Head of Information Security
Role details
Job location
Tech stack
Job description
Job ID:43536 Location:LRQA - London - 4 Moorgate, LRQA Nettitude:Birmingham :1 Position Category:Consulting Position Type:Employee RegularAbout LRQAAt LRQA Cybersecurity, our focus is on excellence in cyber security. We have teams that offer world class services in red teaming, penetration testing, threat intelligence, research and development, detection and response, governance, risk, and compliance, and plenty more. Our business is global and so are our clients. We work closely with central banks, central and local government, critical national infrastructure, large retailers, and plenty more besides!We're an award winning provider of cyber security services and we are at a very exciting stage of development. We are looking for the right people to join us as we embrace the challenges thrown up by the advancements within the IT industry and within the threats faced. LRQA will be at the forefront of this arena and we want to seek the right people to join the team and make it happen.You can find out more about us at https://www.lrqa.com/en/cyber-security-services/The RoleThe purpose of this role is to deliver information security consultancy to LRQA clients, specialising in both strategic consultancy - via the CISO Support Office (CSO) and governance, risk and compliance (GRC). As a Lead Consultant, you will be capable of working autonomously, supporting colleagues and leading engagements to ensure that delivery of LRQA services is delivered effectively, to scope and in line with budget.This role is hybrid, with occasional travel to client sites and LRQA offices as required.What You'll be Doing in Your RoleKey ResponsibilitiesDeliveryA core competency for this role is the ability to effectively deliver engagements to clients to a consistently high standard. As a Lead Information Security Consultant, you would be expected to drive engagements whilst supporting other members of the team with the ultimate aim of achieving excellent client satisfaction results.Examples of the type of delivery activities a Lead Information Security Consultant may participate in include:Provision of client support to achieve compliance/certification against recognised standards such as ISO 27001, the GDPR, NIST CSF and CMMC.Independently conduct ISO/IEC 27001:2022 audit activities.Provision of expert advice to clients on governance structures - including policies, procedures and controls to achieve compliance and reduce risk exposure.Cybersecurity Maturity Assessment engagements.Facilitation of information asset discovery workshops and engagements.Facilitation of risk assessment workshops and engagements.Delivery of business continuity scenario tabletop exercises.Delivery of external stakeholder training and awareness presentations.Service DevelopmentEffective service development is key to the success of GRC and you would contribute to this by providing guidance and using your subject matter expertise and experience to identify
Requirements
design and deliver collateral. Key activities include:Standardization of all customer-facing collateral used throughout every region that we operate in.Implementation and development activities around new and emerging frameworks.Improvement / enhancement suggestions for existing collateral.Development of new collateral where required.Collaboration with the developers of LRQA's portal to aid with integration of Information Security and GDPR requirements.Business Experience CredentialsDegree level qualification in Computer Science, Computer Engineering, IT, Cyber Security, or a related field or 5 years experience working within an information security role.Minimum 5 years experience in delivering consultative engagements using well known risk management and data security frameworks, standards, and methodologies.Current CMMC Professional (CCP) or the ability to attain this within three months.ISO 27001 Lead Auditor or Lead Implementer qualificationExperience implementing SOC 2 Type 2 is strongly preferable.CISSP/CISM (or equivalent) certification preferableExperience in ISO 27001 implementation and use of relevant standards to build control frameworksDemonstrable experience communicating complex information security concepts to top level (C suite) management.Experience in cyber resilience planning, security operations, and managing security professionalsStrong communication skills and the ability to build rapport with key stakeholdersExperience in some or all of the following areas of information security:GDPR regulationTISAXCIS ControlsDORANIS 2 DirectiveHIPAA / NHS DSPT / Healthcare regulationBusiness ContinuitySupplier ManagementIncident ManagementPhysical SecurityWhat we offerWe are a people-focused, high-performing, high-trust professional services team. You'll be part of a diverse and growing international group of consultants, and we go out of your way to make sure our consultants feel part of our team. We use, Chief Information Security Officer- Interim-CISO Interim CISO with extensive experience in managing complex incidents is urgently needed to support a leading London University to address two critical incidents. The Interim CISO will need to be a very senior operator with..., A leading UK bank is seeking an IT Security Leader to drive the organization's IT security strategy while ensuring compliance and managing security operations. The ideal candidate has senior leadership experience in a regulated environment, specifically with ISO/IEC 27001...