Overview
In this role you will support the Director of Business Information Security to safeguard LCH Ltd.’s critical systems and data. You’ll oversee information security and cyber controls, drive risk remediation, and collaborate with three lines of defence and external partners. You’ll assess security architectures, roadmaps, and projects to ensure compliance with policies and standards, while reporting risk posture to leadership. The role blends governance, risk, and technical oversight in a fast-paced financial services environment with broad stakeholder engagement. You’ll help shape security strategy and continuous improvement across LCH Ltd. and LSEG.
Pay / Benefits
- healthcare
- retirement planning
- paid volunteering days
- wellbeing initiatives
Responsibilities
- Review and gap analyze information security and cyber controls enabling business operations
- Oversee control gap/risk remediation activities and track remediation progress
- Monitor security roadmaps, programmes, and report risks and improvement opportunities
- Engage closely with technology and cyber teams delivering security services
- Present updates on cyber initiatives to risk governance meetings across the three lines of defence
- Collaborate with three lines of defence to define and remediate risk posture
- Engage external third parties and ensure contracted security levels are met
- Maintain Cyber Risk Profile and Risk Control Assessments (RCA) for InfoSec/Cyber risks
- Prepare executive MI and security control state presentations
- Assess security architecture designs and risk for projects, ensuring compliance with Policies and Standards
Key requirements
- 10 years minimum experience in senior InfoSec management roles
- Extensive experience in FS or FMI industries
- Strong problem solving, innovation, and critical thinking
- Excellent written/verbal communication and stakeholder management
- Ability to articulate complex concepts to technical and non-technical audiences
- Pragmatic, independent, and able to work in fast-paced environments
- Must have CISSP certification
- excellent communication
- stakeholder management
- ability to explain complex topics to diverse audiences
- Security-GRC expertise
- information security engineering
- vulnerability management
…
