You will implement cybersecurity strategy, controls, and risk management practices. You will lead assurance and certification activities, operate security controls, manage vulnerabilities and incidents, assess third-party risk, and embed security throughout product development, cloud infrastructure, APIs, containerisation, and blockchain technologies.
Responsibilities
- Implement cybersecurity strategy, roadmap, policies, and security control frameworks
- Conduct security risk assessments and drive remediation actions
- Lead security assurance and certification programmes, including SOC 2 and ISO 27001
- Maintain security risk, control, and reporting records
- Conduct third-party security assessments and client security due diligence
- Deliver cybersecurity awareness and training
- Operate security controls across cloud infrastructure, endpoints, networks, and identity and access management
- Manage vulnerability assessments, penetration testing, remediation, and security-event investigations
- Maintain and test incident response procedures and coordinate incident investigations and reviews
- Guide secure configurations, patching, endpoint security, and access controls
- Embed security in product design, development, testing, and deployment
- Drive Secure SDLC, DevSecOps, and security-by-design practices
- Assess and remediate security risks across applications, cloud infrastructure, APIs, containerisation, and blockchain
Requirements
- Degree in information technology, computer science, engineering, cybersecurity, or a related discipline
- CISSP, CISM, CISA, or CCSP certification is preferred
- 7–10 years of information security or cybersecurity experience
- Experience in financial services, fintech, or a highly regulated environment is preferred
- Experience in cloud and application security, Secure SDLC, vulnerability management, identity and access management, security monitoring, and incident response
- Knowledge of ISO 27001, SOC 2, and NIST
- Experience supporting security audits, certifications, and regulatory requirements
- Stakeholder management and communication skills
- Experience in blockchain, digital assets, or distributed ledger technology is an advantage