Match score not available

Director, Data Security

extra holidays - extra parental leave - fully flexible
Remote: 
Full Remote
Contract: 
Experience: 
Expert & Leadership (>10 years)
Work from: 

Offer summary

Qualifications:

5-8 years functional security expertise, B.S. in a technology discipline, Security certifications preferred, Knowledge of Risk Management life cycles, Experience with GDPR and data protection laws.

Key responsabilities:

  • Provide strategic direction for data security
  • Manage and enhance the data security program
  • Communicate risks and remediation methods
  • Perform risk assessments and identify gaps
  • Mentor junior team members
CLS Group logo
CLS Group Financial Services SME https://www.cls-group.com/
501 - 1000 Employees
See more CLS Group offers

Job description

About CLS:

CLS is the trusted party at the centre of the global FX ecosystem.  Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective.  Trillions of dollars’ worth of currency flows through our systems each day. 

Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies.  We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use.

CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market.

Our ambition to make a positive difference starts with our people.  Our values – Protect, Improve, Grow – underpin everything that we do at CLS and define and shape a supportive and inclusive working environment in which everyone is encouraged to be open and forward-thinking.

Job purpose 

 

The Data Security Manager will partner with multiple divisions and technical managers to enhance security aspects of the data security program.  Extensive oversight and control of CLS information assets, mitigating the risks of data loss at CLS in all aspects of day-to-day business.  The individual will be accountable for the Data Security Program, setting strategic direction and driving operational excellence while leveraging resources distributed across several functional teams.  The Data Security Manager will be responsible for analyzing potential weaknesses and identifying a roadmap to improve the security of information assets across CLS.  The candidate will advise Business Owners, developers, and technical teams on options to mitigate risk. The candidate must have excellent verbal, written, analytical and interpersonal communication skills.  

 

Essential Function / major duties and responsibilities of the job 

Strategic 

  • Provide strategic direction specific to data security management 
  • Build and maintain a robust data security program while aligning closely with CLS's mission 
  • Improve and manage the data security program and the company wide security standards for the management of information assets 
  • Contribute to the overall security strategy in its annual iterations 
  • Provide strong knowledge of building security into business expectations for the utilization and hosting of critical CLS data / information assets 
  • Work with the Security Architects to build security into infrastructure and architecture designs and guide the implementation with the Operations team 
  • Provide direction and advice on projects to strengthen the overall cybersecurity posture 
  • Assess SaaS and IaaS cloud services and virtualization technologies and provide direction and input for the maturation of the Cloud Security Framework in respect to data classification 
  • Enhance security programs in response to regulatory requirements, internal audit and planned strategic initiatives 
  • Foster relationships with key functional teams such as IT, Compliance, Operations, Finance, HR, Internal Audit, and Enterprise Risk to support current and future initiatives. 
  • Maintain timely understanding of CLS information assets, where they reside and how they are being utilized and hosted, continually review opportunities to improve the overall controls around data security 
  • Keep informed of new and updated industry frameworks and regulations: GDPR,  ISO 27001/2, SANS Top 20 Critical Security Controls, NIST CSF, SP 800-53, PFMI, CPMI ISOCO and FFIEC handbook 
  • Keep informed of new and emerging security threats & assess effectiveness of current controls to identify opportunities for program improvement 
  • Translate relevant directives, guidance, and rules into actionable data for consumption by the CISO and wider security teams 

Operational 

 

  • Communicate vulnerabilities risks and remediation methods to business owners, developers and technical teams 
  • Perform security testing on data controls using dynamic and static analysis tools 
  • Integrate the defined relevant security controls into data security program 
  • Ensure the operational security teams have the appropriate tooling / capabilities and quality assurance for data security management 
  • Create and deliver knowledge sharing presentations and documentation to security, developers and operations teams 
  • Learn on the job and explore new technologies independently to identify new and emerging security threats 
  • Coordinate and maintain security policies, guidelines and procedures which communicate security controls that reduce risk to levels consistent with CLS risk tolerance.  
  • Prepare and deliver security briefings for consumption by CLS Security, CISO, Executive Management Committee, and the CLS Board of Directors. 
  • Assure compliance with security controls to identify control gaps, develop remediation plans and determine residual risk 
  • Improve security metrics program to report key performance and risk indicators, trend statistical data and publish management reports for Internal Audit, Regulatory Exams, Risk Committee and Board reporting. 
  • Perform risk assessments of third-party vendors according to vendor criticality and vendor type to identify control gaps, develop remediation plans and determine residual risk 
  • Perform risk assessments of applications according to application criticality and application type to identify control gaps, develop remediation plans and determine residual risk 

