Information Security Officer - Post Trade, LCH Ltd

Information Security Officer - Post Trade, LCH Ltd

Full-Time 80000 - 100000 £ / year (est.) No working from home possible
London Stock Exchange Group

At a Glance

  • Tasks: Support the Director of Business Information Security in safeguarding critical systems and data.
  • Company: Join LCH Ltd., a leader in post-trade services within LSEG.
  • Benefits: Competitive salary, diverse work environment, and opportunities for professional growth.
  • Other info: Be part of an equal-opportunity employer committed to diversity and inclusion.
  • Why this job: Make a real impact on information security in a dynamic financial services environment.
  • Qualifications: 10+ years in InfoSec management with strong communication and problem-solving skills.

The predicted salary is between 80000 - 100000 £ per year.

The purpose of this role is to assist the Director of Business Information Security (BISO) in all security matters relating to the oversight of Information and Cyber Security within the LCH Ltd. business line of LSEG’s Post Trade division. The successful candidate will be charged with ensuring that the critical business systems and data assets of LCH Ltd. are adequately protected, and that all related information security and cyber controls remain effective and within risk appetite.

Key Responsibilities

  • Assisting in the oversight of Information Security by:
    • Reviewing and assessing the information security and cyber controls that enable LCH Ltd. to conduct its business in a secure manner, and gap analysis of the same.
    • Overseeing InfoSec/Cyber related control gap/risk remediation activities.
    • Monitoring and analysing the information security roadmaps, strategies, programmes, and projects, and identifying and reporting risks, trends and future opportunities for improvement.
    • Proactively engaging and working closely with technology and cyber teams that deliver services to the firm.
    • Attending risk and governance meetings to provide updates to LCH Ltd. stakeholders from the three lines of defence about the delivery and progress of strategic cyber initiatives.
    • Working with colleagues to define the current risk posture and collaborating to remediate identified risks/issues.
    • Engaging with external third‑party service providers and working closely with internal oversight functions to ensure appropriate security levels are met.
    • Establishing and maintaining a Cyber Risk Profile of LCH Ltd. in line with other LSEG areas.
    • Assisting with the establishment and maintenance of a Risk Control Assessment (RCA) focused on InfoSec/Cyber risks and associated controls.
    • Maintaining key performance and risk indicators so that all management information accurately reflects the current control estate.
    • Providing accurate executive‑level presentation materials that clearly present the current state of security controls.
    • Assessing security architecture designs and risk positions of projects and initiatives, and working with SMEs and design authorities to ensure compliance with policies, standards and design principles.

Engagement with the business to:

  • Develop an understanding of business goals and operational risks.
  • Identify key areas for improvement.
  • Support risk management decision processes and risk forums/committees.
  • Assist with the identification of emerging threats and the analysis to develop and oversee risk mitigation plans.
  • Build strong relationships with business units to understand security‑related risks.
  • Work closely with governance stakeholders in all three lines of defence on matters of information security, cyber risk, data privacy, and regulatory considerations.

Embedding Cyber across the firm by:

  • Working with stakeholders to ensure compliance with LSEG policies, standards and procedures.
  • Constructively challenging established controls to recommend and accommodate continuous improvement.
  • Ensuring stakeholders understand their responsibilities in risk mitigation and remediation.
  • Monitoring industry information security trends and keeping leadership informed of issues that may affect the organisation or business functions.

Security Governance, Technical, and Risk Review:

  • Reviewing and documenting technologies and security controls across the firm, including office spaces, data centres and cloud.
  • Executing maturity assessments against standards such as NIST Cyber Security Framework, ISO27001/2, SOC2.
  • Reviewing projects and initiatives to assess appropriate levels of security design and controls.
  • Identifying technology and security risks, assessing and presenting risk scoring.
  • Producing risk remediation action plans and presenting risk posture to executive bodies.
  • Responding to regulatory and legislative matters.
  • Presenting complex cyber risk matters to clients and regulators.

Partnering with different business control functions:

  • Building knowledge of business units by assisting with security workloads, agendas and difficulties.
  • Maintaining balanced relationships with risk, compliance, legal, HR and audit functions.

Knowledge of technology, security, and threat landscapes:

  • Staying abreast of emerging technologies and security solutions.
  • Maintaining deep knowledge of the cyber threat landscape and evolving cyber risks.
  • Proposing and explaining appropriate cyber‑risk counter‑measures clearly and concisely.
  • Remaining informed on global data protection regulations and legislation.

Experience and Core Skill Requirements

  • 10+ years of senior InfoSec management experience.
  • Extensive previous exposure to FS or FMI industry organisations.
  • High performance in problem solving, innovation and critical thinking.
  • Excellent written and verbal communication and stakeholder management skills.
  • Ability to articulate ideas to both technical and non‑technical audiences.
  • Pragmatic and efficient working style, both independently and within a team.
  • Ability to prioritise workloads with minimal supervision.
  • Experience working in fast‑paced, high‑volume environments.

Must Have Security Certifications

  • CISSP

Desirable & Advantageous Certifications

  • CISSP‑ISSAP
  • CISSP‑ISSEP
  • PCISM
  • CCSP
  • CCSK
  • CEH

Working Knowledge of Security Standards / Frameworks

  • ISO27K
  • ISF SOGP
  • NIST CSF
  • CISSP
  • CSA STAR
  • CBEST
  • TIBER‑EU
  • SOC2

Information Security Officer - Post Trade, LCH Ltd employer: London Stock Exchange Group

LCH Ltd is an exceptional employer, offering a dynamic work environment in the heart of London where innovation and security are at the forefront of our mission. We prioritise employee growth through continuous learning opportunities and a collaborative culture that values diverse perspectives, ensuring that every team member can thrive while contributing to the critical oversight of information and cyber security. With competitive benefits and a commitment to inclusivity, LCH Ltd stands out as a rewarding place for professionals seeking meaningful careers in the financial services sector.

London Stock Exchange Group

Contact Details:

London Stock Exchange Group Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Officer - Post Trade, LCH Ltd

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend events, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their security challenges and be ready to discuss how your experience aligns with their needs. Show them you’re not just another candidate!

Tip Number 3

Practice your pitch! Be clear about your skills and how they relate to the role of Information Security Officer. A confident and concise introduction can make a great first impression.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search.

We think you need these skills to ace Information Security Officer - Post Trade, LCH Ltd

Information Security Management
Cyber Security Oversight
Risk Assessment
Gap Analysis
Control Remediation
Data Privacy Compliance
Stakeholder Engagement

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in information security, especially in the financial services sector. We want to see how your skills align with the specific responsibilities mentioned in the job description.

Showcase Your Achievements:Don’t just list your duties; share your accomplishments! Use metrics where possible to demonstrate how you’ve improved security measures or mitigated risks in previous roles. This helps us see the impact you've made.

Be Clear and Concise:When writing your application, keep it straightforward and to the point. We appreciate clarity, so avoid jargon unless it's relevant. Make it easy for us to understand your qualifications and experiences.

Apply Through Our Website:We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super easy!

How to prepare for a job interview at London Stock Exchange Group

Know Your Stuff

Make sure you brush up on the latest trends in information security and cyber risk. Familiarise yourself with frameworks like NIST and ISO27001, as well as any recent developments in the financial services sector. This will show that you're not just knowledgeable but also genuinely interested in the field.

Showcase Your Experience

Prepare to discuss your previous roles in InfoSec management, especially those that relate to oversight and risk remediation. Use specific examples to illustrate how you've successfully navigated challenges and improved security controls in past positions.

Engage with Stakeholders

Demonstrate your ability to build relationships by discussing how you've collaborated with various teams in the past. Be ready to share examples of how you've communicated complex security concepts to both technical and non-technical audiences, as this is crucial for the role.

Ask Insightful Questions

Prepare thoughtful questions about LCH Ltd.'s current security posture and future initiatives. This not only shows your interest in the company but also gives you a chance to assess if their goals align with your expertise and career aspirations.