At a Glance
- Tasks: Support information security risk management and engage with business stakeholders.
- Company: Join BDO, a leading accountancy and business advisory firm.
- Benefits: Agile working, career development support, and a people-centred culture.
- Other info: Collaborative environment with opportunities for continuous learning and networking.
- Why this job: Make a real impact in managing information security for high-growth businesses.
- Qualifications: Knowledge of information security frameworks and strong communication skills.
The predicted salary is between 40000 - 50000 £ per year.
We’re BDO, an accountancy and business advisory firm, providing the advice and solutions entrepreneurial organisations need to navigate today’s changing world. We work with ambitious, entrepreneurially-spirited and high-growth businesses that fuel the economy and directly advise the owners and management teams that lead them.
The Quality and Risk Management Team (QRMT) at BDO comprises several sub-teams including the Legal Team, Enterprise Risk Management, Economic Crime, Quality Management, Ethics and Independence, and Advisory and Compliance. It provides Partners and staff with the guidance, tools and support to enable them to identify and manage quality and risk issues.
The Business Information Risk Analyst’s (BIRA) role is responsible for supporting the Chief Information Security Office (CISO) service to BDO’s business streams to effectively manage information security risk. This role will play a key part in ensuring the effectiveness of BDO’s information security risk management framework, procedures, and information security controls.
The BIRA will take responsibility for assessing information security risk with the business and ensure that those risks are being managed by the risk owners. Where decisions are made to accept, reduce, share or avoid, the BIRA will ensure appropriate visibility and governance committees are informed.
Your principal accountabilities will be:
- Utilising BDO’s information security risk management tools, procedures and control framework to ensure an accurate risk & control posture is understood and managed for each business stream.
- Maintain the Risk Register and monitor it to ensure that actions are appropriate for the risk and completed by the agreed target dates by engaging regularly with stakeholders.
- Support the business streams to identify and maintain registers of information assets including infrastructure, systems, software, devices and data.
- Build and maintain effective relationships with the risk owners, risk managers and other stream stakeholders.
- Develop collateral and appropriate materials to support engagement with business stakeholders, to explain key information security concepts and build awareness of information security risk and BDO’s control framework.
- Proactively identify and support risk owners and managers to manage and regularly review IS risks and issues for streams.
- Ensure that BDO policy and contractual obligations, and in turn compliance, is understood for each business stream.
- Identify and communicate metrics and reporting requirements to stakeholders that demonstrate security controls are effective.
- Support creation of corrective actions and plans to manage improvement or change where necessary.
- Creation and maintenance of a “security toolkit” with templates of key processes and controls, communicated in language that is relevant and understandable to all audiences.
- Provide targeted security awareness, education, and risk briefings.
- Assist with maintenance of the knowledge base of common information security questions and responses to ensure responses to the business are timely and accurate.
- Manage workload via AzureDevOps (ADO) ensuring that tasks allocated to you are completed within agreed timeframes and progress/completion is reported to the owners of the outcomes.
- Proactively identify and escalate any factors that may impact the time, cost, or quality of allocated outcome before the impact is experienced.
You’ll be someone with:
- Knowledge and experience of information security risk management frameworks and procedures.
- Experience of applying formal risk identification, assessment, and quantification methods.
- Experience of stakeholder engagement and management to achieve defined outcomes.
- Highly self-motivated with keen attention to detail.
- The ability to build good relationships at all levels and influence stakeholders.
- Excellent verbal, written and interpersonal communication skills.
- A good understanding of security frameworks including ISO27001/2, Cyber Essentials Plus, CIS Top 20, Data Protection Act 2018, OWASP Top 10.
- Have or be working towards relevant industry certification such as CISSP, CISM, CRISC or similar.
- Good understanding of governance and decision making in complex organisations.
- Knowledge and experience of continuous improvement processes and approaches.
- Experience of documenting, developing and improving information security processes and procedures.
