Information Security Engagement Consultant
Information Security Engagement Consultant

Information Security Engagement Consultant

Bury Full-Time 36000 - 60000 £ / year (est.) No home office possible
Go Premium
J

At a Glance

  • Tasks: Manage relationships and drive security awareness across the business.
  • Company: Join JD Sports, a leading global retailer in sports fashion and outdoor gear.
  • Benefits: Enjoy a dynamic work environment with opportunities for growth and innovation.
  • Why this job: Be part of a team that shapes security practices and protects the brand's reputation.
  • Qualifications: Ideal candidates should have knowledge of information security frameworks and strong communication skills.
  • Other info: This role offers a chance to influence security culture in a fast-paced retail environment.

The predicted salary is between 36000 - 60000 £ per year.

Information Security Engagement Consultant JD Sports- Head Office, Warwick House, Bury, Bury, United Kingdom Req #320 20 March 2025 Established in 1981 with a single store in the Northwest of England, the JD Group is a leading omni-channel retailer of Sports Fashion, Outdoors and Gyms with our colleagues working in stores across several retail fascias in many markets around the world. JD Sports Fashion Plc was listed on the London Stock Exchange in 1996 and has been a FTSE100 publicly quoted company since 2019 and continues to grow in the UK and internationally. We want to be the leading global omnichannel retailer in the sports and outdoor industry. To be a part of this successful company and help us to achieve this you will have the desire to ingrain our strategic goals of being a people-led, innovative and customer-focused organisation which provides operational excellence whilst identifying new areas of growth as part of our day to day objectives. Job Description for an Information Security Engagement Consultant Business Area Information Security Job Title Information Security Engagement Consultant Scope and Coverage Global Outline Purpose of Role The JD Sports Information Security Engagement Consultant is responsible for: Managing complex relationships, issues, and ambiguity associated with embedding security into diverse business and technical functions. Drive business wide awareness of Risk Management, Security Processes and the part Information Security plays in mitigating and controlling risks. Triage new requests and understand the security resource required to support the secure implementation. Advise the business on the correct security controls and processes that should be in place within their area. Manage the risk profile of their business area to drive accountability for security controls and risk. Understanding and communicating the balance between the needs of the business in creating value, and the importance of managing Information Security Risk to an acceptable level. Impact of Role The ISEC must drive a growing awareness of information, security, and risk management across all elements of the business and will: Provide consultative advice and support to all business entities so that they can engage effectively with Information Security and its people, technologies, processes, and capabilities. Help drive business wide, adoption of good security practice. Reports to This role resides in the Cyber Security Function and reports to the Head of Information Security Engagement (Group BISO) Direct Reports Individual contributor with possible periodic oversight of seconded resources, contingent workers and systems integrators. Key Elements of the Role The Information Security Engagement Consultant (ISEC) performs a critical role in the maintenance and implementation of security for the whole organisation. The ISEC is creative and innovative, capable of thought leadership, and is able to build strong and long-lasting relationships with key stakeholders throughout the business. Strategic Partnerships Help the organisation to adopt a risk-based approach to good security practice. Provide consultative advice and support to all business entities so that they can engage effectively with Information Security and its people, technologies, processes, and capabilities. Help embed an Information Security Management framework and communicate strategy to help drive Information Security awareness. Develop a clear understanding of the business area they are responsible for. Security Consultation The ISEC provides insight based on a knowledge of Information Security tools, technology, processes, standards, and trends. These skills coupled with strong relationship building abilities enable the ISC to: Communicate the criticality of risk management and information security to driving confidence to transact, while protecting against regulatory non-compliance, reputational damage, and financial loss. Work collaboratively with business owners within the various business entities to correctly identify strengths, weaknesses, vulnerabilities, and opportunities for improvement. Formulate clear recommendations, drive governance strategies, and influence business stakeholders and technology stakeholders at all levels. Drive continuous improvement in the adoption and exploitation of good information security practice across the business. Drive security innovation that enables new retail capabilities while working with IT GRC for maintaining appropriate risk controls. Facilitate communication between enterprise security teams and retail business units. Delivery of security services Triage, review and manage new project and security requests to provide a quality, repeatable security assessment. Coordinate between technical teams and business stakeholders during security incidents. Articulate JD Sports’ Information Security policies, standards, processes, and strategy to build understanding and buy-in from the business owners enabling them to engage with information, security, and consume information, security controls and services. Help ensure that information security requirements are considered at the earliest phases of a project, so that the capabilities and services that drive JD Sports’ business have security and information protection built in as standard. Provide training and awareness to the business to allow a greater understanding of their role in protecting JD. Key Attributes of The Jobholder The job holder will demonstrate: Clear, concise, and engaging communication skills, both verbally and written, including an ability to use the full functionality of commonly used reporting and presentation tools. Strong mentoring, and organisational skills with experience of leading and working collaboratively within multi-disciplined teams. An ability to manage and inspire diversely located teams to adopt good security practice and exploit the power of the available tools. A proven ability to work collaboratively and constructively with the various internal entities of large complex organisations and third-party providers. Jobholder Business Impact The job holder must demonstrate a comprehensive understanding of information security and risk management services to drive understanding and adoption of good practice to protect: The business, Operations, Data repositories, Compliance with regulatory requirements, Finances such as cash flow and revenue, Brand reputation and customer confidence, Audit findings to prevent fines and penalties. Quality Support the adoption of repeatable processes, methods, and tools to drive consistent, trusted services. Deliver a high-quality consultative engagement with the wider organisation. Monitor Information Security adoption and help ensure compliance with applicable JD Sports policies and standards as well as recognised best practices. Identify and drive opportunities for continuous improvement initiatives while increasing security coverage on an ongoing basis. Help the business respond to developments in best practice, new and emerging threats, and changes in regulatory requirements. Leadership Provide strategic risk guidance and security thought leadership for IT projects, including the evaluation and recommendation of mitigating controls. Use strong communication skills, and a consultative style of engagement to incrementally drive a risk and security aware culture throughout all parts of JD Sports, and its various entities. Provide thought leadership, recommendations, and oversight to help implement recognised best practice. Use successful implementations as portable examples of excellence that can serve as a template for accelerating global adoption and coverage. Provide risk and security subject matter expertise to support and mentor the various businesses and teams within JD Sports. Key Skills The job holder is expected to possess the following skill set: Ability to advise, guide and inspire adoption of Information Security and Risk Management best practice resulting in an increasingly robust security posture. Proven track record of developing people and relationships. Ability to extract clarity from fast-paced, evolving scenarios by helping to clarify the inevitable ambiguity arising within a large, complex, and interdependent organisation. Ability to articulate goals, achievements, risks, expectations, and needs to individuals and teams at all organisational levels. Ability to formulate and help deliver information, security and risk management, training and awareness programs in collaboration with HR. Demonstrable experience of a wide range of technology security solutions and controls, including hybrid cloud and on-premise security capabilities. Experience with common information security management frameworks, such as International Standards Organization (ISO) 2700X, NIST, CIS, the IT Infrastructure Library (ITIL), Control Objectives for Information and Related Technology (COBIT), Critical Security Controls for Effective Cyber Defense, or the ISF Standard of Good Practice / IRAM2. Awareness of various operating systems including but not limited to Windows, Linux, Unix. Awareness of Database technologies (SQL, Oracle, DB2, Mongo) and associated controls optimised for their protection. Awareness of security controls in widely used technologies e.g., MS Office 365. Awareness of Incident Management and Response tools – IBM Resilient, Remedy, Remedy CMDB. Qualifications Industry Standard qualifications and training such as SANS, GIAC or CISSP are desirable. Values and Behaviours The job holder will be a strategic thinker who is respectful and collaborative and able to work easily within a diverse and dispersed team of professionals and will exhibit: Goal-oriented focus, Integrity, Empathy, Accountability. Flexibility, Creativity. #J-18808-Ljbffr

