Business Information Risk Analyst
Business Information Risk Analyst

Business Information Risk Analyst

Full-Time 28800 - 48000 ÂŁ / year (est.) Home office (partial)
B

At a Glance

  • Tasks: Support information security risk management and engage with business stakeholders.
  • Company: Join BDO, a leading accountancy and business advisory firm.
  • Benefits: Agile working, career development programmes, and a supportive culture.
  • Why this job: Make a real impact on businesses while developing your skills in a dynamic environment.
  • Qualifications: Knowledge of information security frameworks and strong communication skills required.
  • Other info: Collaborative culture with opportunities for continuous learning and growth.

The predicted salary is between 28800 - 48000 ÂŁ per year.

We’re BDO, an accountancy and business advisory firm, providing the advice and solutions entrepreneurial organisations need to navigate today’s changing world. We work with the companies that are Britain’s economic engine – ambitious, entrepreneurially-spirited and high‑growth businesses that fuel the economy - and directly advise the owners and management teams that lead them.

The Quality and Risk Management Team (QRMT) at BDO comprises several sub‑teams including the Legal Team, Enterprise Risk Management, Economic Crime, Quality Management, Ethics and Independence and Advisory and Compliance. It provides Partners and staff with the guidance, tools and support to enable them to identify and manage quality and risk issues. The QRMT is led by the Head of Quality and Risk Management Team, who is a partner who reports into the Head of Quality and Risk for the firm and sits on the BDO Leadership Team.

The Business Information Risk Analyst’s (BIRA) role is responsible for supporting the Chief Information Security Office (CISO) service to BDO’s business streams to effectively manage information security risk. This role will play a key part in ensuring the effectiveness of BDO’s information security risk management framework, procedures, and information security controls. The BIRA role is a focal point for effective engagement between business streams and the CISO team. This role will be a trusted adviser to business stakeholders and provide broad knowledge of the firm’s security strategies, policies, standards, processes, and road maps to enable streams to understand and meet information security requirements.

The BIRA will take responsibility for assessing information security risk with the business and ensure that those risks are being managed by the risk owners. Where decisions are made to accept, reduce, share or avoid, the BIRA will ensure appropriate visibility and governance committees are informed. This role reports to a Business Information Risk Officer (BIRO).

Principal accountabilities:

  • Utilising BDO’s information security risk management tools, procedures and control framework to ensure an accurate risk & control posture is understood and managed for each business stream.
  • Maintain the Risk Register and monitor it to ensure that actions are appropriate for the risk and completed by the agreed target dates by engaging regularly with stakeholders.
  • Support the business streams to identify, and maintain registers of information assets including infrastructure, systems, software, devices and data.
  • Build and maintain effective relationships with the risk owners, risk managers and other stream stakeholders.
  • Develop collateral and appropriate materials to support engagement with business stakeholders, to explain key information security concepts and build awareness of information security risk and BDO’s control framework.
  • Proactively identify and support risk owners and managers to manage and regularly review IS risks and issues for streams.
  • Support the business to assess criticality of assets and services.
  • Ensure that BDO policy and contractual obligations, and in turn compliance, is understood for each business stream.
  • Identify and communicate metrics and reporting requirements to stakeholders that demonstrate security controls are effective.
  • Support creation of corrective actions and plans to manage improvement or change where necessary.
  • Creation and maintenance of a “security toolkit” with templates of key processes and controls, communicated in language that is relevant and understandable to all audiences.
  • Provide targeted security awareness, education, and risk briefings.
  • Support the delivery of supplier security and client security due diligence activities.
  • Assist with maintenance of the knowledge base of common information security questions and responses to ensure responses to the business are timely and accurate.
  • Manage workload via AzureDevOps (ADO) ensuring that tasks allocated to you are completed within agreed timeframes and progress/completion is reported to the owners of the outcomes.
  • Proactively identify and escalate any factors that may impact the time, cost, or quality of allocated outcome before the impact is experienced by ensuring communication is clear and effective at all stages of the deliverable to the outcome owners.

You’ll be someone with:

Knowledge & experience:

  • Knowledge and experience of information security risk management frameworks and procedures.
  • Experience of applying formal risk identification, assessment, and quantification methods.
  • Experience of stakeholder engagement and management to achieve defined outcomes.
  • Highly self‑motivated with keen attention to detail.
  • The ability to build good relationships at all levels and influence stakeholders.
  • Excellent verbal, written and interpersonal communication skills. Listens and communicates technical subjects to both technical and non‑technical audiences, flexes style to suit the needs of the audience.
  • Ability to work with others effectively, with 3rd parties, internal teams, promoting knowledge sharing within and across teams.
  • Good understanding of security frameworks including ISO27001/2, Cyber Essentials Plus, CIS Top 20, Data Protection Act 2018, OWASP Top 10.
  • Have or be working towards relevant industry certification such as CISSP, CISM, CRISC or similar.
  • Good understanding of governance and decision making in complex organisations.
  • Knowledge and experience of continuous improvement processes and approaches.
  • Experience of documenting, developing and improving information security processes and procedures.

