Location: We operate a flexible, hybrid working environment with the candidate required to travel to our Winchester office twice a week.
Candidates must be eligible and willing to undergo Security Clearance.
We offer:
* Up to 85k base salary
* 10% Bonus
* 6% pension contribution
* Private Medical
* 25 days annual leave
* Access to our comprehensive flexible benefits including discounts on big brands, wellness and employee assistance programmes, gymflex, buy and sell annual leave, travel and dental insurance.
Role Profile:
In this mid-level role, you will take responsibility for providing security guidance and testing consultancy. Partnering with Governance Risk & Compliance and Threat & Response teams, you will provide technical security leadership as the IS subject matter expert to support functions, interpret and embed the technical aspects of Arqiva’s information security strategy within their individual function's strategies.
Key Responsibilities:
1. Provide guidance around Arqiva’s technical security risks, aiding delivery teams with solution implementation to meet the expected controls to ensure compliance with ISO27001 ISMS policies, legal, regulatory, or contractual obligations.
2. Help drive projects implementing security obligations of the Telecoms Security Act.
3. Be accountable for reviewing and reporting on allocated functions obligations as above.
4. Enable stakeholders to integrate and embed the technical requirements of Arqiva’s Information Security Management Systems and supporting frameworks within the technical solutions and processes; supporting functions to raise exceptions against Arqiva’s ISMS.
5. Take ownership of specific horizon scanning and engage with external research and advisory organisations, industry bodies, customers, and 3rd party vendors to ensure current knowledge and skills are maintained; ensuring that IS can enhance innovation, improve productivity, and ultimately drive revenue.
6. Support technical and product teams within Arqiva on bids (RFI/RFP) and designs to ensure security requirements are delivered as part of the product.
7. Review project designs, offering actionable recommendations to the project team.
8. Improve on, or develop new processes, procedures, policies, standards, and guidelines to continuously improve Arqiva’s cyber security maturity and promote awareness while providing consistent interpretation of policies.
9. Define the scope for penetration tests, vulnerability assessments, and technical reviews, evaluating results and driving appropriate remedial actions.
Must Haves:
Significant IS experience and knowledge including using artefacts/standards from at least one of the following authorities:
* National Institute for Standards and Technology (NIST) - Cyber Security Framework
* Information Security Foundation (ISF) - The Standard of Good Practice for Information Security, Maturity Model, Benchmark, Using Cloud Services Securely
* Centre for Internet Security (CIS) – Controls, Benchmark
* Cloud Security Alliance (CCA) – Cloud Controls Matrix
Knowledge & appreciation for ISO 27001/27002, the Network & Information Systems Regulations (NIS), ITIL, and particularly the Telecom Security Act (2021) / Telecoms Security Code of Practice (2022).
Good knowledge and experience of the following technologies:
* IP networking concepts and supporting protocols (Dynamic Routing, DNS, NTP, SNMP etc.)
* IT Security systems (Firewalls, IDS/IPS, Web proxy, PAM)
* Operational Technology (OT) security and connectivity, ideally with exposure to the Media and Broadcast sectors, and how this differs from typical IT systems.
* Digital Terrestrial Television (DTT)
* Media Multiplexing and content distribution
* Operations Support Systems (OSS)
Excellent written and verbal communication skills, including executive level internal and customer presentations.
Excellent collaboration and engagement skills to form strong effective partnerships with internal and external stakeholders.
Experience: Minimum 3 years in a dedicated security design/architect/consultant role delivering from requirements to build and transition. Minimum 5 years in information security environments.
Qualifications:
Qualification to RQF/FHEQ Level 5 – diploma of higher education (DipHE), foundation degree, higher national diploma (HND) level 5 award, level 5 certificate, level 5 diploma, level 4 NVQ.
Hold two of the following professional qualifications (preferably one being CISSP):
* CISSP, Certified Information Systems Security Professional (ISC2)
* CCSP, Certified Cloud Security Professional (ISC2)
* CCSK, Certificate of Cloud Security Knowledge (CSA)
* CISM, Certified Information Security Manager (ISCA)
* CEng
* SABSA
* TOGAF
* CEH, Certified Ethical Hacker (EC-Council)
* CCNP Security, Cisco Certified Network Professional (Cisco)
Might Haves:
Experience of working in government or other highly regulated environments. However, we are open to wider applicants with an interest in the sectors we operate in.
We want to work with people who are passionate about what they do and believe in our vision. If you think you have most of the skills and/or experience we are looking for, please do apply for the role - we want to hear from you!
Inclusive Arqiva:
For us, building a working environment that is diverse, inclusive, and engaged is a positive for both our colleagues and our customers. We have invested in our partnerships with initiatives and organisations such as Tommy's Pregnancy at Work, Inclusive Employers and WISE (Women in Science and Engineering).
We have active networks to support our colleagues like our Working Families network, Women at Arqiva, and Diversity Ambassadors. We are working hard to ensure that we are making exciting opportunities accessible to all and that every employee feels valued, heard, and respected.
#J-18808-Ljbffr