Information Security Governance, Risk, and Compliance (GRC) Specialist
Information Security Governance, Risk, and Compliance (GRC) Specialist

Information Security Governance, Risk, and Compliance (GRC) Specialist

City of London Full-Time 36000 - 60000 £ / year (est.) No home office possible
Go Premium
J

At a Glance

  • Tasks: Develop and manage cybersecurity policies, conduct risk assessments, and ensure compliance with regulations.
  • Company: Join Janus Henderson, a leader in financial services committed to a brighter future.
  • Benefits: Inclusive culture, flexible working options, and opportunities for professional growth.
  • Why this job: Make a real impact in cybersecurity while collaborating with diverse teams.
  • Qualifications: Bachelor's degree in IT or Cybersecurity and 3-5 years of experience required.
  • Other info: Embrace a dynamic environment with a focus on continuous learning and development.

The predicted salary is between 36000 - 60000 £ per year.

Information Security Governance, Risk, and Compliance (GRC) Specialist

City: London

Division: Information Security

Why work for us?

A career at Janus Henderson is more than a job, it’s about investing in a brighter future together.

Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We will do this by protecting and growing our core business, amplifying our strengths and diversifying where we have the right.

Our Values are key to driving our success, and are at the heart of everything we do:

Clients Come First – Always | Execution Supersedes Intention | Together We Win | Diversity Improves Results | Truth Builds Trust

If our mission, values, and purpose align with your own, we would love to hear from you!

Your opportunity

Policy Development and Management:

  • Develop and maintain comprehensive cybersecurity policies and procedures.
  • Ensure these policies align with industry standards and regulatory requirements.
  • Assist in the integration of security practices and control across various technical and non-technical departments, enhancing workflow and operational processes.
  • Conduct regular risk assessments to help identify vulnerabilities and threats.
  • Collaborate and oversee the implementation of risk mitigation strategies.
  • Monitor emerging threats and evolving technologies to continuously refine risk assessment protocols.
  • Ability to design and evaluate control metrics for assessing the effectiveness of cybersecurity measures.
  • Collaborate with Enterprise risk management to embed cyber risk into broader risk registers and board-level reporting.

Compliance Management:

  • Monitor and ensure compliance with internal policies, industry standards, and regulatory requirement.
  • Engage with required stakeholders in Technology, Legal, Compliance and Internal Audit as required
  • Compile and deliver detailed compliance reports to senior management
  • Monitor upcoming regulations and prepare compliance roadmaps.

Training and Awareness:

  • Support and enhance engaging cybersecurity awareness training programs.
  • Foster a company-wide culture of cybersecurity awareness.
  • Keep current with the latest cybersecurity trends and best practices to inform training content and security measures
  • Train and guide wider Tech team members on best practices in cybersecurity risk management.
  • Actively participate in the response to security incidents.
  • Support post-incident evaluations and reporting.
  • Collaborate with relevant stakeholders to devise and enforce corrective measures aimed at bolstering defences against future incidents.

Stakeholder Engagement:

  • Maintain clear and effective communication with stakeholders at all levels.
  • Provide expert guidance on cybersecurity best practices.
  • Work collaboratively with Technology and other departments to achieve comprehensive security objective

Must have skills

  • Bachelor’s Degree in Information Technology, Cybersecurity, or a related field; equivalent work experience also considered.
  • 3 to 5 years of professional experience in information security.
  • Certification such as Certified Information Systems Security Professional (CISSP) strongly preferred.
  • Deep understanding of cybersecurity principles, frameworks (such as NIST, ISO/IEC 27001), and compliance standards.
  • Experience with financial service regulations and regulations such as FCA, SEC, MAS, DORA.
  • Proficient knowledge of network security principles and controls such as Firewalls, IPS/IPD, TCP/IP, DHCP, and DNS
  • Extensive experience in securing Operating Systems such as Windows, UNIX/Linux and Mac systems. This includes security access rights, implementing configuration best practices
  • Knowledge of cloud service models (IaaS, PaaS, SaaS) and deployment models (public, private, hybrid, community) and experience in implementing and managing cloud security best practices.
  • In-depth knowledge of IAM principles and technologies to manage digital identities and control user access and experience with Single Sign-On (SSO), Multi-Factor Authentication (MFA), and role-based access control (RBAC) systems to enhance security and operational efficiency.
  • Understanding of Secure DevOps / CI/CD pipeline governance

Supervisory responsibilities

  • No

You will be expected to understand the regulatory obligations of the firm, and abide by the regulated entity requirements and JHI policies applicable for your role.

