Cyber Security Risk Consultant
QinetiQ Group plc, Bristol
Cyber Security Risk Consultant
Salary not available. View on company website.
QinetiQ Group plc, Bristol
- Full time
- Permanent
- Onsite working
Posted 1 week ago, 11 Jun | Get your application in now before you're too late!
Closing date: Closing date not specified
job Ref: 46e700a18f514d6db047e61e6e742998
Full Job Description
Understand and advise on cyber security vulnerability, risks, audit & compliance in a business or operational context and cyber security threat environment, Cyber Risk Advisor/Consultant 1. Create business risk models and associated material, in support of operational cyber security and business planning across a range of different domains or sectors using established frameworks (e.g. NIST, UK Government) 2. Undertake cyber security audit processes in support of operational and business planning activity across a range of different domains or sectors against recognised standards (e.g. ISO27001, UK Government) 3. Undertake cyber security vulnerability analysis to provide a rich picture of organisational maturity and risk exposure to cyber security, in support of operational and business planning activity across a range of different domains or sectors using established frameworks (e.g. NIST, MITRE ATT&CK, UK Government) 4. Identify mitigations for cyber risk in a given business or operational scenario and threat environment 5. Support development of cyber security risk cases in a given business or operational context, Cyber Risk Advisor/Consultant 1. Create business risk models and associated material, in support of operational cyber security and business planning across a range of different domains or sectors using established frameworks (e.g. NIST, UK Government) 2. Undertake cyber security audit processes in support of operational and business planning activity across a range of different domains or sectors against recognised standards (e.g. ISO27001, UK Government)3. Undertake cyber security vulnerability analysis to provide a rich picture of organisational maturity and risk exposure to cyber security, in support of operational and business planning activity across a range of different domains or sectors using established frameworks (e.g. NIST, MITRE ATT&CK, UK Government) 4. Identify mitigations for cyber risk in a given business or operational scenario and threat environment 5. Support development of cyber security risk cases in a given business or operational context
- Knowledge of MITRE ATT&CK
- Understands the impact of cyber risk, security accreditation and certification on business or operational outcomes
- Able to articulate regulatory requirements and devise courses of action to meet these appropriate to the business or operational context.
- Able to devise effective and creative risk mitigation strategies that enhance business outcomes
- Understand cyber risk and mitigations put in place and can provide evidence to help refine risk mitigation approaches
- Able to identify, document and articulate security risk and mitigation approaches, against technology solutions and business processes
- Able to engage and communicate effectively with customers
- Able to engage and communicate effectively with stakeholders at all levels
- Good awareness of digital technology (in particular computer and computer network)
- Awareness of how architects and designers employ the technology to build systems of interest
- Demonstrate good judgement in relation to cyber risk and vulnerability assessment
- Able to articulate evidenced and convincing arguments for recommended courses of action
- Government, defence, CNI market understanding
- Able to work independently and seek guidance on own initiative for unusual or complex situations, STEM degree or equivalent and relevant experience in cyber security role
- Digitally literate (including fluency in Microsoft Office tools)
- Minimum of 2-3 years of experience in security vulnerability, risk, audit & compliance Desirable
- Experience applying/work to relevant NIST and ISO27001 frameworks and standards in different sectors and domains including defence, wider UK Government, critical national infrastructure.
- Experience guiding successful security audit preparation and outcomes
- Membership of CIISec or equivalent, Knowledge of MITRE ATT&CK
- Understands the impact of cyber risk, security accreditation and certification on business or operational outcomes Able to articulate regulatory requirements and devise courses of action to meet these appropriate to the business or operational context.
- Able to devise effective and creative risk mitigation strategies that enhance business outcomes
- Understand cyber risk and mitigations put in place and can provide evidence to help refine risk mitigation approaches
- Able to identify, document and articulate security risk and mitigation approaches, against technology solutions and business processes
- Able to engage and communicate effectively with customers
- Able to engage and communicate effectively with stakeholders at all levels
- Good awareness of digital technology (in particular computer and computer network)
- Awareness of how architects and designers employ the technology to build systems of interest
- Demonstrate good judgement in relation to cyber risk and vulnerability assessment
- Able to articulate evidenced and convincing arguments for recommended courses of action
- Government, defence, CNI market understanding
- Able to work independently and seek guidance on own initiative for unusual or complex situations, STEM degree or equivalent and relevant experience in cyber security role
- Digitally literate (including fluency in Microsoft Office tools) Minimum of 2-3 years of experience in security vulnerability, risk, audit & compliance Desirable
- Experience applying/work to relevant NIST and ISO27001 frameworks and standards in different sectors and domains including defence, wider UK Government, critical national infrastructure.
- Experience guiding successful security audit preparation and outcomes
- Membership of CIISec or equivalent
Direct job link
Relevant jobs
- Tech / Digital / IT Jobs in Barnstaple, Devon
- Tech / Digital / IT Jobs in Bath
- Tech / Digital / IT Jobs in Bournemouth
- Tech / Digital / IT Jobs in Bridgwater, Somerset
- Tech / Digital / IT Jobs in Bridport, Dorset
- Tech / Digital / IT Jobs in Bristol
- Tech / Digital / IT Jobs in Chard, Somerset
- Tech / Digital / IT Jobs in Cheltenham, Sir Fynwy - Monmouthshire
- Tech / Digital / IT Jobs in Christchurch, Forest of Dean
- Tech / Digital / IT Jobs in Cirencester, Gloucestershire
- Tech / Digital / IT Jobs in Devizes, Wiltshire
- Tech / Digital / IT Jobs in Dorchester, Oxfordshire
- Tech / Digital / IT Jobs in Exeter
- Tech / Digital / IT Jobs in Falmouth, Cornwall
- Tech / Digital / IT Jobs in Gloucester
- Tech / Digital / IT Jobs in Heywood, Rochdale
- Tech / Digital / IT Jobs in Melksham, Wiltshire
- Tech / Digital / IT Jobs in Paignton, Torbay
- Tech / Digital / IT Jobs in Plymouth
- Tech / Digital / IT Jobs in Poole, Somerset
- Tech / Digital / IT Jobs in Salisbury
- Tech / Digital / IT Jobs in Stroud
- Tech / Digital / IT Jobs in Swindon, Gloucestershire
- Tech / Digital / IT Jobs in Taunton, Tameside
- Tech / Digital / IT Jobs in Torquay, Torbay
- Tech / Digital / IT Jobs in Trowbridge, Caerdydd - Cardiff
- Tech / Digital / IT Jobs in Truro
- Tech / Digital / IT Jobs in Weston-Super-Mare, North Somerset
- Tech / Digital / IT Jobs in Weymouth, Dorset
- Tech / Digital / IT Jobs in Yeovil, Somerset
Similar jobs for you
Defence Digital - Cyber Security Risk Lead
Ministry Of Defence,
- Full time
- Permanent
Apply on company site
Senior Data Risk Analyst
BGL Group Ltd,
- Full time
- Permanent
Apply on company site
IT Risk Manager
Zurich Insurance,
- Full time
- Permanent
Apply on company site
External Risk Analyst
The Pensions Regulator,
- Full time
- Permanent
Apply on company site
Business Continuity and Crisis Risk Lead
OVO,
- Full time
- Permanent
Apply on company site