Cyber Governance & Risk Analyst

Join a high-profile cyber security function and play a key role in strengthening cyber governance, third-party risk and security assurance across a complex enterprise environment.

Working within the Cyber Security team and closely with the CISO, you’ll partner with technology teams, business stakeholders and external security providers to assess cyber risk and ensure security requirements are embedded across new solutions and third-party engagements.
The Role You’ll take ownership across three core areas:
  • Conduct third-party cyber security assessments, reviewing SOC reports, ISO certifications and other security evidence.
  • Identify vendor security risks, produce risk assessments and track remediation activities.
  • Conduct security risk assessments across new and changing applications, systems and technology solutions.
  • Work with project teams to identify security risks and recommend practical mitigation strategies.
  • Coordinate penetration testing across projects, working with internal teams, external vendors and testing partners.
  • Track vulnerabilities and remediation through to completion.
  • Present penetration testing findings to stakeholders, including executives where required.
  • Help enhance third-party and solution risk assessment frameworks.
About You

We’re looking for someone who combines strong cyber governance and risk capability with the confidence to work across technical and non-technical stakeholders.
You’ll ideally bring:
  • 4+ years' experience across cybersecurity, governance or risk.
  • Hands-on experience conducting third-party/vendor risk assessments.
  • Experience performing solution security risk assessments.
  • Exposure to coordinating penetration testing and vulnerability management.
  • Demonstrated experience implementing and maturing a cybersecurity framework aligned to NIST CSF 2.0.
  • Strong stakeholder management, communication and negotiation skills.
  • A relevant degree or equivalent professional experience.
Cyber security certifications such as CISSP, CISA or CRISC will be highly regarded, while specialist vendor risk or penetration testing certifications are advantageous.

If your strength sits at the intersection of cybersecurity, governance and risk, and you enjoy translating security requirements into practical business outcomes, we’d like to hear from you.

Apply now for a confidential discussion.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available