At a Glance
- Tasks: Join our team to assess security risks and ensure compliance in a dynamic tech environment.
- Company: Cubic, a leader in innovative transportation and defence technology solutions.
- Benefits: Enjoy competitive pay, flexible work options, and opportunities for professional growth.
- Other info: Be part of a diverse team committed to solving global challenges.
- Why this job: Make a real impact on global transportation solutions while enhancing your career in IT security.
- Qualifications: Experience in IT security and compliance, with strong communication skills.
The predicted salary is between 45000 - 55000 £ per year.
When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people’s lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation. Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly.
As a member of the Cubic information security team, you will provide security compliance support for production transaction processing environments. You will evaluate the posture of security controls and operating environment to ensure compliance with organisation security policies and controls. You will plan and prepare the scope of IT compliance evaluation programs across the organisation, isolate potential risks or liabilities, and develop mitigation plans. You will partner with external auditors to coordinate and facilitate PCI-DSS, ISO 27001, etc. compliance/audit efforts.
Responsibilities:
- Perform as the recognized Subject Matter Expert on Security Risk Assessment methodology, policy, strategy and processes.
- Facilitate all security audit operations, including scheduling, vendor coordination, program, and stakeholder coordination.
- Responsible for coordination with the Internal/External Auditors and Information Technology teams to successfully complete periodic audits.
- Lead the design and control reviews and assessments to support continuous compliance with security policies and standards.
- Manage security review processes for all solutions to ensure their design and implementation meet compliance requirements – including PCI-DSS, ISO 27001, SOC 1 & SOC 2 and other regional requirements.
- Document and actively communicate any areas where the solutions and processes are not fully compliant.
- Identify and report significant information security risks associated with applications, development, networking, data centres, Cloud and physical IT infrastructure, vendors and other third parties.
- Work with system operators and security subject matter experts to communicate system compliance gaps and develop acceptable remediation plans.
- Capture compliance gaps and remediation plans in the OneTrust GRC system.
- Liaise with Cubic customers and Security Teams to build positive relationships and outcomes.
- Prepare and maintain process and control documentation.
- Aid in the development of solutions to problems identified during audits and translate these solutions into practical recommendations.
- Follow up on recommendations and appraise corrective actions taken to improve deficient conditions.
- Review vendor contracts and SOC reports to evaluate the impact on the company’s controls.
Skills/Experience/Knowledge:
- Strong written and oral communication skills in English, with capability to use Microsoft Office solutions.
- Ability to effectively and openly collaborate with team members, clients, IT management, staff, and business units in a cross-functional and matrixed IT organisation.
- Familiarity with PCI DSS 4, ISO 27001-2022, and/or SOC I/II requirements and audits.
- Expert level experience collaborating with stakeholders and solution providers in a cross-functional and matrixed IT organisation.
- Exhibits advanced wide-ranging experience, using in-depth professional knowledge, acumen, concepts and company objectives to develop, resolve complex models and procedures.
- Understands and works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors.
Qualifications:
- Experience in services or IT systems in a mission-critical setting.
- University degree in Computer Science, Engineering, or other technical fields, or Business Administration with relevant IT work experience.
- Experience working in IT security and/or Payment Card processing systems.
- The candidate must reside within commuting distance from CTS offices and be able to periodically travel within the region.
We are committed to creating an inclusive workplace and welcome applications from people of all backgrounds. We do not discriminate based on any protected characteristic under applicable law.
Senior Risk Management Analyst in Surrey employer: Cubic Corporation
Cubic Corporation is an exceptional employer that values its employees by fostering a supportive work culture and providing ample opportunities for professional growth within the military technology sector. Located in the UK, we offer competitive benefits, a commitment to safety, and the chance to work with cutting-edge equipment while contributing to the training of military personnel, making your role both meaningful and rewarding.