Jobs Companies NTT GRC Consultant

About this GRC Consultant role at NTT

NTT · Onsite · London, United Kingdom

Continue to make an impact with a company that is pushing the boundaries of what is possible. At NTT DATA, we are renowned for our technical excellence, leading innovations, and making a difference for our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can continue to grow, belong, and thrive.

Your career here is about believing in yourself and seizing new opportunities and challenges. It’s about expanding your skills and expertise in your current role and preparing yourself for future advancements. That’s why we encourage you to take every opportunity to further your career within our great global team.

Your day at NTT DATA
The GRC Consultant (Cyber Assurance / Security Operations Manager) is primarily responsible for ensuring the security controls (people, process, technology) are in place and operating as designed. The primary aim is the design, development, test and evaluation of information security throughout its lifecycle. This is to ensure the business purpose of the system is enabled in a safe and secure manner based on the alignment of identified risks to the acceptable risk posture of the business.
Looking ahead to future opportunities. As our business continues to grow, we are building a pipeline of exceptional talent for upcoming positions across the UK. This advertisement is intended to identify and engage candidates in advance of specific vacancies becoming available. We encourage you to apply if you would like to be considered for future opportunities that match your expertise.

Key responsibilities:
  • Providing security expertise across security standards and accreditations, measure and control the effectiveness of the security controls framework and maintain the Information Security Management System.
  • Deriving and delivering documented Information Security Management Plans which incorporate Regulatory, Legal and Compliance in relation to applicable security policies. Standards and guidelines
  • Assisting with the identification of identified risks and emerging cyber security vulnerabilities and threats. The subsequent analysis to quantify and lead risk mitigation plans
  • Work with Service Management to ensure that partners and suppliers adhere to agreed standards, policies and verify/evidence appropriate compliance and security KPIs
  • Work closely with 1st, 2nd and 3rd lines of defence on all matters relating to cyber security, information assurance, cyber risk, data privacy including regulatory and compliance considerations
  • Lead the development and enhancement of governance, risk and compliance aligned to policy, standards an industry good practice
  • Ensure that continuous assessment, identification, analysis and reporting of useful metrics to enable informed risk based decisions to be taken 
  • Constructively challenge established processes and controls to identify, recommend and facilitate continuous improvement, ensuring that all personnel (including senior stakeholders) understand their responsibilities in relation to security risk mitigation and remediation
  • Review and verify that documentation relating to process and technical security controls are maintained
  • Develops and maintains Information Security Management practice and process to ensure certification to required industry standards (e.g., ISO 27001) within relevant geographic boundaries.
  • Develops, proposes and seeks sponsorship for changes to policies, procedures and controls to ensure the integrity of the in-scope IT services and effective management and control of information assets. Facilitates the implementation of these controls.
  • Performs focused information risk assessments of existing or new services and technologies, alongside the Operational/Service Management team and technology subject matter experts.
  • As required, will extend the assessment of existing and proposed services to third party suppliers, including the facilitation of IT Security checks during the supplier onboarding and contract lifecycle to ensure coherent approach to risk management
  • Coordinate audit, ITHC and risk assurance activities to evidence compliance with established regulatory and governance requirements including governance of any Remediation Action Plan (RAP)   to ensure timely mitigation of identified risks / vulnerabilities
  • Maintains strong working relationships with individuals and groups involved in managing information risk across the in-scope services and aligned suppliers / 3rd parties 
  • Chairs and co-ordinates the Security Working Group (SWG) and actively participates in supporting/governing forums
  • Contribute to the analysis and mitigation of data protection risks
  • Monitors information security incidents, contributing to incident response and root cause analysis. Will own resulting actions as required where they relate to required changes in IT Security and Information Risk Management policy and controls
  • Security operations and incident response, liaison with internal teams and 3rd party suppliers

