IT Security & Controls Senior Analyst role focusing on security posture and compliance requirements. Guiding junior analysts and conducting risk assessments within the financial entity.
Responsibilities
Collaborate at Group level (Ford Motor Company, Ford Motor Credit Company) to continually improve control documents.
Advise Software Engineering teams on meeting their controls responsibilities.
Conduct Security & Risk assessments of Third-party ICT service providers across FCE (IT due diligence reviews).
Identify and report compliance gaps with relevant security regulations and industry standards (e.g., SOX, GDPR, DORA).
Lead on remediation of complex IT Security & Controls related audit findings and control gaps.
Conduct Security & Risk assessments of Third-party ICT service providers.
Requirements
Degree in IT, Cybersecurity, or related field (minimum 2:2 or international equivalent).
Experience in IT Security, with a strong controls mindset and background in system development or management.
Familiarity with SOC 2 Type II, ISO 27001, or similar standards.
Solid understanding of cybersecurity threats, controls, and incident response.
Strong organizational, communication, and documentation skills.
Ability to assess risks and develop practical security solutions.
Certifications such as CRISC, CISM, CISSP, CISA (desirable).
Knowledge of ICT regulations (e.g., DORA, SYSC8, BaFin) (desirable).
Experience in financial services or regulated environments (desirable).
Experience in security awareness and training (desirable).
Benefits
The Company is committed to diversity and equality of opportunity for all and is opposed to any form of less favourable treatment or harassment on the grounds of race, religion or belief, sex, marriage and civil partnership, pregnancy and maternity, age, sexual orientation, gender reassignment or disability
As part of our pre-employment checks process, successful candidates will be required to undergo a criminal record check. This will be conducted in line with the Rehabilitation of Offenders Act 1974 and applied only to unspent convictions.
Security Design Lead in Rabobank's cybersecurity team, designing secure technology solutions for food & agribusiness banking. Collaborating across teams to ensure robust security implementations.
Identity Security Posture Management Specialist enhancing identity security posture at Kemper Insurance. Collaborates across teams to tackle identity risks and compliance challenges in a high - performing culture.
Principal Architect developing cybersecurity strategy for Ensemble's technology - enabled revenue cycle management solutions. Focus on securing cloud architectures and ensuring information assurance in healthcare.
Senior Manager overseeing Security Risk Management at First American. Leading enterprise policies, third - party vendor security, and security strategy execution.
Zscaler Engineer responsible for maintaining cybersecurity tools and developing integrations at HP. Collaborating across teams to enhance data loss prevention strategies and monitor industry threats.
Designer developing comprehensive application solutions for security systems at Johnson Controls. Collaborating on technical sales support and large - scale integrated electronic security systems.
Analyst role supporting Epic Security & Configuration at Acrisure, ensuring application functionality and troubleshooting issues. Collaborating with teams for configuration and security in Applied Epic systems.
Security Detection & Response Engineer for Flutter Entertainment developing security detection frameworks. Collaborating with global teams to enhance cybersecurity operations in complex, multi - cloud environments.
Specialist Software Design Verification Engineer in Cybersecurity at Solventum. Responsible for software verification, testing processes, and compliance with medical device regulations.
Lead defensive threat research on generative and agentic AI systems at RBC. Identify emerging threats and develop proof - of - concept exploits to enhance AI security.