Head of Information Security Governance, Risk
2 weeks ago
**Job Title**:Head of Information Security Governance, Risk & Compliance**Location: London/Frankfurt**
DWS Group (DWS) is one of the world's leading asset managers with EUR 880bn of assets under management (as of 30 September 2021). Building on more than 60 years of experience, it has a reputation for excellence in Germany, Europe, the Americas and Asia. DWS is recognised by clients globally as a trusted source for integrated investment solutions, stability and innovation across a full spectrum of investment disciplines.
We offer individuals and institutions access to our strong investment capabilities across all major asset classes and solutions aligned to growth trends. Our diverse expertise in Active, Passive and Alternatives asset management - as well as our deep environmental, social and governance focus - complement each other when creating targeted solutions for our clients. Our expertise and on-the-ground-knowledge of our economists, research analysts and investment professionals are brought together in one consistent global CIO View, which guides our investment approach strategically.
DWS is transforming and growing its internal information and cyber security team. As the Head of Information Security Governance, Risk & Compliance (GRC) and member of the CISO leadership team you will be accountable for defining and maintaining the information security strategy, policy and standards and ensuring that technology and business units are in compliance with the policy and standards. You will provide assurance that DWS is compliant with legal, regulatory, and industry requirements as applicable by carrying out appropriate internal and external reviews of control effectiveness.
**Your key responsibilities**:
- Lead DWS’s Information Security (IS) Governance, Risk & Compliance (GRC) Team
- Define and maintain the DWS information and cyber security strategy and ensure that: it is aligned with the overall business objectives and strategy, supports the technology strategy, addresses regulatory requirements and client contractual obligations and responds to increasing cyber threat
- Provide strategic direction for DWS Group Information Security and Business Continuity Management Systems, projects and initiatives
- Define and maintain the information and cyber security policy, framework and related processes
- Govern the information and cyber security policies, standards, guidelines and procedures ensuring they reflect the current legal, regulatory and client requirements and threat landscape
- Develop and manage the information and cyber policy exceptions process
- Implement and maintain information and cyber security risk and control framework creating simple, consistent DWS committees and board reporting using key risk, control and performance indicators
- Develop maturity model and track of information and cyber security controls
- Establish an information security training and awareness programme to create and maintain a strong culture of security across DWS, including specialised awareness content for engineers, administrators, and senior management
- Ensure that security internal controls are designed and performed in a way that delivers good business and client outcomes and demonstrates effective management of cyber risk
- Define and implement the user/privileged access attestation process ensuring a robust access control capability
- Assist the business functions and regions with ongoing information & cyber security risk management by assessing and tracking risks and policy exceptions and monitoring of the security position of the business
- Align control requirements to efficiently meet regulatory compliance and resilience requirements in relation to information and cyber security
- Facilitate the information and cyber security steering committees
- Own various DWS internal and external stakeholder relations which includes business, IT, regulators, auditors, and clients
**Your skills and experience**:
- Proven experience of increasing responsibility in information, technical or cyber security roles, with experience in building and leading an information security governance, risk & compliance team
- Security professional related certification - CISSP, CISM, CCSP, SANS or equivalent desirable
- Experience of long-term cyber security strategy development and the credibility required to influence senior stakeholders
- Experience of developing and maintaining security policies, standards and guidelines
- Knowledge of risk assessment methodologies and techniques
- Track record of developing models to establish risk appetite
- Extensive experience of security awareness programme implementation and culture change techniques
- Knowledge of key information and cyber related laws, regulations and standards including (but not limited to) SOX, NYDFS, FCA, SOC, PCI, ISO 27001, HIPAA) and reporting requirements
- Proven experience in implementing of cybersecurity standards and frameworks e.g., ISO27001, NIST,
-
Head of Information Security
2 days ago
London, United Kingdom Birkbeck University of London Full timeAre you ready to take on a pivotal role in safeguarding the future of information security? Join Birkbeck, University of London, as our Head of Information Security & Governance this Autumn 2024. As part of our Information Services department, you will lead a team dedicated to ensuring the confidentiality, integrity, and availability of our institutional...
-
Information Governance Trainee
4 days ago
London, United Kingdom Information Governance Services Full time**Immediate Start**: - **About Us** - **About the Role** **Key duties and responsibilities**: - Support the Lead Consultant and/or Consultants to complete client work; - Work well under instructions and within agreed timelines; - Conduct research and interpret legislation, regulations and/or guidance and provide a digest to fee earners; - Study, attend...
-
Information Risk Specialist
2 weeks ago
London, United Kingdom Information Security Solutions Full timeCompany: Financial Services Location: Hybrid - City of London Reports to Information Risk Manager **Salary**: £80,000 Benefits: Generous No. Required: 1 Start Date: ASAP **The Role** As the Information Security Risk Specialist, you shall support the Information Risk Manager which has responsibility for all Governance Risk and Compliance activities in the...
-
Group Head of IT
1 week ago
Greater London, United Kingdom BUPA Full timeGroup Head of IT & Information Security Risk and Governance Flexible on location - attending meetings in London a couple of times a month. Hybrid & flexible working options. Permanent. Salary - £95,000 - £110,000 per annum + benefits package. Full Time - 35 hours. Closing date for applications - Monday 8th December 2025. We make health happen! At Bupa, our...
-
London, Greater London, United Kingdom Arriva Group Full time £60,000 - £120,000 per yearArriva is a leading European passenger transport partner, operating in 11 countries across the UK and Europe. The company employs around 35,000 people, delivering more than 1.5 billion passenger journeys connecting people and communities safely, reliably and sustainably.We have strong roots dating back to 1938, an ambitious growth and sustainability agenda,...
-
London, Greater London, United Kingdom Arriva Group Full time £80,000 - £120,000 per yearArriva is a leading European passenger transport partner, operating in 11 countries across the UK and Europe. The company employs around 35,000 people, delivering more than 1.5 billion passenger journeys connecting people and communities safely, reliably and sustainably. We have strong roots dating back to 1938, an ambitious growth and sustainability...
-
Head of Information Security
2 days ago
London, United Kingdom Birkbeck, University of London Full timeJoin Birkbeck's Information Services department as a Senior Information Security Analyst and play a pivotal role in safeguarding our institutional systems and data. As part of the Information Security and Governance team, you will support the Head of Information Security & Governance, providing expert advise and help to manage information security, and...
-
Information Security, Governance, Risk and
1 week ago
London, United Kingdom ASOS Full timeCompany Description We're ASOS. We blend our flair for fashion with our love of cutting - edge technology, but more importantly were interested in how we can bring the best out of you. We exist to give people the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you're free to be your true self without judgment, and...
-
Information Security, Governance, Risk and
1 week ago
London, United Kingdom ASOS Full timeCompany Description We're ASOS. We blend our flair for fashion with our love of cutting - edge technology, but more importantly were interested in how we can bring the best out of you. We exist to give people the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you're free to be your true self without judgment, and...
-
London Area, United Kingdom ivee | The job platform for everyone else Full timePlease note:Thanks for your interest in this role - just to be clear, this is not a job working at ivee.This is a live role with a client, listed through ivee.ivee is exclusively for people restarting, pivoting, or returning to work within the UK. Please do not apply if you are outside the UK.Have you taken a career break or are you looking to pivot into...