At a Glance
- Tasks: Develop and manage cybersecurity policies, conduct risk assessments, and ensure compliance.
- Company: Join Janus Henderson, a leader in financial services with a mission to invest in a brighter future.
- Benefits: Enjoy a supportive environment, flexible working options, and opportunities for professional growth.
- Why this job: Make a real impact in cybersecurity while collaborating with diverse teams and enhancing your skills.
- Qualifications: Bachelor’s degree in IT or Cybersecurity, 3-5 years of experience, and relevant certifications preferred.
- Other info: We value diversity and welcome applicants from all backgrounds; flexibility is encouraged.
The predicted salary is between 36000 - 60000 ÂŁ per year.
Why work for us? A career at Janus Henderson is more than a job, it’s about investing in a brighter future together.
Our Mission Janus Henderson’s mission is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world‑class service. We do this by protecting and growing our core business, amplifying our strengths and diversifying where we have the right.
Our Values Clients Come First – Always | Execution Supersedes Intention | Together We Win | Diversity Improves Results | Truth Builds Trust If our mission, values, and purpose align with your own, we would love to hear from you!
Your opportunity
- Policy Development and Management Develop and maintain comprehensive cybersecurity policies and procedures. Ensure these policies align with industry standards and regulatory requirements. Assist in the integration of security practices and controls across various technical and non‑technical departments, enhancing workflow and operational processes.
- Risk Management Conduct regular risk assessments to help identify vulnerabilities and threats. Collaborate and oversee the implementation of risk mitigation strategies. Monitor emerging threats and evolving technologies to continuously refine risk assessment protocols. Design and evaluate control metrics for assessing the effectiveness of cybersecurity measures. Collaborate with Enterprise Risk Management to embed cyber risk into broader risk registers and board‑level reporting.
- Compliance Management Monitor and ensure compliance with internal policies, industry standards, and regulatory requirements. Engage with required stakeholders in Technology, Legal, Compliance and Internal Audit as required. Compile and deliver detailed compliance reports to senior management. Monitor upcoming regulations and prepare compliance roadmaps.
- Training and Awareness Support and enhance engaging cybersecurity awareness training programs. Foster a company‑wide culture of cybersecurity awareness. Keep current with the latest cybersecurity trends and best practices to inform training content and security measures. Train and guide wider tech team members on best practices in cybersecurity risk management.
- Incident Management Actively participate in the response to security incidents. Support post‑incident evaluations and reporting. Collaborate with relevant stakeholders to devise and enforce corrective measures aimed at bolstering defences against future incidents.
- Stakeholder Engagement Maintain clear and effective communication with stakeholders at all levels. Provide expert guidance on cybersecurity best practices. Work collaboratively with Technology and other departments to achieve comprehensive security objectives.
Must have skills
- Bachelor’s Degree in Information Technology, Cybersecurity, or a related field; equivalent work experience also considered.
- 3 to 5 years of professional experience in information security.
- Certification such as Certified Information Systems Security Professional (CISSP) strongly preferred.
- Deep understanding of cybersecurity principles, frameworks (such as NIST, ISO/IEC 27001), and compliance standards.
- Experience with financial service regulations and regulations such as FCA, SEC, MAS, DORA.
- Proficient knowledge of network security principles and controls such as firewalls, IPS/IPD, TCP/IP, DHCP, and DNS.
- Extensive experience in securing operating systems such as Windows, UNIX/Linux and Mac systems, including security access rights, implementing configuration best practices.
- Knowledge of cloud service models (IaaS, PaaS, SaaS) and deployment models (public, private, hybrid, community) and experience in implementing and managing cloud security best practices.
- In‑depth knowledge of IAM principles and technologies to manage digital identities and control user access, and experience with Single Sign‑On (SSO), Multi‑Factor Authentication (MFA), and role‑based access control (RBAC) systems to enhance security and operational efficiency.
- Understanding of Secure DevOps/CI/CD pipeline governance.
