Cyber Assurance and Risk Lead, NTT DATA

GRC

Salary not provided
Expert level
London
NTT DATA

Digital transformation consulting and services

Open for applications

NTT DATA

Digital transformation consulting and services

1001+ employees

B2BConsultingCloud Computing

Open for applications

Salary not provided
Expert level
London

1001+ employees

B2BConsultingCloud Computing

Company mission

To leverage information technology to create new paradigms and values, which help contribute to a more affluent and harmonious society.

Role

Who you are

  • Requires extensive knowledge of GRC frameworks, regulatory compliance obligations and a proactive approach to risk management
  • Minimum of 10 years’ experience in a Governance, Risk and Compliance role, with at least 5 years in a leadership or managerial position
  • Relevant certifications such as CISSP, CISM, CCSP, CISA, CRISC or equivalent experience
  • Expertise and practical knowledge and understanding of industry security frameworks and guidance such as NIST 800-53, NCSC CAF GovAssure, NIST CSF, DORA and NCSC guidelines
  • Good knowledge and understanding of Cyber Security domains, including; network and cloud security, security operations, vulnerability management, Third Party supplier Risk Management, application security, physical security
  • Good knowledge of networking (switching, routing, firewalls)
  • A good understanding of security testing and vulnerability management is important (including pen testing/ITHC, CVSS/CVE)
  • Experience working with security standards such as ISO 27001, 27002, 27017, 27108 etc
  • Please note that candidates must hold or be able to gain UK SC level Security Clearance or higher

Desirable

  • Thrive as a consultant seeking the variety and challenge of engaging with different clients and variety of technologies and solution types
  • Proposes security requirements for new systems or changes to existing systems without close supervision
  • Execute technical management tasks in respect to ongoing client projects
  • Hands on technical background with technologies and systems

What the job involves

  • As a strategic and leadership role you will be instrumental in shaping and driving security and risk programs to align with internal business objectives as well as industry good practice (including Secure by Design aligned to UK Government principles) and regulatory requirements (including GovAssure and NCSC Cyber Assurance Framework)
  • Develop and execute GRC strategies that align with business objectives and inform appropriate supporting business processes
  • Drive pragmatic and creative solutions to GRC challenges, applying agile methodologies to adapt to new regulations, compliance requirements and business change
  • Advise on and foster continuous improvement and effectiveness of GRC processes, driving improved management information to better allow appropriate prioritisation and risk based decisions
  • Lead initiatives that build a culture of accountability and responsibility across engagements
  • Enhance governance processes and advise on how best to evidence alignment with regulatory requirements (such as NCSC CAF) and industry good practice (including Secure by Design)
  • Providing security expertise across security standards and accreditations, measure and control the effectiveness of the security controls framework and maintain the Information Security Management System
  • Deriving and delivering documented Information Security Management Plans which incorporate Regulatory, Legal and Compliance in relation to applicable security policies. Standards and guidelines
  • Assiting with the identification of identified risks and emerging cyber security vulnerabilities and threats. The subsequent analysis to quantify and lead risk mitigation plans
  • Work with Service Management to ensure that partners and suppliers adhere to agreed standards, policies and verify/evidence appropriate compliance and security KPIs
  • Work closely with 1st, 2nd and 3rd lines of defence on all matters relating to cyber security, information assurance, cyber risk, data privacy including regulatory and compliance considerations
  • Lead the development and enhancement of governance, risk and compliance aligned to policy, standards an industry good practice
  • Ensure that continuous assessment, identification, analysis and reporting of useful metrics to enable informed risk based decisions to be taken
  • Develops and maintains Information Security Management practice and process to ensure certification to required industry standards (e.g., ISO 27001) within relevant geographic boundaries
  • Performs focused information risk assessments of existing or new services and technologies, alongside the Operational/Service Management team and technology subject matter experts
  • As required, will extend the assessment of existing and proposed services to third party suppliers, including the facilitation of IT Security checks during the supplier onboarding and contract lifecycle to ensure coherent approach to risk management
  • Maintains strong working relationships with individuals and groups involved in managing information risk across the in-scope services and aligned suppliers / 3rd parties
  • Chairs and co-ordinates Security Working Groups (SWG) and actively participates in supporting/governing forums

Salary benchmarks

Share this job

View 12 more jobs at NTT DATA

Insights

6% employee growth in 12 months

Company

Company benefits

  • A people focused business
  • Excellent opportunities to grow your career, including an online training platform with 3000+ courses, accessible from everywhere, to sharpen your skills
  • A varied client base

Our take

The changes brought on by digitisation have only accelerated in the past few decades, and large organisations have been struggling to keep up. Attracting future investment and ensuring growth is more than a matter of purchasing new tools, it involves a fundamental change in ways of working and company culture that few organisations have the expertise to achieve on their own. The UK and Ireland arm of NTT Data, a global digital transformation consultancy and services firm, exists to support businesses and government organisations through this seismic change.

With digital transformation at the top of most enterprises' agendas, NTT Data faces major competition in this sector from the likes of Deloitte, Accenture and IBM's consulting arm. However NTT Data UK & Ireland brings significant local expertise particularly in UK telecommunications, financial services and the British public sector which gives them an edge in this market.

NTT Data UK&I has ambitious plans to capture 2% of the total digital transformation market in the UK, a sector which was worth £20 billion in 2022 and is projected to increase rapidly year on year. To achieve this it has formed strategic partnerships with infrastructure providers such as Google Cloud, allowing it to offer multi-cloud solutions as part of its suite of services to its clients. If it can leverage the size and expertise of its parent organisation successfully while still retaining its local advantages, it is well placed to achieve this goal.

Steph headshot

Steph

Company Specialist at Welcome to the Jungle