- Company Name
- People's Partnership
- Job Title
- IT Security Consultant
- Job Description
-
Job Title: IT Security Consultant
Role Summary: A cybersecurity professional focused on assessing, designing, and maintaining security controls for internal applications, third‑party vendors, and Azure cloud environments, ensuring compliance with ISO 27001, CIS Controls, GDPR, NIST, and other regulatory frameworks, while providing incident response guidance and threat intelligence.
Expactations: Deliver comprehensive security assessments, audit oversight, incident response and disaster recovery consultancy, develop and maintain security documentation, maintain continuous monitoring of emerging threats, and collaborate with cross‑functional teams to align security with business objectives.
Key Responsibilities:
- Conduct security assessments of third‑party vendors and internal applications.
- Oversee security audits and penetration tests.
- Provide risk mitigation, incident response, and disaster recovery guidance.
- Analyze security events, incidents, and threat indicators.
- Develop and maintain security documentation in accordance with ISO 27001, CIS Controls, GDPR, and NIST.
- Ensure ongoing compliance with industry regulations and internal governance.
- Perform threat modeling and vulnerability management for new technologies.
- Monitor and respond to new threats, vulnerabilities, and regulatory changes.
Required Skills:
- Strong risk identification, assessment, and prioritisation across systems, applications, and vendors.
- Analytical and investigative skills for threat analysis and incident investigation.
- In‑depth knowledge of ISO 27001, CIS Controls, GDPR, and NIST frameworks.
- Experience securing Azure cloud environments with best‑practice configurations.
- Familiarity with threat intelligence and vulnerability management tools.
- Effective communication and stakeholder collaboration.
- Commitment to continuous learning of emerging threats and technologies.
Required Education & Certifications:
- CISSP qualification (or equivalent).
- Relevant tertiary education in Information Security, Computer Science or related field.
- Desirable additional certifications: ISO 27001 Lead Implementer, CISA, CEH, or similar.