[SJ-JOB] MOD CLAS Consultant, London

[email protected] 22 Oct 2008 20:51:46 -0000
Newsgroups gmane.comp.security.jobs
Message-ID <[email protected]>
---------------------------------------------------
SECURITYFOCUS JOBS - NEW OPPORTUNITY
---------------------------------------------------


JOB DESCRIPTION
---------------------------------------------------
Position:       MOD CLAS Consultant
Location:       London, , United Kingdom
Type:           Permanent F/T

Closing Date:   2008-11-10

Senior Security Solution Architect=0D
Reference No. SF-328  =0D
Company Global Consulting Organisation  =0D
Location London  =0D
Salary &pound;40,000 - &pound;66,000  =0D
Package Bonus, car and benefits scheme  =0D
Start Date ASAP  =0D
No. Required 1  =0D
=0D
The Role  =0D
The role holder will be a current and qualified CLAS Consultant, working =
on an assignment basis in the government or commercial sector and will ac=
t as the Chief Security Officer for and the FLEX account. =0D
The successful candidate must be willing to travel across the UK and Euro=
pe as required.=0D
This is an influential and essential position; the successful applicant w=
ill have extensive operational and practical experience of IT service pro=
vision, a considerable amount of which will have been in a security role.=
 =0D
SC/DV clearance is desirable however if the individual does not have such=
 clearance they will be subject to the clearance process as clearance is =
essential for the individual to be able to fulfil this role=0D
The role holder&#146;s initial assignment will be that of a CLAS Consulta=
nt on the FLEX Account, based out of London.=0D
This role is essential to representing the project&#146;s security requir=
ements and standards in the design forums for developing FLEX and produci=
ng security designs for security enforcing components of the infrastructu=
re. =0D
The role holder will be directly involved in design and development of se=
curity components for the FLEX Account and for ensuring the appropriate c=
ompliance standards e.g. CESG InfoSec IS1 and IS2 are considered in any d=
esign work conducted by the programme. =0D
Initial Assignment Summary:=0D
General=0D
The role holder:=0D
May manage a small/medium design team. =0D
Will be a competent design authority on larger or more complex solutions,=
 demonstrating an understanding of the customer&#146;s business and comme=
rcial issues=0D
Will identify, design and deliver larger or more complex architectures, s=
trategies and specific solutions.=0D
Context=0D
Will have a successful track record of delivery, and broad understanding =
of technology and how it is applied. =0D
Be responsible for complex projects which involve solutions which require=
 an element of integration, migration, creation of innovative solutions a=
nd management of risk through appropriate re-use. =0D
Will deal with key customer decision makers such as IT Directors, Program=
me Managers, and Partners. =0D
Dimensions=0D
The role holder may be assigned to a range of projects and will be capabl=
e of:=0D
Leading on projects of &pound;1m &#150; 20m. =0D
Managing and leading teams of up to 10 people. =0D
Liaising with IT Directors/CIO of companies with an IT budget of up to &p=
ound;200m. =0D
Technically vetting bids of up to &pound;20m.=0D
Reporting Relationships=0D
The role holder will work as part of a virtual management team, and will =
report into a number of people including business line managers, and proj=
ect owner/activity leaders.=0D
Job Purpose & Accountability: =0D
Authority =0D
The role holder will:=0D
Have complete responsibility for security input to appropriate qualificat=
ion and business approval meetings for the design of larger and more comp=
lex solutions. =0D
Shape proposals to be commercially acceptable to the customer and may mak=
e solution and service trade-offs as approved by the relevant account/bid=
/capability teams=0D
Cost and risk =0D
The role holder will:=0D
Define the approach to larger and more complex solution development and a=
cceptance testing, controlling technical scope and the work of the design=
 team to ensure an acceptable cost structure. =0D
Be able to identify and manage risk in accordance with relevant approved =
process and procedures=0D
Influence =0D
The role holder will, where relevant, represent the Consultancy at custom=
er forums, conferences, professional bodies to build their reputation in =
the market place=0D
Business development =0D
The role holder will establish customer requirements for a solution by bu=
ilding strong relationships Requirements and design =0D
The role holder will contribute to the definition of customers overall se=
