We are looking for a Cyber Security and Privacy Risk Assurer to support the Technology division of the Insurance Consultancy and Technology (ICT) business unit in managing cyber security risk, particularly in its expanding SaaS portfolio. You will support the business by working with software delivery teams and platform teams to identify, quantify and manage privacy and cyber security risk in new products and by providing ongoing privacy and cyber security risk assurance of live products.
As a cyber risk assurer, you will:
The essential skills / experience for this position are:
• Experience of working in a similar cyber security role within Governance, Risk and Compliance;
• Good understanding of cyber security concepts, controls and cyber risk management;
• Good understanding of software applications and networks;
• Broad understanding of international privacy and security requirements and standards, such as GDPR, SOC2 and ISO27001;
• Good analytic thinking, written and oral skills;
• A desire to work closely and co-operatively with software developers, platform managers, operations teams and all those critical to the development and running of desktop and SaaS products
Desirable skills / experience for this position are:
• Experience of working in DevSecOps environments
• Experience of working in the Cloud environment with Cloud controls
• Experience of being part of a team of security, assurance, and/or compliance professionals
• Information Security specific qualifications (such as CISM, CISSP, CISA)
• Degree in a relevant Business or Information Technology area
• Experience of working within internal or external audit, either within a previous organisation or as part of a professional services firm is desirable.
(ICT_TECH SD_2024_03R)