At a Glance
- Tasks: Lead the charge in managing cyber risk and translating it into business language.
- Company: Join Genius Sports, a forward-thinking company prioritising cybersecurity.
- Benefits: Enjoy a competitive salary, hybrid work options, and a focus on employee wellbeing.
- Other info: Collaborative office culture with opportunities for personal and professional growth.
- Why this job: Make a real impact by shaping security practices that protect the business.
- Qualifications: Experience in security risk management and strong communication skills are essential.
The predicted salary is between 60000 - 80000 ÂŁ per year.
Genius Sports is strengthening how it identifies, quantifies, and manages cyber risk across the enterprise. As Cyber Risk Manager, you will be the operational backbone of our security risk management practice, building the structures, language, and habits that enable the business to make informed, risk‑aware decisions related to cybersecurity every day. You will sit within the Information Security function and report directly to the VP of Cyber Security, working as a peer to the GRC Manager. Your mandate is broader: understanding and communicating security risk as a business issue, not just a technical or regulatory one. Your mission: translate the threat landscape into clear risk positions, drive consistent treatment and ownership across the enterprise, and build a security risk management capability that scales with Genius as it grows.
What you’ll do
- Build and Operate the Cyber Risk Program: Design and own processes for managing security risks in alignment with our broader enterprise risk management framework - defining how security risks are identified, assessed, prioritized, and tracked. Maintain and continuously evolve a security risk register that is actionable and business‑relevant, not a compliance artifact. Ensure security risk posture is visible, understood, and regularly reviewed at leadership level.
- Translate Security Risk into Business Language: Serve as the bridge between technical security findings and business decision‑makers, framing security risk in terms of operational, financial, and reputational impact. Prepare clear, concise security risk reporting for senior stakeholders and ExCo, including heat maps, trend analysis, and treatment status. Support board‑level reporting on cyber risk exposure alongside the CIO and VP of Cyber.
- Drive Risk Treatment and Accountability: Work with business and technology owners to ensure security risks have clear owners, agreed treatment plans, and tracked remediation timelines. Challenge and pressure‑test risk acceptance decisions, ensuring they are informed, documented, and time‑bound. Follow up on treatment commitments and elevate stalled or overdue risk items through the appropriate channels. Identify systemic security risk patterns and surface them as strategic priorities for the VP and CIO.
- Manage Third‑Party and Supply Chain Risk: Own the vendor and third‑party risk assessment process, ensuring critical suppliers are assessed proportionately and reviewed on a regular cycle. Work with Sourcing and Procurement to embed cyber risk criteria into vendor onboarding and contract renewal workflows. Maintain visibility of concentration cyber risk and dependency risk across key technology providers.
- Support Resilience and Incident Learning: Contribute to business continuity and disaster recovery planning from a cyber risk lens, ensuring recovery priorities reflect actual business risk. Participate in post‑incident reviews to identify systemic security risk and feed lessons learned back into the risk register. Support threat intelligence consumption and translate emerging threat actor activity into risk implications for the business.
- Partner Across the Security Function: Work closely with the GRC Manager to ensure compliance requirements are risk‑informed, and that audit findings translate into risk register updates. Collaborate with Security Operations and Engineering to understand the threat and vulnerability landscape and translate technical exposure into risk terms. Support the VP of Cyber Security in building a cohesive, integrated security function where risk, compliance, and operations reinforce each other.
What you’ll bring
- Working knowledge of security related standards and regulations including SOC 2, ISO 27001, global privacy laws.
- Ability to communicate risk credibly to both technical and non‑technical audiences, including senior executives.
- Experience building or maturing a security risk management program, not just operating within one.
- Comfortable challenging risk owners and holding the line on treatment accountability without being adversarial.
- Understanding the threat landscape and how external factors translate into business‑specific risk.
- Experience with third‑party risk management processes and vendor assessment methodologies.
- Hands‑on experience with GRC and risk register platforms, including Hyperproof or similar tools.
- A track record of automating risk reporting is a strong differentiator.
- Certifications such as CRISC, CISM, or CISSP are valued, but practical experience and business judgement matter more.
Benefits
We enjoy an office‑first culture and maximize opportunities to collaborate, connect and learn together. Our hybrid working models differ depending on your role and location. As well as a competitive salary and range of benefits, we’re committed to supporting employee wellbeing and helping you grow your skills, experience and career. Let us know when you apply if you need any assistance during the recruiting process due to a disability.
Cyber Risk Manager employer: Genius Sports Statistician Network
Contact Detail:
Genius Sports Statistician Network Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Risk Manager
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their approach to cyber risk management and be ready to discuss how your skills align with their needs. Show them you’re not just another candidate!
✨Tip Number 3
Practice your pitch! Be clear about your experience and how it relates to the role of Cyber Risk Manager. Use examples that highlight your ability to communicate risk in business terms, as this is key for the position.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who take the initiative to engage directly with us.
We think you need these skills to ace Cyber Risk Manager
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Cyber Risk Manager role. Highlight your experience with security risk management and how it aligns with our mission at Genius Sports. We want to see how you can translate technical jargon into business language!
Showcase Your Skills: Don’t just list your qualifications; demonstrate how you've applied them in real-world scenarios. Whether it's managing third-party risks or building a security risk program, we want to know how your skills can help us strengthen our cyber risk management.
Be Clear and Concise: When writing your application, keep it straightforward. Use clear language and avoid unnecessary jargon. We appreciate direct communication, especially when it comes to complex topics like cybersecurity risks.
Apply Through Our Website: We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team at Genius Sports!
How to prepare for a job interview at Genius Sports Statistician Network
✨Know Your Cyber Risk Landscape
Before the interview, dive deep into the current cyber risk landscape. Familiarise yourself with recent trends, threats, and how they impact businesses. This will help you articulate your understanding of security risks as a business issue, which is crucial for the role.
✨Speak Business, Not Just Tech
Practice translating technical security findings into business language. Prepare examples of how you've communicated risk in terms of operational, financial, and reputational impacts. This will show that you can bridge the gap between technical details and strategic decision-making.
✨Demonstrate Risk Management Experience
Be ready to discuss your experience in building or maturing a security risk management programme. Share specific instances where you've designed processes for managing security risks and how you've ensured accountability among risk owners.
✨Prepare for Scenario Questions
Expect scenario-based questions that test your ability to handle real-world situations. Think about how you would approach risk treatment, vendor assessments, or incident learning. Having structured responses will demonstrate your problem-solving skills and readiness for the role.