Skip to Main Content

Job Title


Qualified Security Assessor


Company : Experis UK


Location : birmingham, midlands


Created : 2025-04-14


Job Type : Full Time


Job Description

About LRQA NettitudeWeve been around since 2003 and our focus has always been on excellence in cyber security. We have teams that offer world class services in red teaming, penetration testing, threat intelligence, research and development, detection and response, governance, risk, and compliance, and plenty more. Our business is global and so are our clients. We work closely with central banks, central and local government, critical national infrastructure, large retailers, and plenty more besides! #LI-NettitudeWere an award winning provider of cyber security services and were are at a very exciting stage of development. We are looking for the right people to join us as we embrace the challenges thrown up by the advancements within the IT industry and within the threats faced. LRQA Nettitude will be at the forefront of this arena and we want to seek the right people to join the team and make it happen.You can find out more about us at www.nettitude.com. If you want to review our research and tooling, then head on over to https://labs.nettitude.comThe roleWe are looking for a QSA to join our GRC team in the UK. This role is home-based, with travel to client sites. Youll be part of a team delivering security consultancy in a client-facing role, with a particular focus on:PCI DSS consultancy and assessmentsSecurity reviews against standards or guidelines such as the NCSC 10 Steps to Cyber Security and NIST CSFISO 27001 gap analysesHelping our clients to implement Information Security Management Systems and achieve and maintain ISO27001 certificationConducting risk assessmentsCreating or supporting third-party risk management and audit programmesEssential skills and experience:Be a current QSA who has completed multiple on-site PCI DSS assessments, and be able to demonstrate a mature understanding of complex PCI DSS environments, and an ability to consult as well as assessHave experience with ISO 27001, including implementing an ISMS and achieving certificationHave experience working with the NIST CSFA good understanding of core concepts and technologies. For example, networking, Windows and Linux operating systems, and security technologies such as antimalware, IDS/IPS, etc. You do not need hands-on experience with these technologies or to have worked in an operational roleBe experienced working as a consultant in a client-facing role, leading delivery. Youll be friendly and approachable and able to work well with our clientsAbility to work in a structured and methodical manner, with support to manage your own time with a focus on quality workYour primary role will be to deliver PCI DSS consultancy and assessment activities to our clients as part of an established and experienced team of consultants. Its not all PCI DSS, though, and youll be involved in other areas as listed above and have opportunities to scope and deliver more bespoke engagements.Location This role is home-based, with an expectation of travel to client sites, primarily in the UK, but with some opportunities for European and international travel; therefore, all candidates must be willing to travelPCI DSS assessment activities require on-site work, but most other work is delivered at least partly from homeWe can support working from across the UKAll applicants will require residence in the UK What youll be doing in your role: In your role, you will deliver consultancy services to our clients, covering the following areas: Conduct security reviews against standards or guidelines such as the NCSC 10 Steps to Cyber Security, NIST CSF, Cyber EssentialsPerform ISO 27001 gap analysesHelp our clients to implement Information Security Management Systems and achieve and maintain ISO27001 certificationPCI DSS consultancy and gap analyses Assistance in implementing PCI DSS requirements such as policy writingComplete on-site assessments and reports on complianceComplete risk assessmentsConduct third-party risk reviewsSupport pre-sales where required by assisting in the pre-sales process, understanding client requirements and contributing to proposals and scoping of engagements Key Skills: Essential skills and experience:Be a current QSA who has completed multiple on-site PCI DSS assessments, and be able to demonstrate a mature understanding of complex PCI DSS environments, and an ability to consult as well as assessHave experience of ISO 27001, including implementing an ISMS and achieving certificationA good understanding of core concepts and technologies. For example, networking, Windows and Linux operating systems, and security technologies such as antimalware, IDS/IPS, etc. You do not need hands-on experience with these technologies or to have worked in an operational roleBe experienced working as a consultant in a client-facing role, leading delivery. Youll be friendly and approachable and able to work well with our clientsAbility to work in a structured and methodical manner, with support to manage your own time with a focus on quality workDesirable skills and experience:Experience working with the NIS directive, NCSC CAF or CAA ASSUREBe experienced at C-Level, including presenting to top-level management, decision makers and risk owners. You will have the ability to articulate information security risks in a way that demonstrates an understanding of the broader business impactDemonstrate leadership as a senior team member. You will be expected to have input into developing the wider team, take ownership of service areas, and be able to support and mentor other team membersExperience in delivering security awareness training to end-usersHand-on technical experience, even if not recent CertificationsAs an active QSA you must hold a certification from list A and list B per the PCI SSC requirements. Whilst a collection of certifications is less important than experience, many areas in which our team works have pre-requisite certifications that our consultants either hold or are working towards achieving. Any of the following certifications would be beneficial: ISO 27001 lead auditor or lead implementer CISSP - (ISC)2 Certified Information System Security Professional CISM - ISACA Certified Information Security Manager CISA - ISACA Certified Information Systems Auditor CRISC - ISACA Certified in Risk and Information Systems Control What we offer: We are a people-focused, high-performing, high-trust professional services team. Youll be part of a diverse and growing international group of consultants, and we go out of our way to make sure our consultants feel part of our team. We use technology to ensure were always communicating with each other and schedule time every week to talk as a team. The successful candidate will have opportunities to:Make a difference as clichd as it sounds, this really is true. We encourage all consultants to challenge norms and empower them to get involved. This might be getting involved with other teams or developing a new service offering but if you want to do something, we always try to make it happenGet involved enjoy blogging or public speaking? Our team is committed to getting involved in industry discussions. We make time to attend conferences and get involved in the infosec communityDevelop their skills we love learning and ensure we find time for professional development. This isnt just about collecting certifications and attending training courses gaining and sharing knowledge in new areas is vital. These dont always have to be directly related to your day job; in fact, we actively encourage developing knowledge in new and exciting domains