Get more replies from employers
Send a job-specific resume in minutes.
WestPoint Search has been retained to appoint an Information Security Risk Manager for an international organisation operating across IT and OT environments. Working directly with the CISO, this newly created role will shape how risk is identified, assessed and communicated across the business.
You will develop the risk management framework, perform BIAs, introduce quantitative methods such as FAIR, and produce executive reporting to inform risk-based investment decisions.
Shape how cyber security risk is understood, quantified and managed across a complex international organisation.
WestPoint Search has been exclusively retained to appoint an Information Security Risk Manager for an international organisation operating across both IT and Operational Technology environments.
Working directly with the CISO, this newly created position offers the opportunity to develop and mature how security risk is identified, assessed and communicated across the organisation.
The ambition is to move beyond traditional risk scoring towards a clearer understanding of business impact, financial exposure and risk-based decision making.
This isn't a role for someone looking to simply maintain an established risk framework. It's an opportunity to help build and shape one.
As the organisation's first dedicated Information Security Risk Manager, you'll have the autonomy to develop a more structured and business-focused approach to cyber security risk.
You’ll:
The objective isn’t simply better risk documentation. It’s helping business and technology leaders understand their security risks, make informed decisions and take ownership of them.
We're looking for an experienced Information Security Risk professional who combines strong risk expertise with the ability to influence across a complex organisation.
You’ll bring:
Experience with FAIR or other quantitative risk methodologies, third-party risk, NIS2, GRC platforms or industrial/OT environments would be advantageous.
You’ll work directly with the CISO, have the autonomy to shape this capability and play a key role in how cyber risk is understood, prioritised and managed across the organisation.