Senior Cyber Risk Management Analyst

3 weeks ago


London, Greater London, United Kingdom Pearson Full time

Position: Senior Cyber Risk Management Analyst

Company: Pearson

Overview of Pearson:

At Pearson, our mission is to 'add life to a lifetime of learning,' enabling individuals to achieve their envisioned futures. We accomplish this by crafting engaging and impactful educational experiences. Established in 1844, Pearson has evolved alongside the changing market landscape, with over 20,000 dedicated employees focused on delivering high-quality, digital-first, accessible, and sustainable learning resources.

About the Chief Information Security Office:

The Chief Information Security Office (CISO) at Pearson is tasked with defining and upholding the enterprise vision, strategy, and program to safeguard the confidentiality, integrity, and availability of our information assets and technologies against various threats and vulnerabilities. Our structure comprises four main pillars: Security Operations, Security Engineering and Architecture, Posture Management, and Governance, Risk, and Compliance.

Role Overview:

As a vital member of the Governance, Risk, and Compliance pillar within CISO, you will establish strong collaborations with all CISO pillars and key stakeholders across Pearson's Digital and Technology sectors and Business Divisions. Your contributions will drive the innovation and evolution of Pearson's Security Risk and Compliance program, emphasizing third-party vendor and supply chain risk management. This includes developing and executing a comprehensive risk management strategy, performing thorough due diligence on third-party practices, and ensuring ongoing monitoring.

Key Responsibilities:

  • Conduct timely security evaluations of third-party suppliers, accurately documenting results and initiating necessary assurance actions.
  • Assist in producing high-quality, informative reports regarding third-party assurance evaluations.
  • Advise stakeholders on minimum Information/Cyber Security requirements for vendor assessments.
  • Collaborate with procurement, legal, and other relevant parties to ensure vendor contracts encompass appropriate security and compliance stipulations.
  • Engage in the collection of Key Risk Indicators (KRIs) and Management Information reporting related to third-party cyber risks and evaluations.
  • Support management with internal reporting, including updates for steering committees and senior management.
  • Develop metrics to demonstrate compliance with security frameworks.
  • Assist internal stakeholders with projects related to third-party information security.
  • Support the broader cyber risk function in third-party/vendor risk assessments.
  • Contribute to the global team's efforts in enhancing the program, implementing identified improvements for greater efficiency and effectiveness.
  • Provide management support and engage with the wider information security community.
  • Become a subject matter expert on third-party security requirements affecting Pearson.
  • Stay informed about the latest cyber threats, attack vectors, and industry best practices in third-party risk management.

Essential Skills & Experience:

  • Experience in the Cyber Security domain, particularly in Governance, Risk, Compliance, and Assurance.
  • Relevant professional certifications in cyber security (e.g., CISSP, CISM, CRISC, CCSP, ISO 27001 LA/LI).
  • Proven expertise with common information security management frameworks, such as ISO/IEC 27001/2, NIST 800-53, NIST CSF, and CIS benchmarks.
  • Experience in translating data privacy legal and regulatory requirements into information security language (e.g., GDPR, CCPA, HIPAA).
  • Excellent verbal and written communication skills, capable of engaging with diverse audiences, including technologists, executives, and business stakeholders.
  • Demonstrated experience in designing, implementing, and managing systems and assurance frameworks.
  • Strong analytical skills and critical thinking abilities, with a knack for problem-solving.
  • High level of initiative, reliability, and thought leadership.

Desirable Skills & Experience:

  • Master's degree in information security or a related field, such as Information Technology.
  • Experience conducting internal audits against recognized standards and frameworks (e.g., ISO 27001, ISO 22301).
  • Background in organizations of similar size or in consulting environments.
  • Knowledge of relevant legal and regulatory frameworks, particularly in the US, UK, and EU.
  • Experience in governing Payment Card Industry Data Security Standards (PCI DSS) compliance within eCommerce is advantageous.

Benefits at Pearson:

  • 25 days of annual leave (increasing by one day for each year of continuous service, up to 30 days); options for annual leave trading.
  • Annual bonus opportunities.
  • Private pension plan where the company contributes double your input, up to 16% based on age.
  • Life, private medical, and dental care insurance options, along with complimentary eye tests.
  • Stock/share purchase options available.
  • Maternity, paternity, and family care leave, along with flexible working policies.
  • Employee wellbeing assistance program.
  • Cycle to work scheme, volunteering days, gym membership discounts in select locations, and retail and leisure discounts.
  • Encouragement for staff to engage in at least 40 hours of training annually, including relevant AWS training and certification.

