Senior Group InfoSec Risk Analyst

Arrow Global Group

Manchester

On-site

GBP 60,000 - 80,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Arrow Global Group is seeking a Group Information Security Risk Analyst in Manchester to maintain the risk framework, deliver high-quality risk assessments, and drive remediation activities across the group and portfolio companies.

You will engage with stakeholders to ensure risk-based approaches are applied, produce management summaries, and support governance reporting. The role requires 5+ years in information security and strong knowledge of ISO27001, NIST CSF, and PCI-DSS.

Qualifications

  • Educated to degree level in Information Security, Cyber Security, Computer Science, Information Systems, Risk Management, Business Management, or equivalent levels of experience.
  • Minimum 5 years' proven experience within Information Security, Cyber Security, IT Risk, or related disciplines.
  • Strong understanding of Information Security Risk Management principles and methodologies.
  • Experience conducting risk assessments, control reviews, audits, or assurance activities.
  • Technical knowledge of information security frameworks and standards including ISO27001, NIST Cybersecurity Framework, CIS Controls, DORA, PCI-DSS.

Responsibilities

  • Conduct information security risk assessments across Arrow Global Group and portfolio companies using recognised risk assessment methodologies and frameworks.
  • Produce high-quality risk assessment reports, management summaries, and recommendations for both technical and non-technical stakeholders.
  • Track and monitor remediation actions arising from assessments, audits, incidents, and reviews, ensuring timely resolution of identified risks.
  • Work closely with stakeholders to ensure recommendations are understood, agreed, and appropriately implemented.
  • Escalate significant, overdue, or unresolved information security risks through appropriate governance channels.
  • Support the ongoing development, maintenance, and improvement of the Group Information Security Risk Framework.
  • Assess the effectiveness of information security controls and identify opportunities for improvement.
  • Liaise with Cyber Security, IT, Business Continuity, Data Protection, Risk, Compliance, and Internal Audit teams to ensure security requirements are reflected in assessment activities.
  • Support third-party security assurance activities, including supplier security reviews and due diligence assessments.
  • Prepare governance reporting through metrics, risk dashboards, management information, and committee papers.

Skills

Information security
Risk assessment
ISO27001
NIST Cybersecurity Framework
PCI-DSS
Cloud security

Education

Bachelor's degree in Information Security

Job description

Arrow Global Group is seeking a Group Information Security Risk Analyst in Manchester to maintain the risk framework, deliver high-quality risk assessments, and drive remediation activities across the group and portfolio companies.

You will engage with stakeholders to ensure risk-based approaches are applied, produce management summaries, and support governance reporting. The role requires 5+ years in information security and strong knowledge of ISO27001, NIST CSF, and PCI-DSS.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Group Information Security Risk Analyst
Group Information Security Risk Analyst

Arrow Global Group • Manchester

On-site
GBP 60,000 - 80,000
Security GRC Analyst: Architecture, Policy & Risk
Security GRC Analyst: Architecture, Policy & Risk

G.Digital • Manchester

On-site
GBP 45,000 - 65,000
InfoSec GRC Analyst: Security Awareness & Training
InfoSec GRC Analyst: Security Awareness & Training

Fitch Group • Manchester

Hybrid
GBP 42,000 - 64,000
Hybrid work model
Training & development opportunities
Tuition reimbursement
+4
Security & Data Privacy Analyst (ISO 27001/SOC 2)
Security & Data Privacy Analyst (ISO 27001/SOC 2)

Interact Software • Manchester

On-site
GBP 45,000 - 65,000
Cyber Security Awareness & GRC Analyst
Cyber Security Awareness & GRC Analyst

Fitch • Manchester

Hybrid
GBP 42,000 - 56,000
Hybrid work two days per week
Tuition reimbursement
Healthcare coverage
+3
GRC Analyst
GRC Analyst

G.Digital • Manchester

On-site
GBP 45,000 - 65,000
Senior GRC Analyst — Hybrid, NIS2 & ISO27001 Focus
Senior GRC Analyst — Hybrid, NIS2 & ISO27001 Focus

Euro Garages • Horwich

On-site
GBP 70,000 - 90,000
Discretionary bonus
Hybrid working
Cycle to Work
+2
Information Security & Compliance Analyst
Information Security & Compliance Analyst

Europa Worldwide Group • United Kingdom

Hybrid
GBP 42,000 - 62,000
Hybrid working
Onsite parking
Canteen onsite
+2
Senior GRC Security Consultant: ISO 27001, PCI, SOC 2
Senior GRC Security Consultant: ISO 27001, PCI, SOC 2

Confidential • Manchester

Hybrid
GBP 50,000 - 60,000
Hybrid work Manchester
Bonus up to 10%
InfoSec training
+5
Information Security Assurance Manager
Information Security Assurance Manager

TalentHawk • England

On-site
GBP 60,000 - 80,000