Cyber Risk & Security Lead
Cyber Risk & Security Lead
Location: Hybrid working – Surrey
Travel: Occasional international travel (Europe, Asia, Caribbean)
Are you looking to work for an established international professional services organisation who put people first? Are you looking to take on a role where you take ownership of cyber risk, resilience, and security assurance across its global operations?
This role is working closely with technology leadership and regional stakeholders and will play a key part in strengthening the organisation’s security posture, improving governance, and ensuring cyber risks are effectively identified, managed, and communicated. This is a visible and influential position offering a balance of strategic input and hands-on involvement.
Key Areas of Responsibility
Cyber Risk, Governance & Assurance
- Own and evolve enterprise-wide cyber risk management practices, ensuring risks are assessed, prioritised, and clearly reported
- Develop and maintain security standards, frameworks, and internal guidance aligned to recognised best practice
- Provide specialist input into regulatory compliance, data protection, and information security obligations
- Support internal and external reviews, audits, and assurance activities across international locations
Security Operations & Incident Management
- Act as a senior point of contact for cyber incidents, coordinating response efforts and post-incident reviews
- Oversee security monitoring and alert handling, ensuring appropriate investigation, escalation, and follow-up
- Review vulnerability assessments and testing outcomes, driving remediation actions with IT and suppliers
- Contribute to business continuity and technology resilience planning
Third-Party, Supplier & Insurance Oversight
- Assess cyber risk relating to third-party suppliers and managed service providers
- Support procurement and contract discussions relating to security services and tooling
- Coordinate insurance-related cyber risk activity, supporting renewals, assessments, and incident engagement where required
Identity, Awareness & Continuous Improvement
- Promote effective access control and identity management practices, including periodic access reviews
- Design and deliver user-focused security awareness activity and guidance
- Track emerging threats and exposure trends, including external risk indicators where appropriate
- Champion continuous improvement in cyber maturity across the organisation
If this is you please apply ASAP as the recruitment process is likely to move swiftly.
.
We do our best to reply to EVERY application!
We have been candidates too and we work hard to treat you in the same way that we would want to be treated. Therefore, we try not to rely on a generic advert disclaimer as this is something that is important for us and the businesses we partner with.
Given the high volume of responses we receive from the combination of job boards, social media and other sources and despite our best efforts, many of our responses will be via email as we simply can’t call every application - We know that may not quite what you want to hear but we hope you’ll understand and that you like our approach.
We work with great people from a wide variety of backgrounds, not just because it’s the right thing to do, but because it makes us, and our clients stronger, more creative and ultimately better at what we all do.
Short-listed candidates will obviously be contacted for this specific role and, regardless of the outcome of this process, feel free to ustilise the ‘job seeker resources’ on our website.