At a Glance
- Tasks: Develop and manage cybersecurity policies, conduct risk assessments, and ensure compliance.
- Company: Join a leading financial services firm committed to cybersecurity excellence.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Collaborative environment with a focus on continuous learning and development.
- Why this job: Make a real impact in safeguarding digital assets and enhancing security culture.
- Qualifications: Bachelor's degree in IT or Cybersecurity; 3-5 years of experience preferred.
The predicted salary is between 50000 - 65000 € per year.
Policy Development And Management
- Develop and maintain comprehensive cybersecurity policies and procedures.
- Ensure these policies align with industry standards and regulatory requirements.
- Assist in the integration of security practices and control across various technical and non-technical departments, enhancing workflow and operational processes.
Risk Management
- Conduct regular risk assessments to help identify vulnerabilities and threats.
- Collaborate and oversee the implementation of risk mitigation strategies.
- Monitor emerging threats and evolving technologies to continuously refine risk assessment protocols.
- Ability to design and evaluate control metrics for assessing the effectiveness of cybersecurity measures.
- Collaborate with Enterprise risk management to embed cyber risk into broader risk registers and board-level reporting.
Compliance Management
- Monitor and ensure compliance with internal policies, industry standards, and regulatory requirements.
- Engage with required stakeholders in Technology, Legal, Compliance and Internal Audit as required.
- Compile and deliver detailed compliance reports to senior management.
- Monitor upcoming regulations and prepare compliance roadmaps.
Training And Awareness
- Support and enhance engaging cybersecurity awareness training programs.
- Foster a company-wide culture of cybersecurity awareness.
- Keep current with the latest cybersecurity trends and best practices to inform training content and security measures.
- Train and guide wider Tech team members on best practices in cybersecurity risk management.
Incident Management
- Actively participate in the response to security incidents.
- Support post-incident evaluations and reporting.
- Collaborate with relevant stakeholders to devise and enforce corrective measures aimed at bolstering defences against future incidents.
Stakeholder Engagement
- Maintain clear and effective communication with stakeholders at all levels.
- Provide expert guidance on cybersecurity best practices.
- Work collaboratively with Technology and other departments to achieve comprehensive security objectives.
Must have skills
- Bachelor’s Degree in Information Technology, Cybersecurity, or a related field; equivalent work experience also considered.
- 3 to 5 years of professional experience in information security.
- Certification such as Certified Information Systems Security Professional (CISSP) strongly preferred.
- Deep understanding of cybersecurity principles, frameworks (such as NIST, ISO/IEC 27001), and compliance standards.
- Experience with financial service regulations and regulations such as FCA, SEC, MAS, DORA.
- Proficient knowledge of network security principles and controls such as Firewalls, IPS/IPD, TCP/IP, DHCP, and DNS.
- Extensive experience in securing Operating Systems such as Windows, UNIX/Linux and Mac systems.
- Knowledge of cloud service models (IaaS, PaaS, SaaS) and deployment models (public, private, hybrid, community) and experience in implementing and managing cloud security best practices.
- In-depth knowledge of IAM principles and technologies to manage digital identities and control user access and experience with Single Sign-On (SSO), Multi-Factor Authentication (MFA), and role-based access control (RBAC) systems to enhance security and operational efficiency.
- Understanding of Secure DevOps / CI/CD pipeline governance.
Supervisory responsibilities
- No.
You will be expected to understand the regulatory obligations of the firm, and abide by the regulated entity requirements and JHI policies applicable for your role.
Janus Henderson (including its subsidiaries) will not maintain existing or sponsor new industry registrations or licenses where not supported by an employee’s job functions (as determined by Janus Henderson at its sole discretion).
All applicants must be willing to comply with the provisions of Janus Henderson Investment Advisory Code of Ethics related to personal securities activities and other disclosure and certification requirements, including past political contributions and political activities. Applicants’ past political contributions or activity may impact applicants’ eligibility for this position.
Janus Henderson is an equal opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. All applications are subject to background checks.
Information Security Governance, Risk, and Compliance (GRC) Specialist in London employer: Janus Henderson Investors
Janus Henderson is an exceptional employer that prioritises a culture of collaboration and continuous learning, making it an ideal workplace for an Information Security Governance, Risk, and Compliance (GRC) Specialist. With a strong commitment to employee growth, we offer comprehensive training programmes and opportunities to engage with cutting-edge cybersecurity practices in a dynamic financial services environment. Our inclusive work culture fosters innovation and ensures that every team member's contributions are valued, all while being located in a vibrant city that supports both professional and personal development.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security Governance, Risk, and Compliance (GRC) Specialist in London
✨Tip Number 1
Network like a pro! Reach out to folks in the cybersecurity field, especially those who work in GRC. Attend industry events or webinars, and don’t be shy about asking for informational interviews. You never know who might have a lead on your dream job!
✨Tip Number 2
Show off your skills! Create a portfolio that highlights your experience with risk assessments, policy development, and compliance management. Use real examples of how you've tackled challenges in past roles. This will make you stand out when chatting with potential employers.
✨Tip Number 3
Stay updated on the latest trends in cybersecurity. Follow relevant blogs, podcasts, and news outlets. Being knowledgeable about emerging threats and technologies will not only help you in interviews but also show that you're passionate about the field.
✨Tip Number 4
Apply through our website! We’ve got loads of opportunities waiting for you. Tailor your application to highlight your experience with frameworks like NIST and ISO/IEC 27001, and don’t forget to mention your certifications. Let’s get you that job!
We think you need these skills to ace Information Security Governance, Risk, and Compliance (GRC) Specialist in London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in cybersecurity, especially in areas like policy development and risk management. We want to see how your skills align with the job description!
Showcase Relevant Experience:When detailing your work history, focus on your achievements in information security and compliance management. Use specific examples that demonstrate your understanding of frameworks like NIST or ISO/IEC 27001, as this will catch our eye.
Be Clear and Concise:Keep your application straightforward and to the point. We appreciate clarity, so avoid jargon unless it’s relevant to the role. Make it easy for us to see why you’re a great fit for the GRC Specialist position!
Apply Through Our Website:We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy to do!
How to prepare for a job interview at Janus Henderson Investors
✨Know Your Cybersecurity Policies
Before the interview, make sure you’re well-versed in the latest cybersecurity policies and procedures relevant to the role. Familiarise yourself with industry standards like NIST and ISO/IEC 27001, as well as any specific regulations mentioned in the job description. This will show that you’re not just a candidate, but someone who understands the landscape.
✨Demonstrate Risk Management Skills
Be prepared to discuss your experience with risk assessments and mitigation strategies. Think of specific examples where you identified vulnerabilities and how you addressed them. This will help illustrate your hands-on experience and ability to contribute to the company’s risk management efforts.
✨Engage with Stakeholders
Communication is key in this role, so be ready to talk about how you’ve effectively engaged with various stakeholders in past positions. Share examples of how you’ve collaborated with teams across departments to enhance cybersecurity practices. This will highlight your ability to work well with others and drive security initiatives.
✨Stay Current with Trends
Show your passion for cybersecurity by discussing recent trends or emerging threats you’ve been following. Mention any relevant training or certifications you’re pursuing, like CISSP, to demonstrate your commitment to continuous learning. This will convey that you’re proactive and dedicated to staying ahead in the field.