Head of Information Security leading cybersecurity strategy and managing risk at TradingHub. Collaborate across teams to maintain security posture for corporate and cloud environments.
Responsibilities
Take ownership of the firm’s Information Security function and maintain/improve its security posture
Take the lead in responding to customer security questionnaires or audit follow-ups
Oversee our regular ISO27001 and SOC 2 Type II audits
Research and choose technical tools to proactively detect and respond to weaknesses, threats and potential compromises
Lead the development, implementation, and continuous improvement of information security practices across all teams
Manage regular pentests by external consultants and coordinate with internal resources to remediate issues
Information security risk assessment of third-party service providers
Offer guidance, direction and approval on security solutions and approaches
Advocate for secure engineering best practices throughout the company
Manage the standards, policies and guidelines of the InfoSec frameworks
Maintain an on-going information security awareness program
Monitor our SIEM, and maintain useful reports and alerts in the system
Requirements
Significant industry experience in a technical security role (Security Engineering or Application Security Engineering)
Experience speaking to customers and establishing a good working relationship with infosec counterparts at major financial institutions
Strong technical intuition, with an ability to partner with engineering to evaluate and develop good security standards
Take a risk-based approach when suggesting improvements, or proposing fixes
Ability to perform design reviews and/or technical assessments of software and infrastructure
Excellent knowledge of InfoSec, risk management and governance, data protection
Programming/scripting experience, especially to automate repetitive tasks
Used to multi-tasking and working in a fast-paced environment
Proven ability to identify and articulate information security requirements, risks and issues, and to make clear decisions / recommendations
Ability to understand business drivers and risk appetite and align information security compliance accordingly
Strong ability to communicate clearly and simply, both verbally and in writing
Benefits
Annual discretionary performance bonus
Hybrid working policy
Office lunches twice a week
Aviva private medical insurance + Unum dental cover
Extended parental leave (up to 6 months of fully paid maternity leave)
25 days annual leave + bank holidays
Enhanced company pension plan
Salary sacrifice scheme
5 days study leave towards professional qualifications
Senior Information Security Engineer at Wells Fargo creating secure environments for cyber research. Collaborating with teams to enhance security and innovate solutions.
Security Officer II ensuring safe environment for patients and visitors at Sutter Health. Responsibilities include patrolling and monitoring, access control, and incident investigation.
Enterprise Security Posture Management Analyst overseeing vulnerabilities and configurations across environments for Black & Veatch. Collaborating with IT on remediation efforts and security enhancements.
Security Business Partner working in a hybrid model coordinating cybersecurity strategies for Liebherr Hotels. Leading projects and ensuring risk - based decision - making in hospitality technology.
Senior Cyber Security Engineer responsible for designing scalable security solutions and mentoring team members at Sonepar. Involved in cloud migration and ensuring protection against evolving threats.
Consultant for Cyber Security at UNITY, advising clients on effective security strategies and implementations to build trust in digital futures. Engage in client transformation for sustainable security programs.
Cyber Security Specialist responsible for monitoring and defending against cyberattacks for an international bank in Zurich. Focus on threat intelligence, incident response, and cyber security compliance.
IT Security Specialist managing security processes and responding to incidents for a technical service company. Collaborating on internal audits and enhancing IT security strategies.
Cybersecurity Governance expert managing cybersecurity efforts for international logistics and services company. Enhancing frameworks, reporting, and conducting gap analyses and pen tests.