 

 

 

Leadership 

  • Provide leadership across Security functions and beyond for all aspects of data security 
  • Individual contributor 
  • Mentor junior members of the team technically and professionally 

 

 

 

Experience / essential and desired for successful job performance 

  • 5-8 years functional security expertise with broad understanding of competencies and the lifecycle of data security management  
  • Experience developing or managing security programs preferably across several domains including metrics and reporting for program maturity and risk reduction 
  • Experience and/or training on GDPR requirements and other data protection laws 
  • Experience defining program roles and responsibilities, assessing / identifying knowledge gaps across teams and implementing required training plans  
  • Ability to collaborate effectively with others to drive forward key security objectives 
  • Strong documentation and report writing skills (to both technical and business audiences). 
  • Excellent time management and organizational skills 
  • Knowledge of policy frameworks and understanding of policies, procedures, guideline structure 
  • Knowledge of firewalls, IPS, DLP, proxies, SEIM, & endpoint protection software 

 

 

Qualifications / certifications 

  • B.S. in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent) 
  • Security certifications such as CompTIA Security +, CISSP, CISA, CRISC, CCNA, GIAC, or equivalent or working towards certification is preferred  
  • Knowledge of Risk Management life cycles based on an established framework: ISO 27001, SANS, NIST SP 800-53, CERT, ENISA.   
  • Working knowledge of the following frameworks and regulations: ISO 27001/2, SANS Top 20 Critical Security Controls,  NIST CSF, and FFIEC handbook 
  • An advanced degree would enhance the candidate’s credentials 

 

Success factors / ‘How’. Personal characteristics contributing to an individual’s ability to excel in the position 

  • Possess a strong service-oriented mind set to consistently deliver balanced security solutions that include people, process and technology 
  • Possess strong technical, analytical and problem solving skills 
  • Self-motivated to exceed management expectations and objectives. 
  • Ability to effectively communicate complex technical issues to both business and technical staff at all levels. 
  • Strong collaboration skills to tackle complex security challenges that may span across multiple internal and external departments and groups 
  • Able to effectively cope with change and comfortably handle risk and ambiguity, not upset when things are up in the air 
  • Tenacious resolve and positive attitude in challenging situation 

 

#LI-JF1

Our commitment to employees:

At CLS, we celebrate diversity and consider this to be one of our strongest assets. We are committed to fostering an environment in which everyone feels comfortable to be who they are, and inclusion is valued. All employees have access to our inclusive benefits, including:

  • Holiday - UK/Asia: 25 holiday days and 3 ‘life days’ (in addition to bank holidays). US: 23 holiday days.
  • 2 paid volunteer days so that you can actively support causes within your community that are important to you.
  • Generous parental leave policies to ensure you can enjoy valuable time with your family.
  • Parental transition coaching programmes and support services.
  • Wellbeing and mental health support resources to ensure you are looking after yourself, and able to support others.
  • Affinity Groups (including our Women’s Forum, Black Employee Network and Pride Network) in support of our organisational commitment to embrace and always be learning more about DE&I.
  • Hybrid working to promote a healthy work/life balance, enabling employees to work collaboratively in the office when needed and work from home when they don’t.
  • Active support of flexible working for all employees where possible.
  • Monthly ‘Heads Down Days’ with no meetings across the whole company.
  • Generous non-contributory pension provision for UK/Asia employees, and 401K match from CLS for US employees.
  • Private medical insurance and dental coverage.
  • Social events that give you opportunities to meet new people and broaden your network across the organisation.
  • Annual flu vaccinations.
  • Discounts and savings and cashback across a wide range of categories including health and retail for UK employees.
  • Discounted Gym membership – Complete Body Gym Discount/Sweat equity program for US employees.
  • All employees have access to Discover – our comprehensive learning platform with 1000+ courses from LinkedIn Learning.
  • Access to frequent development sessions on a number of topics to help you be successful and develop your career at CLS.

Required profile

Experience

Level of experience: Expert & Leadership (>10 years)
Industry :
Financial Services
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Self-Motivation
  • Leadership
  • Analytical Thinking
  • Mentorship
  • Verbal Communication Skills
  • Problem Solving
  • Time Management
  • Organizational Skills

Related jobs