Senior Information Security Consultant

3 days ago


London, United Kingdom Gemserv Full time

**Senior Information Security Consultant**:
Gemserv is an expert provider of professional services, helping clients make the most of a world increasingly driven by data and technology. Gemserv has experienced significant growth in recent years, winning new contracts and seeing our role on existing ones extended.

We have ambitious plans for the future and are now looking to strengthen our Information Security team by employing a Senior Information Security Consultant. We are looking for a passionate and driven individual with practical ISO27001 implementation and auditing experience and an understanding of Smart Energy Code (SEC) Section G to join our growing team.
- Location
- London Office (hybrid working)
- Salary Range
- £50,000 - £55,000 plus bonus and excellent benefits package
- Employment Type
- Permanent
- Contract Basis
- Full time (happy to consider flexible working)
- Travel Commitments
- UK and potential International
- Ref No
- 917

**The Role**:
**Responsibilities**:

- Providing expert advice to Users undertaking User Security Assessments (USAs);
- Monitoring the progress of Users who have booked USAs;
- ensuring an accurate tracking mechanism to record:

- Maintaining and reviewing USA related documentation including the Security Controls Framework, Agreed Interpretations and Decision-Making Principles;
- Undertaking validation of User management responses and Director's Letters;
- Liaising with Users to enable an improved User management response to be provided in advance of the User CIO validation or Security Sub-Committee (SSC) review of Director's Letters where appropriate;
- Briefing the Principal Security Expert on any sensitivities or emerging issues from liaison with Users and / or Shared Resources and providing relevant background and issues to be considered by the SSC.
- Monitoring all security incidents and vulnerabilities reported by Smart Energy Code (SEC) Parties or the DCC and providing an expert assessment of the materiality of the security incident or vulnerability;
- Advising the Principal Security Expert on whether a security incident or vulnerability is material and warrants the mobilization of SMIRT;
- Promptly taking whatever action is directed to undertake analysis of the security incident or vulnerability as required;
- Conducting 'lessons learned' analysis after the resolution of a security incident or vulnerability.
- Undertaking the review of ISO standards, cryptographic standards and best practices as enshrined in the SEC
- Maintain the SEC Security artefacts and, with the approval of the Chair, arrange for regular reviews to ensure that the artefacts are up to date.
- Conduct ad hoc risk assessments of specific risks that may arise from time to time;
- Reviewing user assessment reports and management responses;
- Monitor the threat landscape and advise the SSC of any material changes arising from threats or business impact levels;
- Contribute to procurement exercise for the annual SSC risk assessment where requested by the SSC;
- Provide expert assistance to any external risk assessment commissioned by the SSC.
- Conduct analysis produce papers and presentations; provide advice and make recommendations.

**Requirements**:
To be successful in the role the post-holder should be able to demonstrate experience in the following areas:

- An understanding and practical working knowledge of Smart Energy Code (SEC) Section G
- Technical knowledge of information security compliance (ISO27001), information management, Smart Metering and IT security arrangements.
- Ability to conduct risk assessments and treatments using a hybrid IS1/IS2 and ISO 27005 requirements.
- Have practical experience in undertaking ISO 27001 internal and external (field) audits.
- Have practical knowledge of the threat landscape in Smart Metering.
- Knowledge of Smart Metering and the energy market would be advantageous
- Preferably, an understanding and working of ISO standards including ISO 27001, ISO 27005, ISO 27035 and ISO22301
- ISO 27001 Lead Auditor / Implementer qualification is essential
- Ideally have an industry qualification such as CISA or CISM

**Skills & Qualities**:

- Excellent client consulting skills and ability to engage and build relationships with stakeholders at all levels (including C-suite level)
- Able to conceptualise opportunities and develop these through business development activities.
- Ability to explain complex ideas in a concise manner.
- Ability to work independently with little to no supervision.
- Ability to provide expertise and support in operational risk, governance, business continuity, data protection, data leakage and privacy.
- Passion to develop own skills and knowledge in information security and data protection compliance.
- Proactive, 'hands on' starter finisher and results driven individual.
- Highly organised and able to manage and prioritise workload.
- Strong problem solver with high attention to detail.

The role may require occasional busi



  • London, United Kingdom Bulletproof (Cyber Security) Full time

    WorkNest Cyber LTD (formally known as Bulletproof Cyber), is looking for an ISO27001 subject matter expert with experience of delivering consultancy around all the topic, including gap analysis, audits, implementations projects and ad hoc Information Security queries, to a wide variety of customers.You should have an excellent understanding of ISO27001 with...


  • London, United Kingdom The AA Full time

    **Company Description/ Business Unit**: **Location: London (hybrid working 2 office days per week)** **Employment Type: Permanent, full time** **Additional Benefits: Annual Bonus, Cash-Car Allowance & Private Medical Insurance** Think the AA is just about roadside assistance? Think again. For over a century, we've been evolving and adapting. Today, as...


  • London, United Kingdom The AA Full time

    **Company description**: **Location**: Hybrid working between your home and our Basingstoke office **Employment Type**: Permanent, full time **Salary**:Up to £70,000 per annum (depending on experience and skills) **Additional Benefits**:Car allowance, annual bonus + private medical insurance Solution bringers. Day makers. Extra milers. We are the AA....


  • London, United Kingdom PGI - Protection Group International Ltd Full time

    **Senior Information Security Consultant** PGI is a global consultancy that helps organisations build digital resilience. We deploy our people to implement solutions on behalf of clients or to support them in developing their own capabilities. Our consultants help clients to ensure the confidentiality, integrity, and availability of their organisation's...


  • London, Greater London, United Kingdom Protection Group International Full time

    Information Security Consultant (QSA)PGI is a global consultancy that helps organisations build digital resilience. We deploy our people to implement solutions on behalf of clients or to support them in developing their own capabilities. Our vision is a world resilient to digital threats and online harm. To achieve this, we need to grow our team of talented...


  • London, United Kingdom Sure Exec Search Full time

    Information Security ConsultantLocation: London Work Arrangement: Hybrid (1 day on-site) Rate: £425–£450 per day (Inside IR35, via Umbrella) Duration: 6 months initially (strong extension potential) Start: ImmediateSponsorship: Not availableWe are seeking a highly adaptable Information Security Consultant with strong consultancy experience and the...


  • London, Greater London, United Kingdom Protection Group International Full time

    Information Security Consultant (QSA)PGI is a global consultancy that helps organisations build digital resilience. We deploy our people to implement solutions on behalf of clients or to support them in developing their own capabilities. Our vision is a world resilient to digital threats and online harm. To achieve this, we need to grow our team of talented...


  • London, United Kingdom Waterstons Full time

    Who you'll be joiningWe're problem solvers at heart. Sometimes the answer is technology, sometimes it is strategy, and sometimes it is a strong cup of tea and a bit of thoughtful conversation. Whatever it takes, we work it out with our clients.We're an IT consultancy that helps organisations get the best out of their technology. That means keeping them...


  • london (city of london), United Kingdom Sure Exec Search Full time

    Information Security Consultant Location: London Work Arrangement: Hybrid (1 day on-site) Rate: £425–£450 per day (Inside IR35, via Umbrella) Duration: 6 months initially (strong extension potential) Start: Immediate Sponsorship: Not available We are seeking a highly adaptable Information Security Consultant with strong consultancy experience and the...


  • London, United Kingdom Hamilton Barnes Full time

    Role Are you ready to become an integral part of the cybersecurity defence against emerging threats, including nation-state actors and Advanced Persistent Threat groups? You’ll have the opportunity to step into the role of Senior Information Security Consultant, where your expertise in cybersecurity will make a significant impact. What’s in it for you?...