Personal characteristics:

  • Strong team player able to collaborate effectively with colleagues and management while exhibiting initiative and independence.
  • Good analytical skills with a proactive approach to problem solving.
  • Good presentational & information sharing skills.
  • Demonstrated ability to prioritise and manage competing work assignments in a time sensitive environment on own initiative and in consultation with people management.
  • Keen to learn and develop existing information security skills and take ownership of own learning and development with support from the wider team and the firm.

We’re committed to agile working, and we offer everyone the opportunity to work in ways that suit them, their teams, and the task at hand. At BDO, we’ll help you achieve your personal goals and career ambitions, and we have programmes, resources, and frameworks that provide clarity and structure around career development.

Mutual support and respect is one of BDO’s core values and we’re proud of our distinctive, people‑centred culture. From informal success conversations to formal mentoring and coaching, we’ll support you at every stage in your career, whatever your personal and professional needs. Our agile working framework helps us stay connected, bringing teams together where and when it counts so they can share ideas and help one another.

At BDO, you’ll always have access to the people and resources you need to do your best work. We know that collaboration is the key to creating value and satisfying experiences at work, so we’ve invested in state‑of‑the‑art collaboration spaces in our offices. BDO’s people represent a wealth of knowledge and expertise, and we’ll encourage you to build your network, work alongside others, and share your skills and experiences. With a range of multidisciplinary events and dedicated resources, you’ll never stop learning at BDO.

At BDO, we help entrepreneurial businesses to succeed, fuelling the UK economy. Our success is powered by our people, which is why we’re always finding new ways to invest in you. Across the UK thousands of unique minds continue to come together to help companies we work with to achieve their ambitions. We’ve got a clear purpose, and we’re confident in our future, because we’re adapting and evolving to build on our strengths, ensuring we continue to find the right combination of global reach, integrity and expertise. We shape the future together with openness and clarity, because we believe in empowering people to think creatively about how we can do things better.

Business Information Risk Analyst employer: BDO UK LLP

At BDO, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation. Our commitment to employee growth is evident through tailored career development programmes and a supportive environment that values individual contributions. Located in the heart of the UK, our agile working framework and state-of-the-art collaboration spaces ensure that you have the resources and support needed to thrive as a Business Information Risk Analyst.
B

Contact Detail:

BDO UK LLP Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Business Information Risk Analyst

✨Tip Number 1

Network like a pro! Reach out to current employees at BDO on LinkedIn and ask about their experiences. A friendly chat can give you insider info and might even lead to a referral!

✨Tip Number 2

Prepare for the interview by understanding BDO’s values and how they align with your own. Be ready to share examples of how you've demonstrated these values in your past roles.

✨Tip Number 3

Showcase your problem-solving skills during interviews. Use the STAR method (Situation, Task, Action, Result) to explain how you've tackled challenges in the past, especially related to information security.

✨Tip Number 4

Don’t forget to follow up after your interview! A quick thank-you email reiterating your interest in the role can keep you top of mind for the hiring team.

We think you need these skills to ace Business Information Risk Analyst

Information Security Risk Management
Stakeholder Engagement
Risk Identification and Assessment
Communication Skills
ISO 27001/2
Cyber Essentials Plus
CIS Top 20
Data Protection Act 2018
OWASP Top 10
CISSP
CISM
CRISC
Analytical Skills
Problem-Solving Skills
Continuous Improvement Processes

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter for the Business Information Risk Analyst role. Highlight your experience with information security risk management frameworks and how it aligns with BDO's needs. We want to see how you can bring value to our team!

Showcase Your Communication Skills: Since this role involves engaging with various stakeholders, it's crucial to demonstrate your excellent verbal and written communication skills. Use clear and concise language in your application to show us you can explain complex concepts to both technical and non-technical audiences.

Highlight Your Proactive Approach: We love candidates who take initiative! In your application, share examples of how you've proactively identified and managed risks in previous roles. This will show us that you're not just reactive but can also drive improvements in our risk management processes.

Apply Through Our Website: Don't forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it gives you a chance to explore more about BDO and what we stand for.

How to prepare for a job interview at BDO UK LLP

✨Know Your Risk Management Frameworks

Before the interview, brush up on your knowledge of information security risk management frameworks like ISO27001/2 and Cyber Essentials Plus. Be ready to discuss how you've applied these in past roles or projects, as this will show your understanding of the key concepts BDO values.

✨Engage with Stakeholders

Prepare examples of how you've successfully engaged with stakeholders in previous positions. Highlight your ability to communicate complex technical subjects to both technical and non-technical audiences. This will demonstrate your interpersonal skills and your capability to build relationships, which is crucial for the Business Information Risk Analyst role.

✨Show Your Problem-Solving Skills

Think of specific instances where you've identified risks and implemented solutions. Be ready to discuss your analytical approach and how you prioritise tasks in a time-sensitive environment. This will showcase your proactive mindset and ability to manage competing assignments effectively.

✨Demonstrate Continuous Learning

BDO values personal development, so be prepared to talk about how you stay updated with industry trends and enhance your information security skills. Mention any relevant certifications you're pursuing, like CISSP or CISM, to show your commitment to growth and improvement in the field.

Business Information Risk Analyst
BDO UK LLP

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

B
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>