Engineer the Quantum RevolutionYour expertise can help us shape the future of quantum computing at Oxford Ionics.

View Open Roles

First Line Security Risk Manager

eFinancialCareers
Greater London
4 weeks ago
Create job alert

First Line Security Risk ManagerFirst Line Security Risk Manager

Department: IT Operations

Employment Type: Permanent - Full Time

Location: UK - London

Reporting To: Kirsty Kelly

Description

We are seeking a proactive and experienced First Line Security Risk Manager to lead the implementation and management of information security risk practices across our organisation. In this role, you will be the first line of defense for security risk management and play a critical part in ensuring securityernance, policypliance, and operational risk ownership across business functions.

You will report directly to the Group CISO and work closely with business units, IT,pliance, and audit to ensure security risks are effectively identified, assessed, documented, and mitigated in line with our overall risk appetite.

About the role

The ideal manager for this position will lead and maintain the first line Information Security Risk Management function. Additionally, this person will be responsible for:

Conducting and documenting security risk assessments across systems, projects, and processes. Owning and managing the Group security risk register, ensuring timely updates, mitigation tracking, and escalation where required. Working closely with the 2nd line to manage security risks across the group. Supporting the Group CISO in risk reporting to executive stakeholders. Managing the exception to security policy process, including risk-based reviews, documentation, approvals, and renewals. Liaising with business stakeholders to assess and document residual risk where security standards cannot be met Supporting the creation, maintenance, and review of security policies and procedures to ensure alignment with regulatory, industry, and business requirements. Mapping security policies to procedures and controls to ensure clear operational accountability. Facilitating awareness andpliance of security policies across business units And many other security-related activities!


About you

The ideal candidate for this position will have:
Hands-on experience managing risk assessments, policy exceptions, andernance processes. Proven experience (minimum 5+ years) in security risk management, essential that this is within financial services or a regulated industry. Strong understanding of information security principles, standards (, ISO 27001, NIST), and regulatory requirements (, NYDFS, GDPR). Experience with risk and control frameworks (, IRAM2, FAIR, COBIT) essential. Working knowledge of global regulations: GDPR, DORA, APRA CPS 234, CCPA, etc. Strong familiarity with UK and international regulatory frameworks in the US, Europe and Australia. Adept at translatingplex regulatory or technical requirements into practical business-aligned risk management principles. Collaborative, adaptable, and capable of operating across time zones and cultures.
Core Values

Love what you do:
We show up each day ready to take on the world. Our passion and intensity set us apart and makes the difference to our colleagues, customers, brokers and carriers.

Challenge everything:
We're never afraid to question the way that things are done and we constantly challenge ourselves and others to makes things better.

Have fun, be good:
Insurance is a serious business, but we don't take ourselves too seriously. We make it fun to work at CFC, we wee all viewpoints, and we treat everyone how we would expect to be treated. Job ID cba87bca-06aa-41a3-a0eb-c7ff7cee668c

Related Jobs

View all jobs

Cyber Risk Consultant

Cyber Risk Consultant

Cyber Security Analyst

Cyber Security Analyst

Cybersecurity Trends 2025: A UK Hiring Outlook

Trainee Cyber Security Analyst Apprenticeship

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Pre-Employment Checks for Cyber Security Jobs: DBS, References & Right-to-Work and more Explained

The cyber security sector in the UK stands at the forefront of protecting national infrastructure, business operations, and personal data from increasingly sophisticated cyber threats. As organisations across all sectors recognise cyber security as a critical business function, employers are implementing the most rigorous pre-employment screening processes in the technology industry to ensure they recruit professionals capable of defending against advanced persistent threats and maintaining the highest standards of security and trustworthiness. Whether you're a penetration tester, security analyst, incident response specialist, or chief information security officer, understanding the comprehensive vetting requirements is essential for successfully advancing your career in this security-critical field. This detailed guide explores the extensive background checks and screening processes you'll encounter when applying for cyber security positions in the UK, from fundamental eligibility verification to the most stringent security clearance requirements and specialised threat intelligence assessments.

Why Now Is the Perfect Time to Launch Your Career in Cyber Security: The UK's Digital Defence Revolution

The United Kingdom faces an unprecedented cyber security challenge that presents an extraordinary career opportunity. With cyber attacks increasing by 300% year-on-year and the average cost of a data breach reaching £4.24 million, Britain urgently needs skilled cyber security professionals to defend its digital infrastructure, protect citizens' data, and maintain national security in an increasingly connected world. If you've been considering a career change or seeking to future-proof your professional trajectory, cyber security represents one of the most secure, well-compensated, and socially impactful career choices available. The convergence of escalating threats, skills shortage, government investment, and regulatory requirements has created a perfect storm of opportunity that shows no signs of abating.

Automate Your Cyber Security Jobs Search: Using ChatGPT, RSS & Alerts to Save Hours Each Week

Cyber roles drop across consultancies, MSSPs, hyperscalers, banks, gov & start-ups every day—often buried in ATS portals or duplicated across boards. The fix is simple: put discovery on autopilot with keyword-rich alerts, RSS feeds & a reusable ChatGPT workflow that triages listings, ranks fit, & tailors your CV in minutes. This copy-paste playbook is built for www.cybersecurityjobs.tech readers. It’s UK-centric, practical, & designed to save you hours each week. What You’ll Have Working In 30 Minutes A role & keyword map spanning SecOps/Detection, DFIR, AppSec, Cloud Security, GRC, Red Team, Threat Intel, IAM/PAM, OT/ICS & Vulnerability Management. Shareable Boolean search strings for Google & job boards to cut noise fast. Always-on alerts & RSS feeds delivering fresh roles to your inbox/reader. A ChatGPT “Cyber Job Scout” prompt that deduplicates, scores fit & outputs tailored actions. A simple pipeline tracker so deadlines & follow-ups never slip.