Engineer, Information Security GRC

Intercontinental Exchange Holdings, Inc.

$90K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • University degree in Information Security, Engineering, MIS, CIS, or related field
  • 3+ years of relevant work experience in Information Security or related disciplines
  • Familiarity with Cybersecurity Frameworks like NIST and COBIT
  • Understanding of Regulatory Compliance processes
  • Experience in financial services or exchange environments is advantageous
  • Strong skills in customer communication and vendor evaluation
  • Proficiency in senior management reporting and metrics generation

Responsibilities

  • Produce regular reports showcasing the status of the Information Security program
  • Maintain corporate InfoSec policies and map them to relevant control standards
  • Organize documentation and respond to regulator, audit, and customer inquiries systematically
  • Oversee access recertification processes and ensure compliance with protocols
  • Develop and manage security awareness and education initiatives
  • Document, measure, and report risk assessments and remediation activities using company platforms

Benefits

  • Exposure to a global Information Security program within a major financial entity
  • Involvement with a best-in-class cybersecurity and physical security program
  • Opportunity to interact with diverse business units and products
  • Professional growth through advanced certifications and hands-on experience
  • Engagement in a culture that emphasizes risk management and compliance best practices
Full Job Description
Overview

Job Purpose

The Engineer, Information Security GRC is part of a team responsible for the global Information Security program.  The role would gain exposure to the full suite of businesses and products which underpin the Parent ICE company.

 

Information Security (“IS”) is charged with:

  • Preventing impactful cybersecurity and physical security incidents,
  • maintaining a reputation with customers, regulators, and key stakeholders as running a best-in-class cybersecurity and physical security program, and
  • avoiding negative impact to business agility and growth from cybersecurity and physical security policies and controls.

Governance, Risk, and Compliance maintain said policies, ensure controls are operating effectively via assessment and attestation, and own the vulnerability management program to identify and correct any problems within.

 

Responsibilities

  • Security Metrics – Uses automated and manual processes to produce regular reports communicating the status of the Information Security program
  • Policies and Procedures – Maintains corporate Information Security policies and departmental procedures and maps them to relevant control standards
  • Regulator, Audit, and Customer Inquiries – Organizes and updates departmental documentation and responds to inquiries in an organized and repeatable fashion
  • Recertification – Operates periodic processes to ensure hire, transfer, and termination protocols are complied with and regular access reviews are conducted
  • Security Awareness – Builds and maintains company awareness and education programs
  • Risk Assessment – Builds and operates the company platform to document, measure, and report assessments, risks, controls, findings, and remediation activity

 

Knowledge and Experience

  • University degree in Information Security, Engineering, MIS, CIS, or related discipline
  • 3+ years of relevant work experience
  • Experience in Cybersecurity Framework (such as NIST, COBIT)
  • Experience with Systems Administration and/or IP Networking is a plus
  • Experience with Regulatory Compliance
  • Experience in an exchange, trading facility, or financial services a plus
  • Experience in Customer communication and Vendor evaluation
  • Experience with senior management and board metrics generation and communication
  • Advanced certifications (for example, the CISSP)
  • Advanced technical writing and/or communication education and experience

 

Specific Technologies

Excel, Workflow automation tools, Data collection, normalization, indexing, correlation, and visualization.  Scripting, regular expressions, string-parsing, light SDLC, and project management.  NIST Cyber Security Framework, CIS, and GRC Platforms.

Similar Jobs

More Jobs at Intercontinental Exchange Holdings, Inc.

More Information Technology Jobs

Find similar Engineer, Information Security GRC jobs: