Shape the Future of AIJoin one of the UK's fastest-growing companies and become a Professional Development Expert in Artificial Intelligence.

View Roles

Cyber Risk Consultant

M&G
Stirling
3 weeks ago
Create job alert

At M&G our purpose is to give everyone real confidence to put their money to work. As an international savings and investments business with roots stretching back more than 170 years, we offer a range of financial products and services through Asset Management, Life and Wealth. All three operating segments work together to deliver attractive financial outcomes for our clients, and superior shareholder returns.

Through our behaviours of telling it like it is, owning it now, and moving it forward together with care and integrity; we are creating an exceptional place to work for exceptional talent.

We will consider flexible working arrangements for any of our roles and also offer work place accommodations to ensure you have what you need to effectively deliver in your role.

Overall Job Purpose

The M&G plc Risk & Compliance function, within the second line of defence, is responsible for effectively advising and challenging key stakeholders, challenging risks effectively and proactively, and adding value through providing enhanced business insights to ensure that risk is managed in line with the expectations of clients, shareholders and regulators, and to support the delivery of customers’ long term needs. The Cyber Risk Oversight VP reports to the Head of Technology Risk and Support Functions Oversight, M&G plc, and to the Director of Risk and Compliance, M&G Global. This role is primarily responsible for providing oversight of cyber security risk across M&G plc, including delivering a second line evaluation of the strength of first line security measures and controls. The role manages the planning and delivery of Red Team Cyber testing activities by qualified third parties, and provides effective end to end stakeholder engagement in relation to the findings made during these tests. The role is also responsible for developing and operating a second line model for delivering oversight of M&G’s cyber threat intelligence capability and techniques. The role works in close partnership with stakeholders across the business in Technology, Security, Non-Financial Risk, external suppliers and with programme leads to ensure effective oversight of cyber risk across M&G plc. The role leads on facilitating the risk appetite statements relating to cyber security risks The role also supports the delivery of wider Risk and Compliance projects, strategic and management activities, business development and digital initiatives.

Responsibilities

The key responsibilities of this role are to support the delivery of the Technology Risk team’s objectives to support the embedding of the technology risk framework across M&G plc in relation to cyber security risk, and to provide consolidated risk analysis and information for Senior Management as required. The role is required to:

Manage the planning, engagement and delivery of Red Team Cyber testing activities with appropriately qualified third party cyber specialists. Oversee and guide cyber security risk mitigation programmes, projects and control improvement initiatives, including the use of AI in enhancing cyber security. Assess first line processes and technical analysis of cyber security events and root cause, as well as remedial solutions, and provide a second line view on their effectiveness. Provide advice and guidance on compliance with regulatory requirements that relate to cyber risk and contribute to regulatory enquiries. Assess the effectiveness of processes and internal controls implemented by the first line, including the Security Operations Centre (SOC) and infrastructure functions, through a programme of a sampling to evaluate their quality and associated documentation, and provide feedback for action. Work closely with existing IT, security and business functions as well as collaborating with third parties and business partners, both to receive input and to provide practical and actionable intelligence. Nurture strong working relationships with stakeholders at functional levels. Manage the risk appetite statements for technology and digital risks in relation to cyber and provide reporting of performance against these statements using sampling methods. Develop and maintain high level Cyber Risk policy, embedding relevant Group, regulatory and industry good practice requirements. Participate in cyber incident response planning, testing, and execution when required. Participate in the annual programme of deep dive and thematic reviews, leading reviews where these relate to cyber across all business areas and outsourced service providers as may be required. Oversee the identification, assessment, processing, analysis, and reporting of tactical and strategic threat intelligence to assist in decision making and actively thwart emergent and current threats targeting our organisation. Contribute to the continuous improvement of the Technology Risk function. Identify and lead digital initiatives that deliver efficiencies and improved ways of working commensurate with best practices of FTSE 100 digitally enabled business. Ensure compliance to the people policies, Group Code of Conduct and embedding of desired behaviours, including completion of any mandatory training requirements. Being personally accountable for supporting the identification, assessment, management and reporting risks within your area of responsibility, including supporting formal risk management activities e.g. Risk & Control Self Assessments and timely closure of Assurance actions. Work flexibly in support of the wider Risk and Compliance agenda. Line management of a Risk professional in the Technology Risk team.

Key Interfaces

Internal:

M&G plc Risk and Compliance All M&G plc UK Business Areas and Senior Management Teams Internal Audit

External:

M&G plc Risk and Compliance All M&G plc UK Business Areas and Senior Management Teams Internal Audit

