Information Security Risk

1 week ago


London, Greater London, United Kingdom WeAreTechWomen Full time

Our people make us who we are. We're a diverse and inclusive bunch, and it's important you can feel you belong here. We value everybody for who they are and what they bring to the table, supporting one another as we continue to deliver for our customers.

LI-KS1

  • Create & Maintain an information security management system (ISMS) capable of demonstrating compliance against internal security requirements and external commitments including certification and regulatory requirements.
  • Provide subject matter expertise in the application of established standards including NIST, PCI-DSS, GDPR, COBIT, ISO 27001 and Cyber Essential compliance to any new or existing programme of work.
  • Prepare and support internal and / or external compliance audit activities.
  • Manage remediation of any audit (internal & External) non-conformities.
  • Ensuring security policy (on a risk-based approach) is produced, signed off from relevant stakeholders, published and communicated. Also ensure that the policy is being managed in-life and updated through yearly or ad-hoc reviews.
  • Relevant security standards documentation is being produced in consultation with Technical teams.
  • Lead on providing information on requests from Three UK Customers (B2B) on Three UK's security practices.
  • Provide support in proactive and effective oversight (and where appropriate challenge) of the technology and security risk management frameworks, methodologies, processes, assurance, remediation and reporting activities across the company.
  • Assist with the design, build and implementation of a Technology and Security Risk framework through working in conjunction with technology, security and Enterprise Risk and compliance teams.
  • Support Technology and Security teams in Undertaking risk assessments and identifying emerging risks through continuous assessment of the inherent and residual risk exposure. Provide robust challenge to the operational teams as they identify, assess, manage and report their technology risks (including Information Security and Cyber Risk) through various tools and activities (including risk and control assessments, key indicators, issue and incident management, and control assurance).
  • Manage and continually improve Three's Security Exception process.
  • Work effectively with Enterprise risk and compliance function to escalate any enterprise level Technology and Security risks.
  • Operate GRC tool for Risk Management to record, track and monitor risks and controls.
  • Support ongoing education and awareness activities around agreed Security policies, Risk management frameworks and governance across the company.
  • Working with Stakeholders and Partners to ensure that Three delivers and remains compliant against key
    security and privacy standards and certifications
  • Maintains up-to-date knowledge of the legal & regulatory requirements that can impact Technology and
    Operations and its Partners.
  • Uses comprehensive knowledge of legal and regulatory obligations and industry best practice and frameworks
    (e.g NIST, COBIT, ISO27001, PAS 555) to ensure technology standards compliance is achieved.
  • Schedules risk and compliance audits, review the outcomes audit process; Directs compliance issues to
    appropriate resources for investigation and resolution.

Our people make us who we are. We're a diverse and inclusive bunch, and it's important you can feel you belong here. We value everybody for who they are and what they bring to the table, supporting one another as we continue to deliver for our customers.

LI-KS1

  • One of the Risk or security certifications (CISSP, CRISC, CISM)
  • Good knowledge and practical experience of NIST, PCI-DSS, GDPR, COBIT, ISO 27001 or Cyber Essentials.
  • Previous experience in similar role. Ability to work in dynamic and changing environment.
  • Excellent team player who can influence, help and support others.
  • Working with Stakeholders and Partners to ensure that Three delivers and remains compliant against key
    security and privacy standards and certifications
  • Maintains up-to-date knowledge of the legal & regulatory requirements that can impact Technology and
    Operations and its Partners.
  • Uses comprehensive knowledge of legal and regulatory obligations and industry best practice and frameworks
    (e.g NIST, COBIT, ISO27001, PAS 555) to ensure technology standards compliance is achieved.
  • Schedules risk and compliance audits, review the outcomes audit process; Directs compliance issues to
    appropriate resources for investigation and resolution.
#J-18808-Ljbffr

  • London, Greater London, United Kingdom Security Bank & Trust Co. Full time

    Overview:Join a dynamic team at our client, where innovation and collaboration drive their mission to redefine automotive excellence. Since the inception of Project Grenadier in 2017, the company has experienced rapid growth, transitioning from a startup to a thriving enterprise.The Role:As an IT Risk and Security Architect, you will play a pivotal role in...


  • London, Greater London, United Kingdom Yolk Recruitment Ltd Full time

    Conexus has partnered with a Global Pharmaceutical Company to source an Information Security Risk Manager who will be responsible for assessing, reporting, and managing information security risks identified in our systems and data, business processes, and third-party service providers. You will work closely with IT colleagues and business stakeholders based...


  • London, Greater London, United Kingdom Conexus DX Limited Full time

    Conexus has partnered with a Global Pharmaceutical Company to source an Information Security Risk Manager who will be responsible for assessing, reporting, and managing information security risks identified in our systems and data, business processes, and third-party service providers. You will work closely with IT colleagues and business stakeholders based...


  • London, Greater London, United Kingdom Boston Consulting Group Full time

    WHAT YOU'LL DO As the Information Security Risk Manager at BCG, you will be a key player in our efforts to protect digital assets and manage cybersecurity risks. This pivotal role involves overseeing the risk management framework, maintaining the risk register, and managing the overall risk operations within the organization. Your strategic and operational...


