Cyber Security Risk & Policy Manager
Cyber Security Risk & Policy Manager
Salary: £85,000 - £100,000 total package
12 Month FTC
Monthly Travel to Exeter, Plymouth, Taunton, Bristol, Cardiff or Warwick
Clearance: SC
About the Role
An exciting opportunity for a Cyber Security Risk & Policy Manager to join our client on a 12-month fixed-term contract, supporting the security of a large and complex enterprise environment.
This role is responsible for identifying, assessing, managing and reporting cyber security risks across the organisation, ensuring risks are appropriately understood, treated and aligned with business objectives, regulatory requirements and risk appetite.
This is a 12-month FTC requiring attendance once per month at Exeter, Plymouth, Taunton, Bristol, Cardiff or Warwick. They are offering a total package of between £85,000 - £100,000 on Pro-Rata, there may be some flexibility for the right candidate.
You will work closely with technology, business, compliance, audit and security teams to strengthen cyber security governance and resilience.
Key Responsibilities
As a Cyber Security Risk & Policy Manager, you will be responsible for:
- Developing, implementing and maintaining the cyber security risk management framework.
- Maintaining the Cyber Security Risk Register, including risk assessment and treatment throughout the risk lifecycle.
- Developing and maintaining cyber security policies, standards and supporting documentation.
- Working with technology and business stakeholders to track cyber security programmes and risk mitigation activity.
- Identifying potential delays, bottlenecks and issues affecting cyber security risk reduction.
- Supporting internal and external audits and regulatory compliance activities.
- Ensuring cyber security risk is appropriately considered across projects and technology initiatives.
- Developing and managing cyber security risk metrics and KPIs.
- Maintaining awareness of emerging regulations, threats, technologies and industry best practice.
- Building strong relationships with senior stakeholders across technology, security and operational teams.
Who We Are Looking For
- Experience in cyber security risk management and risk assessments.
- Strong understanding of cyber security controls, risk frameworks and governance.
- Working knowledge of ISO 27001, ISO 27005, NIST, CIS Controls and CAF.
- Experience developing or maintaining cyber security policies and standards.
- Strong stakeholder management and communication skills.
- Experience tracking security programmes, workstreams and timelines.
- Good understanding of IT systems and supporting technologies.
- Understanding of SCADA and Operational Technology (OT) would be advantageous.
- Degree or professional qualification in Cyber Security, Information Security, Computer Science, Risk Management or a related discipline, or equivalent experience.
- Experience working within Critical National Infrastructure (CNI), or other highly regulated environments would be beneficial.
This is a UK-based role and applicants must have the full and permanent right to work in the UK.
"Apply Now" for immediate review!
Cyber Security Risk & Policy Manager, ISO 27001, ISO 27005, NIST, CIS Controls ,Cyber Security Risk & Policy Manager. Cyber Security Risk & Policy Manager, SCADA, Risk, Cyber Security Risk & Policy Manager
Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter - @Circle_Rec and LinkedIn - Circle Recruitment.