6 дней назад
Risk Manager (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Risk Manager (Cybersecurity) (Information Security/GRC): Leading information security and business risk assessments, treatment programmes, and governance across a cloud identity and access management platform with an accent on enterprise risk, third-party oversight, and audit readiness. Focus on maintaining risk registers, defining risk indicators and appetite, improving control effectiveness, and translating complex technology risks into defensible business decisions.
Location: UK - Remote
Company
develops a cloud identity platform that helps enterprises secure digital experiences, identities, and access management.
What you will do
- Lead and continuously improve the information security risk management lifecycle, from identification and assessment through treatment, acceptance, monitoring, and reporting.
- Run enterprise, business-unit, project, technology, third-party, and supplier risk assessments with consistent documentation and business context.
- Maintain risk registers, treatment plans, action ownership, due dates, escalation paths, and residual-risk reporting.
- Define risk appetite, tolerance indicators, key risk indicators, governance routines, workflows, and management reporting.
- Partner with security, engineering, product, legal, privacy, finance, sales, customer success, and control owners to improve controls, evidence, remediation, and audit readiness.
- Support ISMS, BCMS, and AIMS risk components, customer assurance activities, regulatory requests, security questionnaires, and GRC capability development.
Requirements
- Demonstrable experience leading information security risk assessments and treatment programmes in complex, technology-led organisations.
- Knowledge of recognised frameworks and standards such as ISO 27001, SOC 2, ISO 27017, ISO 27018, NIST, HIPAA, or similar.
- Strong understanding of risks across systems, networks, applications, cloud services, identity platforms, and business processes.
- Experience with AWS, GCP, or Azure and the ability to translate technical issues into business risk.
- Experience with risk registers, risk acceptance, exception management, remediation tracking, control validation, residual-risk reporting, and third-party risk management.
- Strong communication, judgement, prioritisation, analytical thinking, and stakeholder-influence skills.
Nice to have
- Experience with enterprise risk reporting, key risk indicators, risk appetite statements, risk committees, customer assurance, or security questionnaires.
- Experience with GRC, risk, audit, or compliance platforms and workflow automation.
- Experience in SaaS, cloud, identity, or software development environments.
- Certifications such as CISSP, CISM, CISA, CRISC, CGEIT, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
Culture & Benefits
- Flexible and collaborative work environment with startup-oriented values.
- Employee Resource Groups, company and team bonding events, and global volunteering initiatives.
- Generous paid time off and holiday schedule.
- Parental leave, healthcare options, retirement programmes, and education reimbursement.
- Commuter offset available in specific locations.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
Head of Information Security (AI)
6 дней назад
Manager, Technology & Cybersecurity Risk / Risk Data Analyst (AI)
109 000 - 169 000$
11 дней назад
Head of Information Security (Cybersecurity)
11 дней назад
Head of Information Security (Cybersecurity)
9 дней назад
Information Security Analyst (AI Cybersecurity)
9 дней назад