Cloud & Data Security SME
Join to apply for the Cloud & Data Security SME role at TOCUMULUS.
Roles and Responsibilities
- Ensure effective management and control of Cyber Security, IT, and information risk for CLIENT EMEA entities by implementing appropriate security, IT and relevant controls, ensuring they are followed and evidenced across the entire business and IT department.
- Liaise with Cyber Security and IT functions within CLIENT EMEA business entities and CLIENT group to ensure a consistent approach to all controls, standards and policies across the organisation.
- Ensure all necessary Cyber Security controls are in place and that an appropriate strategy to protect the firm from all Cyber, external and internal threats is defined and implemented.
- Develop, implement and manage compliance with appropriate IS and Cyber Security policies, standards and procedures.
- Support the relationship and reporting requirements between Technology and internal and external bodies (e.g. auditors, management committees, Tokyo head office, regulators via Compliance, Operational Risk).
- Act as the Cloud & Data Security lead under a dual-hat arrangement across CLIENT’s banking arm and securities business, making decisions on behalf of both entities with equal authority.
- Ensure NIST, ISO27002 and CIS aligned risk controls cover Cyber Security policies & standards.
- Ensure CLIENT EMEA operates under comprehensive and relevant Cyber Security policies and standards with appropriate staff awareness, compliance monitoring and reporting.
- Proactively manage Cloud Security toolsets (e.g. CSPM) and oversee container security controls for containerised workloads.
- Review and assess enterprise cloud architectures for security gaps and recommend mitigations.
- Monitor, investigate, and track cloud security alerts using integrated ticketing workflows in ServiceNow.
- Develop, improve and enforce cloud security standards, policies and procedures.
- Conduct Cyber Security reviews for existing and new, on-prem, cloud and 3rd party systems, solutions, firewall rules, architecture, and network designs to ensure consistency with CLIENT’s risk appetite, policy and standard requirements.
- Possess technical knowledge in Data Protection technology (DLP, Data Access Governance) and administer DLP tools (configuring policies, upgrading, patching).
- Serve as the Cloud Security center of excellence for CLIENT EMEA and ensure an appropriate professional response to any Cyber Security issues raised by the business activities.
- Liaise and collaborate with IT teams to highlight, manage and mitigate Cyber Security alerts, threats and vulnerabilities within appropriate timeframes.
- Collaborate with Technology and Business teams to ensure all CLIENT systems meet security standards or agree appropriate mitigation measures.
- Maintain up-to-date, working knowledge of current laws, regulations and best practices relating to Cyber Security.
- Support Operational Risk management & Operational Security duties when requested.
- Support CLIENT EMEA Cyber Security risk profile and associated operational risk reporting.
- Support Audit & Regulatory liaison and provide timely answers to information requests.
- Address issues and remedial actions resulting from Cyber Security incidents and audits within agreed timelines.
Requirements
- Degree or equivalent in IT related discipline with some programming knowledge or understanding.
- Strong Cloud, Information or Cyber Security background with over 8 years of experience.
- Strong ability to implement security solutions that enable business and work with vendors.
- Deep knowledge of cyber security frameworks, standards, and regulations such as ISO27001, NIST, CIS, GDPR, etc.
- Strong ability to analyse and distil complex issues and present succinct updates to management.
- Active involvement in internal and external audits and experience managing Audit relationships.
- Relevant professional certifications such as CISSP, CISM, CCSP, Azure Security Engineer Associate, Microsoft Cybersecurity Architect, AWS Certified Security – Specialty or CEH are preferred, as is exposure to GRC frameworks including ISO27001, NIST, CIS benchmarks & Cyber Essentials / Plus.
- Excellent communication and interpersonal skills.
- A structured, logical and proactive approach to work.
- Results driven with a strong sense of accountability.
- Configuration of data security tools (configuring policies, response rules & notifications).
- Monitoring and analysis of alerts.
- Ability to operate with urgency and prioritise work accordingly.
- Calm approach with the ability to perform well in a pressured environment.
- Strong decision-making skills and sound judgement.
- Comfortable taking ownership of workstreams and seeing them through to completion.
- Self-awareness and confidence to challenge business requirements and deliver difficult messages.
- Commitment to continuous learning and improvement in the rapidly evolving field of Cyber Security.
Seniority Level
Not Applicable
Employment Type
Full-time
Job Function
Information Technology
Industries
IT Services and IT Consulting