Senior Information Security Consultant

The Automobile Association
London, UK
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Adobe Analytics Software System Penetration Testing Software as a Service Cloud Computing Security Cyber Security PCI Data Security Standards Web Platforms Information Security Management System

Job description

Experteer Overview As Senior Information Security Consultant, you will shape the future of cyber security across The AA and embed security into technology change from day one. You’ll work across cloud, digital platforms and major transformation programmes to enable innovation while managing cyber risk. Reporting to the CISO, you’ll influence solution design, strengthen governance and ensure regulatory compliance across the technology estate. This role offers the chance to impact a well-known brand while advancing security at scale. Pay / Benefits * Act as cyber security subject matter expert across technology and business change throughout the project lifecycle * Lead security risk assessments, control assurance activities and penetration testing to mitigate risks before go-live * Maintain and evolve Information Security Management System aligned with ISO 27001, NIST and PCI DSS * Partner with Architecture, Engineering, Technology and third-party suppliers to embed security controls * Produce security documentation, risk reports and recommendations for business decisions and regulatory compliance * Contribute to security awareness initiatives and governance, policies and assurance processes Tasks * Proven experience in an Information Security Consultant, Cyber Security Consultant, Security Architect or Cyber GRC role in a complex tech environment * Strong knowledge of ISO 27001, PCI DSS, NIST or equivalent standards * Experience conducting security risk assessments and advising on secure design across multiple projects * Good understanding of cloud security, enterprise infrastructure, networks, SaaS and modern applications * Excellent stakeholder management and communication skills with ability to influence technical and non-technical audiences * Professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor or PCI DSS would be advantageous Key requirements * annual bonus * cash-car allowance * private medical insurance * 25 days annual leave plus bank holidays * pension with up to 7% employer contribution * employee assistance programme

Requirements

Produce security documentation, risk reports and recommendations for business decisions and regulatory compliance * Contribute to security awareness initiatives and governance, policies and assurance processes Tasks * Proven experience in an Information Security Consultant, Cyber Security Consultant, Security Architect or Cyber GRC role in a complex tech environment * Strong knowledge of ISO 27001, PCI DSS, NIST or equivalent standards * Experience conducting security risk assessments and advising on secure design across multiple projects * Good understanding of cloud security, enterprise infrastructure, networks, SaaS and modern applications * Excellent stakeholder management and communication skills with ability to influence technical and non-technical audiences * Professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor or PCI DSS would be advantageous Key requirements * annual bonus * cash-car allowance * private medical insurance * 25 days annual leave aay _ bank holidays * pension with up to 7% employer contribution * employee assistance programme

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on eu.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:57 min

Following security research and continuous developer education

Martin Schmiedecker · LIVE

1:54 min

Measuring developer experience during architecture modernization

Mauricio Frias Mauricio Frias

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:31 min

Web platform advancements and shared technological ecosystems

Nico Martin · LIVE

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all