Cybersecurity Risk Analyst

Cybersecurity Risk Analyst

Full-Time 50000 - 65000 £ / year (est.) Home office (partial)
Hard Rock Digital

At a Glance

  • Tasks: Join our team to protect cloud gaming infrastructure and customer data using AI-driven risk management.
  • Company: Hard Rock Digital, a leader in online gaming and entertainment.
  • Benefits: Flexible vacation, remote work options, and opportunities for personal growth.
  • Other info: Diverse and inclusive culture that values your unique perspective.
  • Why this job: Be at the forefront of cybersecurity and AI innovation in a dynamic environment.
  • Qualifications: 3-5 years in cybersecurity risk management with strong AI tool experience.

The predicted salary is between 50000 - 65000 £ per year.

Hard Rock Digital is a team focused on becoming the best online sportsbook, casino, and social gaming company in the world. We’re building a team passionate about learning, operating, and creating innovative products and technologies for millions of consumers. We care about each customer interaction, experience, behaviour, and insight and strive to ensure we always act authentically.

Rooted in the kindred spirits of Hard Rock and the Seminole Tribe of Florida, Hard Rock Digital taps into a brand known worldwide as a leader in gaming, entertainment, and hospitality. We’re bringing that legacy into the digital space.

We are seeking an experienced Cybersecurity Risk Analyst to join the Security Risk Management (SRM) team at a leading US online gaming platform. Reporting to the Director of SRM, this role is critical in protecting our cloud-based gaming infrastructure, customer data, and financial systems while ensuring compliance with gaming regulations and industry standards.

This role goes beyond traditional GRC. Our SRM team operates an AI-augmented Integrated Management System (IMS) built on ISO 27001 PDCA principles, where agentic AI tooling and its ecosystem of security skills are core to daily workflow. The ideal candidate brings strong risk management fundamentals and the ability to leverage AI tools to accelerate risk assessment, compliance evidence gathering, policy development, and executive reporting. We need someone who can hit the ground running with our AI-driven approach and actively identify new ways to apply AI across all SRM use cases.

This role is crucial for proactively managing technology risks and maintaining a strong security posture in an evolving threat landscape. The ideal candidate combines strong technical knowledge with business acumen and AI fluency to effectively communicate and manage risks across all organizational levels.

What You'll Do

  • Risk Assessment and Management
    • Conduct comprehensive risk assessments of cloud infrastructure, gaming applications, CI/CD pipelines, DevOps processes, payment processing systems, and all other aspects of internal technology operations.
    • Develop and maintain risk registers, threat models, vulnerability and threat management programs, and risk treatment plans across eight enterprise risk categories.
    • Perform quantitative and qualitative risk analysis using industry-standard methodologies (ISO 27005, ISO 31000, NIST RMF).
    • Evaluate third-party vendor security risks and assess supply chain vulnerabilities using structured TPRM frameworks.
    • Leverage AI tools to accelerate risk identification, analysis, and reporting workflows.
  • Risk Mitigation and Control Implementation
    • Develop and recommend risk mitigation strategies and security controls.
    • Collaborate with technical teams to implement security measures and monitor their effectiveness.
    • Track remediation efforts and verify risk reduction activities via GRC platform integrations.
    • Create and maintain risk metrics and key risk indicators (KRIs).
  • Compliance and Governance
    • Ensure alignment with regulatory and industry requirements including state-specific gaming regulations (GLI-19, GLI-33, GLI-GSF), ISO 27001, ISO 42001, PCI DSS v4.0, SOC 2, NIST CSF, and GDPR.
    • Support internal and external audits by gathering evidence, preparing documentation, and coordinating audit activities.
    • Maintain security policies, procedures, and risk management frameworks within the IMS.
    • Contribute to AI governance activities including AI service registry maintenance, Shadow AI detection, and ISO 42001 compliance.
    • Assist in developing and updating the organization's cybersecurity and AI governance strategy.
  • AI-Augmented Risk Operations
    • Use agentic AI tools with associated skills and agents as core productivity multipliers for risk analysis, policy drafting, compliance validation, and reporting.
    • Operate within a git-based Integrated Management System, using AI skills for tasks such as ISO evidence gathering, threat modelling, third-party risk assessment, and executive communication.
    • Identify opportunities to extend agentic automation by integrating new MCP servers and APIs into existing AI workflows.
    • Identify and develop new AI-driven approaches to SRM challenges, continuously exploring how AI can improve risk assessment accuracy, audit preparation efficiency, and compliance coverage.
  • Reporting and Communication
    • Prepare risk reports and dashboards for management, audit committees, and gaming regulators.
    • Present risk findings and recommendations to technical and non-technical audiences.
    • Document risk assessment methodologies and maintain assessment artifacts.
    • Provide risk-based guidance for security strategy decisions.
  • Incident Response and Business Continuity
    • Participate in security incidents for risk impact assessment and lessons learned.
    • Participate in site reliability incident response activities, particularly post-incident reviews.
    • Support business continuity and disaster recovery planning.
    • Conduct tabletop exercises and risk scenario planning.

