IT Quality, Security & Risk Analyst
Graduate job Glasgow (Glasgow City)
Job description
At ScottishPower, we believe in working together to make a world of difference. So, knowing that our people are our strongest asset, we’re always looking for individuals whose energy, intelligence and passion can help us reach our goals.
The IT Quality, Security and Risk (QSR) Analyst is part of the Systems UK Department in the Corporate business, liaising with Information Technology and Operational Technology, IT Programmes and Projects, Compliance and many External bodies. The role acts as the local co-ordinator for activities driven from the Global IT QSR and Corporate Cybersecurity teams.
The post holder, working under direction, will form part of the wider virtual team and be responsible for contributing, developing, and monitoring the IT Quality, Security and Risk framework in place for ScottishPower.
ACCOUNTABILITIES
- Provide technical IT Security advice and support to Management, the Business and Projects whilst striking a balance with both global and local requirements and obligations.
- Produce and implement local technology security procedures in line with Group Policies and ensure that technology decisions are compliant with Enterprise Security Architecture.
- Perform quality checks and risk assessments to ensure that appropriate security controls are in place and highlight any deficiencies and gaps for management consideration.
- Where required, coordinate delivery of mitigating actions to ensure risk levels are aligned with risk appetite.
- Work closely with other areas of the Group (Global QSR team, SP Businesses, Corporate Security) to ensure that IT Security meets the growing needs of the Business.
- Assist in the design and implementation of a global IT Quality, Security and Risk initiatives and global cyber security projects.
- Ensure that the appropriate technology controls are in place to support local and global compliance requirements.
- Provide local, IT technical support for UK and global security incident assessment and investigation.
- Work with the wider team to deliver IT Security awareness training and material as a required.
SKILLS, KNOWLEDGE AND EXPERIENCE
- Educated to degree level with a professional IT security qualification or equivalent experience.
- Strong understanding experience of IT Security concepts.
- Relevant professional qualification desirable, e.g. CISSP, SSCP
- Excellent communication and documentation skills.
- Strong analytical, influencing and interpersonal skills, with proven ability to communicate effectively at all levels.
- Ability to operate and engage at all levels in the Organisation.
- Knowledge of Information Security & Risk Management (ISO 27001/2/5 awareness preferred).
- Knowledge of IT Service Management (ITIL awareness preferred).
- Knowledge of legal, regulatory and industrial compliance obligations (e.g. DPA, PCI DSS, CNI).
- Project Management experience.
- Experience of Audit Compliance testing methodology and approach.
- Proficient with Microsoft Office products including Visio.
- Analytical, logical and data analysis skills.
- Policy Procedural development experience.
- Ability to work on own initiative.
- Efficiency orientated.
- Strong Customer focus.
MINIMUM CRITERIA
- IT Security professional qualification (or similar), or extensive relevant experience.
- ITIL and or ISO 27001/2/5 implementation experience.
- Security incident, threat and vulnerability assessment experience.
- Good knowledge of key business process, service performance and risk management.
- Good knowledge of IT and communications systems architecture and design.
BENEFITS
- Grade: PC17
- Salary: From £42,000
- Bonus up to 10%
- Single Cover Healthcare
- Pension plan
- Share incentive plan
- Enhanced maternity and adoption leave provisions
- Childcare Vouchers
- Enhanced annual leave
- Caring and development breaks
- Training and development
- And more.
ADDITIONAL INFORMATION
- Location: Spean Street, Cathcart*
- *In 2016 the department will move to the new ScottishPower HQ in Glasgow City Centre
No of Vacancies: 1 - Contract Type: Permanent
- Employment Status: Full Time
- Selection Method: Competency Based Interview
- Competencies: Achieving Results & Continuous Improvement, Initiative, Teamwork, Communication and Influencing, Flexibility & Globalisation.
CLOSING DATE: 12th OCTOBER 2015