At a Glance
- Tasks: Lead the charge in safeguarding critical business systems and data assets.
- Company: Join a leading financial services firm focused on information security.
- Benefits: Competitive salary, professional development, and a dynamic work environment.
- Other info: Collaborative culture with opportunities for career growth and innovation.
- Why this job: Make a real impact in cyber security while working with cutting-edge technologies.
- Qualifications: 10+ years in InfoSec management with strong knowledge of security frameworks.
The predicted salary is between 80000 - 100000 £ per year.
Requirements
- The role will best suit an experienced Information Security Manager with extensive experience gained from having previously operated within Senior Management level InfoSec/Cyber roles within the FS or FMI industries.
- The successful candidate must be a subject matter expert in Information Security, as the role demands a very strong knowledge in all areas of information security and cyber security, as well as in-depth knowledge of legacy, existing, and emerging technologies including cloud and security technologies/controls.
- In addition to a solid Security Governance Risk and Compliance (Security-GRC) skillset, a prior background in information security engineering, vulnerability management, security architecture, and security operations will be advantageous in this role given the various levels of stakeholders as well as the tech/cyber projects that the successful candidate will engage with daily.
- 10 years minimum experience in senior InfoSec management roles.
- Extensive previous exposure to FS or FMI industry organisations.
- High performance in problem solving, innovating and critical thinking.
- Excellent written/verbal communication and stakeholder management skills.
- Ability to articulate ideas to both technical and non-technical audiences.
- Must be capable of working pragmatically and efficiently in both a team and alone.
- Able to prioritise workloads efficiently and appropriately with minimal supervision.
- Able to work in fast paced, high-volume workload environment, prioritising accordingly.
- Must have security certifications: CISSP.
- Desirable: CISSP-ISSAP, CISSP-ISSEP, CISM, CCSP, CCSK, CEH.
- Desirable working knowledge of security standards/frameworks: ISO27K, ISF SOGP, NIST CSF, CIS, CSA STAR, CBEST, TIBER-EU, SOC2.
What the job involves
- The purpose of this role is to assist the Director of Business Information Security (BISO) in all security matters relating to the oversight of Information and Cyber Security within the LCH Ltd. business line of LSEG’s Post Trade division.
- The successful candidate will be charged with ensuring that the critical business systems and data assets of LCH Ltd. are adequately protected, and that all related information security and cyber controls remain effective and within risk appetite and/or have appropriate risk treatment plans in place to bring them back into risk appetite.
- Assisting in the oversight of Information Security by:
- Reviewing and assessing the information security and cyber controls that enable LCH Ltd. to conduct its business in a secure manner, and gap analysis of the same.
- The oversight of InfoSec/Cyber related control gap/risk remediation activities.
- Monitoring and analysing the information security roadmaps, strategies, programmes, and projects within LCH Ltd., and identifying and reporting risks, trends and future opportunities for improvement and enhancement.
- Proactively engaging and working closely with the technology and cyber teams that are delivering technology and cyber services to the firm.
- Attending risk and governance meetings to provide updates to the LCH Ltd. stakeholders from the three lines of defence regarding the delivery and progress of the various strategic cyber initiatives and broader cyber programme within LSEG.
- Working with colleagues from the three lines of defence to define the current risk posture of LCH Ltd. and collaborating with those stakeholders to remediate identified risks/issues.
- Engaging with external third parties who provide services to LCH Ltd. and working closely with the established internal third-party oversight functions to ensure appropriate and contracted levels of security are met.
- Establish and maintain a Cyber Risk Profile of LCH Ltd. in line with other areas of LSEG.
- Assisting with the establishment and maintenance of a Risk Control Assessment (RCA) that focuses on InfoSec/Cyber risks and associated controls.
- Engagement with the business to:
- Develop an understanding of business goals and operational risks.
- Identifying key areas for improvement.
- Support the risk management decision processes and risk forums/committees.
- Assisting with the identification of emerging information and cyber security threats to the business, and the subsequent analysis to realise and oversee risk mitigation plans.
- Build strong relationships within the business to gain an understanding of security-related business risks.
- Work closely with governance stakeholders in the 1st, 2nd, and 3rd lines of defence on all matters relating to information security, cyber risk, data privacy, including all regulatory and legislative considerations.
- Embedding Cyber across the firm by:
- Working closely with all necessary stakeholders in the business and technology areas to ensure compliance with established LSEG policies, standards, and procedures.
- Constructively and pragmatically challenging established controls to ensure, recommend, and accommodate continuous improvement.
