At a Glance
- Tasks: Lead cybersecurity governance projects and mentor team members while ensuring compliance with regulations.
- Company: Join Allstate, a leader in protecting families for over 90 years with innovative solutions.
- Benefits: Enjoy flexible working options, generous benefits, and access to world-class learning platforms.
- Why this job: Be part of a socially responsible organisation where your work has purpose and growth is supported.
- Qualifications: 5+ years in security/technology audit; knowledge of NIST standards; relevant certifications preferred.
- Other info: Allstate values diversity and encourages applications from under-represented groups.
The predicted salary is between 54000 - 84000 £ per year.
At Allstate, great things happen when our people work together to protect families and their belongings from life's uncertainties. For more than 90 years, our innovative drive has kept us a step ahead of our customers' evolving needs.
Your role in the team:
The Security Governance Lead Consultant develops and evaluates compliance with programs, processes, and procedures to mitigate cybersecurity risk and ensure protection of company information and assets; researches and develops interpretations of industry and government regulations, standards, and contract requirements for application to assigned area of operations.
Key responsibilities:
- Provides leadership and mentoring for less experienced team members on assigned projects and in area of expertise.
- Reviews and validates with Legal resources and communicates interpretations of regulatory, contract, and industry requirements for business and technical managers for cybersecurity governance and suggests application to assigned area; oversees the creation, organization, and maintenance of required filings and documentation.
- Performs ongoing and forensic audits of governance process and procedure compliance; tracks metrics, analyzes results, and develops recommendations for changes and enhancements; communicates to business and technical leadership.
- Works with business and technical leaders to develop governance plan and metrics for assigned area; develops, communicates, and executes programs and processes that provide guidance and promote cybersecurity risk awareness and management in alignment with operational needs.
This job does not have supervisory responsibilities.
Essential Skills:
- All applicants must demonstrate they have a legal right to work in the UK for employment at Allstate. Allstate is not providing sponsorship for this vacancy.
- 5+ years of security/technology audit experience, including development of control test plans/scripts.
- Working knowledge of NIST CSF 2.0 and/or NIST 800.53 rev. 5.
- Experience in automating control testing processes.
- Experience managing multiple assignments and projects at once.
Desirable Skills:
- 8+ years of security/technology audit experience, including development of control test plans/scripts.
- CISA, CRISC, CISSP, CISM, or other relevant certifications (preferred).
- Experience communicating effectively with resources of all levels (analyst to executive).
- Proven experience challenging ideas, asserting your expertise, and being comfortable making recommendations in a professional manner.
- Experience working in a role that requires strong attention to detail.
Why join us?
Allstate NI is proud to be Allstate's European Digital Centre of Excellence, recent winners of 'Best Use of Cloud Services' at the Belfast Telegraph IT Awards 2024, and recognised for our community and sustainability impact at the 2024 Business in the Community Awards and Gold accreditation for Environmental Responsibility.
We offer:
- A generous, flexible benefits package including annual leave, healthcare and dental cover, pension, and lifestyle discounts.
- Access to world-class learning platforms and award-winning L&D.
- Clear career paths, internal mobility, and a strong focus on growth.
- A people-first culture with flexible working options.
Be part of a high-performing, socially responsible organisation where your work has purpose, and your growth is supported every step of the way.
Statement on Fair Employment and Equal Opportunities:
Allstate NI wishes to ensure equal opportunity is given to all job applicants. This company will not discriminate on the grounds of race, gender (including gender reassignment status), sexual orientation, religious belief, political opinion, marital status, age or disability. We are an equal opportunities employer. We welcome applications from all suitably qualified persons. However, as women are currently under-represented in our workforce, we would particularly welcome applications from women. All appointments will be made on merit.
Applicants should note Allstate NI complete AccessNI background checks on all candidates offered a position.
Security Governance - Lead Consultant (hybrid/remote) employer: Allstate
Contact Detail:
Allstate Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Governance - Lead Consultant (hybrid/remote)
✨Tip Number 1
Familiarise yourself with NIST CSF 2.0 and NIST 800.53 rev. 5, as these are crucial for the role. Consider joining online forums or groups where professionals discuss these frameworks to gain insights and tips.
✨Tip Number 2
Network with current or former employees of Allstate, especially those in cybersecurity roles. They can provide valuable information about the company culture and expectations, which can help you tailor your approach.
✨Tip Number 3
Stay updated on the latest trends in cybersecurity governance and compliance. Follow industry news and participate in webinars to demonstrate your commitment to continuous learning during interviews.
✨Tip Number 4
Prepare to discuss specific examples from your past experience where you've successfully managed multiple projects or automated control testing processes. This will showcase your ability to handle the responsibilities outlined in the job description.
We think you need these skills to ace Security Governance - Lead Consultant (hybrid/remote)
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Security Governance Lead Consultant position. Tailor your application to highlight relevant experience in cybersecurity governance and compliance.
Highlight Relevant Experience: In your CV and cover letter, emphasise your 5+ years of security/technology audit experience. Include specific examples of how you've developed control test plans or automated control testing processes, as these are key aspects of the role.
Showcase Your Skills: Mention any relevant certifications such as CISA, CRISC, CISSP, or CISM. Also, demonstrate your ability to communicate effectively with various stakeholders, as this is crucial for the position.
Craft a Strong Cover Letter: Use your cover letter to express your passion for cybersecurity and your understanding of industry regulations like NIST CSF 2.0. Make it personal by explaining why you want to work at Allstate and how you can contribute to their mission.
How to prepare for a job interview at Allstate
✨Understand the Role
Make sure you have a solid grasp of the responsibilities and expectations for the Security Governance Lead Consultant position. Familiarise yourself with key terms like NIST CSF 2.0 and NIST 800.53 rev. 5, as well as the importance of compliance in cybersecurity.
✨Showcase Your Experience
Prepare to discuss your relevant experience in security/technology audits, particularly any projects where you've developed control test plans or automated testing processes. Be ready to provide specific examples that highlight your expertise.
✨Communicate Effectively
Since the role involves communicating with various levels of management, practice articulating complex ideas clearly and concisely. Think about how you can convey technical information to non-technical stakeholders.
✨Demonstrate Leadership Skills
Even though this position doesn't have supervisory responsibilities, it's important to show your ability to mentor and lead less experienced team members. Share instances where you've guided others or taken initiative in past roles.