Enable job alerts via email!

Director, Data Security

CLS Group

London

On-site

GBP 80,000 - 100,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Data Security Manager to lead the data security program and enhance the security posture across multiple divisions. This role involves strategic oversight, risk assessment, and collaboration with various teams to ensure compliance with regulatory requirements. The ideal candidate will have a strong background in data security management, excellent communication skills, and the ability to mentor junior team members. Join a dynamic environment where your expertise will contribute to safeguarding critical information assets and driving operational excellence in data security practices.

Qualifications

  • 5-8 years of functional security expertise in data security management.
  • Experience with GDPR and other data protection laws is essential.

Responsibilities

  • Provide strategic direction for data security management.
  • Communicate vulnerabilities and remediation methods to technical teams.
  • Perform risk assessments of applications and third-party vendors.

Skills

Data Security Management
Risk Assessment
Analytical Skills
Communication Skills
Documentation Skills
Collaboration Skills
Problem-Solving Skills

Education

B.S. in a technology discipline
Advanced degree

Tools

Firewalls
IPS
DLP
Proxies
SEIM
Endpoint Protection Software

Job description

Job Purpose

The Data Security Manager will partner with multiple divisions and technical managers to enhance security aspects of the data security program. Extensive oversight and control of CLS information assets, mitigating the risks of data loss at CLS in all aspects of day-to-day business. The individual will be accountable for the Data Security Program, setting strategic direction and driving operational excellence while leveraging resources distributed across several functional teams. The Data Security Manager will be responsible for analyzing potential weaknesses and identifying a roadmap to improve the security of information assets across CLS. The candidate will advise Business Owners, developers, and technical teams on options to mitigate risk. The candidate must have excellent verbal, written, analytical and interpersonal communication skills.

