Cybersecurity Consultant, GISI Consulting Group

Cybersecurity Consultant, GISI Consulting GroupAbout GISI Consulting
Group and PalladiumGISI Consulting
Group (GISI CG) is a top 10 global provider of program and project management
and engineering consulting services delivering outcomes and solutions for some
of the most complex challenges. We deliver services in infrastructure & mobility, earth
& water, and government & society segments across more than 100
countries. With over 5,000 projects
annually and a global team of over 11,000 professionals, our advisory,
consulting, design and program management capabilities enable us to create a
safer and more sustainable world. Learn more about GISI CG at Palladium, a GISI company, works to design, develop and deliver
positive impact on the lives and livelihoods of people around the globe;
broaden access to health, water, power, and infrastructure; build enduring,
sustainable, and transformative institutions and market systems to address
global challenges; and conserve the natural world. We operate in over 90
countries and have a workforce of 2,100 talented, motivated, and diverse staff
around the world. This role will be hired through Palladium, an operational
platform for GISI CG.This OpportunityThe Cybersecurity Consultant will support
GISI Consulting Group's (GCG) Operating Companies (OPCOs) in strengthening
their cybersecurity posture by advancing their cybersecurity maturity in
alignment with GCG global security strategy, policies, and standards. The role
will act as an advisor to local business and technology teams, conduct
cybersecurity maturity assessments, identify gaps and risks, drive remediation
initiatives, and support the implementation of security best practices across
diverse business environments. The Manager will work closely with the ICT
Cybersecurity and Compliance workstream teams to ensure consistent application
of security controls.

This consultancy is up to ten months with
the possibility of an extension to one year.

LocationThis role will be based remotely in the UK. To be
considered for this position, you must have valid work rights in the country
where the role is based. Please note that visa sponsorship is not available for
this role. Reporting LinesThe Consultant will work under the direction of the SVP, IT Operations (based in the US)This role will have regular meetings with the Cybersecurity and Compliance workstream teams and key stakeholders from the OPCOsPrimary Roles and Responsibilities Partner with assigned OPCOs to assess, improve,
and monitor their cybersecurity maturity and alignment with GCG's
Information Security Policies and standardsIdentify, assess, and monitor applicable local
privacy, regulatory and contractual requirements for assigned OPCOs, and
ensure alignment with both local obligations and GCG's standardsDevelop and maintain remediation roadmaps and
action plans to address identified security gapsSupport OPCOs in implementing security controls,
standards, and procedures in accordance with GCG's cybersecurity
requirementsProvide guidance on cybersecurity governance,
risk management, vulnerability management, incident response, data
protection, identity and access management, and third-party risk
managementDevelop SOPs, templates, checklists, and guidance
documents to support consistent adoption of cybersecurity best practicesEssential
CriteriaBachelor's degree in Computer Science, Cybersecurity, or equivalent8+ years of relevant ICT experience in the field of cybersecurityStrong understanding of cybersecurity frameworks and industry best practices, including NIST CSF, CIS Controls, ISO 27001, and risk management principlesDemonstrated experience assessing and improving cybersecurity maturity programsKnowledge of security governance, compliance, vulnerability management, incident response, identity and access management, and data protectionStrong analytical and problem-solving capabilities with the ability to translate technical risks into business impactAbility to manage multiple initiatives and priorities across different operating companiesExcellent communication, presentation, stakeholder management, and relationship-building skillsStrong project management and organizational skills. Ability to work independently while collaborating effectively within a global team environmentDesired CriteriaCybersecurity certification desirableApplications will be accepted on a rolling basis. We encourage you to
apply early as the position may close once a suitable candidate is found. Please
note that only shortlisted candidates will be contacted.

Equity,
Diversity & Inclusion - Palladium is committed to embedding equity, diversity, and inclusion into
everything we do. We welcome applications from all sections of society and
actively encourage diversity to drive innovation, creativity, success and good
practice. We positively welcome and seek to ensure we achieve diversity in our
workforce; and that all job applicants and employees receive equal and fair
treatment regardless of their background or personal characteristics. These
include: (but are not limited to) socio-economic background, age, race, gender
identity and expression, religion, ethnicity, sexual orientation, disability,
nationality, veteran, marital or Indigenous status. Should you
require any adjustments or accommodations to be made during the recruitment
process (due to disability, neurodiversity, or for any other circumstance),
please email our team at accessibility@thepalladiumgroup.com and we will be in touch to discuss.

Safeguarding - We define Safeguarding as "the
preventative action taken by Palladium to protect our people, clients and the
communities we work with from harm". We are committed to ensuring that all
children and adults who come into contact with Palladium are treated with
respect and are free from abuse. All
successful candidates will be subject to an enhanced selection process
including safeguarding-focused interviews and a rigorous due diligence process.

Job Details

Company
Palladium Group
Location
London, UK
Hybrid / Remote Options
Employment Type
Full-time
Posted