Information Security Officer
Role: Information Security Officer
Location: London / Belfast
Start Date: ASAP
End Date: 6 Months
Daily Rate: Competitive Day Rate, Inside IR35
Payroll provider – Rockford Payroll Info for Contingent Workers – Rockford Pay
The Information Security Officer is a senior level professional position responsible for driving efforts to prevent, monitor and respond to information/data breaches and cyber-attacks. The overall purpose of this role is to ensure the execution of Information Security (IS) directives and activities in alignment with the client’s information and cybersecurity policy within the supported business units, primarily the client’s Technology Infrastructure.
- Identify
opportunities to automate and standardize information security controls
and for the supported groups.
- Resolve
any vulnerabilities or issues detected in an application or
infrastructure.
- Analyze
source code to mitigate identified weaknesses and vulnerabilities within
the system.
- Review
and validate automated testing results and prioritize actions that resolve
issues based on overall risk.
- Scan
and analyze applications with automated tools, and perform manual testing
if necessary.
- Reduce
risk by analyzing the root cause of issues, their impact, and required
corrective actions.
- Direct
the development and delivery of secure solutions by coordinating with
business and technical contacts.
- Contribute
to execution of the architectural vision for all IT systems through major,
complex IT architecture projects.
- Security
Architecture: Collaborate with IT to ensure system architecture follows
corporate policies and IT best practices.
- Risk
management: Identify, assess and mitigate security risks. Identify
application compensating controls for non-compliant items.
- Provide
technical leadership and is responsible for developing components of, or
the overall systems design.
- Translate
complex business problems into sound technical solutions.
- Provide
integrated systems planning and recommends innovative technologies that
will enhance the current system.
- Recommend
appropriate infrastructure platforms, and communication links required to
support IT goals and strategy.
- Impact
the architecture function by influencing decisions through advice, counsel
or facilitating services.
- Guide,
influences and persuades others with developed communication and diplomacy
skills.
- Strong
understanding of cloud security architectures (i.e. AWS Well-Architected
Framework, Google Cloud Security Command Centre).
- Knowledge
of the Identity and Access management (IAM) security models of AWS and
GCP.
- In-depth
knowledge of cloud infrastructure and architecture (e.g. VPC, EC2,
S3, Cloud Storage and Compute Engine.
- Familiarity
with compliance and risk frameworks (NIST, ISO 27001, CSA STAR)
- Experience
in business engagement for Information Security, Risk or Control &
Compliance, IT Analysis / Design or Program / Project Management.
- Perform
Information Security risk assessments and familiarity with Information
Security Risk Governance.
- At
least 2 years’ experience securing cloud environments particularly AWS and
GCP
- Bachelors
degree or higher (Computer Science or Cybersecurity preferred) or
equivalent work experience.
- Industry
certifications such as CISSP/CISM/CCSP are desired.
- Have
good communication skills with the ability to articulate clearly in high
stress situations.
- Self-starter
with good problem-solving skills.
- Proven
influencing and relationship management skills.
- Familiarity with IaC security (Terraform, CloudFormation)
- Advanced
proficiency with Microsoft Office tools and software.
- Public
Cloud Solution Architect or Security Certifications are plus (i.e. AWS
Certified Solution Architect, GCP Professional Cloud Security Engineer)