- Ensuring LCH Ltd. stakeholders understand their responsibilities in relation to security risk mitigation and remediation.
- Monitoring industry information security trends and keeping business leadership informed about information security-related issues and activities potentially affecting the organisation and specific business functions.
- Security Governance, Technical, and Risk Review:
- Review and documenting of technologies and security controls across the firm, including areas such as office spaces, data centres and cloud.
- Executing and concluding security controls maturity assessments against industry standards such as the NIST Cyber Security Framework, ISO27001/2, SOC2, etc.
- Working closely with stakeholders to review all projects and initiatives, assessing them for appropriate/correct levels of security design and controls.
- Identification of technology and security risks across the firm and the assessment and appropriate risk scoring and presentation of the same.
- Produce appropriate risk remediation action plans and ability to present and take ownership of risk treatment proposals and action plans.
- Review and appropriate response to regulatory and legislative matters.
- Produce and present risks and risk postures/cyber maturity to senior/executive bodies.
- Able to clearly and precisely present complex cyber risk matters to clients and regulators.
- Partnering with the different business control functions:
- Build knowledge of business units by assisting them with their security workloads, agendas, and difficulties.
- Maintaining a balanced relationship with risk, compliance, legal, human resources, and internal and external audit functions.
- Knowledge of technology, security, and threat landscapes:
- Staying abreast of emerging technologies, including all security technologies.
- Sustaining a deep and in-depth knowledge of the cyber threat landscape.
- Maintain and constantly enriching knowledge of information security and cyber risks as they develop.
- Being able to propose and explain appropriate cyber risk counter measures clearly and concisely.
- Remaining informed and knowledgeable on primary global data protection regulations and legislation.
Information Security Officer (Post Trade, LCH Ltd) employer: London Stock Exchange
LCH Ltd is an exceptional employer, offering a dynamic work environment in the heart of London where innovation and security are at the forefront of our mission. We prioritise employee growth through continuous learning opportunities and a collaborative culture that encourages problem-solving and critical thinking. With a strong commitment to work-life balance and competitive benefits, we empower our team to thrive while safeguarding the future of financial markets.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security Officer (Post Trade, LCH Ltd)
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the InfoSec community. Attend industry events, webinars, or even local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your expertise! When you get the chance to chat with potential employers, make sure to highlight your experience in security governance and risk management. Share specific examples of how you've tackled challenges in previous roles to demonstrate your problem-solving skills.
✨Tip Number 3
Don’t just apply anywhere—apply through our website! We’ve got a streamlined process that makes it easy for you to showcase your skills and experience directly to us. Plus, it shows you’re genuinely interested in being part of our team.
✨Tip Number 4
Prepare for interviews by brushing up on your communication skills. You’ll need to articulate complex cyber security concepts to both technical and non-technical audiences. Practice explaining your past projects and how they relate to the role you’re applying for.
We think you need these skills to ace Information Security Officer (Post Trade, LCH Ltd)
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Information Security Officer role. Highlight your experience in InfoSec and Cyber roles, especially within the FS or FMI industries. We want to see how your skills match what we're looking for!
Showcase Your Expertise:Don’t hold back on showcasing your subject matter expertise in Information Security. Mention your certifications like CISSP and any relevant frameworks you’re familiar with. This is your chance to shine, so let us know what you bring to the table!
Communicate Clearly:Since this role involves engaging with both technical and non-technical audiences, make sure your application reflects your excellent communication skills. Use clear language and avoid jargon where possible. We appreciate straightforwardness!
Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you don’t miss out on any important updates. Plus, it’s super easy!
How to prepare for a job interview at London Stock Exchange
✨Know Your Stuff
Make sure you brush up on your knowledge of information security and cyber security. Given the role's demands, being a subject matter expert is crucial. Familiarise yourself with legacy, existing, and emerging technologies, especially cloud and security controls.
✨Showcase Your Experience
Prepare to discuss your extensive experience in senior InfoSec management roles, particularly within the FS or FMI industries. Be ready to share specific examples of how you've tackled challenges and contributed to security governance, risk, and compliance.
✨Communicate Clearly
You’ll need to articulate complex ideas to both technical and non-technical audiences. Practice explaining your past projects and their impacts in simple terms, ensuring you can engage stakeholders effectively during the interview.
✨Stay Current
Keep yourself updated on the latest trends in information security and cyber threats. Being knowledgeable about current industry standards and frameworks like ISO27K and NIST CSF will show that you're proactive and committed to continuous improvement.