At a Glance
- Tasks: Lead the information security strategy and oversee application security across Europe.
- Company: Join Trayport, a dynamic leader in financial services, committed to innovation and security.
- Benefits: Enjoy a collaborative culture, continuous learning opportunities, and a diverse work environment.
- Why this job: Make a significant impact in a growing organisation while working with industry experts.
- Qualifications: Proven experience in information security, preferably in financial services, with strong leadership skills.
- Other info: Trayport values diversity and offers accommodations for applicants and employees.
The predicted salary is between 72000 - 100000 ยฃ per year.
Head of Information Security, Europe page is loaded
Head of Information Security, Europe
Apply locations London – 2 Gresham Street time type Full time posted on Posted 5 Days Ago job requisition id R-5246 The Head of Information Security, Europe reports directly to the Chief Information Security Officer, TMX Group and has a dotted line reporting relationship to the Chief Technology Officer, Trayport.
The Head of Information Security will be responsible for defining, implementing, and managing the organization's information security strategy and framework for Europe. This critical role involves overseeing all aspects of information security, including a strong focus on application security, ensuring compliance with ISO27001 standards, financial services regulations, and other relevant legal and contractual requirements. As a senior leader of the Enterprise Information Security team, the role will also be accountable to provide information security oversight, through leadership and guidance across the TMX Group. The successful candidate will be a strategic leader with a strong technical background, including deep application security knowledge, and the ability to effectively communicate security risks and requirements across all levels of the business.
Key Responsibilities
- Information Security Strategy and Governance : Develop, implement, and maintain a comprehensive information security strategy aligned with business objectives and risk tolerance. Establish and enforce information security policies, procedures, and standards in accordance with ISO27001, customer requirements, relevant legislation, and application security best practices.
- Communication : Develop and maintain an organization-wide security culture. Build and implement a company-wide communication strategy to promote information security, including application security, within the organization.
- Team Leadership and Development : Lead and develop the Information Security team. Recruit, retain, and develop talent and expertise, including application security specialists. Set and maintain the teamโs culture and tone.
- Business Continuity and Disaster Recovery : Contribute to the development and testing of business continuity and disaster recovery plans from an information security perspective, including considerations for application security.
- Security Monitoring and Incident Response : Establish and maintain processes for continuous security monitoring and detection of security events, including application-specific security events. Lead the investigation and resolution of security incidents, including those related to application vulnerabilities, root cause analysis, and implementation of corrective actions.
- Reporting : Provide regular reports on the organization's security posture, including application security vulnerabilities and risks, risks, and compliance status to the Trayport Board, other internal sub-Boards, and relevant stakeholders.
- Compliance and Assurance : Ensure ongoing compliance with ISO27001 certification requirements, including managing audits, reviews, and continual improvement of the Information Security Management System (ISMS). Stay abreast of and ensure adherence to regulations (e.g., GDPR, NIS2, DORA) and other relevant legal and contractual obligations, as well as application security standards.
- Risk Management : Lead the information security risk management process, including identification, assessment, treatment, and monitoring of risks, with a particular emphasis on application security risks. Conduct regular risk assessments and vulnerability analyses of systems, applications, and infrastructure.
- Security Operations : Oversee the management of security technologies and controls, including but not limited to, firewalls, intrusion detection/prevention systems, security information and event management (SIEM), data loss prevention (DLP), vulnerability management tools, and application security testing tools.
- Secure Software Development Lifecycle (SSDLC) : Integrate security best practices into the software development lifecycle. Work closely with development teams to ensure secure coding practices, conduct comprehensive security testing (e.g., penetration testing, vulnerability scanning, application security reviews), and promote a security-aware development culture with a strong application security focus.
- Third-Party Risk Management : Develop and implement a program for assessing and managing the information security risks, including application security risks, associated with third-party vendors and service providers.
- Security Awareness and Training : Develop and deliver information security awareness training programs for all employees to foster a security-conscious culture, including specific training on application security best practices.
General Responsibilities
- Act as the primary point of contact for all information security matters.
- Advise the business on information security best practices and the potential impact of emerging threats.
- Collaborate with IT, legal, compliance, and other departments to ensure a cohesive approach to risk management and security.
- Manage the information security budget and resources effectively.
- Participate in relevant industry forums and stay updated on the latest security trends and technologies.
Required Qualifications and Skills:
- Proven experience in a senior information security role, preferably within the financial services or a similarly regulated industry.
- Demonstrable experience in implementing and managing an ISMS aligned with ISO27001, including successful participation in certification audits.
