At a Glance
- Tasks: Lead cyber and IT risk management, ensuring effective communication and mitigation of risks.
- Company: Join Johnson Matthey, a global leader in sustainable technologies with over 13,000 employees.
- Benefits: Enjoy competitive pay, excellent pension contributions, 25 days annual leave, and flexible working options.
- Why this job: Be part of a mission-driven company making the world cleaner and healthier through innovation.
- Qualifications: Experience in cyber security, IT controls, and risk management is essential.
- Other info: Open to part-time and flexible working arrangements; inclusive culture prioritised.
The predicted salary is between 43200 - 72000 £ per year.
The Purpose of the Cyber & IT Risk Manager is to complement and enhance Johnson Matthey's cyber security and IT/OT risk posture by identifying, assessing, analysing and communicating IT and cyber-security risks, and both the existence and efficacy of controls relating to those risks. The role is responsible for ensuring that the organisation understands, prioritises and appropriately manages its cyber and IT risks, with clear ownership and action plans being defined and progressed.
Your responsibilities:
- Develop, implement, schedule and drive a cyber and IT risk management program which includes regular assessment, prioritisation, and review of remediation and mitigation activities, with clearly defined management ownership.
- Ensure that the risk management program is aligned with business priorities and risk appetite, assessing and clearly communicating those risks in a non-technical, easily digestible manner that ensures all stakeholders can make informed decisions on these risks.
- Ensure that risks are assessed, recorded and communicated at the appropriate level of detail for both the audience and their effective mitigation, including maintaining a clear view of the linkages to enterprise-level (principal) risks and what actions drive a reduction in those risks.
- Engage with senior leaders across both IT and business units to drive pragmatic action plans for mitigation, including supporting the development of business cases.
- Developing and maintaining risk management processes, procedures, and tools to ensure timely identification, assessment, and mitigation of risks.
- Own and manage the security impact assessment process, ensuring that JM gains early visibility of potential risks associated with proposed changes.
- Own and manage the third-party risk management process, ensuring an effective prioritisation and tiering model is in place to identify and assess third parties that pose the most significant risk to JM.
- Developing, maintaining and operating cyber and IT controls assurance processes, including being responsible for the JM ITGC framework and ensuring system owners understand their responsibilities.
- Conduct thorough assessments of control environments, systems, processes, and practices to identify control gaps, including those associated with audit actions, customer and stakeholder requirements.
- Act as point of contact and co-ordination for cyber and IT-related audits, ensuring accurate information is provided and collating inputs from relevant teams.
- Keep up to date with regulatory and legislative developments relating to cyber and IT, identifying and assessing any changes that are relevant to JM and developing recommendations and action plans, communicating these as necessary to senior management.
Requirements for the role:
- Experience and knowledge of cyber and IT controls and supporting associated audits.
- Technical and/or practical experience of cyber security controls/capabilities and relevant standards e.g. ISO27001.
- IT controls implementation and assurance, including but not limited to IT general controls.
- Enterprise software capabilities and technologies, including but not limited to ERP, CRM, enterprise operating systems (e.g. Windows/Linux).
- Relevant legislation such as NIS2, GDPR and Computer Misuse Act.
- Relevant industry standards such as MITRE and NIST.
- Risk management best practices.
- Demonstrable experience in technology security-related roles, with demonstrable experience of identifying and managing information security risks in complex or critical scenarios.
- IT and/or cyber-security risk management experience.
- Knowledge and experience of writing technical reports, documentation, policies and standards accurately and to designated timescales.
- Understanding of enterprise IT infrastructure and architectures.
How you will be rewarded:
We offer a competitive compensation and benefits package including bonus, excellent pension contributions and 25 days annual leave (varies for shift-based roles). At JM, an inclusive culture is integral to our values and ambitions for the future. We are committed to ensuring that everyone can bring their full self to work and thrive in their career.
Johnson Matthey is open for discussion on part time, job share and flexible working patterns.
Closing date for applications: This job advertisement will be posted for a minimum of 2 weeks, early application is advised.
For any queries or should you require any reasonable adjustments to support your application please contact us. To submit your application, please click the "Apply" button online. All applications are carefully considered and your details will be stored on our secure Application Management System.
Johnson Matthey respects your privacy and is committed to protecting your personal information. For more information about how your personal data is used please view our privacy notice.
Johnson Matthey Plc is an equal opportunities employer and positively encourages applications from suitably qualified and eligible candidates regardless of sex, race, disability, age, sexual orientation, marriage or civil partnership, pregnancy or maternity, religion or belief.
Cyber and IT Risk Manager in Royston, Hertfordshire employer: Johnson Matthey Plc
Contact Detail:
Johnson Matthey Plc Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber and IT Risk Manager in Royston, Hertfordshire
✨Tip Number 1
Familiarise yourself with the latest cyber security frameworks and standards, such as ISO27001 and MITRE. This knowledge will not only help you understand the role better but also demonstrate your commitment to staying updated in the field.
✨Tip Number 2
Network with professionals in the cyber security and IT risk management sectors. Attend industry events or webinars to connect with potential colleagues and learn about the latest trends and challenges in the field.
✨Tip Number 3
Prepare to discuss real-world scenarios where you've identified and managed IT risks. Having specific examples ready will showcase your practical experience and problem-solving skills during interviews.
✨Tip Number 4
Research Johnson Matthey's recent initiatives and projects related to cyber security and sustainability. Being knowledgeable about the company’s goals will allow you to tailor your discussions and show how you can contribute to their mission.
We think you need these skills to ace Cyber and IT Risk Manager in Royston, Hertfordshire
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Cyber and IT Risk Manager position. Tailor your application to highlight relevant experience in cyber security and risk management.
Highlight Relevant Experience: In your CV and cover letter, emphasise your experience with cyber security controls, risk management best practices, and any relevant technical skills. Use specific examples to demonstrate your ability to manage IT risks effectively.
Craft a Strong Cover Letter: Your cover letter should clearly articulate why you are a good fit for Johnson Matthey. Discuss your understanding of their mission and how your skills align with their goals, particularly in sustainable technologies and risk management.
Proofread Your Application: Before submitting, carefully proofread your CV and cover letter for any spelling or grammatical errors. A polished application reflects your attention to detail, which is crucial for a role focused on risk management.
How to prepare for a job interview at Johnson Matthey Plc
✨Understand the Cyber and IT Risk Landscape
Before your interview, make sure you have a solid grasp of the current cyber and IT risk landscape. Familiarise yourself with relevant standards like ISO27001 and legislation such as GDPR. This knowledge will help you demonstrate your expertise and show that you're proactive about staying informed.
✨Prepare for Scenario-Based Questions
Expect to face scenario-based questions that assess your problem-solving skills in real-world situations. Think of examples from your past experience where you've successfully identified and mitigated risks. Be ready to explain your thought process and the outcomes of your actions.
✨Communicate Clearly and Effectively
Since the role involves communicating complex risks to non-technical stakeholders, practice explaining technical concepts in simple terms. Use clear, concise language and avoid jargon. This will showcase your ability to bridge the gap between technical and business teams.
✨Showcase Your Collaborative Skills
The Cyber and IT Risk Manager role requires engaging with senior leaders and various teams. Prepare to discuss how you've successfully collaborated with others in previous roles. Highlight any experience you have in driving action plans and working across departments to achieve common goals.