At Janus Henderson Investors we’re committed to an inclusive and supportive environment. We believe diversity improves results and we welcome applications from candidates from all backgrounds. Don’t worry if you don’t think you tick every box, we still want to hear from you! We understand everyone has different commitments and while we can’t accommodate every flexible working request we’re happy to be asked about work flexibility and our hybrid working environment. If you need any reasonable accommodations during our recruitment process, please get in touch and let us know at recruiter@janushenderson.com.

All applicants must be willing to comply with the provisions of Janus Henderson Investment Advisory Code of Ethics related to personal securities activities and other disclosure and certification requirements, including past political contributions and political activities. Applicants’ past political contributions or activity may impact applicants’ eligibility for this position. Janus Henderson is an equal opportunity /Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. All applications are subject to background checks.

#J-18808-Ljbffr

Information Security Governance, Risk, and Compliance (GRC) Specialist employer: Janus Henderson AAA CLO ETF

At Janus Henderson, we pride ourselves on fostering a collaborative and inclusive work culture that prioritises employee growth and development. As an Information Security Governance, Risk, and Compliance (GRC) Specialist in London, you will benefit from our commitment to diversity, continuous learning, and a supportive environment that encourages innovation and excellence. Join us to be part of a mission-driven team dedicated to achieving superior financial outcomes while ensuring the highest standards of cybersecurity and compliance.
J

Contact Detail:

Janus Henderson AAA CLO ETF Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Governance, Risk, and Compliance (GRC) Specialist

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by researching the company and its values. Make sure you can articulate how your skills align with their mission. Show them you’re not just another candidate, but someone who truly gets what they’re about.

✨Tip Number 3

Practice makes perfect! Do mock interviews with friends or use online platforms. The more comfortable you are talking about your experience and skills, the better you’ll perform when it counts.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who take that extra step to engage with us directly.

We think you need these skills to ace Information Security Governance, Risk, and Compliance (GRC) Specialist

Cybersecurity Policy Development
Risk Assessment
Compliance Management
Stakeholder Engagement
Knowledge of NIST and ISO/IEC 27001
Understanding of FCA, SEC, MAS, DORA regulations
Network Security Principles
Operating Systems Security (Windows, UNIX/Linux, Mac)
Cloud Security Best Practices
Identity and Access Management (IAM)
Single Sign-On (SSO) and Multi-Factor Authentication (MFA)
Secure DevOps / CI/CD Pipeline Governance
Communication Skills
Training and Awareness Program Development

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in cybersecurity and compliance. Use keywords from the job description to show that you understand what we're looking for.

Showcase Your Skills: Don’t just list your qualifications; demonstrate how your skills align with our mission and values. Share specific examples of how you've tackled challenges in information security or risk management.

Be Clear and Concise: Keep your application straightforward and to the point. We appreciate clarity, so avoid jargon and ensure your writing is easy to read. This will help us see your potential right away!

Apply Through Our Website: We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy!

How to prepare for a job interview at Janus Henderson AAA CLO ETF

✨Know Your Cybersecurity Policies

Before the interview, make sure you’re well-versed in the latest cybersecurity policies and procedures relevant to the role. Familiarise yourself with frameworks like NIST and ISO/IEC 27001, as well as financial service regulations such as FCA and SEC. This will show that you’re not just a candidate but someone who understands the landscape.

✨Showcase Your Risk Assessment Skills

Be prepared to discuss your experience with conducting risk assessments and how you've identified vulnerabilities in past roles. Bring examples of how you’ve collaborated on risk mitigation strategies and the impact they had on your previous organisations. This will demonstrate your hands-on experience and strategic thinking.

✨Engage with Stakeholders

Highlight your ability to communicate effectively with various stakeholders. Share specific instances where you’ve provided expert guidance on cybersecurity best practices or worked collaboratively with different departments. This will illustrate your interpersonal skills and your understanding of the importance of teamwork in achieving security objectives.

✨Stay Current with Trends

Make it clear that you’re committed to continuous learning by discussing recent trends in cybersecurity. Mention any recent training or certifications you’ve pursued, and how you plan to keep up with emerging threats and technologies. This shows your dedication to the field and your proactive approach to professional development.

Information Security Governance, Risk, and Compliance (GRC) Specialist
Janus Henderson AAA CLO ETF
Location: City of London
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

J
  • Information Security Governance, Risk, and Compliance (GRC) Specialist

    City of London
    Full-Time
    36000 - 60000 £ / year (est.)
  • J

    Janus Henderson AAA CLO ETF

    50-100
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>