Job Search and Career Advice Platform

Enable job alerts via email!

Information Security Governance, Risk, and Compliance (GRC) Specialist

Janus Henderson AAA CLO ETF

London

On-site

GBP 50,000 - 70,000

Full time

30+ days ago

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading financial services company in London is seeking an experienced Information Security Governance, Risk, and Compliance (GRC) Specialist to join their team. You will be responsible for developing cybersecurity policies, conducting risk assessments, and ensuring compliance with industry regulations. The ideal candidate will have a Bachelor's degree in Information Technology or Cybersecurity, strong experience in information security, and relevant certifications. This position offers a dynamic environment where you can contribute to enhancing cybersecurity practices.

Qualifications

  • 3 to 5 years of professional experience in information security.
  • Certification such as Certified Information Systems Security Professional (CISSP) strongly preferred.
  • Experience with financial service regulations.

Responsibilities

  • Develop and maintain cybersecurity policies and procedures.
  • Conduct regular risk assessments to identify vulnerabilities.
  • Support and enhance cybersecurity awareness training programs.

Skills

Cybersecurity principles
Compliance management
Risk assessment
Network security principles
Cloud security best practices
IAM principles

Education

Bachelor’s Degree in Information Technology or Cybersecurity

Tools

Firewall
Single Sign-On (SSO)
Multi-Factor Authentication (MFA)
Job description
Information Security Governance, Risk, and Compliance (GRC) Specialist

City: London

Division: Information Security

We are seeking an experienced Information Security Governance, Risk, and Compliance (GRC) Specialist to join our team.

Our Mission at Janus Henderson is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service.

Our Values are key to driving our success, and are at the heart of everything we do: Clients Come First - Always | Execution Supersedes Intention | Together We Win | Diversity Improves Results | Truth Builds Trust

Responsibilities
  • Develop and maintain comprehensive cybersecurity policies and procedures.
  • Ensure these policies align with industry standards and regulatory requirements.
  • Assist in the integration of security practices and control across various technical and non-technical departments, enhancing workflow and operational processes.
  • Conduct regular risk assessments to help identify vulnerabilities and threats.
  • Collaborate and oversee the implementation of risk mitigation strategies.
  • Monitor emerging threats and evolving technologies to continuously refine risk assessment protocols.
  • Ability to design and evaluate control metrics for assessing the effectiveness of cybersecurity measures.
  • Collaborate with Enterprise risk management to embed cyber risk into broader risk registers and board-level reporting.
Compliance Management
  • Monitor and ensure compliance with internal policies, industry standards, and regulatory requirements.
  • Engage with required stakeholders in Technology, Legal, Compliance and Internal Audit as required.
  • Compile and deliver detailed compliance reports to senior management.
  • Monitor upcoming regulations and prepare compliance roadmaps.
Training and Awareness
  • Support and enhance engaging cybersecurity awareness training programs.
  • Foster a company-wide culture of cybersecurity awareness.
  • Keep current with the latest cybersecurity trends and best practices to inform training content and security measures.
  • Train and guide wider Tech team members on best practices in cybersecurity risk management.
  • Actively participate in the response to security incidents.
  • Support post-incident evaluations and reporting.
  • Collaborate with relevant stakeholders to devise and enforce corrective measures aimed at bolstering defences against future incidents.
Requirements
  • Bachelor’s Degree in Information Technology, Cybersecurity, or a related field; equivalent work experience also considered.
  • 3 to 5 years of professional experience in information security.
  • Certification such as Certified Information Systems Security Professional (CISSP) strongly preferred.
  • Deep understanding of cybersecurity principles, frameworks (such as NIST, ISO/IEC 27001), and compliance standards.
  • Experience with financial service regulations and regulations such as FCA, SEC, MAS, DORA.
  • Proficient knowledge of network security principles and controls such as Firewalls, IPS/IPD, TCP/IP, DHCP, and DNS.
  • Extensive experience in securing Operating Systems such as Windows, UNIX/Linux and Mac systems.
  • Knowledge of cloud service models (IaaS, PaaS, SaaS) and deployment models (public, private, hybrid, community) and experience in implementing and managing cloud security best practices.
  • In-depth knowledge of IAM principles and technologies to manage digital identities and control user access and experience with Single Sign-On (SSO), Multi-Factor Authentication (MFA), and role-based access control (RBAC) systems to enhance security and operational efficiency.
  • Understanding of Secure DevOps / CI/CD pipeline governance.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.