Security Architect

Tiger Resourcing Solutions Limited ,
Redhill, Surrey
Salary: Up to £550 per day

Overview

Security Architect - ISO27001 - GDPR - PCI INSIDE IR35 Job Summary: The Security Architect is responsible for supporting multiple projects and programmes by defining and championing information security solutions. The role will work closely with systems and project engineers, developers, internal/external business stakeholders and project managers within various departments to assess risk and deliver pragmatic, flexible and sustainable security that includes people, process and technology. Essential Job Duties and Responsibilities: Provide information security technical consultancy to the business. Champion best practices for architecture and design principles for the use of existing and new information security technologies across internal and customer systems Conduct security business impact analysis and audit for new and existing business applications or IT infrastructure. Provide advice and guidance on the application and operation of physical, procedural and technical security controls (eg the key controls in ISO27001 and/or PCI-DSS). Assist the Systems Engineering teams in the design and development of bespoke customer solutions, ensuring solutions fit into the standard set of products the business offers and that they are supportable and clearly documented. Ensure that technical standards for information security fit policy requirements and are maintained, communicated and implemented. Minimum Job Requirements: Skills knowledge and experience: Essential: Solid exposure of taking a leading role in the establishment and implementation of security architecture, policies and procedures. Experience of secure development life cycles (SDL) Good understanding of enterprise-scale security management process and infrastructure Exposure to current information security standards and regulations such as PCI-DSS, ISO 27001, SOX, UK DPA Exposure to enterprise IT infrastructure and tools (eg Microsoft, Cisco, Sun, Oracle) Desirable: Experience of transactional revenue systems, Embedded systems, Smartcards, mobile payment systems Knowledge of cryptographic services Knowledge of wider security, audit, risk and compliance standards eg PCI-P2PE, PCI-POI-PTS, ISO 22301, ISO27005, ISO31000, NIST, GDPR Understanding of security within agile/DevOps and waterfall project methods, product development Experience of application security testing tools, eg SonarQube In depth understanding of information security control tools, eg ArcSight, Qualys, Splunk, Trend Micro DeepSecurity, Imperva, Tenable Nessus, TripWire, Cisco IPS, McAfee, IBM Guardium, Centrify, Barracuda Experience of quality management systems and external audit standards eg ISO 9001, ISAE3402 Education and qualifications Essential: Degree or equivalent and/or equivalent level of experience in relevant subject Certification as an Information Security professional (eg IISP/CISA/CISM/CISSP/ISA) Current driving license This job was originally posted as www.totaljobs.com/job/89646011