GRC Consultant

NTT Limited

Greater London

On-site

GBP 70,000 - 110,000

Full time

13 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

NTT DATA is hiring a GRC Consultant (Cyber Assurance / Security Operations Manager) to ensure security controls—people, process and technology—are in place, operating as designed, and aligned to the business risk posture. You will design, develop, test and evaluate information security throughout its lifecycle to enable safe and secure outcomes for business services.

In this role you will lead governance, risk and compliance initiatives, coordinate with suppliers and internal teams, manage

Responsibilities

  • Provide security expertise across security standards and accreditations.
  • Measure and control the effectiveness of the security controls framework and maintain the Information Security Management System.
  • Develop Information Security Management Plans incorporating Regulatory, Legal and Compliance in relation to security policies.
  • Identify risks and emerging cyber vulnerabilities; lead risk mitigation plans.
  • Coordinate with Service Management to ensure partners and suppliers adhere to standards and verify KPIs.
  • Work with 1st, 2nd and 3rd lines of defence on cyber risk and data privacy considerations.
  • Lead governance, risk and compliance improvements aligned to policy and industry best practice.
  • Maintain documentation for process and security controls and support ISO 27001 readiness.

Job description

Make an impact with NTT DATA Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion - it’s a place where you can grow, belong and thrive.

Your day at NTT DATA

The GRC Consultant (Cyber Assurance / Security Operations Manager) is primarily responsible for ensuring the security controls (people, process, technology) are in place and operating as designed. The primary aim is the design, development, test and evaluation of information security throughout its lifecycle. This is to ensure the business purpose of the system is enabled in a safe and secure manner based on the alignment of identified risks to the acceptable risk posture of the business. Looking ahead to future opportunities. As our business continues to grow, we are building a pipeline of exceptional talent for upcoming positions across the UK.

Key responsibilities

Providing security expertise across security standards and accreditations, measure and control the effectiveness of the security controls framework and maintain the Information Security Management System. Deriving and delivering documented Information Security Management Plans which incorporate Regulatory, Legal and Compliance in relation to applicable security policies. Standards and guidelines Assisting with the identification of identified risks and emerging cyber security vulnerabilities and threats. The subsequent analysis to quantify and lead risk mitigation plans Work with Service Management to ensure that partners and suppliers adhere to agreed standards, policies and verify/evidence appropriate compliance and security KPIs Work closely with 1st, 2nd and 3rd lines of defence on all matters relating to cyber security, information assurance, cyber risk, data privacy including regulatory and compliance considerations Lead the development and enhancement of governance, risk and compliance aligned to policy, standards an industry good practice Ensure that continuous assessment, identification, analysis and reporting of useful metrics to enable informed risk based decisions to be taken Constructively challenge established processes and controls to identify, recommend and facilitate continuous improvement, ensuring that all personnel (including senior stakeholders) understand their responsibilities in relation to security risk mitigation and remediation Review and verify that documentation relating to process and technical security controls are maintained Develops and maintains Information Security Management practice and process to ensure certification to required industry standards (e.g., ISO 27001) within relevant geographic boundaries. Develops, proposes and seeks sponsorship for changes to policies, procedures and controls to ensure the integrity of the in-scope IT services and effective management and control of information assets. Facilitates the implementation of these controls. Performs focused information risk assessments of existing or new services and technologies, alongside the Operational/Service Management team and technology subject matter experts. As required, will extend the assessment of existing and proposed services to third party suppliers, including the facilitation of IT Security checks during the supplier onboarding and contract lifecycle to ensure coherent approach to risk management Coordinate audit, ITHC and risk assurance activities to evidence compliance with established regulatory and governance requirements including governance of any Remediation Action Plan (RAP) to ensure timely mitigation of identified risks / vulnerabilities Maintains strong working relationships with individuals and groups involved in managing information risk across the in-scope services and aligned suppliers / 3rd parties Chairs and co-ordinates the Security Working Group (SWG) and actively participates in supporting/governing forums Contribute to the analysis and mitigation of data protection risks Monitors information security incidents, contributing to incident response and root cause analysis. Will own resulting actions as required where they relate to required changes in IT Security and Information Risk Management policy and controls Security operations and incident response, liaison with internal teams and 3rd party suppliers

Desirable Skills and Experience
  • Experience with the design concepts associated with adoption of Cloud platforms (AWS and/or Microsoft Azure)
  • An understanding of the native security capabilities and good practice within Cloud platforms (AWS and/or Microsoft Azure)
  • CISSP, CISM, CCSP, CRISC or equivalent experience
  • Good knowledge covering several of the following examples (this list is not exhaustive): AD (Active Directory), Cryptography, End User Computing, IAM, PKI, Server hardening, SIEM, SOAR, virtualisation (VMware)
  • Familiarity with MITRE ATT&CK
  • Familiarity with ITIL
Workplace type

About NTT DATA

NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world’s leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. Our consulting and industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 70 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is part of NTT Group, which invests over $3 billion each year in R&D.

Equal Opportunity Employer

NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category.

Is innovation part of your DNA? Do you want to enable a connected future for people, organizations, and society? Join our growing global NTT family and you’ll be part of the world’s largest ICT company (by revenue). We’ve combined the capabilities of 28 remarkable companies to become one, leading technology services provider. Together, we help our people, clients, and communities do great things with technology to create a more secure and connected future. We employ 40,000 people across 57 countries. By bringing together the world’s best technology companies and emerging innovators, we work together to deliver sustainable outcomes to businesses and the world. Innovation is part of our DNA. We believe it’s key to what makes us different. So, we strive to move forward, challenge the status quo, and drive excellence through the technologies we integrate and the services we deliver around the world. The result is connected cities, connected factories, connected healthcare, connected agriculture, connected conservation, connected mobility, and connected sport. Together we enable the connected future. You’ll be joining a global employer that is committed to attracting, growing and keeping the best talent. A place where you will be at the heart of our success!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Architect
Security Architect

The Nippon Telegraph and Telephone Corporation (NTT) • City Of London

On-site
GBP 90,000 - 125,000
Cloud Security Architect (security assessments)
Cloud Security Architect (security assessments)

NTT DATA • England

On-site
GBP 70,000 - 90,000
Flexible working options
Continuous growth and development opportunities
Security Architect
Security Architect

NTT DATA • Greater London

On-site
GBP 85,000 - 120,000
Flexible work options
Tailored benefits
Security Architect
Security Architect

NTT DATA, Inc. • Greater London

On-site
GBP 85,000 - 120,000
Data Business Analyst
Data Business Analyst

NTT Limited • Greater London

On-site
GBP 55,000 - 70,000
Security development & Test Manager
Security development & Test Manager

NTT DATA UK Ltd. • Birmingham

Hybrid
GBP 80,000 - 110,000
Flexible work options
Learning & Development opportunities
Diversity & inclusion program
Information Security Manager
Information Security Manager

NTT DATA • England

Hybrid
GBP 60,000 - 80,000
Flexible work options
Continuous learning opportunities
Inclusive work environment
Security Architect
Security Architect

NTT Limited • Greater London

On-site
GBP 90,000 - 130,000
Solution Architect - UK Defence Accounts
Solution Architect - UK Defence Accounts

NTT Limited • Birmingham

On-site
GBP 75,000 - 110,000
Telco/Design Architect
Telco/Design Architect

NTT DATA • Greater London

Hybrid
GBP 70,000 - 90,000
Flexible work options
Continuous growth and development opportunities
Diversity and inclusion initiatives