Support multiple projects and programmes by defining and championing information security solutions. The role will work closely with systems and project engineers, developers, internal / external business stakeholders and project managers within various departments to assess risk and deliver pragmatic, flexible and sustainable security that includes people, process and technology.
- Provides information security technical consultancy to the business. Champion best practices for architecture and design principles for the use of existing and new information security technologies across internal and customer systems.
- Conducts security business impact analysis/ audit for new and existing business applications or IT infrastructure, and provides advice and guidance on the application and operation of physical, procedural and technical security controls (e.g. the key controls in ISO27001 and/or PCI-DSS).
- Assist the system engineering team in the design and development of bespoke customer solutions so that they fit into the standard set of products the business offers and ensure that they are supportable and clearly documented.
- Ensures that technical standards for information security fit policy requirements and are maintained, communicated and implemented.
- Assist engineering and business development teams to clarify customer security requirements and develop security responses for customer bids.
- Assist development of processes and systems to enable effective security engineering within projects.
- Act as a member of design review boards within engineering development process.
- Delivery of security support processes to customer services staff, including internal training and documentation as appropriate to support project transition.
- Some manual handling may occasionally be required
- Degree or equivalent qualifications /experience
- Certification as an Information Security professional (e.g. IISP/CISA/CISM/CISSP/ ISA)
- Current driving licence
- Solid exposure of taking a leading role in the establishment and implementation of security architecture, policies and procedures.
- Experience of secure development lifecycles (SDL)
- Good understanding of enterprise-scale security management process and infrastructure
- Exposure to current information security standards and regulations such as PCI-DSS, ISO 27001, SOX, UK DPA
- Exposure to enterprise IT infrastructure and tools (e.g. Microsoft, Cisco, Sun, Oracle)
- Must be able to work effectively and uphold professional standards and confidentiality with clients internal and external customers as well as staff at all levels of the organisation. The role will also be required to work with security vendors and customers.
- Able to work on own initiative, unsupervised
- Attention to detail and adherence to procedures
- Strong customer service skills
- Strong verbal and written communications skills
- Ability to learn on the job