise Risk to support current and future initiatives.
- Keep informed of new and emerging security threats & assess effectiveness of current controls to identify opportunities for program improvement.
- Provide expert-level security architecture design, analysis, and consultation to enterprise-wide programs, ensuring security risks are appropriately mitigated during the planning and design stages.
- Work closely with technology teams, including Infrastructure, Cloud, Development, and Security, to embed security into solutions from the outset.
- Oversee and guide assessments of new technologies, vendors, and third-party services to ensure compliance with enterprise security standards and reduce potential risk exposure.
- Lead and guide project and program managers to ensure the integration of security architecture across various initiatives, with a focus on scalability, compliance, and risk management.
- Define, monitor, and enforce security architecture governance processes to ensure that security standards and controls are met across the enterprise.
Knowledge, skills and abilities:
- 8+ years of experience in information security, with a strong background in security architecture across large, complex enterprise environments.
- Proven ability to design, implement, and lead security initiatives across cloud, network, application, and infrastructure domains.
- Extensive experience working with senior leadership and stakeholders to drive strategic security initiatives, influencing decisions at the enterprise level.
- Strong understanding of security frameworks, including NIST CSF, SABSA etc, and the ability to apply them in diverse environments.
Qualifications and certifications:
- Degree in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent).
- Professional certifications such as CISSP, CISA, CISM, CRISC, SABSA, or equivalent.
- Deep expertise in risk management frameworks, including ISO 27001, NIST SP 800-53, and SANS Top 20 Critical Security Controls.
- Experience with cloud security solutions and services.
Our commitment to employees:
We are a small company with a big mandate, so every person is essential to our success. We are also committed to employing and retaining the most talented and dedicated people. What makes us interesting goes beyond our competitive salaries and great benefits. Our work environment is designed around quality outcomes, not output. The FX market would cease to function without our services, and we take pride in being responsible for keeping it running smoothly. We are different from other financial institutions in that we have a flatter and more transparent structure with accessible leadership. You will be seen, heard and empowered to develop your career. We are a purpose-driven organization, with an inclusive culture that focuses on doing what is right. The well-being of our people is as important to us as the resilience of our systems. In addition to encouraging our people to ‘locate for their day,’ we run a range of initiatives that support employees’ sense of belonging and physical, emotional and mental well-being.
Our extensive benefits for employees typically include:
- Vacation/annual leave: 25 days in UK/Asia + 3 life days, 23 in US + 3 life days.
- Private medical and dental cover and life insurance.
- Generous pension contributions in the UK and Asia; matching 401(k) in the US.
- Paid volunteer days.
- ‘Locate for your day’ hybrid working – 2 days a week in office.
- Access to Discover – our learning platform with 1000+ courses from LinkedIn Learning.
- Paid parental leave / Coaching and support services.
- Career development / LinkedIn Learning.
- ‘Heads down days’ with no meetings on the last Friday of every month.
- Wellbeing / Mental health support.
- Diversity Council / Affinity groups (Women’s Forum, Black Employee Network, Pride Network, Parents & Caregivers Network, Sustainability Network).
Awards:
- The Sunday Times Best Places to Work 2023 & 2024 / Big Company / The Sunday Times Awards.
- Third place in Britain’s Healthiest Workplace 2022 / Medium Company / Vitality Awards.
Enterprise Security Architect employer: CLS-Group
Contact Detail:
CLS-Group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Enterprise Security Architect
✨Tip Number 1
Familiarise yourself with the SABSA framework and its six layers, as this is crucial for the Enterprise Security Architect role. Understanding how to apply this framework in risk management and security strategy development will give you a significant edge during discussions with our team.
✨Tip Number 2
Stay updated on the latest industry trends and regulations such as GDPR and ISO 27001. Being able to discuss these topics knowledgeably will demonstrate your proactive approach to security and compliance, which is highly valued at CLS.
✨Tip Number 3
Build connections with professionals in IT security and related fields. Networking can provide insights into the role and help you understand the challenges and expectations of an Enterprise Security Architect, making you a more compelling candidate.
✨Tip Number 4
Prepare to discuss your experience in leading security initiatives across various domains, especially cloud and infrastructure. Highlighting specific examples of how you've influenced strategic decisions will showcase your leadership capabilities and alignment with our goals.
We think you need these skills to ace Enterprise Security Architect
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in security architecture, risk management, and cloud security. Use keywords from the job description to demonstrate that you meet the specific requirements of the Enterprise Security Architect role.
Craft a Compelling Cover Letter: In your cover letter, explain why you are passionate about security architecture and how your skills align with CLS's mission. Mention specific projects or achievements that showcase your ability to lead security initiatives and influence decisions at the enterprise level.
Showcase Relevant Certifications: List any professional certifications such as CISSP, CISA, or SABSA prominently in your application. These credentials are crucial for demonstrating your expertise and commitment to the field of information security.
Highlight Collaborative Experience: Emphasise your experience working with cross-functional teams and senior leadership. Provide examples of how you've successfully integrated security into business objectives and influenced key decisions, as this is a vital aspect of the role.
How to prepare for a job interview at CLS-Group
✨Understand the Security Landscape
Familiarise yourself with the latest trends in security architecture, especially those relevant to the financial sector. Be prepared to discuss how you would address emerging threats and align security strategies with business objectives.
✨Showcase Your Experience
Highlight your extensive experience in information security and security architecture. Be ready to provide specific examples of how you've successfully implemented security initiatives across cloud, network, application, and infrastructure domains.
✨Demonstrate Leadership Skills
Since this role involves influencing senior leadership and stakeholders, prepare to discuss your approach to leading security initiatives. Share instances where you've effectively communicated complex security concepts to non-technical audiences.
✨Align with Company Values
Research CLS's values of Protect, Improve, and Grow. During the interview, express how your personal values align with theirs and how you can contribute to fostering a supportive and inclusive working environment.