Senior Information Security Risk Analyst

Medical Protection Society

Leeds

Hybrid

GBP 80,000 - 100,000

Full time

34 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Discretionary bonus
Pension 11%
Annual leave 25 days
Private medical cover
Car salary sacrifice
Death in service
Wellbeing support
Hybrid working
Inclusive culture

Job summary

Medical Protection Society is seeking a Senior Information Security Risk Analyst in Leeds, hybrid role. You will lead complex risk assessments, design controls, and manage security risks in line with regulatory requirements and risk appetite.

You will mentor junior analysts, shape risk processes, and partner with senior stakeholders to translate technical risk into business outcomes, while ensuring ongoing resilience and security maturity.

Qualifications

  • Proven experience in information security risk management, governance, and security assurance within complex or regulated environments.
  • Strong knowledge of cyber security risks, controls, cloud technologies, and regulatory frameworks.
  • Experience leading security risk assessments across systems, suppliers, projects, and change initiatives.
  • Ability to translate complex technical risks into clear, pragmatic business outcomes.
  • Excellent stakeholder management, communication, and influencing skills, including engagement with senior leaders.
  • Confident working autonomously while contributing to a collaborative, high performing security culture.
  • Strong analytical skills, professional judgement, and a proactive approach to risk management.
  • Experience mentoring or supporting junior analysts and promoting security best practice.
  • Relevant certifications such as CISSP, CISM, CRISC, or ISO 27001 qualifications are desirable.

Responsibilities

  • Lead security risk assessments for complex systems, suppliers, projects, and business change initiatives.
  • Assess the effectiveness of security controls, identifying gaps and supporting pragmatic risk treatment plans.
  • Provide expert security risk guidance for projects, procurement, and supplier onboarding activities.
  • Produce clear, high quality risk assessments, treatment plans, exceptions, and management reporting.
  • Deliver risk based advice and constructive challenge to technical and business stakeholders.
  • Support the continuous improvement of information security risk processes and ways of working.
  • Mentor junior analysts, providing guidance and quality assurance to strengthen team capability.
  • Support audit, compliance, and assurance activities, ensuring findings are tracked through to resolution.
  • Monitor emerging threats, regulatory changes, and compliance requirements, escalating risks where appropriate.

Skills

Security risk management
Governance
Security assurance
Cloud technologies
Regulatory frameworks
Stakeholder management
Communication
Analytical skills
Mentoring
Cyber security

Job description

Role Title: Senior Information Security Risk Analyst
Location: Leeds (Hybrid - 2 days per week on site)
Contract: Permanent
Working Pattern: Full Time

MPS has a new opportunity as a Senior Information Security Risk Analyst to play a pivotal role in strengthening and evolving our cyber and information security capabilities. Acting as a trusted expert, you'll lead complex security initiatives, drive the design and assurance of effective security controls, and manage security risks in line with organisational priorities, regulatory requirements, and risk appetite. Working with significant autonomy and influence, you'll translate complex technical and regulatory challenges into pragmatic business outcomes while helping to shape security best practice, mentor colleagues, and enhance organisational resilience and security maturity

As our new Senior Information Security Risk Analyst, you will also:
  • Lead security risk assessments for complex systems, suppliers, projects, and business change initiatives.
  • Assess the effectiveness of security controls, identifying gaps and supporting pragmatic risk treatment plans.
  • Provide expert security risk guidance for projects, procurement, and supplier onboarding activities.
  • Produce clear, high quality risk assessments, treatment plans, exceptions, and management reporting.
  • Deliver risk based advice and constructive challenge to technical and business stakeholders.
  • Support the continuous improvement of information security risk processes and ways of working.
  • Mentor junior analysts, providing guidance and quality assurance to strengthen team capability.
  • Support audit, compliance, and assurance activities, ensuring findings are tracked through to resolution.
  • Monitor emerging threats, regulatory changes, and compliance requirements, escalating risks where appropriate.
We are looking for:
  • Proven experience in information security risk management, governance, and security assurance within complex or regulated environments.
  • Strong knowledge of cyber security risks, controls, cloud technologies, and regulatory frameworks.
  • Experience leading security risk assessments across systems, suppliers, projects, and change initiatives.
  • Ability to translate complex technical risks into clear, pragmatic business outcomes.
  • Excellent stakeholder management, communication, and influencing skills, including engagement with senior leaders.
  • Confident working autonomously while contributing to a collaborative, high performing security culture.
  • Strong analytical skills, professional judgement, and a proactive approach to risk management.
  • Experience mentoring or supporting junior analysts and promoting security best practice.
  • Relevant certifications such as CISSP, CISM, CRISC, or ISO 27001 qualifications are desirable.