curity architecture, designing new solutions of appropriate size and comp=
lexity, and will manage the work of specialists contributing to the desig=
n and implementation of the solution.=0D
Managing relationships =0D
When appropriate, the role holder will effectively influence at board lev=
el to achieve national recognition =0D
Knowledge re-use =0D
The role holder will share knowledge with colleagues to make a useful con=
tribution to the Consultancies knowledge and to drive the continual need =
for reuse. =0D
Skills - Mandatory: =0D
Customer facing skills and be capable of holding meaningful and supportiv=
e meetings with the customer.=0D
Proven communication and consulting skills=0D
Demonstrable technical leadership expertise=0D
Customer and business orientation, with sound commercial and financial aw=
areness =0D
Effective working relationships with both customers&#146; senior manageme=
nt =0D
The ability to write accurate, clear and concise documents.=0D
Evidence of having delivered successful security solutions on very large =
projects=0D
Experience of security in UK Central Government=0D
Status as a current and qualified CLAS Consultant. =0D
An in-depth understanding of CESG documents and compliance standards e.g.=
 InfoSec IS1 and IS2.=0D
The ability to produce RMADS capable of being approved by the relevant ac=
creditor.=0D
A thorough understanding of IS27001 and other relevant security standards=
=0D
A working knowledge of security legislation e.g. DPA, SOX & FOI.=0D
A general understanding of current security services and technologies =0D
=0D
Specifically the CSO will:=0D
Monitor all aspects of the service to ensure conformance to the security =
policy.=0D
Oversee the day to day operation of the systems, including that of the se=
curity and audit mechanisms.=0D
Manage the security team, set priorities, and prepare plans, forecasts an=
d reports.=0D
Develop cost-effective, pragmatic standard policies and provide clear sta=
tements of the consequence of non-compliance; these standard policies wil=
l support the business of new departments in areas such as the support of=
 3rd-party applications.=0D
Liaise with potential FLEX customers to discuss implications of security =
requirements.=0D
Lead the security working group to shape the &#147;back-end&#148; service=
s and agree acceptable pragmatic solutions with the customer and accredit=
or.=0D
Provide Operational Security input to Change Proposals and Requests for S=
ervice=0D
Be the point of contact for security related matters, e.g. incident repor=
ting.=0D
Co-ordinate response to alerts.=0D
Liaise with clients and local management unit representatives =0D
Liaise with security management within the Consultancy and other organisa=
tions delivering services to the account.=0D
Monitor security through the lifecycle of systems and applications.=0D
Raise security awareness.=0D
Investigate security incidents =0D
Manage alerts when security events occur and escalate as necessary=0D
Manage the production of security work instructions.=0D
Manage system security administration tasks in accordance with security o=
perating procedures and work instructions.=0D
Manage the production, maintenance and compliance of all account security=
 related processes and procedures.=0D
Skills - Useful: =0D
Industry certification in security technologies such as networking/firewa=
lls/Windows/CISSP/IISP =0D
Working knowledge of CRAMM or other risk assessment skills.=0D
ISO27001 audit qualification=0D
Project management skills=0D
Working knowledge of CRAMM=0D
Skills - on the Job: =0D
Be a self starter able to work on their own initiative.=0D
Have excellent analytical and communication skills.=0D
Be able to deal with, and influence senior internal and external customer=
s.=0D
Have technical report writing skills.=0D
Have strong presentation and facilitation skills=0D
Understand global strategies and methodologies.=0D
Belong to the Technical and Architecture Professional Community (TAC) and=
 will follow TAC development activities.=0D
Manage people as appropriate.


JOB REQUIREMENTS
---------------------------------------------------
Please note that in order to apply for any vacancy in the UK, you will ne=
ed either a valid EC Passport or valid Work Permit enabling you to work i=
n the UK.


CONTACT
---------------------------------------------------
www.informationsecuritysolutions.com/jobs/ref328 =20

Information Security Solutions
Iain Sutherland

[email protected]



---------------------------------------------------
SECURITYFOCUS JOBS
---------------------------------------------------
SecurityFocus now offers an online interface for
searching and managing job opportunities and resumes.

http://www.securityfocus.com/jobs