×
Register Here to Apply for Jobs or Post Jobs. X

GRC Consultant

Job in London, Greater London, W1B, England, UK
Listing for: The Nippon Telegraph And Telephone Corporation (NTT)
Full Time position
Listed on 2026-09-03
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Job Description & How to Apply Below
Make an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.

Your day at NTT DATAThe GRC Consultant (Cyber Assurance / Security Operations Manager) is primarily responsible for ensuring the security controls (people, process, technology) are in place and operating as designed. The primary aim is the design, development, test and evaluation of information security throughout its lifecycle. This is to ensure the business purpose of the system is enabled in a safe and secure manner based on the alignment of identified risks to the acceptable risk posture of the business.

Looking ahead to future opportunities. As our business continues to grow, we are building a pipeline of exceptional talent for upcoming positions across the UK. This advertisement is intended to identify and engage candidates in advance of specific vacancies becoming available. We encourage you to apply if you would like to be considered for future opportunities that match your expertise.

Key responsibilities:

Providing security expertise across security standards and accreditations, measure and control the effectiveness of the security controls framework and maintain the Information Security Management System.

Deriving and delivering documented Information Security Management Plans which incorporate Regulatory, Legal and Compliance in relation to applicable security policies. Standards and guidelines

Assisting with the identification of identified risks and emerging cyber security vulnerabilities and threats. The subsequent analysis to quantify and lead risk mitigation plans

Work with Service Management to ensure that partners and suppliers adhere to agreed standards, policies and verify/evidence appropriate compliance and security KPIsWork closely with 1st, 2nd and 3rd lines of defence on all matters relating to cyber security, information assurance, cyber risk, data privacy including regulatory and compliance considerations

Lead the development and enhancement of governance, risk and compliance aligned to policy, standards an industry good practice

Ensure that continuous assessment, identification, analysis and reporting of useful metrics to enable informed risk based decisions to be taken Constructively challenge established processes and controls to identify, recommend and facilitate continuous improvement, ensuring that all personnel (including senior stakeholders) understand their responsibilities in relation to security risk mitigation and remediation

Review and verify that documentation relating to process and technical security controls are maintained

Develops and maintains Information Security Management practice and process to ensure certification to required industry standards (e.g., ISO 27001) within relevant geographic boundaries.

Develops, proposes and seeks sponsorship for changes to policies, procedures and controls to ensure the integrity of the in-scope IT services and effective management and control of information assets. Facilitates the implementation of these controls.

Performs focused information risk assessments of existing or new services and technologies, alongside the Operational/Service Management team and technology subject matter experts.

As required, will extend the assessment of existing and proposed services to third party suppliers, including the facilitation of IT Security checks during the supplier onboarding and contract lifecycle to ensure coherent approach to risk management

Coordinate audit, ITHC and risk assurance activities to evidence compliance with established regulatory and governance requirements including governance of any Remediation Action Plan (RAP)   to ensure timely mitigation of identified risks / vulnerabilities

Maintains strong working relationships with individuals and groups involved in managing information risk across the in-scope services and aligned suppliers / 3rd parties Chairs and co-ordinates the Security Working Group (SWG) and actively participates in supporting/governing forums

Contribute to the analysis and mitigation of data protection risks

Monitors information security incidents, contributing to incident response and root cause analysis. Will own resulting actions as required where they relate to required changes in IT Security and Information Risk Management policy and controls

Security operations and incident response, liaison with internal teams and 3rd party suppliers

To thrive in this role, you need to have:

A track record of delivering security solutions for large-scale infrastructure, transformation or integration programmes

Practical knowledge and understanding of industry security frameworks and guidance such as NIST CSF, NIST 800-53, NCSC CAF and other NCSC guidelines

Good knowledge of networking (switching, routing,…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary