Technical Information Security Officer
Location: We operate a flexible, hybrid working environment with the candidate required to travel to our Winchester office twice a week. Candidates must be eligible and willing to undergo Security Clearance We offer Up to 85k base salary10% Bonus 6% pension contribution Private Medical 25 days annual leave Access to our comprehensive flexible benefits including discounts on big brands, wellness and employee assistance programmes, gymflex, buy and sell annual leave, travel and dental insurance Work. Life. Smarter. Our commitment to a flexible and hybrid working cultureRole Profile In this mid-level role you will take responsibility for providing security guidance and testing consultancy, partnering with Governance Risk & Compliance and Threat & Response teams, you will provide technical security leadership as the IS subject matter expert to support functions, interpret and embed the technical aspects of Arqiva’s information security strategy within their individual function's strategies. Who We Are Arqiva is at the heart of the broadcast and utilities sector in the UK and beyond. Through our infrastructure we ensure media and data is taken from, and delivered to where it is most valued, whether that’s from broadcasters to your TV screen or radio, or from your smart meter to the utility company. Even if you haven’t heard of us before, the chances are you’re indirectly a customer of ours and our infrastructure is part of your everyday life! We have a rich heritage and an exciting future ahead of us, and there’s so much more to us that we can’t wait to share with you. Key Responsibilities will include Provide guidance around Arqiva’s technical security risks, aiding delivery teams with solution implementation to meet the expected controls to ensure compliance to ISO27001 ISMS policies, legal, regulatory, or contractual obligations.Help drive projects implementing security obligations of the Telecoms Security Act.Enable stakeholders to integrate and embed the technical requirements of Arqiva’s Information Security Management Systems and supporting frameworks within the technical solutions and processes; supporting functions to raise exceptions against Arqiva’s ISMS.Take ownership of specific horizon scanning and engaging with external research and advisory organisations, industry bodies, customers, and 3rd party vendors to ensure current knowledge and skills are maintained; ensuring that IS can enhance innovation, improve productivity, and ultimately drive revenue.Support technical and product teams within Arqiva on bids (RFI/RFP) and designs to ensure security requirements are delivered as part of the product.Review project designs, offering actionable recommendations to the project team.Improve on, or develop new processes, procedures, policies, standards, and guidelines to continuously improve Arqiva’s cyber security maturity and promote awareness while providing consistent interpretation of policies.Define the scope for penetration tests, vulnerability assessments and technical reviews, evaluating results and driving on appropriate remedial actions.Assist and support Information Security Risk Assessors with risk assessments and appraisals.Must Haves Significant IS experience and knowledge including using artefacts / standards from at least one of the following authorities: National Institute for Standards and Technology (NIST) - Cyber Security FrameworkInformation Security Foundation (ISF) - The Standard of Good Practice for Information Security, Maturity Model, Benchmark, Using Cloud Services SecurelyCentre for Internet Security (CIS) - Controls, BenchmarkCloud Security Alliance (CCA) - Cloud Controls MatrixKnowledge & appreciation for ISO 27001/27002, the Network & Information Systems Regulations (NIS), ITIL and particularly the Telecom Security Act (2021) / Telecoms Security Code of Practice (2022). Good knowledge and experience of the following technologies: IP networking concepts and supporting protocols (Dynamic Routing, DNS, NTP, SNMP etc.)IT Security systems (Firewalls, IDS/IPS, Web proxy, PAM)Operational Technology (OT) security and connectivity, ideally with exposure to the Media and Broadcast sectors, and how this differs from typical IT systems.Satellite communicationsBroadcast RadioDigital Terrestrial Television (DTT)Media Multiplexing and content distributionOperations Support Systems (OSS)Experience: Min 3 yrs. in a dedicated security design/architect/consultant role delivering from requirements to build and transition. Min 5 yrs. in information Security environments Qualifications Qualification to RQF/FHEQ Level 5 - diploma of higher education (DipHE), foundation degree, higher national diploma (HND) level 5 award, level 5 certificate, level 5 diploma, level 4 NVQ Hold two of the following professional qualifications (preferably one being CISSP): CISSP, Certified Information Systems Security Professional (ISC2)CCSP, Certified Cloud Security Professional (ISC2)CCSK, Certificate of Cloud Security Knowledge (CSA)CISM, Certified Information Security Manager (ISCA)TOGAFCEH, Certified Ethical Hacker (EC-Council)CCNP Security, Cisco Certified Network Professional (Cisco) Inclusive Arqiva For us, building a working environment that is diverse, inclusive and engaged, is a positive for both our colleagues and our customers. This is why we have invested in our partnerships with initiatives and organisations such as Tommy's Pregnancy at Work, Inclusive Employers and WISE (Women in Science and Engineering). We also have active and thriving networks to support our colleagues like our Working Families network, Women at Arqiva and Diversity Ambassadors. We are working hard to ensure that we are making exciting opportunities accessible to all, and that every employee feels valued, heard and respected so that we can continue to build a high performance, high engagement culture.
read more