At a Glance
- Tasks: Lead the charge in managing cyber risks and translating them into business language.
- Company: Join Genius Sports, a leader in sports data and technology.
- Benefits: Enjoy a competitive salary, hybrid work options, and a focus on employee wellbeing.
- Other info: Collaborative office culture with opportunities for professional growth.
- Why this job: Make a real impact by shaping cybersecurity strategies that protect the business.
- Qualifications: Experience in security risk management and strong communication skills are essential.
The predicted salary is between 60000 - 80000 ÂŁ per year.
Genius Sports is strengthening how it identifies, quantifies, and manages cyber risk across the enterprise. As Cyber Risk Manager, you will be the operational backbone of our security risk management practice, building the structures, language, and habits that enable the business to make informed, risk‑aware decisions related to cybersecurity every day. You will sit within the Information Security function and report directly to the VP of Cyber Security, working as a peer to the GRC Manager.
Your mandate is broader: understanding and communicating security risk as a business issue, not just a technical or regulatory one. Your mission is to translate the threat landscape into clear risk positions, drive consistent treatment and ownership across the enterprise, and build a security risk management capability that scales with Genius as it grows.
What you’ll do:
- Build and Operate the Cyber Risk Program: Design and own processes for managing security risks in alignment with our broader enterprise risk management framework - defining how security risks are identified, assessed, prioritized, and tracked. Maintain and continuously evolve a security risk register that is actionable and business‑relevant, not a compliance artifact. Ensure security risk posture is visible, understood, and regularly reviewed at leadership level.
- Translate Security Risk into Business Language: Serve as the bridge between technical security findings and business decision‑makers, framing security risk in terms of operational, financial, and reputational impact. Prepare clear, concise security risk reporting for senior stakeholders and ExCo, including heat maps, trend analysis, and treatment status. Support board‑level reporting on cyber risk exposure alongside the CIO and VP of Cyber.
- Drive Risk Treatment and Accountability: Work with business and technology owners to ensure security risks have clear owners, agreed treatment plans, and tracked remediation timelines. Challenge and pressure‑test risk acceptance decisions, ensuring they are informed, documented, and time‑bound. Follow up on treatment commitments and elevate stalled or overdue risk items through the appropriate channels. Identify systemic security risk patterns and surface them as strategic priorities for the VP and CIO.
- Manage Third‑Party and Supply Chain Risk: Own the vendor and third‑party risk assessment process, ensuring critical suppliers are assessed proportionately and reviewed on a regular cycle. Work with Sourcing and Procurement to embed cyber risk criteria into vendor onboarding and contract renewal workflows. Maintain visibility of concentration cyber risk and dependency risk across key technology providers.
- Support Resilience and Incident Learning: Contribute to business continuity and disaster recovery planning from a cyber risk lens, ensuring recovery priorities reflect actual business risk. Participate in post‑incident reviews to identify systemic security risk and feed lessons learned back into the risk register. Support threat intelligence consumption and translate emerging threat actor activity into risk implications for the business.
- Partner Across the Security Function: Work closely with the GRC Manager to ensure compliance requirements are risk‑informed, and that audit findings translate into risk register updates. Collaborate with Security Operations and Engineering to understand the threat and vulnerability landscape and translate technical exposure into risk terms. Support the VP of Cyber Security in building a cohesive, integrated security function where risk, compliance, and operations reinforce each other.
What you’ll bring:
- Working knowledge of security related standards and regulations including SOC 2, ISO 27001, global privacy laws.
- Ability to communicate risk credibly to both technical and non‑technical audiences, including senior executives.
- Experience building or maturing a security risk management program, not just operating within one.
- Comfortable challenging risk owners and holding the line on treatment accountability without being adversarial.
- Understanding the threat landscape and how external factors translate into business‑specific risk.
- Experience with third‑party risk management processes and vendor assessment methodologies.
- Hands‑on experience with GRC and risk register platforms, including Hyperproof or similar tools. A track record of automating risk reporting is a strong differentiator.
- Certifications such as CRISC, CISM, or CISSP are valued, but practical experience and business judgement matter more.
Benefits: We enjoy an office‑first culture and maximize opportunities to collaborate, connect and learn together. Our hybrid working models differ depending on your role and location. As well as a competitive salary and range of benefits, we’re committed to supporting employee wellbeing and helping you grow your skills, experience and career.
Let us know when you apply if you need any assistance during the recruiting process due to a disability.
Cyber Risk Manager in London employer: Genius Sports Statistician Network
Contact Detail:
Genius Sports Statistician Network Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Risk Manager in London
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their approach to cyber risk management and be ready to discuss how your skills align with their needs. Show them you’re not just another candidate!
✨Tip Number 3
Practice your pitch! Be clear about your experience and how it relates to the role of Cyber Risk Manager. Use examples that highlight your ability to communicate risk in business terms, as this is key for the position.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search.
We think you need these skills to ace Cyber Risk Manager in London
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Cyber Risk Manager role. Highlight your experience in security risk management and how it aligns with our mission at Genius Sports. We want to see how you can bring value to our team!
Showcase Your Communication Skills: Since you'll be translating technical jargon into business language, it's crucial to demonstrate your ability to communicate effectively. Use clear, concise language in your application to show us you can bridge the gap between tech and business.
Highlight Relevant Experience: Don’t forget to mention any hands-on experience you have with GRC and risk register platforms. If you've automated risk reporting or managed third-party risks, let us know! We love seeing practical experience that matches our needs.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows us you're keen on joining our team!
How to prepare for a job interview at Genius Sports Statistician Network
✨Know Your Cyber Risk Landscape
Before the interview, dive deep into the current cyber risk landscape. Familiarise yourself with recent trends, threats, and regulations like SOC 2 and ISO 27001. This will help you speak confidently about how these factors impact business decisions.
✨Translate Technical Jargon
Practice explaining complex security concepts in simple terms. You’ll need to bridge the gap between technical findings and business implications, so being able to communicate effectively with non-technical stakeholders is key.
✨Showcase Your Risk Management Experience
Be ready to discuss specific examples of how you've built or matured a security risk management programme. Highlight your hands-on experience with GRC tools and how you've automated risk reporting to make it more actionable.
✨Prepare for Scenario Questions
Expect scenario-based questions where you might need to challenge risk owners or propose treatment plans. Think through past experiences where you’ve had to navigate these situations and be prepared to share your thought process.