IT Security Governance, Risk & Controls Analyst in London

IT Security Governance, Risk & Controls Analyst in London

London Full-Time No working from home possible
R

Overview

In this role you strengthen security governance, risk and controls across Ricoh's European IT landscape. You partner with infrastructure, cloud, identity and operations teams to translate frameworks into practical controls. You will own the IT Security Risk Register and support assurance activities, audits and remediation. This role offers the chance to raise security maturity and impact across a large, multinational environment.

Pay / Benefits

  • fair rewards
  • flexible working
  • wellbeing resources
  • learning pathways
  • mentoring
  • volunteering and sustainability initiatives

Responsibilities

  • Develop, maintain and embed IT security policies, standards, procedures and control requirements
  • Support development and continuous improvement of the IT security governance and control framework
  • Own and maintain the IT Security Risk Register with monitoring and management of risks
  • Facilitate technology and security risk assessments with mitigation plans
  • Assess control effectiveness and identify gaps for improvement
  • Translate frameworks (ISO 27001, NIST CSF) into practical operational controls
  • Support audit, assurance and compliance activities (ISO 27001, Cyber Essentials, internal programmes)
  • Collaborate with technology teams to ensure controls are understood and operating effectively
  • Provide reporting on security risks, control effectiveness, and remediation activities
  • Track remediation actions and address risks and gaps with stakeholders
  • Support continuous improvement of governance, risk and control processes in Europe IT
  • Build relationships with technical and business stakeholders as a trusted security partner

Key requirements

  • Experience in IT Security, Information Security Governance, IT Risk, Security Controls, GRC or similar
  • Experience developing security policies, standards, procedures and control frameworks
  • Strong understanding of governance and risk management principles
  • Experience conducting or supporting risk assessments and maintaining risk registers
  • Knowledge of ISO 27001 and NIST CSF
  • Experience assessing control design and effectiveness and supporting remediation
  • Understanding of vulnerability management, patching, identity and access management, privileged access management and backup governance
  • Experience supporting audits, assurance reviews and compliance programmes
  • Strong analytical and problem-solving skills with ability to translate risks into actions
  • Excellent communication and stakeholder management with technical and senior leadership
  • Proactive approach to improving security maturity, governance and controls
  • Certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer are advantageous
  • strong communication
  • stakeholder management
  • problem-solving
  • IT Security
  • Security Governance
  • IT Risk

IT Security Governance, Risk & Controls Analyst in London employer: Ricoh

Ricoh is an exceptional employer that prioritises a people-first culture, fostering an inclusive environment where employees can thrive and make a meaningful impact. With a strong commitment to professional development, flexible working arrangements, and a focus on sustainability, Ricoh empowers its workforce to grow and succeed while contributing to a better future. Join us in a collaborative atmosphere that values your voice and encourages innovation across our European operations.

R

Contact Details:

Ricoh Recruitment Team