What We're Looking For

  • Education
    • Bachelor's degree in Computer Science, Information Security, Technology Risk Management, or related field.
  • Experience
    • 3-5 years of experience in cybersecurity risk management, GRC, or IT audit within the technology industry.
    • Demonstrated experience with risk assessment methodologies and frameworks (ISO 27005, ISO 31000, NIST RMF).
    • Knowledge of security controls and their implementation across cloud environments.
    • Experience with GRC platforms (Vanta experience preferred).
    • Practical experience using AI/LLM tools in a professional security or risk management context.
  • AI and Technology Skills (Critical)
    • Demonstrated proficiency with AI coding assistants and agentic AI tools.
    • Ability to craft effective prompts and work iteratively with AI to produce high-quality risk assessments, policies, and compliance documentation.
    • Comfort working in a git-based workflow.
    • Understanding of AI governance concepts.
    • Familiarity with Model Context Protocol (MCP) or similar frameworks.
  • Technical Skills
    • Understanding of security technology concepts.
    • Familiarity with cloud security across major providers (AWS, Azure, GCP).
    • Knowledge of network protocols and security architectures.
    • Understanding of Zero Trust architecture principles.
    • Basic scripting abilities for automation.
    • Familiarity with REST APIs.
  • Soft Skills
    • Strong analytical and problem-solving abilities.
    • Excellent written and verbal communication skills.
    • Ability to translate technical risks into business impact.
    • Detail-oriented with strong organizational skills.
    • Ability to work independently and manage multiple projects simultaneously.
    • Strong interpersonal skills for stakeholder management.
    • Intellectual curiosity and a growth mindset.
  • Certifications (Preferred)
    • CRISC, CISA, CISSP, ISO 27001 Lead Implementer/Auditor, ISO 42001 familiarity, CompTIA Security+ or CySA+.
  • Additional Preferred Qualifications
    • Experience in online gaming, sports betting, or other regulated industry sectors.
    • Knowledge of gaming-specific compliance frameworks.
    • Experience with specific GRC platforms.
    • Experience building or contributing to AI governance programs.
    • Knowledge of emerging threats and threat intelligence.
    • Experience with DevSecOps and agile methodologies.

What We Offer

  • Flexible vacation allowance.
  • Remote or Hybrid Flexibility.
  • Innovative Environment.
  • Growth Opportunities.
  • Diverse and Inclusive.

We care deeply about every interaction our customers have with us, and trust and empower our staff to own and drive their experience. Our vision for our business and customers is built on fostering a diverse and inclusive work environment where, regardless of background or beliefs, you feel able to be authentic and bring all your talent into play.

Cybersecurity Risk Analyst employer: Hard Rock Digital

At Hard Rock Digital, we pride ourselves on being an exceptional employer that champions innovation and inclusivity. Our flexible work arrangements, whether remote or hybrid, empower employees to thrive while contributing to a dynamic team dedicated to redefining the online gaming experience. With a strong focus on personal and professional growth, we offer unique opportunities to engage with cutting-edge AI technologies in a supportive environment that values diverse perspectives.

Hard Rock Digital

Contact Details:

Hard Rock Digital Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cybersecurity Risk Analyst

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Show off your skills! Create a portfolio or a personal project that highlights your expertise in cybersecurity and AI tools. This will give you something tangible to discuss during interviews and set you apart from the crowd.

Tip Number 3

Prepare for the interview like it’s the big game! Research the company, understand their products, and be ready to discuss how your skills align with their needs. Practice common interview questions and think about how you can demonstrate your problem-solving abilities.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at Hard Rock Digital.

We think you need these skills to ace Cybersecurity Risk Analyst

Cybersecurity Risk Management
Risk Assessment Methodologies
ISO 27001
NIST RMF
AI Tools Proficiency
GRC Platforms Experience
Cloud Security Knowledge

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Cybersecurity Risk Analyst role. Highlight relevant experience and skills that match the job description, especially your knowledge of AI tools and risk management frameworks.

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your background makes you a perfect fit for our team. Don’t forget to mention your enthusiasm for AI-driven approaches!

Showcase Your Technical Skills:Be sure to include any technical skills that are relevant to the role, like your experience with GRC platforms or AI coding assistants. We want to see how you can leverage these tools in your work!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands and shows us you’re serious about joining our innovative team!

How to prepare for a job interview at Hard Rock Digital

Know Your AI Tools

Familiarise yourself with the AI tools mentioned in the job description, like agentic AI and coding assistants. Be ready to discuss how you've used these tools in your previous roles, as this will show your practical experience and understanding of their application in cybersecurity risk management.

Understand Risk Assessment Frameworks

Brush up on risk assessment methodologies such as ISO 27005 and NIST RMF. Prepare to explain how you've applied these frameworks in past projects, as demonstrating your knowledge here will be crucial for the role.

Prepare for Technical Questions

Expect technical questions related to cloud security, compliance regulations, and security controls. Review key concepts and be ready to provide examples of how you've tackled similar challenges in your previous positions.

Showcase Your Communication Skills

Since you'll need to translate technical risks into business impact, practice explaining complex concepts in simple terms. Think of examples where you've successfully communicated risk findings to non-technical stakeholders, as this will highlight your ability to bridge the gap between tech and business.