Job Search and Career Advice Platform

Enable job alerts via email!

Cyber Security Risk & Controls Analyst

LegalAndGeneral

Greater London

On-site

GBP 45,000 - 65,000

Full time

3 days ago
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading UK financial services group in Greater London is seeking a Cyber Security Risk and Controls Analyst to support the management and improvement of cyber security controls. The role involves key responsibilities such as maintaining compliance, addressing security risks, and ensuring effective risk management practices. Successful candidates will have familiarity with security frameworks and would ideally hold relevant cybersecurity qualifications. This position offers a dynamic work environment focusing on the continuous enhancement of cybersecurity.

Benefits

Participation in performance-related bonus plan
Generous pension contribution
Life assurance
Healthcare Plan
At least 25 days holiday
Competitive family leave
Electric car scheme
Employee discounts

Qualifications

  • Familiarity with security frameworks like NIST CSF, COBIT, ISO27001/2.
  • Understanding of regulatory requirements (FCA/PRA regulations, UK GDPR).
  • Experience in cybersecurity risk and assurance within a regulated environment.

Responsibilities

  • Maintain and monitor key cyber security controls for compliance.
  • Support the identification and closure of cyber security issues.
  • Contribute to cyber security risk and control self-assessments.

Skills

Familiarity with security frameworks such as NIST CSF, COBIT, ISO27001/2
Understanding of regulatory requirements relevant to financial services
Ability to interact with cyber security stakeholders
Experience in cyber security risk, governance or assurance
Experience testing and assuring cyber security controls implementation
Cyber security related qualifications such as CISM or CISSP
Job description
Company Description

Legal & General (L&G) is a leading UK financial services group and major global investor.
We have been safeguarding people's financial futures since 1836, and strive to build a better society, while improving the lives of our customers and creating value for shareholders.
We are one of the world's largest asset managers and provide powerful asset origination capabilities. Together, these underpin our retirement and protection solutions: we are an international player in pension risk transfer, in UK and US life insurance, and in UK workplace pensions and retirement income.
Our Group Functions provide the services that all areas of the business need. This requires a talented and diverse team behind the scenes, who enable everyone at L&G to do what they do best.
Joining us means helping to improve the lives of our customers and contributing to the success of the business every day.

Job Description

As a Cyber Security Security Risk and Controls Analyst you will support the execution and continuous improvement of risk and control activities within the first-line Global Cyber Security Risk and Controls Function. The role works closely with control owners, product teams, and risk partners to help ensure that risks are effectively identified, assessed, managed, and reported across areas such as third-party risks specific to technology, cyber security and information technology risk.
The Cyber Security Risk and Controls Analyst provides hands-on support in the maintenance and assurance of controls, issue tracking, evidence gathering, and risk reporting. It drives control effectiveness, policy compliance and effective risk management across L&G globally.

What you'll be doing
  • Maintaining and monitoring key cyber security controls to ensure control performance is effective and appropriately evidenced for compliance, audit and assurance purposes
  • Supporting the identification, management and closure of cyber security issues, audit actions and remediation plans to ensure timely resolution and control improvements
  • Contributing to cyber security risk and control self-assessments (RCSAs), supplier assessments or thematic reviews to ensure accurate identification of control weaknesses, exposures and required enhancements
  • Assisting in the application of cyber security policies, standards and regulatory requirements across global technology teams to ensure appropriate alignment, awareness and compliance across teams
  • Undertaking cyber security controls testing, assurance reviews and preparation for internal or external audits to ensure that evidence is complete, timely and meets defined control objectives
  • Working closely with technology teams, Business Technology Risk Partners and subject matter experts to ensure a shared understanding of effective cyber security risk management processes and supporting the embedding of strong risk culture
  • Maintaining and sharing up-to-date knowledge of specialist cyber security domain to ensure risk and control activities reflect current threats, best practices and regulatory requirements
  • Providing SME support on IT and change initiatives with respect to delivering improvements to customer support and experience
Qualifications

Who we're looking for:

  • Familiarity with security frameworks such as NIST Cyber Security Framework (CSF), COBIT, ISO27001/2 and COSO
  • Understanding of regulatory requirements relevant to financial services (e.g. FCA/PRA regulations, UK GDPR, DORA)
  • Ability to interact with cyber security stakeholders, product owners and technical operational roles
  • Experience in cyber security risk, governance or assurance within a complex, regulated environment
  • Experience testing and assuring cyber security controls implementation, controls automation, risk frameworks, and audit responses across cyber security
  • Cyber security related qualifications such as CISM or CISSP would also be a plus
Benefits
  • The opportunity to participate in our annual, performance -related bonus plan and valuable share schemes
  • Generous pension contribution
  • Life assurance
  • Healthcare Plan (permanent employees only)
  • At least 25 days holiday, plus public holidays, 26 days after 2 years' service. There's also the option to buy and sell holiday
  • Competitive family leave
  • Participate in our electric car scheme, which offers employees the option to hire a brand-new electric car through tax efficient salary sacrifice (permanent employees only)
  • There are the many discounts we offer - both for our own products and at a range of high street stores and online
  • In 2023, some of our workspaces were redesigned. Our offices are great spaces to connect and collaborate and have your wellbeing at the heart
Additional Information

At L&G, we believe it's possible to generate positive returns today while helping to build a better future for all.
If you join us, you'll be part of a welcoming, inclusive culture, with opportunities to collaborate with people of diverse backgrounds, views, and experiences. Guided by leaders with integrity who care about your future and wellbeing. Empowered through initiatives which support people to develop their careers and excel.
We care passionately about outcomes rather than attendance and are therefore open to discussing all kinds of flexible working options including part-time, term-time and job shares. Although some roles have limited flexibility due to customer demand, we accommodate requests when we can.
It doesn't matter if you don't meet every single criterion in this advert. Instead, think about what you excel at and what else you can bring in terms of strengths, potential and connection to our purpose.

Videos To Watch

https://www.youtube.com/watch?v=djTs2V4JUFs

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.