CyberSecurity Risk Manager
- Develop and maintain the organisation’s cybersecurity risk management strategy
- Conduct cybersecurity risk assessments and analyses to identify threats, categorise assets, assess vulnerabilities, and recommend risk treatment options
- Identify and assess cybersecurity-related threats and vulnerabilities of ICT systems and maintain awareness of the evolving threat landscape
- Perform Business Impact Assessments and support cybersecurity risk-based decision making
- Design, implement, monitor, and evaluate cybersecurity controls to ensure risks remain at acceptable levels
- Implement and maintain cybersecurity risk management frameworks, methodologies, standards, and best practices
- Support compliance with security, risk, governance, and regulatory requirements
- Enable business stakeholders, asset owners, and executives to make risk-informed decisions
- Promote a cybersecurity risk-aware culture across the organisation
- Develop and maintain cybersecurity risk registers, reports, metrics, and documentation
- Support threat modelling activities for systems, applications, and DevOps environments
- Contribute to the design of Zero Trust Architecture and security controls for critical enterprise services, including Directory Services
- Support personal data protection and information security governance initiatives
- Communicate risk management activities, findings, and recommendations to relevant stakeholders
- Minimum 9 years of relevant IT professional experience, with at least 6 years in a cybersecurity risk management, information security governance, cybersecurity architecture, or similar role.
- Minimum education level: Level 7 (Master's degree or equivalent) in an ICT-relevant field.
- At least 4 of the following certifications:
- CISA (Certified Information Systems Auditor)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CISSP (Certified Information Systems Security Professional)
- CGRC (Certified in Governance, Risk and Compliance)
- CSSLP (Certified Secure Software Lifecycle Professional)
- CCSP (Certified Cloud Security Professional)
- CISSP-ISSMP (Certified Information Systems Security Management Professional)
- GSNA (GIAC Certified Systems and Network Auditor)
- GCCC (GIAC Certified Critical Controls)
- GIAC Certified ISO-27000 Specialist
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
- ISO 27005 Risk Manager
- or equivalent, internationally recognized certification
- Excellent verbal and written communication in English, C1+ certificate desirable
- Advanced knowledge of cybersecurity risk management frameworks, methodologies, standards, regulatory requirements, tools, best practices, cyber threats, threat taxonomies, vulnerabilities, risk assessment methodologies, risk treatment strategies, and security controls.
- Experience performing cybersecurity risk assessments, cyber risk analysis, Business Impact Assessments, threat modelling activities, and monitoring the effectiveness of security controls within enterprise environments.
- Experience implementing cybersecurity governance, risk and compliance processes, including ServiceNow GRC, personal data protection documentation, and organisational risk management practices.
- Experience designing and assessing security architectures and controls, including Zero Trust Architecture, Secure Software Development Lifecycle (Secure SDLC), threat modelling for DevOps environments, and security controls for Directory Services.
- Ability to analyse and consolidate organisational risk management and quality management practices, propose and manage risk treatment, risk mitigation and risk-sharing strategies, and communicate recommendations to technical and non-technical stakeholders, including senior management.
- Excellent communication, documentation, analytical, problem-solving, and stakeholder management skills, with the ability to work independently and provide expert guidance on cybersecurity risk management matters.