Company

Barclay SimpsonSee more

addressAddressLondon, Greater London
type Form of workContract
salary SalaryCompetitive
CategoryIT

Job description

Information Security, Agile Security and Risk Management Specialist required for global financial services firm. The role will be to augment the Information Security team to perform risk assessments of projects, provide guidance and acquire outcomes/decisions from the scrum master, enterprise architect, technical architect, solutions architect, data privacy officer, portfolio management office, strategic change development, IT Infrastructure and Operations and penetration testers.
About the role
The specialist will work under the responsibility of the Head of IS Services and Risk Management and will report to the Secure Project Lifecycle Team Lead. The responsibilities of the role will include the following:
  • Review submission of IS Criticality Assessment (ISCA) questionnaire
  • Determine high-level security requirements and project criticality, based on standard project activities and data classification from DP pre-screening
  • Work with assigned architect to ensure security requirements are finalized in design (High-Level Design), review with Enterprise Architecture, Solutions Architecture, Cyber Security and Cyber Assurance
  • Review of all security requirements and evidence provided by the scrum master to support closure of each requirement:
    • Review and feedback on ISCA questionnaire
    • Review and feedback on High-Level Design (HLD)
    • Present at ISCA Project Technical Review
    • Attend and obtain HLD sign-off at Technical Design Authority, Solutions Design Authority (SDA)
    • Obtain Business Partner Risk Evaluation Platform (BPREP) scorecard for 3 rd Party SaaS solutions from Security Contracts team
    • Obtain Identity & Access Management (IAM) assessment signoff from IAM Team.
    • Obtain Minimum Technical Security Baseline compliance reporting from QualysGuard
    • Obtain Cloud Permit from Enterprise Architecture
    • Obtain Code Review and Analysis - in-house solutions only.
    • Self-serve vulnerability assessment compliance report of assets in scope
    • Liaise with Cyber Assurance on penetration testing of solution and obtain sign-off
    • Obtain Digital Hub registration for external facing solutions from Cyber Assurance
    • Produce ASRM Security Assessment closure report
  • Perform a final review of all open security requirements and their status before any stage gate approval can be provided (effectively the Production Go/No-go decision). Ensure the firm ASRM processes are followed
  • Store all evidence in IS project's shared area
  • Update the project register daily to ensure project status is maintained and update the ASRM Security Assessment template as a record of activity. Submit ASRM form for sign off to complete the risk assessment
  • Manage project RAG status ensuring activities trending amber and red are highlighted to management and the scrum master
  • Liaise with the scrum master to support the development of the risk acceptance (PM is responsible) where needed
  • Attend meetings with the scrum master, delivery squads, stakeholders, ISCA technical review, architectural design authorities and pen testing reviews. Challenge design decisions not compliant with security, escalate issues when they become known, and offer options to resolve
All deliverables are subject to internal quality assurance and peer reviews will be conducted by the Information Security team
As an ideal candidate, you will have an industry certification such as CISSP/CISM/CRISC and have expert knowledge of project-based Information Security. You will also have a proven track record of delivery in a similar role. Experience in financial services is highly advantageous.
Refer code: 2691394. Barclay Simpson - The previous day - 2024-02-03 06:29

Barclay Simpson

London, Greater London
Popular Information Security Specialist jobs in top cities
Jobs feed

Theatre Nurse / ODP

Appoint Healthcare

Harpenden, Hertfordshire

£27,500 - £35,000/annum EXCELLENT BENEFITS

Orthopaedic Scrub Practitioner

Meridian Business Support

Cambridge, Scottish Borders

£27,000 - £38,000/annum

BMS Band 6 - Haematology and Blood Transfusion

Synlab

Basildon, Essex

£35,392 - £42,618/annum

Immunisation Nurse

Gel Resourcing Ltd

Henley-on-Thames, Oxfordshire

£32 - £34/hour

Senior OHA / OHA

Gel Resourcing Ltd

Kingston upon Hull, East Riding of Yorkshire

£45,000 - £49,000/annum Competitive additional benefits

Nurse Assessor

Gaia Recruitment Ltd

Wandsworth, Greater London

£43,875/annum

Disability Assessor Nurse

Stonebranch Healthcare

Reading, Berkshire

£42,000 - £50,400/annum excellent benefits

Early Years SEN Teacher

Prospero Teaching

London, England

£180 - £250/day paid to scale

Locum Educational Psychologist

Nonstop Consulting

East of England

£500 - £550/day

Head Veterinary Nurse

Health Recruit Network

Kettering, Northamptonshire

£35,000 - £39,000/annum

Share jobs with friends

Information Assurance Specialist

City, University Of London

£49,794 to £59,421 per annum

London, Greater London

2 weeks ago - seen

Security Specialist, Information & Analysis

International Sos

London, England

a month ago - seen

Information Security Governance, Risk and Compliance Specialist

Sportradar

London, Greater London

2 months ago - seen

Information Security Assurance Specialist

Copper.co

London, England

2 months ago - seen

Information Security Policy & Governance Specialist

Zego

London, Greater London

2 months ago - seen

Information Security Specialist

Limbic

London, Greater London

3 months ago - seen

Senior Information Security Compliance Specialist - Sovereign Cloud

SAP

London, Greater London

4 months ago - seen