Jobs
>
London

    Information Security Risk - London, United Kingdom - Genius Sports Group

    Default job background
    Description

    Security Risk & Compliance Principal

    A bit about us

    Do you want to join one of the world's fastest growing sports technology companies?

    Genius Sports is at the epicentre of the global network connecting sports, brands and fans through official live data. Our mission is simple. We champion a more sustainable sports data ecosystem that benefits all parties.

    We're looking for enthusiastic and ambitious people to join our talented team.

    If you see yourself becoming part of a global family building the future of sports entertainment together, then come and grow with us.

    We put trust in our people to deliver the difference for our clients around the world . It's why many of the world's largest leagues & federations such as the NFL, English Premier League, FIBA and NCAA choose to work with Genius Sports.

    THE ROLE

    We are accelerating our security journey, aiming to deliver the most trusted sports technology and data on the market, elevating security as a competitive differentiator. Our Security vision is to win customers, partners and fans based on trust in our ability to always protect their data. We strive to achieve this through our mission to always embed Security into the way we act and the products we deliver.

    Are you ready to play defence? We are seeking a n experience Security Risk & Compliance Principal who can take the lead in ensuring we meet our security compliance , and

    This is a great opportunity to join our team at a fantastic time of growth and truly make an impact.

    The successful candidate will be an engaging, self-starter who is able to operate with high levels of autonomy and strives for continuous improvement. The candidate should have a track record of leading in the Security GRC domain within highly technology driven environments. They will feel comfortable holding others accountable to compliance and risk management responsibilities and be confident in challenging when needed. The ability to influence cross-functionally and at a senior level and galvanise others behind the importance of risk and compliance will be critical in this role.

    The Role

    Compliance O versight

    • Ensure compliance with the Security aspects of applicable laws, regulations, and industry standards including ISO 27001, SOX, PCI DSS, Data Protection.
    • Maintain and continuously improve our ISO 27001 Information Security Management System, ensuring it is effective and well embedded across the business.
    • Lead all internal and external auditing activities, including facilitating audits and delivering your own audits .
    • Develop and maintain pragmatic and relevant s ecurity policies and procedures .

    Security R isk and Control Management

    • Develop, implement, and maintain comprehensive security risk management processes to ensure security risks are effectively identified, assessed and managed.
    • Identify, evaluate, monitor and drive accountability for security risk mitigation and control compliance across all the business .
    • Collaborate closely with our Risk team to ensure a lignment to our Enterprise Risk Management framewor k and requirements.
    • M onitor and analyse emerging threats and trends to proactively identify and adjust security risks and appropriate controls.

    Third Party Security

    • Mature our third-party security risk management capabilities, ensuring third-parties are adequately assessed and adhere to our standards.
    • Propose and ensure deployments of security measures to minimise third party risk .
    • Ensure the satisfactory completion of due diligence requests from third parties including customers and partners.
    • Collaborate with our Privacy and Legal teams to negotiate security terms in vendor and customer contracts, ensuring they protect the needs of the business.

    Other

    • Contribute to the successful execution of the Security s trategy , own ing the delivery of risk and compliance aspects .
    • Drive continuous improvement to streamline and mature our processes, working cross-functionally with key stakeholders .
    • Communicate security, risk, and compliance initiatives, and outcomes to senior leadership, the broader organi s ation and external stakeholder s.
    • Develop and provide frequent reports on our security risk and compliance profile to key stakeholders.

    REQUIRED SKILLS & EXPERIENCE

    Who you are:

    • A n experienced, self-starter who strives for continuous improvement, bringing solutions to the table and taking ownership for delivery.
    • Able to operate with high levels of autonomy and build or adapt processes, rather than rely on pre-existing ones.
    • Able to hold others accountable to their responsibilities and influence through encouragement and convey ing the value of risk and compliance .
    • Views security as an enabler, promoting a positive mindset around security , but able to be firm when needed.
    • Empathetic to competing priorities, able to disagree and commit, and remain resilient.
    • Technology minded without needing to be a deep expert. An understanding of software development practices and cloud environments, able to understand and build credibility with highly technical teams (e.g. IT, Engineers, Product).
    • Able to develop and deliver reporting at an Exec level with the confidence to call out deficiencies in a constructive manner.

