Information Security Office Consultant - Business Functions
Job Details
Cyber security is an integral part of our culture, and as an industry leader within financial services, it is vital that we all play our part in keeping customers’ data secure. We see security as an enabler and differentiator to enable business innovation and growth, rather than a step in a compliance process.
This role sits in our UK ISO (Information Security Office) team, and will work to embed a positive security culture and to ensure that security risks are properly understood and managed. Working both internally across UK Cyber, and with the wider business, this position will play a key role in solving business problems within cyber guard rails and building pragmatic security controls into our day to day operational processes.
You will also work with technical subject matter experts within our Advisory ISO team to ensure that we communicate technical information in accessible terms for business audiences, including senior management. This is a key part of our drive to communicate a consistent data-driven, risk-based set of priorities and updates.
What you will do:
Engage with business functions, projects and activities to ensure that key business processes deliver security balanced with ease of use - making the secure way the easy way to operate.
Provide a forward-looking view to Cyber of business activities which affect current understanding of cyber risk, and update business functions on relevant Cyber projects.
Provide cyber consultancy to business stakeholders and UK Cyber teams.
Support work to increase awareness of cyber risk across key business stakeholders.
Review existing processes to identify cyber risks, and propose any required mitigating work.
Assess compliance with Cyber policies and standards.
Work with Advisory ISO colleagues to ensure that we present consistent, compelling narratives on risks associated with cyber vulnerabilities.
What we are looking for
Practical experience of working in or leading components of a structured security programme, working with business teams to identify and manage cyber risk.
Demonstrable experience in cyber risk analysis, assessment and mitigation.
Experience in a financial or highly regulated environment.
A detailed understanding of ISO 27001, ITIL, COBIT, PCI DSS and NIST Cyber Security Frameworks.
Working knowledge of GDPR.
Relevant security certifications such as CISSP, CISM, CISA, CRISC, ISEB Certificate in Information Security Management Principles.
Effective written and verbal communication skills.
Where and how you'll work
This is a permanent position and can be based in our Nottingham Head Office.
Our hybrid working model offers you the flexibility to work from our offices and from home, when you need to.
We're big on collaboration and connection, and so generally encourage our associates to use our offices on Tuesdays, Wednesdays and Thursdays.
The number of days you spend in the office will usually be led by the type of work you’re doing, and the hybrid working patterns of the people you partner most closely with.
Many of our associates have flexible working arrangements, and we're open to talking about an arrangement that works for you.
What’s in it for you
Bring us all this - and you’ll be well rewarded with a role contributing to the roadmap of an organisation committed to transformation
We offer high performers strong and diverse career progression, investing heavily in developing great people through our Capital One University training programmes (and appropriate external providers)
Immediate access to our core benefits including pension scheme, bonus, generous holiday entitlement and private medical insurance – with flexible benefits available including season-ticket loans, cycle to work scheme and enhanced parental leave
Open-plan workspaces and accessible facilities designed to inspire and support you. Our Nottingham head-office has a fully-serviced gym, subsidised restaurant, mindfulness and music rooms. In London, you can heighten your mood with a run on our rooftop running track or an espresso at the Workshop Coffee café
What you should know about how we recruit
We pride ourselves on hiring the best people, not the same people. Building diverse and inclusive teams is the right thing to do and the smart thing to do. We want to work with top talent: whoever you are, whatever you look like, wherever you come from. We know it’s about what you do, not just what you say. That’s why we make our recruitment process fair and accessible. And we offer benefits that attract people at all ages and stages.
We also partner with organisations including the Women in Finance and Race At Work Charters, Stonewall and upReach to find people from every walk of life and help them thrive with us. We have a whole host of internal networks and support groups you could be involved in, to name a few:
REACH – Race Equality and Culture Heritage group focuses on representation, retention and engagement for associates from minority ethnic groups and allies
OutFront – to provide LGBTQ+ support for all associates
Mind Your Mind – signposting support and promoting positive mental wellbeing for all
Women in Tech – promoting an inclusive environment in tech
EmpowHER - network of female associates and allies focusing on developing future leaders, particularly for female talent in our industry
If you require a reasonable adjustment, please contact ukrecruitment@capitalone.com All information will be kept confidential and will only be used for the purpose of applying a reasonable adjustment.
For technical support or questions about Capital One's recruiting process, please send an email to Careers@capitalone.com
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
Who We Are
At Capital One, we're building a leading information-based technology company. Still founder-led by Chairman and Chief Executive Officer Richard Fairbank, Capital One is on a mission to help our customers succeed by bringing ingenuity, simplicity, and humanity to banking. We measure our efforts by the success our customers enjoy and the advocacy they exhibit. We are succeeding because they are succeeding.
Guided by our shared values, we thrive in an environment where collaboration and openness are valued. We believe that innovation is powered by perspective and that teamwork and respect for each other lead to superior results. We elevate each other and obsess about doing the right thing. Our associates serve with humility and a deep respect for their responsibility in helping our customers achieve their goals and realize their dreams. Together, we are on a quest to change banking for good.
Sign up for job alerts
Don’t see a role that’s right for you? Don’t fret. You can sign up for our job alerts and we’ll make sure to let you know when the right one comes up.