Maintain IT security framework, policy and standard (including internal and external policy compliance)
Monitor regulation compliance (in relation to Cyber; i.e. GDPR)
Work with different departments in the organization to operationalise best practice
Operate Cyber security risk assessment programme
Participate in DR and IT Service continuity planning
Maintain Cyber Security Architecture
Provide security guidance on the design of applications and network architectures
Manage Cyber security incident response program
Monitor security threats and execute responses through SIEM tools
Assess and improve the organisation's security capabilities/measures, such as firewalls, anti-virus software and passwords, to identify any weak points that might make information systems vulnerable to attack
Analysis and Implementation of Security Solutions (tools and technology) to meet security requirements
The Successful Applicant
A bachelor's degree in information technology or computer science is required.
10 years' work experience, with 3 or more in a cyber security or information security management position, is also required.
Comprehensive understanding of Information Security Frameworks (e.g. ISO 27001, SOX, PCI DSS and Cyber Essentials) and UK and EU data protection laws, including GDPR.
Knowledge of security investigation techniques, the rules of evidence and practical experience of computer forensics would be useful.
Experience with strategic security planning with proven ability to work collaboratively with other departments to resolve complex issues with innovative solutions
Experience and understanding of the information risk implications of third party relationships
Working knowledge of Infrastructure security and hardening, Ethical Hacking or Penetration Testing
Working knowledge of Identity and Access Management
Deployment and management of vulnerability and patch management software