WSPβs Information Security Office (ISO) is responsible for the deployment of the information security framework in to both the IT organisation and wider business community. This includes the Governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our clients.
The role of Regional Information Security Officer is a business facing role, though it may involve some interaction with clients and third parties. The role has a dual reporting relationship to the BISO and to the regional ITBP.
This position requires a senior management professional with relevant experience and a strong working knowledge of IT security, risk management, regulatory compliance, information and public cloud service technology, IT operations management principles, and third-party contract management.
Responsibilities:
-
Working directly with business leadership within region and at all levels of the organisation to deliver an effective, world class information security program.
-
Establish and maintain the Information Security Governance framework; including running the regional Information Security Committee; coordinating IS risk management, executive reporting and participate in other forums where information security input and approval is required based on documented policies and processes.
-
Implementing and Operating the ISO270001 aligned Data and Information Security Management System in region.
-
Enhancing the security culture within region, driving business change initiatives and owning security e-learning.
-
Developing and maintaining an understanding of regional IS requirements, including client and regulatory/legal requirements. Working with key stakeholders, including the Head of Legal and business leads to provide input and security assurance for new bids and acquisitions.
-
Working with corporate and regional IT teams and providing security guidance for new IT projects in region (working with the Security Architect function where needed)
-
Liaise with the relevant regional functions β Risk Management, Commercial, HR, Legal, Compliance, Procurement, Facilities / Physical Security - to ensure IS coordination and risk management in region.
-
The management and co-ordination of any security incident response within region.
-
Provide SME and guidance to their region on any security needs or requirements. Act as an advisor to their regional ITBP on all information security related matters.
-
Work with the BISO and ISO on the Global Information Security Framework; contributing to the development of new processes, identifying and resolving risks and providing regular reports on security matters and metrics.
Leadership and People Responsibilities:
-
Displays leadership and independence in performing their role, with an ability to make complex decisions with limited input and review from senior staff.
-
High level of personal integrity, and the ability to professionally handle confidential matters and exude the appropriate level of judgment and maturity.
-
Assist in the training, and coaching of new and existing staff, and provide coaching to staff executing all aspects of information security and risk assessment and support. Manage the process of translating into any local languages.
-
Develop positive working relationships with other team members and business partners and partner across teams to align with WSP internal and external client demands
-
Capable of rapidly assimilating and internalizing complex business, technology, and risk management concepts and dependencies
-
Capable of clearly defining, presenting and selling recommended strategies to senior management teams
-
Critical thinker with strong problem-solving skills, project management skills; financial/budget management, scheduling and resource management.
-
Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate between specialized groups of business unit and IT professionals
-
Accommodation of schedule for international conference calls
Finance/Budgetary Responsibilities:
- Support the BISO / ITBP in developing the budget projections based on objectives
Requirements:
-
8+ years related senior level experience in Information Security, IT risk, IT Audit or a similar position involving IT and business change
-
Graduate of a four-year college or university, preferably with a degree in computer science or information management
-
Professional certification in one or more of the following disciplines β IT governance (e.g., CGEIT), security (e.g., CISSP, CISM), internal audit (CISA) or Payment Card Industry (PCI)
-
Working (not necessarily technical) knowledge of security technologies (encryption, data protection, network intrusion prevention, host intrusion prevention, firewalls, privilege access, etc.)
-
Working (not necessarily technical) knowledge of enterprise IT security concerns and technologies, including but not limited to VPNs, network security, encryption, authentication, application-level network protocols, PKI, IPSec, Firewall, SSH, SSL, DES, LAN/WAN, and TCP/IP
Work on landmark projects around the world and embrace opportunities to make an even bigger impact in the communities you care about. What if you could do the
With us, you can. Apply today.
Regional Information Security Officer (RISO) β UK & South Africa in London employer: WSP
WSP is an exceptional employer that fosters a collaborative and innovative work culture, providing employees with the opportunity to lead impactful projects in urban drainage and wastewater modelling. With a strong focus on professional development, our team members benefit from extensive training and growth opportunities, all while working in a hybrid environment that promotes work-life balance. Located across the UK, we offer a dynamic workplace where your contributions directly influence local and national infrastructure solutions.