IT Risk & Security Analyst recruitment

Main Duties

• Undertaking work on a range of projects supporting GIS Security projects.

• This could include working closely with project teams within Global Technology.

• The role will involve close liaison with areas of the Business, IRM, Compliance, and Audit to deliver solutions and effect their implementation.

• Review new and proposed technologies to identify security risks, vulnerabilities and non-compliance;

• Review changes to existing technologies to identify security risks, vulnerabilities and non-compliance;

• Analyse internal and external threats to the environment;

• Drive to understand the global IT environment and strategic requirements;

• Pro-actively provide transparent and integrated risk controls that are commensurate with identified risks;

• Seek global consistency and accountability;

• Foster a culture of information security awareness in all aspects of work;

• Communicate risks in an appropriate and expeditious manner;

• Position security as a preventative measure, rather than just a reactive response;

• Working closely with the security operations team and assisting with integration of toolkit and development of processes

Preferred:

•             Qualified in one or more fields of Information Security (e.g. CISA, CISSP, GIAC, etc.).

•             IT Audit Qualification or comparable professional certification. 

Experience required:

Essential:

•             Business focus with thorough appreciation of IT issues and how IT enables the Investment banking business.

•             Thorough understanding of information security issues

•             Good experience of working in Projects and exposure to project management techniques.

•             Good experience of risk management concepts and principles and ability to treat information security as a risk management, not IT, issue.

•             Global focus.     

Preferred:

•             Preferred 6 years or more relevant experience.

Please only apply if you are currently working within Informatiion Security Risk, ONLY shortlisted candidates will be contacted