
Posted 15 days ago
No clicks
**Information Security Officer – Cyber Risk & Governance** Support LCH's BISO in safeguarding business services, systems, and data assets. Key responsibilities include overseeing InfoSec and cyber controls, reviewing control effectiveness, tracking remediation, and applying cyber, technology, and risk domain knowledge. Requires experienced InfoSec professional with FS/FMI background, strong technical expertise, and stakeholder engagement skills. Ideal candidate maintains relevant certifications (CISSP, CISM) and understands NIST, SOC 2, CBEST/TIBER-EU.
- Compensation
- Not specified
- City
- Not specified
- Country
- United Kingdom
Currency: Not specified
Full Job Description
The purpose of this role is to support the Director of Business Information Security (BISO) in the oversight of Information Security across LCH.
The role contributes to ensuring that LCHs critical business services, systems, and data assets are adequately protected, that information security and cyber controls are effective and operating within defined risk appetite, and that any identified gaps have appropriate and proportionate risk treatment plans in place.
The role will best suit an experienced Information Security Professional with experience gained from having previously operated within InfoSec/Cyber roles within the FS or FMI industries. The successful candidate must have subject matter expertise in Information Security, as the role demands a strong knowledge in all areas of information security and cyber security, as well as in-depth knowledge of legacy, existing, and emerging technologies including cloud and security technologies/controls. In addition, a prior background in information security engineering, security architecture, and security operations will be advantageous in this role given the various levels of stakeholders as well as the tech/cyber projects that the successful candidate will engage with daily.
Enter the key responsibilities of the role:
Information Security & Cyber Oversight
Support the oversight of Information Security and Cyber Security controls that enable LCH to operate securely and resiliently.
Review and assess the design and operational effectiveness of security controls, identifying gaps, weaknesses, and improvement opportunities.
Support the tracking, reporting, and followup of InfoSec and Cyber risk remediation actions.
Monitor cyberrelated roadmaps, programmes, and initiatives impacting LCH, identifying risks, dependencies, and areas requiring escalation.
Cyber & Technology Domain Knowledge
Apply strong cyber and technology domain knowledge to understand, assess, and articulate security risks and control effectiveness across:
Identity & Access Management (IAM) and Privileged Access Management (PAM)
Infrastructure and platform technologies, including virtualised environments
Vulnerability management tooling, prioritisation, and remediation approaches
Cloud and SaaS security concepts, including shared responsibility models
Secure Development Lifecycle (SDLC) principles and application security fundamentals
Use this knowledge to engage credibly with technical specialists and translate technical issues into clear, riskbased insights for stakeholders.
Vulnerability & Risk Remediation
Review vulnerability and security findings from enterprise tooling, dashboards, and assurance activities.
Analyse trends and systemic risk themes across vulnerability and control findings.
Coordinate with technology and engineering teams to support timely remediation of vulnerabilities, tracking progress and escalating delays or constraints as required.
Support riskbased remediation and risk acceptance decisions in line with LCH and LSEG risk appetite.
Governance, Risk & Reporting
Contribute to risk, security, and governance forums by providing accurate, evidencebased updates on cyber risk posture, remediation progress, and control effectiveness.
Work with colleagues across the first, second, and third lines of defence to support a consistent and wellunderstood cyber risk posture for LCH.
Support the development and maintenance of the LCH Cyber Risk Profile.
Assist with Risk & Control Assessments (RCA) covering InfoSec and Cyber risks.
Maintain key risk and performance indicators, ensuring management information accurately reflects the current control environment.
Engagement with the Business
Develop and maintain a strong understanding of LCH business services, objectives, and operational risks, and how these influence cyber and information security risk.
Identify key areas for improvement across cyber risk, control effectiveness, and governance.
Support risk management decisionmaking, including contributions to relevant risk forums and governance committees.
Assist with the identification of emerging cyber and information security threats, supporting analysis and mitigation planning.
Build effective relationships across the business to gain a clear understanding of securityrelated risks and priorities.
