Overview
The Cyber Risk Analyst will support a large organisation in enhancing its cyber security framework by focusing on the management of cyber and technology risks. This contract position involves working closely with various stakeholders to identify, assess, and mitigate risks effectively, ensuring that they align with the organisation's overall risk management strategy. The contractor will be instrumental in maintaining and improving the organisation's risk register while collaborating with technical and business counterparts.
Responsibilities
- Own and maintain the cyber/technology risk register.
- Identify and assess new cyber and technology risks.
- Review and challenge existing risks, controls, and treatment plans.
- Assess inherent and residual risk.
- Work with risk owners to agree on appropriate remediation and mitigation activities.
- Track risk treatment actions through to completion.
- Facilitate risk reviews and workshops with technical and business stakeholders.
- Ensure risks are clearly articulated in business terms, including likelihood, impact, and potential exposure.
Requirements
- Strong experience in Cyber Risk, Technology Risk, Information Security Risk, or GRC.
- Demonstrable experience managing and maintaining a cyber/technology risk register.
- Strong understanding of risk assessment, treatment, and control effectiveness.
- Experience managing remediation actions and collaborating with risk owners.
- Confident stakeholder management skills, including the ability to challenge senior stakeholders.
- Good understanding of cyber security controls and technology environments.
- Experience with security or risk frameworks such as NCSC CAF, NIS, ISO 27001/ISO 27005, or NIST.