Information Security Officer
Job description
About the role
The acts as the trusted strategic advisor to the Executive Team and Board on information security, risk, and compliance matters. You will own the independent assurance of the bank's control environment, ensuring that robust and proportionate policies and standards are aligned with the institution's growth ambitions. This role requires collaboration with the Chief Risk Officer and Data Protection Officer to oversee the integrity of risk management and data protection frameworks. You will work closely with first line functions including IT, operational resilience, and data management to challenge and improve security practices. The position is pivotal in increasing security awareness, skills, and understanding across the entire bank. You will provide clear, transparent reporting on the institution's risk posture to senior leadership and governance bodies. This role demands a critical mindset that questions assumptions and drives continuous improvement in security outcomes. You will own key projects and transformational initiatives that shape the future of information security within the organisation.
Key facts
What you'll do
Provide independent assurance to the Executive Team and Board on the effectiveness of the information security control environment.
Collaborate with the Chief Risk Officer and Data Protection Officer to ensure robust and proportionate policies, standards, and frameworks are implemented.
Work with first line colleagues responsible for information security, IT, operational resilience, and data management to identify and mitigate risks.
Increase information security awareness, skills, and understanding across the bank through targeted communication and engagement activities.
Support the delivery of projects and transformational change initiatives that enhance the security and resilience of the organisation.
Challenge existing practices and act as a critical friend to improve security standards and control efficacy.
Maintain transparent communication with senior leadership regarding the bank's risk posture and emerging security issues.
Own the monitoring and review of security controls to ensure they remain fit for purpose in a evolving threat landscape.
Partner with regulatory stakeholders to ensure compliance with relevant frameworks and regulatory expectations.
Drive the continuous improvement of information security processes, policies, and technologies across the bank.
Provide subject matter expertise on information security trends, risks, and best practices to influence strategic decision-making.
Support the management, storage, and use of data to ensure appropriate security measures are embedded throughout the data lifecycle.
Requirements
You must hold a relevant degree or possess equivalent practical experience in information security, risk management, or a related field.
You must demonstrate a strong understanding of information security frameworks, standards, and regulatory requirements relevant to the financial services sector.
You must have experience in developing, implementing, and monitoring information security policies and control frameworks.
You must possess excellent analytical and problem-solving skills to assess complex risk scenarios and recommend appropriate controls.
You must have strong communication and influencing skills to engage effectively with senior leadership and technical teams.
You must be able to work independently and as part of a collaborative team in a fast-paced banking environment.
You must have a proven track record of managing and prioritising multiple projects and competing priorities in a dynamic setting.
You must be committed to maintaining high standards of integrity, confidentiality, and professionalism in all aspects of the role.
Nice to have
Experience in a regulated financial services environment.
Knowledge of relevant UK financial regulatory expectations and standards.
Experience with information security frameworks such as ISO 27001, NIST, or PCI DSS.
Understanding of data protection principles and data privacy regulations.
Experience in delivering security awareness training and fostering a strong security culture.
Familiarity with operational resilience frameworks and testing methodologies.
Practical notes
This is a full time role based in London.
The role may involve occasional travel within the UK.
Candidates must be eligible to work in the United Kingdom without the need for sponsorship.
Applications will be reviewed on a rolling basis until the position is filled.