Senior Information Risk Manager

Senior Information Risk Manager

Full-Time On-site
C

Cyber Security | Technology Risk | People Leadership

Office attendance: typically four days per week in Edinburgh City Centre

If you have the technical depth to challenge cyber security specialists and the judgement to explain risk clearly to senior leaders, this role offers both scope and room to grow.

We are recruiting an Information Risk Senior Manager to lead a specialist team within an established risk function.

The organisation is expanding its use of AI and other technologies and you will help it move forward with confidence by making sure security risks are understood, controls are tested and decisions are based on evidence.

The role offers a potential path towards broader information security leadership for someone who wants to build on strong technical experience.

The opportunity

You will lead a team covering information security risk, technology risk, data protection and emerging technology. The team already has experienced specialists. Your contribution will be to bring stronger technical challenge across cyber security and technology while setting priorities and developing the people around you.

This is a risk oversight role with close involvement in practical security decisions. You will need to understand how technology works, ask searching questions of operational teams and judge whether proposed controls will work in practice.

Key responsibilities

  • Lead and coach the Information Risk team, creating clear priorities across a broad portfolio of work.
  • Direct an assurance programme covering areas such as penetration testing, cyber resilience, cloud services, applications, access controls and third parties.
  • Challenge security findings and proposed actions, working closely with technical and operational specialists.
  • Maintain effective risk frameworks and policies, including arrangements supporting ISO 27001.
  • Assess the security implications of technology change and AI adoption.
  • Support cyber incident preparation and response, then use lessons learned to strengthen controls.
  • Present clear advice and reporting to senior stakeholders and governance forums.

About you

You will bring substantial experience in cyber security, information security or technology risk. You should be able to discuss technical issues credibly with security specialists, while explaining their business impact to people without a technical background.

Experience using NIST or a comparable structured security framework is important. You will also understand how to scope assurance work, assess the evidence it produces and decide where further action is needed.

You may already lead a team or be ready to take on broader leadership responsibility. Either way, you will be proactive, collaborative and comfortable making balanced decisions when the answer is not straightforward. Relevant experience could come from financial services, professional services or another organisation with complex technology and risk requirements.

Why consider this role?

You will inherit an experienced team, have meaningful influence over the approach to emerging technology risk and gain exposure to senior decision makers. There is also scope to develop towards a more senior information security leadership role over time.

The working pattern is typically four days per week in the office, with some flexibility discussed on a case by case basis.

#J-18808-Ljbffr

Senior Information Risk Manager employer: Change Recruitment

Join a dynamic consultancy firm that values its employees and fosters a supportive work culture. With competitive salaries, performance bonuses, and a robust pension scheme, this role offers not just a job but a pathway to long-term career development in an international setting. If you are organised and personable, this is the perfect opportunity to thrive in a professional environment while making a meaningful impact as the first point of contact for clients.

C

Contact Details:

Change Recruitment Recruitment Team