Group Information Security Risk Analyst

Arrow Global Group

Manchester

On-site

GBP 60,000 - 80,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Arrow Global Group is seeking a Group Information Security Risk Analyst in Manchester to maintain the risk framework, deliver high-quality risk assessments, and drive remediation activities across the group and portfolio companies.

You will engage with stakeholders to ensure risk-based approaches are applied, produce management summaries, and support governance reporting. The role requires 5+ years in information security and strong knowledge of ISO27001, NIST CSF, and PCI-DSS.

Qualifications

  • Educated to degree level in Information Security, Cyber Security, Computer Science, Information Systems, Risk Management, Business Management, or equivalent levels of experience.
  • Minimum 5 years' proven experience within Information Security, Cyber Security, IT Risk, or related disciplines.
  • Strong understanding of Information Security Risk Management principles and methodologies.
  • Experience conducting risk assessments, control reviews, audits, or assurance activities.
  • Technical knowledge of information security frameworks and standards including ISO27001, NIST Cybersecurity Framework, CIS Controls, DORA, PCI-DSS.

Responsibilities

  • Conduct information security risk assessments across Arrow Global Group and portfolio companies using recognised risk assessment methodologies and frameworks.
  • Produce high-quality risk assessment reports, management summaries, and recommendations for both technical and non-technical stakeholders.
  • Track and monitor remediation actions arising from assessments, audits, incidents, and reviews, ensuring timely resolution of identified risks.
  • Work closely with stakeholders to ensure recommendations are understood, agreed, and appropriately implemented.
  • Escalate significant, overdue, or unresolved information security risks through appropriate governance channels.
  • Support the ongoing development, maintenance, and improvement of the Group Information Security Risk Framework.
  • Assess the effectiveness of information security controls and identify opportunities for improvement.
  • Liaise with Cyber Security, IT, Business Continuity, Data Protection, Risk, Compliance, and Internal Audit teams to ensure security requirements are reflected in assessment activities.
  • Support third-party security assurance activities, including supplier security reviews and due diligence assessments.
  • Prepare governance reporting through metrics, risk dashboards, management information, and committee papers.

Skills

Information security
Risk assessment
ISO27001
NIST Cybersecurity Framework
PCI-DSS
Cloud security

Education

Bachelor's degree in Information Security

Job description

Group Information Security Risk Analyst

Department: Governance & Risk

Employment Type: Permanent - Full Time

Location: Manchester, UK

Description

The Group Information Security Risk Analyst will play a key role within Arrow's Group Information Security Function by maintaining the Information Security Risk Framework, delivering high-quality risk assessments and reporting, engaging with stakeholders to drive remediation activities, and ensuring a proportionate and risk-based approach is applied across a diverse range of business sectors.

The role will also support wider Information Security activities including third-party security assurance, due diligence reviews, responses to security questionnaires, audit activities, and security awareness initiatives as required.

About the role
  • Conduct information security risk assessments across Arrow Global Group and portfolio companies using recognised risk assessment methodologies and frameworks.
  • Produce high-quality risk assessment reports, management summaries, and recommendations for both technical and non-technical stakeholders.
  • Track and monitor remediation actions arising from assessments, audits, incidents, and reviews, ensuring timely resolution of identified risks.
  • Work closely with stakeholders to ensure recommendations are understood, agreed, and appropriately implemented.
  • Escalate significant, overdue, or unresolved information security risks through appropriate governance channels.
  • Support the ongoing development, maintenance, and improvement of the Group Information Security Risk Framework.
  • Assess the effectiveness of information security controls and identify opportunities for improvement.
  • Apply recognised security frameworks and standards including ISO27001, NIST Cybersecurity Framework, CIS Controls, PCI-DSS, and other relevant best practices in a proportionate and risk-based manner.
  • Liaise with Cyber Security, IT, Business Continuity, Data Protection, Risk, Compliance, and Internal Audit teams to ensure security requirements are appropriately reflected within assessment activities.
  • Support third-party security assurance activities, including supplier security reviews, due diligence assessments, and ongoing monitoring of third-party risks.
  • Contribute to governance reporting through the preparation of metrics, risk dashboards, management information, and committee papers.
  • Maintain awareness of emerging threats, vulnerabilities, regulatory developments, Artificial Intelligence (AI) risks, and industry best practices.
About you
  • Educated to degree level in Information Security, Cyber Security, Computer Science, Information Systems, Risk Management, Business Management, or equivalent levels of experience.
  • A minimum of 5 years' proven experience within Information Security, Cyber Security, IT Risk, or related disciplines.
  • Strong understanding of Information Security Risk Management principles and methodologies.
  • Experience conducting risk assessments, control reviews, audits, or assurance activities.
  • Technical knowledge of information security frameworks and standards including ISO27001, NIST Cybersecurity Framework, CIS Controls, DORA, PCI-DSS, and related security practices.
  • Strong communicator with positive influencing and interpersonal skills.
  • Ability to synthesise complex technical and business information and present findings in a clear and concise manner.
  • Effective prioritisation and organisational skills with the ability to manage multiple competing priorities.
  • Strong analytical and problem-solving skills.
  • Experience producing professional reports and management presentations.
  • Understanding of cloud technologies and associated information security risks.
  • Awareness of Artificial Intelligence (AI), associated risks, governance considerations, and emerging industry developments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Group InfoSec Risk Analyst
Senior Group InfoSec Risk Analyst

Arrow Global Group • Manchester

On-site
GBP 60,000 - 80,000
Group Information & Security Manager
Group Information & Security Manager

Oscar • Doncaster

Hybrid
GBP 90,000 - 120,000
30% Annual Bonus
Hybrid Working
Company Pension Scheme
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 40,000 - 60,000
Information Security Governance & Risk Analyst
Information Security Governance & Risk Analyst

Made4Tech Global • Greater Manchester

On-site
GBP 50,000 - 75,000
Information Security Analyst
Information Security Analyst

Herbert Smith Freehills Kramer • City Of London

On-site
GBP 60,000 - 80,000
Information Risk Manager
Information Risk Manager

HW Finance • Skipton

On-site
GBP 65,000 - 95,000
Information Security and Data Protection Analyst
Information Security and Data Protection Analyst

Interact Software • Manchester

On-site
GBP 45,000 - 65,000
Information Security GRC Manager
Information Security GRC Manager

AJ Bell • Manchester

Hybrid
GBP 65,000 - 85,000
27 days’ holiday
Pension with matched contributions up to 8%
Discretionary bonus and share awards
+3
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
Security Assurance Analyst
Security Assurance Analyst

Caraffi • Reading

Hybrid
GBP 60,000 - 85,000