Experience and Skills

12+ yrs of relevant experience in in a Risk/Audit function/Big4 within a financial institution, directly delivering cyber security and cyber threat intelligence activities. Significant knowledge of Cybersecurity organization practices, risk management principles, architectural requirements, engineering threats and vulnerabilities, including incident response methodologies. Excellent stakeholder management skills, with the ability to successfully navigate a complex organisation as well as build strong relationships and work collaboratively with teams across the business. Knowledge of insurance / investment products, markets and competitors. Experience within financial services companies or consulting/technology companies supporting. financial services clients in cyber security and Technology risk (2LOD) functions. Experience in developing and embedding Cyber risk policies, setting Cyber risk appetite and embedding processes to assess performance against the same. Experience in managing a team of cyber/security specialists. Experience in leading reviews, where these relate to Cyber risk and understanding the lessons learnt. Delivery of gap analysis against Cyber Security policy, standards and technology risk requirements. Experience in developing, operating and maintaining a Cyber threat intelligence framework. Strong understanding of cyber security products and technologies utilized in Enterprise environments. Strong understanding of Cloud computing platforms, primarily Amazon AWS and Microsoft Azure. Experience as part of a security operations or incident response organization would be beneficial. Experience in investigating fraud and eCrime. Keen understanding of national and international laws, regulations, policies and ethics related to financial industry cybersecurity. Understanding of threat modelling techniques with some experience in developing threat models. Significant experience of reporting and presenting cyber risks and controls information with the wider business, regulatory and industry context, in a simple and effective way. Experience of authoring papers for Risk Committees and senior management teams. Knowledge of industry best practice and good network / links with individuals and external bodies. Curious and continually looking to seek out improvements and not just accepting the status quo. Ability to work collaboratively across immediate team and broader technology function whilst also being to work independently under own initiative. Strong drive and delivery, committed to achieving results and delivering on time. Strong analytical thinking and a critical evaluator of information/issues. Strong work ethic with the highest levels of professionalism, commitment and integrity. Gravitas and ability to be pragmatic where appropriate. Ability to operate remotely, in a diverse and multi-cultural environment with international work or consultancy exposure.

Education and Professional Qualifications

Graduate/Post-Graduate degree in Engineering, Information Technology or Computer Science Relevant Certification in Cyber Security and cloud such as CISSP, CISA, CISM

Experience Level: Manager/Expert

Recruiter: Helen Simons

We have a diverse workforce and an inclusive culture at M&G plc, underpinned by our policies and our employee-led networks who provide networking opportunities, advice and support for the diverse communities our colleagues represent. Regardless of gender, ethnicity, age, sexual orientation, nationality, disability or long term condition, we are looking to attract, promote and retain exceptional people. We also welcome those who take part in military service and those returning from career breaks.

M&G is also proud to be a , and we welcome applications from candidates with long-term health conditions, disabilities, or neuro-divergent conditions. Being a Disability Confident Leader means that candidates who meet the minimum criteria of a job, will be offered an interview if they 'opt in' to the scheme when applying.

If you need assistance or an alternative means of applying for a role due to a disability or additional need, please let us know by contacting us at:

Related Jobs

View all jobs

Cyber Risk Consultant

Senior Cyber Security Consultant

Security Consultant

Security Consultant

Cyber Security Consultant - Strategy, Engagement & Risk

DV Cleared OT Security Consultant

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Why Now Is the Perfect Time to Launch Your Career in Cyber Security: The UK's Digital Defence Revolution

The United Kingdom faces an unprecedented cyber security challenge that presents an extraordinary career opportunity. With cyber attacks increasing by 300% year-on-year and the average cost of a data breach reaching £4.24 million, Britain urgently needs skilled cyber security professionals to defend its digital infrastructure, protect citizens' data, and maintain national security in an increasingly connected world. If you've been considering a career change or seeking to future-proof your professional trajectory, cyber security represents one of the most secure, well-compensated, and socially impactful career choices available. The convergence of escalating threats, skills shortage, government investment, and regulatory requirements has created a perfect storm of opportunity that shows no signs of abating.

Automate Your Cyber Security Jobs Search: Using ChatGPT, RSS & Alerts to Save Hours Each Week

Cyber roles drop across consultancies, MSSPs, hyperscalers, banks, gov & start-ups every day—often buried in ATS portals or duplicated across boards. The fix is simple: put discovery on autopilot with keyword-rich alerts, RSS feeds & a reusable ChatGPT workflow that triages listings, ranks fit, & tailors your CV in minutes. This copy-paste playbook is built for www.cybersecurityjobs.tech readers. It’s UK-centric, practical, & designed to save you hours each week. What You’ll Have Working In 30 Minutes A role & keyword map spanning SecOps/Detection, DFIR, AppSec, Cloud Security, GRC, Red Team, Threat Intel, IAM/PAM, OT/ICS & Vulnerability Management. Shareable Boolean search strings for Google & job boards to cut noise fast. Always-on alerts & RSS feeds delivering fresh roles to your inbox/reader. A ChatGPT “Cyber Job Scout” prompt that deduplicates, scores fit & outputs tailored actions. A simple pipeline tracker so deadlines & follow-ups never slip.

10 Cyber Security Recruitment Agencies in the UK You Should Know (2025 Job‑Seeker Guide)

UK cyber security hiring remains resilient in 2025, driven by nation-state threats, cloud security investments, and NCSC regulatory pressures. Lightcast reports +42 % YoY growth in UK roles mentioning “SOC”, “cyber risk”, “offensive security” or “GRC”. Yet despite 30,000 active cyber professionals, monthly live vacancies remain in the 2,500–2,900 range. The result: strong demand across public and private sector. We reviewed 50 + consultancies and included only those that: Are registered in the UK (Companies House) Operate a dedicated Cyber Security / InfoSec / Risk & Compliance desk Posted at least 5 UK cyber security roles between March and June 2025 This guide includes 2025 salary ranges, key skills, interview prep tips, and a verified recruiter directory.