Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this GRC Consultant role.
Rezi rewrites your resume against NTT Ltd.'s job description. Free.

Tailor your resume to this GRC Consultant role.
Rezi rewrites your resume against NTT Ltd.'s job description. Free.
Don't guess if your resume is good enough.
See how it scores against the GRC Consultant posting at NTT Ltd. — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the GRC Consultant posting at NTT Ltd. — free, in seconds.
About the Role
The GRC Consultant (Cyber Assurance / Security Operations Manager) is responsible for ensuring security controls are in place and operating effectively. The role focuses on the design, development, testing, and evaluation of information security throughout its lifecycle to enable business objectives safely and securely.
Responsibilities
- Provide security expertise across security standards and accreditations.
- Measure and control the effectiveness of the security controls framework.
- Maintain the Information Security Management System.
- Derive and deliver documented Information Security Management Plans incorporating Regulatory, Legal, and Compliance requirements.
- Assist with the identification of risks and emerging cyber security vulnerabilities and threats.
- Analyze risks and lead mitigation plans.
- Work with Service Management to ensure partner and supplier adherence to standards and policies.
- Verify compliance and security KPIs with partners and suppliers.
- Collaborate with 1st, 2nd, and 3rd lines of defence on cyber security, information assurance, cyber risk, and data privacy.
- Lead the development and enhancement of governance, risk, and compliance aligned to policy, standards, and industry best practices.
- Ensure continuous assessment, identification, analysis, and reporting of metrics for informed risk-based decisions.
- Challenge established processes and controls to identify and facilitate continuous improvement.
- Ensure personnel understand their security risk mitigation and remediation responsibilities.
- Review and verify documentation for process and technical security controls.
- Develop and maintain Information Security Management practice and process for industry standard certification (e.g., ISO 27001).
- Develop, propose, and seek sponsorship for changes to policies, procedures, and controls.
- Facilitate the implementation of security controls.
- Perform information risk assessments of existing or new services and technologies.
- Assess existing and proposed services to third-party suppliers.
- Facilitate IT Security checks during supplier onboarding and contract lifecycle.
- Coordinate audit, ITHC, and risk assurance activities.
- Govern Remediation Action Plans (RAPs) for timely mitigation of risks/vulnerabilities.
- Maintain working relationships with individuals and groups managing information risk.
- Chair and coordinate the Security Working Group (SWG).
- Actively participate in supporting/governing forums.
- Contribute to the analysis and mitigation of data protection risks.
- Monitor information security incidents.
- Contribute to incident response and root cause analysis.
- Own resulting actions related to IT Security and Information Risk Management policy and controls.
- Manage security operations and incident response.
- Liaise with internal teams and third-party suppliers.
Requirements
- A track record of delivering security solutions for large-scale infrastructure, transformation, or integration programmes.
- Practical knowledge and understanding of industry security frameworks and guidance such as NIST CSF, NIST 800-53, NCSC CAF and other NCSC guidelines.
- Good knowledge of networking (switching, routing, firewalls).
- In-depth knowledge of modern security concepts, common attack vectors, malware, security analytics, and threat intelligence.
- A good understanding of security testing and vulnerability management (including pen testing/ITHC, CVSS/CVE).
- Experience working with security standards such as ISO 27001, 27002, 27017, 27018 etc.
Skills
- Cloud platforms (AWS and/or Microsoft Azure) design concepts
- Native security capabilities within Cloud platforms (AWS and/or Microsoft Azure)
- CISSP, CISM, CCSP, CRISC or equivalent experience
- AD (Active Directory)
- Cryptography
- End User Computing
- IAM
- PKI
- Server hardening
- SIEM
- SOAR
- Virtualisation (VMware)
- MITRE ATT&CK
- ITIL
Location
- UK
Work Type
- Full-time
Experience Level
- Senior
About the Company
- NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune Global 100.
- We are committed to accelerating client success and positively impacting society through responsible innovation.
- We are one of the world’s leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services.
- Our consulting and industry solutions help organizations and society move confidently and sustainably into the digital future.
- As a Global Top Employer, we have experts in more than 70 countries.
- We offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners.
- NTT DATA is part of NTT Group, which invests over $3 billion each year in R&D.
Equal Opportunity
- NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity.
- We are committed to providing an environment free of unfair discrimination and harassment.
- We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category.
- Join our growing global team and accelerate your career with us.