Cyber Security Risk & Policy Manager

Circle Group Ltd
Bristol, UK
9 days ago
Apply on www.totaljobs.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Compensation
£85,000.0 - £100,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Supervisory Control and Data Acquisition (SCADA) Information Technology Operational Systems CIS Benchmarks

Job description

An exciting opportunity for a Cyber Security Risk & Policy Manager to join our client on a 12-month fixed-term contract, supporting the security of a large and complex enterprise environment.

This role is responsible for identifying, assessing, managing and reporting cyber security risks across the organisation, ensuring risks are appropriately understood, treated and aligned with business objectives, regulatory requirements and risk appetite., You will work closely with technology, business, compliance, audit and security teams to strengthen cyber security governance and resilience., As a Cyber Security Risk & Policy Manager, you will be responsible for:

  • Developing, implementing and maintaining the cyber security risk management framework.
  • Maintaining the Cyber Security Risk Register, including risk assessment and treatment throughout the risk lifecycle.
  • Developing and maintaining cyber security policies, standards and supporting documentation.
  • Working with technology and business stakeholders to track cyber security programmes and risk mitigation activity.
  • Identifying potential delays, bottlenecks and issues affecting cyber security risk reduction.
  • Supporting internal and external audits and regulatory compliance activities.
  • Ensuring cyber security risk is appropriately considered across projects and technology initiatives.
  • Developing and managing cyber security risk metrics and KPIs.
  • Maintaining awareness of emerging regulations, threats, technologies and industry best practice.
  • Building strong relationships with senior stakeholders across technology, security and operational teams.

Requirements

  • Experience in cyber security risk management and risk assessments.
  • Strong understanding of cyber security controls, risk frameworks and governance.
  • Working knowledge of ISO 27001, ISO 27005, NIST, CIS Controls and CAF.
  • Experience developing or maintaining cyber security policies and standards.
  • Strong stakeholder management and communication skills.
  • Experience tracking security programmes, workstreams and timelines.
  • Good understanding of IT systems and supporting technologies.
  • Understanding of SCADA and Operational Technology (OT) would be advantageous.
  • Degree or professional qualification in Cyber Security, Information Security, Computer Science, Risk Management or a related discipline, or equivalent experience.
  • Experience working within Critical National Infrastructure (CNI), or other highly regulated environments would be beneficial.

This is a UK-based role and applicants must have the full and permanent right to work in the UK.

Benefits & conditions

This is a 12-month FTC requiring attendance once per month at Exeter, Plymouth, Taunton, Bristol, Cardiff or Warwick. They are offering a total package of between £85,000 - £100,000 on Pro-Rata, there may be some flexibility for the right candidate.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

41 sec

Introducing the blockchain operating system as a platform layer

Andrej Šarić · World Congress 2023

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:13 min

Differentiating standalone automotive operating systems from projected mobile experiences

Stephan Schuster · World Congress 2022

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

Videos

See all

Related articles

See all