    What you'll bring:

    • Ex tensive ex perience overseeing risk and compliance activities, including leading the maintenance and improvement of ISO 27001 certified ISMS .
    • Deep understanding of risk management practices and experience driving risk culture.
    • E xpertise in applicable laws, regulations and standards including Data Protection Laws, SOX, ISO 27001, SOC 2 and NIST.
    • Relevant certifications in cybersecurity, GRC, or related areas is desirable (e.g., CIS M , CISSP, Lead Auditor ).
    • Experience in a technology and software engineering led organisation working with Agile methodologies is desirable .

    What's in it for you?

    As well as a competitive salary and annual leave allowance, our benefits include health insurance, skills training and much more, depending on the location. We also offer a host of softer benefits, including many social events throughout the year such as summer and winter holiday parties, monthly team building events, sports tournaments, charity days and wellbeing activities.

    How we work

    We have adapted a forward-thinking 'Ways of Working' framework, which sets out (amongst other things) the opportunities for Geniuses to work flexibly, remotely and on working holidays. It affects different teams and locations differently, so please ask for further information in how it would work with this role.

    Our employees are empowered to stretch the boundaries of what's achievable, always reaching further and pushing the edges to see what gives. We collaborate, we innovate, and we celebrate. We will continue to grow as an organisation and continue to invest in our highly talented and diverse team of Geniuses.

    Genius Sports Group is proud to be an equal opportunities employer. We recognize and celebrate the benefits that a diverse and inclusive workforce bring to our business, our customers and our staff. We welcome and will consider all applications regardless of age, different abilities or disability, gender re-assignment, marriage, pregnancy, maternity, race or nationality, religion or belief, sex and sexual orientation (and any other applicable status). Please let us know when you apply if you need any assistance during the recruiting process due to a disability.

    #J-18808-Ljbffr


  • Parliamentary Digital Service London, United Kingdom

    Employer 1 · - Parliamentary Digital Service · Directorate 1 · - Cyber Security · Band / Grade 1 · - B1 · Salary 1 · - £41,340 - £47,975 · Contract Type 1 · - Permanent · Location 1 · - Hybrid (on-site and remote) · Security Level 1 · - Security Check (SC) · Interview Format 1 · ...


  • HSBC London, United Kingdom

    Our Global Risk function, led by the Group Chief Risk Officer, oversees a comprehensive risk management framework that is applied throughout the Group. We focus on creating an environment that encourages our people to speak up and do the right thing. This responsibility includes ...


  • Experis LTD London, United Kingdom

    **Information Security Risk Manager** · **Location: City of London** · **Salary: £80,000** · An exciting opportunity for an **Information Security Risk Manager** to join one of our clients, who are a multinational reinsurance company and number one in their space You will be resp ...


  • Akkodis London, United Kingdom

    **Role**:Cyber Security Risk Manager · **Salary**:£55k to £72k (negotiable) · **Location**:Birmingham or London · Monday & Friday work from home - Tuesday, Wednesday & Thursday on site · **Benefits**:Disc Bonus, Private Healthcare, 30 days holidays, 8% Contributory Pension · **Re ...


  • McKinsey & Company London, United Kingdom

    **Who You'll Work With**: · - You'll work with and support our Client Services Teams in our UK offices. You will come from a public sector and/or defense background with experience in relevant areas such as Security Policy Framework (SPF), Government Functional Standard 007 (Secu ...


  • Citi London, United Kingdom

    **Responsibilities** · Reporting into the Head of Enterprise Technology and Cyber Risk (ETCR), the Enterprise Technology & Cyber Risk - Operations Lead will have oversight responsibility for a significant portfolio of the Enterprise Operations & Technology (EO&T) organization. Th ...