You’ll be able to be yourself; we’ll recognise and value you for who you are and celebrate and reward your contributions to our business. We’re committed to agile working, and we offer everyone the opportunity to work in ways that suit them, their teams, and the task at hand.
At BDO, we’ll help you achieve your personal goals and career ambitions, and we have programmes, resources, and frameworks that provide clarity and structure around career development.
Mutual support and respect is one of BDO’s core values and we’re proud of our distinctive, people-centred culture. From informal success conversations to formal mentoring and coaching, we’ll support you at every stage in your career, whatever your personal and professional needs.
We know that collaboration is the key to creating value and satisfying experiences at work, so we’ve invested in state-of-the-art collaboration spaces in our offices. BDO’s people represent a wealth of knowledge and expertise, and we’ll encourage you to build your network, work alongside others, and share your skills and experiences.
We’re looking forward to the future at BDO, helping entrepreneurial businesses to succeed, fuelling the UK economy. Our success is powered by our people, which is why we’re always finding new ways to invest in you.
Business Information Risk Analyst in City of Westminster employer: BDO LLP
At BDO, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation. Our commitment to employee growth is evident through tailored career development programmes and a supportive environment that values individual contributions. Located in the heart of the UK, our state-of-the-art offices provide the perfect backdrop for you to thrive as a Business Information Risk Analyst, while working alongside talented professionals dedicated to helping entrepreneurial businesses succeed.
StudySmarter Expert Advice🤫
We think this is how you could land Business Information Risk Analyst in City of Westminster
✨Tip Number 1
Network like a pro! Reach out to current or former BDO employees on LinkedIn. Ask them about their experiences and any tips they might have for landing the Business Information Risk Analyst role. Personal connections can give you insights that no job description can.
✨Tip Number 2
Prepare for the interview by understanding BDO’s values and culture. They’re all about trust and collaboration, so think of examples from your past where you’ve demonstrated these qualities. Show them you’re not just a fit for the role, but for the team too!
✨Tip Number 3
Practice your communication skills! As a Business Information Risk Analyst, you’ll need to explain complex security concepts to non-technical stakeholders. Try explaining a technical topic to a friend or family member to refine your approach.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining BDO and ready to take that next step in your career.
We think you need these skills to ace Business Information Risk Analyst in City of Westminster
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter for the Business Information Risk Analyst role. Highlight your experience with information security risk management frameworks and any relevant certifications. We want to see how your skills align with what we’re looking for!
Showcase Your Communication Skills:Since this role involves engaging with various stakeholders, it’s crucial to demonstrate your excellent verbal and written communication skills. Use clear and concise language in your application to show us you can communicate complex ideas effectively.
Highlight Your Proactive Approach:We love candidates who take initiative! In your application, share examples of how you've proactively identified and managed risks in previous roles. This will help us see your problem-solving skills in action.
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re serious about joining our team at BDO!
How to prepare for a job interview at BDO LLP
✨Know Your Risk Management Frameworks
Familiarise yourself with key information security risk management frameworks like ISO27001/2 and Cyber Essentials Plus. Be ready to discuss how these frameworks apply to BDO's operations and how you can contribute to their effectiveness.
✨Showcase Your Stakeholder Engagement Skills
Prepare examples of how you've successfully engaged with stakeholders in the past. Highlight your ability to communicate complex technical concepts to both technical and non-technical audiences, as this will be crucial in your role as a Business Information Risk Analyst.
✨Demonstrate Proactive Problem Solving
Think of specific instances where you've identified risks or issues before they became problems. Discuss your approach to problem-solving and how you prioritise tasks, especially in time-sensitive environments, to show that you're self-motivated and detail-oriented.
✨Prepare for Scenario-Based Questions
Anticipate scenario-based questions related to risk assessment and management. Practice articulating your thought process on how you would handle various situations, ensuring you convey your analytical skills and proactive approach to managing information security risks.