Information Security Risk Manager

Munich Re
London, UK
1 day ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Cyber Security Information Security Management Information Technology

Job description

Experteer Overview In this role you will provide independent, second-line oversight of Information Security and Cyber risk for UK entities within a global group. You will act as ISO for UK entities, guiding risk decisions and challenging first-line controls, while aligning with UK regulation and Group standards. You will influence senior stakeholders across a multi-entity environment and contribute to resilience and outsourcing risk management. This position offers high visibility and the opportunity to shape risk practices across the organization. Pay / Benefits * Provide independent second-line oversight on Information Security and Cyber risks across UK entities * Review and challenge first-line IT and business controls, risk assessments, and remediation activities * Monitor risk exposure and ensure timely closure of control gaps * Drive implementation and embedding of the Group Information Security Management (ISM) framework * Align with UK regulatory expectations (FCA, PRA, Lloyd’s) and internal policies * Translate regulatory and Group requirements into actionable control frameworks * Act as the Information Security Officer (ISO) for UK entities * Provide risk opinions on IT and cyber initiatives, change programmes, and third-party relationships * Support management of cyber incidents and resilience activities from a risk perspective * Deliver risk reporting to governance committees and senior management Tasks * Experience in Information Security / Cyber Risk / IT Risk roles * Strong background in information security frameworks (ISO 27001, NIST) * Experience in Second Line of Defence or advisory roles * Proven ability to provide independent challenge and escalation to senior management * Experience in complex, multi-entity or international organizations (highly desirable) * Deep expertise in cybersecurity and information security risks * Broad understanding of enterprise risk management frameworks * Knowledge of operational resilience and third-party risk * Strong influencing and stakeholder-management skills * Degree in Information Security, IT, Computer Science or related field (or equivalent experience) * Insurance or financial services experience beneficial but not essential Key requirements * 25 days Annual Leave + bank holidays * 10% Non-contributory Pension * Eligibility for an Annual Bonus * Private Medical + Dental Insurance * Hybrid Working + IT Home Set-up Support * Study & continuing Professional Development Support

Requirements

the and internal policies * Translate regulatory and Group requirements into actionable control frameworks * Act as the Information Security Officer (ISO) for UK entities * Provide risk opinions on IT and cyber initiatives, change programmes, and third-party relationships * Support management of cyber incidents and resilience activities from a risk perspective * Deliver risk reporting to governance committees and senior management Tasks * Experience in Information Security / Cyber Risk / IT Risk roles * Strong background in information security frameworks (ISO 27001, NIST) * Experience in Second Line of Defence or advisory roles * Proven ability to provide independent challenge and escalation to senior management * Experience in complex, multi-entity or international organizations (highly desirable) * Deep expertise in cybersecurity and information security risks * Broad understanding of enterprise risk management frameworks * Knowledge of operational resilience and third-party risk

  • Strong influencing and stakeholder-management skills * Degree in Information Security, IT, Computer Science or related field (or equivalent experience) * Insurance or financial services experience beneficial but not essential Key requirements * 25 days Annual Leave + bank holidays * 10% Non-contributory Pension * Eligibility for an Annual Bonus * Private Medical + Dental Insurance * Hybrid Working + IT Home Set-up Support * Study & continuing Professional Development Support

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on eu.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

4:25 min

The growing power and security responsibility of developers

Tino Sokic · WWC 2023

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

Videos

See all

Related articles

See all