Join a high-profile cyber security function and play a key role in strengthening cyber governance, third-party risk and security assurance across a complex enterprise environment.
Working within the Cyber Security team and closely with the CISO, you’ll partner with technology teams, business stakeholders and external security providers to assess cyber risk and ensure security requirements are embedded across new solutions and third-party engagements.
The Role You’ll take ownership across three core areas:
- Conduct third-party cyber security assessments, reviewing SOC reports, ISO certifications and other security evidence.
- Identify vendor security risks, produce risk assessments and track remediation activities.
- Conduct security risk assessments across new and changing applications, systems and technology solutions.
- Work with project teams to identify security risks and recommend practical mitigation strategies.
- Coordinate penetration testing across projects, working with internal teams, external vendors and testing partners.
- Track vulnerabilities and remediation through to completion.
- Present penetration testing findings to stakeholders, including executives where required.
- Help enhance third-party and solution risk assessment frameworks.
About You
We’re looking for someone who combines strong cyber governance and risk capability with the confidence to work across technical and non-technical stakeholders.
You’ll ideally bring:
- 4+ years' experience across cybersecurity, governance or risk.
- Hands-on experience conducting third-party/vendor risk assessments.
- Experience performing solution security risk assessments.
- Exposure to coordinating penetration testing and vulnerability management.
- Demonstrated experience implementing and maturing a cybersecurity framework aligned to NIST CSF 2.0.
- Solid stakeholder management, communication and negotiation skills.
- A relevant degree or equivalent professional experience.
Cyber security certifications such as CISSP, CISA or CRISC will be highly regarded, while specialist vendor risk or penetration testing certifications are advantageous.
If your strength sits at the intersection of cybersecurity, governance and risk, and you enjoy translating security requirements into practical business outcomes, we’d like to hear from you.