This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Security Architect will Contribute to the design, implementation and ongoing development of the security architecture of the client's IT systems. The Security Architect will draw upon Enterprise Security Architecture or Security Solutions Architecture to Contribute to: - Identify business objectives, user needs, risk appetite and cyber security obligations - Identify vulnerabilities, perform threat modelling, undertake risk assessment, evaluate the effectiveness of security controls - Verify and evidence alignment to 'Secure by Design' principles, corporate security policy/standards as well as industry recognised frameworks and best practice Contribute to deliver and continually enhance a coherent approach to the design of secure client end-to-end solutions Contribute to secure conceptual, logical and high level designs by identifying appropriate security controls to be embedded in solutions that meet business requirements whilst evidencing alignment to the target risk appetite. Contribute to the design and be able to articulate and justify design recommendations at security architecture assurance gates Contribute to design documentation, options papers, risk assessments, stakeholder presentations and be able to effectively communicate these to both senior technical and non-technical stakeholders Contribute to reference architecture of established patterns, principles and guidelines Contribute to the development of the Security Practice skills and capabilities to ensure consistent high quality of service delivery and expertise. Active coaching and mentoring of junior members of the team Contribute to the development of collateral to support Security Consulting 'go to market' propositions and service offerings. Contribute to the development and presentation of compelling client proposals collaborating with teams across our business. Contribute to documented Information Security Management Plans which incorporate Regulatory, Legal and Compliance in relation to applicable security policies. Standards and guidelines Contribute to the identification of identified risks and emerging cyber security vulnerabilities and threats. The subsequent analysis to quantify and lead risk mitigation plans Work with Service Management to ensure that partners and suppliers adhere to agreed standards, policies and verify/evidence appropriate compliance and security KPIs Work closely with 1st, 2nd and 3rd lines of defense on all matters relating to cyber security, information assurance, cyber risk, data privacy including regulatory and compliance considerations Contribute to the development and enhancement of governance, risk and compliance aligned to policy, standards an industry good practice Ensure that continuous assessment, identification, analysis and reporting of useful metrics to enable informed risk-based decisions to be taken Constructively challenge established processes and controls to identify, recommend and facilitate continuous improvement, ensuring that all personnel (including senior stakeholders) understand their responsibilities in relation to security risk mitigation and remediation Review and verify that documentation relating to process and technical security controls are maintained# Thrive as a consultant seeking the variety and challenge of engaging with different clients and variety of technologies and solution types. Developing security vulnerabilities and techniques for applying effective controls. Contribute to the development of secure system without close supervision. Contribute to security requirements for new systems or changes to existing systems without close supervision. Execute technical management tasks in respect to ongoing client projects.
Job Responsibility:
Identify business objectives, user needs, risk appetite and cyber security obligations
Identify vulnerabilities, perform threat modelling, undertake risk assessment, evaluate the effectiveness of security controls
Verify and evidence alignment to 'Secure by Design' principles, corporate security policy/standards as well as industry recognised frameworks and best practice
Contribute to deliver and continually enhance a coherent approach to the design of secure client end-to-end solutions
Contribute to secure conceptual, logical and high level designs by identifying appropriate security controls to be embedded in solutions that meet business requirements whilst evidencing alignment to the target risk appetite
Contribute to the design and be able to articulate and justify design recommendations at security architecture assurance gates
Contribute to design documentation, options papers, risk assessments, stakeholder presentations and be able to effectively communicate these to both senior technical and non-technical stakeholders
Contribute to reference architecture of established patterns, principles and guidelines
Contribute to the development of the Security Practice skills and capabilities to ensure consistent high quality of service delivery and expertise
Active coaching and mentoring of junior members of the team
Contribute to the development of collateral to support Security Consulting 'go to market' propositions and service offerings
Contribute to the development and presentation of compelling client proposals collaborating with teams across our business
Contribute to documented Information Security Management Plans which incorporate Regulatory, Legal and Compliance in relation to applicable security policies
Standards and guidelines
Contribute to the identification of identified risks and emerging cyber security vulnerabilities and threats
The subsequent analysis to quantify and lead risk mitigation plans
Work with Service Management to ensure that partners and suppliers adhere to agreed standards, policies and verify/evidence appropriate compliance and security KPIs
Work closely with 1st, 2nd and 3rd lines of defense on all matters relating to cyber security, information assurance, cyber risk, data privacy including regulatory and compliance considerations
Contribute to the development and enhancement of governance, risk and compliance aligned to policy, standards an industry good practice
Ensure that continuous assessment, identification, analysis and reporting of useful metrics to enable informed risk-based decisions to be taken
Constructively challenge established processes and controls to identify, recommend and facilitate continuous improvement, ensuring that all personnel (including senior stakeholders) understand their responsibilities in relation to security risk mitigation and remediation
Review and verify that documentation relating to process and technical security controls are maintained
Requirements:
Awareness and understanding of industry security frameworks and guidance such as NIST CSF, NIST 800-53, NCSC CAF and other NCSC guidelines
Good knowledge of networking (switching, routing, firewalls)
Awareness or limited experience with the design concepts associated with adoption of Cloud platforms (AWS and/or Microsoft Azure)
An understanding of the native security capabilities and some practice within Cloud platforms (AWS and/or Microsoft Azure)
Understanding of modern security concepts, common attack vectors, malware, security analytics and threat intelligence
A understanding of security testing and vulnerability management is important (including pen testing/ITHC, CVSS/CVE)
Some experience working with security standards such as ISO 27001, 27002, 27017, 27108 etc
Nice to have:
Minimum of 5 years of experience in Cyber Security
Any One of the certifications (CISSP, CISM, CCSP, CRISC) or equivalent experience
Good knowledge covering at least 2 of the following examples (this list is not exhaustive): AD, Cryptography, End User Computing, IAM, PKI, Server hardening, SIEM, SOAR, virtualization (VMware)
What we offer:
A range of tailored benefits that support your physical, emotional, and financial wellbeing