About this role
Job Description OVERVIEW Job Title Consultant Job Code 696223 Grade I3 Group - Division Legal, Risk & Governance Department Cybersecurity Unit - ROLE PURPOSE The aim is to state the overall significance of the job from the organization's perspective. The role exists to lead and support cybersecurity activities by assessing security risks, strengthening controls, supporting compliance with cybersecurity requirements, coordinating with internal stakeholders, and contributing to the protection of Elm’s information assets, systems, and digital services. The role contributes to Elm’s strategic and operational objectives by enabling secure business operations, improving cybersecurity maturity, and ensuring cybersecurity practices are implemented in alignment with approved policies, procedures, regulatory requirements, and information security standards. KEY ACCOUNTABILITIES & ACTIVITIES This section describes the principal outputs required from the job. Key Accountabilities Key Activities 1. Cybersecurity Governance Support • Lead assigned cybersecurity governance activities to ensure alignment with approved policies, standards, and regulatory requirements. • Support the review and implementation of cybersecurity frameworks, procedures, and control requirements. • Coordinate with relevant stakeholders to ensure cybersecurity requirements are understood and applied across assigned areas. 2. Cybersecurity Risk Assessment • Conduct cybersecurity risk assessments for systems, services, processes, and business initiatives. • Identify security risks, control gaps, threats, and vulnerabilities that may impact confidentiality, integrity, or availability. • Recommend practical mitigation actions and follow up on risk treatment plans with relevant stakeholders. 3. Security Controls Assessment • Assess the effectiveness of cybersecurity controls and identify areas requiring improvement. • Review control implementation evidence and validate alignment with internal cybersecurity requirements. • Support continuous improvement of control design, implementation, and monitoring practices. 4. Compliance and Regulatory Alignment • Support compliance activities related to cybersecurity regulations, internal policies, and applicable standards. • Coordinate evidence collection, gap analysis, and remediation follow-up for cybersecurity compliance requirements. • Prepare compliance updates, findings, and recommendations for management review. 5. Cybersecurity Advisory and Stakeholder Support • Provide cybersecurity guidance to business and technical teams within the assigned scope. • Support projects and initiatives by reviewing cybersecurity requirements and advising on secure implementation practices. • Coordinate with stakeholders to address cybersecurity concerns, clarify requirements, and support informed decision-making. 6. Security Monitoring and Incident Support • Support cybersecurity monitoring activities by reviewing security alerts, trends, and reported incidents within the assigned scope. • Coordinate with relevant technical teams to investigate security events and support incident response activities. • Document findings, actions, and recommendations to strengthen detection, response, and prevention capabilities. 7. Vulnerability and Threat Management Support • Support vulnerability assessment activities by reviewing findings, prioritizing risks, and following up on remediation actions. • Coordinate with system owners and technical teams to ensure vulnerabilities are addressed based on risk and business impact. • Monitor emerging cybersecurity threats and contribute to awareness of risks relevant to Elm’s environment. 8. Cybersecurity Reporting and Continuous Improvement • Prepare cybersecurity reports, dashboards, and status updates covering risks, controls, compliance, incidents, and improvement actions. • Analyze cybersecurity performance indicators to identify trends, gaps, and opportunities for improvement. • Contribute to initiatives that enhance cybersecurity maturity, operational resilience, and protection of information assets. 9. Policies, Processes & Procedures • Follow all relevant departmental policies, processes, standard operating procedures, and instructions so that work is carried out in a controlled and consistent manner. • Comply with all relevant safety, quality, and environmental management policies, procedures, and controls to ensure a healthy and safe work environment. 10. Information Security • Comply with all relevant information security practices and standards to ensure data integrity and confidentiality. JOB SPECIFICATIONS Academic and professional qualifications • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Computer Engineering, or a related field. • Professional certifications in cybersecurity, information security, risk management, governance, or related fields are preferred. Years and Nature of Experience • 4–6 years of relevant experience in cybersecurity, information security, cybersecurity governance, risk and compliance, security operations, vulnerability management, or a related field. • Experience in assessing cybersecurity risks, reviewing security controls, supporting compliance activities, coordinating with stakeholders, preparing cybersecurity reports, and contributing to security improvement initiatives.