Security Specialist

Maidenhead, England  ‐ Onsite
This project has been archived and is not accepting more applications.
Browse open projects on our job board.

Description

Security Specialist

Job Family: Operations

Town:Maidenhead

Department: UK Business Operations - Security & Risk Management

Context and purpose:

You`ll be joining the Security team in the fastest growing UK mobile operator; an expanding team with a clear vision to deliver a safe experience of our brand for our customers, our staff and our shareholder. We want someone to come into the team to play a pivotal role in helping to continue to develop and shape our operational security against a backdrop of significant evolutionary change in our security capabilities. We want someone who is easy to do business with, an approachable and trustworthy individual with a keen eye for detail to ensure that our security is the best it can be.

Scope:

This role forms part of the Risk and Security team. Risk and Security is part of the wider Business Operations function. We are responsible for managing Information Security, Business Risk Management, Business Continuity and Physical Security.
The role will work very closely with our Managed Service Providers and will also interface to security teams within our operations in India as well as a wide variety of internal stakeholder areas.
You`ll be dealing with a variety of challenges including working on a programme to significantly improve our security capability through outsourced transformation.
You`ll be working with onshore and offshore teams to understand what`s happening on our network and make sense of it in a business context and supporting those teams in helping set the strategic and tactical direction for security.
You`ll also be keeping an eye on our own internal product development processes and designing security in and risk out from early in the lifecycle.
On top of that, there`s a variety of other security programmes and projects to work on covering security awareness, risk, key management, user management, third-party reviews and compliance activities relating to PCI DSS, ND1643, and Cyber Essentials

Responsibilities:
Provide input and support into the management of security toolsets, including IDS and Log Management tools, ensuring that indications of malicious activity are identified, investigated and resolved.
Performance of network reviews and certification against industry standards including PCI DSS and ND1643 Interconnect Standard, Cyber Essentials
Identify, log, communicate and manage security weaknesses and risks throughout the business, working cross-functionally to remediate or control those risks.
Implement and maintain a suite of security metrics to enable the effectiveness of the security strategy and operation to be measured and related security issues to be understood and managed.
To provide and support an assurance process around our product pipeline from a security perspective -designing security features in and vulnerabilities out as part of product development.
Recommend, develop, publish, implement and monitor security policy and procedures for the business taking into account legislation, business culture and risk.
To manage the security processes that support the customer including carrying out day to day operational security requests
Supports, advises and gives guidance to internal customers on security risk matters ensuring that risks and weaknesses throughout the business are correctly identified, prioritised, investigated and resolved

Our candidate must have:
A strong, technical understanding of information security and risk principles with an ability to recommend simple, straightforward solutions that are relevant to the organisation (experience of administration of Windows, Linux or Solaris- good to have)
Good understanding of authentication and directory services like Active Directory
Strong grasp of network technologies
An inherent and effective ability to influence the security agenda across and up the organisation
Effective relationship building and stakeholder management skills
Key capability in managing change and coping with change
An ability to remain calm under pressure and manage incidents to resolution
Clear competence working within, across or leading virtual teams to a clear outcome
Excellent skills in multi-tasking and managing priorities
First class communication skills - we really need someone who can listen and absorb, talk and hold the attention of others and produce documentation that is simple, effective and concise
An approach that is diligent and professional and that engenders trust with others
Previous experience of auditing network infrastructure and achieving compliance to industry standards.
Experience working in an environment where some (or all) security services are outsourced to a third-party
Professional qualifications e.g. CISSP, CISM, CISA, CRISC (or a desire to achieve those)
Involvement in security awareness campaigns within large organisations
Security clearance to SC level (or an ability to be cleared) would be an advantage but is not essential
Start date
ASAP
Duration
3 months
From
Project People GmbH
Published at
21.02.2018
Contact person:
Colin Crawford
Project ID:
1507995
Contract type
Freelance
To apply to this project you must log in.
Register