At a Glance
- Tasks: Lead security governance and risk management to ensure a robust security posture.
- Company: Join CLS Group, a leader in financial services and technology.
- Benefits: Enjoy a full-time role with opportunities for professional growth and development.
- Why this job: Make a real impact on cybersecurity while collaborating with diverse teams.
- Qualifications: 5+ years in Information Security, with strong risk management skills required.
- Other info: Ideal for those passionate about continuous learning in a dynamic environment.
The predicted salary is between 43200 - 72000 £ per year.
The individual will be part of the security function that is responsible for security governance, risk and assurance, to ensure the organisations security posture is robust, compliant against the security policy, standards and controls. The position will require close collaboration with technical, operational, compliance and audit teams to create a secure and compliant technology environment.
What you will be doing:
- Maintain security policy, standards, procedures and frameworks.
- Ensure alignment with security industry standards such as NIST CSF and NIST 800-53.
- Act as an advisor to colleagues across the organisation on best security practice.
- Conduct regular risk assessments and maintain risk register in RSA Archer.
- Identify, assess and prioritize security risk across the organisation’s information assets and environments.
- Understand security gaps and provide evaluation and treatment options, consultation on remediation approaches to address gaps and continue ongoing monitoring of remediation, re-assess until reduced to an acceptable level.
- Support Cybersecurity Risk Management strategies based on security findings and observations.
- Profile and assign asset security criticality and prioritize risk assessments.
- Monitor improvements against the baselined risk to evidence and report where security risk is being reduced to an acceptable level across security functions.
- Run lessons learned forums and recommend improvements to security controls.
- Represent security on audits and assessments, ensuring compliance with internal and external requirements.
- Provide assurance to stakeholders through detailed reporting and metrics.
What we’re looking for:
- Minimum of 5 years’ experience in Information and Cyber Security, with minimum of 2 years’ experience in a security risk team.
- Highly organised with experience of planning and reporting data, information and updates.
- Ability to collaborate effectively with others to drive forward key security objectives.
- Expert in technical writing reports and documenting risk assessment findings and mitigation plans clearly and accurately.
- Meticulous attention to detail to ensure data accuracy and integrity and ensure thorough and accurate risk assessment.
- Problem solving ability to grasp security issues that impact multiple entities and troubleshoot with proposing and consulting with colleagues on effective solutions to mitigate risks.
- Excellent verbal and written communication skills to convey complex technical information clearly and effectively.
- Strong understanding of security risk management and taxonomy principles, to reduce risk to an acceptable level.
- Knowledge of vulnerability management and incident management practices.
- Experience with GRC tools and best practices. RSA Archer is preferred.
- Financial and/or Banking industry experience preferred.
- Ideally qualified in MSc Information Security, CICA, CRISC, CISM and/or Data analysis beneficial but not essential if experience validates skills.
- Proficiency in security frameworks (e.g., NIST CSF, ISO 27001, SOC1,2).
- Prince 2, MSP, APMQ advantageous.
- A desire to continue learning and developing security skills and qualifications.
Seniority level: Mid-Senior level
Employment type: Full-time
Job function: Information Technology
Industries: Financial Services, Banking, and Investment Banking
Contact Detail:
CLS-Group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Vice President, Security Governance, Risk and Assurance
✨Tip Number 1
Network with professionals in the cybersecurity field, especially those who have experience in security governance and risk management. Attend industry events or webinars to connect with potential colleagues and learn about the latest trends and challenges in the sector.
✨Tip Number 2
Familiarise yourself with the specific security frameworks mentioned in the job description, such as NIST CSF and ISO 27001. Being able to discuss these frameworks confidently during interviews will demonstrate your expertise and commitment to the role.
✨Tip Number 3
Prepare to showcase your problem-solving skills by thinking of examples where you've successfully identified and mitigated security risks in previous roles. This will help you illustrate your ability to handle the responsibilities outlined in the job description.
✨Tip Number 4
Stay updated on the latest developments in cybersecurity, particularly in the financial services sector. Being knowledgeable about current threats and compliance requirements will position you as a strong candidate who understands the unique challenges faced by organisations like CLS Group.
We think you need these skills to ace Vice President, Security Governance, Risk and Assurance
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in Information and Cyber Security, particularly focusing on your time in security risk teams. Use specific examples that demonstrate your expertise in security governance and risk management.
Craft a Compelling Cover Letter: In your cover letter, express your passion for security governance and risk assurance. Mention how your skills align with the requirements listed in the job description, such as your experience with NIST standards and your ability to collaborate across teams.
Highlight Technical Writing Skills: Since the role requires expert technical writing, include samples or descriptions of reports you've written in the past. Emphasise your ability to document risk assessment findings and mitigation plans clearly and accurately.
Showcase Problem-Solving Abilities: Provide examples in your application that illustrate your problem-solving skills, especially in relation to security issues that impact multiple entities. Discuss how you have proposed effective solutions to mitigate risks in previous roles.
How to prepare for a job interview at CLS-Group
✨Know Your Security Frameworks
Familiarise yourself with key security frameworks like NIST CSF and ISO 27001. Be prepared to discuss how these frameworks apply to the role and how you have implemented them in past positions.
✨Demonstrate Risk Assessment Skills
Be ready to explain your experience with conducting risk assessments and maintaining risk registers. Use specific examples to illustrate how you've identified, assessed, and prioritised security risks in previous roles.
✨Showcase Collaboration Experience
Highlight your ability to work with cross-functional teams, including technical, operational, compliance, and audit teams. Share examples of how you've successfully collaborated to achieve security objectives.
✨Prepare for Technical Questions
Expect questions that test your understanding of security governance and risk management principles. Brush up on your knowledge of vulnerability management and incident management practices to confidently address any technical queries.