- Proactively identifying and analysing the impact of potential risks, in relation to data privacy, information security and the systems, using GAP analysis to investigate these and determining recommendations to mitigate these risks
- Implementing risk management strategies and controls with the aim of mitigating risks in collaboration with IT teams and other business units, and ensuring the business is compliant with industry regulations
- Developing security of information policies and procedures for the business and its employees to follow, ensuring the business is compliant with these internal policies through the process of conducting audits and assessments
- Overseeing the delivery of risk awareness training programmes across the business for all relevant employees, with the aim of promoting a continuous environment where security awareness is a top priority
- Providing regular reporting for senior management professionals on the status and progress of risks and the strategies to mitigate them
- Ensuring that the business aligned strategically with risk management policies and that these policies are cohesive with business objectives
- Engaging with stakeholders who are affected by risks and related prevention strategies to ensure that everyone has a good understanding of these risks and the controls in place to manage them
- Experience from within a fully regulated industry/sector
- At least 5 years of experience in information risk management
- Excellent understanding of information security principles, cyber security threats and IT infrastructure
- Experience working with frames such as ISO 27001, NIST & COBIT
- A degree in computer science, risk management or information security or related field
- Strong communication skills