Enterprise Security Risk Manager

Core-Asset Consulting Ltd

City of Edinburgh

On-site

GBP 70,000 - 110,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Core-Asset Consulting is seeking an Enterprise Security Risk Manager to Edinburgh to translate security strategy into day-to-day assurance and risk management. You will assess cyber risk, review technology and AI solutions, and lead security investigations while coordinating testing and regulatory activity.

The role requires you to review security designs, manage risk across the firm, and provide expert security guidance to Technology and the wider business.

Qualifications

  • Strong practical experience of cyber risk assessment, security assurance and control evaluation.
  • Experience reviewing security designs for technology change, software development and third-party solutions.
  • Experience with the Microsoft 365 security stack and related tooling.
  • Incident triage, threat hunting and investigation capabilities.
  • Experience designing tests and assessing security controls.

Responsibilities

  • Assess cyber risks, control strengths, security exceptions and attack paths.
  • Review security designs before production use across technology and departments.
  • Triage security incidents and lead investigations into data protection and insider risk alerts.
  • Design penetration tests and attack simulations and drive remediation.
  • Review endpoint, identity, data protection and cloud security controls.
  • Conduct due diligence on third parties and AI providers; manage risk data and reporting.
  • Produce risk and assurance artifacts and support audits and governance forums.
  • Communicate requirements across the firm and advise stakeholders.

Skills

cyber risk assessment
security assurance
security design review
Microsoft 365 Defender
Entra
Purview
incident triage
threat hunting
penetration testing design
data protection controls
third-party & AI security due care
regulatory & audit knowledge
stakeholder management

Tools

Microsoft 365 Defender
Entra
Purview

Job description

Our client, a specialist investment management firm based in Edinburgh, is looking to appoint an Enterprise Security Risk Manager to join their team.

This role translates our client's security strategy into effective day-to-day assurance and risk management.You will assess cyber risk, review technology and AI solutions, lead security investigations and control assurance, coordinate testing and regulatory activity, and provide expert security advice to Technology and the wider business.You'll also represent the security function on key governance forums, including the Information Security Working Group, Third Party Oversight Working Group and Business Continuity Working Group.Our client places a strong emphasis on client-first thinking, collaboration and integrity across the business.

A recognised cyber security qualification such as CISSP, CISM, CRISC or equivalent is desirable for this role.

Skills/Experience:
  • Strong practical experience of cyber risk assessment, security assurance and control evaluation
  • Experience reviewing security designs for technology change, software development and third-party solutions
  • Strong practical experience of the Microsoft 365 security stack, including Entra, Defender and Purview
  • Strong incident-triage, threat-hunting and investigation skills
  • Experience designing and interpreting penetration tests, attack simulations and security-control assurance
  • Good understanding of identity, endpoint, data-protection, mobile-device, email/web and cloud security controls
  • Experience of third-party and AI security due diligence, including data protection and supplier assurance
  • Working knowledge of regulatory frameworks, security standards, risk registers and audit processes
  • Strong communication, training and stakeholder-management skills across technical and non-technical audiences
Core Responsibilities:
  • Assess cyber risks, control strengths, security exceptions, threat-intelligence findings and attack paths
  • Review security designs for Technology, departmental and citizen-developed solutions before production use
  • Triage security incidents and lead threat hunting and investigations into data-protection, information-protection and insider-risk alerts
  • Design penetration tests and attack simulations, assess findings and drive remediation of material weaknesses
  • Review the effectiveness of endpoint, encryption, identity, conditional-access, mobile-device and web/email security controls
  • Perform security due diligence on third parties and AI providers, including data-use, model-training and data-residency controls
  • Produce the Cyber RCSA and undertake cyber-insurance, internal-audit and external-audit casework
  • Conduct regulatory and standards gap analyses and communicate relevant requirements across the firm
  • Design access-review processes, security management information and assurance reporting
  • Design and deliver phishing simulations, bespoke security training and targeted awareness activity
  • Lead monthly technical reviews with the SOC and challenge service quality and control effectiveness
  • Advise Technology and business teams on security risks and escalated material issues to the Head of Enterprise Security

Core-Asset Consulting is an equal opportunities recruiter and we welcome applications from everyone irrespective of age, disability, gender, gender identity or expression, race, colour, ethnic or national origin, sexual orientation, religion or belief, marital/civil partner status or pregnancy.

To apply for this vacancy applicants must be eligible to work in the UK in accordance with the Immigration, Asylum and Nationality Act 2006.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Enterprise Security Risk Manager
Enterprise Security Risk Manager

Head Resourcing Ltd • City of Edinburgh

On-site
GBP 65,000 - 70,000
Enterprise Cyber Risk & Security Assurance Lead
Enterprise Cyber Risk & Security Assurance Lead

Core-Asset Consulting Ltd • City of Edinburgh

On-site
GBP 70,000 - 110,000
Senior Cyber Risk & Security Assurance Lead
Senior Cyber Risk & Security Assurance Lead

Head Resourcing Ltd • City of Edinburgh

On-site
GBP 65,000 - 70,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 40,000 - 60,000
Senior Information Security Analyst
Senior Information Security Analyst

Cathcart Technology • City of Edinburgh

Hybrid
GBP 90,000 - 120,000
Bonus
Share scheme
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 60,000 - 80,000
Cyber Risk & Security Manager
Cyber Risk & Security Manager

Spirit UK Ltd • Greater London

Hybrid
GBP 50,000 - 70,000
ICT Cyber and Information Security Manager
ICT Cyber and Information Security Manager

ISR RECRUITMENT LIMITED • Tees Valley

On-site
GBP 90,000 - 130,000
Enterprise Governance Analyst
Enterprise Governance Analyst

Core-Asset Consulting Ltd • City of Edinburgh

On-site
GBP 70,000 - 100,000
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Control Risks • Greater London

Hybrid
GBP 90,000 - 130,000
Hybrid work arrangement
Global bonus scheme
Equal opportunity employer