At a Glance
- Tasks: Join our GRC team to deliver PCI DSS consultancy and security assessments.
- Company: LRQA Nettitude is a leading global provider of cyber security services since 2003.
- Benefits: Enjoy remote work flexibility, professional development opportunities, and a supportive team culture.
- Why this job: Make a real impact in cyber security while working with diverse clients and innovative projects.
- Qualifications: Must be a current QSA with experience in PCI DSS and ISO 27001.
- Other info: Home-based role with travel opportunities across the UK and beyond.
The predicted salary is between 36000 - 60000 ÂŁ per year.
About LRQA Nettitude
We’ve been around since 2003 and our focus has always been on excellence in cyber security. We have teams that offer world class services in red teaming, penetration testing, threat intelligence, research and development, detection and response, governance, risk, and compliance, and plenty more. Our business is global and so are our clients. We work closely with central banks, central and local government, critical national infrastructure, large retailers, and plenty more besides!
We’re an award winning provider of cyber security services and we’re at a very exciting stage of development. We are looking for the right people to join us as we embrace the challenges thrown up by the advancements within the IT industry and within the threats faced. LRQA Nettitude will be at the forefront of this arena and we want to seek the right people to join the team and make it happen.
The role
We are looking for a QSA to join our GRC team in the UK. This role is home-based, with travel to client sites. You’ll be part of a team delivering security consultancy in a client-facing role, with a particular focus on:
- PCI DSS consultancy and assessments
- Security reviews against standards or guidelines such as the NCSC 10 Steps to Cyber Security and NIST CSF
- ISO 27001 gap analyses
- Helping our clients to implement Information Security Management Systems and achieve and maintain ISO27001 certification
- Conducting risk assessments
- Creating or supporting third-party risk management and audit programmes
Essential skills and experience:
- Be a current QSA who has completed multiple on-site PCI DSS assessments, and be able to demonstrate a mature understanding of complex PCI DSS environments, and an ability to consult as well as assess
- Have experience with ISO 27001, including implementing an ISMS and achieving certification
- Have experience working with the NIST CSF
- A good understanding of core concepts and technologies. For example, networking, Windows and Linux operating systems, and security technologies such as antimalware, IDS/IPS, etc. You do not need hands-on experience with these technologies or to have worked in an operational role
- Be experienced working as a consultant in a client-facing role, leading delivery. You’ll be friendly and approachable and able to work well with our clients
- Ability to work in a structured and methodical manner, with support to manage your own time with a focus on quality work
Your primary role will be to deliver PCI DSS consultancy and assessment activities to our clients as part of an established and experienced team of consultants. It’s not all PCI DSS, though, and you’ll be involved in other areas as listed above and have opportunities to scope and deliver more bespoke engagements.
Location
This role is home-based, with an expectation of travel to client sites, primarily in the UK, but with some opportunities for European and international travel; therefore, all candidates must be willing to travel. PCI DSS assessment activities require on-site work, but most other work is delivered at least partly from home. We can support working from across the UK. All applicants will require residence in the UK.
What you’ll be doing in your role:
In your role, you will deliver consultancy services to our clients, covering the following areas:
- Conduct security reviews against standards or guidelines such as the NCSC 10 Steps to Cyber Security, NIST CSF, Cyber Essentials
- Perform ISO 27001 gap analyses
- Help our clients to implement Information Security Management Systems and achieve and maintain ISO27001 certification
- PCI DSS consultancy and gap analyses
- Assistance in implementing PCI DSS requirements such as policy writing
- Complete on-site assessments and reports on compliance
- Complete risk assessments
- Conduct third-party risk reviews
- Support pre-sales where required by assisting in the pre-sales process, understanding client requirements and contributing to proposals and scoping of engagements
Key Skills:
Essential skills and experience:
- Be a current QSA who has completed multiple on-site PCI DSS assessments, and be able to demonstrate a mature understanding of complex PCI DSS environments, and an ability to consult as well as assess
- Have experience of ISO 27001, including implementing an ISMS and achieving certification
- A good understanding of core concepts and technologies. For example, networking, Windows and Linux operating systems, and security technologies such as antimalware, IDS/IPS, etc. You do not need hands-on experience with these technologies or to have worked in an operational role
- Be experienced working as a consultant in a client-facing role, leading delivery. You’ll be friendly and approachable and able to work well with our clients
- Ability to work in a structured and methodical manner, with support to manage your own time with a focus on quality work
Desirable skills and experience:
- Experience working with the NIS directive, NCSC CAF or CAA ASSURE
- Be experienced at C-Level, including presenting to top-level management, decision makers and risk owners. You will have the ability to articulate information security risks in a way that demonstrates an understanding of the broader business impact
- Demonstrate leadership as a senior team member. You will be expected to have input into developing the wider team, take ownership of service areas, and be able to support and mentor other team members
- Experience in delivering security awareness training to end-users
- Hand-on technical experience, even if not recent
Certifications
As an active QSA you must hold a certification from list A and list B per the PCI SSC requirements. Whilst a collection of certifications is less important than experience, many areas in which our team works have pre-requisite certifications that our consultants either hold or are working towards achieving. Any of the following certifications would be beneficial:
- ISO 27001 lead auditor or lead implementer
- CISSP - (ISC)2 Certified Information System Security Professional
- CISM - ISACA Certified Information Security Manager
- CISA - ISACA Certified Information Systems Auditor
- CRISC - ISACA Certified in Risk and Information Systems Control
What we offer:
We are a people-focused, high-performing, high-trust professional services team. You’ll be part of a diverse and growing international group of consultants, and we go out of our way to make sure our consultants feel part of our team. We use technology to ensure we’re always communicating with each other and schedule time every week to talk as a team.
