Key Notes
At least eight years in information-security governance, management and operations plus two recognised security certifications are required. You’ll cover security strategy, risk, compliance, incidents, supplier assurance and continuity for Indra’s TfL mobility programme. The London role requires two on-site days weekly for the first three months, then mainly remote working with up to one on-site day weekly.
What You'll Work On
- Define and monitor information-security strategy, governance, ISMS controls and security plans.
- Lead risk assessment, treatment, incident response, audits and corrective actions.
- Maintain dashboards, policies, continuity testing and compliance with ISO 27001, GDPR, CAF and NIST CSF.
- Assure third parties and new services while building security awareness across the organisation.
Why This Role Matters
- TfL ticketing services handle travel and payment information; security assessments and supplier assurance identify where controls fall short of programme risk and compliance requirements.
- Business-continuity impact assessments and exercises establish recovery needs for the mobility programme, giving service owners evidence to address gaps in incident and recovery arrangements.
What They Are Looking For
- Experience: Applicants need eight-plus years in security governance, management and operations within large, complex organisations.
- Qualification: Applicants need relevant computing or telecommunications degree.
- Experience: Applicants need at least two credentials from CISA, CISM, CRISC, CISSP, ISO 27001, ISO 22301, CEH, CCSP or SSCP.
- Stakeholder: Applicants need strong risk, audit, compliance and stakeholder skills; cloud, AI, OT, GRC or critical-infrastructure experience is useful.