This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking an experienced ISO27001 auditor to join our globally expanding External Security Certifications team. In this role, you will support the internal and external ISO27001 audit program and BSI Kitemark & Cyber Essentials recertification projects. As part of an expanding scope you will be required to travel and support audit within the UK, with potential for international travel based on requirements. You’ll work closely with an experienced team to support vulnerability management, plan and perform audit functions and represent the bank to external auditors.
Job Responsibility:
Allocation of the correct risk rating and remediation prioritisation to a vulnerability based on industry standards for assessment, available threat intelligence concerning exploitation, the reachability of the host (or asset) and the value of the service(s) running on the impacted host
Development of vulnerability management operating model, policies and procedures to ensure consistency in vulnerability identification, remediation and reporting. Element owner of the Vulnerability Management Standard including Issues Management and Regulatory alignment
Communication of vulnerabilities to relevant parties including senior stakeholders, vendors, external security partners and affect business units using reports and dashboards and provide recommendations for improvement in vulnerability management practices
Collaboration with Threat intelligence and Cyber Operations teams to assess and contextualise exposure to latest threat trends and exploits and set appropriate remediation timescales
Definition of requirements and acceptance criteria for the implementation and maintenance of automation tools to streamline vulnerability management processes within operating systems and applications
Reporting of remediation status of Security Assurance Specialist team findings against Key Risk Indicators
Requirements:
ISMS ISO27001 Internal Auditor – Ability to plan, deliver and report on an Information Security Management System internal continual assessment of a site location, function or process
Understanding of technical requirements and passing criteria as laid down by the UK National Cyber Security Centre for Cyber Essentials Plus
Understanding of technical requirements and passing criteria for BSI Kitemark certifications
Nice to have:
ISMS ISO27001 Lead Auditor – Ability to plan, deliver and report on an Information Security Management System internal and external continual assessment of a site location, function or process
CISM certification or similar Cyber Security Management experience
Clear articulation of Cyber, IT & Information Security certifications, tools and functions within Barclays and the services and product set of the Group to meet certification criteria