At a Glance
- Tasks: Lead security governance and risk management to ensure a robust security posture.
- Company: Join CLS Group, a leader in financial services and technology.
- Benefits: Enjoy a full-time role with opportunities for professional growth and development.
- Why this job: Make a real impact on cybersecurity while collaborating with diverse teams.
- Qualifications: 5+ years in Information Security, with strong risk management skills required.
- Other info: Ideal for those passionate about continuous learning in a dynamic environment.
The predicted salary is between 43200 - 72000 £ per year.
The individual will be part of the security function that is responsible for security governance, risk and assurance, to ensure the organisations security posture is robust, compliant against the security policy, standards and controls. The position will require close collaboration with technical, operational, compliance and audit teams to create a secure and compliant technology environment.
What you will be doing:
- Maintain security policy, standards, procedures and frameworks.
- Ensure alignment with security industry standards such as NIST CSF and NIST 800-53.
- Act as an advisor to colleagues across the organisation on best security practice.
- Conduct regular risk assessments and maintain risk register in RSA Archer.
- Identify, assess and prioritize security risk across the organisation’s information assets and environments.
- Understand security gaps and provide evaluation and treatment options, consultation on remediation approaches to address gaps and continue ongoing monitoring of remediation, re-assess until reduced to an acceptable level.
- Support Cybersecurity Risk Management strategies based on security findings and observations.
- Profile and assign asset security criticality and prioritize risk assessments.
- Monitor improvements against the baselined risk to evidence and report where security risk is being reduced to an acceptable level across security functions.
- Run lessons learned forums and recommend improvements to security controls.
- Represent security on audits and assessments, ensuring compliance with internal and external requirements.
- Provide assurance to stakeholders through detailed reporting and metrics.
What we’re looking for:
- Minimum of 5 years’ experience in Information and Cyber Security, with minimum of 2 years’ experience in a security risk team.
- Highly organised with experience of planning and reporting data, information and updates.
- Ability to collaborate effectively with others to drive forward key security objectives.
- Expert in technical writing reports and documenting risk assessment findings and mitigation plans clearly and accurately.
- Meticulous attention to detail to ensure data accuracy and integrity and ensure thorough and accurate risk assessment.
- Problem solving ability to grasp security issues that impact multiple entities and troubleshoot with proposing and consulting with colleagues on effective solutions to mitigate risks.
- Excellent verbal and written communication skills to convey complex technical information clearly and effectively.
- Strong understanding of security risk management and taxonomy principles, to reduce risk to an acceptable level.
- Knowledge of vulnerability management and incident management practices.
- Experience with GRC tools and best practices. RSA Archer is preferred.
- Financial and/or Banking industry experience preferred.
- Ideally qualified in MSc Information Security, CICA, CRISC, CISM and/or Data analysis beneficial but not essential if experience validates skills.
- Proficiency in security frameworks (e.g., NIST CSF, ISO 27001, SOC1,2).
- Prince 2, MSP, APMQ advantageous.
- A desire to continue learning and developing security skills and qualifications.
Seniority level: Mid-Senior level
Employment type: Full-time
Job function: Information Technology
Industries: Financial Services, Banking, and Investment Banking
Vice President, Security Governance, Risk and Assurance employer: CLS Group
Contact Detail:
CLS Group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Vice President, Security Governance, Risk and Assurance
✨Tip Number 1
Network with professionals in the cybersecurity field, especially those who have experience in security governance and risk management. Attend industry events or webinars to connect with potential colleagues and learn about the latest trends and challenges in the sector.
✨Tip Number 2
Familiarise yourself with the specific security frameworks mentioned in the job description, such as NIST CSF and ISO 27001. Being able to discuss these frameworks confidently during interviews will demonstrate your expertise and commitment to the role.
✨Tip Number 3
Prepare to showcase your problem-solving skills by thinking of examples where you've successfully identified and mitigated security risks in previous roles. This will help you illustrate your ability to handle the responsibilities outlined in the job description.
✨Tip Number 4
Research CLS Group and their current security posture. Understanding their specific challenges and how your experience aligns with their needs will allow you to tailor your discussions and show that you're genuinely interested in contributing to their security governance efforts.
We think you need these skills to ace Vice President, Security Governance, Risk and Assurance
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in Information and Cyber Security, particularly focusing on security governance, risk management, and assurance. Use specific examples that demonstrate your expertise in these areas.
Craft a Compelling Cover Letter: In your cover letter, express your passion for security governance and risk management. Mention how your skills align with the requirements of the role and provide examples of past achievements that showcase your ability to collaborate effectively and drive security objectives.
Highlight Technical Writing Skills: Since the role requires expert technical writing, ensure you include examples of reports or documentation you've created in previous roles. This could be risk assessment findings or mitigation plans that clearly convey complex information.
Showcase Continuous Learning: Mention any ongoing education or certifications related to security frameworks (like NIST CSF or ISO 27001) and your desire to continue developing your skills. This demonstrates your commitment to staying current in the field.
How to prepare for a job interview at CLS Group
✨Know Your Security Frameworks
Familiarise yourself with key security frameworks like NIST CSF and ISO 27001. Be prepared to discuss how these frameworks can be applied in the role and how they align with the organisation's security posture.
✨Demonstrate Risk Assessment Skills
Be ready to explain your experience with conducting risk assessments and maintaining risk registers. Use specific examples from your past roles to illustrate how you've identified, assessed, and prioritised security risks.
✨Showcase Collaboration Experience
Highlight your ability to work with cross-functional teams, including technical, operational, compliance, and audit teams. Share examples of how you've successfully collaborated to achieve security objectives.
✨Prepare for Technical Questions
Expect questions that test your understanding of security governance and risk management principles. Brush up on your knowledge of vulnerability management and incident management practices to confidently address any technical queries.