More than you expected
The UK member firms of Grant Thornton are part of global network of independent audit, tax and advisory firms, made up of some 76,000 in over 150 countries. We're a team of independent thinkers who put quality, inclusion and integrity first. All around the world we bring a different experience to our clients. A better experience. One that delivers the expertise they need in a way that goes beyond. Personal, proactive, and agile. That's Grant Thornton.
Job Description:
Main Responsibilities
The Senior Associate will support with the implementation of the cybersecurity compliance programme, including:
- Collaboration with IT assurance engagement teams across the GT network
- Review of data and evidence obtained in the field, including reviews for completeness, consistency and clarity.
- Evaluate cybersecurity risks and advise on risk mitigation activities.
- Engagement with compliance colleagues, Technology and Business leaders, including the delivery of reporting material and presentations.
- Tracking and coordination of follow up remediation cycles for those firms with findings of non-compliance.
- Drive developments and improvements to the programme for future assessment cycles.
This role will also include broader support to the team such as:
- Respond to firm enquiries and mailbox management.
- Provide advice and guidance on a variety of security topics.
- Develop guides, templates and other material to support the implementation of security standards.
- Research security best practices and provide appropriate reporting.
This role is eligible for either a permanent employee or a two-year secondment agreement with a Grant Thornton member firm resource.
Education / Qualifications
- Bachelor’s degree in IT/Computer Science desirable
- One of or similar to the following is desirable:
- CompTIA Security+ or CASP+
- Associate of (ISC)2
ISO27001 Practitioner
Proven Experience
2 years’ experience in a similar role.
- Prior experience within a security compliance assurance or auditing position.
- Understanding of relevant regulatory requirements and assurance processes, including various auditing standards such as NIST and ISO27001
- Analytical skills to collect, analyse and interpret information and/or data into useful insight
- Excellent communication skills, both verbal and written, with the ability to initiate and lead conversations with senior stakeholders
- Ability to prioritise and manage a varying workload
Experience - Desirable
- Experience with using GRC solutions as part of a risk management programme.
- Understanding of cyber security best practices including knowledge of the general cyber threat landscape and common security controls architecture.
- Due to the global scope of the role, any multi-language capability would be highly desirable.