Назад
Company hidden
6 дней назад

Risk Manager (Cybersecurity)

Формат работы
remote (только United_kingdom)
Тип работы
fulltime
Английский
b2
Страна
UK/US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Risk Manager (Cybersecurity) (Information Security/GRC): Leading information security and business risk assessments, treatment programmes, and governance across a cloud identity and access management platform with an accent on enterprise risk, third-party oversight, and audit readiness. Focus on maintaining risk registers, defining risk indicators and appetite, improving control effectiveness, and translating complex technology risks into defensible business decisions.

Location: UK - Remote

Company

hirify.global develops a cloud identity platform that helps enterprises secure digital experiences, identities, and access management.

What you will do

  • Lead and continuously improve the information security risk management lifecycle, from identification and assessment through treatment, acceptance, monitoring, and reporting.
  • Run enterprise, business-unit, project, technology, third-party, and supplier risk assessments with consistent documentation and business context.
  • Maintain risk registers, treatment plans, action ownership, due dates, escalation paths, and residual-risk reporting.
  • Define risk appetite, tolerance indicators, key risk indicators, governance routines, workflows, and management reporting.
  • Partner with security, engineering, product, legal, privacy, finance, sales, customer success, and control owners to improve controls, evidence, remediation, and audit readiness.
  • Support ISMS, BCMS, and AIMS risk components, customer assurance activities, regulatory requests, security questionnaires, and GRC capability development.

Requirements

  • Demonstrable experience leading information security risk assessments and treatment programmes in complex, technology-led organisations.
  • Knowledge of recognised frameworks and standards such as ISO 27001, SOC 2, ISO 27017, ISO 27018, NIST, HIPAA, or similar.
  • Strong understanding of risks across systems, networks, applications, cloud services, identity platforms, and business processes.
  • Experience with AWS, GCP, or Azure and the ability to translate technical issues into business risk.
  • Experience with risk registers, risk acceptance, exception management, remediation tracking, control validation, residual-risk reporting, and third-party risk management.
  • Strong communication, judgement, prioritisation, analytical thinking, and stakeholder-influence skills.

Nice to have

  • Experience with enterprise risk reporting, key risk indicators, risk appetite statements, risk committees, customer assurance, or security questionnaires.
  • Experience with GRC, risk, audit, or compliance platforms and workflow automation.
  • Experience in SaaS, cloud, identity, or software development environments.
  • Certifications such as CISSP, CISM, CISA, CRISC, CGEIT, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.

Culture & Benefits

  • Flexible and collaborative work environment with startup-oriented values.
  • Employee Resource Groups, company and team bonding events, and global volunteering initiatives.
  • Generous paid time off and holiday schedule.
  • Parental leave, healthcare options, retirement programmes, and education reimbursement.
  • Commuter offset available in specific locations.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →