Information Security Governance Risk and
il y a 4 jours
**Information Security Governance Risk & Compliance,**
***Analyst (EMEA)**
**Who we’re looking for**
**About Schroders**
We’re a global investment manager. We help institutions, intermediaries and individuals around the world invest money to meet their goals, fulfil their ambitions, and prepare for the future.
We have around 6,000 people on six continents. And we’ve been around for over 200 years, but keep adapting as society and technology changes. What doesn’t change is our commitment to helping our clients, and society, prosper.
**The team**
***At Schroders, our IT is not just focused on technology; it's about leveraging cutting-edge technology to solve problems, support the business, and deliver high-quality solutions. We foster a culture of innovation and strive for excellence in everything we do. Our IT function operates globally but is managed locally, allowing us to develop and implement systems and processes across our international offices.
Within Schroders, the Global Information Security function plays a crucial role in ensuring the safe operation of our business in a constantly evolving threat and technological landscape. The function consists of dedicated teams responsible for Cyber Security and Operations, Threat Intelligence, Governance Risk and Compliance, Technology Risk, as well as the Information Security Change Programme. These teams work together to effectively manage the risks to our information assets and enable our business to operate securely.
**What you’ll do**
- Work with the Information Security team to understand and assess effectiveness of controls. Identify and risk rate gaps for treatment
- Translate technical elements and cyber risk into language that the Business can absorb and understand
- Lead the Risk Control Assessment, interview owners, assess levels of risk - Liaise with business and key stakeholders to perform assessments and identify risk
- Perform supply chain due diligence and facilitate the management of findings and communicate issues to stakeholders
- Oversee reporting and MI on progress of risk deduction and remediation - Respond to client security questionnaires, RFP/RFI's, and audit requests
- Where needed, embed local requirements into global processes. Document/Design workflows of various activities to support the Information Security team
- Interpret and perform gap analysis against cyber and data privacy regulations
**The knowledge, experience and qualifications you need**
- Stakeholder engagement is key, forming collaborative working relationships across Information Security and the wider Global Technology teams
- Sound understanding of risk and in particular cyber threats that pose concern to our organisation as well as an appreciation of the regulatory landscape
- Understanding of risks of Cloud Technologies (IaaS, PaaS) and outsourcing (Saas) as well MITRE attack frameworks
- Proven ability to analyse and manage remediation of risks or gaps through to resolution
- Familiar with EU financial regulation, NIST Cybersecurity Framework or ISO27001
- Willingness to learn and develop Governance, Risk and Compliance skillsets
- Continuous improvement mind-set, challenges the status quo and seeks self-improvement
- Strong verbal and written communications skills to effectively communicate security risks, compliance requirements, and recommendations to stakeholders
- Strong organizational skills to manage and prioritize multiple tasks, projects, and deadlines effectively
- Fluent in English
**The knowledge, experience and qualifications that will help**
- Financial Industry background is a plus
- An information security qualification is beneficial (e.g. CISM, CSSP, )
**What you’ll be like**
- Analytical and detail-oriented
- Critical thinker
- Ethical
- Continuous learner
- Collaborative
**We recognise potential, whoever you are**
Our purpose is to provide excellent investment performance to clients through active management. Diversity of thought facilitated by an inclusive culture will allow us to make better decisions and better achieve our purpose. This is why inclusion and diversity are a strategic priority for us and why we are an equal opportunities employer: you are welcome here regardless of your age, disability, gender identity, religious beliefs, sexual orientation, socio-economic background or any other protected characteristics
-
Information Security Governance Consultant
il y a 1 semaine
Luxembourg Excellium Services Temps pleinYou wish to join Excellium because You’re passionate, keen to learn & a fun coworker! As part of a dynamic and passionate team, you will have the opportunity to fully invest yourself, to innovate and to create in the fields of expertise we deal with. Listening is one of our key values, which helps everyone feel integrated within Excellium family....
-
Information Security Governance Consultant
il y a 2 semaines
Luxembourg SIRCONSULTING RH Temps pleinWe are looking for our future Information Security Governance Consultant to complete our team. Your missions are defined as follows: - Assist our clients in the implementation of their strategy - Identify the security projects - Assess the maturity of controls - Manage Information Security and its risks Required profile: - Master's degree - SCADA...
-
Information Security Risk
il y a 3 jours
Luxembourg Luxfactory Temps pleinLocation: Luxembourg | Contract: Permanent Key Responsibilities - Develop, maintain, and manage documentation related to the Information Security Management System (ISMS) - Harmonize and regularly update security policies and procedures to ensure organizational consistency and regulatory compliance - Participate in the risk management framework by...
-
Senior Information Security
il y a 2 semaines
Luxembourg Luxfactory Temps pleinWe are currently looking for a highly experienced **Information Security & Risk Management Consultant** for a strategic assignment. **Location**: Luxembourg (on-site at client premises, with possible remote flexibility) The consultant will take the lead in designing, developing, and implementing a **comprehensive IT Risk 3D Matrix** tailored to the...
-
Information Security Manager
il y a 4 jours
Luxembourg Next Gate Tech Temps plein**What You Will Do**: In this role, you will be responsible for developing and implementing our organization's information security strategy, as well as ensuring compliance with relevant laws, regulations, and industry standards. You will work closely with stakeholders across the organization to identify and mitigate security risks, and be responsible for...
-
Chief Information Security Officer
il y a 1 semaine
Luxembourg, Luxembourg Julius Baer Temps pleinAt Julius Baer, we celebrate and value the individual qualities you bring, enabling you to be impactful, to be entrepreneurial, to be empowered, and to create value beyond wealth. Let's shape the future of wealth management together. The CISO Europe Hub is a senior leadership role responsible for defining and executing the regional Information & Cyber...
-
Information Security Officer
il y a 6 jours
Luxembourg, Luxembourg Luxair Temps pleinFor our department IT Security within General Services, we are looking for a (an):Information Security Officer (m/f/x)Description:As Information Security Officer you will activelycontribute to maintaining and strengthening Luxair group's information securityposture.Drivenby a strong interest in cybersecurity, you will actively support the Head of...
-
Information Security Officer
il y a 1 semaine
Luxembourg Findel Airport ING Temps pleinInformation Security Officer In order to strengthen the delivery organisation, ING Luxembourg is looking for an Information Security Officer on a temporary contract bases. Job description: Your mission will be to reinforce a team of Security Officers in order to maintain the bank within its IT risk appetite and participate in the implementation of the DORA...
-
Information Security Consultant
il y a 1 semaine
Luxembourg, Luxembourg Forvis Mazars Temps pleinOperating as an internationally integrated partnership in over 100 countries and territories, Forvis Mazars Group specialises in audit, tax and advisory services. The partnership draws on the expertise and cultural understanding of over 40,000 professionals across the globe to assist clients of all sizes at every stage in their development.As a ICT risk and...
-
Information Security Consultant
il y a 1 semaine
Luxembourg Lux-Advisory Temps plein**Mission** In support of the Risk Management team, the Consultant will provide the following services: - Establish risk guidelines for the information security strategy - Establish guidelines for the design of the information security controls - Align the risk appetite for security incidents and vulnerability management with the IT Security function -...