Senior Information Security Consultant

2 weeks ago


London, Greater London, United Kingdom Gemserv Ltd Full time

Gemserv is an expert provider of professional services. We are purpose-driven, working across multiple sectors including energy, low carbon, the public sector and health to tackle today's social and environmental challenges. Established in 2002, the business provides a range of consultancy and outsourcing capabilities including programme management, market design and governance. We also have extensive and award winning capabilities across cyber security, data privacy and digital transformation. We are a B Corp, IIP Gold accredited and a Financial Times Leading Management Consultancy for 2021 and 2022. Our purpose is to make things that matter work better for everyone.

The nature of what we do means we are very much a people business. The contribution every member of the team makes to our diverse range of experience, skills and personalities is valued. We invest heavily in learning and development to enable our people to develop skills and gain experience which will enhance career prospects for life. Many who started their careers with us have rapidly progressed to more senior positions. At Gemserv no two days are the same, but we believe in a flexible approach to working which we know our employees value. We also offer an attractive package of benefits in addition to highly competitive salaries including bonus scheme, pension and healthcare, season ticket loans, discounted gym membership, Cycle to Work scheme and more. Job Description

The Role

The role will be dedicated (initially) to supporting the delivery of information security services to our contract to deliver the Smart Energy Code (SEC). Therefore, an understanding of the Energy Sector or Smart Metering would be a distinct advantage. The delivery of this multi-party code requires excellent communication and stakeholder management skills, so you would need to be a clear, concise, and authoritative communicator able to deliver to a broad range of audiences. The successful candidate will be screened against BS7858:2019 which is a key requirement. The candidate if successful will be part of the wider Cyber Security Practice and will be expected to support the delivery of information security services to our clients.

We would be interested in hearing from candidates who are looking for both permanent and fixed-term contract employment.

Responsibilities

  • Providing expert advice to Users undertaking User Security Assessments (USAs);
  • Monitoring the progress of Users who have booked USAs;
  • ensuring an accurate tracking mechanism to record:
  • Maintaining and reviewing USA-related documentation including the Security Controls Framework, AgreedInterpretations and Decision-Making Principles;
  • Undertaking validation of User management responses and Director's Letters;
  • Liaising with Users to enable an improved User management response to be provided in advance of the User CIOvalidation or Security Sub-Committee (SSC) review of Director's Letters where appropriate;
  • Briefing the Principal Security Expert on any sensitivities or emerging issues from liaison with Users and/or SharedResources and providing relevant background and issues to be considered by the SSC.
  • Monitoring all security incidents and vulnerabilities reported by Smart Energy Code (SEC) Parties or the DCC and providing an expert assessment of the materiality of the security incident or vulnerability;
  • Advising the Principal Security Expert on whether a security incident or vulnerability is material and warrants the mobilization of SMIRT;
  • Promptly taking whatever action is directed to undertake analysis of the security incident or vulnerability as required;
  • Conducting 'lessons learned' analysis after the resolution of a security incident or vulnerability.
  • Undertaking the review of ISO standards, cryptographic standards, and best practices as enshrined in the SEC
  • Maintain the SEC Security artifacts and, with the approval of the Chair, arrange for regular reviews to ensure that the artifacts are up to date.
  • Conduct ad hoc risk assessments of specific risks that may arise from time to time;
  • Reviewing user assessment reports and management responses;
  • Monitor the threat landscape and advise the SSC of any material changes arising from threats or business impact levels;
  • Contribute to procurement exercise for the annual SSC risk assessment where requested by the SSC;
  • Provide expert assistance to any external risk assessment commissioned by the SSC.
  • Conduct analysis produce papers and presentations; provide advice and make recommendations.
Qualifications

Requirements

To be successful in the role the post-holder should be able to demonstrate experience in the following areas:

  • An understanding and practical working knowledge of the Smart Energy Code (SEC) Section G
  • Technical knowledge of information security compliance (ISO27001)information management, Smart Metering, and IT security arrangements.
  • Ability to conduct risk assessments and treatments using a hybrid IS1/IS2 and ISO 27005 requirements
  • Have practical experience in undertaking ISO 27001 internal and external (field) audits
  • Have practical knowledge of the threat landscape in Smart Metering
  • Knowledge of Smart Metering and the energy market would be advantageous
  • Preferably, an understanding and working of ISO standards including ISO 27001, ISO 27005, ISO 27035 andISO22301
  • Ideally, have an industry qualification such as CISA or CISM

