Overview
In this role you will shape and manage the cybersecurity policy framework to protect clients and the firm. You will integrate security practices across tech and non-tech teams, enhancing governance and risk controls. You’ll drive regulatory alignment, incident response, and ongoing awareness to sustain a strong security posture. You join a values-driven, inclusive team that values collaboration and practical risk-based improvements. This position offers scope to influence security at scale and through cross-functional partnerships.
Pay / Benefits
- hybrid working environment
- inclusive and supportive culture
- flexible working arrangements
- accommodation during recruitment process
- opportunity to influence security at scale
Responsibilities
- Develop and maintain comprehensive cybersecurity policies and procedures aligned with standards and regulations
- Lead risk assessments and oversee implementation of risk mitigation strategies across the organization
- Ensure compliance management, monitoring policies, and regulatory requirements; prepare senior management reports
- Support cybersecurity awareness training programs and foster a security-conscious culture
- Participate in incident response and post-incident evaluations, driving corrective actions
- Engage with stakeholders across Technology, Legal, Compliance, and Internal Audit to align security objectives
Key requirements
- Bachelor’s Degree in Information Technology, Cybersecurity, or related field; equivalent work experience considered
- 3 to 5 years of information security experience
- CISSP certification strongly preferred
- Strong understanding of cybersecurity frameworks (NIST, ISO/IEC 27001) and regulatory standards
- Experience with financial service regulations (FCA, SEC, MAS, DORA)
- Proficient in network security concepts (Firewalls, IPS/IDS, TCP/IP, DHCP, DNS)
- Experience securing Windows, UNIX/Linux, and Mac OS
- Knowledge of cloud security (IaaS, PaaS, SaaS) and cloud deployment models
- IAM knowledge including SSO, MFA, RBAC; understands secure DevOps/CI/CD governance
- Stakeholder engagement
- Collaborative teamwork
- Clear communication
- Firewalls
- IPS/IDS
- TCP/IP
…
