Security Auditor & Risk Assessor
4 days ago
Etwall
AMS is a global workforce solutions partner committed to creating inclusive, dynamic, and future-ready workplaces. We help organisations adapt, grow, and thrive in an ever-evolving world by building, shaping, and optimising diverse talent strategies.\n\nOur Contingent Workforce Solution (CWS) is one way we support our clients. Acting as an extension of their recruitment teams, we connect them with skilled interim and temporary professionals, fostering workplaces where everyone can contribute and succeed.\n\nOn behalf of our globally respected client who develop cutting-edge technologies that deliver clean, safe and competitive solutions to meet the planet's vital power needs we are looking for a Security Auditor & Risk Assessor for a 12 month contract based in Derby.\n\nPlease note this role is hybrid position in which you would be required to work onsite 3 days per week and work from home 2 days per week\n\nPurpose of the role: \nYou will lead and perform independent security audits and risk assessments to identify vulnerabilities, control weaknesses, and policy non-compliance across IT systems, applications, and third-party environments, whilst evaluating risk exposure and partner with stakeholders to develop and implement remediation plans that strengthen the organisation's overall security posture.\n\nWhat you'll do:\n\nReporting into the Security team, you will:\n\nSupport the VP Digital Risk & Compliance in defining and delivering a risk based audit and assessment programme across IT systems, business units, supply chain partners, and third-party providers.\nConduct comprehensive security audits and risk assessments, evaluating control effectiveness, identifying gaps, and assessing risk exposure.\nProduce clear, timely audit and risk assessment reports, including risk ratings and prioritised recommendations.\nDevelop and agree risk treatment and remediation plans with system and business owners to mitigate identified risks.\nAnalyse audit and assessment outputs to identify systemic risks and trends, driving improvements in policy, processes, controls, and technology.\nPresent findings, risk insights, and recommendations to senior stakeholders in a clear and compelling manner.\nSupport the development and enhancement of Information Security policies, standards, and procedures aligned to recognised frameworks (e.g., ISO 27000)The skills you'll need:\n\nStrong understanding of information security principles, risk management, and audit methodologies.\nKnowledge of enterprise IT systems, applications, security practices, security controls and architectures.\nFamiliarity with recognised cyber security frameworks and standards (e.g., ISO 27000, NIST, NIS2, CIS), including their application in audit and risk assessment contexts.\nDesirable but not essential, familiarity with EASA Part-IS regulation and associated requirements.\nAbility to assess and articulate risk clearly, with experience in risk-based decision-making approaches.\nExcellent communication and stakeholder engagement skills, with the ability to influence outcomes.\nBroad IT security knowledge supported by relevant certifications or experience.\nAwareness of cloud technologies and risk considerations in enterprise environments.\nProactive mindset with willingness to learn and contribute to wider compliance domains such as Product Safety, Data Privacy, and Export Control.Desirable Qualifications\n\nDegree or MSc in Information Security (or equivalent)\nCISSP, CISM, CRISC, or equivalent.\nISO 27001 Lead Implementer / Lead Auditor.\nExperience with Microsoft Azure or other cloud platforms.Next steps\n\nWe will only accept workers operating via an Umbrella or PAYE engagement model.\n\nIf you are interested in applying for this position and meet the criteria outlined above, please click the link to apply and we will contact you with an update in due course.\n\nAMS, a Recruitment Process Outsourcing Company, may in the delivery of some of its services be deemed to operate as an Employment Agency or an Employment Business