This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
This role sits within the Second Line of Defence (2LOD) Risk function and provides independent oversight and challenge of Cyber Security risk across Vocalink Mastercard. You will act as a functional risk partner to the First Line of Defence Cyber Security function, ensuring robust risk management practices are embedded and aligned with regulatory expectations and industry best practice. The role supports the delivery of a secure and resilient service to millions of citizens and businesses, safeguarding critical payment infrastructure and data assets. You will champion cyber security and resilience risk internally and at senior management level, helping to maintain trust in the UK financial system.
Job Responsibility:
Provide second line expertise and challenge around all aspects of Cyber Security related risks
Support the Vocalink risk management approach and implemented policies and procedures to minimize Cyber Security risk exposure and drive robust controls
Support the implementation and embedding of the Enterprise Risk Management Framework for Cyber Security risk, ensuring completeness and accuracy of risk assessments, control standards, residual risk evaluations, and issue management
Partner with first line Cyber Security teams to promote balanced risk-taking and a strong risk culture
Represent Cyber Security risk at relevant committees and forums, deputising for the VP Risk Management when required
Provide clear and concise risk briefings to senior stakeholders, including the CRO ensuring timely escalation of material risks and appetite breaches
Liaise with and support the risk and control owners to resolve any questions, queries and challenges relating to cyber security relevant certification and or customer requirements for example, during an audit as well as in the pre and post audit stages
Requirements:
Professional cyber security certifications (e.g., CRISC, CISA, CISM, CISSP, ISO 27001 Lead Auditor) preferred
Knowledge of key cyber security relevant control domains, frameworks and standards (e.g., NIST, ISO27001, CSF, CRI, MITRE, etc.)
Strong understanding of risk management principles and the Three Lines of Defence model
Enthusiastic about cyber security including tracking industry trends and emerging risks
Experience of applying operational risk frameworks and understanding of risk assessment methodologies
Proven experience in Cyber Security risk and controls oversight within a financial institution or critical infrastructure environment
Ability to analyse complex data with attention to detail and articulate risk insights clearly to technical and non-technical audiences
Skilled in building trusted relationships with stakeholders at all levels
Highly organised, adaptable, and able to work independently with minimal supervision and as part of a team
Excellent written and verbal communication skills
Nice to have:
Experience within Critical National Infrastructure responsible organisations
Financial Services experience particularly in payments and relevant infrastructure
Experience working with regulators (Bank of England supervision)