Essential Functions / Major Duties and Responsibilities
Strategic
  1. Provide strategic direction specific to data security management.
  2. Build and maintain a robust data security program while aligning closely with CLS's mission.
  3. Improve and manage the data security program and the company-wide security standards for the management of information assets.
  4. Contribute to the overall security strategy in its annual iterations.
  5. Provide strong knowledge of building security into business expectations for the utilization and hosting of critical CLS data/information assets.
  6. Work with the Security Architects to build security into infrastructure and architecture designs and guide the implementation with the Operations team.
  7. Provide direction and advice on projects to strengthen the overall cybersecurity posture.
  8. Assess SaaS and IaaS cloud services and virtualization technologies and provide direction and input for the maturation of the Cloud Security Framework in respect to data classification.
  9. Enhance security programs in response to regulatory requirements, internal audit and planned strategic initiatives.
  10. Foster relationships with key functional teams such as IT, Compliance, Operations, Finance, HR, Internal Audit, and Enterprise Risk to support current and future initiatives.
  11. Maintain timely understanding of CLS information assets, where they reside and how they are being utilized and hosted, continually review opportunities to improve the overall controls around data security.
  12. Keep informed of new and updated industry frameworks and regulations: GDPR, ISO 27001/2, SANS Top 20 Critical Security Controls, NIST CSF, SP 800-53, PFMI, CPMI ISOCO and FFIEC handbook.
  13. Keep informed of new and emerging security threats & assess effectiveness of current controls to identify opportunities for program improvement.
  14. Translate relevant directives, guidance, and rules into actionable data for consumption by the CISO and wider security teams.
Operational
  1. Communicate vulnerabilities, risks and remediation methods to business owners, developers and technical teams.
  2. Perform security testing on data controls using dynamic and static analysis tools.
  3. Integrate the defined relevant security controls into data security program.
  4. Ensure the operational security teams have the appropriate tooling/capabilities and quality assurance for data security management.
  5. Create and deliver knowledge sharing presentations and documentation to security, developers and operations teams.
  6. Learn on the job and explore new technologies independently to identify new and emerging security threats.
  7. Coordinate and maintain security policies, guidelines and procedures which communicate security controls that reduce risk to levels consistent with CLS risk tolerance.
  8. Prepare and deliver security briefings for consumption by CLS Security, CISO, Executive Management Committee, and the CLS Board of Directors.
  9. Assure compliance with security controls to identify control gaps, develop remediation plans and determine residual risk.
  10. Improve security metrics program to report key performance and risk indicators, trend statistical data and publish management reports for Internal Audit, Regulatory Exams, Risk Committee and Board reporting.
  11. Perform risk assessments of third-party vendors according to vendor criticality and vendor type to identify control gaps, develop remediation plans and determine residual risk.
  12. Perform risk assessments of applications according to application criticality and application type to identify control gaps, develop remediation plans and determine residual risk.
Leadership
  1. Provide leadership across Security functions and beyond for all aspects of data security.
  2. Individual contributor.
  3. Mentor junior members of the team technically and professionally.
Experience / Essential and Desired for Successful Job Performance
  1. 5-8 years functional security expertise with broad understanding of competencies and the lifecycle of data security management.
  2. Experience developing or managing security programs preferably across several domains including metrics and reporting for program maturity and risk reduction.
  3. Experience and/or training on GDPR requirements and other data protection laws.
  4. Experience defining program roles and responsibilities, assessing/identifying knowledge gaps across teams and implementing required training plans.
  5. Ability to collaborate effectively with others to drive forward key security objectives.
  6. Strong documentation and report writing skills (to both technical and business audiences).
  7. Excellent time management and organizational skills.
  8. Knowledge of policy frameworks and understanding of policies, procedures, guideline structure.
  9. Knowledge of firewalls, IPS, DLP, proxies, SEIM, & endpoint protection software.
Qualifications / Certifications
  1. B.S. in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent).
  2. Security certifications such as CompTIA Security +, CISSP, CISA, CRISC, CCNA, GIAC, or equivalent or working towards certification is preferred.
  3. Knowledge of Risk Management life cycles based on an established framework: ISO 27001, SANS, NIST SP 800-53, CERT, ENISA.
  4. Working knowledge of the following frameworks and regulations: ISO 27001/2, SANS Top 20 Critical Security Controls, NIST CSF, and FFIEC handbook.
  5. An advanced degree would enhance the candidate’s credentials.
Success Factors / Personal Characteristics Contributing to an Individual’s Ability to Excel in the Position
  1. Possess a strong service-oriented mindset to consistently deliver balanced security solutions that include people, process and technology.
  2. Possess strong technical, analytical and problem-solving skills.
  3. Self-motivated to exceed management expectations and objectives.
  4. Ability to effectively communicate complex technical issues to both business and technical staff at all levels.
  5. Strong collaboration skills to tackle complex security challenges that may span across multiple internal and external departments and groups.
  6. Able to effectively cope with change and comfortably handle risk and ambiguity, not upset when things are up in the air.
  7. Tenacious resolve and positive attitude in challenging situations.

#LI-JF1

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Data Privacy Manager

Broadgate

London

Hybrid

GBP 70,000 - 90,000

4 days ago
Be an early applicant

Data Protection Partner

Michael Page Legal

London

On-site

GBP 80,000 - 120,000

Yesterday
Be an early applicant

Senior Counsel / Counsel, Data & Privacy

Airwallex

London

On-site

GBP 70,000 - 90,000

5 days ago
Be an early applicant

Data Protection Partner

Michael Page (UK)

City Of London

On-site

GBP 80,000 - 150,000

Yesterday
Be an early applicant

Data Privacy Counsel

Graff Search

Greater London

Hybrid

GBP 60,000 - 100,000

22 days ago

Associate - Data Protection

TN United Kingdom

London

On-site

GBP 50,000 - 90,000

23 days ago

Special Counsel - Data Protection & Cyber

JR United Kingdom

London

On-site

GBP 70,000 - 120,000

Today
Be an early applicant

Data Protection Associates | Elite US Firm

JR United Kingdom

London

On-site

GBP 60,000 - 100,000

17 days ago

Cybersecurity & Data Privacy Associate

Douglas Scott Legal Recruitment

London

Hybrid

GBP 70,000 - 100,000

5 days ago
Be an early applicant