Reading, Berkshire, United Kingdom Hybrid / WFH Options
Deloitte LLP
one end to end programme process including the use of ServiceNow Integrated Risk Management module to support integrated IT risk Management processes. An understanding of the principals around CMMI, COBIT, ITIL, PMI, Prince2, ISO27001, SOC2. Cybersecurity or IT Risk Management experience which should include either control testing or compliance assessment experience. A strong understanding of system development life cycles approaches More ❯
demonstrating compliance against internal security requirements and external commitments including certification and regulatory requirements. Provide subject matter expertise in the application of established standards including NIST, PCI-DSS, GDPR, COBIT, ISO 27001 and Cyber Essential compliance to any new or existing programme of work. Prepare and support internal and/or external compliance audit activities. Manage remediation of any audit … Maintain up-to-date knowledge of legal & regulatory requirements impacting Technologyand Operations and its Partners. Apply comprehensive knowledge of legal, regulatory obligations, and industry best practices (e.g., NIST, COBIT, ISO27001, PAS 555) to ensure compliance with technology standards. Schedule and review risk and compliance audits; direct issues to appropriate resources for investigation and resolution. Our people make us who … deliver for our customers. LI-KS1 Possess one of the Risk or security certifications (CISSP, CRISC, CISM). Have good knowledge and practical experience of NIST, PCI-DSS, GDPR, COBIT, ISO 27001, or Cyber Essentials. Previous experience in a similar role, with the ability to work in a dynamic and changing environment. Excellent team player who can influence, help, andMore ❯
risk and controls processes. Good understanding of the retail industry and its needs towards technology risks and controls. Strong understanding with various control frameworks and regulatory requirements, such as COBIT, NIST-CSF, Sarbanes-Oxley (SOX), Privacy (CCPA, GDPR, etc.), and other leading practice frameworks. An ability to communicate complex and technical issues to diverse audiences, orally and in writing, in More ❯
as NIST, PCI, GDPR, ISO Series, OWASP the IT Infrastructure Library (ITIL), the ISF Standards of Good Practice (SoGP) and ISACA's ControlObjectivesforInformationandrelatedTechnology (COBIT) frameworks. Actively represent the security organisation within business project initiatives, providing technical security leadership to ensure that security requirements and outcomes are defined and considered throughout the lifecycle of projects More ❯
in a similar role, with the ability to adapt in a dynamic environment. Strong team player with a supportive attitude. Experience with best practice frameworks such as ITIL/COBIT, and industry or academic credentials in risk management. More ❯