Our Cyber Strategy & Risk Consulting Team are looking for an experienced Security Consultant. You will be assigned to teams working with clients immediately and have experience working within the Public Sector. You have UK security clearance and are a UK resident (5+years).
You are able to apply skills to implement security governance and oversee security controls for UK Government and non-Government clients. You demonstrate experience of communicating with and building relationships with business executives, internal stake holders and less experienced team members.
The role will provide leadership on IBM accounts in identifying and resolving security, regulatory, risk, and compliance issues, exposures, and vulnerabilities to uphold a commitment to privacy and data security.
The role requires a professional who has a proven track record on public sector security industry trends/concerns/issues, while pursuing and maintaining multiple certifications in key security regulatory, risk and compliance disciplines, eg CISSP and/or CISM.
We are seeking an experienced Security Consultant with a specialism in Information Assurance to join our team. The ideal candidate will have a strong background in implementing and maintaining Information Security Management Systems (ISMS) based on ISO 27001, ISO 27002, ISO 27005, UK Government Secure by Design and other industry leading frameworks, such as NIST.
You will be responsible for developing, implementing, and overseeing the implementation of Security Management Plans (SMP) and ISMS in large public sector and industrial contracts. Key responsibilities will include:
- Lead the development, implementation and maintenance of ISMS aligned with client requirements, leading standards, and frameworks.
- Lead in the implementation of UK Government Secure by Design principles.
- Lead activities to assure the ongoing compliance of IBM services.
- Conduct risk assessments, identify vulnerabilities, and lead the development and implementation of risk management strategies with Senior Leadership, including the development of appropriate risk treatment plans.
- Stay up to date with the latest security trends, threats, and best practices particularly in the public sector and also across the wider industry.
- Analyse market trends, competitive landscapes, and emerging technologies to inform strategic decision-making.
- Collaborate with senior leadership to define organizational priorities and strategic objectives.
- Design and facilitate workshops, training sessions, and stakeholder engagements to foster a culture of risk awareness and mitigation.
IBM helps our client to craft and execute strategic initiatives to mitigate risk, capitalize on opportunities, and drive sustainable growth. As part of our Cyber Strategy & Risk practice you will also have opportunity to take on cross-industry consulting engagements by leveraging your expertise to provide thought leadership on industry best practices, regulatory compliance, and risk governance frameworks to clients.
If you are passionate about success, consulting and cybersecurity, with both your career and solving clients’ business challenges, this role is for you.
Sure you are ready to take your career to the next level and shape the future of technology with us, and we want to hear from you! Please submit your resume outlining your relevant experience and why you're passionate about joining our team. We look forward to welcoming you to the IBM family.
Required Professional and Technical Expertise :
- Hands-on experience of implementing UK Government Secure by Design principles.
- Minimum of 5 years of experience in delivering cybersecurity Assurance/Information Assurance, including the development and maintenance of an ISMS.
- Proven experience in strategic planning, risk management, or management consulting within the technology sector.
- Strong analytical skills with the ability to translate complex data into actionable insights.
- Excellent communication and presentation skills, with the ability to influence stakeholders at all levels of the organization.
- SC Clearance (valid current SC clearance is preferred but must be eligible for SC)
Security Expertise:
- Professional certifications such as CISSP, CISM, or CRISC, are highly desirable.
- In-depth knowledge of ISO 27001, ISO 27002, ISO 27005, and other relevant ISO standards.
- Familiarity with NIST frameworks, such as NIST SP 800-53 and NIST Cybersecurity Framework.