NTT DATA Logo

NTT DATA

GRC Consultant

Posted 6 Days Ago
Be an Early Applicant
In-Office
London, Greater London, England, GBR
Entry level
In-Office
London, Greater London, England, GBR
Entry level
Ensures information security controls are designed, tested, effective, and aligned with business risk. Responsibilities include maintaining ISO-aligned security management systems, conducting risk and supplier assessments, coordinating audits and remediation, managing compliance metrics, supporting incident response, governing security forums, and advising stakeholders on cyber risk, data protection, vulnerabilities, and regulatory requirements.
The summary above was generated by AI

Make an impact with NTT DATA
Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.

Your day at NTT DATA
The GRC Consultant (Cyber Assurance / Security Operations Manager) is primarily responsible for ensuring the security controls (people, process, technology) are in place and operating as designed. The primary aim is the design, development, test and evaluation of information security throughout its lifecycle. This is to ensure the business purpose of the system is enabled in a safe and secure manner based on the alignment of identified risks to the acceptable risk posture of the business.
Looking ahead to future opportunities. As our business continues to grow, we are building a pipeline of exceptional talent for upcoming positions across the UK. This advertisement is intended to identify and engage candidates in advance of specific vacancies becoming available. We encourage you to apply if you would like to be considered for future opportunities that match your expertise.
Key responsibilities:
  • Providing security expertise across security standards and accreditations, measure and control the effectiveness of the security controls framework and maintain the Information Security Management System.
  • Deriving and delivering documented Information Security Management Plans which incorporate Regulatory, Legal and Compliance in relation to applicable security policies. Standards and guidelines
  • Assisting with the identification of identified risks and emerging cyber security vulnerabilities and threats. The subsequent analysis to quantify and lead risk mitigation plans
  • Work with Service Management to ensure that partners and suppliers adhere to agreed standards, policies and verify/evidence appropriate compliance and security KPIs
  • Work closely with 1st, 2nd and 3rd lines of defence on all matters relating to cyber security, information assurance, cyber risk, data privacy including regulatory and compliance considerations
  • Lead the development and enhancement of governance, risk and compliance aligned to policy, standards an industry good practice
  • Ensure that continuous assessment, identification, analysis and reporting of useful metrics to enable informed risk based decisions to be taken 
  • Constructively challenge established processes and controls to identify, recommend and facilitate continuous improvement, ensuring that all personnel (including senior stakeholders) understand their responsibilities in relation to security risk mitigation and remediation
  • Review and verify that documentation relating to process and technical security controls are maintained
  • Develops and maintains Information Security Management practice and process to ensure certification to required industry standards (e.g., ISO 27001) within relevant geographic boundaries.
  • Develops, proposes and seeks sponsorship for changes to policies, procedures and controls to ensure the integrity of the in-scope IT services and effective management and control of information assets. Facilitates the implementation of these controls.
  • Performs focused information risk assessments of existing or new services and technologies, alongside the Operational/Service Management team and technology subject matter experts.
  • As required, will extend the assessment of existing and proposed services to third party suppliers, including the facilitation of IT Security checks during the supplier onboarding and contract lifecycle to ensure coherent approach to risk management
  • Coordinate audit, ITHC and risk assurance activities to evidence compliance with established regulatory and governance requirements including governance of any Remediation Action Plan (RAP)   to ensure timely mitigation of identified risks / vulnerabilities
  • Maintains strong working relationships with individuals and groups involved in managing information risk across the in-scope services and aligned suppliers / 3rd parties 
  • Chairs and co-ordinates the Security Working Group (SWG) and actively participates in supporting/governing forums
  • Contribute to the analysis and mitigation of data protection risks
  • Monitors information security incidents, contributing to incident response and root cause analysis. Will own resulting actions as required where they relate to required changes in IT Security and Information Risk Management policy and controls
  • Security operations and incident response, liaison with internal teams and 3rd party suppliers
To thrive in this role, you need to have:
  • A track record of delivering security solutions for large-scale infrastructure, transformation or integration programmes
  • Practical knowledge and understanding of industry security frameworks and guidance such as NIST CSF, NIST 800-53, NCSC CAF and other NCSC guidelines
  • Good knowledge of networking (switching, routing, firewalls)
  • In-depth knowledge of modern security concepts, common attack vectors, malware, security analytics and threat intelligence.
  • A good understanding of security testing and vulnerability management is important (including pen testing/ITHC, CVSS/CVE)
  • Experience working with security standards such as ISO 27001, 27002, 27017, 27108 etc

