Engineer, Information Security GRC
Intercontinental Exchange
London, UK
28 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Microsoft Excel
Control Objectives for Information and Related Technology (COBIT)
Cyber Security
Information Security Management
Internet Protocol
Parsing
Systems Development Life Cycle
Regular Expressions
Scripting
Indexer
RSA Archer Platform
Job description
The Engineer, Information Security GRC is part of a team responsible for the global Information Security program. The role would gain exposure to the full suite of businesses and products which underpin the Parent Intercontinental Exchange (ICE) company.
Information Security (βISβ) is charged with:
- Preventing impactful cybersecurity and physical security incidents,
- maintaining a reputation with customers, regulators, and key stakeholders as running a best-in-class cybersecurity and physical security program, and
- avoiding negative impact to business agility and growth from cybersecurity and physical security policies and controls.
Governance, Risk, and Compliance maintain said policies, ensure controls are operating effectively via assessment and attestation, and own the vulnerability management program to identify and correct any problems within.
Responsibilities
- Security Metrics - Uses automated and manual processes to produce regular reports communicating the status of the Information Security program
- Policies and Procedures - Maintains corporate Information Security policies and departmental procedures and maps them to relevant control standards
- Regulator, Audit, and Customer Inquiries - Organizes and updates departmental documentation and responds to inquiries in an organized and repeatable fashion
- Recertification - Operates periodic processes to ensure hire, transfer, and termination protocols are complied with and regular access reviews are conducted
- Security Awareness - Builds and maintains company awareness and education programs
- Risk Assessment - Builds and operates the company platform to document, measure, and report assessments, risks, controls, findings, and remediation activity
Requirements
- University degree in Information Security, Engineering, MIS, CIS, or related discipline
- 3+ years of relevant work experience
- Experience in Cybersecurity Framework (such as NIST, COBIT)
- Experience with Systems Administration and/or IP Networking is a plus
- Experience with Regulatory Compliance
- Experience in an exchange, trading facility, or financial services a plus
- Experience in Customer communication and Vendor evaluation
- Experience with senior management and board metrics generation and communication
- Advanced certifications (for example, the CISSP)
- Advanced technical writing and/or communication education and experience
- Specific Technologies:
- Excel, Workflow automation tools, Data collection, normalization, indexing, correlation, and visualization
- Scripting, regular expressions, string-parsing, light SDLC, and project management
- NIST Cyber Security Framework, CIS, and GRC Platforms
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dejobs.orgGood distractions
Talks and stories from around this role β technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
6 months ago
EM
Eli McGarvie
Software Engineer Salary London
about 3 years ago
EM
Eli McGarvie
Data Engineer Salary UK
about 3 years ago
LM
Luis Minvielle
Top-Paying Tech Jobs (with Salaries)
over 2 years ago
LM
Luis Minvielle
UK Business Culture and Etiquette
over 2 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago