Skip to main content
AfterDuty

Information Security Officer - Post Trade, LCH Ltd

LSEG · London, Greater London

Type
Full-time
Posted
4 days ago

Overview

Your security governance and risk assessment skills from policing transfer, but this senior FS role demands deep technical cyber expertise.

About this role

The purpose of this role is to assist the Director of Business Information Security (BISO) in all security matters relating to the oversight of Information and Cyber Security within the LCH Ltd. business line of LSEG’s Post Trade division. The successful candidate will be charged with ensuring that the critical business systems and data assets of LCH Ltd. are adequately protected, and that all related information security and cyber controls remain effective and within risk appetite and/or have appropriate risk treatment plans in place to bring them back into risk appetite.

The role will best suit an experienced Information Security Manager with extensive experience gained from having previously operated within Senior Management level InfoSec/Cyber roles within the FS or FMI industries.

The successful candidate must be a subject matter expert in Information Security, as the role demands a very strong knowledge in all areas of information security and cyber security, as well as in-depth knowledge of legacy, existing, and emerging technologies including cloud and security technologies/controls. In addition to a solid Security Governance Risk and Compliance (Security-GRC) skillset, a prior background in information security engineering, vulnerability management, security architecture, and security operations will be advantageous in this role given the various levels of stakeholders as well as the tech/cyber projects that the successful candidate will engage with daily.

Key responsibilities include

  • Assisting in the oversight of Information Security by:
  • Reviewing and assessing the information security and cyber controls that enable LCH Ltd. to conduct its business in a secure manner, and gap analysis of the same.
  • The oversight of InfoSec/Cyber related control gap/risk remediation activities
  • Monitoring and analysing the information security roadmaps, strategies, programmes, and projects within LCH Ltd., and identifying and reporting risks, trends and future opportunities for improvement and enhancement.
  • Proactively engaging and working closely with the technology and cyber teams that are delivering technology and cyber services to the firm.
  • Attending risk and governance meetings to provide updates to the LCH Ltd. stakeholders from the three lines of defence regarding the delivery and progress of the various strategic cyber initiatives and broader cyber programme within LSEG.
  • Working with colleagues from the three lines of defence to define the current risk posture of LCH Ltd. and collaborating with those stakeholders to remediate identified risks/issues.
  • Engaging with external third parties who provide services to LCH Ltd. and working closely with the established internal third-party oversight functions to ensure appropriate and contracted levels of security are met.
  • Establish and maintain a Cyber Risk Profile of LCH Ltd. in line with other areas of LSEG.
  • Assisting with the establishment and maintenance of a Risk Control Assessment (RCA) that focuses on InfoSec/Cyber risks and associated controls, etc.
  • Maintaining the established key performance and key risk indicators and ensuring that all management information (MI) is an accurate reflection of the current control’s estate.
  • Maintaining an accurate set of executive level presentation materials that clearly and accurately present the current state of security control within LCH Ltd.
  • Assessing the security architecture solution designs and risk position of projects and initiatives undertaken by LCH Ltd. and working closely with associated SMEs and design authorities to ensure projects are delivered in compliance with Policies and Standards, and with security design principles considered/implemented as key success deliverables.
  • Engagement with the business to:
  • Develop an understanding of business goals and operational risks
  • Identifying key areas for improvement
  • Support the risk management decision processes and risk forums/committees
  • Assisting with the identification of emerging information and cyber security threats to the business, and the subsequent analysis to realise and oversee risk mitigation plans,
  • Build strong relationships within the business to gain an understanding of security-related business risks.
  • Work closely with governance stakeholders in the 1st, 2nd, and 3rd lines of defence on all matters relating to information security, cyber risk, data privacy, including all regulatory and legislative considerations.
  • Embedding Cyber across the firm by:
  • Working closely with all necessary stakeholders in the business and technology areas to ensure compliance with established LSEG policies, standards, and procedures, etc.
  • Constructively and pragmatically challenging established controls to ensure, recommend, and accommodate continuous improvement.
  • Ensuring LCH Ltd. stakeholders understand their responsibilities in relation to security risk mitigation and remediation.
  • Monitoring industry information security trends and keeping business leadership informed about information security-related issues and activities potentially affecting the organisation and specific business functions.
  • Security Governance, Technical, and Risk Review:
  • The review and documenting of technologies and security controls across the firm, including areas such as; office spaces, data centres and cloud.
  • Executing and concluding security controls maturity assessments against industry standards such as the NIST Cyber Security Framework, ISO27001/2, SOC2, etc
  • Working closely with stakeholders to review all projects and initiatives, assessing them for appropriate/correct levels of security design and controls.
  • Identification of technology and security risks across the firm and the assessment and appropriate risk scoring and presentation of the same.
  • Produce appropriate risk remediation action plans and ability to present and take ownership of risk treatment proposals and action plans.
  • Review and appropriate response to regulatory and legislative matters
  • Produce and present risks and risk postures / cyber maturity to senior/executive bodies.
  • Able to clearly and precisely present complex cyber risk matters to clients and regulators.
  • Partnering with the different business control functions:
  • Build knowledge of business units by assisting them with their security workloads, agendas, and difficulties.
  • Maintaining a balanced relationship with risk, compliance, legal, human resources, and internal and external audit functions.
  • Knowledge of technology, security, and threat landscapes:
  • Staying abreast of emerging technologies, including all security technologies,
  • Sustaining a deep and in-depth knowledge of the cyber threat landscape,
  • Maintain and constantly enriching knowledge of information security and cyber risks as they develop,
  • Being able to propose and explain appropriate cyber risk counter measures clearly and concisely.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Working to legislation & regulation
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted 3 days ago

  • Full-time

    £61,440 – £69,120Estimated

    Your risk assessment and analytical skills from policing transfer directly to cyber assurance.

    Posted 5 days ago

  • Director - Risk Management

    SHI International · London

    Full-time

    Your threat assessment and multi-agency command experience directly transfer to building enterprise risk frameworks and governance.

    Posted 5 days ago

  • GRC Manager - 6 month FTC

    Trayport · London

    Full-time

    Your experience managing risk, policy, and regulatory compliance under frameworks like PACE transfers directly to GRC.

    Posted 5 days ago