R3 is a financial innovation firm that leads a consortium partnership with over 100 of the world’s leading financial institutions. We work together to design and deliver advanced distributed ledger technologies to the global financial markets.
R3 has employees based in over 11 (and counting!) countries across the globe, with our headquarters in London, alongside office locations in New York City and Singapore. Our vibrant and centrally located offices are filled with collaborative spaces, healthy (and some not so healthy!) snacks and state of the art work spaces and equipment.
Reporting to the information security manager, and part of a small team of information security specialists, the cyber security specialis will ensure that R3’s technical and organisational security control environment is robust, fit for purpose and provides the assurance required by some exacting clients.
You will be helping to develop the control environment for the Corda Network, a publicly-available internet of Corda enterprise blockchain nodes. This is an exciting role, and not for the faint hearted.
This is a customer-facing role. you’ll need to have excellent communication skills and must be comfortable as the R3 security lead in engagements with client security architects and technology risk management teams.
You’ll have a combination of both technical and organisational security skills. Your background will be within financial services, telecoms or critical infrastructure service provider, or maybe an enterprise-scale end-user security department. You’ll be used to working in environments with comprehensive security control environments, but have the insight to bring a risk-based approach to a fast-moving company with a start-up culture.
This is an opportunity to help “write the book” on building on the security controls and providing high levels of assurance for enterprise blockchain deployments. If this sounds like you, read on.
Responsibilities (the cyber security specialist will …. )
- Play a lead role within R3’s security transformation program, specifying and implementing technical and organisational security controls required for a world-class enterprise software and service delivery organisation.
- Deputise for the Information Security Manager where necessary, providing support and leadership for a growing team of governance, risk and compliance, security engineering and security research specialists.
- Consult with R3 clients and partners to understand their security requirements. Lead client security and technology risk management reviews, compile responses for reviews, negotiate remedial activities with R3 internal teams, and manage such activities to completion.
- Provide security representation in technical design reviews, Lead risk and security assessment and threat modelling activities for processes and systems as required and ensuring R3’s products and services are secure by design.
- As part of the wider security team, design technical and organisational security controls for R3’s cloud and on-premises infrastructure, and corporate IT. This will range from creating and reviewing high-level policy documents through to defining, implementing and testing technical security controls for R3s entire service portfolio.
- Work with the wider security team to prepare for and undergo external service auditor assessments of the security control environments which you help to develop.
Qualifications (the must haves …. )
- First and foremost we want you to love what you do. You’ll need to be a security evangelist within R3 and the community of Corda Network participants, both current and future.
- You will have at least five years senior (preferably technical team lead) roles within a security organisation in a blue-chip or high-growth technology organisation.
- You’ll have experience in multiple security domains. Those with deep, specialist skills in one or two domains only need not apply.
- Hands-on experience is essential. Whilst we’re not expecting to hire a DevSecOps engineer or security researcher you will be expected to hold your own in a team that includes those skills. We expect the ability to execute, and the experience to be effective in a short period of time from all team members.
- You’ll need excellent communication skills, both verbal and written. You must be capable of delivering concise, plain English descriptions of complex security concepts to senior R3 and client stakeholders. You should sufficient gravitas to influence small groups of senior management members or board-level members, but also have the energy to present to a conference hall.
- You will be capable of defining security requirements and implementing controls and metrics for complex, long-term projects involving substantial multi-disciplinary teams.
- You must have worked within an organisation that carried industry recognised credentials such as ISO 27001 certification or SOC 2 reports. You will have played a lead role in gaining those credentials.
- Financial services experience would be ideal, but experience in other areas such as telecoms or other critical infrastructure may also be a good fit.
- You must be able to display extensive experience in working in both cloud and on-premises deployments. Microsoft Azure is our platform of choice, but AWS or GCP skills are transferable. Containerisation and container orchestration security skills would be a big plus.
- You will have an appreciation of the variety of technical products available to R3 including endpoint security, identity and access management, network security controls (firewalls, VPN), intrusion detection and security event management/log analysis tools.
Qualifications (the nice to haves…)
- Relevant professional qualifications would be great. We have ISACA and ISC2 members in the team already and so obviously look favourably on professional certifications, so long as they are relevant. You’ll need to demonstrate that any certifications you claim are valid and current (we will check).
- Experience of designing and implementing technical security controls that are required for GDPR, PCI-DSS, HIPAA or other similar regulations in on-premises and cloud environments.
- Understanding of public key infrastructure would be very useful. We’d be particularly interested to hear from people who’ve worked in internal PKI teams or for commercial CAs.
- Experience with the management and protection of cryptographic key material, including the deployment, and operation of on-premises HSMs would be a plus.
- An engineering or science degree would be great, but outstanding career experience is just as important. Be prepared to tell us all about that experience.