
IT Security Engineering Manager
- London
- Permanent
- Full-time
- This role may require work out of hours
- Align Teams' objectives to OKRs
- Be the escalation point for security Tooling issues and critical security breaches
- Responsible for team development, upskilling & mentoring
- Responsible for vendor/MSSP relationships for the group-wide organization
- Provide oversight, guidance and leadership of the IT Security Engineering Team
- Drive improvements and feature enhancement to ensure ROI
- Own the management reporting and provided monthly Executive level reporting
- Drive process/procedure changes accordingly
- Ensure quality of ticketing & runbook maintenance
- Cultivate and maintain strong vendor relationships
- Have an attitude of continuous improvement
- Be accountable/responsible for security tool health throughout the estate
- Manage the governance initiative for security tooling
- Engage with vendors to introduce formal QBRs, tool reviews, feature enhancements and adoption
- Create and own the overarching security tooling strategy
- Regular tool reviews
- Documented process for a formalized approach to security tool selection
- Participate in CAB, Tool review or Architecture Review Boards (ARBs)
- Stay current with the latest security news, threats, intelligence, tactics, techniques, and vulnerabilities. Research and analyze new threats and vulnerabilities to determine exposure.
- Assist and/or lead efforts to isolate, contain, respond to, and recover from security incidents
- Identify, review, prioritize, plan, coordinate, and follow-up on the remediation of vulnerabilities
- Configure, customize, tune, manage, troubleshoot, and maintain effective and efficient operation of security technologies, such as SIEM, endpoint security, secure web gateway, CASB, DLP, email security, intrusion detection/prevention systems, etc. This may also include scripting, automation, and orchestration across various platforms
- Define, document, and follow approved processes for all the responsibilities included in this job description. Create and maintain documentation for systems, including design and operation
- Review systems, configurations, and processes to ensure and report on compliance with ION policy, client requirements, audit controls, regulations, and industry best practices. Provide best practice security recommendations to IT and other teams within ION, based on review results
- Respond to information security-related inquiries and requests
- Degree/diploma/certifications in a technology-related field and/or relevant working experience; highly desired certifications include:
- Security+, CCSP, CEH, GCIH, GMON, CASP, or CISSP
- 10+ years' experience in information security with at least 3-5 years in a Security Engineering role
- Fundamental understanding of programming/scripting
- The following general characteristics are required:
- A team player with the ability to work independently and unsupervised
- Ability to own delegated tasks and see them through to completion
- Ability to manage time and prioritize work to maximize productivity
- Excellent communication skills (both written and verbal)
- Exceptional attention to detail and quality
- Excellent problem-solving techniques and trouble analysis skills
- The candidate should have a good knowledge of:
- Endpoint security concepts, controls, and best practices for workstations (e.g. Windows and Mac) and server (e.g. Windows and Linux) operating systems
- SIEM technology to monitor, analyze, and respond to security events. To develop and implement security policies, managing SIEM systems, and investigating incidents.
- General IT networking concepts, protocols, standards and network security concepts, controls, and best practices
- Cryptography fundamentals and data security controls and best practices
- Forensic investigation techniques
- Security standards/best practices and frameworks
- Over 2,000 of the world's leading corporations, including 50% of the Fortune 500 and 30% of the world's central banks, trust ION solutions to manage their cash, in-house banking, commodity supply chain, trading and risk.
- Over 800 of the world's leading banks and broker-dealers use our electronic trading platforms to operate the world's financial market infrastructure.