> Markdown version of [/jobs/ext/3047109-cyber-security-risk-policy-manager](https://www.wearedevelopers.com/jobs/ext/3047109-cyber-security-risk-policy-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Risk & Policy Manager - **Company:** Circle Group Ltd - **Location:** Bristol, UK - **Salary:** £85,000.0 - £100,000.0 - **Contract:** Temporary contract - **Skills:** Cyber Security, Supervisory Control and Data Acquisition (SCADA), Information Technology, Operational Systems, CIS Benchmarks - **Published:** September 24, 2026 - **Apply:** https://www.totaljobs.com/job/cyber-security-risk-manager/circle-group-job108027654 ## About the Role * Experience in cyber security risk management and risk assessments. * Strong understanding of cyber security controls, risk frameworks and governance. * Working knowledge of ISO 27001, ISO 27005, NIST, CIS Controls and CAF. * Experience developing or maintaining cyber security policies and standards. * Strong stakeholder management and communication skills. * Experience tracking security programmes, workstreams and timelines. * Good understanding of IT systems and supporting technologies. * Understanding of SCADA and Operational Technology (OT) would be advantageous. * Degree or professional qualification in Cyber Security, Information Security, Computer Science, Risk Management or a related discipline, or equivalent experience. * Experience working within Critical National Infrastructure (CNI), or other highly regulated environments would be beneficial. This is a UK-based role and applicants must have the full and permanent right to work in the UK. ## Description An exciting opportunity for a Cyber Security Risk & Policy Manager to join our client on a 12-month fixed-term contract, supporting the security of a large and complex enterprise environment. This role is responsible for identifying, assessing, managing and reporting cyber security risks across the organisation, ensuring risks are appropriately understood, treated and aligned with business objectives, regulatory requirements and risk appetite., You will work closely with technology, business, compliance, audit and security teams to strengthen cyber security governance and resilience., As a Cyber Security Risk & Policy Manager, you will be responsible for: * Developing, implementing and maintaining the cyber security risk management framework. * Maintaining the Cyber Security Risk Register, including risk assessment and treatment throughout the risk lifecycle. * Developing and maintaining cyber security policies, standards and supporting documentation. * Working with technology and business stakeholders to track cyber security programmes and risk mitigation activity. * Identifying potential delays, bottlenecks and issues affecting cyber security risk reduction. * Supporting internal and external audits and regulatory compliance activities. * Ensuring cyber security risk is appropriately considered across projects and technology initiatives. * Developing and managing cyber security risk metrics and KPIs. * Maintaining awareness of emerging regulations, threats, technologies and industry best practice. * Building strong relationships with senior stakeholders across technology, security and operational teams. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Enterprise Linux as Container Images](https://www.wearedevelopers.com/videos/1610-enterprise-linux-as-container-images) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)