Director, Internal Audit (Information Security)
About CLS:
CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars’ worth of currency flows through our systems each day.
Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies. We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use.
CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market.
Our ambition to make a positive difference starts with our people. Our values – Protect, Improve, Grow – underpin everything that we do at CLS and define and shape a supportive and inclusive working environment in which everyone is encouraged to be open and forward-thinking
Job information:
- Functional title - Internal Audit (Information Security)
- Department - Internal Audit
- Corporate level - Director
- Report to - Director, Internal Audit (Information Security)
- Location - London, on-site 2 days per week
Job Purpose:
CLS Internal Audit (IA) is an independent function. The Chief Internal Auditor (CIA) reports functionally to the Chairman of the Audit & Finance Committee and administratively to the Chief Executive Officer. The IA team provides a comprehensive audit service to the CLS Group of Companies and controls advice to the Board and senior management.
The Director will support the Executive Director in providing risk-based integrated audit coverage and independent assessment of the effectiveness of key applications, projects, and related IT controls and risks across CLS. IA's ways of working reflect the requirements of CLS's designation as a Systemically Important Financial Market Utility (SIFMU). The requirements of the Audit Plan are diverse and challenging. The Director will be primarily focused on leading and overseeing a portfolio of audits, continuous monitoring. It is important that the Director be versatile and flexible in working in a team on a larger/complex audit, as line managing and guiding a small team. Importantly, the Director will be expected to have a good understanding of financial services business practices and will be able to contribute to integrated audits of CLS’s various business divisions.
Essential Functions:
Stakeholder Management / Strategic: (20%)
- Perform continuous monitoring of the business, under the direction of the Executive Director, to identify emerging risks and issues and report to audit management and the Audit & Finance Committee.
- Communicating audit work overseen and managed to regulators and executive management.
- Develop and maintain working relationships with all levels of management and external parties.
- To monitor strategic developments within CLS and highlight any unidentified risks or potential control issues.
Audit Delivery Management: (50%)
- Manage the development of the annual Audit Plan (for their respective portfolio) based on an assessment of the key risks within CLS and continuous review of risks to ensure the plan is amended where appropriate.
- Oversee and manage independent validation to confirm management’s remediation of audit and regulatory issues.
- Responsible for managing the planning and execution of complex audits and high-level reviews.
- Oversee and prioritize audit delivery across a portfolio of audits.
- Lead complex, non-routine, and cross-functional activities to support senior management in improving the departmental processes.
- Provide timely progress updates within the reporting system and to the Executive Director.
- Assist the wider Internal Audit Division in areas of Information Security, including participating in integrated audits, providing Subject Matter Expertise (SME) in planning activities, and knowledge sharing.
People Management: (25%)
- Manage direct reports, or other members of the Internal Audit team (including co-source and SME resources), for the applicable portfolio audits.
- Performance management of direct reports (including coaching and performance reviews)
- Recruitment and retention of talent.
Professional Development (5%)
- Proactively maintain knowledge, skills and disciplines, with on-going professional development.
- Identify and share useful learning opportunities for other Internal Audit team members.
- Maintain the professional standard of the Internal Audit function and work within its agreed Terms of Reference and IIA standards/guidelines, Charter and Mandate.
- Demonstrate adaptability to ensure that the audit focus is maintained on key issues, under the guidance of audit senior management.
Knowledge, Skills, and Abilities:
- Extensive experience working within Internal Audit in a financial services environment (ideally banking) and audit experience across a range of different information technology in a financial institution.
- Ability to provide technical Subject Matter Expertise during integrated audits.
- Strong analytical skills.
- Experience of dealing with all levels of management.
- Excellent communication skills, both written and verbal.
- Experience and understanding of regulatory requirements, e.g., FRBNY, FCA.
- Strong IT security and technical knowledge with approximately 10+ years of experience within the industry.
- Working experience with common security/technology risk frameworks, for instance, ISO 27000, NIST, CIS Critical Security Controls, Cloud Controls Matrix, COBIT, and IIA GTAGs.
- Working experience with regulatory standards / requirements (US, UK) i.e., GDPR, BCBS 239, FFIEC 101, 3402, CHAP.
- Working experience and/or knowledge of Security domains including Access management, Threat management, Incident response and recovery, Data protection, Vulnerability management, Monitoring and logging, Physical security, and Security risk management and governance.
- Working experience and/or knowledge of Cloud, Block chain, high volume transaction systems.
- Working experience and/or knowledge of application controls, input/output, configuration, application controls.
- Working experience and/or knowledge middleware, networks, operating systems, databases (Unix, Windows, AIX, DB2, Citrix).
- Working experience and/or knowledge of data analytics/ predictive analytics, data governance.
- Understand policy/directives, and ability to assess risks across all types of IT systems and operations.
Essential Qualifications:
- Degree level education (desirable) - Bachelors degree in computer science, computer engineering, information technology, or related field of study.
- Audit certifications (required) - CISA, CISM, or CISSP
- Audit certifications (desirable) - CMIIA (UK), CIA (US), CGEIT, CompTIA, SANS, ISC2, Prince2, Agile etc.
Success Factors:
- Must be a strong team player, able to integrate and work alongside a diverse team of professionals to drive team success.
- Confident in managing integrated and non-integrated audits, and leading other audit team members.
- Excellent interpersonal and communications skills (verbal and written), including the ability to deliver challenging messages at all levels of management.
- Must be able to work independently on projects without assistance.
- Proactive, self-motivated - ability to plan, organise, perform, and manage work with minimal supervision.
- Results oriented – able to deliver high quality results in an environment of changing demands, variable workloads, and tight timescales.
- Ability to engage stakeholders.
- Innovative problem-solving approach. Able to think on a broad scale about issues affecting the company, not just those related to IA or the control environment.
- Able to interpret internal and external issues and recommend solutions/best practices.
Our commitment to employees:
We are a small company with a big mandate, so every person is essential to our success. We are also committed to employing and retaining the most talented and dedicated people.
What makes us interesting goes beyond our competitive salaries and great benefits. Our work environment is designed around quality outcomes, not output. The FX market would cease to function without our services, and we take pride in being responsible for keeping it running smoothly.
We are different from other financial institutions in that we have a flatter and more transparent structure with accessible leadership. You will be seen, heard and empowered to develop your career.
We are a purpose-driven organization, with an inclusive culture that focuses on doing what is right. The well-being of our people is as important to us as the resilience of our systems. In addition to encouraging our people to ‘locate for their day,’ we run a range of initiatives that support employees’ sense of belonging and physical, emotional and mental well-being.
Our extensive benefits for employees typically include:
- Vacation/annual leave: 25 days in UK/Asia + 3 life days, 23 in US + 3 life days
- Private medical and dental cover and life insurance
- Generous pension contributions in the UK and Asia; matching 401(k) in the US
- Paid volunteer days
- ‘Locate for your day’ hybrid working – 2 days a week in office.
- Access to Discover – our learning platform with 1000+ courses from LinkedIn Learning.
- Paid parental leave / Coaching and support services
- Career development / LinkedIn Learning
- ‘Heads down days’ with no meetings on the last Friday of every month
- Wellbeing / Mental health support
- Diversity Council / Affinity groups (Women’s Forum, Black Employee Network, Pride Network, Parents & Caregivers Network, Sustainability Network)
- Social events
Awards:
- The Sunday Times Best Places to Work 2023 & 2024 / Big Company / The Sunday Times Awards
- Third place in Britain’s Healthiest Workplace 2022 / Medium Company / Vitality Awards