At a Glance
- Tasks: Lead security risk management strategy and mitigate operational risks.
- Company: Join Cambridge University Press & Assessment, a leading academic publisher.
- Benefits: Enjoy competitive salary, 28 days leave, private medical insurance, and flexible working.
- Why this job: Make a real impact in a collaborative environment focused on innovation.
- Qualifications: 5+ years in governance, risk, or compliance with relevant certifications.
- Other info: Diverse and inclusive workplace with excellent career growth opportunities.
The predicted salary is between 53300 - 71300 £ per year.
Join our organisation as a Security Risk Lead. Utilise your expertise and drive to safeguard operations in this impactful role.
We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge.
About the role
The Security Risk Lead plays a pivotal role by driving Cambridge University Press & Assessment's security risk management strategy. This position is responsible for identifying, assessing, and mitigating operational, financial, and strategic security risks across the organisation to ensure a resilient and compliant security framework.
Overseeing the Security Risk Manager, the Security Risk Lead will work closely with senior stakeholders to develop and embed risk management processes that align with the organisation's priorities. They will also take the lead on key initiatives to reduce the organisation's risk exposure, delivering critical risk insights and reports.
- Lead and improve the security risk management strategy, in line with Enterprise risk strategy, identifying, analysing, and evaluating risks that may affect the organisation.
- Implement controls to mitigate risks and ensure effective execution.
- Manage and support the Security Risk Manager.
- Prepare and present regular risk reports for senior management.
- Oversee the analysis and monitoring of risks, ensuring emerging risks are flagged.
- Ensure compliance with regulatory requirements.
- Monitor industry trends and best practices.
- Collaborate with the Head of Security GRC and teams to manage incidents and propose corrective actions.
- Provide risk management training and develop a risk-aware culture.
- Support the development of security risk policies and frameworks.
- Collect data for risk assessments and foster a collaborative risk management approach.
- Provide risk management input on key projects.
- Represent the organisation in industry forums.
This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition.
About You
We are looking for someone with extensive knowledge of security risk management frameworks and methodologies (e.g., ISO 31000, 27001, 27005, NIST) and regulatory requirements in the industry. The ideal candidate will have a relevant degree in Risk Management, Finance, Business, or a related field, or appropriate business experience, along with active CRISC or 27005 Risk Manager certification.
You should have a minimum of 5 years or demonstrated experience in a governance, risk, or compliance role within an information security context. Strong analytical and problem-solving abilities, excellent written and verbal communication skills, and proficiency in risk management software and MS Office Suite are essential. You should be detail-oriented with strong organisational and project management skills, and able to work well in a team-oriented environment and build relationships with stakeholders.
If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria:
- Design or implementation of parts of or all of a Risk Management Framework.
- Managed risks within an operational environment.
- Developed risk management recommendations for senior leadership.
- Managed and maintained a comprehensive risk management framework, including risks registers, control tracking, governance fora and reporting measures.
We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition.
Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route.
Rewards and benefits
We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package, featuring family-friendly and planet-friendly benefits including:
- 28 days annual leave plus bank holidays.
- Private medical and Permanent Health Insurance.
- Discretionary annual bonus.
- Group personal pension scheme.
- Life assurance up to 4 x annual salary.
- Green travel schemes.
Ready to pursue your potential? Apply now.
We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 17th April 2026. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after it closes.
If you are shortlisted and progressed through the stages, you can expect:
- A 15-minute screening call with the Hiring Manager.
- First stage virtual interview via MS Teams.
- You will be provided with a brief to complete a role-related task which will need to be returned by email in advance of your interview.
- Final stage interview: in-person at our offices in Cambridge.
If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs.
Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry.
We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter.
Why join us
Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration.
Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background. We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
Security Risk Lead in Cambridge employer: CAMBRIDGE UNIVERSITY PRESS & ASSESSMENT
Contact Detail:
CAMBRIDGE UNIVERSITY PRESS & ASSESSMENT Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Risk Lead in Cambridge
✨Tip Number 1
Network like a pro! Reach out to your connections in the security risk management field. Attend industry events or webinars, and don’t be shy about introducing yourself. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Prepare for those interviews! Research Cambridge University Press & Assessment thoroughly. Understand their security risk management strategies and think about how your experience aligns with their needs. Tailor your responses to show you’re the perfect fit.
✨Tip Number 3
Show off your skills! If you’ve got relevant certifications or have implemented risk management frameworks before, make sure to highlight these during your discussions. Concrete examples of your past successes can really set you apart from the competition.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining our team at Cambridge University Press & Assessment.
We think you need these skills to ace Security Risk Lead in Cambridge
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in security risk management. Use keywords from the job description to show that you understand what we're looking for.
Showcase Your Skills: Don’t just list your qualifications; demonstrate how your skills align with the role. If you've worked with frameworks like ISO 31000 or NIST, give examples of how you've applied them in real situations.
Be Clear and Concise: When writing your application, keep it straightforward. Use clear language and avoid jargon unless it's relevant. We want to see your communication skills shine through!
Apply Through Our Website: Remember to submit your application via our official online process. This helps us keep everything organised and ensures your application gets the attention it deserves!
How to prepare for a job interview at CAMBRIDGE UNIVERSITY PRESS & ASSESSMENT
✨Know Your Frameworks
Familiarise yourself with security risk management frameworks like ISO 31000 and NIST. Be ready to discuss how you've applied these in your previous roles, as this will show your expertise and understanding of the industry standards.
✨Prepare for Scenario Questions
Expect scenario-based questions that assess your problem-solving skills. Think of specific examples where you identified and mitigated risks, and be prepared to explain your thought process and the outcomes.
✨Engage with Stakeholders
Since the role involves collaboration with senior stakeholders, practice articulating how you would communicate risk insights effectively. Highlight your experience in building relationships and fostering a risk-aware culture within teams.
✨Showcase Your Analytical Skills
Be ready to demonstrate your analytical abilities during the interview. Bring examples of how you've used data to inform risk assessments or decision-making processes, and discuss any tools or software you’re proficient in.