At a Glance
- Tasks: Lead the Bank's Information Security activities and manage risk identification and remediation.
- Company: Join the European Bank for Reconstruction and Development, a mission-driven organisation promoting sustainable growth.
- Benefits: Enjoy a diverse work culture, flexible working options, and opportunities to make a real-world impact.
- Why this job: Be at the forefront of Cybersecurity in a dynamic international environment with a focus on innovation.
- Qualifications: Experience as a Head of Information Security or CISO, strong communication skills, and project management abilities required.
- Other info: Diversity is key; we welcome applicants from all backgrounds and promote an inclusive workplace.
The predicted salary is between 48000 - 72000 £ per year.
We are looking for a highly skilled Head of Information Security to join our Operational Risk Management (ORM) team at the European Bank for Reconstruction and Development (EBRD). This is a unique opportunity to play a vital role in leading the Bank\’s Information Security activities and working closely with IT Security to deliver the Bank\’s Cyber Resilience Programme.
Your Role and Purpose
As the Head of Information Security, you will report to the Director, Operational Risk Management (ORM) and be responsible for leading the Bank\’s Information Security risk identification and remediation activities. Including:
- Determining Information Security risk vision and strategy
- Providing expert Information Security consultancy and advice to Senior Management as well as the Bank\’s governance mechanisms i.e. Risk and Executive Committees, Board.
- Interfacing with first line (IT Security) and working closely with the CISO to provide oversight and assurance over key first-line activities, in particular, working with the CISO to design and deliver the Bank\’s multi-year Cyber Resilience Programme.
- Creating and managing the Bank\’s Information Security vision and strategy going forward.
- Interfacing with the Business to provide specialist advice, oversight and insight to ensure business operations follow good Information Security practice and policy.
- Scoping, conducting, and designing Information Security risk programmes and thereafter managing the subsequent remediation.
- Design, manage and deliver specialist assurance activities over first-line and the wider business including, Red & Purple Team assessments, Data Leakage, and Disinformation & Dark-Web Assessments and Social Engineering exercises.
Key Responsibilities
- Measure and report on the implementation and compliance of the Bank\’s Information Security framework (policies, procedures, guidance) throughout the organisation and verify the implementation of Information Security controls and evaluate their effectiveness.
- Manage internal teams and external consultants as they provide support in the delivery of risk mitigation activities.
- Influence and support change by aligning policy updates with new regulations and business needs and critically, emerging security threats.
- Manage the programmes which provide security oversight over internal IT and Business projects and external suppliers.
- Act as the Information Security SME to support the Bank\’s delivery of the new GRC solution, ensuring that existing solutions and services which deliver risk assessments, and third party supplier assurance assessments, are successfully transitioned over to the new GRC solution.
- Track and advise on industry security trends and their implications.
What We\’re Looking For
- Experience as a \’Head of Information Security\’ or CISO.
- Leading teams and enterprise risk remediation programmes.
- Designing and delivering enterprise Information Security risk remediation programmes.
- Designing and delivering enterprise Cybersecurity risk remediation programmes.
- Ability to read, understand and analyse regulatory information, \’good practice\’ and develop Information Security strategies and programs.
- Strong written and verbal communication skills, especially the ability to translate technical details into business-friendly language.
- Strong project management and stakeholder engagement abilities.
- Ability to work independently, manage multiple priorities, and maintain high attention to detail.
- A collaborative mindset with strong influencing and problem-solving capabilities is a must.
- Strong technical skills and/or previous background as to effectively challenge first-line.
- Excellent oral and written communication skills to effectively interact with executive management, internal and external clients.
- Knowledge of AI risks and technologies/services is an advantage.
- Working experience in a consulting environment is an advantage.
- Knowledge of Ethical Hacking techniques is an advantage.
- Strong project management skills.
- Strong understanding of NIST, ISO27001
Why Join EBRD?
Working with us means contributing to projects that promote economic transition and sustainable growth. You\’ll be part of a diverse, mission-driven team with a real-world impact across the EBRD\’s regions. In this role, you\’ll be at the heart of strengthening our Information Security and Cybersecurity activities, working in a dynamic, international environment.
What is it like to work at the EBRD?
