Information Security Risk Analyst & Strategic Partner in City of Westminster

Information Security Risk Analyst & Strategic Partner in City of Westminster

City of Westminster Full-Time 40000 - 50000 £ / year (est.) Home office (partial)
B

At a Glance

  • Tasks: Support BDO's Chief Information Security Office in managing information security risks.
  • Company: Join BDO, a leading accountancy and business advisory firm.
  • Benefits: Flexible working, career development, and a supportive team culture.
  • Other info: Collaborative environment with opportunities for continuous learning and growth.
  • Why this job: Make a real impact on businesses while enhancing your information security skills.
  • Qualifications: Knowledge of information security frameworks and strong communication skills required.

The predicted salary is between 40000 - 50000 £ per year.

We’re BDO, an accountancy and business advisory firm, providing the advice and solutions entrepreneurial organisations need to navigate today’s changing world. We work with ambitious, entrepreneurially-spirited and high-growth businesses that fuel the economy and directly advise the owners and management teams that lead them.

The Quality and Risk Management Team (QRMT) at BDO comprises several sub-teams including the Legal Team, Enterprise Risk Management, Economic Crime, Quality Management, Ethics and Independence, and Advisory and Compliance. It provides Partners and staff with the guidance, tools and support to enable them to identify and manage quality and risk issues.

The Business Information Risk Analyst’s (BIRA) role is responsible for supporting the Chief Information Security Office (CISO) service to BDO’s business streams to effectively manage information security risk. This role will play a key part in ensuring the effectiveness of BDO’s information security risk management framework, procedures, and information security controls.

Your principal accountabilities will be:

  • Utilising BDO’s information security risk management tools, procedures and control framework to ensure an accurate risk & control posture is understood and managed for each business stream.
  • Maintain the Risk Register and monitor it to ensure that actions are appropriate for the risk and completed by the agreed target dates by engaging regularly with stakeholders.
  • Support the business streams to identify and maintain registers of information assets including infrastructure, systems, software, devices and data.
  • Build and maintain effective relationships with the risk owners, risk managers and other stream stakeholders.
  • Develop collateral and appropriate materials to support engagement with business stakeholders, to explain key information security concepts and build awareness of information security risk and BDO’s control framework.
  • Proactively identify and support risk owners and managers to manage and regularly review IS risks and issues for streams.
  • Ensure that BDO policy and contractual obligations, and in turn compliance, is understood for each business stream.
  • Identify and communicate metrics and reporting requirements to stakeholders that demonstrate security controls are effective.
  • Support creation of corrective actions and plans to manage improvement or change where necessary.
  • Creation and maintenance of a “security toolkit” with templates of key processes and controls, communicated in language that is relevant and understandable to all audiences.
  • Provide targeted security awareness, education, and risk briefings.
  • Support the delivery of supplier security and client security due diligence activities.
  • Assist with maintenance of the knowledge base of common information security questions and responses to ensure responses to the business are timely and accurate.
  • Manage workload via AzureDevOps (ADO) ensuring that tasks allocated to you are completed within agreed timeframes and progress/completion is reported to the owners of the outcomes.
  • Proactively identify and escalate any factors that may impact the time, cost, or quality of allocated outcome before the impact is experienced.

You’ll be someone with:

  • Knowledge and experience of information security risk management frameworks and procedures.
  • Experience of applying formal risk identification, assessment, and quantification methods.
  • Experience of stakeholder engagement and management to achieve defined outcomes.
  • Excellent verbal, written and interpersonal communication skills.
  • A good understanding of security frameworks including ISO27001/2, Cyber Essentials Plus, CIS Top 20, Data Protection Act 2018, OWASP Top 10.
  • Good understanding of governance and decision making in complex organisations.
  • Experience of documenting, developing and improving information security processes and procedures.

You’ll be able to be yourself; we’ll recognise and value you for who you are and celebrate and reward your contributions to our business. We’re committed to agile working, and we offer everyone the opportunity to work in ways that suit them, their teams, and the task at hand.

At BDO, we’ll help you achieve your personal goals and career ambitions, and we have programmes, resources, and frameworks that provide clarity and structure around career development.

Mutual support and respect is one of BDO’s core values and we’re proud of our distinctive, people-centred culture. Our agile working framework helps us stay connected, bringing teams together where and when it counts so they can share ideas and help one another.

We know that collaboration is the key to creating value and satisfying experiences at work, so we’ve invested in state-of-the-art collaboration spaces in our offices. BDO’s people represent a wealth of knowledge and expertise, and we’ll encourage you to build your network, work alongside others, and share your skills and experiences.

We’re looking forward to the future at BDO, helping entrepreneurial businesses to succeed, fuelling the UK economy. Our success is powered by our people, which is why we’re always finding new ways to invest in you.

Information Security Risk Analyst & Strategic Partner in City of Westminster employer: BDO LLP

At BDO, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation. Our commitment to employee growth is evident through tailored career development programmes and a supportive environment that values individual contributions. Located in the heart of the UK, our state-of-the-art facilities and agile working framework ensure that you have the resources and flexibility needed to thrive in your role as an Information Security Risk Analyst.

B

Contact Details:

BDO LLP Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Risk Analyst & Strategic Partner in City of Westminster

Tip Number 1

Network like a pro! Reach out to people in the industry, attend events, and connect with BDO employees on LinkedIn. Building relationships can open doors that applications alone can't.

Tip Number 2

Prepare for interviews by researching BDO’s values and recent projects. Show them you’re not just another candidate; you’re genuinely interested in their mission and how you can contribute.

Tip Number 3

Practice your communication skills. You’ll need to explain complex security concepts clearly, so get comfortable discussing technical topics in a way that anyone can understand.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining the BDO team.

We think you need these skills to ace Information Security Risk Analyst & Strategic Partner in City of Westminster

Information Security Risk Management
Stakeholder Engagement
Risk Identification and Assessment
ISO 27001/2
Cyber Essentials Plus
CIS Top 20
Data Protection Act 2018

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the Information Security Risk Analyst role. Highlight your relevant experience and skills that align with BDO's needs, especially in risk management frameworks and stakeholder engagement.

Showcase Your Communication Skills:Since this role involves collaborating with various stakeholders, demonstrate your excellent verbal and written communication skills. Use clear and concise language in your application to show you can explain complex security concepts to different audiences.

Highlight Your Proactive Approach:BDO values self-motivated individuals who can manage their own tasks. In your application, share examples of how you've taken initiative in previous roles, particularly in identifying and managing information security risks.

Apply Through Our Website:We encourage you to submit your application through our website. This ensures it reaches the right people and gives you a chance to explore more about BDO and our culture while you're at it!

How to prepare for a job interview at BDO LLP

Know Your Stuff

Make sure you have a solid understanding of information security risk management frameworks and procedures. Brush up on ISO27001/2, Cyber Essentials Plus, and other relevant standards. Being able to discuss these confidently will show that you're serious about the role.

Engage with Stakeholders

Prepare to talk about your experience in stakeholder engagement and management. Think of examples where you've successfully collaborated with others to achieve defined outcomes. This is key for the BIRA role, so be ready to share how you build relationships and influence decisions.

Show Your Analytical Skills

Be prepared to demonstrate your analytical skills and proactive problem-solving approach. Think of specific instances where you've identified risks and implemented solutions. This will highlight your ability to manage competing work assignments effectively.

Communicate Clearly

Practice explaining technical concepts in simple terms. You’ll need to communicate with both technical and non-technical audiences, so being able to flex your communication style is crucial. Prepare some examples of how you've done this in the past.