Information Security Specialist – Project Rome
London
Applications have closed
R3
R3 is leading the digitization of financial services, enabling an open, trusted and enduring digital economy. Learn more about R3's Corda.Responsibilities
- Play a lead role within R3's new product squad specifying and implementing technical and organizational security controls required for world-class enterprise software and service delivery organization.
- Consult with R3 clients and partners to understand their security requirements. Lead client security and technology risk management reviews, compile responses for reviews, negotiate remedial activities with R3 internal teams, and manage such activities to completion.
- Provide security representation in technical design reviews, Lead risk and security assessment and threat modeling activities for processes and systems as required, and ensuring R3's products and services are secure by design.
- Work with the wider security team to prepare for and undergo external service auditor assessments of the security control environments which you help to develop
- Lead the development of an infosec framework for R3’s Managed Services offering based on validated data and proof points, using design thinking methods for iterative agile delivery.
- Stakeholder engagement. Act as the interface to the Infosec team for engaging stakeholders on inbound requirements.
- Consolidate uses cases into granular requirements that can be understood in a consistent framework and architecture. Work with the rest of the squad to create a framework that can be applied by partners to meet customer security objectives.
- Work with the Program Management team to establish a detailed delivery schedule for the security features of the new offering. Partner with the test team to ensure the solution meets the product specifications.
Qualifications
- First and foremost we want you to love what you do. You'll need to be a security evangelist within R3 and the community of Corda Network participants, both current and future.
- You will have at least five years of senior (preferably technical team lead) roles within a security organization in a blue-chip or high-growth technology organization.
- You'll have experience in multiple security domains. Those with deep, specialist skills in one or two domains only need not apply.
- Hands-on experience is essential. Whilst we're not expecting to hire a DevSecOps engineer or security researcher you will be expected to hold your own in a team that includes those skills. We expect the ability to execute, and the experience to be effective in a short period of time from all team members.
- You'll need excellent communication skills, both verbal and written. You must be capable of delivering concise, plain English descriptions of complex security concepts to senior R3 and client stakeholders. You should sufficient gravitas to influence small groups of senior management members or board-level members, but also have the energy to present to a conference hall.
- You will be capable of defining security requirements and implementing controls and metrics for complex, long-term projects involving substantial multi-disciplinary teams.
- You must have worked within an organization that carried industry recognized credentials such as ISO 27001 certification or SOC 2 reports. You will have played a lead role in gaining those credentials.
- Financial services experience would be ideal, but experience in other areas such as telecoms or other critical infrastructure may also be a good fit.
- You must be able to display extensive experience in working in both cloud and on-premises deployments. Microsoft Azure is our platform of choice, but AWS or GCP skills are transferable. Containerisation and container orchestration security skills would be a big plus.
PREFERRED QUALIFICATIONS
- Relevant professional qualifications would be great. We have ISACA and ISC2 members in the team already and so obviously look favorably on professional certifications, so long as they are relevant. You'll need to demonstrate that any certifications you claim are valid and current (we will check).
- Experience in designing and implementing technical security controls that are required for GDPR, PCI-DSS, HIPAA, or other similar regulations in on-premises and cloud environments.
- An engineering or science degree would be great, but outstanding career experience is just as important. Be prepared to tell us all about that experience
Tags: Agile AWS Azure Banking Blockchain Cloud DevSecOps GCP GDPR HIPAA ISACA ISO 27001 Risk management Security assessment SOC 2
Perks/benefits: Career development Flex vacation Gear Home office stipend Startup environment Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Ethical hacker / Pentester H/F jobs
- Open Staff Security Engineer jobs
- Open Information Security Specialist jobs
- Open Cyber Security Architect jobs
- Open Manager Pentest H/F jobs
- Open Senior Cyber Security Engineer jobs
- Open Senior Information Security Analyst jobs
- Open Cyber Security Specialist jobs
- Open Principal Security Engineer jobs
- Open Product Security Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Cybersecurity Analyst jobs
- Open IT Security Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Consultant SOC / CERT H/F jobs
- Open Cybersecurity Consultant jobs
- Open Chief Information Security Officer jobs
- Open Senior Information Security Engineer jobs
- Open Security Specialist jobs
- Open Cybersecurity Specialist jobs
- Open Senior Penetration Tester jobs
- Open Security Researcher jobs
- Open Sr. Security Engineer jobs
- Open Senior Security Architect jobs
- Open Security Operations Analyst jobs
- Open CISM-related jobs
- Open ISO 27001-related jobs
- Open Network security-related jobs
- Open Application security-related jobs
- Open Windows-related jobs
- Open Agile-related jobs
- Open Pentesting-related jobs
- Open Vulnerability management-related jobs
- Open GCP-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open CISA-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Java-related jobs
- Open DevOps-related jobs
- Open Security assessment-related jobs
- Open Kubernetes-related jobs
- Open Security Clearance-related jobs
- Open Malware-related jobs
- Open CI/CD-related jobs
- Open IDS-related jobs
- Open DevSecOps-related jobs
- Open CEH-related jobs