Were searching for a Senior/Manager Client Information Security (Infra) to be part of our diverse team of talent here at NCS!
If you believe in going above and beyond want to exemplify the best and wish to bring people and technology together like never before then we would love to have a conversation with you!
What we seek to accomplish together:
- Drive the implementation of NCS cybersecurity data protection and privacy policies standards and processes within the practice. You will work to continually improve the security posture of projects through proactive risk management and the establishment of a broad range of cybersecurity controls
- Provide direct support to colleagues to ensure cybersecurity is addressed throughout the engagement delivery lifecycle from infrastructure and security tooling choices to the secure storage processing and deletion of client data.
- Act as a single point of contact and escalation for the SOC Threat Intel and Crisis Response teams for practicerelated cybersecurity incidents ensuring timely identification remediation and lessons learned.
- Manage the security SLA governance and provide practicelevel cybersecurity reporting metrics and forecasting to leadership.
- Responsible for information security data protection privacy GRC and audit requests for the practice acting as single point of contact on relevant client security assessment and audits execution. Eg. independent thirdparty attestations of industry cybersecurity standards and certifications such as ISO 27001 SOC 2 for practicespecific solutions and products
- Contribute to the definition of the client specific security baseline. Consult and advise internal and external clients about security topics and support the opportunity management process by providing subject matter expertise and support
- Help win client business by providing cybersecurity assurance to RFIs RFPs proposals contract drafting security questionnaires workshops and other client due diligence processes
Qualifications :
A little about you:
- Degree/Diploma or higher in Computer Science Information Systems or equivalent
- At least one industry recognized security certification is such as Certified Information Security Management (CISM) Certified Information Systems Security Professional (CISSP)
- 5 years of experience in information security management either in domains of Cyber Security Operations Incident Response Forensic Investigation Threat Intelligence or Vulnerability Management
- Good working knowledge of security risk management security governance framework and compliance (IT Security Audit / log review)
- Understanding of information security principles ISO 27001 controls Center for Internet Security (CIS) controls Cloud Controls Matrix (CCM) controls.
- Experience with application security security technologies and tooling e.g. vulnerability scanners firewalls network application security security technologies (system hardening IDS/IPS firewall)
- Experience carrying out security incident response penetration testing vulnerabilities scanning and security assessment
- Senior stakeholder management and working across various parts of the organization
- Team player with good interpersonal influencing skills
- Strong communication skills both written and verbal
Remote Work :
No
Employment Type :
Fulltime