Job Description: Employer: DWS Group
Title: Information Security Officer (ISO)
Location: London
About DWS:
Today, markets face a whole new set of pressures – but also a whole lot of opportunity too. Opportunity to innovate differently. Opportunity to invest responsibly. And opportunity to make change.
Join us at DWS, and you can be part of an industry-leading firm with a global presence. You can lead ambitious opportunities and shape the future of investing. You can support our clients, local communities, and the environment.
We’re looking for creative thinkers and innovators to join us as the world continues to transform. As whole markets change, one thing remains clear; our people always work together to capture the opportunities of tomorrow. That’s why we are ‘Investors for a new now’.
This is your chance to invest in your future.
Team / division overview
DWS Group operates in a business environment with an almost complete dependence on information, which is processed and transmitted by information systems and interconnected computer networks and stored physically and electronically. Information security risk and threat landscape are dynamic and requirements for security are constantly growing. It is essential for DWS that confidentiality, integrity (authenticity) and availability of information are protected, and risk is managed according to DWS’ Risk Appetite and in accordance with legal and regulatory requirements.
The role of the DWS Information Security Officer (ISO) is aligned to the DWS COO divisional unit and will report into the Divisional Information Security Officer (D-ISO). DWS ISO assumes ownership for the assigned IT Assets from an information security (IS) perspective.
Role Details:
As an Information Security Officer you will:
- Assume ownership and responsibility for assigned IT assets, in line with the Group Information Security management processes and the DWS ISMS.
- Execute IS Risk assessments and compliance evaluations for assigned IT assets.
- Assign accurate information classification to assigned IT assets based on confidentiality of Information.
- Maintain the Information Security related documentation of assigned IT assets in the Group’s asset inventory.
- Establish a good working relationship with Business Application Owners (BAO) and other Subject Matter Experts (SME) of the divisions and functions of the assigned assets and develop profound knowledge of the supported processes and data.
- Support key role holders such as ITAOs and TISOs to develop a secure environment by evaluating the Information Security requirements as early as possible in the system development life cycle to select the applicable Information Security Controls for implementation.
- Provide guidance to ITAOs and TISOs on the implementation of compensating Controls in case of deviations from the applicable Information Security Controls.
- Execute and document periodical recertification of user access rights in their area of responsibility in compliance with the Group’s identity and access processes.
- Support implementation of Segregation of Duty (SoD) rules for the assigned IT assets.
- Contribute to the Information Security incident management process in the case of a security breach.
- Deliver all items requested during regulatory and internal Information Security related audits.
- Remain fully trained and skilled by completing the required Information Security trainings provided by CSO or as requested by the Divisional CISO or the Divisional ISO.
We are looking for:
- Proven experience of working in Information Security and/or Information Technology, ideally in a regulated financial institute.
- Strong communication (written and verbal) skills with the ability to effectively communicate with different stakeholders within IT and business functions.
- Knowledge on Information Security Controls, Data Protection Policy, Information classification principles and segregation of duties requirements within a financial organization.
- Positive attitude and a team player.
- Proactive and ability to work independently in a global team.
- Open to learn, adapt and work with new technologies.
- Outstanding problem solving, analytical and project management skills.
- Proficiency with Microsoft Office programs.
- Fluent English and communication skills.
- Degree-level IT and/or information security qualification, or equivalent experience in Information Security and IT Security.
- General understanding of current security industry standards, best practices, and/or frameworks i.e.: NIST, ENISA, ISO27001, OWASP.
What we’ll offer you:
At DWS we’re serious about diversity, equity and creating an inclusive culture where colleagues can be themselves. It’s important to us that you enjoy coming to work - feeling healthy, happy and rewarded. At DWS, you’ll have access to a range of benefits which you can choose from to create a personalised plan unique to your lifestyle.
Some of our core benefits:
- 30 days’ holiday + bank holidays, with the option to purchase additional days.
- A non-contributory pension scheme, up to 10%.
- Physical and Mental Health Well-Being benefits including Private Medical Cover, a complimentary GP service and the support of Mental Health First Aiders.
- Family friendly benefits including generous parental leave packages to healthcare plans and travel insurance.
- The opportunity to support our CSR strategy focused on combatting climate change and achieving greater social justice.
DWS’ Hybrid Working model in the UK is designed to find the right balance between in-person collaboration and engagement in the office, which is core to our working culture, and working from home. Employees who wish to sign-up to our Hybrid Working model are required to work in the office two days a week, and given the flexibility to work from home for the remaining three.
If you require any adjustments or changes to be made to the interview process for any reason including a disability or long-term health condition, please contact your recruiter and let them know what assistance you may need.