Product Risk Assessment Lead - Cyber & Tech Risk (PL)
Role: Product Risk Assessment Lead - Cyber & Tech Risk (PL) Grade: GG14 Profile: People Leader Application Health (AppHealth) is a new initiative to provide greater visibility and assessment to the Cyber and Technology Risk aspects of LSEG’s in-service application estate. This new role will be the Product Owner for AppHealth; including holding the vision, and driving the development of the Product and the overall capability, in conjunction with adjacent teams who deliver the engineering solution and the accompanying service provision. This initiative is currently in the early stages of development after successful proofs of concept, with a defined future demand and enhancement runway and emerging target operating model. This includes both technology and greater alignment with the Group’s corporate planning function; providing insight and feedback on targeted risk reduction activity. This role is within a broader Security Architecture team comprising both Secure Design and the Cyber Third Party Risk Management (TPRM) groups. Other teams within the Security Architecture function work with engineering teams; with a separate group delivering a formal control function for Security Architecture. An element of this role is to assist with connecting the outputs and outcomes of Application Health with these teams to enhance the Group’s overall security and technology risk posture. Reports to: Director - Security Architecture Key Relationships & Committees
- Head of Cyber & Technology Risk GRC (and team)
- Business Information Security Officers
- Security Domain Forum and other relevant Domain Fora
- Business Aligned Principal Security Architects
- Security Architecture Review Team
- CyberSecurity Engineering
- CyberSecurity Application Security Team
- Cloud Security Architecture
- Various cloud Communities of Practice
- Be the Product Owner for AppHealth and be the focal point for the overall vision and direction.
- Align the question set/responses, compliance and scoring capabilities, function, outcomes and robustness of AppHealth with the requirements of Key Controls managed by the Cyber GRC function, and align with other Group requirements such as uplift programme spend
- Seek, prioritise and act appropriately upon feedback provided on AppHealth; maintain appropriate traceability and progress tracking
- Be the go-to person for AppHealth, comfortable with speaking and presenting to a range of stakeholders from Application Owners through to senior Engineering leaders, and their teams.
- Drive the definition and delivery of the service provision accompanying AppHealth – working with accompanying teams to maximise effectiveness and efficiency of provision
- Develop appropriate, relevant documentation, for AppHealth’s broad range of stakeholders.
- Engage with Application Owners and their teams, Operational and Architecture leads, the BISO community to communicate the outcomes of AppHealth.
- Nurture technical practices in order to deliver technical excellence
- Foster and support experimentation and innovation in solving problems
- Manage third parties in their deliveries related to the domain area, as required
- Finances for the function and any product or services are accurately budgeted for and managed
- Provides company representation, internally and externally, related to the role, as needed.
- People Leadership of a small team outside the UK – anticipated to be around 2-3 people
- Line management of team members, throughout the AppHealth lifecycle – onboarding, assessment, results, reporting etc.
- Working to resolve challenges encountered by the team.
- Ensure correct resources allocated to deliver the function – working in conjunction with other managers within the Cyber and Technology Risk function.
- Build the AppHealth capability into the solution for the DORA periodic assessment requirement
- Build the service provision for AppHealth to support and accompany the software capability, including the correct level of assessment/assurance resulting from AppHealth survey submissions
- Developing and publishing core metrics for the AppHealth function and the outcomes of AppHealth surveys; providing appropriate output metrics to divisionally aligned engineering teams.
- Represent AppHealth and its results to senior stakeholders.
- 7+ years of increasing responsibility in technical engineering or cyber security/technology risk roles, with an emphasis on cyber security experience.
- Proven experience in assessing and applying security controls into distributed systems (on premises and cloud)
- Thorough understanding of the latest security principles, risk mitigation techniques and protocols
- Able to determine how to pragmatically measure qualitative outcomes, and determine appropriate ranking and relevance to the Group
- Critical thinker
- Problem solving skills, ability to work under pressure and self-starter
- Applied understanding of topics such as authentication, access control, encryption, cloud security, operating system security, network security, database security.
- Experience in working across organisational boundaries to deliver Group-wide outcomes
- Experience with specialist individual contributors in technology domains.
- Inspiring and empowering a matrix team in the delivery of outcomes.
- Experience in working with remote team members
- Must have a collaborative work style ensuring that stakeholders are engaged in decision making processes.
- Highly adaptable and able to approach challenges differently to achieve goals.
- Must have a collaborative work style ensuring that stakeholders are engaged in decision making processes.