GRC Consultant

NTT
London
Full timeFunction: Legal, Risk & ComplianceSkills: ["Stakeholder management","Risk analysis","Continuous improvement","Communication","Cross-functional collaboration"]

Ensure security controls are designed, developed, tested, and operated effectively across their lifecycle by aligning identified risks to the organization’s acceptable risk posture. Lead information security governance through plans that incorporate regulatory, legal, and compliance needs, coordinate evidence for compliance and assurance activities, and support incident response and root-cause actions. Partner with service management and all defense lines, measure security control effectiveness, and drive continuous improvement toward standards such as ISO 27001.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
NTT
NTT
1 week ago

GRC Consultant

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 21 hours agoStatus: Live

Job Summary

Ensure security controls are designed, developed, tested, and operated effectively across their lifecycle by aligning identified risks to the organization’s acceptable risk posture. Lead information security governance through plans that incorporate regulatory, legal, and compliance needs, coordinate evidence for compliance and assurance activities, and support incident response and root-cause actions. Partner with service management and all defense lines, measure security control effectiveness, and drive continuous improvement toward standards such as ISO 27001.
Location: London
Employment Type: Full time
Job Function: Legal, Risk & Compliance

Key Responsibilities

  • •Ensure security controls (people, process, technology) are in place and operating as designed, and measure/control their effectiveness.
  • •Develop documented Information Security Management Plans incorporating regulatory, legal, and compliance requirements and applicable security standards.
  • •Identify and analyze risks, emerging cyber security vulnerabilities and threats, and lead risk mitigation planning.
  • •Coordinate audit, ITHC, and risk assurance activities to evidence compliance with regulatory and governance requirements, including remediation actions.
  • •Monitor information security incidents, contribute to incident response and root cause analysis, and own resulting changes to IT security and information risk management policy and controls.

Key Requirements

  • •Track record delivering security solutions for large-scale infrastructure, transformation, or integration programmes.
  • •Practical knowledge of industry security frameworks and guidance such as NIST CSF, NIST 800-53, NCSC CAF and related NCSC guidelines.
  • •Good knowledge of networking (switching, routing, firewalls) and in-depth knowledge of modern security concepts, attack vectors, malware, security analytics, and threat intelligence.
  • •Understanding of security testing and vulnerability management, including pen testing/ITHC and CVSS/CVE.
  • •Experience working with security standards such as ISO 27001, 27002, 27017, 27108 (or equivalent).
Skills:Stakeholder managementRisk analysisContinuous improvementCommunicationCross-functional collaboration
Certifications:CISSPCISMCCSPCRISC
Tech Stack:ISO 27001ISO 27002ISO 27017ISO 27108NIST CSFNIST 800-53NCSC CAFAWSMicrosoft AzureActive Directory (AD)CryptographyIAMPKIServer hardeningSIEMSOARVirtualization (VMware)MITRE ATT&CKITILPen testing

Company Brief

NTT
Dimension Data, operating under NTT Ltd, provides managed IT services, cloud and data center solutions, networking, cybersecurity, and digital transformation services to enterprise customers worldwide.
Industry: Professional Services
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Established Company
Valuation: Public Company (Market Cap in USD)
Headquarters: London, United Kingdom
Founded: 1983
WebsiteLinkedIn