Cybersecurity Risk Analyst

Creative Artists Agency

Greater London

On-site

GBP 60,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Creative Artists Agency in Greater London is seeking a hands-on security professional. This role focuses on the end-to-end delivery of security services, protecting enterprise systems and data.

The successful candidate will support a Technology Vendor Management program, conduct security assessments, and coordinate security metrics, requiring at least 3 years of IT experience and familiarity with cloud technologies.

Qualifications

  • At least 3+ years’ experience in Information Technology.
  • At least 2 years’ experience in cybersecurity risk management.
  • Strong understanding of the fundamental operations of servers, operating systems, cloud applications and infrastructure.
  • Hands-on experience in Azure, AWS cloud environments.

Responsibilities

  • Support a Technology Vendor Management program, ensuring technology risk reviews.
  • Conduct thorough vendor, product and application security assessments.
  • Coordinate with IRM leadership to develop and deliver key security metrics.

Skills

Information Technology
cybersecurity risk management
analytical skills
cloud environments (Azure, AWS)
data privacy regulations (GDPR, CCPA)
information security frameworks (NIST, ISO27001)
third-party risk management
Microsoft Office suite
JIRA

Education

Bachelor’s or master’s degree in a relevant field

Tools

security analytics tooling
third-party risk management tools (One Trust, SIG)
Splunk

Job description

Overview

This is a hands‑on security position within the Information Security group, focused on ensuring consistent, measurable end‑to‑end delivery of security services. The successful candidate will develop and deploy capabilities that protect enterprise systems and data through the necessary security controls and tools, supporting a fast‑paced, technology‑forward environment that includes early adoption of cloud services.

Responsibilities
  • Support a Technology Vendor Management program, ensuring technology risk reviews across multiple disciplines, monitoring renewals and savings opportunities.
  • Participate in risk reviews of the IT control framework (NIST CSF, CIS, ITIL, ISO 270001, etc.).
  • Conduct thorough vendor, product and application security assessments in partnership with systems owners to integrate security early during the project lifecycle.
  • Partner with business groups to review workflows, producing output to enhance security processes in support of those workflows.
  • Coordinate, across service owners, the implementation of core security integrations (SSO, event logs, secrets, alerting, threat modeling and backup/recovery) with applications developed in‑house and in externally/SaaS hosted environments.
  • Ensure the security considerations identified are implemented and solutions are configured securely.
  • Coordinate with IRM leadership to develop and deliver key security metrics, ensuring technical security controls meet desired objectives and demonstrating measurable effectiveness.
Qualifications
  • At least 3+ years’ experience in Information Technology.
  • At least 2 years’ experience in cybersecurity risk management.
  • Bachelor’s or master’s degree in a relevant field.
  • Strong analytical skills in conducting due diligence to identify, assess and prioritise vendor risks.
  • Familiarity with information security frameworks (NIST, ISO27001), data privacy regulations (GDPR, CCPA), and information security certifications (SOC, ISO, PCIDSS, FedRAMP).
  • Experience coordinating technical integrations for security tooling and processes.
  • Ability to review complex systems architectures to identify key security integration opportunities.
  • Produce comprehensive written security assessments of vendor security postures.
  • Experience using security analytics tooling to produce operational metrics and dashboards.
  • Strong understanding of the fundamental operations of servers, operating systems, cloud applications and infrastructure.
  • Core skills in cybersecurity fundamentals and third‑party risk management.
  • Familiarity with third‑party risk management tools/processes such as One Trust, SIG or similar GRC platforms.
  • Hands‑on experience in Azure, AWS cloud environments and familiarity with core cloud services and architecture.
  • Familiarity with core security concepts of single sign‑on (e.g., PingFed, SAML), identity and access administration (Active Directory, Azure AD, AWS IAM), event management (Splunk).
  • Expertise in Microsoft Office suite and JIRA.
Equal Opportunity Employer

Creative Artists Agency (“CAA”) is committed to promoting equal opportunities in employment and creating a workplace culture in which diversity and inclusion is valued and everyone is treated with dignity and respect. As part of its zero‑tolerance approach to discrimination in any form, applicants will receive equal treatment regardless of age, disability, gender reassignment, marital or civil partner status, pregnancy or maternity, race, colour, nationality, ethnic or national origin, religion or belief, sex or sexual orientation, or any other legally recognised protected basis under UK law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst
Cyber Security Analyst

SmartestEnergy Business Limited • Ipswich

Hybrid
GBP 60,000 - 100,000
Flexible Working
Global Impact
Commitment to Diversity and Inclusion
Cyber Risk & Security Assurance Analyst
Cyber Risk & Security Assurance Analyst

Creative Artists Agency • Greater London

On-site
GBP 60,000 - 90,000
Cyber Security Analyst
Cyber Security Analyst

Novia Financial plc • Bath

On-site
GBP 55,000 - 75,000
Cyber Security Analyst
Cyber Security Analyst

SmartestEnergy • Ipswich

On-site
GBP 50,000 - 75,000
Flexible Working
Diversity and Inclusion Commitment
Cyber Risk & Security Manager
Cyber Risk & Security Manager

Spirit UK Ltd • Greater London

Hybrid
GBP 50,000 - 70,000
Global Cybersecurity Analyst: Risk & Incident Response
Global Cybersecurity Analyst: Risk & Incident Response

SmartestEnergy Business Limited • Ipswich

On-site
Cyber Security Lead
Cyber Security Lead

Chambers & Partners • Greater London

Hybrid
GBP 90,000 - 130,000
Information Security Specialist
Information Security Specialist

Cboe Global Markets • Greater London

On-site
GBP 50,000 - 70,000
Security Assurance Lead
Security Assurance Lead

Cambridge University Press & Assessment • Cambridgeshire and Peterborough

Hybrid
GBP 55,000 - 73,000
28 days leave
Private medical insurance
Permanent Health Insurance
+5
Cyber Security Analyst
Cyber Security Analyst

Cyber Security training courses • Belfast City District

Hybrid
GBP 45,000 - 65,000
Hybrid working arrangements
Professional development