Information Security Consultant
Infosec Consultant, Cyber And Information Security, Security Transformation, SC - Security Clearance, Hybrid Working, Security By Design, Architecture Function, Technical Designs, Security Testing, Cloud Hosting Environments, CISSP, CISA, CISM, CCSP, ISO27k, NCSC Cyber Assessment Framework (CAF), GDPR, Cyber Essentials, CIS Critical Controls, NIST, OWASP, PCI-DSS, Microsoft Azure, IaaS
Annual Salary: Up to £70,000
Location: Gatwick, Hybrid (UK-wide candidates considered)
Security Level: SC - Vetting required
Join one of our Aviation clients, recognised as a world leader in its field. Their diverse activities enable the aviation industry to meet the highest safety standards. They're currently concluding a multi-year security transformation programme, making this an exciting time to join their security function. As an Information Security Consultant, you will play a pivotal role in applying, embedding, and enhancing updated tooling and procedures.
Day-to-Day of the Role
- Focus on cyber and information security controls and assurance, vital for achieving strategic objectives with a known level of risk.
- Act as the subject matter expert for security controls relating to the solution being delivered, providing guidance regarding technical and procedural security best practice to projects and internal teams.
- Ensure the protection of systems and information internally and by third parties, focusing on security by design through projects and business change.
- Work closely with the Architecture function and engage with stakeholders across the organisation.
- Assess the impact of projects on information security, ensuring secure design and solution delivery within the organisation's risk appetite.
- Validate security configurations and access to security infrastructure tools, including firewalls, web application firewalls (WAFs), anti-malware/endpoint protection systems, etc.
- Review project documentation, including technical designs, and coordinate security testing to ensure information security requirements are met.
Required Skills & Qualifications
- Demonstrable practical application of information security concepts and practices.
- Experience in reviewing technical designs and solutions to identify security risks and opportunities.
- Knowledge of implementing secure solutions within Cloud hosting environments.
- Excellent communication skills, with the ability to document and explain security principles clearly.
- Understanding and experience in applying controls and compliance with regulations (e.g., ISO27k, NCSC Cyber Assessment Framework (CAF), GDPR, Cyber Essentials, CIS Critical Controls, NIST, OWASP, PCI-DSS).
Desirable Skills
- Professional Information Security certifications (e.g., CISSP, CISA/CISM).
- An understanding of UK government information technology frameworks and systems
- Practical knowledge and experience of implementing secure solutions within Microsoft Azure and its services and components
- Excellent understanding of the current and emerging threats and countermeasures in information security.
- Familiarity with Agile and Waterfall project methodologies.
Our Benefits
- 28 days annual leave
- Generous pension scheme (up to 12% employer contribution).
- Access to wellbeing resources, including a free onsite gym at Gatwick and mental health support.
- Professional development opportunities.
In the first instance please submit your CV.