|Location||Leeds west yorkshire, United Kingdom|
|Date Posted||April 12, 2018|
|Salary||60,000 plus 10% bonus and benefits + free parking|
Here we have a brand-new LEAD Information / Cyber Security vacancy, based in Leeds.
If this role is not for you please take note of our referral scheme which equals £500, paid directly to you on the referred candidates start date. We also offer £500 starter bonus to the candidate that begins their new career!
Position: Lead Information / Cyber Security Officer
Size of team: 15 FTE's
Salary: 60k & added bonus 10% + other % benefits
Key Stakeholders: Heads of Departments, Directors, CIO
Main purpose of job
As a key member of the Information / Cyber Security team, the Lead Information / Cyber Security Officer , will be engaged with the business and provide consultative and specialist services to assist and improve its information security posture ensuring secure business processes and delivering secure services to clients and consumers. You will be the subject matter expert for the business function(s) and will be responsible for ensuring policy is embedded within working practice, risk assessing relevant projects, 3rd parties and key assets with a preventative risk mindset. You will have a good understanding of the key assets, processes and the current / emerging threat landscape, ensuring risks are identified and managed with appropriate best practice controls and measures.
• Implementation of the Information / Cyber Security strategy and measurement of progress through performance metrics.
• Contribute to the development of policies, standards and guidelines and ensure these are embedded within the business.
• Contribute to the development of awareness and training programmes and assist with delivery to staff and the Information Governance Coordinator community.
• Provide a preventative risk management service through risk assessing and supporting higher risk projects / initiatives / procurement from the earliest stage.
• Provide subject matter expertise and guidance to leadership and staff across the group
• Ensure information security incidents are reported, managed and remediated in a timely manner.
• Ensure exceptions to policy or part of a policy are recorded, assessed and managed.
• Support the Sales process for reviewing, assessing and responding to information security requirements in new contracts.
• Support client, consumer and regulatory compliance reviews and activities.
• Provide regular reporting of the information security status for stakeholders.
• Contribute to the functional responsibilities of the Information / Cyber Security
• Any other duties commensurate with the role
Functional expertise/main job related skills
• Enterprise-wide knowledge of Information security, Information governance, Information Security risk management and Data Protection within the finance business sector.
• A good understanding of technical security processes, cloud services and secure software development and testing.
• Identifying, assessing, reporting and mitigating information security risks within business processes and personnel engagement, projects, systems, 3rd party and client engagements and physical / operational environments.
• The ability to develop and leverage strong relationships with internal and external stakeholders (managers, clients, regulators and suppliers).
• A good understand of agencies and specialist forums to leverage threat landscapes and Information Security best practice eg: ENISA, NIST, ISF (Information Security Forum).
• Delivering credible engagement with business and technology functions and stakeholders.
• Effective written and verbal communication (procedure documentation and management reporting).
• Project Management and problem solving / troubleshooting (technical and management)
• Self-motivated and able to working independently / without supervision (manage own workload); and
• Collaboration (effective team player) Required experience
• Demonstrable work experience within business focused Information Security Management System environments.
• Knowledge of industry standards: ISO 27001; PCI DSS; ISO31000; and ITIL.
• Ensuring previous compliance to the Data Protection Act 1998 and contributing to
the planning and preparation for GDPR.
• Either a recognised Information Security qualification, or working towards a
relevant certification (e.g. CISA, CISM, CISSP, CRISC, ISO 27001 Lead Auditor Certification, and / or Membership of the Institute of Information Security Professionals), or commensurate experience.
• Outsourcing and Cloud service provision including eg: PaaS, SaaS, IaaS.
• Understanding of SIEM, IDS / IPS, Vulnerability Scanning / Penetration Testing, Mobile Device Management.