NTT DATA
Security Consultant - Operational Security & GRC

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Security Consultant / Operational Security & GRC
Hybrid variable London or Birmingham
The team that you’ll be working with:
NTT DATA is one of the world’s largest global security service providers, partnering with some of the most recognized security technology brands. We’re looking for passionate, curious, and motivated individuals to join our team.
What you'll be doing:
Working in a client-facing consultancy role, you will provide operational security management, oversight and GRC advisory services. You will help clients translate business, threat and regulatory requirements into practical operational risk decisions and security improvements.
- Security governance and oversight: Establish, operate and improve proportionate security governance, policies, standards, control frameworks, decision forums and reporting. Provide independent oversight of security performance, control ownership, risk treatment and remediation.
- Operational security management: Oversee day-to-day security risks across technology and service environments, ensuring that vulnerabilities, threats, alerts, incidents and control weaknesses are assessed, prioritised, assigned and progressed to closure.
- Vulnerability and exposure oversight: Review vulnerability and security testing outputs, challenge prioritisation using asset criticality, exploitability, threat intelligence and business impact, and monitor remediation, exceptions and risk acceptance.
- Threat and alert oversight: Work with security operations, technology and service teams to interpret threat intelligence and material alerts, identify emerging exposure, confirm appropriate response and escalate risks requiring management action.
- Risk management: Facilitate risk identification and assessment, maintain risk and issue records, define treatment plans, evaluate residual risk and support accountable risk acceptance. Ensure clear traceability from threats and vulnerabilities to risks, controls and actions.
- Control assurance and compliance: Assess the design and operating effectiveness of security controls against contractual, legal, regulatory and recognised framework requirements, including ISO/IEC 27001, NIST CSF and applicable sector obligations.
- Audit and remediation: Plan and support internal and external audits, coordinate evidence, respond to findings and maintain oversight of corrective actions. Challenge closure evidence and report overdue, systemic or material control gaps.
- Security reporting: Produce concise management information covering risk exposure, vulnerabilities, threats, alerts, incidents, control performance, compliance and remediation. Use defined data sources, thresholds and trends to support risk-based decisions.
- Stakeholder and client engagement: Act as a trusted adviser to client security leaders, service owners, technical teams, auditors and third parties. Translate complex operational and regulatory matters into clear decisions, ownership and action.
- Consulting delivery: Lead or contribute to security assessments, governance reviews, operating model development, control improvement programmes and client deliverables. Shape pragmatic recommendations that are proportionate to the client’s risk appetite and operating context.
- Continuous improvement: Identify recurring weaknesses and opportunities to simplify governance, strengthen controls, improve data quality and embed sustainable security practices.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What experience you’ll bring:
You will bring broad information security experience and be comfortable moving between governance, operational oversight and hands-on consultancy. Evidence should include a number of the following:
- Five or more years’ experience in information security management, operational security, GRC, security consulting, risk, audit or compliance roles.
- At least one of the following professional certification such as CISM, CISSP, CRISC, CISA or ISO/IEC 27001 Lead Auditor or Lead Implementer.
- UK Cyber Security Council title advantageous (Practitioner)
- Strong understanding of governance, risk and control frameworks such as ISO/IEC 27001, NIST CSF and NIST 800-53, together with relevant legal, regulatory, contractual and sector requirements.
- Experience overseeing vulnerabilities, threats, alerts, incidents, security risks and remediation across enterprise technology or managed service environments.
- Practical knowledge of vulnerability management and security operations, including risk-based prioritisation, escalation, exception management and closure assurance.
- Experience completing security risk assessments, control assessments, compliance reviews or audits and translating findings into prioritised treatment plans.
- Ability to define meaningful security measures, reporting and RAG thresholds using reliable data sources to support management oversight and risk-based decisions.
- Consulting experience, including discovery, stakeholder interviews, analysis, report writing, presenting recommendations and supporting clients through implementation or remediation.
- Credibility with senior stakeholders, technical teams, service providers, auditors and regulators, with the confidence to provide constructive challenge and escalate material concerns.
- A practical leadership style that balances independent oversight with direct involvement in resolving security issues and improving controls.
- Clear written and verbal communication, with the ability to explain technical, risk and compliance matters to both technical and non-technical audiences.
- Strong attention to detail, sound judgement and the ability to manage competing priorities in a client-facing environment.
- A valid right to work in the UK and eligibility to obtain UK Security Check clearance.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Who we are:
We’re a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects. Our inclusive work environment prioritises mutual respect, accountability, and continuous learning for all our people. This approach fosters collaboration, well-being, growth, and agility, leading to a more diverse, innovative, and competitive organisation. We are also proud to share that we have a range of Inclusion Networks such as: the Women’s Business Network, Cultural and Ethnicity Network, LGBTQ+ & Allies Network, Neurodiversity Network and the Parent Network. For more information on Diversity, Equity and Inclusion please click here: Creating Inclusion Together
What we’ll offer you:
We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options. For more information on NTT DATA UK & Ireland please click here: NTT DATA We are an equal opportunities employer. We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We are also a Disability Confident Committed Employer - we want to see every candidate performing at their best throughout the job application and interview process, if you require any reasonable adjustments during the recruitment process, please let us know and we look forward to hearing from you.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location