Business Information Security Officer (Engine by Starling)

Business Information Security Officer (Engine by Starling)

Full-Time 70000 - 90000 £ / year (est.) Home office (partial)
Engine by Starling

At a Glance

  • Tasks: Shape security objectives and lead a growing Information Security team.
  • Company: Join Engine, a dynamic company partnered with Starling Bank.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Embrace a culture of innovation and continuous improvement in a supportive environment.
  • Why this job: Make a real impact in cybersecurity while collaborating with diverse stakeholders.
  • Qualifications: Experience in information security roles and strong leadership skills required.

The predicted salary is between 70000 - 90000 £ per year.

Requirements

  • Deep understanding and knowledge of cyber security principles, security standards and regulatory compliance and its application in a wide variety of organisations with a strong risk culture.
  • Experience in a business facing security role, ideally in an Information Security Director, BISO, CISO or similar capacity.
  • Strong business acumen and commercial awareness with previous experience in a senior client-facing role or similar.
  • Be a self-starter / self-motivated with the ability to lead, inspire and drive change through an organisation.
  • Have the ability to be pragmatic while balancing the needs of Engine against security.
  • Ability to work with a variety of stakeholders across all levels and can adapt communication style to different stakeholders.
  • Have an ability to think and plan strategically and systematically while recognising the need to deliver to the business requirements.
  • Have previous experience working in a complex IT organisation encompassing service delivery, application development and IT infrastructure.
  • An understanding of best practice within Information Security and risk management including standards such as ISO 27001, NIST, Cyber Essentials and COBIT.
  • An understanding of legislation and regulations that impact information Security, e.g. Data Protection Act and GDPR, Freedom of Information Act, PCI DSS.
  • Have previous experience in leading, developing and motivating a team of subject matter experts.
  • An understanding of current and emerging threats and countermeasures and the organisational challenges to addressing these threats.
  • A good practical knowledge of security technologies and wider business solutions including Identity and access management, SIEM, remote working and cloud technologies.
  • Experience of working in a banking or financial services environment would be beneficial.
  • ISC2 CISSP or ISACA CISM, ISACA CRISC, CISA or Open FAIR qualifications would be beneficial.

What the job involves

  • This role will shape our Security objectives, practices and associated policies and processes within Engine as well as lead the continuous improvement of our Information Security capabilities whilst managing a growing Information Security Team.
  • The successful candidate will act as the liaison between Engine and Starling Bank’s Information Security teams whilst also ensuring that they are the point of contact for all Information security related questions raised by Engine clients and our auditors.
  • We’re looking for a curious, versatile, adaptable and experienced information security or cyber specialist with executive presence and strong leadership skills who enjoys the challenge of a varied and collaborative role.
  • You’ll enjoy problem solving, working with a wide variety of stakeholders, and enabling us to be creative in continuing to provide innovative products and services to support our clients, and stay at the forefront of all things Information Security.
  • Manage and maintain the Information Security Policy and Information Security Management System to ensure it meets the needs of Engine, its clients, employees and other stakeholders and compliance with the relevant industry standards, regulatory and certification requirements such as ISO 27001.
  • Oversee Engine’s Information Security governance documents (processes, standards and procedures) and optimise reporting of identified threats and vulnerabilities.
  • Oversee the process for obtaining and maintaining compliance certifications and accreditations including but not limited to ISO 27001, SOC 1, SOC 2 and PCI DSS/3DS through engagement with internal teams and our external auditors.
  • Maintain the Information Security Risk Register; identifying, assessing and mitigating information security risks (including security risks related to third-parties and partners) and ensuring coherence with Engine’s Risk Management framework.
  • Act as a point of contact for all Information Security related client queries and issues; providing expert opinion and communication during initial client conversations, RFPs, RFIs, delivery and throughout the client lifecycle.
  • Act as an Information Security point of contact for Business Continuity Planning and Disaster Recovery; this includes responsibility for initiation and execution of cyber business impact analysis.
  • Advise the wider organisation on compliance and governance requirements.
  • Oversee Incident Response related to Information Security and ensure coherence and collaboration with the broader Technology response capability.
  • Liaise with external bodies and organisations to keep abreast of the threat landscape, emerging trends, technologies and legislation that have an impact on Information Security.
  • Assist as necessary to investigate security breaches and pursue associated disciplinary and legal matters.
  • Lead and manage a team of subject matter experts to ensure Information Security is managed effectively throughout the IT service delivery lifecycle, addressing client needs.
  • Promote security awareness by collaborating with the relevant teams to provide training and awareness to the wider Engine organisation.

