Job description
ISSCA - ISO27001 PSN & CE Assurance Professional
- Audit/Assessments - To gain assurance that these are being planned and performed for the assigned business processes by the certification’s anniversary.
- Security Assurance – provides regular evidence-based assurance of BT’s cyber defense compliance at Line 2, and drives improvements to BT’s cyber security risk posture in relation to our current assured certifications.
- Issues and Escalations – To be able to clearly describe the current compliance status for any of the assigned business processes. Identifying issues that requires further action(s) to ensure that the correct steps are taken to protect and preserve our assured certifications. To be formally tracked and if not resolved within agreed timescales the role holder must escalate the matter immediately.
- Driving Change - To ensure that any changes across our various security certification schemes are incorporated within our business processes ‘in good time’ to maintain compliance.
- Communications - Acts as a communications bridge between our various security certifications schemes governance and the ‘working level’ within allocated business processes.
- Security Forums - Running relevant governance forums relating to the enactment of certification & assurance schemes where required.
- Risk Management - Identifying, collating, and communicating and monitoring risk management plans that affect certification.
- Sharing best practice and approaches with peers and first line teams to drive consistency and adherence to certification requirements
- Champion for driving compliance for BT BAU security and certification schemes.
- Maintaining high productive and effective working relationships with first line teams in the CFUs, product and capability owners.
- Working as part of an effective matrix team pan-CFU to enact components of certification.
- Facilitating dialogue with external parties, control boards & regulators etc.
- Story-telling - The ability to articulate the requirement and benefits of our current assured certifications.
- Business acumen - Understanding the value that compliance of our assured certifications brings to BT.
- Skill Sharing - The ability to knowledge share with other members within our organisation. (Mandatory)
- Technical requirements with knowledge of:
o ISO27001* (Mandatory)
o IISP (Preferred)
o MS Office (Mandatory)
o SharePoint (Preferred)
- at least one of whilst working towards both.
- Experience of supporting security compliance in a business environment. (Mandatory)
- Practical experience in one of IT Security, Physical Security, Systems Development, Systems Support / Operation (Mandatory)
- Understanding of security frameworks, policies & processes. (Mandatory)
- Demonstrable experience in BT processes for the management of operational and technology changes (Preferred)
- Demonstrable experience of team working in both hierarchical and matrix teams. (Mandatory)
- Competitive salary
- 25 days annual leave (plus bank holidays)
- 10% on target bonus
- Life Assurance
- Pension scheme
- Option to join the Healthcare Cash Plan or other benefits such as dental insurance, gym memberships etc.
- 50% off BT and EE mobile pay monthly or SIM only plans
- Exclusive colleague discounts on our latest and greatest BT broadband packages
- BT TV, including BT Sport and the NOW Entertainment membership, and 25% off NOW Sport, Cinema and Kids
- 30% discount for friends and family on EE mobile pay monthly and SIM only plans