Business Information Risk Analyst in London

Business Information Risk Analyst in London

London Full-Time 54000 - 66000 £ / year (est.) Home office (partial)
B

At a Glance

  • Tasks: Support information security risk management and engage with business stakeholders.
  • Company: Join BDO, a leading accountancy and advisory firm focused on entrepreneurial growth.
  • Benefits: Agile working, career development programmes, and a supportive culture.
  • Other info: Collaborative environment with opportunities for continuous learning and networking.
  • Why this job: Make a real impact in managing information security for ambitious businesses.
  • Qualifications: Knowledge of information security frameworks and strong communication skills.

The predicted salary is between 54000 - 66000 £ per year.

Ideas | People | Trust

We’re BDO. An accountancy and business advisory firm, providing the advice and solutions entrepreneurial organisations need to navigate today’s changing world.

We work with the companies that are Britain’s economic engine – ambitious, entrepreneurially-spirited and high-growth businesses that fuel the economy - and directly advise the owners and management teams that lead them.

We’ll broaden your horizons

The Quality and Risk Management Team (QRMT) at BDO comprises several sub-teams including the Legal Team, Enterprise Risk Management, Economic Crime, Quality Management, Ethics and Independence and Advisory and Compliance.

It provides Partners and staff with the guidance, tools and support to enable them to identify and manage quality and risk issues.

The QRMT is led by the Head of Quality and Risk Management Team, who is a partner who reports into the Head of Quality and Risk for the firm and sits on the BDO Leadership Team.

We’ll help you succeed

Leading organisations trust us because of the quality of our advice.

That quality grows from a thorough understanding of their business, and that understanding comes from working closely with them and building long‑lasting relationships.

You’ll be someone who is both comfortable working proactively and managing your own tasks, as well as confident collaborating with others and communicating regularly with senior managers, directors, and BDO’s partners to help businesses effectively.

You’ll be encouraged to identify and draw attention to opportunities for enhancing our delivery and providing additional services to organisations we work with.

Role Purpose

The Business Information Risk Analyst’s (BIRA) role is responsible for supporting the Chief Information Security Office (CISO) service to BDO’s business streams to effectively manage information security risk.

This role will play a key part in ensuring the effectiveness of BDO’s information security risk management framework, procedures, and information security controls.

The BIRA role is a focal point for effective engagement between business streams and the CISO team.

This role will be a trusted adviser to business stakeholders and provide broad knowledge of the firm’s security strategies, policies, standards, processes, and road maps to enable streams to understand and meet information security requirements.

The BIRA will take responsibility for assessing information security risk with the business and ensure that those risks are being managed by the risk owners.

Where decisions are made to accept, reduce, share or avoid, the BIRA will ensure appropriate visibility and governance committees are informed.

This role reports to a Business Information Risk Officer (BIRO).

  • In this busy and rewarding role your principal accountabilities will be:
  • Utilising BDO’s information security risk management tools, procedures and control framework to ensure an accurate risk & control posture is understood and managed for each business stream.
  • Maintain the Risk Register and monitor it to ensure that actions are appropriate for the risk and completed by the agreed target dates by engaging regularly with stakeholders.
  • Support the business streams to identify, and maintain registers of information assets including infrastructure, systems, software, devices and data.
  • Build and maintain effective relationships with the risk owners, risk managers and other stream stakeholders.
  • Develop collateral and appropriate materials to support engagement with business stakeholders, to explain key information security concepts and build awareness of information security risk and BDO’s control framework.
  • Proactively identify and support risk owners and managers to manage and regularly review IS risks and issues for streams.
  • Support the business to assess criticality of assets and services.
  • Ensure that BDO policy and contractual obligations, and in turn compliance, is understood for each business stream.
  • Identify and communicate metrics and reporting requirements to stakeholders that demonstrate security controls are effective.
  • Support creation of corrective actions and plans to manage improvement or change where necessary.
  • Creation and maintenance of a “security toolkit” with templates of key processes and controls, communicated in language that is relevant and understandable to all audiences.
  • Provide targeted security awareness, education, and risk briefings.
  • Support the delivery of supplier security and client security due diligence activities.
  • Assist with maintenance of the knowledge base of common information security questions and responses to ensure responses to the business are timely and accurate.
  • Manage workload via Azure Dev Ops (ADO) ensuring that tasks allocated to you are completed within agreed timeframes and progress/completion is reported to the owners of the outcomes.
  • Proactively identify and escape any factors that may impact the time, cost, or quality of allocated outcome before the impact is experienced by ensuring communication is clear and effective at all stages of the deliverable to the outcome owners.

