- A keen learner.
- Experience working in a Cyber Security role.
- Good verbal and written communication skills.
- Provide professional advice and consultancy to Vitality business areas on Information Security best practice.
- Assist in the development, maintenance and improvement of the Information Security Management System (ISMS), so that certification to ISO27001 is maintained.
- Undertake internal audits based on ISO27001 requirements.
- Identify and assess information security risks and define appropriate mitigating controls. Carry out risk assessments as required of business processes and systems and projects.
- Mature the Data Loss Prevention and Access Management capabilities within Vitality.
- Contribute to the continuous improvement of Vitality’s Information Security posture.
- Engagement with project managers to ensure risks are identified and are being addressed through the SDLC.
- Define, implement and maintain information security policies, standards, procedures and processes.
- Undertake security due diligence on third party suppliers including site visits as required.
- Contribute to the development of information security training and awareness activities.
- Support audit efforts related to information security.
- Participate in the management of information security incidents.
- A professional certification such as CISSP/CISA/CRISC or the wiliness to undertake self-study to achieve one.
- Experience working in an Information Security role.
- Excellent understanding of Information Security principles, data protection and regulatory compliance.
- Problem definition and solution identification.
- Demonstrated ability to identify and implement process improvements.
- Excellent verbal and written communication skills; ability to articulate technical knowledge to non-technical audience.
- Experience in performing risk assessments and business impact analysis.
- Experience of working with projects throughout the SDLC.
- Experience of developing and implementing information security policies and procedures.
- Knowledge and experience of ISO27001/2, PCI DSS and other industry frameworks.
- Ability to conduct internal audits and write associated audit reports.
- Appropriate level of technical knowledge.
- Experience of information security monitoring tools (e.g. Mail Marshal / Websense / McAfee / Splunk etc).
- Sound understanding of security standards, data protection and regulatory compliance (e.g. Financial Conduct Authority and Information Commissioners Office).
- Bonus Schemes – A bonus that regularly rewards you for your performance
- A pension of up to 12%– We will match your contributions up to 6% of your salary
- Our award-winning Vitality health insurance – With its own set of rewards and benefits
- Life Assurance – Four times annual salary
- Help you to be the healthiest you’ve ever been.
- Create an environment that embraces you as you are and enables you to be your best self.
- Give you flexibility on how, where and when you work.
- Help you advance your career by playing you to your strengths.
- Give you a voice to help our business grow and make Vitality a great place to be.
- Give you the space to try, fail and learn.
- Provide a healthy balance of challenge and support.
- Recognise and reward you with a competitive salary and amazing benefits.
- Be there for you when you need us.
- Provide opportunities for you to be a force for good in society.