The ideal candidate is passionate about Information Security and Information Technology.
Core technical skills
Application security across the SDLC: hands-on use of SAST, DAST, and SCA tools, plus the ability to act as the go-to expert who helps developers fix vulnerabilities (not just report them).
Vulnerability management: scanning, prioritizing, tracking, and driving remediation to closure.
OWASP Top 10: strong working knowledge of common web application vulnerabilities and how to mitigate them.
Cloud security: experience with AWS (preferred) and Azure, especially around cloud migration.
Access governance: identity and access management concepts such as least privilege, access reviews, and entitlements.
Broad IT and emerging tech knowledge: familiarity with information systems generally, including the security implications of AI.
Risk, governance, and analysis
Security control analysis: assessing whether controls actually meet the firm's security requirements.
KRI reporting: building data- and metrics-based analysis to monitor and report risk proactively.
Audit collaboration: working with Internal Audit and Risk Management teams on evidence, findings, and control effectiveness.
Must have investment or Financial experience.
Qualifications
Bachelor's degree in Computer Science, Engineering, Computer Security, or Information Systems.
7+ years of experience spanning software development, information security, and cloud environments.