You’ll be someone with

  • Knowledge & experience
  • knowledge and experience of information security risk management frameworks and procedures
  • Experience of applying formal risk identification, assessment, and quantification methods
  • Experience of stakeholder engagement and management to achieve defined outcomes
  • Highly self‑motivated with keen attention to detail
  • The ability to build good relationships at all levels and influence stakeholders
  • Excellent verbal, written and interpersonal communication skills.

Listens and communicates technical subjects to both technical and nontechnical audiences, flexes style to suit the needs of the audience

  • Ability to work with others effectively, with 3rd parties, internal teams, promoting knowledge sharing within and across teams
  • A good understanding of security frameworks including ISO27001/2, Cyber Essentials Plus, CIS Top 20, Data Protection Act 2018, OWASP Top 10
  • Have or be working towards relevant industry certification such as CISSP, CISM, CRISC or similar
  • Good understanding of governance and decision making in complex organisations
  • Knowledge and experience of continuous improvement processes and approaches
  • Experience of documenting, developing and improving information security processes and procedures
  • Personal characteristics
  • Strong team player able to collaborate effectively with colleagues and management while exhibiting initiative and independence
  • Good analytical skills with a proactive approach to problem solving
  • Good presentational & information sharing skills
  • Demonstrated ability to prioritise and manage competing work assignments in a time sensitive environment on own initiative and in consultation with people management
  • Keen to learn and develop existing information security skills and take ownership of own learning and development with support from the wider team and the firm

You’ll be able to be yourself; we’ll recognise and value you for who you are and celebrate and reward your contributions to our business.

We’re committed to agile working, and we offer everyone the opportunity to work in ways that suit them, their teams, and the task at hand.

At BDO, we’ll help you achieve your personal goals and career ambitions, and we have programmes, resources, and frameworks that provide clarity and structure around career development.

We’re in it together

Mutual support and respect is one of BDO’s core values and we’re proud of our distinctive, people‑centred culture.

From informal success conversations to formal mentoring and coaching, we’ll support you at every stage in your career, whatever your personal and professional needs.

Our agile working framework helps us stay connected, bringing teams together where and when it counts so they can share ideas and help one another.

At BDO, you’ll always have access to the people and resources you need to do your best work.

We know that collaboration is the key to creating value and satisfying experiences at work, so we’ve invested in state‑of‑the‑art collaboration spaces in our offices.

BDO’s people represent a wealth of knowledge and expertise, and we’ll encourage you to build your network, work alongside others, and share your skills and experiences.

With a range of multidisciplinary events and dedicated resources, you’ll never stop learning at BDO.

We’re looking forward to the future

At BDO, we help entrepreneurial businesses to succeed, fuelling the UK economy.

Our success is powered by our people, which is why we’re always finding new ways to invest in you.

Across the UK thousands of unique minds continue to come together to help companies we work with to achieve their ambitions.

We’ve got a clear purpose, and we’re confident in our future, because we’re adapting and evolving to build on our strengths, ensuring we continue to find the right combination of global reach, integrity and expertise.

We shape the future together with openness and clarity, because we believe in empowering people to think creatively about how we can do things better.

  • #LI-SS3
  • #J-18808-Ljbffr

Business Information Risk Analyst in London employer: BDO UK LLP

BDO UK LLP is an excellent employer, offering a dynamic work culture that prioritises professional growth and development within the privacy sector. Located in Greater Manchester, employees benefit from a collaborative environment where they can lead impactful projects, build strong client relationships, and enhance their expertise in data protection regulations. With a commitment to employee well-being and continuous learning, BDO UK LLP stands out as a rewarding place to advance your career.

B

Contact Details:

BDO UK LLP Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Business Information Risk Analyst in London

Join Compliance Communities

Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!

Attend Industry Conferences

Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.

Leverage Your University Career Services

If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.

Showcase Your Knowledge Online

Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like BDO UK LLP looking for candidates who are engaged and informed.

We think you need these skills to ace Business Information Risk Analyst in London

Information Security Risk Management
Risk Identification and Assessment
Stakeholder Engagement
Attention to Detail
Communication Skills
Relationship Building
ISO 27001/2

Some tips for your application 🫡

Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!

Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.

Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!

Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at BDO UK LLP. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!

How to prepare for a job interview at BDO UK LLP

Master the Regulations

Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!

Show Your Analytical Skills

Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!

Know Your Tools

Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!

Align with Company Culture

Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with BDO UK LLP’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!