Work closely with stakeholders across the three lines of defence on information security, cyber risk, and data privacy matters, including regulatory and legislative considerations.
Stakeholder & ThirdParty Engagement
Work closely with LCH technology and cyber teams delivering infrastructure, platform, and application services.
Engage with internal thirdparty oversight functions to support assurance over suppliers and service providers.
Maintain effective working relationships with risk, compliance, legal, and audit functions.
Executive Communication
Prepare and maintain clear, accurate executivelevel materials that reflect the current security posture of LCH.
Develop briefing papers, management updates, and presentations for senior stakeholders and governance committees.
Confidently support senior leaders by stepping in to represent the function when required, delivering updates with minimal oversight.
Communicate complex cyber risk matters in a clear, concise, and regulatorappropriate manner.
Knowledge of Technology, Security & Threat Landscapes
Maintain awareness of emerging technologies and relevant security capabilities.
Sustain a strong working understanding of the cyber threat landscape, particularly as it applies to Financial Market Infrastructure (FMI) organisations.
Continuously develop knowledge of evolving cyber and information security risks.
Contribute to the articulation of appropriate cyber risk mitigations, explaining effectiveness and limitations clearly.
Maintain awareness of key global data protection and privacy regulations relevant to LCH.
Operates with a high degree of autonomy, managing responsibilities with minimal daytoday supervision.
Brings a strong learning mindset and proactive attitude, actively seeking to broaden capability across cyber risk, controls, governance, and regulation.
Enter the essential experience and skills required:
Experience in Information Security, Cyber Risk, Technology Risk, or Security Governance roles.
Strong conceptual knowledge of:
IAM / PAM
Infrastructure and platform technologies
Vulnerability management
Cloud and SaaS security concepts
SDLC principles
Experience working with risk, controls, and governance processes.
Excellent written and verbal communication skills.
Ability to operate independently and prioritise effectively.
Desirable & Advantageous Certifications
CISSP
CISM
CCSP
Working Knowledge of Security Standards & Frameworks
NIST Cyber Security Framework
SOC 2
CBEST / TIBEREU
Career Stage:
Senior AssociateLondon Stock Exchange Group (LSEG) Information:
Join us and be part of a team that values innovation, quality, and continuous improvement. If you're ready to take your career to the next level and make a significant impact, we'd love to hear from you.
LSEG is a leading global financial markets infrastructure and data provider. Our purpose is driving financial stability, empowering economies and enabling customers to create sustainable growth.
Our purpose is the foundation on which our culture is built. Our values of Integrity, Partnership, Excellence and Change underpin our purpose and set the standard for everything we do, every day. They go to the heart of who we are and guide our decision making and everyday actions.
Working with us means that you will be part of a dynamic organisation of 25,000 people across 65 countries. However, we will value your individuality and enable you to bring your true self to work so you can help enrich our diverse workforce.
We are proud to be an equal opportunities employer. This means that we do not discriminate on the basis of anyones race, religion, colour, national origin, gender, sexual orientation, gender identity, gender expression, age, marital status, veteran status, pregnancy or disability, or any other basis protected under applicable law. Conforming with applicable law, we can reasonably accommodate applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs.
You will be part of a collaborative and creative culture where we encourage new ideas. We are committed to sustainability across our global business and we are proud to partner with our customers to help them meet their sustainability objectives. Our charity, the LSEG Foundation provides charitable grants to community groups that help people access economic opportunities and build a secure future with financial independence. Colleagues can get involved through fundraising and volunteering.
LSEG offers a range of tailored benefits and support, including healthcare, retirement planning, paid volunteering days and wellbeing initiatives.
Please take a moment to read this privacy notice carefully, as it describes what personal information London Stock Exchange Group (LSEG) (we) may hold about you, what its used for, and how its obtained, your rights and how to contact us as a data subject.
If you are submitting as a Recruitment Agency Partner, it is essential and your responsibility to ensure that candidates applying to LSEG are aware of this privacy notice.
Location: London, United Kingdom
Time Type: Full time





