Loading jobs…
Loading jobs…
The Scion Group — Iselin New Jersey
About CLS: CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars’ worth of currency flows through our systems each day.
Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies.
Requirements
by over 96% on average, so clients can put their capital and resources to better use. CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market. Our ambition to make a positive difference starts with our people.
, overseeing application security testing (SAST, SCA, DAST, IAST, API Security), threat modelling, and ensuring effective application vulnerability remediation tracking. This also includes managing secrets for applications and delivering internal/external penetration testing and red teaming exercises. Manage and continuously improve CLS's vulnerability management programmes, including asset baseline management, vulnerability identification, prioritisation, remediation ownership/tracking, disclosure processes, exception management, and patch management.
Oversee executive reporting on vulnerability management and testing. Provide strategic leadership and talent management for the pillar, supporting performance management and career progression, identifying training and development needs, and coordinating budget for internal and external training to enhance team capabilities.
Responsibilities
This role involves building and leading a cross-functional team dedicated to establishing and maintaining robust cyber hygiene across the enterprise, encompassing comprehensive vulnerability management, application security, and the safeguarding of CLS's critical data assets across their entire lifecycle and diverse environments, from on-premise to cloud, ensuring robust protection against evolving cyber threats and stringent regulatory requirement. Define and drive the overarching Cyber Hygiene and Data strategy and framework for CLS, setting the vision for data loss prevention, data protection, application security, and vulnerability management. This includes developing DLP strategies, managing policy exceptions, and defining use cases to protect critical information assets.
Oversee the comprehensive protection of CLS data throughout its lifecycle, including strategic direction for data at rest/in-transit controls, email security, rights management, masking/tokenization, and database security. This also encompasses leading the strategy for cryptographic solutions, key management (lifecycle, inventory), issue identification/remediation, and ensuring cryptographic standards compliance. Establish and enforce robust data governance and classification programmes, encompassing data discovery, landscape assessment, secret scanning, classification criteria definition, handling standards, automated tooling, and compliance monitoring.
Drive continuous improvement in data security risk assessment, prioritisation, and remediation efforts.