Job Search and Career Advice Platform

Enable job alerts via email!

Cyber Risk Oversight Vice President

Cyber Security training courses

Greater London

Hybrid

GBP 90,000 - GBP 120,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A major banking institution is seeking a Cyber Risk Oversight VP to join their team in London. This role involves developing Second Line of Defence capabilities for Cyber risk management while ensuring compliance with regulatory requirements. Candidates should have strong experience in Information Security and Cyber risk, especially within financial services. The role requires attendance in the London office three times a week and emphasizes collaboration across the EMEA region. Relevant certifications like CISSP or CISM are desirable.

Qualifications

  • Excellent knowledge and experience of Information Security, Technology and Cyber risk management.
  • Proven ability to analyze and communicate an organization's Technology and Cyber risks clearly.
  • Strong analytical skills to evaluate risk and understand underlying causes.

Responsibilities

  • Assist with the development of the firm's Second Line of Defence capabilities.
  • Support development and delivery of medium to long-term objectives for Cyber Controls.
  • Provide robust challenge to the First Line of Defence in risk management.

Skills

Cyber and Information Security best practice
Threat Modelling
Vulnerability Risk
Cloud Security Risk
IAM Risk
Network and System Risk
Third Party Risk
Data analysis methods for risk modelling

Education

Educated to degree level or equivalent industry experience
CISSP, CISM, or equivalent certifications
Job description
Overview

My client, an International bank, based in London, are looking to hire a Cyber Risk Oversight VP to join their growing team. For this role you would have to attend their office in London 3 times per week. They are looking for someone who comes from a Technical background (as per the below job description). They are not solely looking for a GRC person.

Main purpose of the role

To assist with the development of the firm's Second Line of Defence capabilities (policies, procedures, risks and controls) to manage Information Security and Cyber risk in London and further support across the EMEA region, in line with regulatory requirements, and to support the achievement of the Bank's strategic objectives.

Key Responsibilities
  • Assist with the continuous embedding of the Operational Risk framework for the Technology and Cyber risks and controls within the Technology function working in conjunction with the First Line teams and Head Office.
  • Monitoring regulatory changes in approach to Technology and Cyber and recommend changes enhancements to the Control framework.
  • Support the development and delivery of medium to long term objectives and actions within the framework, including greater oversight and additional testing of the Technology and Cyber Controls and RCSA's.
  • Participate actively in the delivery of changes, enhancements and projects in conjunction with the Cyber Security teams.
  • Provide robust challenge to the First Line of Defence as they identify, assess, manage and report their risks and issues through various tools and activities including risk and control assessments, key indicators, issue and incident management, and control assurance.
  • Deep dive on the Technology and Cyber KPI/KRI's monitoring monthly trends and threats. Provide challenge on a SME level to the 1st line.
  • Perform Second Line of Defence activities in the evaluation of risks for new products, systems and material change projects.
  • Provide subject matter expertise, and monitor and communicate the risk environment to management, and other key stakeholders effectively.
  • When required, supervise junior members of the team in second line oversight, BAU activities and change initiatives.
  • Assist in the creation and maintenance of a good 3LoD model and work across the region to promote Technology and Cyber Awareness and 2nd line challenge.
Regulatory compliance, affairs and change
  • Comply with and ensure that all staff under your responsibility (where applicable) comply with the entities' policies and procedures as well as all rules, laws and regulatory requirements emanating from any of the regulatory authorities to which the entities are subject.
  • Remain up to date with regulatory changes; ensure that changes are well understood and plans are developed for implementation as appropriate.
Work Experience
  • Knowledge of banking and securities products and services.
  • Excellent knowledge and experience of Information Security, Technology and Cyber risk management and their application within the financial services industry.
  • Proven and demonstrable ability to understand, identify, analyse and communicate clearly an organisation's Technology and Cyber risks.
  • Proven experience in interpreting, understanding and applying legal/regulatory requirements to technology and cyber security.
  • Solid technical and functional knowledge of external regulations, policies and developments for Information Security and Cyber Risk and ability to read across to understand organizational impact.
  • Solid technical and functional knowledge of financial services internal rules and policies.
  • Good understanding of the overall operational processes and technology challenges within the financial services industry.
  • Ability to facilitate smooth communications between London, HO and EMEA offices.
Skills And Experience

Functional / Technical Knowledge and Awareness:

  • Cyber and Information Security best practice (including industry frameworks such as NIST and ISO 27001/2)
  • Cyber Security Risk Assessment and Risk management experience with a focus on;
  • Threat Modelling
  • Vulnerability Risk
  • Cloud Security Risk
  • IAM Risk
  • Network and System Risk
  • Third Party Risk
  • Knowledge of Cyber Incident detection, response and remediation best practice
  • Understanding of Governance, compliance and audit approaches
  • Knowledge of data analysis methods for risk modelling would be advantageous
Education / Qualifications
  • Educated to degree level or equivalent industry experience
  • CISSP, CISM, or equivalent Information Security certifications are desirable
Personal Requirements
  • Strong team player with the ability to collaborate with business stakeholders.
  • Clear and concise written and oral communication.
  • Ability to translate technical requirements for a general audience
  • Strong analytical skills to evaluate risk, understand and communicate underlying causes
  • Excellent accuracy and attention to detail.
  • Good time management and ability to prioritise.
  • Strong problem-solving and critical thinking skills.
  • Excellent Microsoft Office skills
  • Japanese language ability advantageous
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Technology Risk Oversight VP

Cyber Security training courses

Greater London
Hybrid
GBP 80,000 - 100,000
Full time
30+ days ago
Associate Director, Cyber Advisory

Dubizzle Limited

Greater London
Hybrid
GBP 80,000 - 100,000
Full time
30+ days ago
Senior Consultant, Cyber Advisory

Dubizzle Limited

Greater London
Hybrid
GBP 100,000 - 125,000
Full time
30+ days ago
Risk Manager - Technology 2LOD

Cyber Security training courses

Greater London
Hybrid
GBP 60,000 - 80,000
Full time
30+ days ago
Senior Cyber Risk Oversight VP - 2LoD Tech

Cyber Security training courses

Greater London
Hybrid
GBP 90,000 - 120,000
Full time
30+ days ago
Cyber IT Audit Manager VP

Cyber Security training courses

Greater London
On-site
GBP 100,000 - 125,000
Full time
30+ days ago
Vice President, Business Information Security Officer

MUFG Bank, Ltd

City of London
On-site
GBP 70,000 - 90,000
Full time
30+ days ago
IT Risk Manager

Orbis Investment Management Limited

City of London
On-site
GBP 80,000 - 100,000
Full time
30+ days ago
Information Security Architect - Circa £120K - Permanent

Cyber Security training courses

Greater London
Remote
GBP 100,000 - 120,000
Full time
30+ days ago
Director LCH Ltd Technology Risk & Controls

London Stock Exchange Group

Greater London
On-site
GBP 90,000 - 130,000
Full time
30+ days ago