Senior Risk and Controls Consultant in London

Senior Risk and Controls Consultant in London

London Full-Time 48000 - 84000 £ / year (est.) No working from home possible
R

At a Glance

  • Tasks: Join our team to manage and implement security controls across innovative tech projects.
  • Company: Rothesay is the UK's largest pensions insurance specialist, securing pensions for over one million people.
  • Benefits: Enjoy a dynamic work environment with opportunities for growth and collaboration on cutting-edge technology.
  • Other info: We value diversity and inclusivity, welcoming applicants from all backgrounds.
  • Why this job: Be part of a transformative journey in information security, making a real impact on the future.
  • Qualifications: 5+ years in information security, strong knowledge of NIST CSF 2, and excellent communication skills required.

The predicted salary is between 48000 - 84000 £ per year.

Rothesay is the UK’s largest pensions insurance specialist, purpose-built to protect pension schemes and their members’ pensions. With over £70 billion of assets under management, we secure the pensions of more than one million people and pay out, on average, approximately £300 million in pension payments each month.

Rothesay is dedicated to providing excellence in customer service alongside prudent underwriting, a conservative investment strategy and the careful management of risk. We are trusted by the pension schemes of some of the UK’s best known companies to provide pension solutions, including Asda, British Airways, Cadbury, the Civil Aviation Authority, the Co-operative Bank, National Grid, Morrisons, the Post Office and telent.

At Rothesay, we are striving to transform our industry. We believe deeply in creating real security for the future and our leadership in finding new and better ways to do that is the key to our success. To do that, we need the very brightest original thinkers to bring creativity as well as rigour. Rothesay is a rewarding place to work, where quality people can thrive and prosper. We pride ourselves on the connections our people build, many of whom have been with us for over ten years

Job Title: Information Security Risk Manager – Controls
Contract: Permanent

Rothesay is investing heavily in a modern, secure, cloud-native technology stack, backed by executive sponsorship and a multi-year strategic transformation. As part of this journey, we’re expanding our Information Security team to embed security and good risk management into every component of the stack.

This is an opportunity to join a high-impact Information and Technology Risk Management team helping drive strong security practices in our business and with our strategic partners. If you are passionate about frameworks and controls, working with stakeholders to find practical ways to implement and measure controls, and want to be part of an innovative organisation who wants to be the best information security, we want to hear from you.

What you’ll do:

You’ll be a member of the Information and Technology Risk Management team, working with a team of experts to drive assurance and risk management activities across the firm.

Your primary focus will be managing our Controls practice. Your responsibilities will include:

  • Implement the NIST CSF 2 framework at Rothesay, playing a leading role in mapping Rothesay Standards to controls, and working with Technology teams to find practical ways to operate and measure controls across a Cloud-first and everything in code technology stack.
  • Represent the Information Security Department at strategic business projects implementing products, systems and vendors. Your role in these projects will be to identify key controls required, support the business in articulating and implementing control, and to coordinate security assessments.
  • Contribute to the evaluation of security of Artificial Intelligence (AI) internally and in vendor products, and review whether Rothesay uses AI securely and responsibly.
  • Collaborate on and document a comprehensive set of security Standards guiding the implementation of NIST CSF 2 controls throughout the organisation. Socialise and gain support for the standards in Technology functions.
  • Identify and implement Key Control Indicators (KCIs) in Rothesay’s Continuous Controls Management system to monitor operation and alert when controls fail. Work with the vendor to create control dashboards regarding themes such as Identify and Access Management, or Ransomware related controls.
  • Perform thematic security reviews in relation to control topics. Report issues identified and recommendations to senior management.
  • Produce (and automate) regular information security reporting dashboards, KPIs, KCIs, and reporting packs for security topics.

The role is essential for ensuring implementation of the firmwide strategy within the Information Security team.

Other activities include project management, accurately and convincingly representing technical risk and security priorities, measuring key indicators, improving awareness of good security practices, and reporting.

What we’re looking for:

Required:

  • Excellent knowledge of information and cyber security, networks, Cloud, and Internet technologies e.g. encryption, APIs and authentication techniques.
  • Excellent knowledge of security risk management e.g. determining impact, likelihood and compensating controls.
  • Solid understanding of the NIST CSF 2 framework, ISO 27001/2, and other related frameworks e.g. NIST 800-53 and COBIT.
  • Experience in finding pragmatic solutions to implementing and measuring control operation.
  • Experience in scoping and performing thematic security reviews in relation to various information security control topics.
  • Adequate knowledge of modern Artificial Intelligence (AI) systems and security topics e.g. prompt engineering.
  • Ability to develop security standards and guidelines based on best practices, regulatory requirements, and industry standards.
  • Project management abilities (experience with the Atlassian suite of products would be highly advantageous).
  • Strong oral and written communication skills, e.g. engaging workshop facilitation, high quality report writing, etc.
  • Experience in information security risk management at a financial services institution would be advantageous.
  • Ability to multi-task and manage multiple priorities.
  • 5 or more years’ experience in an information security aligned role (e.g. Business Information Security Officer).
  • Certification in Cyber Risk and Information Systems such as CISA or CRISC or equivalent (not required but desirable).
  • Advanced security certifications such as CISSP or equivalent (not required but advantageous).
  • Degree, diploma, or equivalent experience in a technology related field such as Computer Science or Information Sciences (not required but advantageous).

