
Security Risk and Assurance Specialist VP
- London
- Contract
- Full-time
- Maintain and enhance the Security due diligence assurance process in line with EU and UK regulatory expectations
- Deliver a full due diligence assurance on all in scope applications, systems and technologies in support of ECB compliance.
- Define and embed key metrics required for information and cyber security continuous controls management and reporting; driving and tracking mitigations; facilitating periodic review to reflect changing cyber threat landscape and confirm the adequacy of risk and key controls
- Implement risk appetite methodology for EU reporting process, including but not limited to templates, heat maps and dashboard to continually inform on risk appetite position
- Maintain and enhance the EMEA Information Security Risk and Assurance documentation, policy, standard, frameworks, processes and procedures.
- Consistently look for improvements in the efficiency and effectiveness of Information and Cyber Security risk and due diligence assurance reporting
- Risk management techniques such as risk identification, risk evaluation, control mapping and mitigation tracking
- Performance management techniques including developing and maintaining KRIS, KCIs, KPIs and appropriate tolerances
- Security due diligence assurance framework definition, implementation, assessments and reporting
- Stakeholder management, including working with diverse teams in EMEA, North America, Ireland and Japan
- Information and Cyber Risk Frameworks and Standards (e.g., NIST / ISO27001) as well as Regulatory frameworks (e.g., Bank of England FCA/PRA, EU).
- Experience of EMEA Regulations and standards such as DORA/ECB regulatory requirements is required