A blue chip organisation is seeking a talented Information Security professional to manage Information Security policies within their business. The role is a combination of Information Security maintenance and auditing to ensure the protection of all the information/data and technical assets supporting the business.
You will ensure there are appropriate controls in place (Policies, Standards, Procedures, Processes, and Guidelines) and auditing to determine compliance against these controls. As such, the role will help shape the security culture within the organisation.
You should be passionate about embedding information security into the daily operations of an organisation, possess strong risk management skills, and have a working knowledge of ISO 27001.
Responsibilities:
Implementation of policies to ensure compliance with Information Security protocols
Ensure the company maintains their IS status
Provide expert advice to the wider business on Information Security policies and measures
Continually monitor the effectiveness of information security policies and promote improvements when necessary
Conduct staff training into information security awareness
Ensure that the business is compliant with all relevant Information Security Policies and standards
Undertake risk assessments on information security controls
Work with project teams across the business in relation to information security
Ensure the company maintains their Cyber Essentials certification
Completion of client infosec audits
Manage security incidents
PCI DSS assessment
Applicants should meet the following criteria:
An experienced Information Security professional with strong technical skills who is happy to ‘roll up their sleeves’ and dive into the day-to-day work as well as the high level.
Strong experience of information security standards; ISO27001
Experience of undertaking Information Security risk assessments
Strong interpersonal skills with the ability to work with stakeholders across the business
Someone who understands how information security fits into a company commercially - balancing best practices with the reality of a business.
A skilled communicator who can articulate infosec training to the business in an engaging and accessible way.
For a confidential discussion please forward your CV.