DESIRABLE SKILLS AND EXPERIENCE

  • Experience with the design concepts associated with adoption of Cloud platforms (AWS and/or Microsoft Azure)
  • An understanding of the native security capabilities and good practice within Cloud platforms (AWS and/or Microsoft Azure)
  • CISSP, CISM, CCSP, CRISC or equivalent experience
  • Good knowledge covering several of the following examples (this list is not exhaustive): AD (Active Directory), Cryptography, End User Computing, IAM, PKI, Server hardening, SIEM, SOAR, virtualisation (VMware)
  • Familiarity with MITRE ATT&CK
  • Familiarity with ITIL

Workplace type:


About NTT DATA
NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune

Global 100. We are committed to accelerating client success and positively impacting society through

responsible innovation. We are one of the world’s leading AI and digital infrastructure providers, with

unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and

application services. Our consulting and industry solutions help organizations and society move

confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more

than 70 countries. We also offer clients access to a robust ecosystem of innovation centers as well as

established and start-up partners. NTT DATA is part of NTT Group, which invests over $3 billion each

year in R&D.


Equal Opportunity Employer
NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.


Third parties fraudulently posing as NTT DATA recruiters 

NTT DATA recruiters will never ask job seekers or candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties who may attempt to impersonate NTT DATA recruiters whether in writing or by phone in order to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will come from an @nttdata.com email address. If you suspect any fraudulent activity, please contact us.

NTT DATA London, England Office

, United Kingdom, London, United Kingdom, SW1E 5DH

NTT DATA London, England Office

London, United Kingdom

Similar Jobs

17 Days Ago
Hybrid
London, Greater London, England, GBR
Senior level
Senior level
Software
Serve as a customer-facing technical partner in pre-sales, leading discovery, solution validation, tailored demonstrations, integration assessment, deal strategy, trial support, and post-sale handoffs. Demonstrate how Vanta automates GRC programs across SOC 2, ISO 27001, and HIPAA frameworks. Collaborate with Account Executives, customers, Product, and post-sales teams while providing market feedback and shaping solutions.
Top Skills: AWSBashCloud Application ArchitectureGCPJavaScriptLinuxmacOSAzurePythonRest ApisRubyWindows
21 Days Ago
Hybrid
London, Greater London, England, GBR
Senior level
Senior level
Software
Serve as the technical lead in pre-sales for DACH customers: assess technical fit, support trials, design solutions and integrations, create product examples/documentation, provide product and market feedback, and improve pre- to post-sales transitions.
Top Skills: AWSBashCloud Application ArchitectureGCPJavaScriptLinuxmacOSAzurePythonRest ApiRubyWindows
4 Hours Ago
Hybrid
City of London, City and County of the City of London, England, GBR
Senior level
Senior level
Fintech • Financial Services
Leads engineering managers and experienced engineers building and operating front-office trading platforms for structured products, credit trading, and municipal bonds. Drives architecture, modernization, cloud readiness, security, scalability, DevOps, delivery, and operational stability. Partners with product leaders, architects, vendors, and stakeholders to prioritize roadmaps, resolve technical impediments, manage risk, and meet regulatory requirements. Oversees hiring, talent development, performance management, and financial and resource allocation.
Top Skills: .NetAngularC#Ci/Cd PipelinesClaude CodeCloud PlatformsCursorDevOpsEvent-Driven ArchitecturesGithub CopilotJavaMicroservicesReactRest ApisSpring Boot

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account