Cyber Risk Assessor
Contract Type
Location
Industry
Specialisation
Salary
Contact Name
Contact Email
Date published
Job Reference
Description
We are seeking an experienced Cyber Risk Assessor to join a high-performing cyber security team. In this role, you will lead cyber security risk assessments across major technology initiatives, helping the organisation understand, manage, and mitigate cyber risk while enabling business outcomes.
Working closely with business stakeholders, engineers, delivery teams, vendors, and risk specialists, you will provide pragmatic risk advice, influence decision-making, and support the delivery of secure solutions across a complex enterprise environment.
Key Responsibilities
- Lead cyber security risk assessments for projects, programs, and technology initiatives.
- Partner with project teams to identify security risks, gaps, and remediation opportunities.
- Communicate complex technical risks in clear business terms, including to senior stakeholders and decision-makers.
- Collaborate with business, privacy, legal, engineering, and operational teams to develop balanced risk outcomes.
- Provide expert guidance on cyber risk management and security governance practices.\
- Contribute to the development of security standards, assessment methodologies, and process improvements.
- Develop reusable assessment artefacts, findings, and best practices to improve team capability and consistency.
- Monitor emerging threats and industry trends to inform risk assessments and recommendations.
- Mentor and support other risk assessors and security professionals.
About You
You are an experienced cyber security professional with strong risk assessment expertise and the ability to influence stakeholders across technical and business functions. You can simplify complex issues and provide practical, risk-based recommendations.
- Extensive experience in cyber security, including significant experience within risk, governance, or GRC functions.
- Demonstrated experience conducting technical cyber risk assessments.
- Strong knowledge of cyber security frameworks and standards such as ISO 27001, NIST, PCI DSS, or equivalent.
- Experience operating within large, complex enterprise environments.
- Excellent stakeholder engagement and communication skills.Desirable Experience
- Professional certifications such as CRISC, CISSP, CISM, or SABSA.