Назад
Company hidden
9 дней назад

Cyber Risk Analyst

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Risk Analyst (Cybersecurity/Technology Risk): Providing independent second-line oversight of first-line cyber security across M&G, with an accent on control effectiveness, risk metrics, remediation, and incident response. Focus on assessing cyber controls, reviewing testing and assurance outputs, identifying root causes, and communicating pragmatic risk recommendations to stakeholders.

Location: Stirling, United Kingdom

Company

M&G provides asset management, insurance, savings, and investment solutions, with operating segments in Asset Management and Life.

What you will do

  • Provide independent second-line oversight of first-line cyber security controls, assessing their design, implementation, and effectiveness.
  • Review cyber risk metrics, risk processes, RCSAs, assurance actions, and risk appetite alignment.
  • Track and drive remediation of findings from testing, reviews, and incidents, ensuring clear plans and closure.
  • Review cyber processes and technical incident responses to identify gaps, root causes, and pragmatic remedial actions.
  • Provide oversight of cyber risk mitigation projects and control improvement initiatives.
  • Communicate risk findings and recommendations clearly to stakeholders and the wider business.

Requirements

  • At least 3 years of experience in cyber security or an appropriate technology risk function.
  • Broad knowledge of cyber security domains, including risk and audit management, security architecture, DevSecOps, threat intelligence, vulnerability management, and incident response.
  • Understanding of second-line activities, including risk taxonomy, risk appetite, KRIs, and controls.
  • Experience reviewing red-team, penetration-testing, or vulnerability-scanning outputs and assessing their significance.
  • Knowledge of enterprise security products and cloud technologies, with experience using risk and issue tracking tools.
  • Strong analytical, problem-solving, stakeholder engagement, report-writing, and communication skills.

Nice to have

  • Relevant certifications in cyber security, cloud, or risk.
  • Awareness of and interest in AI applications.
  • Experience working in diverse, multicultural teams with international exposure.

Culture & Benefits

  • Flexible working arrangements and workplace adjustments are available.
  • Pension scheme of up to 18%, including employer contributions.
  • 38 days of annual leave including bank holidays, with the option to purchase up to five additional days.
  • Private healthcare, critical illness cover, and life assurance, with additional family options.
  • Paid parental leave and family support covering maternity, adoption, surrogacy, and paternity leave.
  • Inclusive culture with employee-led networks and wellbeing, financial support, and development opportunities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →