Information Security Senior Risk Officer in London

Information Security Senior Risk Officer in London

London Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
NTT

At a Glance

  • Tasks: Lead security governance and strategic oversight for major client accounts.
  • Company: Join NTT DATA, a global leader in tech and business services.
  • Benefits: Flexible work options, tailored benefits, and continuous learning opportunities.
  • Other info: Be part of a diverse team committed to equity and professional growth.
  • Why this job: Make a real impact on security and resilience in a dynamic environment.
  • Qualifications: 7+ years in senior security roles with strong governance and risk management experience.

The predicted salary is between 63000 - 77000 £ per year.

The Account Security Director (vCISO) is the senior security leader responsible for security governance, assurance and strategic security oversight across a major client account.

Acting as the primary security interface between the client security organisation, account leadership and service delivery teams, the role ensures security requirements are understood, embedded and effectively managed throughout the service lifecycle. The role provides trusted security leadership, independent challenge and executive-level advice to ensure services remain aligned with business objectives, contractual obligations, organisational policies, regulatory expectations and risk appetite. Through effective stakeholder engagement and influence, the Account Security Director drives security outcomes, operational resilience and continual improvement in security maturity and assurance effectiveness.

Key Responsibilities:

  • Act as the senior security representative for the account.
  • Build trusted relationships with client security, technology, risk, compliance, audit and business stakeholders.
  • Serve as the primary point of contact for strategic security matters across the account.
  • Provide strategic security advice and guidance to client executives, account leadership and delivery teams.
  • Represent security interests within governance, operational, service review and transformation forums.
  • Influence senior stakeholders to support effective risk-based decision making.
  • Act as a trusted advisor on security, resilience, compliance and risk matters.
  • Act as an escalation point for significant security issues affecting the account.
  • Promote a positive security culture across the account and wider delivery organisation.

Governance, Risk, Assurance & Security Oversight:

  • Own, maintain and continually improve the Account Security Management Plan and associated security governance arrangements.
  • Ensure the Security Management Plan remains aligned with client requirements, contractual obligations, organisational policies and industry good practice.
  • Establish and maintain effective security governance and reporting arrangements across the account.
  • Ensure security risks are identified, assessed, communicated and managed in accordance with business objectives and risk appetite.
  • Provide independent oversight and challenge of security controls, assurance activities and risk treatment plans.
  • Provide oversight of security posture, control effectiveness, risks, issues and remediation activities.
  • Challenge decisions, practices or activities that introduce unacceptable levels of security risk.
  • Drive remediation of security risks, audit findings and control weaknesses through to completion.
  • Promote transparency, ownership and continual improvement across the account.
  • Provide strategic security architecture oversight across the account, ensuring security requirements are reflected within technology strategy, solution design and service evolution.
  • Assess the impact of architectural decisions on security risk, operational resilience, compliance obligations and business objectives.
  • Provide independent security challenge to proposed solutions, identifying opportunities to improve security, resilience and risk management outcomes.
  • Support transformation initiatives by providing strategic security guidance and architecture oversight.
  • Ensure security architecture considerations are integrated into service roadmaps and future-state planning.

Regulatory, Contractual and Compliance Oversight:

  • Maintain a strong understanding of applicable regulatory requirements, industry standards and evolving security expectations relevant to the client environment.
  • Develop and maintain effective working relationships with client Risk, Compliance, Legal, Audit and Operational Resilience stakeholders.
  • Provide trusted advice and guidance on the interpretation and application of regulatory, contractual and security requirements.
  • Ensure regulatory, contractual and policy obligations are understood and appropriately reflected within security governance, assurance and service delivery activities.
  • Support organisational readiness for internal audit, external audit, assurance reviews and regulatory engagement activities.
  • Assess the impact of changes in regulatory, legal and industry requirements on the account and advise on appropriate actions.
  • Promote a proactive approach to compliance, ensuring security controls, processes and governance arrangements continue to support regulatory expectations.
  • Provide oversight and challenge to ensure identified compliance risks, findings and remediation activities are effectively managed through to completion.
  • Ensure security governance and assurance arrangements evolve in line with changes in regulation, business strategy, technology and risk.
  • Drive continual improvement in security governance, assurance and risk management practices.
  • Promote adoption of security best practice across account teams.
  • Support the ongoing development of security maturity, operational resilience and assurance effectiveness across the account.

Qualifications:

  • Minimum 7 years' experience in a senior information security leadership, Security Director, CISO or virtual CISO role.
  • Experience developing and leading security governance, risk management and assurance programmes.
  • Experience reviewing and challenging technology, cloud, infrastructure and transformation initiatives from a security, resilience and risk perspective.
  • Security governance, risk management and assurance, including the design and operation of effective governance and reporting frameworks.
  • Security oversight of technology strategy, cloud adoption, infrastructure modernisation and digital transformation programmes.
  • Risk-based decision making, balancing business objectives, regulatory obligations and security requirements.
  • Regulatory compliance and the practical application of security, resilience, outsourcing and third-party risk management requirements.
  • Translation of complex security, technical and regulatory issues into clear business, risk and assurance outcomes.
  • Commercial awareness and an understanding of how security supports business objectives, operational resilience and customer confidence.
  • Strong judgement and decision-making capability in complex business, technology and risk environments.
  • CISSP, CISM, CRISC, CCISO or equivalent recognised senior cyber security qualification.
  • UK Cyber Security Council Professional or equivalent recognised accreditation.
  • Evidence of continuing professional development and industry engagement.

At NTT DATA, you have endless opportunities to think big, act bold and take ownership. We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options.

We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We actively collaborate with individuals who have disabilities and long-term health conditions which have an effect on their ability to do normal daily activities, ensuring that barriers are eliminated when it comes to employment opportunities. In line with our commitment, we guarantee an interview to applicants who declare to us, during the application process, that they have a disability and meet the minimum requirements for the role. Join us in building a truly diverse and empowered team.

Information Security Senior Risk Officer in London employer: NTT

At NTT DATA, we pride ourselves on being an exceptional employer that fosters a dynamic and inclusive work culture. As the Head of Global Treasury, you will lead a talented team in a role that not only offers competitive compensation and benefits but also provides ample opportunities for professional growth and development within a large multinational environment. Our commitment to innovation and excellence ensures that you will be at the forefront of strategic financial initiatives, making a meaningful impact on our global operations.

NTT

Contact Details:

NTT Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Senior Risk Officer in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including NTT, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through NTT

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at NTT. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Information Security Senior Risk Officer in London

Security Governance
Risk Management
Assurance Programmes
Stakeholder Engagement
Regulatory Compliance
Security Architecture Oversight
Decision-Making Skills

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at NTT insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to NTT that you’re committed to staying ahead in the game.

How to prepare for a job interview at NTT

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at NTT to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at NTT.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.