Risk Lead

Cambridge
3 weeks ago
Create job alert

Risk Lead

Salary: £57,100 - £76,450

Location: Cambridge, Hybrid (2 days per week in the office)

Contract: Full time, permanent, 35 hours per week

Lead with Impact: Shape the Future of Risk Management and Assurance at Cambridge University Press & Assessment.

This is an exciting opportunity for an experienced Risk Lead to join a passionate and fast-paced Exam Technology department.

We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge, an institution which is respected across the globe for its long heritage and ethos of excellence.

About the role

As the Risk Lead, you will play a key role in leading risk management work across high-stakes exam products and services. You will manage risk assessment campaigns, assurance reviews, and contribute to the design and launch of new assessment products. The role involves collaborating with various stakeholders, ensuring governance and compliance, and acting as the Risk Champion.

The Risk Lead will maintain the strategic risk register and develop the ETO risk framework. The Lead role involves strengthening risk management practices across the department. As the Risk Lead you will engage with third-party investigations to ensure compliance. Building effective partnerships and facilitating discussions with stakeholders are also key responsibilities.

Key Responsibilities:

Leadership and Responsibility: Demonstrate a passion for risk management, leading by example and embodying CUP&A behaviours. Take ownership of risk guidelines and frameworks to manage risk within Exam Technology effectively.

Governance & Compliance: Engage with third-party investigations, ensuring compliance with external requirements. Lead ongoing risk assessment campaigns, assurance reviews, and risk reports.

Stakeholder Collaboration: Build trusted relationships with stakeholders, facilitate constructive discussions, and implement risk management processes across Exam Technology.

Communicating and Influencing: Communicate purposefully and clearly, simplifying complexities and influencing others to agree on prevention measures, controls, and solutions.

About you

We are looking for an experienced Risk Lead who can bring a wealth of knowledge and expertise to our team. You are a strategic and collaborative leader with a passion for excellence.

You will have a keen interest in enterprise risk management and how it can help an organisation deliver its strategy and objectives. This may come from a background in risk management, project management or assurance, or in working with senior decision-making functions in your organisation. Although a qualification in risk management is not required to apply for this role, we actively promote learning and development and will support you to develop your risk expertise.

Key skills and experience:

Risk Management Frameworks: familiarity with ISO 31000, NIST, and COSO.

Integrated Risk and Quality Management: knowledge of integrated processes.

Cybersecurity Principles: understanding of threat modelling, vulnerability assessment, and incident response.

Incident Management: knowledge of detection, response, recovery, and post-incident analysis.

Compliance and Regulatory Knowledge: awareness of external requirements and relevant laws like GDPR.

IT Infrastructure and Architecture: knowledge of networks, servers, databases, and cloud services.

The job offers an opportunity to lead our risk management efforts, shaping effective risk management across the Exam Technology and our Solutions teams, in a fast paced, regulated environment.

If you would like to know more about this opportunity and what will make you successful, please see the full job description attached to the bottom of this vacancy on our careers site.

Rewards and benefits

We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package, featuring family-friendly and planet-friendly benefits including:



28 days annual leave plus bank holidays

*

Private medical and Permanent Health Insurance

*

Discretionary annual bonus

*

Group personal pension scheme

*

Life assurance up to 4 x annual salary

*

Green travel schemes

We are a hybrid working organisation, and we offer a range of flexible working options from day one. We expect most hybrid-working colleagues to spend 40-60% of their time at their dedicated office or location. We will also consider other work arrangements if you wish to work more flexibly or require adjustments due to a disability.

Ready to pursue your potential? Apply now.

We review applications on an ongoing basis, with a closing date for all applications being 25th April although we may close it earlier if suitable candidates are identified. Interviews are scheduled to take place on week commencing 12th May.

Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry.

Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov uk website for guidance to understand your own eligibility based on the role you are applying for.

Why join us

Joining us is your opportunity to pursue potential. You'll belong to a collaborative team that's exploring new and better ways to serve students, teachers and researchers across the globe – for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration.

Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it's safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background.

We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities

Related Jobs

View all jobs

Security Risk Lead

Senior Physical Security Engineer / Consultant

Risk Manager

Risk and Compliance Manager - Leading top 100 law firm

Platform Lead Engineer

Security Architect

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Negotiating Your Cybersecurity Job Offer: Equity, Bonuses & Perks Explained

How to Secure Compensation That Reflects Your Value in the UK’s High-Stakes Cybersecurity Sector Introduction As cyber threats grow more sophisticated and frequent, cybersecurity professionals have never been more in demand. From thwarting ransomware attacks to architecting secure cloud infrastructures, mid‑senior cybersecurity experts play a critical role in safeguarding a company’s data and reputation. Thanks to this growing reliance on cybersecurity, employers in the UK are going above and beyond simple salary offers to attract the top echelon of talent. Although base salary remains a key component of any job offer, the broader package—encompassing equity, bonuses, and perks—can often surpass what you’d gain from a small bump in monthly pay. For cybersecurity specialists working in areas such as threat intelligence, incident response, penetration testing, or compliance, the complexity and risk mitigation you bring to the table is massive. Knowing how to negotiate the entire package ensures you are duly rewarded for keeping an organisation’s data, assets, and operations safe. In this guide, we’ll delve into every aspect of negotiating a cybersecurity job offer. Whether you’re pivoting to a mid‑senior role or cementing your expertise at an established security consultancy, understanding the full range of compensation elements will help you secure an offer that acknowledges the criticality of what you do. Let’s explore equity options, performance bonuses, and the perks that matter most, so you can come out of your next job negotiation confident that you’re getting more than just a salary.

Cyber Security Jobs in the Public Sector: Protecting the UK’s Digital Future

Cyber threats have grown exponentially in recent years, targeting both private businesses and government institutions. As technology becomes ever more embedded in daily life—managing everything from national security to healthcare records—the risk of cyber attacks also increases. In the UK public sector, where vital services and sensitive citizen data are at stake, cyber security has become a top priority. For professionals looking for a meaningful career at the intersection of technology, national security, and public service, cyber security jobs in the UK public sector present an exciting and fulfilling path. In this blog post, we’ll delve into why cyber security is so critical to government agencies, the most in-demand roles, the skills and qualifications required, and how to navigate the application process. By the end, you’ll have a clearer sense of how you can leverage your technical expertise to protect the nation’s digital infrastructure.

Contract vs Permanent Cybersecurity Jobs: Which Pays Better in 2025?

Cybersecurity has become one of the fastest-growing and most crucial fields in modern business. With high-profile breaches dominating headlines and the ongoing digital transformation exposing organisations to new threats, companies across the UK are competing to attract skilled cybersecurity professionals. Roles range from penetration testers (pen testers) and SOC (Security Operations Centre) analysts to compliance officers, cloud security architects, threat intelligence analysts, and CISOs (Chief Information Security Officers). As demand continues to surge, cybersecurity salaries have climbed accordingly, and businesses have turned to more flexible hiring practices. Alongside permanent employment, many professionals explore short-term day‑rate contracting or fixed-term contracts (FTCs), searching for the ideal balance of pay, job security, and growth opportunities. Which arrangement truly pays better in 2025—and which best aligns with your ambitions? In this article, we dive into the contract vs. permanent debate with a focus on cybersecurity roles. We will examine the current market, the structure of day‑rate vs. FTC vs. permanent positions, the pros and cons of each, and some hypothetical pay comparisons. By the end, you should have a clearer sense of which career path might suit your situation and goals—whether you are a seasoned specialist aiming for top rates, or an up-and-coming analyst seeking a stable environment to develop in.