No supervisory responsibilities. You will be expected to understand the regulatory obligations of the firm, and abide by the regulated entity requirements and JHI policies applicable for your role.
At Janus Henderson Investors we’re committed to an inclusive and supportive environment. We believe diversity improves results and we welcome applications from candidates from all backgrounds. Don’t worry if you don’t think you tick every box, we still want to hear from you! We understand everyone has different commitments and while we can’t accommodate every flexible working request we’re happy to be asked about work flexibility and our hybrid working environment. If you need any reasonable accommodations during our recruitment process, please get in touch and let us know at recruiter@janushenderson.com.
Janus Henderson (including its subsidiaries) will not maintain existing or sponsor new industry registrations or licenses where not supported by an employee’s job functions (as determined by Janus Henderson at its sole discretion). All applicants must be willing to comply with the provisions of Janus Henderson Investment Advisory Code of Ethics related to personal securities activities and other disclosure and certification requirements, including past political contributions and political activities. Applicants’ past political contributions or activity may impact applicants’ eligibility for this position. Janus Henderson is an equal opportunity /Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. All applications are subject to background checks.
Information Security Governance, Risk, and Compliance (GRC) Specialist employer: Janus Henderson Global Investors
Contact Detail:
Janus Henderson Global Investors Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Governance, Risk, and Compliance (GRC) Specialist
✨Tip Number 1
Network like a pro! Reach out to your connections in the cybersecurity field and let them know you're on the hunt for a GRC Specialist role. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of cybersecurity frameworks and compliance standards. Be ready to discuss how you've tackled risk management in past roles, as this will show you're the right fit for Janus Henderson's mission.
✨Tip Number 3
Don’t just apply anywhere; focus on companies that align with your values. Check out our website for openings at StudySmarter and Janus Henderson, where you can find roles that resonate with your passion for cybersecurity and client service.
✨Tip Number 4
Follow up after interviews! A quick thank-you email can go a long way in showing your enthusiasm for the role. Mention something specific from the interview to remind them why you're the perfect candidate for their team.
We think you need these skills to ace Information Security Governance, Risk, and Compliance (GRC) Specialist
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to reflect the specific skills and experiences that align with the Information Security GRC role. Highlight your understanding of cybersecurity principles and any relevant certifications you hold.
Showcase Your Experience: When detailing your professional experience, focus on your achievements in risk management and compliance. Use concrete examples to demonstrate how you've successfully implemented security measures or developed policies in previous roles.
Be Clear and Concise: Keep your application straightforward and to the point. Avoid jargon unless it's relevant to the role. We want to see your qualifications and experiences clearly without unnecessary fluff.
Apply Through Our Website: We encourage you to submit your application through our website for the best chance of being noticed. It’s the easiest way for us to keep track of your application and ensure it gets to the right people!
How to prepare for a job interview at Janus Henderson Global Investors
✨Know Your Cybersecurity Frameworks
Familiarise yourself with key cybersecurity frameworks like NIST and ISO/IEC 27001. Be ready to discuss how these frameworks apply to the role and how you’ve used them in past experiences. This shows you’re not just knowledgeable but also practical in applying these standards.
✨Demonstrate Risk Management Skills
Prepare examples of how you've conducted risk assessments and implemented mitigation strategies. Highlight any specific incidents where your actions led to improved security measures. This will illustrate your hands-on experience and ability to handle real-world challenges.
✨Engage with Compliance Knowledge
Brush up on financial service regulations like FCA and SEC. Be prepared to discuss how you’ve ensured compliance in previous roles, and think about how you would approach compliance roadmaps for Janus Henderson. This will show that you understand the regulatory landscape and can navigate it effectively.
✨Showcase Communication Skills
Since stakeholder engagement is key, practice articulating complex cybersecurity concepts in simple terms. Think of examples where you’ve successfully communicated with non-technical teams or senior management. This will demonstrate your ability to bridge the gap between technical and non-technical stakeholders.