Information Security Governance, Risk, and Compliance (GRC) Specialist at Janus Henderson | GB | Rezi

Information Security Governance, Risk, and Compliance (GRC) Specialist at Janus Henderson

Information Security Governance, Risk, and Compliance (GRC) Specialist

Janus Henderson · GB

1 months ago

Information Security Governance, Risk, and Compliance (GRC) Specialist

Janus Henderson · GB

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Information Security Governance, Risk, and Compliance (GRC) Specialist role.

Rezi rewrites your resume against Janus Henderson's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Information Security Governance, Risk, and Compliance (GRC) Specialist posting at Janus Henderson — free, in seconds.

About the Role

A career at Janus Henderson is about investing in a brighter future together. Our mission is to help clients define and achieve superior financial outcomes through differentiated insights, disciplined investments, and world-class service. We will do this by protecting and growing our core business, amplifying our strengths and diversifying where we have the right.

Responsibilities

  • Develop and maintain comprehensive cybersecurity policies and procedures.
  • Ensure policies align with industry standards and regulatory requirements.
  • Assist in integrating security practices and controls across technical and non-technical departments.
  • Conduct regular risk assessments to identify vulnerabilities and threats.
  • Collaborate and oversee the implementation of risk mitigation strategies.
  • Monitor emerging threats and evolving technologies to refine risk assessment protocols.
  • Design and evaluate control metrics for assessing cybersecurity measure effectiveness.
  • Collaborate with Enterprise Risk Management to embed cyber risk into broader risk registers and board-level reporting.
  • Monitor and ensure compliance with internal policies, industry standards, and regulatory requirements.
  • Engage with stakeholders in Technology, Legal, Compliance, and Internal Audit.
  • Compile and deliver detailed compliance reports to senior management.
  • Monitor upcoming regulations and prepare compliance roadmaps.
  • Support and enhance cybersecurity awareness training programs.
  • Foster a company-wide culture of cybersecurity awareness.
  • Keep current with the latest cybersecurity trends and best practices.
  • Train and guide wider Tech team members on best practices in cybersecurity risk management.
  • Actively participate in the response to security incidents.
  • Support post-incident evaluations and reporting.
  • Collaborate with stakeholders to devise and enforce corrective measures.
  • Maintain clear and effective communication with stakeholders at all levels.
  • Provide expert guidance on cybersecurity best practices.
  • Work collaboratively with Technology and other departments to achieve comprehensive security objectives.

Requirements

  • Bachelor’s Degree in Information Technology, Cybersecurity, or a related field; equivalent work experience also considered.
  • 3 to 5 years of professional experience in information security.
  • Certification such as Certified Information Systems Security Professional (CISSP) strongly preferred.
  • Deep understanding of cybersecurity principles, frameworks (such as NIST, ISO/IEC 27001), and compliance standards.
  • Experience with financial service regulations and regulations such as FCA, SEC, MAS, DORA.
  • Proficient knowledge of network security principles and controls such as Firewalls, IPS/IPD, TCP/IP, DHCP, and DNS.
  • Extensive experience in securing Operating Systems such as Windows, UNIX/Linux and Mac systems, including security access rights and configuration best practices.
  • Knowledge of cloud service models (IaaS, PaaS, SaaS) and deployment models (public, private, hybrid, community) and experience in implementing and managing cloud security best practices.
  • In-depth knowledge of IAM principles and technologies to manage digital identities and control user access.
  • Experience with Single Sign-On (SSO), Multi-Factor Authentication (MFA), and role-based access control (RBAC) systems.
  • Understanding of Secure DevOps / CI/CD pipeline governance.
  • Must understand regulatory obligations and abide by regulated entity requirements and JHI policies applicable for the role.
  • Must be willing to comply with Janus Henderson Investment Advisory Code of Ethics related to personal securities activities and other disclosure and certification requirements.
  • Applicants' past political contributions or activity may impact eligibility for this position.
  • All applications are subject to background checks.

Skills

  • Cybersecurity policies and procedures
  • Risk assessments
  • Risk mitigation strategies
  • Cybersecurity compliance
  • Cybersecurity awareness training
  • Incident response
  • Stakeholder communication
  • NIST
  • ISO/IEC 27001
  • FCA
  • SEC
  • MAS
  • DORA
  • Firewalls
  • IPS/IPD
  • TCP/IP
  • DHCP
  • DNS
  • Windows security
  • UNIX/Linux security
  • Mac systems security
  • Cloud security best practices
  • IAM principles
  • SSO
  • MFA
  • RBAC
  • Secure DevOps
  • CI/CD pipeline governance

Location

  • Remote
  • Hybrid

Work Type

  • Hybrid

Experience Level

  • 3 to 5 years of professional experience in information security

Education Level

  • Bachelor’s Degree in Information Technology, Cybersecurity, or a related field

Benefits

  • Hybrid working environment

About the Company

  • Janus Henderson Investors is committed to an inclusive and supportive environment.
  • We believe diversity improves results and we welcome applications from candidates from all backgrounds.
  • Janus Henderson (including its subsidiaries) will not maintain existing or sponsor new industry registrations or licenses where not supported by an employee’s job functions.

Equal Opportunity

  • Janus Henderson is an equal opportunity /Affirmative Action employer.
  • All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.