Our agile and innovative approach is what makes life at the EBRD a unique experience! You will be part of a pioneering and diverse international organisation, and use your talents to make a real difference to people\’s lives and help shape the future of the regions we invest in.
The EBRD environment provides you with:
- Varied, stimulating and engaging work that gives you an opportunity to interact with a wide range of experts in the financial, political, public and private sectors across the regions we invest in;
- A working culture that embraces inclusion and celebrates diversity;
- An environment that places sustainability, equality and digital transformation at the heart of what we do.
Diversity is one of the Bank\’s core values which are at the heart of everything it does. A diverse workforce with the right knowledge and skills enables connection with our clients, brings pioneering ideas, energy and innovation. The EBRD staff is characterised by its rich diversity of nationalities, cultures and opinions and we aim to sustain and build on this strength. As such, the EBRD seeks to ensure that everyone is treated with respect and given equal opportunities and works in an inclusive environment. The EBRD encourages all qualified candidates who are nationals of the EBRD member countries to apply regardless of their racial, ethnic, religious and cultural background, gender, sexual orientation or disabilities. As an inclusive employer, we promote flexible working and expecting our employee to attend the office 50% of their working time.
Please note, that due to the high volume of applications received, we regret to inform you that we are unable to provide detailed feedback to candidates who have not been shortlisted (for further consideration).
Job Segment: Information Security, Bank, Banking, Sustainability, Compliance, Technology, Finance, Energy, Legal
Senior Information Security Consultant employer: European Bank for Reconstruction and Development
Contact Detail:
European Bank for Reconstruction and Development Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Information Security Consultant
✨Tip Number 1
Network with professionals in the information security field, especially those who have experience in banking or financial institutions. Attend industry conferences and seminars to meet potential colleagues and learn about the latest trends and challenges in cybersecurity.
✨Tip Number 2
Familiarise yourself with the specific regulations and compliance standards relevant to the European Bank for Reconstruction and Development. Understanding NIST and ISO27001 will give you an edge and demonstrate your commitment to the role.
✨Tip Number 3
Prepare to discuss your previous experiences in leading information security teams and projects. Be ready to share specific examples of how you've successfully managed risk remediation programmes and influenced policy changes in your past roles.
✨Tip Number 4
Showcase your ability to communicate complex technical concepts in a business-friendly manner. Practice explaining your past projects and their impact on the organisation to ensure you can effectively engage with senior management during interviews.
We think you need these skills to ace Senior Information Security Consultant
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience as a Head of Information Security or CISO. Focus on your leadership roles, risk remediation programmes, and any specific achievements in cybersecurity that align with the job description.
Craft a Compelling Cover Letter: In your cover letter, express your passion for information security and how your skills can contribute to the EBRD's Cyber Resilience Programme. Use clear examples from your past experiences to demonstrate your ability to lead teams and manage complex projects.
Highlight Communication Skills: Given the importance of communication in this role, emphasise your strong written and verbal communication skills. Provide examples of how you've successfully translated technical details into business-friendly language for senior management.
Showcase Industry Knowledge: Mention your understanding of industry security trends, NIST, ISO27001, and any knowledge of AI risks or ethical hacking techniques. This will show that you are well-versed in current challenges and solutions in the information security landscape.
How to prepare for a job interview at European Bank for Reconstruction and Development
✨Understand the Role Thoroughly
Before the interview, make sure you have a deep understanding of the responsibilities and expectations of the Head of Information Security role. Familiarise yourself with the Bank's Cyber Resilience Programme and be prepared to discuss how your experience aligns with their needs.
✨Showcase Your Leadership Skills
As this position involves leading teams and managing risk remediation programmes, be ready to share specific examples of your leadership experiences. Highlight how you've successfully influenced change and managed diverse teams in previous roles.
✨Communicate Clearly and Effectively
Strong communication skills are essential for this role. Practice translating complex technical information into business-friendly language. Be prepared to demonstrate your ability to engage with senior management and stakeholders effectively.
✨Stay Updated on Industry Trends
Demonstrate your knowledge of current trends in Information Security and Cybersecurity, including AI risks and ethical hacking techniques. Being able to discuss these topics will show your commitment to staying informed and proactive in the field.