Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We will do this by protecting and growing our core business, amplifying our strengths and diversifying where we have the right. Our Values are key to driving our success, and are at the heart of everything we do: Clients Come First - Always | Execution Supersedes Intention | Together We Win | Diversity Improves Results | Truth Builds TrustIf our mission, values, and purpose align with your own, we would love to hear from you! Your opportunityPolicy Development and Management: Develop and maintain comprehensive cybersecurity policies and procedures. Ensure these policies align with industry standards and regulatory requirements. Risk Management: Conduct regular risk assessments to help identify vulnerabilities and threats. Collaborate and oversee the implementation of risk mitigation strategies. Monitor emerging threats and evolving technologies to continuously refine risk assessment protocols. Collaborate with Enterprise risk management to embed cyber risk into broader risk registers and board-level reporting. Compliance Management: Monitor and ensure compliance with internal policies, industry standards, and regulatory requirement. Engage with required stakeholders in Technology, Legal, Compliance and Internal Audit as requiredCompile and deliver detailed compliance reports to senior managementMonitor upcoming regulations and prepare compliance roadmaps. Training and Awareness: Support and enhance engaging cybersecurity awareness training programs. Foster a company-wide culture of cybersecurity awareness. Keep current with the latest cybersecurity trends and best practices to inform training content and security measuresTrain and guide wider Tech team members on best practices in cybersecurity risk management. Work collaboratively with Technology and other departments to achieve comprehensive security objectiveMust have skillsBachelor's Degree in Information Technology, Cybersecurity, or a related field; equivalent work experience also considered.3 to 5 years of professional experience in information security. Certification such as Certified Information Systems Security Professional (CISSP) strongly preferred. Deep understanding of cybersecurity principles, frameworks (such as NIST, ISO/IEC 27001), and compliance standards. Experience with financial service regulations and regulations such as FCA, SEC, MAS, DORA. Proficient knowledge of network security principles and controls such as Firewalls, IPS/IPD, TCP/IP, DHCP, and DNS Extensive experience in securing Operating Systems such as Windows, UNIX/Linux and Mac systems. This includes security access rights, implementing configuration best practicesKnowledge of cloud service models (IaaS, PaaS, SaaS) and deployment models (public, private, hybrid, community) and experience in implementing and managing cloud security best practices. In-depth knowledge of IAM principles and technologies to manage digital identities and control user access and experience with Single Sign-On (SSO), Multi-Factor Authentication (MFA), and role-based access control (RBAC) systems to enhance security and operational efficiency. Understanding of Secure DevOps / CI/CD pipeline governanceSupervisory responsibilitiesNoYou will be expected to understand the regulatory obligations of the firm, and abide by the regulated entity requirements and JHI policies applicable for your role. We believe diversity improves results and we welcome applications from candidates from all backgrounds. We understand everyone has different commitments and while we can't accommodate every flexible working request we're happy to be asked about work flexibility and our hybrid working environment. If you need any reasonable accommodations during our recruitment process, please get in touch and let us know at recruiter@janushenderson.com. #All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.
Information Security Governance Risk and Compliance Officer in London employer: Janus Henderson
At Janus Henderson, we pride ourselves on being an exceptional employer that fosters a culture of collaboration and inclusivity. Our commitment to employee growth is evident through our comprehensive professional development programs, generous health and wellbeing benefits, and a supportive hybrid working environment. Join us in London, where you can contribute to meaningful financial outcomes while enjoying a vibrant work-life balance and engaging community events.