en

Services

The UK's leading employers trust us to deliver fast, efficient talent solutions that are tailored to their exact requirements. Browse our range of bespoke services and resources.

Read more
Jobs

Let our industry specialists listen to your aspirations and present your story to the most esteemed organisations in the UK, as we collaborate to write the next chapter of your successful career.

See all jobs
Services

The UK's leading employers trust us to deliver fast, efficient talent solutions that are tailored to their exact requirements. Browse our range of bespoke services and resources.

Read more
About Robert Walters UK

Since our establishment in 1985, our belief remains the same: Building strong relationships with people is vital in a successful partnership.

Learn more

Work for us

Our people are the difference. Hear stories from our people to learn more about a career at Robert Walters UK

Learn more

IT Security Risk and Governance, AVP

Save job

My client, an International Financial Services firm based in London, are looking for an IT Security Governance and Risk AVP to join their growing team. They would like individuals to come from Financial Services background. You have to be in the office two times per week.

About the IT Security Goverance and Risk AVP role:

The individual will be part of the security function that is responsible for security governance, risk and assurance, to ensure the organisations security posture is robust, compliant against the security policy, standards and controls. The position will require close collaboration with technical, operational, compliance and audit teams to create a secure and compliant technology environment.

What you will be doing:

  • Maintain security policy, standards, procedures and frameworks.
  • Ensure alignment with security industry standards such as NIST CSF and NIST 800-53.
  • Act as an advisor to colleagues across the organisation on best security practice.
  • Conduct regular risk assessments and maintain risk register in RSA Archer.
  • Identify assess and prioritize security risk across the organisation’s information assets and environments.
  • Understanding security gaps and provide evaluation and treatment options, consultation on remediation approaches to address gaps and continue ongoing monitoring of remediation, re-assess until reduced to an acceptable level.
  • Supporting Cybersecurity Risk Management strategies based on security findings and observations. Including informing improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all security functions
  • Profile and assign asset security criticality and prioritize risk assessments.
  • Where risk driven change is agreed across security functions, monitoring improvements against the baselined risk to evidence and report where security risk is being reduced to an acceptable level across security functions. Including Policy exceptions and dispensations.
  • Run lessons learned forums and recommend improvements to security controls.
  • Represent security on audits and assessments, ensuring compliance with internal and external requirements.
  • Provide assurance to stakeholders through detailed reporting and metrics.

What we are looking for:

  • Minimum of 2 years’ experience in Information and Cyber Security, with a desire to work within a security risk team.
  • Highly organised with experience of planning and reporting data, information and updates.
  • Ability to collaborate effectively with others to drive forward key security objectives.
  • Good level of technical writing reports and documenting risk assessment findings and mitigation plans clearly and accurately.
  • Attention to detail, Meticulous attention to detail to ensure data accuracy and integrity and ensure thorough and accurate risk assessment.
  • Problem solving, ability to grasp security issues that impact multiple entities and troubleshoot with proposing and consulting with colleagues on effective solutions to mitigate risks.
  • Good verbal and written communication skills to convey complex technical information clearly and effectively. Presenting data insights to non-technical stakeholders
  • Base level understanding of security risk management and taxonomy principles, to reduce risk to an acceptable level.
  • Knowledge of vulnerability management and incident management practices.
  • Ability to learn GRC tools and best practices. RSA Archer is preferred.
  • Financial and/or Banking industry experience preferred.

Professional qualifications / certifications

  • Ideally qualified in MSc Information Security, CICA, CRISC, CISM and/or Data analysis beneficial but not essential if experience validates skills.
  • Knowledge of security frameworks (e.g., NIST CSF, ISO 27001, SOC1,2).
  • Prince 2, MSP, APMQ advantageous.
  • A desire to continue learning and developing security skills and qualifications

If the above role is of interest please apply to this advertisement or call me on 0207 509 8040 or email me directly on darius.goodarzi@robertwalters.com

Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates

Contract Type: FULL_TIME

Specialism: Technology & Digital

Focus: Information Security

Industry: Banking

Salary: £80,000 - £90,000 per annum

Workplace Type: Hybrid

Experience Level: Mid Management

Location: London

Job Reference: BXLXWS-90F5FB78

Date posted: 30 April 2025

Consultant: Darius Goodarzi