Information Security Consultant (Governance / Risk / Compliance) - Bradford
Posted 1 day ago by Interface Recruitment UK
Permanent
Not Specified
Other
Yorkshire, Bradford, United Kingdom, BD1 1
Job Description
Information Security Consultant (Governance / Risk / Compliance) - Bradford 
Salary: NEG - please apply regardless of expectations
Work Hours: 9am - 5.30pm
Location: West Yorkshire
Responsibilities:
- Work with the Information Security team to provide advice and guidance on IT security and further develop IT policies and processes across a multi-region infrastructure consisting of 8000+ staff and 100+ sites.
- Review all aspects of the IT environment and its components.
- Support Governance, Risk, and Compliance activities.
- Proactively improve and provide advice and guidance on information security matters.
- Create and maintain policies within our Information Security Management System, to support business requirements and align with ISO 27001.
- Maintain a register of security controls to identify compliance against security standards, including ISO 27001, NIST, COBIT, etc.
- Develop and enhance security policies, processes, procedures, and technical controls to strengthen security capabilities and resilience to cyber threats.
- Maintain and manage the IT Risk Register to ensure that IT risks are regularly reviewed, correctly identified, assessed, reported, and mitigated in line with recommended best practices.
- Identify and raise awareness of security risks.
- Develop a register of regional regulatory privacy requirements and develop processes to monitor regional controls to ensure compliance.
- Perform daily, weekly, and monthly security checks, reconciliation and compliance checks, and investigate exceptions.
- Complete client security requirement questionnaires and support the bidding process.
- Assist with security incident management and response activities.
- Provide general day-to-day support on managing and responding to security alerts from systems and end users.
- Support the wider IT team to provide and share technical knowledge and security best practices.
- Test DR plans, processes and capabilities to ensure they work as designed, identifying gaps and lessons learnt, and work with the business to drive continual development and enhancement.
Technical Requirements:
- At least 13 years educational background.
- Excellent working knowledge of security and governance, risk, and compliance within an enterprise environment.
- Hands-on experience of enterprise information security and standards including Cyber Essentials, ISO 27001, 27002, Data Protection Act, and the General Data Protection Regulation.
- Experience with Microsoft O365 Security solutions, Networking, Security operations, Vulnerability Management, Security Auditing.
- Experience of formal document creation, such as the creation of reports or procedures.
- Experience of carrying out risk reviews, technology audits, or other similar work.
Detailed knowledge of:
- Threat Intelligence analysis and best practice.
- Security Incident Response processes, procedures, and best practices.
- Disaster Recovery and Business Continuity principles and testing methodologies.
- Risk analysis and data management methodologies.
- Event and log analysis.
Core Behavioural Skills:
- Confident individual with good interpersonal skills, able to deal with people at all levels and communicate to users in a clear, non-technical language.
- Team-player.
- Analytically minded, able to break down and understand information.
- Comfortable working in a fast-moving, dynamic environment.
- Strongly customer-focused, used to providing support to demanding users.
- Good organisational skills, used to managing and prioritising own workload.
- Ability to report on progress, timescales, outstanding and completed activities.
Contact:
Additional Benefits: Cycle to work.