Information Security Risk Manager in London

Information Security Risk Manager in London

London Full-Time 60000 - 75000 £ / year (est.) Home office (partial)
Munich Re

At a Glance

  • Tasks: Oversee Information Security risks and provide expert guidance across UK entities.
  • Company: Join Munich Re, a leader in insurance and risk management.
  • Benefits: Enjoy 25 days leave, private medical insurance, and a hybrid working model.
  • Other info: Diversity and inclusion are at our core; we welcome all applicants.
  • Why this job: Make a real impact on cybersecurity while influencing senior stakeholders.
  • Qualifications: Experience in Information Security and strong communication skills required.

The predicted salary is between 60000 - 75000 £ per year.

Munich Re is seeking a highly skilled Information Security Risk Manager (ISRM) to act as the Information Security Subject Matter Expert for a number of UK entities, spanning the UK Specialty Global Markets, Life Branch and Great Lakes operations. This is a specialist role within the Second Line of Defence teams across three entities, offering high visibility across the organisation. You will provide independent oversight, challenge, and expert guidance on Information Security and Cyber risk, working across multiple UK-regulated entities operating within a global Group structure, with dotted-line reporting into Munich Re’s Group IRM function in Munich.

You will play a critical role in ensuring robust risk management practices that align with Group standards, UK regulatory expectations, and evolving cyber threats, while influencing senior stakeholders and shaping risk decisions. Whilst the role will collaborate with stakeholders across the organisation on a daily basis, there is no direct line management within the remit of the role.

Key Responsibilities

  • Information Security Risk Oversight
    • Provide independent second line oversight on Information Security and Cyber risks across UK entities
    • Review and challenge first line (IT and business) controls, risk assessments, and remediation activities
    • Monitor risk exposure and ensure timely and effective closure of control gaps
  • Framework & Governance
    • Drive the implementation and embedding of the Munich Re Group Information Security Management (ISM) framework
    • Ensure alignment with UK regulatory expectations (FCA, PRA, Lloyd’s) and internal policies
    • Translate regulatory and Group requirements into actionable control frameworks
  • Information Security Officer (ISO) Role
    • Act as the ISO for UK entities, providing risk leadership on Information Security matters
    • Serve as a trusted advisor to senior stakeholders on cyber and information risk topics
  • Risk Assessment & Advisory
    • Provide Information Security risk opinions on IT and cyber initiatives, e.g. gap analyses on new regulatory requirements
    • Business change programmes
    • Third-party relationships, e.g. critical IT related service providers – working closely with TRPM experts in the wider risk teams
    • Support entity-level risk identification, assessment, and treatment planning
  • Incident & Resilience
    • Support management of cyber and information security incidents, providing independent risk input
    • Contribute to business impact assessments and operational resilience activities from a cyber security perspective
    • Ensure effective management of outsourcing and supplier cyber risks
  • Reporting & Stakeholder Engagement
    • Deliver clear, insightful reporting to feed to governance committees and senior management, including entity Exco and Board forums
    • Communicate risk exposures, trends, and key issues with clarity and impact
    • Build strong relationships across IT, Risk, Compliance and business teams

What Success Looks Like

  • Effective oversight and reduction of Information Security risk exposure
  • Strong challenge and influence over first line risk practices
  • High-quality, decision-enabling reporting to senior stakeholders
  • Robust alignment with Group and UK regulatory expectations
  • Successful navigation of a complex, multi-entity international environment

Experience & Expertise

  • Experience in Information Security / Cyber Risk / IT Risk roles
  • Strong background in Information Security frameworks (e.g. ISO 27001, NIST)
  • Experience operating in a Second Line of Defence or advisory role
  • Proven ability to provide independent challenge and constructive escalation to senior management
  • Experience in complex, multi-entity or international organisations highly desirable
  • Deep expertise in cybersecurity and information security risks
  • Broad understanding of enterprise risk management frameworks
  • Knowledge of operational resilience and third-party risk
  • Strong influencing skills with the ability to challenge constructively
  • Ability to present confidently to senior committees and leadership teams
  • Degree in Information Security, IT, Computer Science or related field (or equivalent experience)
  • Insurance or financial services experience beneficial but not essential

Application Encouragement

If you are excited about this role but your experience does not align perfectly with everything outlined, or you don’t meet every requirement, we encourage you to apply anyway. You might just be the candidate we are looking for!

Diversity, Equity & Inclusion

At Munich Re, Diversity, Equity, and Inclusion foster innovation and resilience and enable us to act braver and better. Embracing the power of DEI is at the core of who we are. We recognise diversity can be multi‑dimensional, intersectional, and complex, so we want to build a diverse workforce that includes a wide range of racial, ethnic, sexual, and gender identities; economic and geographic backgrounds; physical abilities; ages; life, school, and career experiences; and political, religious, and personal beliefs. Additionally, we are committed to building an equitable and inclusive work environment where this diversity is celebrated, valued, and has equitable opportunities to succeed. All candidates in consideration for any role can request a reasonable adjustment at any point in our recruitment process. You can request an adjustment by speaking to your Talent Acquisition contact.

Benefits

  • 25 days Annual Leave + bank holidays
  • 10% Non‑contributory Pension
  • Eligibility for an Annual Bonus
  • Private Medical + Dental Insurance
  • Critical illness insurance + Life Assurance + Permanent Health Insurance
  • Wellbeing and Development Scheme + EAP + Health Assessments (subject to scheme eligibility)
  • Electric Vehicle Salary Sacrifice Scheme
  • Study & continuing Professional Development Support
  • Hybrid Working + IT Home Set‑up Support

Information Security Risk Manager in London employer: Munich Re

Munich Re is an exceptional employer that prioritises employee growth and well-being, offering a comprehensive benefits package including 25 days of annual leave, a non-contributory pension, and support for professional development. The company fosters a collaborative work culture that values diversity, equity, and inclusion, ensuring that all employees feel valued and empowered to succeed in their roles. With the opportunity to influence senior stakeholders and shape risk decisions within a global framework, this role provides a meaningful and rewarding career path in the dynamic field of Information Security.

Munich Re

Contact Details:

Munich Re Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Risk Manager in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Munich Re, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Munich Re

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Munich Re. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Information Security Risk Manager in London

Information Security Expertise
Cyber Risk Management
ISO 27001
NIST Framework
Risk Assessment
Stakeholder Engagement
Regulatory Compliance (FCA, PRA, Lloyd’s)

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Munich Re insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Munich Re that you’re committed to staying ahead in the game.

How to prepare for a job interview at Munich Re

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Munich Re to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Munich Re.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.