- Strong understanding of financial services regulations and their impact on information security.
- In-depth knowledge of information security frameworks, standards, and best practices (e.g., NIST, CIS).
- Experience with secure software development practices and application security testing.
- Strong technical understanding of network security, system security, and security architecture.
- Experience with risk management methodologies and tools.
- Excellent communication, presentation, and interpersonal skills, with the ability to articulate technical concepts to non-technical audiences.
- Proven leadership and team management skills.
- Relevant professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor are highly desirable.
Desirable Attributes:
- Experience with cloud security principles and practices.
- Familiarity with agile development methodologies.
- Experience in a software development environment.
- Strong analytical and problem-solving skills.
This is a challenging and rewarding opportunity for a seasoned information security professional to make a significant impact in a growing and security-conscious organisation within the financial services sector.
Trayport is committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide accommodations for applicants and employees who require it.
About Us
Our Culture:
At Trayport, our people power our success. We are a place where talented people never stop learning, innovating and working together to make an impact!
We offer you more than a job – we offer you the opportunity to work with, and learn from the most respected industry and thought leaders in the business.Weโre always pushing the boundaries, rapidly expanding our global presence across London, Vienna, Singapore, Bremen and North America. At Trayport, we understand that our people are crucial to our future. We strive to provide a challenging and inspirational atmosphere; employing intelligent, enthusiastic, adaptable individuals and giving them the
freedom, training, and guidance to allow them to consistently achieve their potential. If you share our vision and are motivated to challenge the status quo – we want to hear from you!#J-18808-Ljbffr
Head of Information Security, Europe (London) employer: TMX Group
Contact Detail:
TMX Group Recruiting Team
StudySmarter Expert Advice ๐คซ
We think this is how you could land Head of Information Security, Europe (London)
โจTip Number 1
Network with professionals in the information security field, especially those who have experience in financial services. Attend industry events or webinars to connect with potential colleagues and learn about the latest trends and challenges in application security.
โจTip Number 2
Familiarise yourself with ISO27001 standards and other relevant regulations like GDPR and NIS2. Being well-versed in these frameworks will not only boost your confidence but also demonstrate your commitment to compliance and security best practices during discussions.
โจTip Number 3
Prepare to discuss your leadership style and how you would develop a security culture within the organisation. Think of examples from your past experiences where you successfully led teams or implemented security initiatives that had a positive impact.
โจTip Number 4
Stay updated on the latest security technologies and tools, particularly those related to application security. Being knowledgeable about current trends will help you articulate how you can enhance the organisation's security posture effectively.
We think you need these skills to ace Head of Information Security, Europe (London)
Some tips for your application ๐ซก
Tailor Your CV: Make sure your CV highlights relevant experience in information security, particularly in application security and compliance with ISO27001. Use specific examples that demonstrate your leadership skills and technical expertise.
Craft a Compelling Cover Letter: In your cover letter, express your passion for information security and how your background aligns with the role's responsibilities. Mention your experience with risk management and secure software development practices, and how you can contribute to the company's security culture.
Highlight Relevant Certifications: List any relevant professional certifications such as CISSP, CISM, or ISO 27001 Lead Implementer prominently in your application. These credentials can set you apart from other candidates and demonstrate your commitment to the field.
Showcase Communication Skills: Since the role requires effective communication of security risks to non-technical audiences, provide examples in your application of how you've successfully communicated complex security concepts in previous roles. This will illustrate your ability to bridge the gap between technical and non-technical stakeholders.
How to prepare for a job interview at TMX Group
โจUnderstand the Role Thoroughly
Before the interview, make sure you have a deep understanding of the Head of Information Security role. Familiarise yourself with the key responsibilities, especially around application security and compliance with ISO27001 standards. This will help you articulate how your experience aligns with their needs.
โจShowcase Your Leadership Skills
As a senior position, they will be looking for strong leadership qualities. Prepare examples of how you've successfully led teams, developed talent, and fostered a security culture in previous roles. Highlight your ability to communicate effectively across all levels of an organisation.
โจPrepare for Technical Questions
Expect technical questions related to information security frameworks, risk management methodologies, and application security practices. Brush up on your knowledge of ISO27001, NIST, and CIS standards, and be ready to discuss how you've implemented these in past roles.
โจDemonstrate Your Strategic Thinking
This role requires a strategic mindset. Be prepared to discuss how you would develop and implement an information security strategy that aligns with business objectives. Think about how you can contribute to the overall security posture of the organisation and be ready to share your vision.