Director of Security Assurance and Remediation
My client, an international Financial Services company specialising in Foreign Exchange Settlements, are looking for a Director of Security Assurance and Remediation. This role is London based and would require you to be in the office two times per week.
About the Director of Security Assurannce and Remediation role:
The role is responsible for leading and enforcing Security assurance, remediation, and monitoring across the organization’s environment. This role focuses on ensuring compliance with security standards and controls, developing, maintain and monitor against a consolidated remediation roadmap to drive improvements that reduce security risk to an acceptable level. The individual will oversee security risk reduction reporting, maintaining strong security risk practices and rigour within the team and be a security champion driving a positive risk culture across the organisation. The position will require close collaboration with technical, operational, compliance and audit teams to create a secure and compliant technology environment.
- Develop, maintain security remediation oversight, and conduct reviews across all my client's environments, services, and assets, ensuring compliance with industry standards (e.g., CIS, NIST, ISO 27001, SOC 1/2) and internal security policies across all platforms and environments.
- Lead the security governance mechanism for capturing and managing security baseline adherence to rectify any policy exceptions and dispensations (deviations or gaps) against the security policy standards and controls and align security risks.
- Oversee the remediation review lifecycle, testing of evidence related to remediation plans, producing regular reporting at relevant levels confirming direction of travel of risk improvement or decline.
- Collaborate with security and IT teams on monitoring vulnerability and patch management progress against standards and controls guidelines, with oversight of remediation and timing to reduce risk to an acceptable level.
- Direct, coach and rollout training for team to understanding security gaps and providing evaluation, treatment options and consultation on remediation approaches to address gaps and continue ongoing monitoring of remediation, re-assess and closure of from evaluations.
- Own and manage central repositories of evidence and security artefacts that support multiple internal and external audits and regulatory requirements.
- Stay updated on advancements in security technologies, policies, and regulatory changes, recommending and implementing necessary improvements.
- Key member of the function who regularly reviews Security Policies, Standards and Controls and optimize position on areas associated to regulations and company strategy.
- Integrate processes with Cyber Threat Intelligence to ensure appropriate monitoring of the threat landscape for emerging security risks and ensure swift response to zero-day threats.
- Collaborating on Security Risk Management strategies, aligning toa 3 lines of defence model and enforcing alignment of risk taxonomy to organizational cybersecurity risk management processes, procedures and activities are identified across all security functions.
Leadership
- Leads by Example: Demonstrates the technical and professional skills expected across the global team through personal action.
- Accountable and effective communicator: Clearly takes charge of the duties outlined above and communicates well with stakeholders so teams can operate in unison where required.
- Innovator and Change Agent: Always striving to find ways to automate existing processes, streamline and simplify complexity, and incorporate new ideas and capabilities to enhance our security posture and make the team stronger and better.
- Decisive: provides clear direction during cyber incident response to the Security Operations team and all associated stakeholders.
- Identify risks: Able to synthesize capability gaps and articulate them so the Firm can manage risk in alignment with its risk management strategy.
- Manages ambiguity: operating effectively and decisively, even when things are not certain, or the way forward is unclear.
- Collaborates: building partnerships and working collaboratively with others to meet shared objectives.
- Influence: proven success navigating and operating effectively in a matrix organization.
- Customer focus: building strong partnerships and delivering customer-centric solutions.
- Committed to professional development with a personal appetite to grow and contribute further to the organization over time.
Knowledge, Skills, and abilities
- Bachelor’s degree in computer science, Cybersecurity, Information Technology, or related field. Master’s degree preferred.
- CRISC, CISM, CISA, CDPSE, or similar advanced security certifications.
- Advantageous to have experience in Artificial Intelligence, post quantum computing and cyber risk quantification.
- Considerable experience in cybersecurity, with notable experience in a senior or managerial role focused on security policy, standards, controls testing, governance, and compliance.
- Mastery experience of how security controls are implemented, their effectiveness, and alignment with security policy, standards and NIST best practice guidelines.
- Strong ability to consult with control owners on their security remediation implementations and provide insights on evidence provision required to be compliant.
- Proficient on security data analysis, identify trends and areas for improvement.
- Expert in technical writing reports and documenting risk assessment findings and mitigation plans clearly and accurately.
- Excellent verbal and written communication skills to convey complex technical information clearly and effectively. Presenting data insights to non-technical stakeholders
- Strong understanding of security risk management and taxonomy principles, to reduce risk to an acceptable level.
- Experience with GRC tools and best practices. RSA Archer is preferred.
- Proficiency in security frameworks (e.g., NIST CSF, ISO 27001, SOC1,2).
- Expert knowledge of security assurance practices such as audit, risk assessing, associated lifecycles and key management practices.
- In an ever-changing cyber landscape to be able to lead a team to adapt to changes in line with organisation needs but also in line with the threat landscape.
- High level of integrity and ethical judgement to handle sensitive information responsibly.
- Familiarity with cloud security controls and securing hybrid IT environments.
- Knowledge of vulnerability management and incident management practices.
- Evidence of working in the Financial Service Industry preferred.
If the above role is of interest please do apply to this job advertisement or call me on 0207 509 8040 to find out more. Alternatively you can email me on darius.goodarzi@robertwalters.com
Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates
About the job
Contract Type: FULL_TIME
Specialism: Technology & Digital
Focus: Information Security
Industry: Banking
Salary: £140,000 - £150,000 per annum
Workplace Type: Hybrid
Experience Level: Director
Location: London
FULL_TIMEJob Reference: WF717B-68225CF5
Date posted: 14 May 2025
Consultant: Darius Goodarzi
london information-technology/information-security 2025-05-14 2025-07-13 banking London London GB GBP 140000 150000 150000 YEAR Robert Walters https://www.robertwalters.co.uk https://www.robertwalters.co.uk/content/dam/robert-walters/global/images/logos/web-logos/square-logo.png true