Skills & Qualities

  • Excellent client consulting skills and ability to engage and build relationships with stakeholders at all levels (including C-suite level)
  • Able to conceptualise opportunities and develop these through business development activities.
  • Ability to explain complex ideas concisely.
  • Ability to work independently with little to no supervision.
  • Ability to provide expertise and support in operational risk, governance, business continuity, data protection, data leakage, and privacy.
  • Passion to develop own skills and knowledge in information security and data protection compliance.
  • Proactive, 'hands-on' starter finisher and results-driven individual.
  • Highly organised and able to manage and prioritise workload.
  • Strong problem solver with high attention to detail.

The role may require occasional business travel.

Competitive salary plus bonus and excellent benefits package

Upon employment, employees should also have a sound awareness of the Company's Information, Quality, Environmental and Energy Management Systems.

Additional Information

WHAT WE OFFER
25 days annual leave, plus bank holidays
Profit related Bonus (discretionary)
Reward and recognition schemes
Flexible working
Private Bupa healthcare
Life Assurance (up to 4 times annual salary)
Matched pension contributions
Season Ticket Loan
Cycle to work scheme
Buy and Sell annual leave
Reimbursement of eye test and up to £50 towards glasses or contacts
Corporate gym rates
Employee Assistance Programme
Summer and Christmas parties, along with monthly Gembar

#J-18808-Ljbffr

  • London, Greater London, United Kingdom Adeptis Group Full time £60,000 - £70,000

    Senior Information Security Consultant | Global Cyber Security Company | £60K - 70K Location: Remote My client is a global brand with an excellent local reputation; despite their global presence they have a humble team of security experts spanning technical and information security and due to increased demand and a number of exciting client acquisitions...


  • London, Greater London, United Kingdom Context Information Security Full time

    Love Python and Django? At Context we use Django to develop our in-house web applications, the largest project being our back-office application (CHAOS) that does everything from scheduling jobs to financial forecasting and even planning social events. CHAOS already interfaces with our SugarCRM sales software via a REST API and upcoming integration work will...

  • Senior Python

    2 weeks ago


    London, Greater London, United Kingdom Context Information Security Full time

    Love Python and Django? So do we At Context we use Django to develop our in-house web applications, the largest project being our back-office application (CHAOS) that does everything from scheduling jobs to financial forecasting and even planning social events. CHAOS already interfaces with our SugarCRM sales software via a REST API and upcoming integration...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    Senior Offensive Security Consultant – UK Based - £50k-£75kJoin one of theUK's largest consultanciesas aSenior Penetration Testeras you work closely with some of the industry's best Cybersecurity professionals. The company are rapidly expanding their offensive team and are currently looking for Senior Testers to join their UK based team.The successful...


  • London, Greater London, United Kingdom Adeptis Group Full time £60,000 - £70,000

    Senior Information Security Consultant | Global Cyber Security Company | £60K - 70K Location: Remote My client is a global brand with an excellent local reputation; despite their global presence they have a humble team of security experts spanning technical and information security and due to increased demand and a number of exciting client acquisitions...


  • London, Greater London, United Kingdom Network IT Full time

    Network IT is currently recruiting for an Information Security Consultant, to join our client on a SaaS related workstream, within a multi-year modernisation programme, to provide specialist consultancy into a HR SaaS implementation. Working within a pre-existing security team, you will consult into a HR SaaS implementation workstream, acting as a Security...


  • London, Greater London, United Kingdom Network IT Full time

    Network IT is currently recruiting for an Information Security Consultant, to join our client on a SaaS related workstream, within a multi-year modernisation programme, to provide specialist consultancy into a HR SaaS implementation. Working within a pre-existing security team, you will consult into a HR SaaS implementation workstream, acting as a Security...


  • London, Greater London, United Kingdom Lorien Full time

    (SAAS) Information Security Consultant Day Rate: Up to £800 Inside IR35 DOE The Client: A leading Nordic bank requires a SAAS Information Security Consultant Location: London/Manchester - Hybrid working pattern (1/2 a Week On-site) Duration: 6 Months Rolling Contract The Role: As part of the Information Security Secure Change Team, the Information...


