At a Glance
- Tasks: Support the CISO in managing information security risks across business streams.
- Company: Join a leading firm dedicated to information security and risk management.
- Benefits: Competitive salary, professional development, and a collaborative work environment.
- Other info: Dynamic role with opportunities for growth and learning in a supportive team.
- Why this job: Make a real impact on information security while developing your skills.
- Qualifications: Knowledge of information security frameworks and strong communication skills required.
The predicted salary is between 40000 - 50000 € per year.
The Business Information Risk Analyst’s (BIRA) role is responsible for supporting the Chief Information Security Office (CISO) service to BDO’s business streams to effectively manage information security risk. The role will play a key part in ensuring the effectiveness of BDO’s information security risk management framework, procedures, and information security controls. The BIRA role is a focal point for effective engagement between business streams and the CISO team. It is a trusted adviser to business stakeholders and provides broad knowledge of the firm’s security strategies, policies, standards, processes, and road maps to enable streams to understand and meet information security requirements. The BIRA will assess information security risk with the business and ensure that those risks are being managed by the risk owners. Decisions to accept, reduce, share, or avoid risks are communicated to appropriate visibility and governance committees. This role reports to a Business Information Risk Officer (BIRO).
Principal accountabilities:
- Utilise BDO’s information security risk management tools, procedures and control framework to understand and manage risk posture for each business stream.
- Maintain and monitor the Risk Register to ensure actions are appropriate, completed by agreed target dates and engage regularly with stakeholders.
- Support the business streams to identify and maintain registers of information assets including infrastructure, systems, software, devices and data.
- Build and maintain effective relationships with risk owners, risk managers and other stream stakeholders.
- Develop collateral and appropriate materials to support engagement with business stakeholders, explain key information security concepts and build awareness of information security risk and BDO’s control framework.
- Proactively identify and support risk owners and managers to manage and review IS risks and issues for streams.
- Support the business to assess the criticality of assets and services.
- Ensure that BDO policy and contractual obligations, and in turn compliance, is understood for each business stream.
- Identify and communicate metrics and reporting requirements to stakeholders that demonstrate security controls are effective.
- Support creation of corrective actions and plans to manage improvement or change where necessary.
- Creation and maintenance of a “security toolkit” with templates of key processes and controls, communicated in language that is relevant and understandable to all audiences.
- Provide targeted security awareness, education, and risk briefings.
- Support the delivery of supplier security and client security due diligence activities.
- Assist with maintenance of the knowledge base of common information security questions and responses to ensure timely and accurate responses to the business.
- Manage workload via Azure DevOps ensuring tasks allocated to the analyst are completed within agreed timeframes and progress is reported to owners of the outcomes.
- Proactively identify and escalate any factors that may impact the time, cost, or quality of allocated outcome before the impact is experienced by ensuring communication is clear and effective at all stages of the deliverable to the outcome owners.
Knowledge & experience:
- Knowledge and experience of information security risk management frameworks and procedures.
- Experience of applying formal risk identification, assessment, and quantification methods.
- Experience of stakeholder engagement and management to achieve defined outcomes.
- Highly self‑motivated with keen attention to detail.
- The ability to build good relationships at all levels and influence stakeholders.
- Excellent verbal, written and interpersonal communication skills. Ability to communicate technical subjects to both technical and non‑technical audiences, flexing style to suit the needs of the audience.
- Ability to work with others effectively, with third parties, internal teams, promoting knowledge sharing within and across teams.
- Good understanding of security frameworks including ISO27001/2, Cyber Essentials Plus, CIS Top 20, Data Protection Act 2018, OWASP Top 10.
- Have or be working towards relevant industry certification such as CISSP, CISM, CRISC or similar.
- Good understanding of governance and decision making in complex organisations.
- Knowledge and experience of continuous improvement processes and approaches.
- Experience of documenting, developing and improving information security processes and procedures.
Personal characteristics:
- Strong team player able to collaborate effectively with colleagues and management while exhibiting initiative and independence.
- Good analytical skills with a proactive approach to problem solving.
- Good presentational & information sharing skills.
- Demonstrated ability to prioritise and manage competing work assignments in a time‑sensitive environment on own initiative and in consultation with people management.
- Keen to learn and develop existing information security skills and take ownership of own learning and development with support from the wider team and the firm.
Business Information Risk Analyst in London employer: BDO UK LLP
BDO is an exceptional employer that prioritises employee growth and development, offering a collaborative work culture where innovation and security are at the forefront. As a Business Information Risk Analyst, you will have the opportunity to engage with diverse business streams, enhancing your skills in information security risk management while contributing to a vital aspect of our operations. With a commitment to continuous improvement and a supportive environment, BDO ensures that every team member can thrive and make a meaningful impact.
StudySmarter Expert Advice🤫
We think this is how you could land Business Information Risk Analyst in London
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. The more you engage, the better your chances of landing that Business Information Risk Analyst role.
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of information security frameworks like ISO27001 and Cyber Essentials Plus. We want you to be able to chat confidently about these topics when they come up!
✨Tip Number 3
Showcase your soft skills! Being a great communicator and team player is key in this role. Think of examples from your past experiences where you've successfully engaged with stakeholders or managed risks.
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are proactive about their job search.
We think you need these skills to ace Business Information Risk Analyst in London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience with information security risk management frameworks. We want to see how your skills align with the BIRA role, so don’t hold back on showcasing relevant projects or achievements!
Showcase Your Communication Skills:Since this role involves engaging with various stakeholders, it’s crucial to demonstrate your excellent verbal and written communication skills. Use clear examples in your application that show how you've effectively communicated complex information to different audiences.
Highlight Your Analytical Skills:We’re looking for someone with strong analytical skills and a proactive approach to problem-solving. In your application, share specific instances where you’ve identified risks or improved processes, as this will really resonate with us.
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re keen to join the StudySmarter team!
How to prepare for a job interview at BDO UK LLP
✨Know Your Risk Management Frameworks
Familiarise yourself with key information security risk management frameworks like ISO27001/2 and Cyber Essentials Plus. Be ready to discuss how these frameworks apply to the role and how you can leverage them to support BDO’s business streams.
✨Engage Stakeholders Effectively
Prepare examples of how you've successfully engaged with stakeholders in the past. Highlight your ability to communicate complex security concepts in a way that resonates with both technical and non-technical audiences, as this will be crucial in your role.
✨Showcase Your Analytical Skills
Be prepared to demonstrate your analytical skills through real-life scenarios. Discuss how you've identified, assessed, and managed risks in previous roles, and how you can apply those experiences to improve BDO's risk posture.
✨Demonstrate Continuous Improvement Mindset
Talk about your experience with continuous improvement processes. Share specific examples of how you've documented and improved information security processes, and express your eagerness to learn and develop within the field.