Take ownership of the firm’s Information Security function and maintain/improve its security posture
Take the lead in responding to customer security questionnaires or audit follow-ups
Oversee our regular ISO27001 and SOC 2 Type II audits
Research and choose technical tools to proactively detect and respond to weaknesses, threats and potential compromises
Lead the development, implementation, and continuous improvement of information security practices across all teams
Manage regular pentests by external consultants and coordinate with internal resources to remediate issues
Information security risk assessment of third-party service providers
Offer guidance, direction and approval on security solutions and approaches
Advocate for secure engineering best practices throughout the company
Manage the standards, policies and guidelines of the InfoSec frameworks
Maintain an on-going information security awareness program
Monitor our SIEM, and maintain useful reports and alerts in the system
Requirements
Significant industry experience in a technical security role (Security Engineering or Application Security Engineering)
Experience speaking to customers and establishing a good working relationship with infosec counterparts at major financial institutions
Strong technical intuition, with an ability to partner with engineering to evaluate and develop good security standards
Take a risk-based approach when suggesting improvements, or proposing fixes
Ability to perform design reviews and/or technical assessments of software and infrastructure
Excellent knowledge of InfoSec, risk management and governance, data protection
Programming/scripting experience, especially to automate repetitive tasks
Used to multi-tasking and working in a fast-paced environment
Proven ability to identify and articulate information security requirements, risks and issues, and to make clear decisions / recommendations
Ability to understand business drivers and risk appetite and align information security compliance accordingly
Strong ability to communicate clearly and simply, both verbally and in writing
Benefits
Life at TradingHub is a rewarding journey within a fast-growing company that thrives on innovation and collaboration. By combining the best of both tech and finance, we’re able to solve complex problems together and deliver meaningful results to our customers. Everybody has value to bring, and we welcome individuality as a key driving force behind our collective success.
Rooted in everything that we do are our core values: Accountability, Ambition, Partnership and Trust. These provide the foundation for a sustainable workplace culture and the platform for you to harness your unique experience and become the best version of yourself. We believe in our people and invest in their growth, and together, we can sit on the right side of history.
**Don’t tick every single requirement? **Research shows that candidates from under-represented groups are less likely to apply unless they meet all the criteria. We are dedicated to building a diverse, equitable and inclusive workplace, so if this role excites you, please don't let our specification hold you back. Get in touch!
TradingHub is an equal opportunities employer. We do not discriminate based on race, religion, ethnic or national origins, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, socio-economic background, responsibilities for dependants, physical or mental disability or other applicable legally protected characteristics. TradingHub selects candidates for interview based solely on their skills, experience and qualifications.
We are committed to making our recruitment process accessible to all and we encourage candidates to inform us of any required adjustments. A full copy of our diversity, equity and inclusion policy will be made available to you upon request.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
Information SecurityISO27001SOC 2 Type IIpenetration testingrisk assessmentsecurity standardsdata protectionprogrammingscriptingsecurity compliance