Assistant Manager - Information Security Risk and Governance

JTC Group

Saint Helier

Hybrid

GBP 45,000 - 65,000

Full time

12 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

JTC Group in Jersey is seeking an Information Security Risk and Governance professional to support the daily operations of security controls across our global system, including control oversight, assurance, testing and due diligence as part of the information security strategy.

In a hybrid workplace, you will contribute to risk assessments, maintain the risk register, support audits and help develop Business Continuity Plans with defined RTOs and RPOs.

Qualifications

  • Experience in Information Security Risk and Governance.
  • Strong technical skills with a risk-based approach including GRC solutions and Azure infrastructure.
  • Familiarity with information system frameworks, policies, standards, best practices, processes, and controls.
  • Strong attention to detail.
  • Excellent communication skills both verbal and written.
  • Ability to demonstrate an innovative approach to evolving information security risk and governance.

Responsibilities

  • Policy enforcement: support the implementation of information security policies and standards.
  • Governance, risk and compliance duties, both directly and indirectly.
  • Maintain and update the Information Security Risk Register and escalate as needed.
  • Assist with proactive risk assessments across network, infrastructure, application and third parties.
  • Help develop and maintain Business Continuity Plans (BCP) and BIAs with RTOs/RPOs.
  • Assist with client due diligence, internal and external audits.
  • Support reporting and analytics to track IT security initiatives.
  • Stay updated on security trends, threats, vulnerabilities and controls.
  • Assist with user access reviews and address security risks.
  • Maintain documentation of roles and responsibilities; comply with regulatory and AML requirements.
  • Adhere to CPD requirements and company values.

Skills

Information Security
Risk Governance
GRC
Azure

Education

Certifications

Job description

PURPOSE OF JOB

To support the Information Security Team in managing and overseeing the daily operations of information security risk and governance controls to ensure the ongoing security and efficiency of JTC’s global system. This role includes the deployment of control oversight, assurance, testing and due diligence responsibilities as part of the Group’s overall Information Security strategy.

EMPLOYMENT TYPE

Permanent

DEPARTMENT

Information Systems

DIVISION

Group

WORKPLACE STRUCTURE

Hybrid

ROLE OVERIVEW
PURPOSE OF JOB

To support the Information Security Team in managing and overseeing the daily operations of information security risk and governance controls to ensure the ongoing security and efficiency of JTC’s global system. This role includes the deployment of control oversight, assurance, testing and due diligence responsibilities as part of the Group’s overall Information Security strategy.

Main Responsibilities And Duties
  • Policy Enforcement: Either directly or in-directly support the implementation of the control requirements specified in our Information Security Policy and Standards and best practices. Be a central point of reference for any queries and questions in relation to Information Security Policies and Standards.
  • Governance, Risk and Compliance: Perform the applicable and necessary Information Security Governance duties, both directly and in-directly.
  • Risk Management: Maintain and update the Information Security Risk Register. As well as perform the necessary updates and escalations if necessary.
  • Assessments: Help perform the necessary proactive Information Security Risk Assessments (network, infrastructure, application and 3rd parties) to identify any control gaps and risks, then with the applicable stakeholders agree risk action plans in-line with the groups risk appetite and tolerance levels.
  • Business Continuity: Assist the Information Security Risk and Governance team head with the creation, management, review and maintenance of the Group wide Business Continuity Plans (BCP’s) and Business Impact Analysis (BIA’s). BIAs are to include documented ‘Recovery Time Objectives (RTO’s) and ‘Recovery Point Objectives (RPO’s) in line with business requirements and agreeable with Group Chief Information Office and Senior Director – Head of IT Infrastructure.
  • Due Diligence: Assist when required in completion and evidence gathering as part of client due diligence assessments as and when necessary, consistently, accurate and to a high standard.
  • Audits: Assist when required in completion and evidence gathering as part of internal and external audits as and when necessary, consistently, accurate and to a high standard.
  • Reporting and Analytics: Aid the Group Information Security Officer with the monthly analytical reporting which measures and tracks all IT security related information and initiatives and is delivered to key stakeholders.
  • Training and Development: Research and keep up to date with the latest information technology security trends, threats, vulnerabilities and control measures.
  • Monitoring and Auditing: Assist with user access reviews and address any inconsistencies or security related risks.
  • Documentation: Maintain comprehensive documentation in relation to role and responsibilities .
  • Adhere to Risk & Compliance procedures in relation to regulatory requirements and AML legislation.
  • Adhere to CPD requirements in accordance with qualification level and in-house procedures.
  • Adhere to JTC core values and expected behaviours.
  • Any other duties as deemed necessary by Management.
Essential Requirements
  • Relevant academic and/or professional certification(s).
  • Experience in Information Security Risk and Governance.
  • Strong technical skills with a risk-based approach, including experience with Governance, Risk and Compliance (GRC) solutions and Azure infrastructure.
  • Familiarity with Information System frameworks, policies, standards, best practices, processes, and controls.
  • Strong attention to detail.
  • Excellent communication skills both verbal and written.
  • Ability to demonstrate an innovative approach to emerging changes and advancements in information security risk and governance.
OUR COMMITMENT TO INCLUSION & WELLBEING

JTC is committed to fostering a healthy, inclusive organisation where all individuals feel welcome and feel able to participate in the workplace fully. We value different perspectives, backgrounds and lived experiences. This includes supporting employee wellbeing so that people feel equipped to thrive.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Assistant Manager, Information Security Risk & Governance
Assistant Manager, Information Security Risk & Governance

JTC Group • Saint Helier

Hybrid
GBP 45,000 - 65,000
Senior Administrator - New Business Team
Senior Administrator - New Business Team

JTC Group • Saint Helier

Hybrid
GBP 55,000 - 75,000
Administrator
Administrator

JTC Group • Saint Helier

On-site
GBP 18,000 - 24,000
Cyber Risk, Standards & Governance Lead
Cyber Risk, Standards & Governance Lead

Cyber UK • Greater London

On-site
GBP 60,000 - 80,000
Assistant Manager
Assistant Manager

JTC Group • St Peter Port

On-site
GBP 32,000 - 45,000
Administrator
Administrator

JTC Group • St Helier

On-site
GBP 26,000 - 38,000
Senior Associate – Information Security
Senior Associate – Information Security

Willis Towers Watson • Ipswich

Hybrid
GBP 55,000 - 75,000
25 days annual leave
Private healthcare
Life insurance
+3
Information Security GRC Manager
Information Security GRC Manager

AJ Bell • Manchester

On-site
GBP 65,000 - 85,000
27 days’ holiday
Pension with matched contributions up to 8%
Discretionary bonus and share awards
+3
Head of IT Security
Head of IT Security

Jobsoid Inc. • Greater London

Hybrid
GBP 120,000 - 170,000
Director - Business Development- Fund & Corporate Services
Director - Business Development- Fund & Corporate Services

JTC Group • Greater London

On-site
GBP 70,000 - 110,000
Hybrid work model