Information Security Compliance Consultant

Visa

Not Interested
Bookmark
Report This Job

profile Job Location:

Cambridge - UK

profile Monthly Salary: Not Disclosed
Posted on: 21 hours ago
Vacancies: 1 Vacancy

Job Summary

As Information Information Security Compliance Consultant - Featurespace you will help us achieve our goals and deliver success on behalf of our customers by:

  • Building and overseeing our Information Security controls framework and environment in line with industry standards to ensure enterprise-wide security compliance with Visa Key Controls and Customer expectations.
  • Collaboratively creating implementing and maintaining security policies standards and procedures which improve our posture in alignment with industry best practice internationally recognised compliance standards and Visa Policies and Key Controls.
  • Ensuring the annual successful execution of all compliance recertification efforts by leading and coordinating our preparation responses and submissions for certifications such as PCI DSS SOC2 and DORA etc.
  • Providing assurance to our customers by coordinating the responses to customer RFP questions and customer audits in the Information Security area.
  • Coordinating with and supporting the Visa Legal Governance Risk & Compliance teams in understanding and quantifying security risk responding to third-party requests and performing security assessments of our suppliers their products and services.
  • Driving security awareness promoting security within Featurespace and collaborating with our customers and industry partners to develop the maturity and standing of security within our industry.
  • Acting as a subject matter expert on compliance requirements and consulting across the enterprise to ensure our products and services are secure and compliant by design and facilitating the timely closure of gaps and findings identified through the Visa vulnerability management and secure assessment processes. 

Responsibilities:

As a company we hire people with a willingness to adapt to a variable role so along with the key responsibilities below we ask for ownership of any other duties as required.

  • Create review update and complete information security policy standards and guidelines maintaining document management disciplines and dependency mapping consulting with and coordinating the input of SMEs as needed.
  • Conduct security risk assessments business impact analyses and recommend appropriate control improvements.  Provide oversight and assurance of corrective preventative or remediation activities escalating issues at risk of missing deadlines in a timely and efficient manner.
  • Maintain and govern Featurespace risk records within Visa risk management tooling working in collaboration with the Visa Governance Risk and Compliance team and identified Featurespace Risk Owners to document and quantify risks track remediation plans support risk acceptances and exception requests and facilitate regular risk reviews prioritisation and overall residual risk reduction.
  • Coordinate and lead our responses to customer RFP questions and security audits in a timely and efficient manner helping to create repeatable re-usable answers and examples for common questions and ensuring all responses are traceable to SMEs and responsible teams within the organization. Represent the Information Security Department directly with customers when required.
  • Stay up to date with the latest security and technology trends and development. Research and evaluate emerging security threats and closely monitor and understand current and potential changes to compliance frameworks and regulations making recommendations on mitigations and programs for the organization to address them.
  • Coordinate Security Awareness and Training sourced from the wide Visa Cyber team to ensure that security architecture and compliance concepts and best practices are embedded throughout the Featurespace business and product teams. Develop facilitate and deliver education and training tailored for Featurespace Teams as required to uphold compliance. 
  • Consult with internal teams clients auditors and regulators regarding information security compliance and related topics as necessary.  Act as a subject matter expert when internal teams have questions/need guidance and be a liaison with external compliance advisory firms as well as the governing body and industry communities.
  • Liaise with internal teams and stakeholders (e.g. Legal Privacy GDPR Risk and Compliance) in relation to security compliance to ensure coordination of requirements agreed controls and shared consistent documentation and tooling wherever possible.
  • Gain knowledge and understanding of our goals and culture and ensure that our control and compliance framework delivers the information security architecture and compliance strategy aligned with industry best practices and the company security posture defined by the CISO.
  • Contribute advice and guidance for departmental security strategies to manage identified risks and ensure adoption and adherence to standards and compliance frameworks.
  • Develop and maintain documentation controls processes workflows metrics reporting solutions and applications/tools as needed to ensure effective operation and visibility of the state of the compliance function.
  • Engage as required during actual and simulated incidents and recovery operations.
  • Ensure all processes and controls that fall within your area of responsibility are operating effectively and are correctly evidenced.
  • Travel periodically as required for customer company or relevant events.

This is a hybrid position. Expectation of days in office will be confirmed by your hiring manager.


Qualifications :

  • 3 or more years experience with ensuring information security compliance preferably in highly regulated environments.
  • Strong experience working with building and implementing successfully a range of security control frameworks range such as SOC 2 ISO27000 and PCI e.g. worked as SOC2 Lead Auditor/Implementer.
  • Strong experience of ISMS security risk management and associated practices.
  • Experience of performing internal or third-party security compliance assessments.
  • Bachelors degree preferred in information assurance computer science engineering or related field.
  • Demonstrated ability to multi-task work calmly under pressure think analytically understand complex systems and communicate complexity effectively.
  • Ability to communicate clearly with both technical and non-technical staff and stakeholders at different levels across the business.
  • Excellent written and verbal communication as well as good presentation skills. Proficient English language skills are required.
  • Be able to build relationships and influence actions from all areas of the business including senior leadership engineering teams and auditors and regulators.
  • Ability to adapt and stretch capabilities and skills to meet the business needs of a fast-growing technology firm.
  • Ability to create repeatable and re-usable principles processes and solutions.
  • Broad knowledge / understanding of basic technical security controls / control frameworks including but not limited to areas such as cloud computing network security endpoint security and identity and access management etc.
  • Knowledge of common security vulnerabilities/risk factors in information processes infrastructure and applications e.g. Separation of Duties CVEs OWASP Top 10 etc.

Preferred Qualifications:

  • Preferably one or more of the following security qualifications - ISO270001 LI/LA PCIP ISA CISA CISM or similar
  • Strong/Deep understanding of information security controls technologies policies processes and best practices as applied to applications compute networking cloud and containers.
  • Experience / knowledge of Financial Services Compliance such as PCI

Additional Information :

Visa is an EEO Employer. Qualified applicants will receive consideration for employment without regard to race color religion sex national origin sexual orientation gender identity disability or protected veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with EEOC guidelines and applicable local law.


Remote Work :

No


Employment Type :

Full-time

As Information Information Security Compliance Consultant - Featurespace you will help us achieve our goals and deliver success on behalf of our customers by:Building and overseeing our Information Security controls framework and environment in line with industry standards to ensure enterprise-wide ...
View more view more

Key Skills

  • Economics
  • Assessment
  • Compensation
  • Information Technology Sales
  • IT Service Desk

About Company

Company Logo

Visa (NYSE: V) is a world leader in digital payments, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories. Our purpose is to uplift everyone, everywhere by being the best way to pay and b ... View more

View Profile View Profile