Enable job alerts via email!

IT Security Governance, Risk and Assurance (Financial Services)

Robert Walters UK

London

Hybrid

GBP 90,000 - 110,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player in financial services is seeking a skilled Information Security Governance, Risk and Assurance specialist to enhance their security posture. This dynamic role involves collaborating with various teams to ensure compliance with security policies and industry standards. You will conduct risk assessments, advise on best practices, and monitor improvements across security functions. This hybrid position offers a competitive salary and the opportunity to work with a forward-thinking team dedicated to maintaining a secure technology environment. If you are passionate about cybersecurity and eager to make a significant impact, this role is for you.

Qualifications

  • 5+ years in Information and Cyber Security, with 2+ years in a security risk team.
  • Expert in technical writing and documenting risk assessment findings.
  • Strong understanding of security risk management principles.

Responsibilities

  • Maintain security policies, standards, and frameworks.
  • Conduct regular risk assessments and maintain risk register.
  • Provide assurance through detailed reporting and metrics.

Skills

Information Security
Cyber Security
Risk Assessment
Technical Writing
Problem Solving
Communication Skills
Attention to Detail

Education

MSc in Information Security
CISA
CRISC
CISM

Tools

RSA Archer
GRC Tools

Job description

IT Security Governance, Risk and Assurance (Financial Services)

Save job

My client, a Financial Services company based in London, are looking for an Information Security Governance, Risk and Assurance specialsit to join their growing team. This role is two days per week in the office in London (near Canary Wharf).

About the Information Security Governance, Risk and Assurance specialist:

The individual will be part of the security function that is responsible for security governance, risk and assurance, to ensure the organisations security posture is robust, compliant against the security policy, standards and controls. The position will require close collaboration with technical, operational, compliance and audit teams to create a secure and compliant technology environment.

What you will be doing:

  • Maintain security policy, standards, procedures and frameworks.
  • Ensure alignment with security industry standards such as NIST CSF and NIST 800-53.
  • Act as an advisor to colleagues across the organisation on best security practice.
  • Conduct regular risk assessments and maintain risk register in RSA Archer.
  • Identify assess and prioritize security risk across the organisation’s information assets and environments.
  • Understanding security gaps and provide evaluation and treatment options, consultation on remediation approaches to address gaps and continue ongoing monitoring of remediation, re-assess until reduced to an acceptable level.
  • Supporting Cybersecurity Risk Management strategies based on security findings and observations. Including informing improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all security functions
  • Profile and assign asset security criticality and prioritize risk assessments.
  • Where risk driven change is agreed across security functions, monitoring improvements against the baselined risk to evidence and report where security risk is being reduced to an acceptable level across security functions. Including Policy exceptions and dispensations.
  • Run lessons learned forums and recommend improvements to security controls.
  • Represent security on audits and assessments, ensuring compliance with internal and external requirements.
  • Provide assurance to stakeholders through detailed reporting and metrics.

What we’re looking for:

  • Minimum of 5 years’ experience in Information and Cyber Security, with minimum of 2 years’ experience in a security risk team.
  • Highly organised with experience of planning and reporting data, information and updates.
  • Ability to collaborate effectively with others to drive forward key security objectives.
  • Expert in technical writing reports and documenting risk assessment findings and mitigation plans clearly and accurately.
  • Attention to detail, Meticulous attention to detail to ensure data accuracy and integrity and ensure thorough and accurate risk assessment.
  • Problem solving, ability to grasp security issues that impact multiple entities and troubleshoot with proposing and consulting with colleagues on effective solutions to mitigate risks.
  • Excellent verbal and written communication skills to convey complex technical information clearly and effectively. Presenting data insights to non-technical stakeholders
  • Strong understanding of security risk management and taxonomy principles, to reduce risk to an acceptable level.
  • Knowledge of vulnerability management and incident management practices.
  • Experience with GRC tools and best practices. RSA Archer is preferred.
  • Financial and/or Banking industry experience preferred.
  • Ideally qualified in MSc Information Security, CICA, CRISC, CISM and/or Data analysis beneficial but not essential if experience validates skills.
  • Proficiency in security frameworks (e.g., NIST CSF, ISO 27001, SOC1,2).
  • Prince 2, MSP, APMQ advantageous.
  • A desire to continue learning and developing security skills and qualifications

If the above is of interest please apply to this role or call me on 0207 5098040 to find out more. Alternatively, you can email me your CV to Darius.Goodarzi@robertwalters.com

Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates

About the job

Contract Type: FULL_TIME

Focus: Information Security

Workplace Type: Hybrid

Experience Level: Senior Management

Location: London

Contract Type: FULL_TIME

Specialism: Technology & Digital

Focus: Information Security

Industry: Banking

Salary: £90,000 - £110,000 per annum

Workplace Type: Hybrid

Experience Level: Senior Management

Location: London

FULL_TIME

Job Reference: JLRAXT-B51A7D3A

Date posted: 25 April 2025

Consultant: Darius Goodarzi

london information-technology/information-security 2025-04-25 2025-06-24 banking London London GB GBP 90000 110000 110000 YEAR Robert Walters https://www.robertwalters.co.uk https://www.robertwalters.co.uk/content/dam/robert-walters/global/images/logos/web-logos/square-logo.png true

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

IT Security Governance, Risk and Assurance (Financial Services)

Robert Walters

London

Hybrid

GBP 90,000 - 110,000

30+ days ago

Risk Management, FRTB Lead, Vice President

Morgan Stanley

London

On-site

GBP 90,000 - 150,000

14 days ago

Chief Technology Officer

Gomart

London

Hybrid

GBP 80,000 - 120,000

14 days ago

Head of Operational Risk

Marks Sattin

London

On-site

GBP 80,000 - 120,000

21 days ago

Third-Party Oversight Specialist

JR United Kingdom

Dartford

On-site

GBP 80,000 - 100,000

11 days ago