  • Bupa London, United Kingdom

    **Head of Information Security Risk** · **London / Manchester** · **Flexible / Hybrid working available** · **Permanent** · Here you'll be welcomed. We champion diversity and we understand the importance of our people representing the communities and customers we serve. You'll fi ...


  • Bank of China London, United Kingdom

    General Administration department strategy is to deliver excellent general administrative services to the whole bank covering different functions including project management, facilities, logistic and events, admin and central filing, systems, commercial property and security ope ...


  • UBS London, United Kingdom

    United Kingdom · - Information Technology (IT) · - Group Functions · **Job Reference #** · BR · **City** · - London · **Job Type** · - Full Time · **Your role** · - Do you have a strong technical background and experience working within the web and cloud security team? If so, we' ...


  • UBS London, United Kingdom

    United Kingdom · - Information Technology (IT) · - Group Functions · **Job Reference #** · BR · **City** · - London · **Job Type** · - Full Time · **Your role** · - Partnering both within CISO, Technology Services and with other stakeholders across the firm to ensure on-track rem ...


  • IAG GBS London, United Kingdom

    Full-time · - Directorate: IAG Tech · - Contract Type: Permanent · **Company Description**: · **About IAG Tech** · IAG Tech is a community of IT and digital professionals from across the International Airlines Group (IAG). We drive the technology behind some of the biggest and mo ...


  • Department for Business and Trade London, United Kingdom

    **Details**: · **Reference number**: · **Salary**: · - £25,661 - £32,500- £25,661 to £32,500 - London: £29,282 to £32,500/National: £25,661 - £28,617 (including allowance)- A Civil Service Pension with an average employer contribution of 27%**Job grade**: · - Executive Officer**C ...


  • UBS London, United Kingdom

    United Kingdom · - Information Technology (IT) · - Group Functions · **Job Reference #** · BR · **City** · - London · **Job Type** · - Full Time · **Your role** · - We're looking for Cyber & Information security professional to: · - perform risk assessments and control access to ...


  • NHS England London, United Kingdom

    To support the delivery of its duties and responsibilities, the NHS England Board established a Cyber Security and Risk Committee, as a sub-committee of the Audit and Risk Assurance Committee (ARAC), which forms a core part of NHSE's internal control and risk management system, p ...


  • eFinancialCareers London, United Kingdom

    **Organization Overview**: · Citi Markets Operations is currently at a pivotal point in its evolution and journey to implement a target operating model. We take pride and are passionate about our People and our culture. We are invested in our People and their development. We are ...

  • Meta

    Security Risk

    5 days ago


    Meta London, United Kingdom

    Meta's Integrity, Security, Support & Operations Global Risk and Compliance (ISSO GRC) serves as the primary hub for risk management and compliance across the company, providing support to Meta and its family of apps. Within ISSO GRC, the European Security Office (ESO) is specifi ...


  • Willis Towers Watson Reigate, United Kingdom

    Security Risk Assessor · - Reigate, GB · May 12, 2023 · We are looking for a Cyber Risk Assurer to support the Technology division of the Insurance Consultancy and Technology (ICT) business unit in managing cyber security risk, particularly in its expanding SaaS portfolio. You wi ...


  • Locke and McCloud Greater London, United Kingdom

    Job Description · Security Risk Manager – London hybrid - £60,000 - £80,000 + Benefits · Locke & McCloud are looking for an experienced Security Risk professional to join our clients growing Cyber Security function. Our client is looking for candidates who have a proven track re ...


  • Locke and McCloud Greater London, United Kingdom

    Security Risk Manager – London hybrid - £60,000 - £80,000 + Benefits · Locke & McCloud are looking for an experienced Security Risk professional to join our clients growing Cyber Security function. Our client is looking for candidates who have a proven track record in managing s ...


  • enteles Search London, United Kingdom

    Job Description · Job Description · This position is tailored for individuals at the early to mid-level of their career, ideally with 2 to 3 years of experience in security risk consulting. Candidates beyond this experience level may not be suitable for the role. · As a Risk Cons ...