Managing Information Security Consultant (GRC)

LRQA

Not Interested
Bookmark
Report This Job

profile Job Location:

Birmingham - UK

profile Monthly Salary: Not Disclosed
Posted on: 5 hours ago
Vacancies: 1 Vacancy

Job Summary

Job ID:43406
Location:Birmingham : 1 Trinity Park : Bi LRQA - London - 4 Moorgate
Position Category:Consulting
Position Type:Employee Fixed Term

At LRQA Cybersecurity our focus is on excellence in cyber security. We have teams that offer world class services in red teaming penetration testing threat intelligence research and development detection and response governance risk and compliance and plenty more. Our business is global and so are our clients. We work closely with central banks central and local government critical national infrastructure large retailers and plenty more besides!

Were an award winning provider of cyber security services and were are at a very exciting stage of development. We are looking for the right people to join us as we embrace the challenges thrown up by the advancements within the IT industry and within the threats faced. LRQA will be at the forefront of this arena and we want to seek the right people to join the team and make it happen.

The Role

The purpose of this role is to deliver information security consultancy to LRQA clients specialising in governance risk and compliance (GRC). As a Managing Consultant you will also assume leadership or management responsibilities - for example: People management or service development and ownership.This role is hybrid with occasional travel to client sites and LRQA offices as required.

What Youll be Doing in Your Role

Delivery

A core competency for this role is the ability to effectively deliver engagements to clients to a consistently high standard. As a Managing Information Security Consultant you would be expected to drive engagements whilst supporting other members of the team with the ultimate aim of achieving excellent client satisfaction results.

Examples of the type of delivery activities a Managing Information Security Consultant may participate in include:

  • Provision of client support to achieve compliance/certification against recognised standards such as ISO 27001 the GDPR NIST CSF and PCI DSS.
  • Independently conducted ISO/IEC 27001:2022 audit activities.
  • Provision of expert advice to clients on governance structures including policies procedures and controls to achieve compliance and reduce risk exposure
  • Cybersecurity Maturity Assessment engagements.
  • Facilitation of information asset discovery workshops and engagements.
  • Facilitation of risk assessment workshops and engagements.
  • Delivery of business continuity scenario tabletop exercises.
  • Delivery of external stakeholder training and awareness presentations.

Leadership

  • Mentor coach and guide team members to enhance their technical and consulting capabilities.
  • Develop and deliver training programs on GRC risk management and information assurance best practices.
  • Establish thought leadership by contributing to white papers webinars and conferences in the GRC space.
  • Collaborate with cross-functional teams to drive continuous improvement in service delivery and client satisfaction.

Pre-Sales

Liaising with the Pre-Sales team and account managers attend client meetings and scoping calls to aid in the effective scoping of engagements and delivery of customized consultancy services leveraging other LRQA Cybersecurity products and services where appropriate. This will involve:

  • Identification of client requirements
  • Effort estimation
  • Consultative sales where a need is identified (Light)

Service Development

Effective service development is key to the success of GRC and you would contribute to this by providing guidance and using your subject matter expertise and experience to identify design and deliver collateral. Key activities include:

  • Standardization of all customer-facing collateral used throughout every region that we operate in.
  • Implementation and development activities around new and emerging frameworks.
  • Improvement / enhancement suggestions for existing collateral.
  • Development of new collateral where required.
  • Collaboration with the developers of LRQAs portal to aid with integration of Information Security and GDPR requirements.

Business Experience Credentials

  • Degree level qualification in Computer Science Computer Engineering IT Cyber Security or a related field or 5 years experience working within an information security role
  • Minimum 2 years experience in delivering consultative engagements using well known risk management and data security frameworks standards and methodologies.
  • ISO 27001 Lead Auditor or Lead Implementer qualification
  • CISSP/CISM (or equivalent) certification preferable
  • Experience in ISO 27001/NIST CSF implementation and use of relevant standards to build control frameworks
  • Demonstrable experience communicating complex information security concepts to top level (C suite) management.
  • Experience in cyber resilience planning security operations and managing security professionals
  • Strong communication skills and the ability to build rapport with key stakeholders

Experience in some or all of the following areas of information security:

  • GDPR regulation
  • PCI DSS
  • CMMC
  • SOC 2
  • DORA
  • NIS 2 Directive
  • HIPAA / NHS DSPT / Healthcare regulation
  • Business Continuity
  • Supplier Management
  • Incident Management
  • Physical Security

What we offer

We are a people-focused high-performing high-trust professional services team. Youll be part of a diverse and growing international group of consultants and we go out of your way to make sure our consultants feel part of our team. We use technology to ensure were always communicating with each other and schedule time every week to talk as a team.

The successful candidate will have opportunities to:

  • Make a difference as clichéd as it sounds this really is true. We encourage all employees to challenge norms and empower them to get involved. This might be getting involved with other teams or developing a new service offering but if you want to do something we always try to make it happen
  • Get involved enjoy blogging or public speaking Our team is committed to getting involved in industry discussions. We make time to attend conferences and get involved in the infosec community
  • Develop their skills we love learning and ensure we find time for professional development. This isnt just about collecting certifications and attending training courses gaining and sharing knowledge in new areas is vital. These dont always have to be directly related to your day job; in fact we actively encourage developing knowledge in new and exciting domains

Pre-Employment Checks

If you are successful in securing a role with us we will carry out pre-employment checks in accordance with what is allowed under local checks will include (as permitted):- right to work identification verification of employment history education and criminal may involve the third-party supplier to run the background checks as needed and your data will be retained for a period as needed for the purpose of employing data will be stored in accordance with all relevant privacy contact us if you have any questions or concerns.

Diversity and Inclusion at LRQA:

We are on a mission to be the place where we all want to work and we are passionate about embracing different perspectives because we understand the value this brings to our business our clients and each other. We are all about creating a safer and more sustainable future and our inclusive culture is right at the heart of our business.

Together our employees make our communities better and we want you to be part of our diverse team!

LRQA is a leading global assurance integrity and expertise we bring to our partnership with clients support their journey to a safer more secure and more sustainable future. (Group entities).

Copyright LRQA 2021. All rights of use. Privacy Policy.


Required Experience:

Contract

Job ID:43406Location:Birmingham : 1 Trinity Park : Bi LRQA - London - 4 MoorgatePosition Category:ConsultingPosition Type:Employee Fixed TermAt LRQA Cybersecurity our focus is on excellence in cyber security. We have teams that offer world class services in red teaming penetration testing threat int...
View more view more

Key Skills

  • Economics
  • Assessment
  • Compensation
  • Information Technology Sales
  • IT Service Desk

About Company

Company Logo

We help businesses evolve by connecting them with tomorrow’s thinking, today.

View Profile View Profile