Department: Information Security
Location: Glasgow
Contract Type: Permanent
Role: Information Security Specialist
Key Responsibilities
Training, Awareness & Human Risk
The chosen candidate will be accountable for the successful delivery and continuous improvement of Clyde & Co's security awareness programme, owning the relationship with training providers, developing engaging content and partnering with stakeholders across the firm to drive behavioural change and strengthen the firm's security culture.
- Manage enterprise phishing simulation campaigns, awareness training initiatives and behavioural change activities to improve security culture and reduce cyber risk.
- Coordinate the delivery of annual security campaigns including Cyber Security Awareness Month (CSAM), mandatory training activities and targeted awareness initiatives.
- Monitor emerging threats, industry practices and security awareness trends, recommending improvements to strengthen organisational resilience and human-risk management capabilities.
- Maintain and manage initiative plans, milestones, dependencies and reporting for assigned security improvement programmes.
- Own and maintain strong a productive relationship with external vendors to ensure the quality, effectiveness and continuous improvement of awareness and training services.
- Monitor vendor performance against agreed service levels, success metrics, and contractual commitments, driving improvements where required.
- Produce tailored management reports, dashboards and presentations for senior leaders, providing meaningful insights into programme performance, compliance levels, user behaviour and areas of risk.
- Partner with senior stakeholders to increase engagement, improve training completion rates and promote a strong security culture throughout the firm.
- Present findings, recommendations, and programme updates to management in a clear, concise and business-focused manner.
Supply Chain Risk and Supplier Assurance
The chosen candidate will be responsible for maintaining effective oversight of Clyde & Co's third-party security risk exposure, providing proactive insight into emerging supply chain threats and vulnerabilities and ensuring the firm's supplier assurance processes remain current, risk-based and aligned to the firm's IT&O Risk Management Framework.
- Maintain, execute and enhance third-party and supply chain security risk management processes including tiering of suppliers by risk, periodic and ad hoc third-party information security assessments (TPISA) and ongoing assurance activities.
- Design and operate supplier security assessment mechanisms, including contractual security schedules, supplier risk questionnaires, attestations and contract review processes.
- Manage information security within the supplier relationship throughout the lifecycle, ensuring that supply chain risks, control deficiencies and remediation actions are identified, tracked and addressed in a timely manner.
- Collaborate with Information Security, IT, Procurement, Risk Management, Legal and business stakeholders to ensure security requirements are integrated into operational processes and supplier engagements.
- Monitor, analyse, and assess emerging supply chain security threats, industry trends, regulatory developments, geopolitical risks, and third-party security incidents to identify risks that may impact Clyde & Co's supply chain.
- Develop and maintain a comprehensive understanding of Clyde & Co's supplier estate, identifying areas of concentration risk, systemic risk, fourth-party dependencies, and critical supplier exposures.
- Continuously evaluate and improve third-party risk management processes, methodologies, assessment frameworks, and assurance activities to ensure they remain effective, proportionate, and aligned to the firm's risk appetite and evolving threat landscape.
- Establish and maintain meaningful assurance activities over key(critical) suppliers through the review of independent audits, certifications, penetration test summaries, security attestations, performance metrics, and other relevant evidence.
Email DLP and Information Protection
To continuously enhance Clyde & Co's Email DLP and Information Protection capabilities, ensuring the firm's confidential, sensitive, and client information is protected through effective preventative, detective, and responsive controls while enabling secure business operations and collaboration.
- In conjunction with the Risk department, continue the development and enhancement of