Senior Security Consultant
Core
Define, implement, and monitor corporate information security strategies, governance frameworks, and risk management activities to protect services, systems, and data for a large-scale transport ticketing ecosystem.
Role type
Senior Security Consultant (Information Security Governance & Risk Management)
Builds
Security frameworks, risk management systems, compliance programs, and security awareness initiatives for TfL's ticketing network.
Domain
Public Transportation / Cybersecurity / GRC
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Information security governance, risk management, incident response, regulatory compliance, third-party security management, security policy development, audit coordination, business impact analysis, security metrics reporting
Preferred skills
Cloud security, OT/ICS security, physical security principles, GRC platform usage, SOC operations knowledge, digital forensics, fraud management, automation of security processes
Technologies
ISO 27001/27002, GDPR, Cyber Assessment Framework (CAF), NIST CSF, ARCHER, GlobalSuite
Responsibilities
Define and monitor corporate information security strategies; lead risk identification, assessment, and treatment; oversee security monitoring and incident response; manage supplier and third-party security; develop and maintain security policies and standards; drive continuous improvement through performance monitoring; support business continuity planning; deliver security awareness training
Seniority
Senior, hands-on IC with strategic oversight