Head of Information Security - London, United Kingdom - First Achieve Ltd

Tom O´Connor

Posted by:

Tom O´Connor

beBee Recruiter


Description
Head of Information Security


A growing fintech with a innovative B2B Cloud platform offering fintech as a service to Asset Managers, Wealth managers, Bank & Building societies and Fintechs are in the process of evolving their platform to offering services which will disrupt the wayfinancial services are offered in the market place are seeking a Head of Information security to ensure their platform continues to meet the forever changing compliance and regulation within finance market space.


Responsibilities:


  • Maintaining and developing policies and procedures, consulting with engineering teams on security principles.
  • Responding to customer audit requirements
  • Performing internal audits and assisting with external audits.
  • You'll also be involved in security assurance of software and vendors, investigating escalated alerts from the SIEM.
  • Coordination of pentests (internal and external) and vulnerability remediation from findings
  • Managing and implementing security tools such as DLP and IPS
  • Management of information security risks across the organisation.

Requirements:


  • Working knowledge of security frameworks and security controls e.g. NIST CSF, ISO22301, IS027001, ISAE3000/SOC2, GDPR and PCI DSS.
  • Experience developing, writing, implementing, auditing and improving information security policies and procedures aligned to relevant industry frameworks/standards to ensure that security and compliance accreditations are achieved and maintained.
  • Perform periodic internal audits, reviews and contribute to the continuous improvement of IT security standards, processes and procedures.
  • Ability to perform Business Impact Analysis, risk assessment and treatment.
  • Experience operating, maintaining, auditing and improving Vulnerability Management, SIEM and Threat Intelligence systems.
  • An extensive career in the security space, including GRC expertise and technical threat/vulnerability management experience.
  • Relevant certifications (CISSP etc.)

More jobs from First Achieve Ltd