Security Risk Analyst

ROYAL BOROUGH OF KENSINGTON AND CHELSEA
London, UK
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£53,076.0 - £60,003.0
Working hours
Regular working hours

Tech stack

Cyber Security Digital Technology Information Technology Cybercrime PSN Vulnerability Analysis

Job description

As a Security Risk Analyst, you’ll provide proactive cyber risk analysis to safeguard our digital systems and protect resident data. We’re all in to strengthen our security posture and deliver resilient services for everyone.

Working Style: You’ll be based in the Borough for three days a week, playing a key role in serving the local community. Whether you’re working on-site or collaboratively across teams, you’ll be part of a dedicated team helping to keep our organisation secure.

What you’ll be doing

Your days will be varied, focusing on providing clear, proactive and evidence-based cyber risk analysis to help us understand, prioritise and manage threats. You’ll review updates to the cyber risk register, track agreed actions, identify vulnerabilities and escalate concerns when progress slows. Collaboration is vital, and you’ll work closely with ICT, Information Governance, service areas and suppliers to assess risks linked to new systems, contracts, incidents or audits.

Vetting suppliers who handle Council information will be a key responsibility. You’ll ensure security questionnaires are completed, evaluate threats and likelihoods and agree practical mitigations while managing the supplier risk system. Beyond the technical tasks, you’ll translate complex issues into clear business language for senior leaders and governance boards, championing strong security practices and helping embed a risk-aware culture across the entire organisation., We are a Disability Confident Employer - committed to ensuring that our recruitment and selection process is inclusive and accessible.

Requirements

You’ll bring a degree in ICT, Computer Science or comparable experience within digital, data and technology, alongside a continuous commitment to professional development.

Experience in cyber security, information risk management or information governance within a complex organisation is essential. You’ll need a strong understanding of cyber threats, attack vectors and risk assessment frameworks such as the NCSC Cyber Assessment Framework, ISO 27001 or NIST.

Your ability to translate technical risks into clear, business-focused language is crucial, as are your excellent communication and stakeholder engagement skills. You must be proactive, with the analytical depth to manage competing priorities and drive follow-through on risk actions. A firm understanding of modern technology environments, zero-trust delivery, incident response and UK public sector regulatory requirements like PSN CoCo and UK GDPR is required, combined with a clear commitment to fairness, integrity and equal opportunities.

Benefits & conditions

This new role offers a unique opportunity to make a council-wide impact following a major cyber-attack, backed by excellent senior buy-in and upward support. You’ll be strategically positioned to shape our security approach from day one. We support your career growth with competitive pay, continuous training opportunities, flexible working and comprehensive wellbeing perks to ensure you thrive., New hires will normally start at the minimum of the pay scale. However, a higher starting salary may be negotiated where a candidate demonstrates exceptional skills, knowledge, or experience.

Employees receive annual salary increments until they reach the top of the pay scale, as well as any agreed cost of living pay awards.

About the company

Kensington and Chelsea is home to diverse communities, thriving businesses and unique local places. Everything we do is focused on supporting our residents, strengthening our approach and creating a fairer borough.

As a competent and caring Council, we take pride in our work every day, ensuring our services are delivered with care and competence. We listen to our residents, act with integrity and work together to build a borough that is greener, safer and fairer for all.

In this new role, you’ll step into a critical mission following the cyber-attack in November 2025, playing an essential part in a wider organisational ICT and security restructure. Establishing a new role amidst a high volume of work brings real embedding challenges, but every ounce of effort pays off. When you commit fully, these challenges become opportunities for growth, allowing your risk analysis and supplier vetting to directly reinforce our wider brand and keep the Council secure.

Working Style: You’ll be based in the Borough for three days a week, playing a key role in serving the local community. Whether you’re working on-site or collaboratively across teams, you’ll be part of a dedicated team helping to keep our organisation secure.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · WWC 2023

Videos

See all

Related articles

See all