Information Security Engagement Consultant employer: JD Sports Fashion

JD Sports is an exceptional employer, offering a dynamic work environment at its Head Office in Bury, where innovation and collaboration thrive. Employees benefit from a strong focus on professional development, a culture that values diversity and inclusion, and the opportunity to contribute to a leading global omnichannel retailer in the sports and outdoor industry. With a commitment to operational excellence and employee well-being, JD Sports fosters a workplace where individuals can grow their careers while making a meaningful impact.
J

Contact Detail:

JD Sports Fashion Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Engagement Consultant

✨Tip Number 1

Familiarise yourself with JD Sports' business model and values. Understanding their focus on being a people-led, innovative, and customer-focused organisation will help you align your discussions during interviews and demonstrate how you can contribute to their strategic goals.

✨Tip Number 2

Network with current or former employees of JD Sports, especially those in the Information Security field. Engaging with them can provide valuable insights into the company culture and expectations, which can be beneficial when discussing your fit for the role.

✨Tip Number 3

Stay updated on the latest trends and best practices in information security and risk management. Being able to discuss recent developments or case studies during your interview can showcase your expertise and commitment to continuous improvement in the field.

✨Tip Number 4

Prepare to articulate your experience in managing complex relationships and driving security awareness. Think of specific examples where you've successfully influenced stakeholders or implemented security practices, as this will demonstrate your capability to fulfil the role effectively.

We think you need these skills to ace Information Security Engagement Consultant

Information Security Management
Risk Management
Stakeholder Engagement
Consultative Communication
Security Awareness Training
Incident Management
Technical Security Solutions
ISO 27001 Knowledge
NIST Framework Familiarity
ITIL Understanding
Governance Risk and Compliance (GRC)
Relationship Building
Analytical Thinking
Problem-Solving Skills
Project Management

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience and skills that align with the role of Information Security Engagement Consultant. Focus on your knowledge of information security frameworks, risk management, and any consultative roles you've held.

Craft a Compelling Cover Letter: In your cover letter, express your passion for information security and how your background makes you a perfect fit for JD Sports. Mention specific examples of how you've successfully managed relationships and driven security awareness in previous roles.

Showcase Communication Skills: Since the role requires clear communication, ensure your application reflects your ability to convey complex information simply. Use concise language and structure your application logically to demonstrate your communication prowess.

Highlight Continuous Improvement Initiatives: Discuss any past experiences where you've implemented or contributed to continuous improvement initiatives in security practices. This will show your proactive approach and commitment to enhancing security measures.

How to prepare for a job interview at JD Sports Fashion

✨Understand the Role

Before your interview, make sure you thoroughly understand the responsibilities of the Information Security Engagement Consultant. Familiarise yourself with JD Sports' approach to information security and how this role fits into their overall strategy.

✨Showcase Your Communication Skills

As this role requires clear communication with various stakeholders, be prepared to demonstrate your ability to convey complex information in a simple manner. Use examples from your past experiences where you've successfully communicated security concepts to non-technical audiences.

✨Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Think about past situations where you had to manage security risks or implement security controls, and be ready to discuss your thought process and outcomes.

✨Highlight Your Collaborative Experience

This position involves working with diverse teams across the organisation. Be ready to share examples of how you've collaborated with different departments to enhance security practices, and how you’ve built strong relationships to drive security initiatives.

Information Security Engagement Consultant
JD Sports Fashion
Location: Bury
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

J
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>