About the Role
This role is responsible for leading the development, implementation, and monitoring of information security policies and controls across the organization to safeguard critical assets and maintain regulatory compliance.
Responsibilities
- Lead the creation and enforcement of enterprise-wide information security policies
- Oversee risk assessments and vulnerability management programs
- Manage incident response planning and execution during security events
- Ensure compliance with relevant data protection regulations and standards
- Collaborate with IT and development teams to integrate security into system design
- Conduct regular security audits and control evaluations
- Monitor threat intelligence and adapt defenses accordingly
- Support third-party risk assessments and vendor security reviews
- Lead security awareness training initiatives for employees
- Maintain documentation for security frameworks and control implementations
- Evaluate and recommend security tools and technologies
- Drive continuous improvement of security posture through metrics and reporting
- Serve as a point of contact for security-related inquiries
- Support certification efforts for standards such as ISO 27001 or SOC 2
- Ensure secure configuration of network and cloud infrastructure
- Assist in secure software development lifecycle integration
- Manage access control policies and identity security practices
- Oversee encryption and data protection strategies
- Coordinate with legal and compliance teams on regulatory requirements
- Support forensic investigations when security breaches occur
- Promote a culture of security across departments
- Evaluate emerging threats and adjust security strategies
- Ensure business continuity and disaster recovery plans include security components
- Report security status and risks to senior management
- Maintain up-to-date knowledge of cybersecurity trends and best practices
Compensation
Competitive salary based on experience and qualifications
Work Arrangement
Hybrid work model with flexible scheduling options
Team
Part of the central security team reporting to the Chief Information Security Officer
Why Join Us
- Opportunity to shape the security strategy of a growing financial services organization
- Supportive environment that values innovation and professional development
Technology Stack
- Cloud platforms: AWS and Azure
- Security tools: Splunk, CrowdStrike, Okta, Qualys, and Hashicorp Vault
Available for qualified candidates requiring sponsorship