Cyber Risk Analyst - Edinburgh - Inside IR35
Cyber Security Risk Analyst - Inside IR35
Location: Edinburgh (Hybrid - 2 days onsite per week)Contract: Initial 6 months Rate: £300-£350 per day (Inside IR35)
One of Loriens Public Sector clients are seeking a Cyber Security Risk Analyst to join their cyber security team and work closely across their digital department and with business process owners. This role is key to enhancing processes that identify, assess, and manage technical risks, supporting data-driven security decisions through accurate and up-to-date risk information.
You will contribute to developing cost-effective, objective, and where possible, automated risk management processes, while collaborating with product owners, architects, developers, engineers, and senior security leadership.
Key Responsibilities
- Maintain awareness of the current cyber threat landscape, industry standards, and best practices.
- Support scoping and assessment of risks related to projects, changes, and digital services.
- Conduct and support risk assessments and threat modelling.
- Interpret outputs from assurance activities (e.g., vulnerability scans, audits, penetration tests) and incorporate findings into risk processes.
- Provide clear, prioritised recommendations for risk treatment and mitigation.
- Contribute to the development and improvement of risk management processes and tools.
- Work collaboratively across business and technical teams to ensure effective risk management.
Technical Scope
- Office suite (Excel, Word)
- Cloud platforms (Azure)
- M365 (e.g., Microsoft Forms)
- Power Platform (desirable)
Essential Skills
- Security and Risk Assessment or Audit experience within digital environments.
- Strong understanding of enterprise-scale digital service provision.
- Ability to work effectively in an agile environment.
- Self-starter with a focus on improvements and benefits realisation.
- Collaborative approach with ability to share knowledge and experience.
Desirable
- Familiarity with information/security risk management frameworks and tools.
- Experience with technical risk registers or GRC systems.
- Awareness of cloud and enterprise service environments.
- Understanding of assurance activities such as audits, vulnerability assessments, and penetration tests.
- Formal information or IT risk accreditation (beneficial).
Guidant, Carbon60, Lorien & SRG - The Impellam Group Portfolio are acting as an Employment Business in relation to this vacancy.