Jobs

Virtual CISO


Job details
  • Saepio Information Security
  • High Wycombe
  • 4 days ago

Why Saepio?


The world of cyber security is fast paced and exciting, and so are Saepio!


We are a risk-focused Cyber Security Solutions Provider that works with UK-based corporate customers with anything between 250-5,000 users & sometimes more. Our sole purpose is to help our customers reduce their cyber security risk by increasing their resilience across People, Process and Products following Saepio’s ‘Right size’ approach.


Cyber security is a team sport, and it is our team of talented and driven employees that has been the key to our continued success. We know that, as a cyber security professional, the world is your oyster when it comes to job opportunities, so we aim to build a company culture that you will want to be a part of and that supports you to be the best version of you.


You can find out more about the way we do things at Saepio and what it is like to be a Saepion at our websitehttps://saepio.co.uk/how-we-do-it/.


We recognise that talent comes in many shapes and sizes and from all walks of life and that often the best cyber defenders are the ones that you least expect. We encourage anyone who shares our passion and has the experience/potential to contribute to our success to apply.


The Opportunity for You


As a pure play cyber security company with a broad portfolio of customers, we can say with certainty that this role will ensure that you are working with a wide range of customers focused on solving their security challenges. This opportunity sits within our growing M-CISO Consulting Practice and presents an exciting opportunity to the successful candidate to help us build and grow this service.


With the increasing likelihood and impact of cyber-attacks coupled with a relative lack of internal security knowledge, many Saepio customers turn to us for strategic guidance. Saepio are recruiting for an experienced Information Security Risk Consultant, ideally a former CISO/Hd of IT Security/GRC SME, to work alongside our M-CISO team and deliver an outstanding service to our Customers.


The role is customer facing and customer focused. The successful applicant will be working with key Saepio customers on an onsite, remote, and/or virtual basis as appropriate, helping to develop and deliver the cyber security strategy as well as other security and information risk management initiatives. Operating as a virtual CISO, you will continuously improve and enhance their security posture, drawing on leading industry standards/frameworks e.g. NCSC Cyber Assessment Framework (CAF) that forms the basis of our Cyber Risk Assessment (CRA) approach.


The successful candidate will be expected to exercise a great deal of autonomy when delivering the service; however, there will be support from the broader team in both the Information Security and Customer Service aspects of the role. Saepio will support the training and development of the successful candidate along their journey to becoming a certified Chief Information Security Officer.


Main Responsibilities of this Role


Conduct initial and on-going assessments of maturity against NCSC CAF and/or ISO27001

Guide and drive security initiatives through scheduled weekly, monthly, and quarterly sessions

Establish and maintain an Information Security Management System (ISMS)

Define Risk Management Framework / Risk Register / Risk Treatment Plans

Administer/Inform Risk Committee and Infosec Committee

Produce and present quarterly Board reports

Align the security strategy to the customers business objectives

Understand how security controls can be utilised to plug gaps in a risk centric fashion

Present at Saepio customer events


Knowledge and Skills Required to be successful in the role. The successful candidate should be able to demonstrate the following:


At least 10 years’ experience in a hands-on IT Security function, including time as a CISO/Hd of IT Security/GRC lead/senior Consultant

A broad range of technical and non-technical security related skills and knowledge

Experience of working with, and guiding companies through the attainment of IT and Information Security standards (as a minimum - ISO27001 & Cyber Essentials Plus)

Excellent senior stakeholder management

Proven ability to effectively communicate with all levels at a customer - analyst/manager/head of IT/Board

  • Understanding of, and experience implementing, solutions across the CIS 18 Critical Security Controls

Proven Experience in:

  • Undertaking security gap analysis assessments
  • Developing, documenting, and maintaining security policies, processes, procedures, and standards
  • Security Architecture design
  • Implementing cyber governance and security strategies
  • Producing Weekly/Monthly/Q
  • Quarterly reports/dashboards
  • Working with outputs of SOC tools/systems
  • Risks associated with 3rd party supply chain
  • Increasing security awareness, behavior, and culture
  • Running Incident Management exercises, table-top or otherwise


Desirable Certifications:

Certified Information Systems Security Professional (CISSP)

Certified Information Security Manager (CISM)

CompTIA Security+

Certified Information Privacy Professional

Cyber Essential Plus Assessor

ISO 27001 Implementor/Auditor

CEH

NCSC-approved Cyber Advisor


A full Driving License is also desirable to ease travel to Clients in non-metropolitan areas.

Sign up for our newsletter

The latest news, articles, and resources, sent to your inbox weekly.

Similar Jobs

Senior Azure Cloud Specialist - Cyber & Security Domain Lead

Role Overview:Seeking a strong and influential Azure Cloud Specialist with Subject Matter Expertise (SME) in Virtual Desktop Infrastructure (VDI). The ideal candidate will possess a robust understanding of cybersecurity, with the capability to lead and influence technology decisions.Key Responsibilities:Cybersecurity Leadership:Demonstrate a strong cybersecurity and domain lead mindset, effectively integrating security...

hays-gcj-v4-pd-online Knutsford

Information Security Associate Director

The Associate Director, Information Security GRC will manage the people, processes, and technology related to the company's security GRC group overseeing governance, risk, and compliance activities, such as client audit support, RFP response, internal IT audit, and contract review. To carry out the GRC activities in line with business objectives,...

Belfast

Principal Enterprise Network Security Architect

Principal Enterprise Network Security ArchitectJoin a digital first bank that’s powered by people.Our technology team builds innovative digital solutions rapidly and at scale to deliver the next generation of banking services for our customers around the world.You’ll have an impact on bringing digital-first banking to our customers by defining the...

HSBC Edinburgh

Senior Consultant / Manager, Cyber Strategy, Cyber Transformation

Job descriptionConnect to your IndustryCyber security is critical to every organisation. We are shaping strategies and transforming the management of cyber risk and we need you to join us. You'll build strong relationships as one of the areas of our cyber practice with over 450 extremely talented individuals in the...

Deloitte LLP London

Azure / Cisco / Firewall / Security Engineer London £650/day

IT Infrastructure Engineer / Security Engineer | Azure Server and Network Implementation and Management | Cisco Firewalls, Routers, and Switches | Windows Servers | AD | Exchange | On Prem / Cloud | Banking / Financial Services | £-/day Inside IR35 | London (Hybrid working 2 days in the office...

Adecco London

Head Of Information Security

Kurt Geiger | About UsWe are an inclusive, creative footwear and accessories brand powered by kindness. We want to empower our talent to be confident and true to themselves, the London way. London is our home, our heartbeat, and we draw inspiration from the energy and spirit of the city;...

Kurt Geiger London