Cybersecurity Governance and Risk Specialist

Jane Street Jane Street · Quant · London, United Kingdom · Cybersecurity

Jane Street is seeking a Cybersecurity Governance and Risk Specialist to enhance and champion cybersecurity GRC activities. The role involves collaborating with cross-functional teams to improve governance and risk management, developing policies, monitoring compliance and regulatory requirements, performing control assessments, and conducting third-party vendor assessments. The ideal candidate has experience in technical environments, understands cybersecurity standards and regulatory requirements beyond finance, and is familiar with auditing processes.

What you'd actually do

  1. Developing, maintaining and communicating cybersecurity policies, and helping colleagues understand and apply those security policies to their daily work
  2. Monitoring compliance with internal policies, tracking exceptions and collaborating with teams on exploring alternative risk-reduction measures when necessary
  3. Monitoring regulatory requirements, noting any changes that could impact the firm and collaborating with the relevant teams to ensure we stay in compliance
  4. Performing control assessments, helping identify control gaps or weaknesses and working with the relevant teams to implement improvements to reduce our risk exposure
  5. Supporting the development, automation and maintenance of appropriate metrics to drive informed decision-making

Skills

Required

  • Experience in Cyber Security standards, regulatory requirements and audits that are not just relevant to finance.
  • Familiar with auditing processes and have participated in both internal and external audits
  • Strong written and verbal communicator who can promote consistent messaging while tailoring information to suit the audience's needs
  • Fluency in English required

Nice to have

  • Experience of working in deeply technical environments often engaging with Software Engineers
  • Have a positive and collaborative attitude
  • Work well with a team, and admit to and learn from mistakes
  • Have a strong desire to grow your technical understanding of technology, cybersecurity and associated risks

What the JD emphasized

  • Cyber Security standards, regulatory requirements and audits that are not just relevant to finance.