To thrive in this role, you need to have:
  • A track record of delivering security solutions for large-scale infrastructure, transformation or integration programmes
  • Practical knowledge and understanding of industry security frameworks and guidance such as NIST CSF, NIST 800-53, NCSC CAF and other NCSC guidelines
  • Good knowledge of networking (switching, routing, firewalls)
  • In-depth knowledge of modern security concepts, common attack vectors, malware, security analytics and threat intelligence.
  • A good understanding of security testing and vulnerability management is important (including pen testing/ITHC, CVSS/CVE)
  • Experience working with security standards such as ISO 27001, 27002, 27017, 27108 etc

DESIRABLE SKILLS AND EXPERIENCE

  • Experience with the design concepts associated with adoption of Cloud platforms (AWS and/or Microsoft Azure)
  • An understanding of the native security capabilities and good practice within Cloud platforms (AWS and/or Microsoft Azure)
  • CISSP, CISM, CCSP, CRISC or equivalent experience
  • Good knowledge covering several of the following examples (this list is not exhaustive): AD (Active Directory), Cryptography, End User Computing, IAM, PKI, Server hardening, SIEM, SOAR, virtualisation (VMware)
  • Familiarity with MITRE ATT&CK
  • Familiarity with ITIL

Workplace type:

Equal Opportunity Employer
NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Accelerate your career with us. Apply today

Ready to apply to NTT?
Apply to NTT

About NTT

Is innovation part of your DNA? Do you want to enable a connected future for people, organizations, and society? Join our growing global NTT family and you’ll be part of the world’s largest ICT company (by revenue). We’ve combined the capabilities of 28 remarkable companies to become one, leading technology services provider. Together, we help our people, clients, and communities do great things with technology to create a more secure and connected future. We employ 40,000 people across 57 countries. By bringing together the world’s best technology companies and emerging innovators, we work together to deliver sustainable outcomes to businesses and the world. Innovation is part of our DNA. W

See all jobs at NTT →

Similar jobs

Solirius Reply
Delivery Consultant
Solirius Reply
⚡ Apply early London, England, United Kingdo... Onsite
● New 👁 Seen ✓ Applied 2d ago
U.S. Bank
Technical Sales Consultant
U.S. Bank
⚡ Apply early United Kingdom, United Kingdom Onsite
● New 👁 Seen ✓ Applied 3d ago
Two Circles
Lead Consultant, Content Insights
Two Circles
⚡ Apply early London, England, United Kingdo... Onsite
● New 👁 Seen ✓ Applied 3d ago
Sword Group
Digital Workplace Consultant
Sword Group
⚡ Apply early Glasgow, Scotland, United King... Onsite
● New 👁 Seen ✓ Applied 3d ago
AlphaSense
Pre-Sales Consultant, Corporate (French Speaker)
AlphaSense
⚡ Apply early London, Greater London, Englan... Onsite
● New 👁 Seen ✓ Applied 3d ago
Steer
Transport Modeller: Consultant/Senior Consultant
Steer
⚡ Apply early London, England, United Kingdo... Onsite
● New 👁 Seen ✓ Applied 3d ago
Inizio Ignite
Consultant, Value Pricing and Market Access
Inizio Ignite
⚡ Apply early London, United Kingdom Onsite
● New 👁 Seen ✓ Applied 3d ago
ERM
Managing Consultant- EIA Flood Risk Specialist
ERM
⚡ Apply early Manchester, United Kingdom Onsite
● New 👁 Seen ✓ Applied 4d ago
Brandwatch
Insights Consultant
Brandwatch
⚡ Apply early London, England, United Kingdo... Onsite
● New 👁 Seen ✓ Applied 4d ago

Sign up for suggestions tailored to the jobs you open and the searches you save.

More jobs at NTT

See all jobs at NTT →

Apply now
🤖

Whoa — hold up

JobsRadar was built for real people having a rough time in their job search — not for automated requests. You're clicking way too fast and you're now temporarily blocked.

Come back later. If you're genuinely job hunting, we've got your back — just act like a human.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Get an edge on your job hunt.

Join our Telegram channel for the stuff that helps you land the role — salary benchmarks, the weekly market pulse, and new-feature drops. No spam, just signal.

Join the channel — it's free