At a Glance
- Tasks: Lead the charge in managing Information Security risks and controls across the organisation.
- Company: Join a forward-thinking firm dedicated to risk management and security excellence.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Collaborative environment with strong career advancement potential.
- Why this job: Make a real impact in shaping a risk-aware culture and enhancing security practices.
- Qualifications: Experience in Internal Audit or Cyber/Information Security risk management is essential.
The predicted salary is between 72000 - 108000 £ per year.
This is an exciting opportunity for a talented individual to join our Chief Controls office (CCO), a dedicated first line risk and control function. This role has arisen due to the expansion of responsibilities, offering the successful candidate the opportunity to make an impact and actively contribute to the evolution of this function. As part of the CCO team, you will play a key role:
- Improving the oversight of non-financial risks, bringing risk and control subject matter expertise with specific focus on Information Security, to partner with 1LOD business owners to proactively identify, assess and mitigate risks.
- Providing cross functional oversight across the first line, driving best practices and consistency in control standards for the effective control of Information Security risks to within risk appetite.
- Driving behaviours to foster a risk-aware and risk intelligent culture where employees recognise their role as risk managers and the importance of the control framework.
The role would suit candidates with 2LOD/3LOD experience looking for an opportunity to move into 1LOD, or candidates with solid experience in 1LOD control/control remediation/validation in the Cyber/Information Security space. The Information Security Risk Control Vice President is a key member of the CCO team who will work closely with the Information Security department (part of the Technology division) in the oversight and validation of Information Security risk and controls. This includes but not limited to:
Strategic:- Develop and implement a consistent, effective and efficient approach to the management and oversight of Information Security risks and controls.
- Identify and deliver best practices in control standards across the firm.
- Lead Technology’s engagement with Audit, also key liaison with 2LOD Risk and Compliance.
- Support the identification, assessment of Information Security risks and controls.
- Support in drafting/reviewing self-identified issues (SII) and remediation plans from a risk/control lens to ensure risks are sufficiently assessed, addressed, consider design/operating effectiveness, strategic/tactical solutions etc.
- Support in drafting/reviewing corrective actions for Audit findings.
- Support in validating corrective actions for SII and Audit findings as it comes for closure before submission to 2LOD/Audit, Monitor and report to relevant governance bodies on the status of issue/actions.
- Support in identifying, assessing and recording operational risk events for the security incidents.
- Contribute to risk appetite statements, emerging risks and regular assessment.
- Review KRIs to ensure meaningful metrics for management oversight, review/challenge breaches to understand root causes, consult on lessons learned exercises and work with business owners to develop a ‘path to green’ where appropriate.
- Consolidate and report on the results of risk and control activity to internal stakeholders, escalating as required.
- Support ad-hoc cross-Technology control initiatives where appropriate.
- Build strong relationships with peers to enable cross functional oversight and develop and implement best practices.
- Share knowledge and experience with other members of the team, driving consistency and ‘added value’.
- Establish positive working relationships with senior stakeholders across the business.
What we’re looking for:
- Experience of Internal Audit engagement, controls remediation and audit validation either from a 1LOD ownership perspective or 2LOD/3LOD validation in the Cyber/Information Security domain.
- Strong knowledge of Information Security Processes, Risks.
VP Information Security Risk and Control employer: Morgan McKinley
Join a forward-thinking organisation that prioritises a risk-aware culture and values the contributions of its employees. As a VP Information Security Risk and Control, you will benefit from a collaborative work environment that encourages professional growth and offers opportunities to lead impactful initiatives in Information Security. With a commitment to best practices and a focus on employee development, this role provides a unique chance to shape the future of risk management within a dynamic team.
StudySmarter Expert Advice🤫
We think this is how you could land VP Information Security Risk and Control
✨Tip Number 1
Network like a pro! Reach out to your connections in the Information Security field and let them know you're on the hunt for a VP role. Attend industry events or webinars to meet potential employers and make a lasting impression.
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of non-financial risks and control standards. Be ready to discuss how you've successfully identified and mitigated risks in past roles, showcasing your expertise in Information Security.
✨Tip Number 3
Don’t underestimate the power of follow-ups! After an interview, send a quick thank-you email to express your appreciation and reiterate your interest in the role. It keeps you top of mind and shows your enthusiasm.
✨Tip Number 4
Apply through our website for the best chance at landing that dream job! We’re always looking for talented individuals who can contribute to our Chief Controls office and help us drive a risk-aware culture.
We think you need these skills to ace VP Information Security Risk and Control
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the role of VP Information Security Risk and Control. Highlight your experience in 1LOD and 2LOD/3LOD, focusing on relevant skills and achievements that align with the job description.
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're the perfect fit for this role. Mention specific experiences that demonstrate your expertise in Information Security and risk management.
Showcase Your Leadership Skills:This role requires strong leadership abilities, so don’t shy away from showcasing your past experiences where you’ve led teams or initiatives. We want to see how you can drive a risk-aware culture within the organisation.
Apply Through Our Website:We encourage you to apply through our website for a smoother application process. It’s the best way for us to receive your application and ensure it gets the attention it deserves!
How to prepare for a job interview at Morgan McKinley
✨Know Your Stuff
Make sure you brush up on your knowledge of Information Security processes and risks. Familiarise yourself with the latest trends and best practices in the field, as well as any recent developments in the company’s approach to risk management. This will not only help you answer questions confidently but also show that you're genuinely interested in the role.
✨Showcase Your Experience
Prepare specific examples from your past roles that demonstrate your expertise in risk and control, especially in a Cyber/Information Security context. Be ready to discuss how you've identified, assessed, and mitigated risks in previous positions. This will help the interviewers see how your experience aligns with their needs.
✨Build Relationships
Since this role involves working closely with various teams, think about how you can demonstrate your ability to build strong relationships. Share examples of how you've collaborated with different departments or stakeholders in the past, and highlight your communication skills. This will show that you can foster a risk-aware culture within the organisation.
✨Ask Insightful Questions
Prepare thoughtful questions to ask during the interview. Inquire about the company's current challenges in Information Security, their approach to risk management, or how they measure success in this role. This not only shows your interest but also gives you valuable insights into the company’s priorities and culture.