  • London, Greater London, United Kingdom Brown & Brown Europe Full time

    Information Security Risk AnalystLocation: Hybrid - London Package: Negotiable + BenefitsThe Information Security Risk Analyst III at Brown & Brown is responsible for analysing information security controls both within our organisation and with third-party entities. This analysis aims to identify and assess associated information security risks, and...


  • London, Greater London, United Kingdom Informa Group Plc. Full time

    Informa is a leading international events, intelligence and scholarly research group. We're the specialist's specialist. Through hundreds of powerful brands, we work with businesses and professionals in specialist markets, providing the connections, intelligence and opportunities that help customers grow, do business, make breakthroughs and take better...


  • London, Greater London, United Kingdom Stott and May Full time

    Information Security Governance Lead Location: London, UK Basic + Bonus + Share options + Benefits As an Information Security Governance Lead, you will be an integral part of the Security & Trust Team, driving the implementation of industry standards and best practices. This hands-on role offers a unique opportunity to contribute to a thriving and...


  • London, Greater London, United Kingdom Brown and Brown Insurance Full time

    You are applying for a job at: Brown & Brown (Europe) We are part of Brown & Brown Insurance group. Built on meritocracy, our unique company culture rewards self-starters and those who are committed to doing what is best for our customers. Information Security Risk Analyst Location: Hybrid - London Package: Negotiable + Benefits The Information...


  • London, Greater London, United Kingdom Stott and May Full time

    Job Title: Information Security Governance LeadCompany: Thriving and Progressive CompanyAs an Information Security Governance Lead, you will play a crucial role within the Security & Trust Team, overseeing the enforcement of industry standards and optimal protocols.This dynamic position provides a valuable chance to make a significant contribution to a...


  • London, Greater London, United Kingdom Arc IT Recruitment Full time

    Information Security Risk AnalystLondon / HybridTo £50k plus bonus plus bensInformation Security Risk Analyst is required by financial services organisation. This role will join the 2nd Line Information Security Risk team within the Group Risk Function. The key function of this role will be to investigate potential data incidentsor breaches identified by...


  • London, Greater London, United Kingdom Gemserv Ltd Full time

    Gemserv is an expert provider of professional services. We are purpose-driven, working across multiple sectors including energy, low carbon, the public sector and health to tackle today's social and environmental challenges. Established in 2002, the business provides a range of consultancy and outsourcing capabilities including programme management, market...


  • London, Greater London, United Kingdom ASOS Full time

    Company DescriptionWe're ASOS. We blend our flair for fashion with our love of cutting- edge technology, but more importantly were interested in how we can bring the best out of you.We exist to give people the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you're free to be your true self without judgment, and channel...


  • London, Greater London, United Kingdom eMed Full time

    The Technology/Information Security Risk and Compliance Manager is responsible for technology / information security risk management and security compliance management, supporting eMed's Global Clinical Services / Babylon Healthcare Services Limited's Information Security Management System (ISMS) is adopted and effectively implemented within the UK....


  • London, Greater London, United Kingdom eMed Full time

    The Technology/Information Security Risk and Compliance Manager is responsible for technology / information security risk management and security compliance management, supporting eMed's Global Clinical Services / Babylon Healthcare Services Limited's Information Security Management System (ISMS) is adopted and effectively implemented within the UK. WHAT...


  • London, Greater London, United Kingdom CornerStone - Risk, Cyber & Security Full time

    CornerStone is a leading independent Security Risk Consultancy, and we are now looking for a Technical Security Consultant to join our award-winning team in a UK-wide and Europe capacity. Personal and career development is really important to us, and you can expect our investment in you to include personalised development opportunities combined with a...


  • London, Greater London, United Kingdom WPP Full time

    #LI-Hybrid Why we're hiring:WPP IT provides IT services for WPP, group owned operating companies and agencies. The WPP group is the world's largest communications services group, and as a creative transformation company, WPP is helping its clients transform the future through extraordinary work. WPP IT is an integral part of that journey, and we are proud to...


  • London, Greater London, United Kingdom Xpertise Recruitment Full time £100,000

    Head of Information Security - Midlands (Hybrid) - £100k + Car Allowance + Bonus Information Security | Strategy | Governance | Stakeholder Management | Risk | ISO27001Salary: £100k + Car Allowance + Bonus Midlands (Hybrid) Are you an Information Security leader looking for the next challenge in your career? Have you previously been responsible for...


  • London, Greater London, United Kingdom Capital One Full time

    Cyber Security Manager - ISO About the Job: Join the Information Security Office (ISO) function for the Capital One UK Division. Consult on initiatives, programs, and projects to enhance Information Security. Coordinate proactive Information Security consulting on Cloud, Data Security, and more. Identify, manage, and reduce cyber security risks. Deliver...


  • London, Greater London, United Kingdom CornerStone - Risk, Cyber & Security Full time

    CornerStone is a leading independent Security Risk Consultancy, and we are now looking for a Security Project Manager with a security background and 5 years of experience to join our established award-winning team. We are seeking an individual who is looking to share their extensive skills and knowledge to support the team. This individual should enjoy...


  • London, Greater London, United Kingdom Cloudsecurityexpo Full time £550

    Information Security Consultant - Insurance, CISSP/ CISM London / Hybrid My client is an Insurance specialist who urgently require an Information Security Consultant with proficiency in Information Security Risk and Governance Frameworks, experience of performing Info Security Technical Risk Assessments and expert analytical and reporting skills. Proven...