EMPLOYMENT TYPE: Permanent
DEPARTMENT: Information Systems
DIVISION: Grop
WORKPLACE STRCTRE: Hybrid
ROLE OVERIVEW
PRPOSE OF JOB
To spport the Information SecrityTeam in managing and overseeing the daily operations of information secrityrisk and governance controls to ensre the ongoing secrity and efficiency ofJTC's global system. This role incldesthe deployment of control oversight, assrance, testing and de diligenceresponsibilities as part of the Grop's overall Information Secrity strategy.
MAIN RESPONSIBILITIES AND DTIES
Policy Enforcement: Either directly or in-directly spport the implementation of the control reqirements specified in or Information Secrity Policy and Standards and best practices. Be a central point of reference for any qeries and qestions in relation to Information Secrity Policies and Standards. Governance, Risk and Compliance: Perform the applicable and necessary Information Secrity Governance dties, both directly and in-directly. Risk Management: Maintain and pdate the Information Secrity Risk Register. As well as perform the necessary pdates and escalations if necessary. Assessments: Help perform the necessary proactive Information Secrity Risk Assessments (network, infrastrctre, application and 3rd parties) to identify any control gaps and risks, then with the applicable stakeholders agree risk action plans in-line with the grops risk appetite and tolerance levels. Bsiness Continity: Assist the Information Secrity Risk and Governance team head with the creation, management, review and maintenance of the Grop wide Bsiness Continity Plans (BCP's) and Bsiness Impact Analysis (BIA's). BIAs are to inclde docmented 'Recovery Time Objectives (RTO's) and 'Recovery Point Objectives (RPO's) in line with bsiness reqirements and agreeable with Grop Chief Information Office and Senior Director - Head of IT Infrastrctre. De Diligence: Assist when reqired in completion and evidence gathering as part of client de diligence assessments as and when necessary, consistently, accrate and to a high standard. Adits: Assist when reqired in completion and evidence gathering as part of internal and external adits as and when necessary, consistently, accrate and to a high standard. Reporting and Analytics: Aid the Grop Information Secrity Officer with the monthly analytical reporting which measres and tracks all IT secrity related information and initiatives and is delivered to key stakeholders. Training and Development: Research and keep p to date with the latest information technology secrity trends, threats, vlnerabilities and control measres. Monitoring and Aditing: Assist with ser access reviews and address any inconsistencies or secrity related risks. Docmentation: Maintain comprehensive docmentation in relation to role and responsibilities . Adhere to Risk & Compliance procedres in relation to reglatory reqirements and AML legislation. Adhere to CPD reqirements in accordance with qalification level and in-hose procedres. Adhere to JTC core vales and expected behaviors. Any other dties as deemed necessary by Management. ESSENTIAL REQIREMENTS Relevant academic and/or professional certification(s). Experience in Information Secrity Risk and Governance. Strong technical skills with a risk-based approach, inclding experience with Governance, Risk and Compliance (GRC) soltions and Azre infrastrctre. Familiarity with Information System frameworks, policies, standards, best practices, processes, and controls. Strong attention to detail. Excellent commnication skills both verbal and written. Ability to demonstrate an innovative approach to emerging changes and advancements in information secrity risk and governance. OR COMMITMENT TO INCLSION & WELLBEING JTC is committed to fostering a healthy, inclsive organisation where all individals feel welcome and feel able to participate in the workplace flly. We vale different perspectives, backgronds and lived experiences. This incldes spporting employee wellbeing so that people feel eqipped to thrive.
#LI-AM1