Information Security Governance & Risk Lead

Intelix.AI

AI GovernanceleadLondon Area, United KingdomhybridfulltimeFinancial Services and Technology, Information and MediaAzureManaged KubernetesTerraformGitHubAzure DevOpsISO 27001PCI DSSNIST Cybersecurity Frameworkposted 04 Sep
Unlock apply linkApply links and the original listing are a Pro feature: £4.99/mo or £25 once.
Information Security Governance, Risk \& Compliance Lead Global Bank London | Hybrid. Permanent. Up to £125k + Bonus \& Benefits *This role will suite a senior cybersecurity executive with end-to-end experience establishing and independently managing security, privacy, and risk operations for a regulated, cloud-first SaaS business serving major enterprise clients and processing confidential personal data and high-value transactions.* *ISO 27001, PCI DSS, executive risk oversight, third-party assurance, secure software development, and incident response.* *Practical knowledge of protecting live AI and machine-learning environments and developing AI governance frameworks capabilities that are becoming essential across regulated financial institutions.* The Role: * Ownership of the cybersecurity policy and procedure set, maintained against current and forthcoming regulation. * Security risk assessments, risk treatment and risk acceptance. * Control metrics covering design and operating effectiveness. * Cyber risk position into Enterprise Risk and into board reporting. Cyber is a designated principal risk at board committee level. * Compliance roadmaps for the FCA and for DORA. * Security awareness programme. * Incident response and post-incident corrective work. * Delivery through Technology, Legal, Compliance and Internal Audit. Tech Estate * Azure. Cloud identity. Managed Kubernetes. Hybrid and on-premises in scope. Terraform, GitHub, Azure DevOps. Frameworks * ISO 27001 and the NIST Cybersecurity Framework. Requirements * Ownership of policy sets. * Risk assessments that resulted in engineering change. * Written work read by a regulator or an external auditor. * Working knowledge of identity, cloud service models and pipeline governance. * CISSP, CISM or equivalent. Equivalent experience without the certification will be considered.