Cyber Security Consulting Lead

Company: QBE Insurance Group
Apply for the Cyber Security Consulting Lead
Location: London
Job Description:

Overview

In this role you will lead security assurance and advisory work for IT and business projects (cloud and on‑prem) across Europe and globally, using a NIST-based secure design framework. You will partner with security architecture and delivery teams to embed secure patterns, define non‑functional security requirements, and drive risk mitigations. You’ll guide stakeholders to correct non‑compliant processes and contribute to global security projects, shaping secure outcomes across the organization.

Pay / Benefits

  • 30 days holiday with option to buy up to 2 days
  • Flexible working arrangements
  • Pension plan with 10% employer contributions

Responsibilities

  • Lead security assurance, assessments, and advisory for IT and business projects (cloud and on‑prem) against NIST 800-53
  • Partner with security architecture and design teams to define security patterns and embed controls
  • Develop non‑functional security requirements and provide integration guidance for solutions
  • Conduct security risk assessments and specify mitigations for identified risks
  • Collaborate with IT and business stakeholders to rectify non‑compliant processes
  • Contribute to strategic global and regional security projects and their deployment
  • Support secure design and risk remediation across EO and global security teams

Key requirements

  • Experience applying security and risk-based standards (ISO 2700X, ISO 31000, NIST 800, PCI-DSS)
  • Ability to identify security weaknesses and drive mitigations to a secure outcome
  • Experience across in-house and outsourced delivery models, multiple time zones, multicultural environments
  • Ability to work independently with proactive seeking of support as needed
  • Desirable: financial services domain awareness (APRA, PRA, FCA)
  • Stakeholder management
  • Collaboration and cross-functional influence
  • Independent working style
  • NIST 800-53
  • ISO 2700X / ISO 27001 family
  • Security risk assessments

Posted: September 14th, 2026