At a Glance
- Tasks: Assess and enhance cyber security measures while collaborating with diverse teams.
- Company: Join a leading financial services firm with over 175 years of innovation.
- Benefits: Enjoy 38 days annual leave, competitive pension, and comprehensive health coverage.
- Other info: Flexible working arrangements and a commitment to diversity and inclusion.
- Why this job: Make a real impact in cyber security and help shape the future of finance.
- Qualifications: 10+ years in cyber security with strong stakeholder management skills.
The predicted salary is between 70000 - 90000 £ per year.
Our purpose is to give everyone real confidence to put their money to work. With a heritage dating back more than 175 years, we have a long history of innovation in savings and investments, combining asset management and insurance expertise to offer a wide range of solutions. Our two distinct operating segments, Asset Management and Life, work together to provide access to balanced, long-term investment and savings solutions.
Overall Job Purpose
The Cyber Risk Consultant reports to the Head of Technology Risk Oversight and is part of M&G’s Second Line of Defence. The role is part of the wider M&G plc Risk & Compliance function, which is responsible for providing independent guidance, advice and insight on risk. The role holder is a subject matter expert in cyber security, who will be providing Second Line oversight across M&G plc, delivering independent evaluation of the strength of first line security controls. The role is also responsible for developing and operating a second line model for overseeing M&G’s cyber capabilities, including providing advice and challenge to the First Line of Defence. The role manages the planning and delivery of Red Team Cyber testing activities, and provides effective end to end stakeholder engagement in relation to the findings made during these tests. The role works in close partnership with stakeholders across the business in Technology, Security, Non-Financial Risk, external suppliers, and with programme leads to ensure effective oversight of cyber risk across M&G plc. The role also supports the wider Non-Financial Risk team by providing specialist advice and expertise on technology and cyber risk.
Responsibilities
- Provide an independent assessment of the design and operating effectiveness of selected first line controls, and deliver a second line view of cyber security events and associated remedial actions.
- Provide second line oversight of cyber security programmes, projects and control improvement initiatives, including the cyber security implications of the use of AI.
- Participate in a programme of deep dive thematic reviews, leading reviews where these relate to cyber.
- Manage the planning, engagement and delivery of Red Team Cyber testing activities with appropriately qualified third party cyber specialists.
- Advise on the design and development of risk appetite statements and metrics for technology and digital risks in relation to cyber.
- Provide second line oversight of the end to end processes for cyber threat intelligence.
- Provide advice and guidance on compliance with regulatory requirements that relate to cyber risk, and contribute to regulatory responses.
- Support First Line delivery of Risk & Control Self Assessments and timely closure of assurance actions.
- Build effective relationships with stakeholders in Technology, Security and business functions as well as collaborating with third parties and business partners.
- Ensure compliance to the people policies, Group Code of Conduct and embedding of desired behaviours, including completion of any mandatory training requirements.
- Work flexibly in support of the wider Risk and Compliance agenda.
- Line manage a Risk professional in the Technology Risk team.
Key Interfaces
- M&G plc Risk and Compliance
- All M&G plc UK Business Areas and Senior Management Teams
- Internal Audit
- External Suppliers and Business Partners
- External Auditors
- Regulators
Experience and Skills
- 10+ years’ experience within financial services or consulting/technology companies in a cyber security or technology risk function, or similar experience. (Essential)
- Significant, broad based knowledge of cyber security practices including risk management principles, architectural requirements, security engineering, threat intelligence, vulnerability management, and incident response. (Essential)
- Excellent stakeholder management skills, with the ability to successfully navigate a complex organisation and build strong relationships with teams across the business. (Essential)
- Experience leading cyber risk reviews and presenting information in a simple and effective way. (Essential)
- Able to deliver clear gap analysis against cyber security policy, standards and technology risk requirements, using industry best practice. (Essential)
- Strong understanding of cyber security products and technologies utilized in Enterprise environments and good knowledge of Cloud, primarily Microsoft Azure.
- Previous experience as part of a security operations or incident response organization would be beneficial.
- Good knowledge of threat modelling techniques with some experience in developing threat models.
- Keen understanding of national and international laws, regulations, policies and ethics related to financial industry cybersecurity.
- Ability to operate in a diverse and multi-cultural environment with international work or consultancy exposure.
- Curious mindset, strong analytical thinking, gravitas and ability to be pragmatic where appropriate.
Education and Professional Qualifications Preferred
- Graduate/Post-Graduate degree in Engineering, Information Technology or Computer Science
- Relevant Certification in Cyber Security and cloud such as CISSP, CISA, CISM
What we offer:
At M&G, we’re committed to helping you thrive and supporting your wellbeing, both at work and beyond. Our benefits are designed to help you balance your professional and personal life, while planning confidently for your future. Our UK benefits include:
- As a savings and Investments firm we are proud to offer a valuable pension scheme of 18%, with 13% made up of Employer Contributions and 5% Employee Contributions.
- Enjoy 38 days annual leave including bank holidays, with the opportunity to purchase up to 5 extra days and additional flexibility through our Time Off When You Need It policy – to balance your work and personal commitments.
- Our market leading Inspiring Families policy includes comprehensive support and paid parental leave covering maternity, adoption, surrogacy, and paternity leave - as supporting families is a core aspect of our inclusive culture.
- Health & Protection cover including Private Healthcare, Critical Illness cover and Life Assurance for you, with family options - for peace of mind.
We have a diverse workforce and an inclusive culture at M&G, underpinned by our policies and our employee-led networks who provide networking opportunities, advice and support for the diverse communities our colleagues represent. Regardless of gender, ethnicity, age, sexual orientation, nationality, disability or long term condition, we are looking to attract, promote and retain exceptional people. We also welcome those who take part in military service and those returning from career breaks.
M&G is also proud to be a Disability Confident Leader, and we welcome applications from candidates with long-term health conditions, disabilities, or neuro-divergent conditions. If you need assistance or an alternative means of applying for a role due to a disability or additional need, please let us know by contacting us at: careers@mandg.com
Cyber Risk Consultant in Stirling employer: Prudential UK Services
Contact Detail:
Prudential UK Services Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Risk Consultant in Stirling
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, attend relevant events, and engage with professionals on platforms like LinkedIn. We all know that sometimes it’s not just what you know, but who you know that can help you land that Cyber Risk Consultant role.
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of cyber security practices and risk management principles. We recommend doing mock interviews with friends or mentors to get comfortable discussing your experience and how it relates to the job at M&G.
✨Tip Number 3
Showcase your expertise! Bring examples of your previous work, especially any successful cyber risk reviews or projects you've led. We want to see how you’ve made an impact in your past roles, so be ready to share those stories during your interview.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search. So, go ahead and submit your application for the Cyber Risk Consultant position today!
We think you need these skills to ace Cyber Risk Consultant in Stirling
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Cyber Risk Consultant role. Highlight your experience in cyber security and risk management, and don’t forget to mention any relevant certifications. We want to see how your skills align with what we’re looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to tell us why you’re passionate about cyber security and how your background makes you a great fit for our team. Keep it concise but impactful – we love a good story!
Showcase Your Stakeholder Management Skills: Since this role involves working closely with various stakeholders, make sure to highlight your experience in building relationships and navigating complex organisations. We want to know how you’ve successfully collaborated in the past!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets to us quickly and efficiently. Plus, you’ll find all the details you need about the role and our company culture there!
How to prepare for a job interview at Prudential UK Services
✨Know Your Cyber Security Stuff
Make sure you brush up on your knowledge of cyber security practices, especially risk management principles and incident response. Be ready to discuss specific examples from your experience that demonstrate your expertise in these areas.
✨Showcase Your Stakeholder Skills
Since this role involves a lot of stakeholder engagement, prepare to share how you've successfully navigated complex organisations in the past. Think of examples where you built strong relationships across different teams and how that positively impacted your projects.
✨Prepare for Technical Questions
Expect some technical questions related to cyber security products and technologies, particularly around cloud environments like Microsoft Azure. Brush up on your knowledge of threat modelling techniques and be ready to explain them clearly.
✨Demonstrate Your Curiosity
This role values a curious mindset, so be prepared to ask insightful questions about the company's cyber capabilities and future initiatives. Show that you're not just interested in the role but also in how you can contribute to the company's growth and innovation.