We welcome applicants from all backgrounds, and we encourage you to apply even if you feel you do not match 100% of the technical requirements. We celebrate diversity, promote inclusivity and strive to create a work environment which ensures everyone can be heard.

In return, we can offer you:
  • Discretionary on-target bonus of 10%. Up to a max 20% based on performance
  • 11% pension contribution (3% from you, 8% from us - optional additional matched 3% contributions, e.g. 6% from you, 11% from us)
  • 25 days annual leave. Flexible public holidays and option to buy/sell additional leave
  • Private Medical Cover
  • Car Salary Sacrifice scheme
  • 6x salary death in service
  • Holistic health and wellbeing support package
  • A truly flexible hybrid-working arrangement
  • A culture that promotes inclusivity, wellbeing and rewards hard work
Who We Are

Medical Protection Society (MPS) is the world’s leading protection organisation for Doctors, Dentists and healthcare professionals. We protect and support the professional interests of over 350,000 Members around the world.

We are a not-for-profit organisation, meaning our Members' premiums are kept safe should our Members require support for complaints or claims arising from professional practice, or invested into bettering the organisation, our colleagues and our products.

Our philosophy is to support safe practice in medicine and dentistry by helping to avert problems in the first place. We also actively campaign for regulatory and legal reforms that benefit Members and the wider healthcare professions.

To do this, we need colleagues who are trusted and supported to deliver their best work, whether that be through leadership development, fully-funded training courses or peer-to-peer support. We want our colleagues to feel empowered enough to deliver positive change, display ambition to push themselves and are determined when faced with a challenge, whilst ensuring our Member's best interests are at the core.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Risk Lead (Hybrid)
Senior Information Security Risk Lead (Hybrid)

Medical Protection Society • Leeds

Hybrid
GBP 80,000 - 100,000
Discretionary bonus
Pension 11%
Annual leave 25 days
+6
Portfolio Assurance Analyst
Portfolio Assurance Analyst

Medical Protection Society • Leeds

Hybrid
GBP 45,000 - 55,000
Up to 20% discretionary annual bonus
Annual performance-related pay review
11% pension contribution
+5
Information Security and Compliance Risk Manager
Information Security and Compliance Risk Manager

Bupa • Salford

On-site
GBP 54,000 - 74,000
Annual performance bonus
Private medical insurance
Generous pension contribution
+5
Information Security Analyst
Information Security Analyst

Sopra Steria • Leeds

Hybrid
GBP 21,000 - 35,000
25 days annual leave
Health cash plan
Life assurance
+1
Information Security Analyst
Information Security Analyst

Sellick Partnership • Manchester

Hybrid
GBP 29,000 - 48,000
Claims Manager
Claims Manager

Medical Protection Society • Leeds

Hybrid
GBP 60,000 - 85,000
Up to 15% discretionary bonus
Pension contribution (11%)
26 days plus bank holidays
+2
Senior or Principal Security Consultant (Risk Management)
Senior or Principal Security Consultant (Risk Management)

Logiq • Bristol, Chippenham

Hybrid
GBP 70,000 - 120,000
Competitive salary
Car allowance
Up to 10% performance bonus
+3
Information Risk Manager
Information Risk Manager

Skipton Building Society • Skipton

Hybrid
GBP 70,000 - 90,000
Annual discretionary bonus
25 days annual leave
Company pension contribution
+3
Information Security Analyst
Information Security Analyst

Sopra Steria Ltd • Leeds

Hybrid
GBP 21,000 - 35,000
25 days annual leave
Health cash plan
Life assurance
+1
Engineering Manager – Building Services
Engineering Manager – Building Services

Medical Protection Society • Leeds

On-site
GBP 65,000 - 90,000
On-target bonus 10%
Bonus up to 20%
Pension contributions up to 11%
+7