Information Security Consultant

hace 16 horas


Barcelona, España Advantio A tiempo completo

Advantio is a leading Cyber Security and Managed Security Services (MSS) provider that helps businesses fight Cybercrime, protect data and reduce security risk. Offering a comprehensive portfolio of Cyber Security Advisory & Testing Services, Managed Security Services, Technology Solutions and Cyber Security Education, Advantio is the security partner of choice for many large corporate enterprises globally covering a wide range of industries including but not limited to banking, insurance, gambling, travel, retail, telco, oil & gas and public sector bodies. Advantio primarily serves the Payment Card Industry and when it comes to payment transactions, has been recognised by VISA as one of Europe’s top Qualified Security Assessor (QSA) providers.

*
Role*

Due to our continued expansion we now have an immediate opening for a **_Security Consultant_** in Europe*
Mission: to lead Cyber Security Consultancy engagements with clients and customer within financial services and payment card industries. Focusing on delivery of PCI DSS and/or PA-DSS Information Security compliance assessments, Cyber Security Maturity Assessments and ISO27001 engagements.

*
Responsibilities*

Main:

- Lead customer engagements and provide senior cyber security advice and services to a broad range of clients and industries.
- Provide detailed analytical reporting, internal reporting metrics and program management.
- Provide leadership and mentorship to Junior consultants.

Preliminary Analysis:

- Identifying all the stakeholders, sponsors, technical references (e.g. IT Project Manager, Software Engineer, Security Analyst) of the client in order to define the initial conditions and the needs analysis

Gap Analysis and Scoping
- Review of all locations and flows of cardholder data, as well as asset inventories
- Conducting PCI standards interviews to have a complete map of information/data workflows, processes and procedures, payment card data flow, information security controls
- Conducting technical interviews to understand eventual data security problems from in-depth technical point of view
- Producing Scoping and Gap Analysis Documentation

Remediation
- Providing the customer with a remediation plan/gap report
- Guiding and supporting all the remediation processes ensuring that the gaps are mitigated correctly

Formal Assessment
- Conducting technical interviews to understand eventual data security problems from in-depth technical point of view
- Analysis of network diagrams, asset lists to understand the infrastructure used by the customers

Documentation
- Preparation, validation and approval Reports on Compliance (RoC) and/or Reports of Validation (RoV) according to the standard templates provided by PCI SSC
- Preparation, validation and approval of Attestation of Compliance (AoC) and/or Attestation of Validation (AoV) according to the standard templates provided by PCI SSC
- Submission all the documentation to PCI SSC for the final approval in case of PA-DSS process (signed RoV, AoV, Implementation Guide and Vendor Release Agreement)

**Knowledge and Skills (Security Consultant)**
- Information Security Experience
- PCI DSS (PA-DSS, P2PE, PCI 3DS), GDPR
- Virtualization
- Cloud technologies
- Authentication methods and techniques
- Integrity controls
- Networking
- Operating Systems (Linux/Unix, Windows)
- Italian and English fluency

**Values and Competencies**
- Problem Solving (analysis, helicopter view, problem setting, decision making)
- Planning and Organization (time management, scheduling and control)
- Communication (clearness, listening, persuasion)
- Networking (reinforce relationships, use emotional intelligence and personal proximity)
- Results Orientation (delivering solutions, work under pressures

**Advantio Core Values**
- Harmony, always strive to create harmony
- Openness, always be open
- Social Responsibility, be socially responsible
- Timeless, whatever you build make it timeless
- Accommodating, make our customers feel at Home
- Learning, be a Learn it all
- Deliver, Results



  • Barcelona, España Eurofins A tiempo completo

    Company Description Eurofins Scientific is an international life sciences company which provides a unique range of analytical testing services to clients across multiple industries. The Group believes it is the world leader in food, environment and pharmaceutical products testing and in agroscience CRO services. It is also one of the global independent...


  • Barcelona, Barcelona, España NTT DATA, Inc. A tiempo completo

    Make an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive.Your day at NTT DATAThe Security...


  • Barcelona, España Wise Security Global A tiempo completo

    **What are we looking for?**: Technical education (Bachelor's degree in Computer Science, a related field, or equivalent) will be necessary. High level of English and Spanish will be necessary. Specific experience required: - Designing security governance and compliance projects. - Analyzing, designing and implementing Information Security Management...


  • Barcelona, España Advantio A tiempo completo

    **About Advantio** Established in 2009, Advantio maintains an extensive team of consultants and security testing experts to provide digital security and assurance to its customers. Originally established as a payment compliance market leader, Advantio has grown from an established and leading payment security and compliance organisation in Europe to develop...


  • Barcelona, España NTT DATA A tiempo completo

    **Make an impact with NTT DATA** Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion - it’s a place where you can grow, belong and thrive. **Your day at NTT DATA** This...


  • Barcelona, España Eurofins A tiempo completo

    Company Description **_ Why are we here?_** Eurofins Scientific is an international life sciences company, providing a unique range of analytical testing services to clients across multiple industries, to make life and our environment safer, healthier and more sustainable. From the food you eat, to the water you drink, to the medicines you rely on, Eurofins...


  • Barcelona, España Play'n GO A tiempo completo

    **Job title**:Information Security Manager **Job Details** **Hours**:Full Time **Location**:Fully remote. This opportunity is open to you if you can legally work remotely from the Philippines. **Contract**:Permanent At Play’n GO we enjoy a flexible freedom to shape our own days. Everyone we hire is unique and every role we fill has certain performance...


  • Barcelona, España Zurich Insurance A tiempo completo

    **Our opportunity** The role of Information Security Analyst sits in the Information Security Governance team within Group Cyber Security. This role has a global footprint and is intended to support security assurance of strategic suppliers, group security technologies and other security related internal controls. Information Security Governance is a...


  • barcelona, España SQUAD - Cabinet de conseils et d’expertises A tiempo completo

    Information Security Advisor – Barcelona Since 2011, SQUAD Group has been a key player in the cybersecurity landscape. We partner with leading organizations to protect their information systems through a comprehensive 360° offering of consulting, integration, expertise, and managed services. Our mission: Securing Together! We believe in a collaborative...


  • Barcelona, España Allianz Insurance A tiempo completo

    Allianz Services, as part of Allianz Technology, provides essential services under the Digital Resilience as a Service model, supporting the global Protection & Resilience Service Line. These services enhance the Group's capability to manage information and cyber security risks, ensure regulatory compliance, and maintain operational integrity across all...