The successful candidate will have opportunities to:
- Make a difference – as clichéd as it sounds, this really is true. We encourage all consultants to challenge norms and empower them to get involved. This might be getting involved with other teams or developing a new service offering – but if you want to do something, we always try to make it happen
- Get involved – enjoy blogging or public speaking? Our team is committed to getting involved in industry discussions. We make time to attend conferences and get involved in the infosec community
- Develop their skills – we love learning and ensure we find time for professional development. This isn’t just about collecting certifications and attending training courses – gaining and sharing knowledge in new areas is vital. These don’t always have to be directly related to your “day job”; in fact, we actively encourage developing knowledge in new and exciting domains
Qualified Security Assessor employer: Experis UK
Contact Detail:
Experis UK Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Qualified Security Assessor
✨Tip Number 1
Network with professionals in the cyber security field, especially those who are already working as QSAs. Attend industry events, webinars, or local meetups to connect with potential colleagues and learn about their experiences.
✨Tip Number 2
Familiarise yourself with the latest trends and updates in PCI DSS and ISO 27001 standards. This will not only enhance your knowledge but also demonstrate your commitment to staying current in the field during interviews.
✨Tip Number 3
Prepare to discuss real-world scenarios where you've successfully implemented security measures or conducted assessments. Having specific examples ready will showcase your practical experience and problem-solving skills.
✨Tip Number 4
Research LRQA Nettitude's recent projects and initiatives. Understanding their approach and values will help you tailor your conversations and show that you're genuinely interested in being part of their team.
We think you need these skills to ace Qualified Security Assessor
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your experience as a Qualified Security Assessor (QSA) and showcases your expertise in PCI DSS assessments, ISO 27001 implementation, and client-facing consultancy roles. Use specific examples to demonstrate your skills.
Craft a Compelling Cover Letter: Write a cover letter that not only outlines your qualifications but also expresses your enthusiasm for the role at LRQA Nettitude. Mention how your background aligns with their focus on cyber security excellence and your eagerness to contribute to their team.
Highlight Relevant Certifications: List any relevant certifications you hold, such as ISO 27001 lead auditor or CISSP, clearly in your application. This will help demonstrate your qualifications and commitment to the field of information security.
Showcase Soft Skills: In your application, emphasise your soft skills such as communication, teamwork, and leadership. Since the role involves client interaction and mentoring, showcasing these abilities can set you apart from other candidates.
How to prepare for a job interview at Experis UK
✨Showcase Your QSA Experience
Make sure to highlight your experience as a Qualified Security Assessor. Discuss specific PCI DSS assessments you've completed, focusing on the complexities of the environments you've worked in and how you consulted with clients.
✨Demonstrate Knowledge of Standards
Be prepared to discuss your understanding of ISO 27001, NIST CSF, and other relevant standards. Share examples of how you've implemented these frameworks in past roles, particularly in relation to Information Security Management Systems.
✨Client-Facing Skills Matter
Since this role involves direct client interaction, emphasise your ability to communicate effectively and build relationships. Share anecdotes that demonstrate your friendly and approachable nature while leading consultancy projects.
✨Prepare for Technical Questions
Brush up on core concepts related to networking, operating systems, and security technologies. While hands-on experience isn't necessary, showing a solid understanding of these areas will help you stand out during technical discussions.