Role Purpose
The Cyber Security Engineering Vulnerability & Threat Management (VTM) team are looking for an independent, pro‑active, and aspiring individual who is committed to making a meaningful contribution, as a VTM Analyst. They will play a supporting role utilising their technical experience to enhance VTM solutions that best fit our business requirements. The team is a part of the Cyber Security Engineering function that is developing cyber defence capabilities to protect the business from cyber threats which seek to impact the confidentiality, integrity, and availability of the group.
Reporting & Key Relationships
Report to: Senior Manager, Vulnerability & Threat Management
Direct reports: No direct FTE reports. May manage contingents and vendor/partner resources in their deliveries.
Key relationships: Stakeholders include the wider security team (security architecture, vulnerability and threat management, cyber strategy business function, governance, risk and compliance, programme management); Entity level Business Information Security Officers (BISOs); Infrastructure & Cloud operations, engineering and architecture teams; Internal risk and audit functions; Architecture and corporate approval forums; External partners/vendors and industry schemes.
Location
Bengaluru – Hybrid Working
Key Responsibilities
- Contribute to domain strategies and architectures, leading engineering and associated artefacts across Vulnerability and Threat Management.
- Be responsible for the controls related to the domain area and ensure they remain effective.
- Lead and deliver smaller scale projects or discrete workstreams for larger projects as part of the cyber programme and other initiatives.
- Manage and deliver changes to controls as necessary which are not part of project activity.
- Develop key indicators, analysis and artefacts to continually evidence and report control effectiveness and risk for the group.
- Provide critical issue support for any operational incident from operations or global security operations centre for related domain technologies.
- Accountable for ongoing activities and objectives for the domain area.
- Solve complex problems related to the domain area.
- Remain current with principles, concepts and emerging technologies related to the role.
- Influence vendor roadmaps and functionality in support of LSEG objectives.
Leadership Responsibilities
- This role is an individual contributor and leads no FTE headcount.
Critical Work
- Delivery of activities against agreed cyber security strategies. Shapes project delivery with the project management team and the senior manager of the domain area.
- Delivery of key artefacts associated with the role, supporting evidence and assurance activities.
- Ongoing control operation, effectiveness and evidencing of such.
- Reporting, development and management of agreed measures, key performance indicators and key risk indicators.
Key Critical Metrics
- Delivery of projects and BAU activities within agreed timescales to the required standard.
- Issues that are identified are fixed and remain fixed and do not recur.
- Key artefacts for the activities performed exist, are accurate and of required standard.
- Agreed measures related to controls owned by the role (e.g., Key Risk Indicators) are delivered and managed.
Technical / Job Functional Knowledge
- Knowledge and experience in the engineering and operation of vulnerability and threat management technologies and their integration with relevant platforms. Competent level in the domain technology area.
- Knowledge of different operating systems, platforms, and applications relevant for the domain area and implications for those platforms. Proficient level of knowledge.
- Engineering of layered control capabilities.
- Understanding of information security principles and standard methodologies.
- Good understanding of Adversary Tools, Techniques and Procedures (TTPs) is required.
- Knowledge in domain area and basic knowledge across non-core domain areas.
- Modern engineering practices, automation to drive efficiencies, Infrastructure as Code mentality, and coding/scripting for practical tasks and tool integrations.
- Structured and methodical problem‑solving practices for resolving sophisticated problems.
- Proficiency in policies, standards and security frameworks such as NIST and CIS. Strong skills to author formal documentation.
- Understanding of security metrics to measure control operation and risk.
- This position holder works independently with minimal guidance and is expected to solve problems with sound judgement in a way that aligns with good practice and the long‑term interests of LSEG.
- The role holder is likely to hold one or more of the following security or engineering/architecture specific certifications: CISSP, OSCP, TOGAF, GIAC, or other relevant qualification.
Leadership and Management Experience
- Experience in advocating for and inspiring change to reach the best outcome according to the needs of the organisation, customers and industry trends.
Personal Skills and Capabilities
- Collaborating across the group to deliver successful balanced outcomes for the group and its partners.
- Takes ownership and commits to delivering sustainable outcomes and resolving problems.
- Demonstrates a bias for action.
- Consistent track record of delivering results without compromising on quality.
- Critical thinker who takes broad perspectives to assess and make decisions.
- Willingness and flexibility to work across different technologies.
- Capability to quickly assimilate new concepts and technologies.
- Takes ownership of own career development and learning.
- Supports colleagues with less experience to help in their professional growth.
- Adapts messaging and presentation styles to the requirements of the audience.
- Is measured and considered in complicated and fast‑paced situations.
Diversity & Inclusion
People are at the heart of what we do and drive the success of our business. Our colleagues thrive personally and professionally through our shared values of Integrity, Partnership, Innovation and Excellence, which are at the core of our culture. We embrace diversity and actively seek to attract people with unique backgrounds and perspectives. We are always looking at ways to become more agile, so we meet the needs of our teams and customers. We believe that an inclusive collaborative workplace is pivotal to our success and supports the potential and growth of all colleagues at LSEG.
Benefits
LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.
Equal Opportunity Employer Statement
We are proud to be an equal opportunities employer. We do not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. We can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.
Privacy Notice
Please take a moment to read this privacy notice carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what it’s used for, and how it’s obtained, your rights and how to contact us as a data subject.