JobConnect

Assistant Manager - Information Security Risk and Governance

  • JTC Group
  • Saint Helier, Jersey
  • £55,000 – £70,000

EMPLOYMENT TYPE: Permanent

DEPARTMENT: Information Systems

DIVISION: Group

WORKPLACE STRUCTURE: Hybrid

ROLE OVERIVEW

PURPOSE OF JOB

To support the Information Security Team in managing and overseeing the daily operations of information security risk and governance controls to ensure the ongoing security and efficiency of JTC’s global system. This role includes the deployment of control oversight, assurance, testing and due diligence responsibilities as part of the Group’s overall Information Security strategy.

MAIN RESPONSIBILITIES AND DUTIES

  • Policy Enforcement: Either directly or in-directly support the implementation of the control requirements specified in our Information Security Policy and Standards and best practices. Be a central point of reference for any queries and questions in relation to Information Security Policies and Standards.
  • Governance, Risk and Compliance: Perform the applicable and necessary Information Security Governance duties, both directly and in-directly.
  • Risk Management: Maintain and update the Information Security Risk Register. As well as perform the necessary updates and escalations if necessary.
  • Assessments: Help perform the necessary proactive Information Security Risk Assessments (network, infrastructure, application and 3rd parties) to identify any control gaps and risks, then with the applicable stakeholders agree risk action plans in-line with the groups risk appetite and tolerance levels.
  • Business Continuity: Assist the Information Security Risk and Governance team head with the creation, management, review and maintenance of the Group wide Business Continuity Plans (BCP’s) and Business Impact Analysis (BIA’s). BIAs are to include documented ‘Recovery Time Objectives (RTO’s) and ‘Recovery Point Objectives (RPO’s) in line with business requirements and agreeable with Group Chief Information Office and Senior Director – Head of IT Infrastructure.
  • Due Diligence: Assist when required in completion and evidence gathering as part of client due diligence assessments as and when necessary, consistently, accurate and to a high standard.
  • Audits: Assist when required in completion and evidence gathering as part of internal and external audits as and when necessary, consistently, accurate and to a high standard.
  • Reporting and Analytics: Aid the Group Information Security Officer with the monthly analytical reporting which measures and tracks all IT security related information and initiatives and is delivered to key stakeholders.
  • Training and Development: Research and keep up to date with the latest information technology security trends, threats, vulnerabilities and control measures.
  • Monitoring and Auditing: Assist with user access reviews and address any inconsistencies or security related risks.
  • Documentation: Maintain comprehensive documentation in relation to role and responsibilities .
  • Adhere to Risk & Compliance procedures in relation to regulatory requirements and AML legislation.
  • Adhere to CPD requirements in accordance with qualification level and in-house procedures.
  • Adhere to JTC core values and expected behaviours.
  • Any other duties as deemed necessary by Management.

ESSENTIAL REQUIREMENTS

  • Relevant academic and/or professional certification(s).
  • Experience in Information Security Risk and Governance.
  • Strong technical skills with a risk-based approach, including experience with Governance, Risk and Compliance (GRC) solutions and Azure infrastructure.
  • Familiarity with Information System frameworks, policies, standards, best practices, processes, and controls.
  • Strong attention to detail.
  • Excellent communication skills both verbal and written.
  • Ability to demonstrate an innovative approach to emerging changes and advancements in information security risk and governance.

OUR COMMITMENT TO INCLUSION & WELLBEING

JTC is committed to fostering a healthy, inclusive organisation where all individuals feel welcome and feel able to participate in the workplace fully. We value different perspectives, backgrounds and lived experiences. This includes supporting employee wellbeing so that people feel equipped to thrive.

#LI-AM1

Skills

  • Information Security Governance
  • Risk Management
  • Risk assessment
  • Policy Development
  • Compliance
  • Business Continuity Planning
  • Third-Party Risk Management

Related jobs

JTC GroupApply for this job