Business Information Security Officer – Engine by Starling

🕒 March 27

🏢🏡 London – Hybrid

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🇬🇧 UK Skilled Worker Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Starling Bank

Starling Bank

WebsiteLinkedIn

1001 - 5000 employees

Founded 2014

🏦 Banking

💳 Fintech

💸 Finance

Banking • Fintech • Finance

Starling Bank is a UK-based digital bank providing a range of personal and business banking services. It offers current accounts, savings accounts, euro accounts, and teen-oriented banking. Starling Bank is known for its emphasis on mobile banking, featuring tools for budgeting, bill management, international money transfers, and overdraft facilities. The bank also provides business accounts tailored for sole traders and larger enterprises with multi-currency options. Award-winning security features and 24/7 customer service further define its banking services. As a fully regulated bank, Starling prioritizes sustainable banking and innovation in financial services.

📋 Description

• Manage and maintain the Information Security Policy and Information Security Management System to ensure (i) it meets the needs of Engine, its clients, employees and other stakeholders and (ii) compliance with the relevant industry standards, regulatory and certification requirements such as ISO 27001. • Oversee Engine’s Information Security governance documents (processes, standards and procedures) and optimise reporting of identified threats and vulnerabilities. • Oversee the process for obtaining and maintaining compliance certifications and accreditations including but not limited to ISO 27001, SOC 1, SOC 2 and PCI DSS/3DS through engagement with internal teams and our external auditors. • Maintain the Information Security Risk Register; identifying, assessing and mitigating information security risks (including security risks related to third-parties and partners) and ensuring coherence with Engine’s Risk Management framework. • Act as a point of contact for all Information Security related client queries and issues; providing expert opinion and communication during initial client conversations, RFPs, RFIs, delivery and throughout the client lifecycle. • Act as an Information Security point of contact for Business Continuity Planning and Disaster Recovery; this includes responsibility for initiation and execution of cyber business impact analysis. • Advise the wider organisation on compliance and governance requirements. • Oversee Incident Response related to Information Security and ensure coherence and collaboration with the broader Technology response capability. • Liaise with external bodies and organisations to keep abreast of the threat landscape, emerging trends, technologies and legislation that have an impact on Information Security. • Assist as necessary to investigate security breaches and pursue associated disciplinary and legal matters. • Lead and manage a team of subject matter experts to ensure Information Security is managed effectively throughout the IT service delivery lifecycle, addressing client needs. • Promote security awareness by collaborating with the relevant teams to provide training and awareness to the wider Engine organisation.

🎯 Requirements

• deep understanding and knowledge of cyber security principles, security standards and regulatory compliance and its application in a wide variety of organisations with a strong risk culture. • experience in a business facing security role, ideally in an Information Security Director, BISO, CISO or similar capacity • strong business acumen and commercial awareness with previous experience in a senior client-facing role or similar. • be a self starter / self motivated with the ability to lead, inspire and drive change through an organisation. • have the ability to be pragmatic while balancing the needs of Engine against security. • ability to work with a variety of stakeholders across all levels and can adapt communication style to different stakeholders. • have an ability to think and plan strategically and systematically while recognising the need to deliver to the business requirements. • have previous experience working in a complex IT organisation encompassing service delivery, application development and IT infrastructure. • an understanding of best practice within Information Security and risk management including standards such as ISO 27001, NIST, Cyber Essentials and COBIT. • an understanding of legislation and regulations that impact information Security. E.g. Data Protection Act and GDPR, Freedom of Information Act, PCI DSS. • Have previous experience in leading, developing and motivating a team of subject matter experts. • An understanding of current and emerging threats and countermeasures and the organisational challenges to addressing these threats. • A good practical knowledge of security technologies and wider business solutions including Identity and access management, SIEM, remote working and cloud technologies. • Experience of working in a banking or financial services environment would be beneficial. • ISC2 CISSP or ISACA CISM, ISACA CRISC, CISA or Open FAIR qualifications would be beneficial.

🏖️ Benefits

• 33 days holiday (including public holidays, which you can take when it works best for you) • An extra day’s holiday for your birthday • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off • 16 hours paid volunteering time a year • Salary sacrifice, company enhanced pension scheme • Life insurance at 4x your salary & group income protection • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton • Generous family-friendly policies • Incentives refer a friend scheme • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

Apply Now

Similar Jobs

🕒 March 25

PwC

10,000+ employees

🤝 B2B

📋 Compliance

🏢 Enterprise

WebsiteLinkedIn

Senior Security Architect designing secure information security architectures and advising PwC clients on best practices. Engaging with stakeholders and delivering security frameworks for technology initiatives.

🏢🏡 London – Hybrid

💰 Grant on 2023-10

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🕒 March 25

CDW

10,000+ employees

🏢 Enterprise

☁️ SaaS

🔒 Cybersecurity

WebsiteLinkedIn

Partner Manager driving Cyber Security and Data Protection strategy at CDW. Collaborating with partners and sales teams to ensure revenue growth and market awareness.

🕒 March 24

Hadean

51 - 200

🚗 Transport

WebsiteLinkedIn

Technical Capture Manager at Hadean responsible for delivering defence technology proposals. Translating technology capabilities into solutions for military and defence organisations.

🕒 March 20

CFC

501 - 1000

🔒 Cybersecurity

💳 Fintech

WebsiteLinkedIn

Security Engineer developing and delivering security awareness programs and hands-on IAM configurations at CFC. Playing a key role in strengthening the organization's security posture.

🕒 March 17

Vanta

201 - 500

📋 Compliance

🔐 Security

☁️ SaaS

WebsiteLinkedIn

Senior Software Engineer driving development of privacy features in security platform. Leading technical direction and mentoring engineers for a rapidly growing company.

🏢🏡 London – Hybrid

💰 $40M Series B on 2022-10

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer