Assistant Manager – Information Security Risk and Governance

ROLE OVERIVEW

PURPOSE OF JOB

To support the IT Security Team in managing and overseeing the daily operations of information security risk and governance controls to ensure the ongoing security and efficiency of JTC’s global system.  This role includes the deployment of control oversight, assurance, testing and due diligence responsibilities as part of the Group’s overall Information Security strategy.

MAIN RESPONSIBILITIES AND DUTIES

  • Policy Enforcement: Either directly or in-directly support the implementation of the control requirements specified in our Information Security Policy and Standards and best practices. Be a central point of reference for any queries and questions in relation to Information Security Policies and Standards.
  • Governance, Risk and Compliance: Perform the applicable and necessary Information Security Governance duties, both directly and in-directly.
  • Risk Management: Maintain and update the Information Security Risk Register. As well as perform the necessary updates and escalations if necessary.
  • Assessments: Help perform the necessary proactive Information Security Risk Assessments (network, infrastructure, application and 3rd parties) to identify any control gaps and risks, then with the applicable stakeholders agree risk action plans in-line with the groups risk appetite and tolerance levels.
  • Business Continuity: Assist the Information Security Risk and Governance team head with the creation, management, review and maintenance of the Group wide Business Continuity Plans (BCP’s) and Business Impact Analysis (BIA’s). BIAs are to include documented ‘Recovery Time Objectives (RTO’s) and ‘Recovery Point Objectives (RPO’s) in line with business requirements and agreeable with Group Chief Information Office and Senior Director – Head of IT Infrastructure.
  • Due Diligence: Assist when required in completion and evidence gathering as part of client due diligence assessments as and when necessary, consistently, accurate and to a high standard.
  • Audits: Assist when required in completion and evidence gathering as part of internal and external audits as and when necessary, consistently, accurate and to a high standard.
  • Reporting and Analytics: Aid the Group Information Security Officer with the monthly analytical reporting which measures and tracks all IT security related information and initiatives and is delivered to key stakeholders.
  • Training and Development: Research and keep up to date with the latest information technology security trends, threats, vulnerabilities and control measures.
  • Monitoring and Auditing: Assist with user access reviews and address any inconsistencies or security related risks.
  • Documentation: Maintain comprehensive documentation in relation to role and responsibilities .
  • Adhere to Risk & Compliance procedures in relation to regulatory requirements and AML legislation.
  • Adhere to CPD requirements in accordance with qualification level and in-house procedures.
  • Adhere to JTC core values and expected behaviours.
  • Any other duties as deemed necessary by Management.

ESSENTIAL REQUIREMENTS

  • Relevant academic and/or professional certification(s).
  • Experience in Information Security Risk and Governance.
  • Strong technical skills with a risk-based approach, including experience with Governance, Risk and Compliance (GRC) solutions and Azure infrastructure.
  • Familiarity with Information System frameworks, policies, standards, best practices, processes, and controls.
  • Strong attention to detail.
  • Excellent communication skills both verbal and written.
  • Ability to demonstrate an innovative approach to emerging changes and advancements in information security risk and governance.

OUR COMMITMENT TO INCLUSION & WELLBEING 

JTC is committed to fostering a healthy, inclusive organisation where all individuals feel welcome and feel able to participate in the workplace fully. We value different perspectives, backgrounds and lived experiences. This includes supporting employee wellbeing so that people feel equipped to thrive. 

Come Join us

Whether you are just starting out or seeking new challenges, JTC offers an environment where you can grow, develop, and succeed at every stage of your career.

Stay Connected

Stay up to date with expert insights, latest updates and exclusive content.