Apply Edge Start your job search

Senior Security Consultant

Indra Group UK & Ireland · London, England, United Kingdom

Apply & track with Apply Edge
About Indra Group UK & IrelandIndra is a leading global technology and consulting company, and a trusted technological partner for the core business operations of its clients worldwide. It stands at the forefront of key sectors including Transport, Defence, Air Traffic Management and Space, alongside advanced Information Technology services delivered through Minsait, and cutting-edge capabilities in Sovereign AI, Cybersecurity, and Cyberdefence via IndraMind.The company's business model is built around a comprehensive portfolio of proprietary products, combining strong innovation with a high-value focus for customers.With more than 2,500 projects implemented across 50 countries and over 100 cities, Indra is a global benchmark in innovative transportation and mobility solutions. It is recognised as one of the world's top three companies in public transportation management systems. Indra's technology supports the daily journeys of over 78 million people, helping to reduce more than 10 million tonnes of CO₂ emissions annually, and helping save nearly 3,000 lives through improved traffic management and road safety.Indra Group is paving the way to a more secure and better-connected future through innovative solutions, trusted relationships and the very best talent. Sustainability sits at the heart of its strategy and culture, driving efforts to address current and future social and environmental challenges.In the 2024 financial year, Indra achieved revenues of €5.5 billion, over 60,000 professionals, maintained a local presence in 46 countries, and operated across more than 140 countries worldwide.As the technological partner for its customers' key operations, Indra is at the core of their business, and Indra's four values guide everything we do:Innovation - Our capacity for innovation, cutting-edge solutions, and specialised team of professionals enables us to drive a safer, more connected future through technology.Trust - We work with strength, commitment, and reliability, delivering quality solutions to build trust with customers, employees, partners, investors, and society.Connection - We harness the power of collaboration, connect ideas and solutions, and adapt to our customers' needs, supporting them on the path to a better future.Foresight - We anticipate future needs to make the world safer and more connected, transforming our experience and knowledge into solutions for a better tomorrow.About The ProjectTransport for London (TfL) has awarded Indra a long-term contract to operate, develop, enhance and expand ticketing and access control systems across London's transport network through to 2034, with extension options to 2039.This programme covers the maintenance, operation and evolution of a large-scale, complex ecosystem, including turnstiles, validators, ticket machines, sales terminals, back-office systems, payment gateways, IT infrastructure and cybersecurity that supports over 8.6 million daily journeys.Therefore, Indra will become TfL's strategic technology partner to guarantee the operation and evolution of the world's largest and most sophisticated ticketing system. Following a transition period of approximately two years, Indra will serve as the sole provider across the network that includes more than 8,500 buses, nearly 400 Underground stations, around 300 rail stations (Overground, DLR, Elizabeth Line and suburban services), 4,000 Oyster Card outlets, seven customer service centres, and 24 river boat boarding points.Drawing on over 30 years of experience in urban public transport solutions, Indra will manage and evolve all aspects of the system. The project also envisages, in partnership with TfL, the implementation of new technologies to develop the system, make it more efficient and automate key processes; in short, to jointly create the next generation of the ticketing system for London.Role OverviewThe Senior Security Consultant plays a pivotal role in shaping and executing the organisation's information security strategy, governance and risk management activities to protect services, systems and data. The role is responsible for implementing security frameworks, leading risk and incident management, ensuring regulatory compliance, managing third‑party security, and driving continuous improvement through monitoring, reporting and awareness initiatives.Key ResponsibilitiesDefine, implement and monitor corporate information security strategies, objectives and governance frameworksDesign and implement information security management systems and security master plansLead risk management activities, including risk identification, assessment, treatment and reportingDefine cybersecurity action plans and oversee their executionEnsure the protection of services, business processes and information assetsOversee security monitoring, incident investigation and response activities, including coordination of disciplinary or legal actions where requiredManage and coordinate independent security audits and remediation follow-up activitiesDrive continuous improvement by monitoring security performance, reporting on security posture and defining corrective actionsDevelop and manage dashboards and metrics for operational security reportingSupport business continuity by performing business impact analyses and defining continuity and testing plansImplement and maintain information security controls aligned with applicable laws, regulations, standards and best practices, including ISO 27001/27002, GDPR, Cyber Assessment Framework (CAF) and NIST CSFDevelop and maintain information security policies, standards and procedures, ensuring organisational complianceDefine, coordinate and assess the implementation of specific security controls for new systems and servicesManage supplier and third-party security, including supply chain security considerationsDeliver security awareness and training initiatives to promote a strong security culture across the organisationWorking model:First 3 months: 2 days onsite per weekThereafter: fully remote with a maximum of 0-1 day onsite (as required)RequirementsKey RequirementsMinimum of 8 years' experience in information security governance, management and operations, including the delivery of security projects in large and complex organisationsBachelor's or Master's degree in Computer Engineering, Telecommunications Engineering or a related disciplineAdditional Required QualificationsAt least two of the following certifications: CISA, CISM, CRISC, CISSP, ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, ISO 22301 Lead Auditor, CEH, CCSP or SSCPWillingness to travel when requiredDesirable QualificationsExperience in the design and implementation of other management systems, such as ISO 27701, ISO 22301, ISO 20000, ISO 9001 and ISO 14001Knowledge of security in cloud environments, artificial intelligence, industrial control systems (ICS), operational technology (OT) and the Internet of Things (IoT)Knowledge of physical security principles and controlsExperience with GRC tools such as ARCHER, GlobalSuite or similar platformsPreferred ExperienceExperience performing compliance and certification audits, including ISO 27001 and GDPRHands-on exposure to technical security solutions and controlsKnowledge of sector-specific regulatory and security frameworks in areas such as banking, energy, telecommunications and media, industrial protection, and critical infrastructure protectionKnowledge of SOC operations, digital forensics and fraud managementExperience with GRC / IRM platforms and the automation of security and compliance processesAdditional security certifications such as CGEIT, C|CISO, QSA, CDPP, or Security Director certification issued by the Spanish Ministry of the InteriorCore CompetenciesStrong analytical and problem-solving skillsCollaborative mindset and ability to work effectively in multidisciplinary teamsCapacity for continuous learning, innovation and adaptationProactive approach with a strong sense of ownership and initiativeHigh level of integrity, accountability, commitment and professional confidenceStrong customer focus and results orientationBenefitsHolidays: 25 days per annum + 8 days bank holidays (options to buy/sell days)Pension - 4% employee and 4% employerPrivate medical insurance (including dental & optical)Life assuranceIncome protectionEmployee assistance programsFlexible/remote working optionsCharitable initiativesSocial events (formal & informal)Learning and development programsInnovative & collaborative work environmentIndra is an equal employment opportunity employer. Applicants are considered without regard to race, colour, religion, sex, sexual orientation, gender identity, origin, disability or other characteristics protected by law.