JCW Group · 6 days ago
Director, Information Security Risk Management Lead
JCW Group is seeking a senior Information Security Risk Management Lead to own second-line oversight of information security risk within a complex, highly regulated financial services environment. This role involves challenging risk assessments and control effectiveness while shaping the firm’s information security risk posture and influencing senior leadership.
Responsibilities
Lead second-line oversight of information security risk across the enterprise
Challenge risk assessments, control design, and control effectiveness
Own and oversee information security risk policies, standards, and procedures
Provide independent challenge on incidents, remediation actions, and risk appetite
Engage regularly with senior leadership, audit, and regulators
Lead and develop junior risk professionals
Qualification
Required
10+ years' experience in information security risk, governance, or operational risk
Mandatory financial services experience (banking, capital markets, payments, insurance, FMIs)
Strong familiarity with frameworks such as NIST, ISO 27001, ORX, Basel
Experience operating in a second-line risk function
Ability to influence and challenge senior stakeholders