  • London, Greater London, United Kingdom TechNET IT Recruitment Ltd Full time

    Information Security ConsultantLondon/Dunstable HybridSalary package up to £70,000We have an exciting opportunity for an Information Security Consultant within our IT Team based in London Holborn.The purpose of this role is to ensure the security of information and systems across a business or technical portfolio, you'll also be supporting the business in...


  • London, Greater London, United Kingdom Pearson Carter Full time

    Pearson Carter are working with a Global Construction Consultancy who are in search of a Strong Security Specialist with Deep Microsoft Tech knowledge to join their growing teamMy client has had a big IT investment and because of this they're looking to get started on some exciting new projects. The company has projects with Microsoft Azure, Power Platform,...


  • London, Greater London, United Kingdom Handelsbanken Full time

    Job Introduction Our UK Information Security Team is growing and its scope covers the full breadth of information security disciplines, including privacy. We already have excellent relationships with our stakeholders, including system owners, senior management and IT teams in the UK and Sweden. To help these stakeholders provide excellent support to our...


  • London, Greater London, United Kingdom Hamilton Barnes Associates Limited Full time £50,000

    Join this team as an Information Security Consultant dedicated to supporting the delivery of information security services for Smart Energy Code (SEC) contract. You'll be a crucial part of ensuring compliance and providing expert advice within the energy sector, offering a rewarding opportunity to make a tangible impact. Conduct 'lessons learned' analysis...


  • London, Greater London, United Kingdom Wanstor Full time

    Information Security Consultant Department: Security Employment Type: Permanent - Full Time Location: Hybrid Reporting To: Chris Connolly Description Summary We are pleased to be advertising an exciting opportunity for a Information Security / Data Protection professional. This role will act as a focal point for security governance, risk &...


  • London, Greater London, United Kingdom Wanstor Full time

    Description:SummaryWe are pleased to be advertising an exciting opportunity for a Information Security / Data Protection professional. This role will act as a focal point for security governance, risk & compliance activities within Wanstor, and undertake GRC consultancy for our customers.Taking responsibility for planning and carrying out security control...


  • London, Greater London, United Kingdom Talan Full time

    Company Description Gemserv is dedicated to providing professional services across various sectors, such as energy, low carbon, public sector, and health, to address current social and environmental challenges. Established in 2002, Gemserv specializes in consultancy and outsourcing services, including program management, market design, and governance. The...


  • London, Greater London, United Kingdom Barclay Simpson Full time

    Information Security Consultant: London- £500 per day (outside IR35) Job type: Contract Sector: Financial Services, Insurance Job reference: JEM / 39761Information Security Consultant required leading financial services firm. The role will be centred around providing technical assurance & implementing controls to a range of different projects.Outline of the...

  • Security Consultant

    2 weeks ago


    London, Greater London, United Kingdom Cyber Security Jobsite Full time

    Home Security Consultant - Policy Lead - Internation... Security Consultant - Policy Lead - International Travel Cyber Security Jobsite Posted today This advertiser has chosen not to accept applicants from your region. Full Job Description Location(s): UK, Europe & Africa : UK : London || UK, Europe &Africa : UK : Gloucester || UK, Europe & Africa...


  • London, Greater London, United Kingdom Handelsbanken plc Full time

    Job Introduction Our UK Information Security Secure Change Team provides InfoSec Subject Matter Expertise to the Bank's change portfolio. As part of the Information Security Secure Change Team, the Information Security Consultant (SaaS) will be an Information Security subject matter expert supporting a complex SaaS implementation. This will include...


  • London, Greater London, United Kingdom 55 Exec Search Full time

    Our client, a renowned and award-winning global Cyber Security Advisory business, is expanding their Cyber Risk Advisory team. They are seeking a Senior or Managing grade GRC Cyber Security Consultant with aspirations to become a PCI QSA. The ideal candidate will have a broad range of cyber risk advisory skills (PCI DSS, ISO27001, GDPR, Data Privacy & Risk...


  • London, Greater London, United Kingdom Gemserv Ltd Full time

    Gemserv is an expert provider of professional services. We are purpose-driven, working across multiple sectors including energy, low carbon, the public sector and health to tackle today's social and environmental challenges. Established in 2002, the business provides a range of consultancy and outsourcing capabilities including programme management, market...