Working Arrangement: Hybrid, with flexible working options
Contract: Permanent, full-time
Overview
Our client, an international insurance business, is seeking a Cyber Security Consulting Lead to provide security assurance and technology assessments for IT and business change projects across cloud and on-premises environments.
You will work closely with architects, solution design specialists and business stakeholders to identify cyber threats, assess control gaps and embed security requirements into solution designs. The role has significant scope across security architecture, risk assessment, NIST-based assurance and global security initiatives.
Responsibilities
- Lead cyber security assurance, assessments and advisory activity for IT and business projects.
- Assess solutions against NIST 800-53 security standards and compliance requirements.
- Partner with security architecture and technical teams to define security patterns and embed appropriate controls.
- Develop non-functional security requirements and guide their integration into solution designs.
- Conduct security risk assessments and recommend appropriate mitigations.
- Identify security weaknesses and drive remediation through to secure outcomes.
- Guide and influence stakeholders in addressing non-compliant processes.
- Contribute to strategic regional and global cyber security projects and initiatives.
Requirements
- Demonstrable experience applying security and risk standards, including ISO 2700X, ISO 31000, NIST 800 and PCI DSS.
- Strong understanding of identifying security weaknesses and managing mitigations through to resolution.
- Experience working across in-house and outsourced service models.
- Experience working across multiple time zones and multicultural environments.
- Ability to work independently while seeking appropriate support when required.
- Financial services experience, including awareness of APRA, PRA and FCA requirements.
- Certified Information Systems Security Professional (CISSP).
- Sherwood Applied Business Security Architecture (SABSA) certification or equivalent.
- Certified Cloud Security Professional (CCSP) or equivalent.
- Certified in Risk and Information Systems Control (CRISC).
- Certified Information Security Manager (CISM) or another relevant security certification.
- 30 days' annual holiday, with the option to buy up to two additional days.
- Flexible working options, including part-time, job share and compressed hours.
- Employer pension contributions of 10% of basic salary.