- 4 active jobs (view)
- www.marcusdonald.com
Description
Marcus Donald are currently recruiting for a huge Telco, who are looking to recruit a Risk Manager. Your responsibilities will initially be heavily focused towards the centralisation and implementation of the revised Risk Framework.
Working within the Security Governance Risk and Compliance team you will report directly to the Head of Security Governance Risk and Compliance, with your success being critical to the continued focus and attention on business risk appetite.
*Hybrid working – 1-2 days per week in Hampshire*
(Like many, the business are currently reviewing their hybrid working strategy and therefore, this could be amended in time)
Risk Manager – Responsibilities:
- Independently undertake risk management activities within a given area of practice or expertise, usually within established security and risk management governance structures and frameworks
- Provide tailored advice to a range of stakeholders on how to remediate identified risks
- Provide expert security advice that highlights Cyber Security related risks
- Ensure that security policies and security controls remain appropriate and proportionate to the assessed risks
- Accountable for providing security advice and latest best practice, with a business first risk-based approach
Risk Manager – Requirements:
- Ideally you have built and implemented a Cyber Risk Framework
- Knowledge of UK Government Security Policy Framework, International Information Assurance Standards, e.g., ISO 27001, DPA, NIST, ISF Standard of good practise
- Knowledge of application, infrastructure and networking security controls and systems covering physical, procedural and technical areas, particularly in relation to data management
- Strong stakeholder management experience and the ability to communicate with an engineer or an exec
Risk Manager – Desired:
- Certifications; CRISC, ISO27001 Lead Auditor or Lead Implementer, Data Protection Practitioner etc
- Demonstrable SME level expertise in respect to information security risk management processes, frameworks and procedures with large critical national infrastructure organisations
It is of high importance that you are able to work independently, have previously/are currently and can take ownership of the critical centralisation of the Risk Framework and confidently engage with Stakeholders.
This job description is a diluted version with most important points included, there is a more informative job description available for you to paint a better picture of the role and of course we would be more than happy to discuss the position with you in more detail. If you would like to contact me directly, my email is bjames@marcusdonald.com