We’re not just looking for someone to implement controls — we’re looking for someone who wants to influencehow we build securely, empower vendor owners to have productive conversations about security, and help shift security left in a meaningful, pragmatic way.

Disclaimer This position description is intended to describe the duties most frequently performed by an individual in this position. It is not intended to be a complete list of assigned duties, but to describe a position level. The role shall be performed within a professional office environment. Rothesay has health and safety polices that are available for all workers upon request. There are no specific health risks associated with the role.

InclusionRothesay actively promotes diversity and inclusivity. We know that our success depends on our people and that by nurturing a culture that values difference, we create a stronger, more dynamic business. We welcome applications from all qualified candidates, regardless of race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability or age.

Apply for this job

*

indicates a required field

First Name *

Last Name *

Preferred First Name

Email *

Phone

Resume/CV

Enter manually

Accepted file types: pdf, doc, docx, txt, rtf

Enter manually

Accepted file types: pdf, doc, docx, txt, rtf

LinkedIn Profile

Website

LinkedIn Profile

Website

Previous Bonus: *

Are you connected to any current employees of Rothesay? If yes, please confirm how you are connected. * Select...

Please provide the name and team of your referrer. if you haven\'t been referred please select n/a *

Please confirm your current employer

Please select your current sector * Select...

Diversity, Equity and Inclusion Monitoring (UK)

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.

What is your gender? Select...

What is your age? Select...

How would you best describe your ethnicity? Select...

What is your religion? Select...

How would you describe your sexual orientation? Select...

How would you describe your sexual identify? Select...

Are you a person living with a disability? According to the Equality Act, a person is disabled if they have a physical or mental impairment, and the impairment has a substantial and long-term adverse effect on their ability to carry out normal day-to-d Select...

What is the highest level of qualification you have achieved? Select...

What is the highest level of qualifications achieved by either of your parent(s) or guardian(s) by the time you were 18? Select...

What was the occupation of your main household earner when you were aged about 14? Select...

#J-18808-Ljbffr

Senior Risk and Controls Consultant in London employer: Rothesay

Rothesay is an exceptional employer, offering a dynamic work environment where innovation and collaboration thrive. With a strong commitment to employee growth, we provide extensive training opportunities and encourage our team members to contribute to meaningful projects that shape the future of pension security. Located in the heart of the UK, our inclusive culture values diversity and fosters long-term relationships, making Rothesay a rewarding place for professionals seeking to make a real impact.

R

Contact Details:

Rothesay Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Risk and Controls Consultant in London

Tip Number 1

Familiarise yourself with the NIST CSF 2 framework, as this is a key focus for the role. Understanding how to map Rothesay Standards to controls will give you an edge in discussions during interviews.

Tip Number 2

Showcase your experience with cloud technologies and security risk management. Be prepared to discuss specific examples of how you've implemented controls in a cloud-first environment, as this will resonate well with the hiring team.

Tip Number 3

Highlight your ability to collaborate with various stakeholders. Prepare to share instances where you've successfully engaged with teams to implement security measures, as teamwork is crucial in this role.

Tip Number 4

Stay updated on current trends in information security, especially regarding AI systems. Being able to discuss how Rothesay can securely leverage AI will demonstrate your forward-thinking approach and alignment with their innovative culture.

We think you need these skills to ace Senior Risk and Controls Consultant in London

Information Security Management
Cyber Security Knowledge
Cloud Technologies
NIST CSF 2 Framework
ISO 27001/2 Standards
NIST 800-53 Framework
COBIT Framework

Some tips for your application 🫡

Tailor Your CV:Make sure your CV highlights relevant experience in information security and risk management. Use keywords from the job description, such as 'NIST CSF 2 framework' and 'cyber security', to demonstrate your fit for the role.

Craft a Compelling Cover Letter:In your cover letter, express your passion for information security and how your background aligns with Rothesay's mission. Mention specific projects or experiences that showcase your ability to implement controls and manage risks effectively.

Showcase Your Knowledge:During the application process, be prepared to discuss your understanding of frameworks like NIST CSF 2 and ISO 27001/2. Highlight any relevant certifications or training that demonstrate your expertise in these areas.

Highlight Soft Skills:Rothesay values strong communication and project management skills. Provide examples in your application that illustrate your ability to engage stakeholders, facilitate workshops, and manage multiple priorities effectively.

How to prepare for a job interview at Rothesay

Understand the NIST CSF 2 Framework

Make sure you have a solid grasp of the NIST Cybersecurity Framework (CSF) 2.0, as this will be crucial for your role. Be prepared to discuss how you would implement and measure controls within Rothesay's cloud-native technology stack.

Showcase Your Risk Management Skills

Demonstrate your knowledge of security risk management by discussing past experiences where you determined impact and likelihood of risks. Highlight any pragmatic solutions you've implemented in previous roles.

Prepare for Thematic Security Reviews

Be ready to talk about your experience in scoping and performing thematic security reviews. Think of specific examples where you identified control topics and how you reported issues and recommendations to senior management.

Communicate Effectively

Strong communication skills are essential for this role. Practice articulating complex security concepts clearly and concisely, as you'll need to engage with various stakeholders and facilitate workshops.