Strategic Ciso Consultant - Birmingham, United Kingdom - LRQA group

LRQA group
LRQA group
Verified Company
Birmingham, United Kingdom

1 month ago

Tom O´Connor

Posted by:

Tom O´Connor

beBee Recruiter


Description

About Nettitude
Nettitude is a LRQA Company. We've been around since 2003 and our focus has always been on excellence in cyber security.

We have teams that offer world class services in red teaming, penetration testing, threat intelligence, research and development, detection and response, governance, risk, and compliance, and plenty more.

Our business is global and so are our clients. We work closely with central banks, central and local government, critical national infrastructure, large retailers, and plenty more besides

We're an award winning provider of cyber security services and we're are at a very exciting stage of development.

We are looking for the right people to join us as we embrace the challenges thrown up by the advancements within the IT industry and within the threats faced.

Nettitude will be at the forefront of this arena and we want to seek the right people to join the team and make it happen.


Role definition


The role of the senior CISO level consultant is primarily characterised as technical and business focused contributions at a senior or board level, helping to advise and set direction.

The role is to lead the advice, consulting, the coaching of the client on CISO level issues and be able to deliver effective project management and program oversight.


However, with this said, the knowledge and experience of the senior CISO Consultant means that there will be a dependence on ensuring tactical level work is completed and may involve times where the tactical work is done by the senior CISO consultant, but this is not the main effort.


The role


As well as delivering ongoing CISO services, you'll also have opportunities to deliver other Nettitude services including security awareness training, third-party risk reviews, and cybersecurity assessments in mergers and acquisitions.


What you'll be doing in your role:

  • Leading Virtual CISO, interim CISO and CISO support engagements.
  • Contributing to board level briefings on status and future planning.
  • Conducting security benchmarking reviews against standards or guidelines such as the NCSC 10 Steps to Cyber Security, NIST CSF, CIS controls
  • Performing gap analyses, providing strategic and tactic recommendations as part of the security maturity and resilience journey.
  • Helping our clients to implement Information Security Management Systems, and achieve and maintain security certifications (e.g., ISO27001) and regulatory compliance.
  • Conducting risk assessments at a technical level and providing risk models against ISO27001 and NIST
  • Technical understanding of threats and vulnerabilities from SOC outputs and being able to implement a vulnerability management program.
  • Creating thirdparty risk management and audit programmes for clients and build necessary risk models.

Key Skills:


Personal Competencies:


  • Degree level education in a technical degree which is relevant to the role.
  • Solid track record of consultancy and/or internal experience in leading and managing a cyber security function within a business or a client facing environment.
  • Demonstrable experience in risk management assessment, treatment, and remediation.
  • Innovative and creative thinker ability to think on the spot and provide solutions.
  • Be able to deliver difficult messages whilst showing empathy and be able to provide a solution.
  • Willingness to "roll up your sleeves" and get involved and take responsibility for ensuring we always exceed client expectation.

Business Experience credentials.

  • CISSP/CISM (or equivalent) certification is preferable but not a prerequisite.
  • Representation in regular information security governance forums, working groups or change advisory boards to advise and guide on information security requirements.
  • Representation briefing and support of board level activity where required by the customer, acting in an advisory or mentoring capacity as defined by the client.
  • Strong understanding of ISO 27001/NIST CSF and experience in implementation of an ISMS and experience in using relevant standards and guidelines to build and implement control frameworks.
  • Oversight and strategic advice, guidance, and support in the maintenance of compliance regimes such as PCI DSS and GDPR.
  • Provision of Management information and reporting applicable to the vCISO activities.
  • Security best practice reviews at a strategic and tactical level.


  • Cyber Resilience Planning

  • Incident Management, Business Continuity and Disaster Recovery.


  • Security Operations

  • Understand the 3 lines of defence and be able to deploy effective vulnerability management countermeasures.
  • Experience of managing security professionals and recruitment of talent for the relevant teams
  • Strong communication skills and an ability to build rapport with key stakeholders.
  • Be able to frame a new solution to client needs and define expected deliverables.

Location
This role is remote. We can support working from

More jobs from LRQA group