Korn Ferry Project Solutions is supporting a major health insurance client with a strategic Prevalent AI Insights (PAI)/Data-Driven Security initiative within its Group Chief Information Security Office (GISO) and are seeking an experienced Cyber Security Risk & Assurance SME to join the engagement.
You'll provide cyber risk and assurance expertise across discovery, data onboarding, testing, go-live and service transition, ensuring that Information Security metrics, source data and assessment logic provide a reliable view of control effectiveness and residual risk.
Requirements
- 10+ years' experience in Cyber Security Risk, Assurance, GRC or Information Security
- Strong experience in cyber security risk management, control effectiveness assessment and assurance
- Experience interpreting cyber security data, metrics and reporting to support risk-based decision making
- Proven experience validating security data and Prevalent AI Insights (PAI)/reporting outputs against source evidence, control assessments, audits, incidents and risk registers
- Strong understanding of security controls, risk assessment methodologies and assurance practices
- Experience with cyber risk registers, control frameworks and compliance reporting
- Experience supporting audits, regulatory reviews and assurance programmes
- Ability to identify material control, reporting and data quality gaps and drive remediation
- Ability to define risk-based testing scenarios and provide recommendations to support go-live decisions
- Ability to constructively challenge findings and provide independent assurance
- Strong stakeholder management, workshop facilitation and communication skills
- Experience working within large, global, complex and matrixed organisations
- Financial services experience required, ideally banking, insurance or another highly regulated environment
- Experience working across multiple business units, geographies, Markets and federated security functions
Desirable
- Experience with cyber security KPIs/KRIs and control effectiveness metrics
- Experience with data-driven security reporting, security analytics or insight platforms
- Experience working with Metric Owners, Insight Leads, GRC, Technology and business stakeholders
- NIST CSF, ISO 27001, CIS Controls or equivalent framework experience
- CISSP, CISM, CRISC or equivalent certification