Β 

Senior Information Security Consultant

Senior
πŸ‡¬πŸ‡§ United Kingdom

The Role

The role will be dedicated (initially) to supporting the delivery of information security services to our contract to deliver the Smart Energy Code (SEC). Therefore, an understanding of the Energy Sector or Smart Metering would be a distinct advantage. The delivery of this multi-party code requires excellent communication and stakeholder management skills, so you would need to be a clear, concise, and authoritative communicator able to deliver to a broad range of audiences. The successful candidate will be screened against BS7858:2019 which is a key requirement. The candidate if successful will be part of the wider Cyber Security Practice and will be expected to support the delivery of information security services to our clients.

We would be interested in hearing from candidates who are looking for both permanent and fixed-term contract employment.

Responsibilities

  • Providing expert advice to Users undertaking User Security Assessments (USAs);
  • Monitoring the progress of Users who have booked USAs;
  • ensuring an accurate tracking mechanism to record:
  • Maintaining and reviewing USA-related documentation including the Security Controls Framework, AgreedInterpretations and Decision-Making Principles;
  • Undertaking validation of User management responses and Director's Letters;
  • Liaising with Users to enable an improved User management response to be provided in advance of the User CIOvalidation or Security Sub-Committee (SSC) review of Director's Letters where appropriate;
  • Briefing the Principal Security Expert on any sensitivities or emerging issues from liaison with Users and/or SharedResources and providing relevant background and issues to be considered by the SSC.
  • Monitoring all security incidents and vulnerabilities reported by Smart Energy Code (SEC) Parties or the DCC and providing an expert assessment of the materiality of the security incident or vulnerability;
  • Advising the Principal Security Expert on whether a security incident or vulnerability is material and warrants the mobilization of SMIRT;
  • Promptly taking whatever action is directed to undertake analysis of the security incident or vulnerability as required;
  • Conducting 'lessons learned' analysis after the resolution of a security incident or vulnerability.
  • Undertaking the review of ISO standards, cryptographic standards, and best practices as enshrined in the SEC
  • Maintain the SEC Security artifacts and, with the approval of the Chair, arrange for regular reviews to ensure that the artifacts are up to date.
  • Conduct ad hoc risk assessments of specific risks that may arise from time to time;
  • Reviewing user assessment reports and management responses;
  • Monitor the threat landscape and advise the SSC of any material changes arising from threats or business impact levels;
  • Contribute to procurement exercise for the annual SSC risk assessment where requested by the SSC;
  • Provide expert assistance to any external risk assessment commissioned by the SSC.
  • Conduct analysis produce papers and presentations; provide advice and make recommendations.

Requirements

Requirements

To be successful in the role the post-holder should be able to demonstrate experience in the following areas:

  • An understanding and practical working knowledge of the Smart Energy Code (SEC) Section G
  • Technical knowledge of information security compliance (ISO27001) information management, Smart Metering, and IT security arrangements.
  • Ability to conduct risk assessments and treatments using a hybrid IS1/IS2 and ISO 27005 requirements
  • Have practical experience in undertaking ISO 27001 internal and external (field) audits
  • Have practical knowledge of the threat landscape in Smart Metering
  • Knowledge of Smart Metering and the energy market would be advantageous
  • Preferably, an understanding and working of ISO standards including ISO 27001, ISO 27005, ISO 27035 andISO22301
  • ISO 27001 Lead Auditor / Implementer qualification is essential
  • Ideally, have an industry qualification such as CISA or CISM

Skills & Qualities

  • Excellent client consulting skills and ability to engage and build relationships with stakeholders at all levels (including C-suite level)
  • Able to conceptualise opportunities and develop these through business development activities.
  • Ability to explain complex ideas concisely.
  • Ability to work independently with little to no supervision.
  • Ability to provide expertise and support in operational risk, governance, business continuity, data protection, data leakage, and privacy.
  • Passion to develop own skills and knowledge in information security and data protection compliance.
  • Proactive, 'hands-on' starter finisher and results-driven individual.
  • Highly organised and able to manage and prioritise workload.
  • Strong problem solver with high attention to detail.

The role may require occasional business travel.

Competitive salary plus bonus and excellent benefits package

Upon employment, employees should also have a sound awareness of the Company's Information, Quality, Environmental and Energy Management Systems.

Β 

Talan

Talan

An international advisory group on innovation and transformation through technology, with 5000 employees, and a turnover of 600M€

Consulting
Technology
Large Enterprise

Other jobs at Talan

Β 

Β 

Β 

Β 

Β 

Β 

Β 

Β 

View all Talan jobs

Why OmniJobs?

  • Rare & hidden jobs
  • New jobs every day
  • No expired job posts
  • All jobs in English

Receive emails about similar jobs

Get alerts to your inbox about new open jobs that are similar to this one.

πŸ‡¬πŸ‡§ United Kingdom
"Senior Information Security Consultant"

No spam. No ads. Unsubscribe anytime.

Similar jobs

Β 

Β 

Β 

Β 

Β 

Β 

Β 

Β