All Jobs Vacancy

Cyber Security Risk & Policy Manager

Posted 1 week ago by Circle Recruitment

About the Role

An exciting opportunity for a Cyber Security Risk & Policy Manager to join our client on a 12-month fixed-term contract, supporting the security of a large and complex enterprise environment.

This role is responsible for identifying, assessing, managing and reporting cyber security risks across the organisation, ensuring risks are appropriately understood, treated and aligned with business objectives, regulatory requirements and risk appetite.

This is a 12-month FTC requiring attendance once per month at Exeter, Plymouth, Taunton, Bristol, Cardiff or Warwick. They are offering a total package of between £85,000 - £100,000 on Pro-Rata, there may be some flexibility for the right candidate.

Key Responsibilities

  • Developing, implementing and maintaining the cyber security risk management framework.
  • Maintaining the Cyber Security Risk Register, including risk assessment and treatment throughout the risk lifecycle.
  • Developing and maintaining cyber security policies, standards and supporting documentation.
  • Working with technology and business stakeholders to track cyber security programmes and risk mitigation activity.
  • Identifying potential delays, bottlenecks and issues affecting cyber security risk reduction.
  • Supporting internal and external audits and regulatory compliance activities.
  • Ensuring cyber security risk is appropriately considered across projects and technology initiatives.
  • Developing and managing cyber security risk metrics and KPIs.
  • Maintaining awareness of emerging regulations, threats, technologies and industry best practice.
  • Building strong relationships with senior stakeholders across technology, security and operational teams.

Who We Are Looking For

  • Experience in cyber security risk management and risk assessments.
  • Strong understanding of cyber security controls, risk frameworks and governance.
  • Working knowledge of ISO 27001, ISO 27005, NIST, CIS Controls and CAF.
  • Experience developing or maintaining cyber security policies and standards.
  • Strong stakeholder management and communication skills.
  • Experience tracking security programmes, workstreams and timelines.
  • Good understanding of IT systems and supporting technologies.
  • Understanding of SCADA and Operational Technology (OT) would be advantageous.
  • Degree or professional qualification in Cyber Security, Information Security, Computer Science, Risk Management or a related discipline, or equivalent experience.
  • Experience working within Critical National Infrastructure (CNI), or other highly regulated environments would be beneficial.

This is a UK-based role and applicants must have the full and permanent right to work in the UK.

Rate:
£100,000/year
Location:
Exeter
IR35 Status:
Fixed-Term
Remote Status:
Hybrid
Industry:
Cybersecurity
Seniority Level:
Mid-Level

Take-Home Pay

£5,833 per month

Visit calculators for additional details

Share job