At a Glance
- Tasks: Lead the Bank's Information Security activities and manage risk identification and remediation.
- Company: Join the European Bank for Reconstruction and Development, promoting economic transition and sustainable growth.
- Benefits: Enjoy a diverse work culture, flexible working options, and opportunities to make a real-world impact.
- Why this job: Be at the forefront of Cybersecurity in a dynamic, international environment with a mission-driven team.
- Qualifications: Experience as a Head of Information Security or CISO, strong communication, and project management skills required.
- Other info: Diversity and inclusion are core values; all qualified candidates are encouraged to apply.
The predicted salary is between 72000 - 100000 £ per year.
We are looking for a highly skilled Head of Information Security to join our Operational Risk Management (ORM) team at the European Bank for Reconstruction and Development (EBRD). This is a unique opportunity to play a vital role in leading the Bank's Information Security activities and working closely with IT Security to deliver the Bank's Cyber Resilience Programme.
Your Role and Purpose
As the Head of Information Security, you will report to the Director, Operational Risk Management (ORM) and be responsible for leading the Bank's Information Security risk identification and remediation activities. Including:
- Determining Information Security risk vision and strategy
- Providing expert Information Security consultancy and advice to Senior Management as well as the Bank's governance mechanisms i.e. Risk and Executive Committees, Board.
- Interfacing with first line (IT Security) and working closely with the CISO to provide oversight and assurance over key first-line activities, in particular, working with the CISO to design and deliver the Bank's multi-year Cyber Resilience Programme.
- Creating and managing the Bank's Information Security vision and strategy going forward.
- Interfacing with the Business to provide specialist advice, oversight and insight to ensure business operations follow good Information Security practice and policy.
- Scoping, conducting, and designing Information Security risk programmes and thereafter managing the subsequent remediation.
- Design, manage and deliver specialist assurance activities over first-line and the wider business including, Red & Purple Team assessments, Data Leakage, and Disinformation & Dark-Web Assessments and Social Engineering exercises.
Key Responsibilities
- Measure and report on the implementation and compliance of the Bank's Information Security framework (policies, procedures, guidance) throughout the organisation and verify the implementation of Information Security controls and evaluate their effectiveness.
- Manage internal teams and external consultants as they provide support in the delivery of risk mitigation activities.
- Influence and support change by aligning policy updates with new regulations and business needs and critically, emerging security threats.
- Manage the programmes which provide security oversight over internal IT and Business projects and external suppliers.
- Act as the Information Security SME to support the Bank's delivery of the new GRC solution, ensuring that existing solutions and services which deliver risk assessments, and third party supplier assurance assessments, are successfully transitioned over to the new GRC solution.
- Track and advise on industry security trends and their implications.
What We’re Looking For
- Experience as a 'Head of Information Security' or CISO.
- Leading teams and enterprise risk remediation programmes.
- Designing and delivering enterprise Information Security risk remediation programmes.
- Designing and delivering enterprise Cybersecurity risk remediation programmes.
- Ability to read, understand and analyse regulatory information, 'good practice' and develop Information Security strategies and programs.
- Strong written and verbal communication skills, especially the ability to translate technical details into business-friendly language.
- Strong project management and stakeholder engagement abilities.
- Ability to work independently, manage multiple priorities, and maintain high attention to detail.
- A collaborative mindset with strong influencing and problem-solving capabilities is a must.
- Strong technical skills and/or previous background as to effectively challenge first-line.
- Excellent oral and written communication skills to effectively interact with executive management, internal and external clients.
- Knowledge of AI risks and technologies/services is an advantage.
- Working experience in a consulting environment is an advantage.
- Knowledge of Ethical Hacking techniques is an advantage.
- Strong project management skills.
- Strong understanding of NIST, ISO27001.
Why Join EBRD?
Working with us means contributing to projects that promote economic transition and sustainable growth. You’ll be part of a diverse, mission-driven team with a real-world impact across the EBRD's regions. In this role, you’ll be at the heart of strengthening our Information Security and Cybersecurity activities, working in a dynamic, international environment.
