Job description
Who we are & what we do
Founded in 2016, Chetwood Financial is a digital bank using technology to make people better off. At Chetwood, we think differently. We act differently. Unlike traditional banking models, we’re not obsessed with customer ownership and cross-selling other products. We use our banking and technology experience to design and manufacture stand-alone financial products that meet the needs of those using them and by building unique and dynamic products, we make engaging with personal finances easier than ever before.
We’re always on the lookout for exceptional talent to join the team who share a belief in making a positive difference – making financial services better for customers by challenging conventions.
Role Purpose:
For the role as Security Analyst you will be the subject matter expertise in relation to IT and Information Security controls and assurance, Cyber Security threat and vulnerability management and response, and supplier security due diligence and assurance. The role is a key part of the Cyber/Information Security function. It plays a key role in the security service offered to keep the bank and our customer assets safe. As a Security Analyst you will lead a broad range of initiatives covering, but not limited to Security Operations, Security Assurance, Threat Detection, Incident Management and Response in the objective to protect the organisation against internal and external cyber security threats.
Responsibilities:
- Support Chetwoods Vulnerability Management, Penetration Testing, Cloud Security Posture Management (CSPM) and Security control maturity processes.
- Supplier security due diligence and assurance.
- Create and deliver security awareness and training.
- Leverage and contribute towards Chetwood's Policies, Processes, Procedures and Guidelines.
- Engage with and support IT, Enterprise and Operational Risk Management Processes.
- Threat intelligence - evaluate and refine available technical intelligence feeds to drive maximum value. Research threats, Indicators of Compromise (IoCs) and threat actor Tactics, Techniques and Procedures (TTPs) to support Threat Hunting.
- Assist projects with transition into production by leveraging our Security go-live assurance criteria, whilst maintaining go-live status tracking reports.
- Act as part of the Incident Response team where appropriate and provide operational support during ongoing incidents and in the development of incident response playbooks.
- Coordinate and act as the first point of contact for key Security Operational initiatives such as Penetration tests and Audits.
Skills and experience:
- Financial services experience is preferable, ideally within a challenger bank or financial technology (‘FinTech’) organisation.
- Knowledge of the following security domains: Data Security, Logging and Monitoring, Malware Detection, Threat Detection & Incident Response, Threat Intelligence, IAM & PAM, Network Security / Perimeter Security, Email Security, Data Loss Prevention, Anti-Virus and Endpoint Protection.
- Supply Chain Risk Management – Knowledge of supplier assurance practices
- Security risk and control assurance.
- Broad Security Control Frameworks and standards and techniques such as NIST CSF, ISO 270001 / 2, Cyber Essentials, CIS Controls, PCI DSS, GDPR, Cyber Kill Chain and Mitre ATT&CK, along with UK and EU regulation.
- Self-starter, willingness to learn new skills and be self-motivated.
- Excellent verbal and written communication skills.
Relevant certifications:
There are no formal requirements for any qualifications or certifications. However, one or more of the following may serve as an advantage, or a willingness to work towards.
- Technology recognised certifications such as Public Cloud (AWS/Azure/GCP), EDR, SIEM and VM vendor certifications.
- Industry-recognized certifications such as CompTIA Security+, GIAC Security Essentials (GSEC), ISO 27001 Lead Auditor/Implementer, ISC2, ISACA and EC-Council.
What we offer:
- A fantastic opportunity to contribute, challenge and learn as we build a bank from scratch
- A relaxed, sociable and flexible working environment.
- Great benefits include: life insurance, pension, private medical insurance (including dental and optical), free breakfast and drinks, monthly social events.
- Competitive salary.
- Opportunity to be part of a well-funded, progressive and exciting Fintech.
Chetwood Highlights:
Here are just a few examples of what we’ve achieved so far and what’s coming soon:
- Secured strategic investment from Elliott Advisors of £150mil of capital, underpinning the planned growth of the business over the next few years.
- Secured a full banking licence from the PRA in 2018 - the only retail bank to do so that year.
- Launched the LiveLend Reward Loan; the world’s first dynamic loan that responds to improvements in customers’ credit score.
- Secured several distribution partnerships with our lending product and have already seen 400%+ growth in new business since 2019.
- Launched SmartSave; providing customers with a simple, online savings account at a great rate.
- Achieved and maintained an ‘Excellent’ Trustpilot rating from both lending and savings customers.
- Launched Wave Credit Card; digital first credit card available to use immediately after successful application.
- Acquired Yobota - a FinTech company delivering core banking platform underpinning number of loans and savings products on the market.
- Chetwood Financial Ltd does not accept speculative or unsolicited CVs from Recruitment Agencies.