Enable job alerts via email!

Information Security Risk Lead (Financial Services)

Robert Walters UK

London

Hybrid

GBP 120,000 - 140,000

Full time

3 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a forward-thinking company as an Information Security Risk Lead, where your expertise will shape the future of risk management in a dynamic environment. With over a decade of experience in information security governance and operations, you will lead the implementation of critical frameworks designed to identify and mitigate security risks. This role offers the opportunity to work closely with various corporate departments and security teams, ensuring the highest levels of security in a globally recognized financial services firm. Embrace this chance to make a significant impact and advance your career in a collaborative and innovative atmosphere.

Benefits

Accelerated career progression
Dynamic culture
Expert training

Qualifications

  • 10+ years of experience in information security governance and risk management.
  • Broad technology experience in a global, regulated environment.

Responsibilities

  • Lead implementation of risk management frameworks to mitigate information security risks.
  • Provide credible challenge to the effectiveness of information security processes.

Skills

Information Security Governance
Risk Management
Cyber Resilience
Incident Response
Cloud Security
Network Security
Identity & Privileged Access Management
Threat/Vulnerability Management
Secure Coding Practices

Education

B.S. in a technology discipline

Tools

MS PowerPoint
MS Excel
Enterprise GRC tools (e.g. Archer)

Job description

Information Security Risk Lead (Financial Services)

The Information Security Risk Management Lead is a key member of the Risk Management team and is responsible for leading the implementation of the Enterprise and Operational Risk Management frameworks designed by my client to identify, measure, monitor and mitigate information security risks. The successful candidate serves as a second set of eyes to management to provide review and credible challenge of the effectiveness of information security processes and controls. This position is highly engaged with the firm-wide Information Security teams who provide security solutions as well as all corporate departments that own information security risk.

What they are looking for:

  1. 10+ years of experience specifically related to information security governance, operations, and risk management.
  2. Broad-based technology experience at substantial scale and complexity in a global, highly regulated, high-volume transaction environment. Experience must include time operating within transaction services environments characterized by the need for continuous availability and the highest levels of security.
  3. Experience with developing and managing Operational Risk programs, establishing framework and on-going process in accordance with best practices and Basel requirements.
  4. Comfortable leading in a complex matrixed organization, ideally in a global firm with a dynamic and rapidly changing environment.
  5. Experience leading within a highly regulated environment, with a preference for experience at the international and federal levels. Deep knowledge of policy frameworks and a strong understanding of policies, procedures, guidelines, and structure.
  6. Functional expertise, with operational knowledge of and exposure to various current and emerging information security areas such as:
    1. Cyber resilience
    2. Identity & privileged access management
    3. Secure coding practices
    4. Incident response
    5. Artificial Intelligence
    6. Third-party risk management
    7. Cloud security configuration and control frameworks
    8. Threat/vulnerability management
    9. Network security

Professional qualifications / certifications:

  1. B.S. in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent).
  2. Relevant certification is desirable, e.g., CISSP, CISM, CISA, CRISC.
  3. Working knowledge of Risk Management life cycles based on an established framework: NIST CSF, NIST SP 800-53, ORX, ISO 27001, SANS, CERT, ENISA, CSA, OACA, ISACA.
  4. Proficiency in MS PowerPoint and Excel.
  5. Experience in broader MS Office suite, including Project and Visio is a plus.
  6. Experience with enterprise GRC tools, e.g. Archer is a plus.

If the above role is of interest please apply to this ad or call me on 0207 509 8040 for more info.

About the job

Contract Type: FULL_TIME

Focus: Information Security

Workplace Type: Hybrid

Experience Level: Director

Location: London

Salary: £120,000 - £140,000 per annum

Job Reference: R9TEE5-DABABA25

Date posted: 4 April 2025

Consultant: Darius Goodarzi

Come join our global team of creative thinkers, problem solvers and game changers. We offer accelerated career progression, a dynamic culture and expert training.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.