Information Security Specialist – Project Rome
R3 is revolutionizing the way banking and commercial transactions happen with our distributed ledger technology, Corda. DLT, aka ‘blockchain’, allows for not only dramatic efficiencies in the way commercial transactions occur but enables new things that have not even been dreamed up yet. We are creating a new future for global commerce.This role of Information Security Specialist is part of “project Rome”, a newly formed team working closely with selected partners to bring their application to market as a service. This exciting project combines the best of Corda based solutions and allows customers to use them in an unparalleled experience. You will be working in a multidisciplinary team, developing and bringing this new service to market. You will work alongside, and support our Customers, as well as many different teams within R3 – therefore being a team player, having a great personality, a sense of humour, being able to work under pressure, being empathetic towards different cultures, communicating effectively and hitting deadlines are all paramount to enjoying life at R3. We are seeking an experienced Information Security Expert to help us drive this revolution. You will be helping to develop the control environment for R3’s Managed Services offering to end customers. This is a customer-facing role where you will be interacting with both customers as well a highly demanding institutional end user. you will need to have excellent communication skills and must be comfortable as the R3 security lead in engagements with client security architects and technology risk management teams.You will have a combination of both technical and organisational security skills. Your background will be within financial services, telecoms, or critical infrastructure service provider, or maybe an enterprise-scale end-user security department. You'll be used to working in environments with comprehensive security control environments but have the insight to bring a risk-based approach to a fast-moving company with a start-up culture. Affinity and, or experience with an Agile way of working and design thinking methodologies will help you excel as part of a multidisciplinary team.This is an opportunity to help "write the book" on building on the security controls and providing high levels of assurance for enterprise blockchain deployments.
- Play a lead role within R3's new product squad specifying and implementing technical and organizational security controls required for world-class enterprise software and service delivery organization.
- Consult with R3 clients and partners to understand their security requirements. Lead client security and technology risk management reviews, compile responses for reviews, negotiate remedial activities with R3 internal teams, and manage such activities to completion.
- Provide security representation in technical design reviews, Lead risk and security assessment and threat modeling activities for processes and systems as required, and ensuring R3's products and services are secure by design.
- Work with the wider security team to prepare for and undergo external service auditor assessments of the security control environments which you help to develop
- Lead the development of an infosec framework for R3’s Managed Services offering based on validated data and proof points, using design thinking methods for iterative agile delivery.
- Stakeholder engagement. Act as the interface to the Infosec team for engaging stakeholders on inbound requirements.
- Consolidate uses cases into granular requirements that can be understood in a consistent framework and architecture. Work with the rest of the squad to create a framework that can be applied by partners to meet customer security objectives.
- Work with the Program Management team to establish a detailed delivery schedule for the security features of the new offering. Partner with the test team to ensure the solution meets the product specifications.
- First and foremost we want you to love what you do. You'll need to be a security evangelist within R3 and the community of Corda Network participants, both current and future.
- You will have at least five years of senior (preferably technical team lead) roles within a security organization in a blue-chip or high-growth technology organization.
- You'll have experience in multiple security domains. Those with deep, specialist skills in one or two domains only need not apply.
- Hands-on experience is essential. Whilst we're not expecting to hire a DevSecOps engineer or security researcher you will be expected to hold your own in a team that includes those skills. We expect the ability to execute, and the experience to be effective in a short period of time from all team members.
- You'll need excellent communication skills, both verbal and written. You must be capable of delivering concise, plain English descriptions of complex security concepts to senior R3 and client stakeholders. You should sufficient gravitas to influence small groups of senior management members or board-level members, but also have the energy to present to a conference hall.
- You will be capable of defining security requirements and implementing controls and metrics for complex, long-term projects involving substantial multi-disciplinary teams.
- You must have worked within an organization that carried industry recognized credentials such as ISO 27001 certification or SOC 2 reports. You will have played a lead role in gaining those credentials.
- Financial services experience would be ideal, but experience in other areas such as telecoms or other critical infrastructure may also be a good fit.
- You must be able to display extensive experience in working in both cloud and on-premises deployments. Microsoft Azure is our platform of choice, but AWS or GCP skills are transferable. Containerisation and container orchestration security skills would be a big plus.
- Relevant professional qualifications would be great. We have ISACA and ISC2 members in the team already and so obviously look favorably on professional certifications, so long as they are relevant. You'll need to demonstrate that any certifications you claim are valid and current (we will check).
- Experience in designing and implementing technical security controls that are required for GDPR, PCI-DSS, HIPAA, or other similar regulations in on-premises and cloud environments.
- An engineering or science degree would be great, but outstanding career experience is just as important. Be prepared to tell us all about that experience
Job tags: Architecture AWS Azure Banking GDPR Go HIPAA ISO 27001 PCI Risk management SOC 2
Job region(s): Europe
Job stats: 8 2 0
More Information Security position highlights
- Explore open Information Security Architect Jobs
- Explore open SOC Analyst Jobs
- Explore open Threat Intelligence Response Analyst Jobs
- Explore open Senior Penetration Tester Jobs
- Explore open Staff Security Engineer Jobs
- Explore open Information Security Officer Jobs
- Explore open Vulnerability Analyst Jobs
- Explore open Software Security Engineer Jobs
- Explore open Threat Intelligence Analyst Jobs
- Explore open Infrastructure Security Engineer Jobs
- Explore open Computer Network Defense & Incident Response Analyst - Mid to Senior Level Jobs
- Explore open DevOps Security Engineer Jobs
- Explore open Senior Information Security Engineer Jobs
- Explore open Chief Information Security Officer Jobs
- Explore open IAM Engineer Jobs
- Explore open Computer Forensic Software Engineer Jobs
- Explore open Staff Engineer, Cloud Security Jobs
- Explore open Manager, Cybersecurity and Trust Jobs
- Explore open Sr. Software Engineer - Detection Engineering Jobs
- Explore open Cybersecurity Analyst Jobs
- Explore open Cybersecurity Engineer Jobs
- Explore open Personnel Security Officer Jobs
- Explore open Engineering Manager - Information Security, Bangalore Jobs
- Explore open Senior Information Security Analyst Jobs
- Explore open Cyber Threat Analyst Jobs
- Explore open Clearance-related jobs
- Explore open CEH-related jobs
- Explore open Audits-related jobs
- Explore open Open Source-related jobs
- Explore open Forensics-related jobs
- Explore open PCI-related jobs
- Explore open Risk management-related jobs
- Explore open IDS-related jobs
- Explore open NIST-related jobs
- Explore open Ruby-related jobs
- Explore open OSCP-related jobs
- Explore open Machine Learning-related jobs
- Explore open Splunk-related jobs
- Explore open AI-related jobs
- Explore open Google-related jobs
- Explore open IPS-related jobs
- Explore open Security assessments-related jobs
- Explore open Threat detection-related jobs
- Explore open Encryption-related jobs
- Explore open Unix-related jobs
- Explore open Docker-related jobs
- Explore open DNS-related jobs
- Explore open PowerShell-related jobs
- Explore open TCP/IP-related jobs