At a Glance
- Tasks: Safeguard global financial markets by validating and improving cyber security controls.
- Company: Join the London Stock Exchange Group, a leader in financial markets infrastructure.
- Benefits: Flexible hybrid work, diverse culture, and opportunities for personal and professional growth.
- Why this job: Make a real impact in cyber security while working with cutting-edge technologies.
- Qualifications: Experience in technical audits and strong understanding of cyber security principles.
- Other info: Be part of a collaborative team that values innovation and continuous improvement.
The predicted salary is between 36000 - 60000 £ per year.
Are you a top-tier Cyber Security specialist and want to use your expertise to help safeguard the infrastructure that powers global financial markets? We are seeking a Cyber Security Controls Specialist to work within the engineering team. This role is important in ensuring that our controls are well-understood, effectively implemented, and accurately represented during internal and external audits and assessments. The ideal candidate will bring a strong blend of technical expertise, audit experience, and risk management knowledge. You will be the lead in representing technical controls to auditors, translating sophisticated security controls into clear, auditable evidence and narratives. You will help the teams in ensuring robust evidence exists to support control design and operation on an ongoing basis.
Key Responsibilities
- Control Testing & Validation: Conduct proactive internal control assessment activities to validate the effectiveness of controls and identify areas for improvement for the team. Ensuring controls are accurately documented, maintained and with the correct measurements in place to simplify audit and assessment activities.
- Audit & Assessment: Lead the team response to audits, regulatory, customer assessments, and compliance reviews by representing and providing clear, concise, and technically accurate evidence and explanations. A key outcome is servicing multiple concurrent audit and assessment activities through standardised processes and evidence.
- Technical Translation: Translate sophisticated technical security concepts and measures into plain-friendly language appropriate for collaborators, auditors, and risk managers.
- Risk Management: Collaborate with teams to ensure cyber risks are appropriately identified, assessed, accurately recorded and mitigated through effective control design and operation.
- Continuous Improvement: Identify gaps or weaknesses in existing controls and related documentation and recommend improvements by working closely with the control owners. Being technical, you have the ability to not only understand how security controls work but to influence how they’re designed, implemented, and measured in conjunction with the team.
Required Qualifications & Experience
- Audit & Controls Experience: Proven experience working in a technical audit role assessing controls in highly regulated global organisations. Has comprehensive understanding of control evidencing and appropriate robust measures.
- Technical Cyber Security Expertise: Strong understanding of common security technologies, security threats, security frameworks, foundational technologies such as cloud and associated processes. Practical experience of providing guidance and support to first line of defence technical engineering teams in uplifting control related evidence and measures. Demonstration of continuous learning to expand technical understanding of controls to a comprehensive level.
- Communication Skills: Outstanding ability to communicate technical concepts to non-technical audiences, including auditors, senior management, and business partners. Comfortable in questioning and challenging assertions when the facts, metrics and anecdotes differ.
- Risk Management: Solid understanding of risk management principles and how they apply to cyber security controls and governance. Experience of transforming risk conversations from theoretical to actionable, challenge assumptions, and bridge the gap between policy and practice. Experience of working in common GRC tooling platforms to capture and handle issues and risks.
- Continuous Control Monitoring & Automation (Preferred): Experienced in automating controls monitoring, analysis and evidence collection to simplify assurance processes.
- Certifications (Preferred): CISSP, CISA, CRISC or similar, and technical security certifications are highly desirable.
What you’ll get in return
We recognise that to attract the best talent, we need to be flexible, and we are open to discussing work arrangements with you. We take a hybrid approach to the workplace; this role is hybrid/digital first. As a global business, we rely on diversity of culture and thought to deliver on our goals. People are at the heart of what we do and drive the success of our business. Our colleagues thrive personally and professionally through our shared values of Integrity, Partnership, Innovation and Excellence which are at the core of our culture. We embrace diversity and actively seek to attract people with unique backgrounds and perspectives. We are always looking at ways to become more agile, so we meet the needs of our teams and customers. We believe that an inclusive collaborative workplace is pivotal to our success and supports the potential and growth of all colleagues at LSEG.
Career Stage & Information
Career Stage: Manager
London Stock Exchange Group (LSEG) Information: Join us and be part of a team that values innovation, quality, and continuous improvement. If you’re ready to take your career to the next level and make a significant impact, we’d love to hear from you. LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth. Our values of Integrity, Partnership, Excellence and Change underpin our purpose and guide our decision making and everyday actions. We are 25,000 people across 65 countries and are committed to diversity and inclusion. We are an equal opportunities employer. This means we do not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. We can reasonably accommodate applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs.
Security Controls Specialist - London Stock Exchange Group employer: Jobs via eFinancialCareers
Contact Detail:
Jobs via eFinancialCareers Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Controls Specialist - London Stock Exchange Group
✨Tip Number 1
Network like a pro! Reach out to your connections in the cyber security field, especially those at the London Stock Exchange Group. A friendly chat can open doors and give you insights that job descriptions just can't.
✨Tip Number 2
Prepare for interviews by brushing up on your technical knowledge and audit experience. Be ready to discuss how you've tackled challenges in previous roles, especially around control testing and risk management. We want to see your expertise shine!
✨Tip Number 3
Showcase your communication skills! Practice explaining complex security concepts in simple terms. This is key when dealing with auditors and non-technical stakeholders, so make sure you're comfortable translating tech jargon into plain English.
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you're genuinely interested in being part of our team at LSEG. Let's get you on board!
We think you need these skills to ace Security Controls Specialist - London Stock Exchange Group
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the role of Security Controls Specialist. Highlight your audit experience, technical expertise, and risk management knowledge. We want to see how your skills align with what we’re looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about cyber security and how your background makes you a perfect fit for our team. Keep it concise but impactful – we love a good story!
Showcase Your Communication Skills: Since this role involves translating complex technical concepts into plain language, make sure to demonstrate your communication skills in your application. We want to see how you can bridge the gap between technical and non-technical audiences.
Apply Through Our Website: Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team at StudySmarter!
How to prepare for a job interview at Jobs via eFinancialCareers
✨Know Your Cyber Security Stuff
Make sure you brush up on your technical knowledge before the interview. Understand common security technologies, threats, and frameworks relevant to the role. Being able to discuss these confidently will show that you're not just a paper expert but someone who can genuinely contribute.
✨Prepare for Audit Scenarios
Since this role involves leading responses to audits, think about past experiences where you've dealt with audits or assessments. Be ready to share specific examples of how you validated controls and what improvements you suggested. This will demonstrate your hands-on experience and problem-solving skills.
✨Practice Your Communication Skills
You’ll need to translate complex technical concepts into plain language. Practise explaining your previous projects or experiences to someone without a technical background. This will help you articulate your thoughts clearly during the interview, especially when discussing with auditors or non-technical stakeholders.
✨Show Your Continuous Learning Mindset
The job description highlights the importance of continuous improvement and learning. Be prepared to discuss any recent certifications, courses, or self-study you've undertaken. This shows that you're proactive about staying updated in the fast-evolving field of cyber security.