You may be put off applying for a role because you don't tick every box. Forget that! While we can’t accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren’t sure if you're 100% there yet, get in touch anyway.

Business Information Security Officer (Engine by Starling) employer: Engine by Starling

At Engine, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. As a Business Information Security Officer, you'll have the opportunity to lead a talented team while shaping our security objectives in a supportive environment that values professional growth and development. Located in a vibrant area, we provide competitive benefits and a commitment to work-life balance, making Engine a rewarding place to advance your career in information security.

Engine by Starling

Contact Details:

Engine by Starling Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Business Information Security Officer (Engine by Starling)

Tip Number 1

Network like a pro! Reach out to your connections in the industry, especially those who work at Engine or Starling. A friendly chat can open doors and give you insider info that could help you stand out.

Tip Number 2

Prepare for interviews by researching common questions for security roles. Think about how your experience aligns with the job description and be ready to share specific examples of your past successes.

Tip Number 3

Show off your passion for information security! During interviews, discuss current trends and threats in the field. This not only demonstrates your knowledge but also your enthusiasm for the role.

Tip Number 4

Don’t hesitate to apply through our website! Even if you don’t tick every box, we value diverse experiences and perspectives. If you’re excited about the role, go for it!

We think you need these skills to ace Business Information Security Officer (Engine by Starling)

Cyber Security Principles
Regulatory Compliance
Risk Management
Information Security Standards (ISO 27001, NIST, Cyber Essentials, COBIT)
Data Protection Legislation (GDPR, Data Protection Act)
Client-Facing Experience
Leadership Skills

Some tips for your application 🫡

Show Off Your Cyber Security Knowledge:Make sure to highlight your understanding of cyber security principles and standards in your application. We want to see how your experience aligns with the requirements, so don’t hold back on showcasing your expertise!

Tailor Your Application:When applying, tailor your CV and cover letter to reflect the specific skills and experiences mentioned in the job description. We love seeing candidates who can adapt their communication style to different stakeholders, so make that clear!

Be Yourself!:We’re looking for a self-starter with strong leadership skills, so let your personality shine through in your application. Share examples of how you’ve inspired change or led teams in the past – we want to know what makes you tick!

Apply Through Our Website:Don’t forget to apply through our website! It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining our team at StudySmarter!

How to prepare for a job interview at Engine by Starling

Know Your Cyber Security Stuff

Make sure you brush up on your knowledge of cyber security principles and standards like ISO 27001 and NIST. Be ready to discuss how these apply in real-world scenarios, especially in a banking or financial services context.

Show Off Your Leadership Skills

Prepare examples that showcase your ability to lead and inspire teams. Think about times when you've driven change or motivated others in a complex IT environment. This role is all about managing a team of experts, so highlight your experience in this area.

Tailor Your Communication Style

You’ll be dealing with various stakeholders, so practice adapting your communication style to different audiences. Whether it’s technical jargon for IT folks or simplified explanations for clients, being versatile will set you apart.

Stay Current with Threats and Trends

Familiarise yourself with the latest threats and countermeasures in information security. Be prepared to discuss emerging trends and how they impact organisations. Showing that you're proactive about staying informed will impress your interviewers.