2 дня назад
Cyber Security Governance & Assurance Specialist
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cyber Security Governance & Assurance Specialist (GRC/ISO 27001/NIST): Delivering and assuring cyber security controls, governance frameworks, risk processes, and compliance reporting for UK Government customer platforms with an accent on control effectiveness, audit readiness, and security-by-design. Focus on assessing cyber risks, validating controls, driving remediation, and translating technical risk into measurable business impact.
Location: Hybrid role based at the New Bailey Manchester office or One Braham London office, with 3 days together and 2 days wherever. Security clearance eligibility is required.
Company
A UK communications group serving consumers, businesses, public sector organisations, and communications providers through major telecommunications brands.
What you will do
- Identify, assess, and report cyber security and information risks in line with internal, regulatory, contractual, and statutory requirements.
- Establish, maintain, and improve information governance, cyber security, data protection, and GRC frameworks.
- Design and enforce security policies, standards, and control baselines aligned with ISO 27001, NIST, and CIS.
- Evaluate security controls, perform assurance testing, support audits and maturity assessments, and drive remediation.
- Analyse cyber risk registers, policy exceptions, audit findings, and data security reviews to produce management and executive reporting.
- Work with infrastructure, cloud, engineering, business, and communications teams to embed security by design and improve security awareness.
Requirements
- Experience in security assurance and governance, including assurance reviews, control testing, audit support, and governance forums.
- Experience with governance, risk management, compliance, risk assessments, remediation, and GRC tooling.
- Experience designing policies, standards, and security control frameworks.
- Knowledge of ISO 27001, NIST, and CIS frameworks.
- Eligibility for security clearance is required.
Nice to have
- Cyber security, governance, or risk certifications such as CISSP, CISM, CRISC, or ISO 27001 Lead Implementer/Auditor.
- Experience in regulated industries, including telecommunications, finance, or the public sector.
- Experience with audit management, external certification processes, cloud security governance, DevSecOps, or Zero Trust.
- Experience influencing security culture and driving awareness across teams.
- Familiarity with large-scale enterprise environments.
Culture & Benefits
- Hybrid working model with flexibility to work away from the office for two days per week.
- 10% on-target annual bonus.
- Private GP access, healthcare and dental options, gym memberships, and other flexible benefits.
- Paid carers leave of up to two weeks and enhanced maternity, paternity, and adoption leave.
- Pension scheme with 5% employee and 10% employer contributions.
- Holiday purchase scheme and discounts on telecommunications products.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →