Identify, plan, coordinate and supervise the delivery of security assessments and other security services required.
Manage a virtual team/other resources on a project by project basis as required.
Provide security consultancy to ensure new projects and services are deployed in a manner that ensures adoption of the relevant security strategy, designs, standards, controls and tools.
Accountable for representing GIS in cross-functional change programmes and business area meetings to ensure that information security considerations are included and considered and informed decisions are made to achieve agreed outcomes.
Involvement and contribution in designs with regard to IT security controls, providing guidance early in project planning and solution definition phases.
Lead the provision of detailed specifications for IT security solutions and supporting the development of testing plans.
Working closely with development projects to ensure proper deployment of IT security solutions.
Security Risk Assessments
Review IT security solutions for projects and confirm that these meet GIS Standards.
Undertake and facilitate risk and vulnerability assessments of applications and systems to ensure technical vulnerabilities are identified and correctly managed.
Assist Risk Owners to accurately assess the likelihood and impact of technical vulnerabilities.
Provide accurate and timely data for technical vulnerability reports as per approved standards and processes.
Production and management of design review memos as per approved standards and processes.
General Advice & Guidance
To provide technical advice and guidance on IT security related queries to both project and run areas as and when required.
To provide Information Security subject matter expertise to business and technology customers.
Due Diligence Activities
Performing due diligence activities in relation to 3rd parties. Including the identification of system controls and assessing their effectiveness.
To produce due diligence reports to be used in the creation of action plans to guide any remedial actions needed.
Leading in the negotiation phases of contract development with 3rd parties in relation to identifying and agreeing security requirements.
To create appropriate security schedules and specifications in support of the above.
Supplier & Product Evaluation
Assist in the supplier assessment process to ensure that a supplier s capability to support services to an agreed level/standard is accurately assessed and reported.
Assist with product evaluation activities to ensure products are fit for purpose and comply with minimum security requirements.
Security Incidents
Supporting security incident investigations as required.
What we re looking for:
Knowledge in multiple information security technologies and their strengths and shortcomings.
Proven experience with securing information for cross-functional, cross-platform applications.
Monitors marketplace trends and experiences on security, audit and control issues.
Knowledgeable of common application control techniques.
Knowledge of analytic techniques and methods.
Understands security controls from a people, process and technology perspective.
Clear articulation of common IT & Information Security structure, tools and functions within Financial Services organisations.
Familiar with integration and implementation issues and their security implications.
Understanding of security architectural principles and standards.
Knowledgeable about existing best practices for integration of security controls.
Explored and evaluated security considerations for multiple technologies.
,
Employement Category:
Employement Type: Full time Industry: Banking / Financial Services Role Category: General / Operations Management Functional Area: Not Applicable Role/Responsibilies: Security Conultant