Job Summary:
The Information System Security Consultant provides expert security consulting services to internal stakeholders. This role involves assessing security risks designing comprehensive security solutions and collaborating with technical teams to mitigate threats and respond to breaches. The consultant plays a key role in ensuring the organizations networks and systems remain secure by developing and implementing effective security policies processes and technologies.
Key Responsibilities:
-
Security Assessment and Consulting
- Analyze internal client operations to identify key information security threats and business risks.
- Provide strategic recommendations to mitigate identified risks and vulnerabilities.
- Conduct regular security audits and gap analyses.
-
Incident Response and Mitigation
- Collaborate with technical teams to address security breaches and vulnerabilities.
- Develop and implement incident response protocols to minimize damage and restore operations efficiently.
- Ensure thorough documentation of security incidents and resolution processes.
-
Security Program Development
- Design and outline coherent tailored security service solutions and programs.
- Establish and enforce security guidelines standards and procedures.
- Provide input into the development of security roadmaps and improvement plans.
-
Policy and Process Management
- Identify define and monitor security policies and processes.
- Ensure alignment with industry best practices and regulatory compliance requirements.
- Continuously evaluate and improve existing security protocols and workflows.
-
Technology and Solution Implementation
- Recommend and implement advanced security technologies to mitigate risks.
- Work with crossfunctional teams to deploy security solutions effectively.
- Monitor the performance and reliability of security technologies and systems.
-
Training and Awareness
- Educate internal teams and stakeholders on security policies risks and best practices.
- Create awareness programs to promote a culture of security within the organization.
Key Skills and Competencies:
- Strong knowledge of information security principles frameworks (e.g. ISO 27001 NIST CIS) and technologies.
- Handson experience with security tools such as firewalls intrusion detection/prevention systems (IDS/IPS) and endpoint protection.
- Proven expertise in risk assessment vulnerability management and incident response.
- Familiarity with regulatory requirements such as GDPR HIPAA or PCIDSS.
- Analytical thinking and problemsolving skills to assess threats and develop actionable solutions.
- Excellent communication and interpersonal skills to interact with diverse stakeholders.
- Ability to work collaboratively in crossfunctional teams.
Qualifications:
- Bachelors degree in Computer Science Information Technology Cybersecurity or a related field (or equivalent experience).
- Industry certifications such as CISSP CISM CEH or similar are highly desirable.
- 5 years of experience in information security IT risk management or a related field.