What is it like to work at the EBRD?
Our agile and innovative approach is what makes life at the EBRD a unique experience! You will be part of a pioneering and diverse international organisation, and use your talents to make a real difference to people’s lives and help shape the future of the regions we invest in.
The EBRD environment provides you with:
- Varied, stimulating and engaging work that gives you an opportunity to interact with a wide range of experts in the financial, political, public and private sectors across the regions we invest in;
- A working culture that embraces inclusion and celebrates diversity;
- An environment that places sustainability, equality and digital transformation at the heart of what we do.
Diversity is one of the Bank's core values which are at the heart of everything it does. A diverse workforce with the right knowledge and skills enables connection with our clients, brings pioneering ideas, energy and innovation. The EBRD staff is characterised by its rich diversity of nationalities, cultures and opinions and we aim to sustain and build on this strength. As such, the EBRD seeks to ensure that everyone is treated with respect and given equal opportunities and works in an inclusive environment. The EBRD encourages all qualified candidates who are nationals of the EBRD member countries to apply regardless of their racial, ethnic, religious and cultural background, gender, sexual orientation or disabilities. As an inclusive employer, we promote flexible working and expect our employees to attend the office 50% of their working time.
Please note, that due to the high volume of applications received, we regret to inform you that we are unable to provide detailed feedback to candidates who have not been shortlisted.
Senior Information Security Consultant | London, UK employer: EBRD
Contact Detail:
EBRD Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Information Security Consultant | London, UK
✨Tip Number 1
Network with professionals in the information security field, especially those who have experience in risk management or have worked at EBRD. Attend industry events or webinars to connect with potential colleagues and learn more about the bank's culture.
✨Tip Number 2
Stay updated on the latest trends in cybersecurity and information security frameworks like NIST and ISO27001. This knowledge will not only help you in interviews but also demonstrate your commitment to the field.
✨Tip Number 3
Prepare to discuss your previous experiences in leading information security teams and projects. Be ready to provide specific examples of how you've successfully managed risk remediation programmes and influenced policy changes.
✨Tip Number 4
Familiarise yourself with EBRD's mission and values, particularly their focus on sustainability and diversity. Tailor your discussions to show how your personal values align with theirs, which can set you apart from other candidates.
We think you need these skills to ace Senior Information Security Consultant | London, UK
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in Information Security, particularly any roles as a Head of Information Security or CISO. Use keywords from the job description to demonstrate your fit for the role.
Craft a Compelling Cover Letter: Write a cover letter that showcases your leadership skills and experience in managing enterprise risk remediation programmes. Be sure to explain how your background aligns with the responsibilities outlined in the job description.
Highlight Communication Skills: Since strong written and verbal communication skills are essential for this role, provide examples in your application of how you've successfully translated technical information into business-friendly language in previous positions.
Showcase Project Management Experience: Detail your project management experience, especially in relation to Information Security initiatives. Mention specific projects where you managed teams or influenced change, aligning with the key responsibilities of the position.
How to prepare for a job interview at EBRD
✨Understand the Role Thoroughly
Before the interview, make sure you have a deep understanding of the responsibilities and expectations of the Head of Information Security role. Familiarise yourself with the Bank's Cyber Resilience Programme and be prepared to discuss how your experience aligns with their needs.
✨Showcase Your Leadership Skills
As this position involves leading teams and managing risk remediation programmes, be ready to share specific examples of your leadership experiences. Highlight how you've successfully influenced change and managed projects in previous roles.
✨Communicate Clearly and Effectively
Strong communication skills are essential for this role. Practice explaining complex technical concepts in simple terms, as you'll need to convey information to senior management and stakeholders who may not have a technical background.
✨Stay Updated on Industry Trends
Demonstrate your knowledge of current trends in Information Security and Cybersecurity during the interview. Be prepared to discuss recent developments, such as AI risks and ethical hacking techniques, and how they might impact the Bank's operations.