Senior IT Cyber GR&C Analyst in London

Senior IT Cyber GR&C Analyst in London

London Full-Time No working from home possible
A

At a Glance

  • Tasks: Support IT governance, cyber risk assessments, and compliance activities in a dynamic environment.
  • Company: Join a leading global specialty (re)insurance business known for innovation and collaboration.
  • Benefits: Competitive salary, health benefits, and opportunities for professional growth.
  • Other info: Work with cutting-edge technology and develop your skills in a supportive team.
  • Why this job: Make a real impact on cyber security and risk management in a global setting.
  • Qualifications: Bachelor's degree in Cybersecurity or related field; 5 years' experience in IT governance or risk management.

Our client is a leading global specialty (re)insurance business, recognised for its innovative approach to underwriting and strong reputation across international markets. With operations spanning multiple locations, the business focuses on delivering bespoke insurance and reinsurance solutions across a diverse portfolio of specialty risks. Combining underwriting expertise, entrepreneurial thinking, and a collaborative culture, they continue to drive growth while investing in technology, talent, and operational excellence

PURPOSE OF THIS ROLE

The Senior IT Cyber Governance, Risk & Compliance Analyst will support the development, implementation and oversight of the organisation's IT governance, cyber risk and compliance activities. This role involves supporting IT and cyber risk assessments, compliance with relevant regulatory and control frameworks, audit activity, and the identification and tracking of vulnerabilities, control gaps and remediation actions across IT systems and processes. The Senior IT Cyber Governance, Risk & Compliance Analyst will work closely with internal stakeholders to help ensure that IT and cyber activities are aligned with regulatory expectations, internal policies and good practice.

KEY RESPONSIBILITIES

Compliance and Risk Management

  • Support compliance with applicable regulatory, IT, cyber and control frameworks, which may include DORA, ISO 27001, NIST CSF, SOX and Cyber Essentials.
  • Support the evaluation and management of IT, cyber, compliance and security risks across systems, processes and operations.
  • Monitor emerging technology, cyber and operational resilience risks to support proactive risk management and timely escalation.
  • Assist in preparing for and supporting regulatory inspections and internal, external and third-party audits.
  • Support the tracking of cyber risk remediation actions, including actions arising from risk assessments, assurance reviews, incidents, audits, control reviews and control improvement initiatives.
  • Support the maintenance of the cyber risk register, including the capture of risks, issues and remediation actions, and the preparation of updates for governance forums.
  • Support third-party and supplier security assurance activities, including security due diligence, assessment of supplier responses and tracking of supplier remediation actions.
  • Coordinate and evidence user access reviews and privileged access reviews with system owners and the business, supporting the move to tool-based access certification.
  • Perform first-line compliance monitoring and control checks against information security policies and standards, including the tracking of policy exceptions.

Policy & Procedure Development

  • Support the development, implementation and updating of IT risk, cyber security and compliance policies, standards and procedures to ensure alignment with legal, regulatory, control and sound practice requirements.
  • Maintain an up-to-date understanding of applicable regulatory requirements and help implement changes to comply with new or evolving regulations.
  • Assist in developing and delivering internal training and awareness on IT governance, cyber risk and compliance topics.

Reporting & Communication

  • Support the preparation of cyber risk, control and remediation reporting for management and governance forums.
  • Support the development and tracking of key performance indicators (KPIs) related to IT risk and compliance.
  • Support internal breach notification and escalation processes where required, in coordination with Legal, Data Protection and relevant stakeholders, including supporting regulatory reporting where appropriate.

SKILLS, QUALIFICATIONS AND EXPERIENCE

  • Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or a related field, or equivalent experience.
  • Relevant certifications such as CRISC, CISA, CISM, ISO 27001 or CISSP, or a willingness to undertake similar, are desirable.
  • Minimum of 5 years' experience in IT governance, risk management, cyber or information security, or a related role, with a strong knowledge of related control and compliance requirements.
  • Working knowledge of key technology areas, including infrastructure, applications, networking, cloud services, vulnerability management, incident management and access controls.
  • Experience supporting audit, regulatory or compliance activities, including evidence coordination, issue tracking and remediation follow-up. Experience with SOX compliance and ITGCs is desirable.
  • Experience in insurance or wider financial services, or another regulated environment, is desirable.
  • Excellent communication skills, with the ability to convey technical information to non-technical stakeholders.

#J-18808-Ljbffr

Senior IT Cyber GR&C Analyst in London employer: Avencia Talent Solutions Limited

Avencia Talent Solutions offers a dynamic and supportive work environment as a Finance Business Partner, where you will play a crucial role in driving financial insights and decision-making for a leading Corporate & Specialty Insurer. With a strong emphasis on employee growth and development, the company fosters a culture of collaboration and innovation, providing opportunities to enhance your financial acumen while working alongside experienced professionals in a global setting. Located in the UK and Ireland, this role not only allows you to contribute to meaningful projects but also to be part of a well-established organisation with over 120 years of industry experience.

A

Contact Details:

Avencia Talent Solutions Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior IT Cyber GR&C Analyst in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Avencia Talent Solutions Limited, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Avencia Talent Solutions Limited

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Avencia Talent Solutions Limited. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Senior IT Cyber GR&C Analyst in London

IT Governance
Cyber Risk Management
Compliance Frameworks (DORA, ISO 27001, NIST CSF, SOX, Cyber Essentials)
Risk Assessment
Audit Coordination
Vulnerability Management
Control Gap Identification

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Avencia Talent Solutions Limited insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Avencia Talent Solutions Limited that you’re committed to staying ahead in the game.

How to prepare for a job interview at Avencia Talent Solutions Limited

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Avencia Talent Solutions Limited to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Avencia Talent Solutions Limited.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.