Job Search and Career Advice Platform

Enable job alerts via email!

Information Security Lead, Europe

Corpay

Greater London

On-site

GBP 70,000 - 90,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading fintech organization in the UK seeks a Business Information Security Officer to manage cybersecurity and compliance efforts across multiple regions. The ideal candidate will have a strong background in information security, with at least 10 years of relevant experience. Responsibilities include advising business units on security practices, managing risk assessments, and ensuring compliance with regulations such as PCI and GDPR. You will liaise with IT and leadership to enhance security culture while navigating multiple projects in a dynamic environment.

Qualifications

  • 10+ years of technical information security experience.
  • 5 years working with business leadership on enterprise projects.
  • Experience in various information security management tools.

Responsibilities

  • Act as a trusted advisor for business security and compliance.
  • Communicate security risks to business and IT units.
  • Lead cybersecurity initiatives and incident response activities.

Skills

Vulnerability assessment
Incident response
Project management
Data encryption standards
Network level security

Education

Bachelor’s degree in IT or Information Security
CISSP
CRISC
CISA

Tools

SIEMs
Firewalls
Intrusion Prevention Systems
Job description

Your role

Responsible for monitoring, reacting and reporting on information security events as well as supporting the management of security operations activities within the core business lines in the U.K., Europe, Australia and New Zealand. Provide governance and support for regulatory and industry compliance requirements, facilitate audit activities and direct remediation efforts to ensure compliance and security best practices, and serve as a trusted security advisor.

What you'll be doing
Role and Responsibilities

The business information security officer (BISO) serves as a trusted security advisor to lines of business and IT leadership. The BISO understands security risks and technologies and is able to effectively communicate them to business and IT units. The BISO works in tandem with the business across multiple services and platforms to address risk, while advising business leaders to ensure they are making decisions with security in mind. The BISO is an advanced role supporting the cybersecurity program. This individual provides leadership, executive support, and strategic and tactical guidance for a world-class cybersecurity program supporting enterprise security initiatives. As a business enabler, the BISO is an effective communicator with the technical aptitude to drive security fundamentals into aspects of the business.

  • Serve as a trusted advisor to business unit and IT leadership.
  • Act as a liaison to ensure cybersecurity practices are built into business unit initiatives for the entire lifecycle.
  • Work closely with security leadership to instill cybersecurity policies and practices throughout business units to address security operations, incident response, application security and infrastructure.
  • Be actively informed and engaged in security projects across the business.
  • Provide disaster recovery and business continuity planning advice when working with leaders for business and cybersecurity resiliency.
  • Enforce the strong security culture set forth by the CISO, ensuring uniformity across security leadership, business units and employees.
  • Advise business units on enterprise-wide people, process and technology security recommendations.
  • Maintain up-to-date knowledge related to security threats, vulnerabilities and mitigations set forth to reduce the attack surface; circulate this knowledge through the business units.
  • Identify and document threats and vulnerabilities that may impact the business and address them regularly with business units.
  • Provide motivation to business units to adopt cybersecurity controls.
  • Build relationships with business units to deliver security-by-design controls incorporated into projects, architecture, infrastructure and applications.
  • Stay abreast of new laws, regulations and standards, and assess their impact to the business.
  • Support the effort to maintain security requirements for regulatory bodies such as PCI, SOX, GDPR, and ISO standards.
  • Lead the effort to ensure appropriate monitoring is in place and react quickly to security incidents using multiple sources and tools (e.g. SIEMs, vulnerability scans Firewalls and IPS, etc.).
  • Support and facilitate the development of an information security risk management program and knowledgeable in various risk assessment methodologies within the line of businesses.
  • Perform other duties as assigned.
Qualifications and Education Requirements

At least 10+ years of technical information security experience including but not limited to vulnerability assessment, intrusion detection, incident response, forensics, system audit, firewall management and support to compliance audits (e.g. PCI-DSS, SOX, ISO27001, etc.). At least 5 years’ experience working with business leadership and enterprise projects. Experience managing projects and deliverables in a complex matrix. Must understand and demonstrate following security technology and concepts : File Integrity Monitoring, Firewalls and IPS functionality, server hardening, security incident qualifiers, risk assessment ranking, application security concepts and protocols, network level security concepts, data encryption standards and implementation, cloud security and auditing. Minimum of 3 years of IT and / or Information Security compliance and audit support (e.g. PCI DSS, SOX, SSAE18, GDPR, etc.). High level of integrity, trustworthiness and confidence, and able to represent the company and security leadership with the highest level of professionalism.

Education & Certifications : Bachelor’s degree in IT or Information Security, CISSP, CRISC, CISA, or other relevant certification.

Additional Notes

Ideal candidates will be a self-starter, can manage multiple projects / initiatives at once, with experience in multiple information security management and monitoring tools as well as navigating a variety of industry and international regulatory frameworks. Work in fast past highly technical environment. Strong verbal and written communication skills with the ability to effectively communicate and articulate information security and compliance related topics and strategies to both peers and senior leadership.

About Corpay

Corpay is a global technology organisation that is leading the future of commercial payments with a culture of innovation that drives us to constantly create new and better ways to pay. Our specialized payment solutions help businesses control, simplify, and secure payment for fuel, general payables, toll and lodging expenses. Millions of people in over 80 countries around the world use our solutions for their payments.

All offers of employment made by Corpay (and its subsidiary companies) are subject to the successful completion of satisfactory pre-employment vetting by an independent supplier (Experian). This is in accordance with Corpay’s Resourcing Policy and include employment referencing, identity, adverse financial, criminal and sanctions list checks. We do this to meet our legal and regulatory requirements.

Corpay is dedicated to encouraging a supportive and inclusive culture among our employees. It is within our best interest to promote diversity and eliminate discrimination in the workplace. We seek to ensure that all employees and job applicants are given equal opportunities.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.