img
Permanent

Vice President, Vulnerability Management

London
money-bag Negotiable
90E2372F32192004FF2DC0CDC1ADAC29
Posted Yesterday

Vice President, Vulnerability ManagementAbout CLS:

CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars’ worth of currency flows through our systems each day.

Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies. We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use.

CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market.

Our ambition to make a positive difference starts with our people. Our values – Protect, Improve, Grow – underpin everything that we do at CLS and define and shape a supportive and inclusive working environment in which everyone is encouraged to be open and forward-thinking

Job information:

Functional title - Vulnerability Management

Department – IT Security

Report to - Director

What you will be doing:

SME Consultancy :

As part of the IT Security team, develop and implement CLS IT Strategy in consultation with the CLS IT teams, ensuring that all initiatives are mirrored in respective strategies including the overall CLS Strategy

Provide security advice and support for information technology projects as Vulnerability Management subject matter expert (SME)

Research new security related products and services to ensure that CLS is equipped with appropriate industry best tools and solutions

Vulnerability Management :

Subject Matter Expert (SME) for vulnerability management within the Security Operations Department.

Manage vulnerability management platforms, including configuration, tuning, connectors, and coverage.

Coordinate with engineering, infrastructure and application development teams to track SLA attainment and escalate blockers.

Apply threat-based prioritization using CVSS, threat intelligence, exploitability data, KEV lists, and business context.

Coordinate the response to high profile vulnerabilities, including zero-days and critical CVEs with impact analysis and action plans.

Produce weekly and monthly reporting on trends, KRIs, KPIs, backlog health, and risk posture for senior audiences.

Execute governance for exception handling and risk acceptance in line with policy. Maintain the exception register and review cadence.

Manage the remediation backlog, change windows, and patch orchestration to meet SLAs.

Lead, coach, and grow a team of analysists, engineers, and program managers.

Support audits and evidence collection for standards and frameworks such as NIST CSF and ISO 27001.

Manage vendor relationships, licensing, and tool roadmaps in coordination with the Director.

Regulatory Compliance and Reporting :

Ensure vulnerability management efforts and documentation comply with industry standards and best practices (GDPR, SOC, NIST, ISO etc.)

Maintain detailed documentation and reporting for audits and compliance reviews.

Process Improvement and Risk Mitigation:

Develop and refine vulnerability management standard operating procedures and playbooks.

Recommend and implement process improvements to enhance vulnerability management capabilities.

Operational :

Operate and maintain controls related to vulnerability management.

Conduct vulnerability management risk assessments for all high impact projects, defining security mitigating controls that impact the technology architectures of CLS, service providers, and business partners

Review and update vulnerability management procedures to reflect best practice and mitigate current and emerging threats

Assigned ownership of vulnerability management related FRB and Internal Audit finding(s) and effect timely resolution

Maintain relationships with third-party vulnerability management vendors and strategic partners

What we’re looking for:

‘Hands-on’ vulnerability management experience

Ensure a risk-based approach to vulnerability management is adopted in every part of the business and solutions

Work with members of the IT Security team to help design, implement and maintain security

Operate and maintain IT Security controls related to Vulnerability Management

Deliver vulnerability management projects from concept, approval, design, and implementation to operation

Ability to collaborate effectively with others to drive forward key security objectives

Strong documentation and report writing skills (to both technical and business audiences)

Excellent time management and organizational skills combined with technical vulnerability management acumen

Financial and/or Banking industry experience preferred

Qualifications / certifications:

Technology discipline (Computer Science, Computer Engineering, Cybersecurity or equivalent)

10+ Years of experience within the cybersecurity industry with 5+ years in specific vulnerability management roles

Security certifications such as CISSP, CISM, OSCP, GIAC GSEC, GEVA or equivalent is preferred

Proven success operating a mature vulnerability management program at scale

Strong understanding of scanning technologies, CVSS, and threat modelling

Familiarity with compliance frameworks and standards such as NIST and ISO

Experience managing technical teams and working cross-functionally with non-security stakeholders

Experience integrating vulnerability management with ticketing and asset management tools

Clear communicator who can brief executives and drive action

Our commitment to employees:We are a small company with a big mandate, so every person is essential to our success. We are also committed to employing and retaining the most talented and dedicated people.

What makes us interesting goes beyond our competitive salaries and great benefits. Our work environment is designed around quality outcomes, not output. The FX market would cease to function without our services, and we take pride in being responsible for keeping it running smoothly.

We are different from other financial institutions in that we have a flatter and more transparent structure with accessible leadership. You will be seen, heard and empowered to develop your career.

We are a purpose-driven organization, with an inclusive culture that focuses on doing what is right. The well-being of our people is as important to us as the resilience of our systems. In addition to encouraging our people to ‘locate for their day,’ we run a range of initiatives that support employees’ sense of belonging and physical, emotional and mental well-being.

Our extensive benefits for employees typically include:

Vacation/annual leave: 25 days in UK/Asia + 3 life days, 23 in US + 3 life days

Private medical and dental cover and life insurance

Generous pension contributions in the UK and Asia; matching 401(k) in the US

‘Locate for your day’ hybrid working – 2 days a week in office.

Access to Discover – our learning platform with 1000+ courses from LinkedIn Learning.

Paid parental leave / Coaching and support services

‘Heads down days’ with no meetings on the last Friday of every month

Diversity Council / Affinity groups (Women’s Forum, Black Employee Network, Pride Network, Parents and Caregivers Network, Sustainability Network)

Social events

Awards:

The Sunday Times Best Places to Work 2023 and 2024 / Big Company / The Sunday Times Awards

Third place in Britain’s Healthiest Workplace 2022 / Medium Company / Vitality Awards

Seniority level

Mid-Senior level

Employment type

Full-time

Job function

Information Technology

Industries

Financial Services, Banking, and Investment Banking

#J-18808-Ljbffr

Other jobs of interest...

Perform a fresh search...

  • Create your ideal job search criteria by
    completing our quick and simple form and
    receive daily job alerts tailored to you!

Jobs. Straight to your inbox!