Office location: Hammersmith - hybrid working 3 days in the office
About the role and the Team:
As a business-critical new role into the business, you will support the Senior Cyber Governance, Risk, Compliance and Regulatory Manager in developing and delivering a programme to improve our security posture and to align with our compliance and regulatory obligations, including Cyber Essentials, NCSC CAF and Telecoms Security Act (TSA). We are looking for a technical analyst with experience in translating regulatory requirements into BAU behaviours and someone who has strong stakeholder management is also key.
You will work with internal teams provide technical and tactical advice to many areas of the business (e.g. Procurement, HR, Business Compliance, Architecture, IT Infrastructure and Design) to create and implement security policies, standards, processes and controls in line with current regulations and standards, e.g., TSA, Cyber Essentials Plus and NCSC CAF.
What will you be doing?
1. Governance and Compliance
Work with internal and external teams providing technical and tactical advice and support the implementation of a required governance and control frameworks, including compliance monitoring and assurance.Work with regulatory and compliance teams to provide technical support and responses to requests for information from our regulators, insurer, auditors and third parties.Work with internal and external teams to manage and retain our certification, schedule audits, and ensure non compliances are remediated, on-going.Develop and deliver technical security standards against compliance framework requirements.
2. Risk Management
Monitor, Measure and Maintain cyber security technical risks.Drive cyber risk remediation activities.Active participation in identifying technical security risks requiring mitigation.
3. Technical and Tactical
Support Vulnerability Management activities across a broad technology estate (servers, user endpoints, network devices, in-house applications).Support Penetration/Security Testing activities and follow-up on resulting remediation tasks.Active participation in security tooling proofs of concept (PoCs).Pro-actively seek to improve technical security controls.Exhibit a curious & inquisitive nature e.g. pro-actively research new technologies.Adopt an attitude of – what might a bad actor do here, and what can we do to stop them?Ability to translate technical risks/topics into meaningful business language/adapt language to your target audience.
What we are looking for:
4. Understanding of identifying technical risk and security compliance opportunities, threats, and vulnerabilities.
5. High level of experience of Information Security implementation, development or operations.
6. High level of experience of Information Security Risk Management.
7. High level of understanding of the technologies and architectures used to support information security.
8. Hold a current UK Security Clearance or be willing to undergo security vetting.
9. Experience supporting a Vulnerability Management function.
10. Knowledge of common technical security misconfigurations.
11. Experience using common scripting & query languages (e.g. Python, Bash, PowerShell, SQL).
12. A good understanding of Architecture, process mapping.
13. Excellent verbal & written communication skills.
Why work for us?
We're in our customer's corner and our vision is to be the UK's most loved and desired broadband provider, that shows the way broadband is done!
Awarded Broadband Provider of the Year Uswitch Telecoms Awards, as voted for by 20, customers, plus Fair Terms Gold Award. We're also very proud to have been awarded Great Place to Work Certification (-23) and UK's Best Workplaces for Wellbeing
Going beyond the expected
Whatever we're doing – whether we're liaising with property professionals, delivering our network, or installing in a customer's home, going beyond the expected is the benchmark for everything we do. How we work is shaped by our three culture principles:
14. We work smarter, together
15. We stay focused
16. We strive for excellence
Some of our key Benefits
17. Competitive salary
18. 25 days' paid holiday increasing each year, to a max of 35
19. Extra days off for your birthday, moving home, wedding/civil partnership and to volunteer
20. Private medical Insurance provided by AXA health
21. Life assurance giving you cover of 4 times your base salary
22. Partnership with the Kings Trust
23. Our pension scheme matches your contributions up to 4%
24. Retail offers — discounts from hundreds of recognisable brands
25. Free Hyperoptic broadband if you live in a Hyperoptic area
26. Enhanced pay for new parents
We're committed to providing equal opportunities to all applicants and employees. In fact, this is at the heart of our culture and values. We welcome applications from candidates from all walks of life.