ABOUT THE JOB:
Key Decisions:
- Determining if solutions are in line with Group Information Risk Policy
- Determining appropriate security controls to address risks
- Managing technical deviations/significant risks and provide recommendations for alternative solutions and/or compensating controls to reduce impacts.
Key Accountabilities
- Providing security consultancy to enable the Business and Project teams to understand impacts from proposed system changes and solutions. Includes handing difficult conversations and influencing colleagues to manage the solution requirements and reflect the need for security.
- Analysing the non-normative flows through systems, applications and proposed solutions to identify risks, security threats and vulnerabilities in order to identify required security control components and countermeasures.
- Contribute with Senior Security Architects towards significant architectural decisions with senior management, sponsors and projects to ensure secure outcomes and appropriate governance practices are adhered to, including notifications to Technology Architecture Forums.
- Leveraging and updating existing control reference patterns and developing new patterns to outline integration approaches, use-cases, re-use, and technical reference for Enterprise security capabilities.
- Proactively managing risk and assurance requirements when developing designs that change risk posture within agreed Risk Appetite and ensure compliance.
Key Interfaces:
- Business domain Execs, Product Owners
- Technology delivery teams / execs
- Release train engineers
- Architecture & Strategy & Advisory
- Governance, Risk and Compliance
Key Performance Indicators:
- Engagement and influence security aspects of relevant target state architectures/central roadmaps
- Operate as a trusted security advisor to technical and business colleagues
CAPABILITIES, EXPERIENCE & QUALIFICATION REQUIREMENTS
Essential capabilities:
- Decision Quality, Strategic Mindset, Situational Adaptability, Self-awareness, Excellent English Communicator, Accountability.
Other capabilities (Technical):
- Proven experience with strong business engagement, influencing skills with the ability to navigate complex topics with fact-based analysis.
- Understand the trade-offs involved in security change while simultaneously delivering technical capability & business benefit. Requires commercial acumen, business alignment and ability to negotiate.
Experience:
- 5+ years experience in the Technology industry
- 3+ years experience in information security. Domains / Roles of experience can include, but is not limited to:
- Security Risk Management,
- GRC,
- Security Audit,
- Security Analyst,
Qualification Requirements:
- Degree in Computer Science / information systems or equivalent technical qualification
- Security Certifications would be beneficial, or a commitment to pursue a recognised security industry certification.