Overview
In this role, you will design and operate security controls across people, process and technology to enable the business safely. You will shape the Information Security Management System and drive governance, risk and compliance across the organisation and its suppliers. You’ll work with cross-functional teams to analyse threats, measure control effectiveness and support risk-based decision making. This is a chance to contribute to secure transformations for large-scale infrastructure and complex programmes within a globally active consulting leader.
Responsibilities
- Provide security expertise across standards and accreditations and maintain the ISMS
- Develop Information Security Management Plans covering regulatory, legal and compliance aspects
- Identify risks and emerging threats and lead mitigation actions
- Collaborate with Service Management and suppliers to enforce standards and verify security KPIs
- Engage with 1st-3rd line of defence on cyber security, risk, data privacy and compliance
- Lead governance, risk and compliance improvements aligned to policy and industry good practice
- Produce and track security metrics to support risk-based decisions
- Challenge and improve processes to ensure clear ownership of security risk
- Review documentation for process and technical security controls
- Develop and maintain ISMS to achieve required industry certifications (e.g., ISO 27001)
- Propose changes to policies/procedures and coordinate their implementation
- Conduct focused information risk assessments and extend assessments to third-party suppliers
- Coordinate audit, ITHC and risk assurance activities and remediation actions
- Maintain strong relationships with information risk stakeholders across services and third parties
- Chair/participate in Security Working Group and governance forums
- Contribute to data protection risk analysis and incident response initiatives
- Lead security operations, incident response and liaison with internal teams and suppliers
Key requirements
- Track record delivering security solutions for large-scale infrastructure/transformation programmes
- Practical knowledge of security frameworks (NIST CSF, NIST 800-53, NCSC CAF)
- Strong networking knowledge (switching, routing, firewalls)
- Deep understanding of modern security concepts, threats, analytics and threat intel
- Experience with security testing and vulnerability management (pen testing/ITHC, CVSS/CVE)
- Experience with standards such as ISO 27001/27002/27017/27108
- Stakeholder management
- Analytical mindset
- Constructive challenge of processes
- NIST CSF
- NIST 800-53
- NCSC CAF
…
