At a Glance
- Tasks: Lead cyber and IT risk management, ensuring effective communication and mitigation of risks.
- Company: Join Johnson Matthey, a global leader in sustainable technologies with over 13,000 employees.
- Benefits: Enjoy competitive pay, bonuses, excellent pension contributions, and 25 days annual leave.
- Why this job: Be part of a mission-driven company focused on making the world cleaner and healthier.
- Qualifications: Experience in cyber security controls, risk management, and technical report writing is essential.
- Other info: Flexible working options available; we value diversity and inclusion in our workplace.
The predicted salary is between 43200 - 72000 £ per year.
The Purpose of the Cyber & IT Risk Manager is to complement and enhance Johnson Matthey’s cyber security and IT/OT risk posture by identifying, assessing, analysing and communicating IT and cyber-security risks, and both the existence and efficacy of controls relating to those risks. The role is responsible for ensuring that the organisation understands, prioritises and appropriately manages its cyber and IT risks, with clear ownership and action plans being defined and progressed.
Your responsibilities:
- Develop, implement, schedule and drive a cyber and IT risk management program which includes regular assessment, prioritisation, and review of remediation and mitigation activities, with clearly defined management ownership.
- Ensure that the risk management program is aligned with business priorities and risk appetite, assessing and clearly communicating those risks in a non-technical, easily digestible manner that ensures all stakeholders can make informed decisions on these risks.
- Ensure that risks are assessed, recorded and communicated at the appropriate level of detail for both the audience and their effective mitigation, including maintaining a clear view of the linkages to enterprise-level (principal) risks and what actions drive a reduction in those risks.
- Ensure a clear risk hierarchy.
- Engage with senior leaders across both IT and business units to drive pragmatic action plans for mitigation, including supporting the development of business cases.
- Developing and maintaining risk management processes, procedures, and tools to ensure timely identification, assessment, and mitigation of risks.
- Own and manage the security impact assessment process, ensuring that JM gains early visibility of potential risks associated with proposed changes.
- Ensure that this process is linked to the wider risk management process, with appropriate visibility provided to relevant stakeholders.
- Own and manage the third-party risk management process, ensuring an effective prioritisation and tiering model is in place to identify and assess third parties that pose the most significant risk to JM.
- Ensure a clear third-party risk reporting capability is in place to enable JM to make appropriate decisions regarding its third-party risk profile.
- Developing, maintaining and operating cyber and IT controls assurance processes, including being responsible for the JM ITGC framework and ensuring system owners understand their responsibilities.
- Conduct thorough assessments of control environments, systems, processes, and practices to identify control gaps, including those associated with audit actions, customer and stakeholder requirements.
- Ensure effective action is taken to resolve any issues and identify root causes and remediations that can be addressed through continual improvement.
- Act as point of contact and co-ordination for cyber and IT-related audits, ensuring accurate information is provided and collating inputs from relevant teams.
- Keep up to date with regulatory and legislative developments relating to cyber and IT, identifying and assessing any changes that are relevant to JM and developing recommendations and action plans, communicating these as necessary to senior management.
Requirements for the role:
- Experience and knowledge of cyber and IT controls and supporting associated audits.
- Technical and/or practical experience of cyber security controls/capabilities and relevant standards e.g. ISO27001.
- IT controls implementation and assurance, including but not limited to IT general controls.
- Enterprise software capabilities and technologies, including but not limited to ERP, CRM, enterprise operating systems (e.g. Windows/Linux).
- Relevant legislation such as NIS2, GDPR and Computer Misuse Act.
- Relevant industry standards such as MITRE and NIST.
- Risk management best practices.
- Demonstrable experience in technology security-related roles, with demonstrable experience of identifying and managing information security risks in complex or critical scenarios.
- IT and/or cyber-security risk management experience.
- Knowledge and experience of writing technical reports, documentation, policies and standards accurately and to designated timescales.
- Understanding of enterprise IT infrastructure and architectures.
How you will be rewarded:
We offer a competitive compensation and benefits package including bonus, excellent pension contributions and 25 days annual leave (varies for shift-based roles). At JM, an inclusive culture is integral to our values and ambitions for the future. We are committed to ensuring that everyone can bring their full self to work and thrive in their career.
Cyber and IT Risk Manager employer: Johnson Matthey
Contact Detail:
Johnson Matthey Recruiting Team
globalrecruit@matthey.com
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber and IT Risk Manager
✨Tip Number 1
Familiarise yourself with the latest cyber security frameworks and standards, such as ISO27001 and NIST. This knowledge will not only help you understand the role better but also demonstrate your commitment to staying updated in a rapidly evolving field.
✨Tip Number 2
Network with professionals in the cyber security and IT risk management sectors. Attend industry events or webinars where you can meet potential colleagues or mentors who can provide insights into the company culture at Johnson Matthey and the specifics of the role.
✨Tip Number 3
Prepare to discuss real-world scenarios where you've identified and managed IT risks. Having concrete examples ready will showcase your practical experience and problem-solving skills, which are crucial for this position.
✨Tip Number 4
Research Johnson Matthey’s recent initiatives and projects related to sustainability and technology. Understanding their mission and how your role as a Cyber and IT Risk Manager fits into their goals will help you articulate your value during discussions.
We think you need these skills to ace Cyber and IT Risk Manager
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Cyber and IT Risk Manager position. Tailor your application to highlight relevant experience and skills that align with the job description.
Highlight Relevant Experience: In your CV and cover letter, emphasise your experience with cyber security controls, risk management, and any relevant audits. Use specific examples to demonstrate your ability to identify and manage information security risks.
Craft a Strong Cover Letter: Your cover letter should clearly articulate why you are a good fit for the role. Discuss your understanding of the company's mission and how your background in cyber security aligns with their goals, particularly in sustainable technologies.
Proofread Your Application: Before submitting, carefully proofread your CV and cover letter for any spelling or grammatical errors. A polished application reflects attention to detail, which is crucial for a role focused on risk management.
How to prepare for a job interview at Johnson Matthey
✨Understand the Cyber and IT Risk Landscape
Before your interview, make sure you have a solid grasp of the current cyber and IT risk landscape. Familiarise yourself with relevant standards like ISO27001 and industry frameworks such as MITRE and NIST. This knowledge will help you demonstrate your expertise and show that you're proactive about staying informed.
✨Prepare for Scenario-Based Questions
Expect to face scenario-based questions that assess your problem-solving skills in real-world situations. Think of examples from your past experience where you've identified and managed information security risks. Be ready to discuss the actions you took and the outcomes achieved.
✨Communicate Clearly and Effectively
Since the role involves communicating complex risks to non-technical stakeholders, practice explaining technical concepts in simple terms. Use clear, concise language and avoid jargon. This will showcase your ability to bridge the gap between technical and business teams.
✨Showcase Your Collaborative Skills
The Cyber and IT Risk Manager role requires engaging with senior leaders and various teams. Prepare to discuss how you've successfully collaborated with others in previous roles. Highlight any experience you have in driving action plans or developing business cases, as this will demonstrate your ability to work cross-functionally.