FNZ Group
We provide a global, end-to-end wealth management platform that integrates technology, business & investment operations all in a regulated financial institution.
At FNZ, our purpose is to make wealth management more accessible, bringing easier, fairer and more inclusive solutions to people worldwide. Here in the Global Cyber & Information Security team, we are on a mission to embed cyber resilience across FNZ, protecting the platforms that support investment solutions for over 20 million people.
We are looking for a result-driven, exceptional and proven Cyber Security Program Director, reporting to the Group CISO, to lead the delivery of cybersecurity and information security programs aligned with the security strategy.
You will focus on translating strategic objectives into actionable initiatives, ensuring timely execution and measurable outcomes.
You will have a strong background in program management, experience in delivering cybersecurity initiatives, understanding of security frameworks, and cross-functional leadership to drive the successful delivery of critical security projects.
You will have experience in regulated financial services across different regions and jurisdictions. You will have previous experience of complex, rapidly changing environments, specifically M&A activities. You will be able to rapidly identify areas of improvement and make changes for the good of the business.
Specific Role Responsibilities
- Program Delivery, Performance Measurement and Reporting:
- Lead the planning, execution, and delivery of cyber and information security enhancement programs in alignment with the FNZ cyber and information security strategy.
- Enhance program governance structures, ensuring projects adhere to scope, timeline, and budget.
- Define and track program metrics to evaluate the effectiveness of delivered initiatives.
- Monitor program performance and ensure objectives are met through clear milestones, deliverables, and KPIs.
- Develop detailed reports and dashboards to communicate program status, risks, and achievements to leadership and management members.
- Utilize feedback to improve future program delivery processes and outcomes.
- Strategic Execution:
- Translate the FNZ's cyber and information security into detailed program plans, ensuring alignment with business priorities and risk management goals.
- Collaborate with security leadership to prioritize initiatives and allocate resources effectively.
- Drive continuous alignment between program delivery and the organization’s evolving security landscape.
- Risk Management and Compliance:
- Ensure all program activities are conducted in compliance with relevant regulations, standards, and best practices (e.g., NIST CSF, ISO 27001, GDPR, DORA, SOC2 Type2).
- Manage risk assessments across all program initiatives and implement appropriate mitigation strategies.
- Coordinate with security GRC team, internal and external auditors to ensure programs meet compliance requirements.
- Stakeholder Collaboration:
- Act as the primary liaison between program teams, business units, IT, and executive stakeholders to ensure alignment and buy-in.
- Deliver regular updates on program progress, challenges, and successes to leadership and other stakeholders.
- Facilitate effective communication and collaboration across cross-functional teams to ensure program objectives are achieved.
- Team Leadership and Development:
- Lead, manage, and mentor a small hybrid team of project managers and assigned cybersecurity professionals to deliver program objectives.
- Foster a culture of accountability, innovation, and excellence within the team.
- Provide guidance and support to ensure professional growth and skill development among team members.
Experience Required
- Proven experience in delivering large-scale cybersecurity programs within complex, multinational organizations.
- Demonstrable track record of successful delivery against KPIs.
- Strong project and program management skills, with certifications such as PMP, PgMP, or PRINCE2 being a plus.
- Exceptional analytical, problem-solving, and decision-making capabilities.
- Excellent communication and stakeholder management skills, with the ability to influence at all levels of the organization.
- Understanding of regulatory requirements impacting security.
- Knowledge of cybersecurity frameworks, standards, and best practices (e.g., NIST CSF, ISO 27001, CIS Controls).
- Understanding of cyber operations, threat landscape and the techniques, tactics & procedures of advanced adversaries.
- Understanding of security technologies, tools, methodologies including SIEM, IDP/IPS, EDR, IAM, VM.
- Exceptional ability to manage internal and external stakeholders.
- Ability to work under pressure in a fast-paced environment.
- Excellent spoken and written English.