Information Security Risk Assessment Consultant

Posted 2 days ago
Capita
Information Security Risk Assessment Consultant
Apply Now

Full job description

Capita

Salary: £720 per day

Join us as an Information Security Risk Assessment Consultant with EDF Energy

(Barnwood 3 days in the Office, 6 month contract)

In Scope of IR35

About Capita

At Capita, we support clients across a range of sectors, including local Government, central Government, education, transport, health, life and pensions, insurance and other private sector organisations. We support with expertise applied by the talent across our business in combination with technology, insight and analytics to keep our clients ahead of change, sharper than competitors and more efficient than ever – and we always need new talent to help us achieve our goals.

About EDF Energy

We want to bring affordable, low-carbon energy to everyone and to do that requires both sharp minds and smart ideas to help shape the UK’s energy future. With the development of a new nuclear power station on the horizon, our goal is to become the best and most trusted energy supplier for our customers, through a combination of trust, transparency and teamwork.

The role

The post holder will provide support to the NG Information Security Team to ensure that all aspects of IT & OT (Operation Technology) security policies & operational compliance, covering their systems and digitised information, are adhered to in a proactive manner. This will include leading the improvement of these processes and the tooling that supports them, assisting in risk management, IT audit and assurance activities, regular operational compliance monitoring and guidance to IT & OT Risk and Systems Owners.

To actively provide security governance, oversight and assurance for assigned projects, meeting the requirements of the information security policies and advising on current industry standards, guidance and good practice. The consultant will be responsible for ensuring data and systems are adequately protected whilst being compliant with legislation and regulation. There is a requirement to support the Information Security team in activities to implement the NG Information Security Management System (ISMS). Due to the nature of the position SC level clearance is a requirement or must be achievable.

Key Tasks & Responsibilities

· Review, design and implement Process and Tooling improvements in Information Security Risk Management 

· Communicate information security matters with senior stakeholders throughout the organisation Implement a cohesive communication plan to improve understanding of ISMS and risk management focused on business and system owners and other supporting teams.

· Prioritise, create and agree security risk assessments in support and behalf of systems owners.

· Collate, clarify and classify assets in preparation of risk assessments. This may require travel to asset locations to verify asset details and interconnections.

· Ensure assessments are carried out by using a consistent process.

· Engage with the ISMS working group and stakeholders, including the presentation of risk assessments and recommendations.

· Provide sound understanding of technical issues in the area of responsibility to systems owners.

· Provide – when required – process, procedure and security policy guidance along with interpretation for Nuclear Generation staff.

· To manage security related requests and changes.

Skills, Qualifications & Experience

· Experience of working as part of a team and in actively contributing to overall team deliverables.

· A strong communicator with the ability to influence people.

· Experience in Information Security and related technologies.

· Experience of conducting security risk assessments, audit and assurance activities including the use of risk assessment methodologies – ideally ISO 27005.

· Experience of ISO27001 and working with an Information Security Management System – ISMS.

· Experience of leading Process Improvement in Information Security Risk Management

· Ideally have experience of working in accredited environments.

· Implementation of controls, risk mitigation and management.

· Ideally have an understanding of ‘Operational Technology’ within a highly regulated industry, preferably the nuclear industry.

· Ability to build relationships with the other IT & OT functions and their business representatives.

· Ability to work on their own initiative, with minimal supervision and meet demanding milestones as part of a small security team.

· Experience of balancing provision of IT/OT security controls that adequately protect data and systems.

· Current knowledge of the IT/OT threat environment, threat actors and the impact of these on system security.

· Can demonstrate the ability to take responsibility and make sound decisions on security related issues.

· Trustworthy with high standards of personal integrity.

· Possession of professional certifications and membership in professional associations is highly desirable (e.g. CISSP, ISO27000 certification, CISM, CEH, NCSC, CCP).

· Background in the workings of an IT /OT organisation – e.g. computer operations, operation analysis, system programming, networking, and database administration.

· Holds, or is able to obtain, SC clearance.

To apply for this job please visit definitejobs.co.uk.

Similar jobs