Lloyd’s is the world’s leading insurance and reinsurance marketplace. We share the collective intelligence and risk sharing expertise of the market’s brightest minds, working together for a braver world.
Our role is to inspire courage, so tomorrow’s progress isn’t limited by today’s risks.
Our shared values: we are brave; we are stronger together; we do the right thing; guide what we do and how we act. If you share our values and our passion to build a future that’s more sustainable, resilient and inclusive, you’ll find a home at Lloyd’s – build a braver future with us.
Lloyd’s are seeking to recruit a Head of Information Security Services. You will Safeguard our digital assets, managing security teams and partners, and ensuring compliance with regulatory requirements. As a candidate you should be a highly skilled and experienced Head of Information Security Services and will support the CISO in leading our cybersecurity strategy and operations. This position requires a strategic thinker, operational excellence, and with leadership, technical, and communication skills.
Principal Accountabilities
Strategic Support and Delivery
- Assists the CISO in developing and implementing the organisation’s cyber security strategy
- Prioritise and align security initiatives with business goals and regulatory requirements
Operational Oversight
- Oversees day-to-day security operations, including incident response, threat detection, and vulnerability management. Delivery of continuous improvement across all security domains key performance indicators
- Manage the relationship with and performance of our security partners (Accenture, ReliaQuest, Mandiant)
- Act as the lead for strategic transformational security projects (e.g. Identity and access mgt transformation)
- Coordinates with IT, legal, compliance, and risk teams to ensure security policies are enforced
- Regulatory Compliance for IT and Cyber Security: Meeting regulatory requirements, responding to audits, and ensuring audit actions are completed
- Third-Party Security: Develop and maintain a third-party security assurance framework including completing security checks and risk assessments for third parties
- Information Security Management System (ISMS): Manage and improve the Corporation’s ISMS, maintain ISO27001 certification and prioritise security measures for development and fixing issues
Leadership and Team Management
- Manages security teams and specific functions: Security Operations Centre (SOC), Governance, Risk, and Compliance (GRC), Identity and Access Management (IAM) and Data Protection
- Influences Lloyd’s leadership team to adopt security measures, while also enabling business outcomes
- Represents Lloyd’s in Industry and market collaboration groups, leading improvement initiatives
- Mentors and develops cybersecurity staff, ensuring a talent pipeline for long term succession
Risk Management
- Identifies, assesses, and mitigates cybersecurity risks, working closely with the Risk function
- Supports audits, compliance checks, and risk assessments and ensures appropriate closure of actions
Communication and Reporting
- Acts as a liaison between technical teams and executive leadership
- Prepares reports and presentations on security metrics, incidents, and risk posture – the reports are crisp, concise and compelling resulting in action to improve Lloyd’s security posture
Skills Knowledge and Experience
- Proven track record in information security leadership at a senior level, for a large organisation
- Developing and implementing risk/threat based strategic plans
- Operating security services and improving them over time
- Engaging with regulators and responding to regulatory audits
- Third party security assurance activity
- Performing risk and compliance reviews on systems/processes
- Deep practical knowledge of the people, process, and technology components of Information Security.
- Broad understanding of information technology with depth in at least one domain.
- How different cyber risks can materialise across the layers of defence.
- Passionate about staying abreast of the threat landscape, exploits, attacker tools, techniques and procedures, and latest security technologies.
- Industry frameworks such as NIST Cyber Security Framework, Centre for Internet Security (CIS) Critical Security Controls (CSC), ISO 27001, MITRE ATT&CK, Cyber Kill Chain, etc.
- Technical knowledge of cyber security preventative controls and good practice standards
- Handling multiple projects at once, making the best use of limited resources, and providing clear reports on progress, benefits, and risks
- Building and managing high-performing teams and supporting growth. Motivating people and fostering a culture of openness and responsibility
- Identifying stakeholders and influencing them to improve security, collaboration with Experts: Working well with technical experts and technology leaders
Diversity and inclusion are a focus for us – Lloyd’s aim is to build a diverse, inclusive environment that reflects the global markets we work in. One where everyone is treated with dignity and respect to achieve their full potential. In practice, this means we are positive and inclusive about making workplace adjustments, we offer regular health and wellbeing programmes, diversity and inclusion training, employee networks, mentoring and volunteering opportunities as well as investment into your professional development. You can read more about diversity and inclusion on our website.
We understand that our work/life balance is important to us all and that a hybrid of working from the office and home can offer a great level of flexibility. Flexible working forms part of a total reward approach which offers a host of other benefits over and above the standard offering (generous pension, healthcare, wellbeing etc). These include financial support for training, education & development, a benefit allowance (to spend on our flexible benefits such as gym membership, dental insurance, extra holiday or to partake in our cycle to work scheme), employee recognition scheme and various employee discount schemes.
By choosing Lloyd's, you'll be part of a team that brings together the best minds in the industry, and together with our underwriters and brokers, we create innovative, responsive solutions allowing us to share risk and solve complex problems.
Should you require any additional support with your application, or any adjustments, please click the following link;
https://cleartalents.com/apply/lloyds-msa1645695881
Please note, clicking on this link does not register your application for the vacancy