Cyber Security Risk & Controls Analyst in Aberdeen

Cyber Security Risk & Controls Analyst in Aberdeen

Aberdeen Full-Time 48234 - 58952 £ / year (est.) Home office (partial)
L

At a Glance

  • Tasks: Support cyber security risk management and improve controls across a global financial services team.
  • Company: Join Legal & General, a leading UK financial services group with a commitment to societal betterment.
  • Benefits: Enjoy competitive pay, generous holiday, healthcare, and flexible working options.
  • Other info: Be part of an inclusive culture that values diverse perspectives and career growth.
  • Why this job: Make a real impact in cyber security while developing your skills in a supportive environment.
  • Qualifications: Familiarity with security frameworks and experience in cyber security risk or governance.

The predicted salary is between 48234 - 58952 £ per year.

Legal & General (L&G) is a leading UK financial services group and major global investor. We’ve been safeguarding people’s financial futures since 1836, and strive to build a better society, while improving the lives of our customers and creating value for shareholders. We are one of the world’s largest asset managers and provide powerful asset origination capabilities. Together, these underpin our retirement and protection solutions: we are an international player in pension risk transfer, in UK and US life insurance, and in UK workplace pensions and retirement income. Our Group Functions provide the services that all areas of the business need. This requires a talented and diverse team behind the scenes, who enable everyone at L&G to do what they do best. Joining us means helping to improve the lives of our customers and contributing to the success of the business every day.

As a Cyber Security Risk and Controls Analyst you will support the execution and continuous improvement of risk and control activities within the first-line Global Cyber Security Risk and Controls Function. The role works closely with control owners, product teams, and risk partners to help ensure that risks are effectively identified, assessed, managed, and reported across areas such as third-party risks specific to technology, cyber security and information technology risk. The Cyber Security Risk and Controls Analyst provides hands-on support in the maintenance and assurance of controls, issue tracking, evidence gathering, and risk reporting. It drives control effectiveness, policy compliance and effective risk management across L&G globally.

What you’ll be doing:

  • Maintaining and monitoring key cyber security controls to ensure control performance is effective and appropriately evidenced for compliance, audit and assurance purposes.
  • Supporting the identification, management and closure of cyber security issues, audit actions and remediation plans to ensure timely resolution and control improvements.
  • Contributing to cyber security risk and control self-assessments (RCSAs), supplier assessments or thematic reviews to ensure accurate identification of control weaknesses, exposures and required enhancements.
  • Assisting in the application of cyber security policies, standards and regulatory requirements across global technology teams to ensure appropriate alignment, awareness and compliance across teams.
  • Undertaking cyber security controls testing, assurance reviews and preparation for internal or external audits to ensure that evidence is complete, timely and meets defined control objectives.
  • Working closely with technology teams, Business Technology Risk Partners and subject matter experts to ensure a shared understanding of effective cyber security risk management processes and supporting the embedding of strong risk culture.
  • Maintaining and sharing up-to-date knowledge of specialist cyber security domain to ensure risk and control activities reflect current threats, best practices and regulatory requirements.
  • Providing SME support on IT and change initiatives with respect to delivering improvements to customer support and experience.

Qualifications

Who we’re looking for:

  • Familiarity with security frameworks such as NIST Cyber Security Framework (CSF), COBIT, ISO27001/2 and COSO.
  • Understanding of regulatory requirements relevant to financial services (e.g. FCA/PRA regulations, UK GDPR, DORA).
  • Ability to interact with cyber security stakeholders, product owners and technical operational roles.
  • Experience in cyber security risk, governance or assurance within a complex, regulated environment.
  • Experience testing and assuring cyber security controls implementation, controls automation, risk frameworks, and audit responses across cyber security.
  • Cyber security related qualifications such as CISM or CISSP would also be a plus.

Whatever your role, we reward performance and behaviour with a package that looks after all the things that are important to you. Here are some of the benefits we offer:

  • The opportunity to participate in our annual, performance-related bonus plan and valuable share schemes.
  • Generous pension contribution.
  • Life assurance.
  • Healthcare Plan (permanent employees only).
  • At least 25 days holiday, plus public holidays, 26 days after 2 years’ service. There’s also the option to buy and sell holiday.
  • Competitive family leave.
  • Participate in our electric car scheme, which offers employees the option to hire a brand-new electric car through tax efficient salary sacrifice (permanent employees only).
  • There are the many discounts we offer – both for our own products and at a range of high street stores and online.
  • In 2023, some of our workspaces were redesigned. Our offices are great spaces to connect and collaborate and have your wellbeing at the heart.

Additional Information

At L&G, we believe it's possible to generate positive returns today while helping to build a better future for all. If you join us, you’ll be part of a welcoming, inclusive culture, with opportunities to collaborate with people of diverse backgrounds, views, and experiences. Guided by leaders with integrity who care about your future and wellbeing. Empowered through initiatives which support people to develop their careers and excel. We care passionately about outcomes rather than attendance and are therefore open to discussing all kinds of flexible working options including part-time, term-time and job shares. Although some roles have limited flexibility due to customer demand, we accommodate requests when we can. It doesn’t matter if you don’t meet every single criterion in this advert. Instead, think about what you excel at and what else you can bring in terms of strengths, potential and connection to our purpose.

Cyber Security Risk & Controls Analyst in Aberdeen employer: Legal & General

Legal & General is an exceptional employer that fosters a dynamic work culture in the heart of London, offering employees the chance to make a significant impact through data-driven insights. With a strong emphasis on professional development and collaboration, you will have access to numerous growth opportunities while working alongside diverse teams in a supportive environment. The company's commitment to innovation and strategic decision-making ensures that your contributions will be valued and recognised.

L

Contact Details:

Legal & General Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Security Risk & Controls Analyst in Aberdeen

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Legal & General, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Legal & General

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Legal & General. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cyber Security Risk & Controls Analyst in Aberdeen

Cyber Security Risk Management
Control Assurance
Risk Assessment
Compliance Monitoring
NIST Cyber Security Framework (CSF)
COBIT
ISO27001/2

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Legal & General insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Legal & General that you’re committed to staying ahead in the game.

How to prepare for a job interview at Legal & General

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Legal & General to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Legal & General.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.