le Summary:
- Supports the development and maintenance of robust control frameworks and a unified Technology & Cyber Security Control library.
- Helps implement process control monitoring capabilities to oversee control execution across Engineering.
- Contributes to driving a positive risk culture within Engineering by implementing processes for control effectiveness demonstration.
- Requires organised, methodical thinking with strong attention to detail for creating control test plans and documentation.
What you’ll be doing:
- Control Library Management: Maintain and regularly update the centralised Technology & Cyber Security control library, ensuring controls align with industry frameworks (NIST, ISO, COBIT) and regulatory requirements (e.g. DORA). Help translate complex framework/regulatory requirements into clear, actionable controls.
- Control Testing: Conduct Tests of Design Assurance and Operating Effectiveness Assurance for key controls at both group and divisional levels, providing critical support for Group Engineering, Risk & Control Assessments. Document test results and identify areas for improvement.
- Evidence Management: Establish and oversee processes to ensure control evidence is properly documented, stored, and accessible at required frequencies. Create standardised templates for evidence collection to improve consistency. Review monitoring results for completeness and accuracy, driving corrective actions as needed. Thoroughly review monitoring results for completeness and accuracy, challenging questionable evidence and driving corrective actions with Self-Identified Issues( SIIs) when deficiencies are identified.
- Assurance Coordination: Plan and coordinate periodic independent assurance activities with internal audit teams and external assessors, preparing documentation and facilitating access to evidence.
- Key Control Indicators (KCIs): Implement, track, and analyse Key Control Indicators (KCIs) aligned to the control library, helping to identify trends and potential weaknesses before they impact operations.
- Reporting & Visualisation: Maintain detailed control performance dashboards and metrics that clearly communicate control status to various stakeholders, from technical teams to executive leadership. Perform sample-based testing of control operating effectiveness.
- Remediation Management: Identify thematic control weaknesses and collaborate with control/process owners to develop and implement effective remediation strategies with clear timelines and accountability. Represent Engineering in risk discussions with internal stakeholders.
- Stakeholder Engagement: Represent Technology Controls Governance team in risk discussions with internal stakeholders, translating Enterprise Risk Management Framework (ERMF) concepts into Group Engineering consumable material.
Qualifications
- Relevant degree in IT, Cybersecurity or Risk Management (Desirable).
- 3+ years’ experience in technology controls or compliance.
- Strong knowledge of control frameworks (NIST, ISO, COBIT).
- Demonstrable knowledge of key controls across Technology process areas (e.g. incident, Change, Capacity management).
- Experience in control implementation across Technology process areas.
- Experience in control testing and evidence validation.
- Proven team management and project delivery skills.
- Excellent analytical, communication abilities and presentation skills.
- Experience with GRC tools and control automation.
LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.
Our purpose is the foundation on which our culture is built. Our values of
Integrity, Partnership,
Excellence and
Change underpin our purpose and set the standard for everything we do, every day. They go to the heart of who we are and guide our decision making and everyday actions.
Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce. You will be part of a collaborative and creative culture where we encourage new ideas and are committed to sustainability across our global business. You will experience the critical role we have in helping to re-engineer the financial ecosystem to support and drive sustainable economic growth. Together, we are aiming to achieve this growth by accelerating the just transition to net zero, enabling growth of the green economy and creating inclusive economic opportunity.
LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.
We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyone’s race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.
Please take a moment to read this privacy notice carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what it’s used for, and how it’s obtained, your rights and how to contact us as a data subject.
If you are submitting as a Recruitment Agency Partner, it is essential and your responsibility to ensure that candidates applying to LSEG are aware of this privacy notice.