About this role
Key responsibilities:
Governance & Policy Management
- Own the lifecycle management of Information Security policies, standards, frameworks and procedures.
- Develop, review and maintain governance documentation to ensure alignment with business objectives and regulatory requirements.
- Establish governance processes to ensure policies, standards and controls are consistently implemented across the organisation.
- Monitor adherence to security policies and standards and drive remediation of non-compliance findings.
Information Security Management System (ISMS)
- Lead the ongoing maintenance, effectiveness and continual improvement of the Information Security Management System (ISMS).
- Drive ISO 27001 certification & recertification activities and ensure certification evidence, control documentation and audit records are maintained and auditable.
- Coordinate internal audit programmes, external certification audits and remediation activities.
Risk Management
- Own and continuously improve the enterprise information security risk management framework.
- Maintain and oversee the Group Security Risk Register. Facilitate risk identification, assessment, treatment, acceptance and reporting activities across business units.
Client Assurance & Regulatory Compliance
- Lead responses to client security questionnaires, due diligence requests, regulatory enquiries and customer assessments.
- Manage and coordinate customer Right-to-Audit engagements, particularly with regulated financial institutions and strategic clients.
- Act as the primary contact for external auditors, assessors & customer assurance teams
- Monitor emerging regulatory requirements and assess their impact on the organisation.
Third-Party Risk Management
- Conduct & oversee security assessments for vendors, suppliers and strategic partners.
- Review contracts, security documentation, certifications and audit reports to evaluate risk and ensure supplier risks are appropriately documented, managed and escalated.
Stakeholder Management
- Partner with Security Operations, Engineering, Architecture, Legal, Compliance, Internal Audit and business stakeholders to address identified risks and compliance obligations.
- Provide guidance and subject matter expertise on governance, regulatory compliance and risk management matters.
- Support security awareness initiatives and promote a culture of risk management and compliance.
Required Skills, Experience & Qualification:
- Min 8 to 10 years of experience in Governance, Risk & Compliance, Information Security, Audit or Risk Management roles, preferably within a financial services environment
- Bachelor’s degree of equivalent related experience.
- ISO27001 Lead Implementer / Auditor - demonstrable experience leading ISO 27001 certification and recertification programmes within large, complex organisations.
- Proven experience designing, implementing and maintaining enterprise risk management frameworks.
- Extensive experience developing, reviewing and managing information security policies, standards and control frameworks.
- Significant experience managing customer assurance activities, security questionnaires and Right-to-Audit engagements.
- Experience presenting risk and compliance information to senior stakeholders and executive leadership.
- Strong knowledge of:
- ISO 27001 / ISO 27002
- ISO 31000 / ISO 27005
- ISO 22301 / ISO 42001
- NIST Cybersecurity Framework
- SOC 1 / SOC 2
- GDPR
- DORA
- NIS2
- Experience presenting risk and compliance information to senior stakeholders and executive leadership.