Flexible Working: Pearson is dedicated to hybrid working practices, allowing employees to manage their office attendance flexibly. Our core hours are Monday to Friday, 10 AM to 4 PM GMT/BST, accommodating personal commitments.

Diversity: At Pearson, we celebrate the strength of an inclusive culture and a sense of belonging. We foster an environment where differences are valued as strengths, and opportunities are equitable and accessible.

Application Process: Thank you for considering a position at Pearson. Please submit your updated CV and, if desired, a cover letter in English. For any inquiries or further information, feel free to reach out.

What to Expect from Pearson:

Did you know Pearson was recognized as one of the 10 most innovative education companies of 2022? At Pearson, we are committed to enhancing lives through learning, striving to meet the evolving needs of the global population with a digital-first approach. Our strategic vision is supported by five core business divisions: Assessment & Qualifications, Virtual Learning, English Language Learning, Workforce Skills, and Higher Education, alongside corporate divisions including Digital & Technology, Finance, Global Corporate Marketing & Communications, Human Resources, Legal, Strategy, and Direct to Consumer.

We believe that diversity, equity, and inclusion are vital to fostering innovation and vibrancy in our workplace. Our people are at the heart of our mission, and we are dedicated to creating an environment where talent can learn, grow, and thrive.


  • Business Analyst

    3 weeks ago


    London, Greater London, United Kingdom AXA Group Full time

    Senior Business Analyst - Global Financial Lines & Cyber Underwriting AXA XL is at the forefront of underwriting solutions in Financial Lines and Cyber insurance, catering to a diverse range of clients. This position presents an exceptional opportunity for a Senior Business Analyst to elevate their career within the Global Financial Lines & Cyber...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    Senior SOC Analyst – Remote / Hybrid OpportunityLT Harper - Cyber Security Recruitment is seeking a highly skilled Cyber Security Operations Centre (SOC) Consultant to join our team. As a leading cyber security recruitment agency, we specialise in Offensive & Defensive Security and are undergoing a period of significant growth within the UK.This is an...


  • London, Greater London, United Kingdom CornerStone - Risk, Cyber & Security Full time

    Job Description**About CornerStone - Risk, Cyber & Security**We are a leading, award-winning, independent international Security Risk Consultancy, and we are now seeking a highly skilled Business Development Manager to join our growing team. Our company culture is built upon innovation, teamwork, taking ownership, and supporting each other. We invest in our...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    About the Role:LT Harper - Cyber Security Recruitment is seeking an experienced Cyber Security Risk Management Leader to join our team. As a key member of our organization, you will be responsible for overseeing the development, implementation, and continuous improvement of our information security risk management framework.Key Responsibilities:Design and...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    About the Role:LT Harper - Cyber Security Recruitment is seeking an experienced Cyber Security Risk Management Leader to join our team. As a key member of our organization, you will be responsible for overseeing the development, implementation, and continuous improvement of our information security risk management framework.Key Responsibilities:Design and...


  • London, Greater London, United Kingdom Lorien Full time

    Job OverviewCyber Risk Product AnalystLocation: Remote/HybridCompensation: Competitive Salary (Dependent on Experience)About the Company: Our client is a leading global insurance provider specializing in innovative risk solutions. They are seeking a Cyber Risk Product Analyst with a strong background in underwriting and cyber risk management.Key...


  • London, Greater London, United Kingdom CornerStone - Risk, Cyber & Security Full time

    About CornerStone - Risk, Cyber & SecurityCornerStone is a leading, award-winning, independent international Security Risk Consultancy, and we are now seeking a Business Development Manager to join our growing team. We are looking for an individual who enjoys working in a fast-paced, collaborative environment that is built upon innovation, teamwork, taking...


  • London, Greater London, United Kingdom CornerStone - Risk, Cyber & Security Full time

    About CornerStone - Risk, Cyber & SecurityCornerStone is a leading, award-winning, independent international Security Risk Consultancy, and we are now seeking a Business Development Manager to join our growing team. We are looking for an individual who enjoys working in a fast-paced, collaborative environment that is built upon innovation, teamwork, taking...


  • London, Greater London, United Kingdom KDR Talent Solutions Full time £50,000 - £65,000

    About the RoleKDR Talent Solutions is seeking a highly skilled Cyber Security Risk Analyst to join our team. As a key member of our organization, you will be responsible for evaluating cyber security controls, conducting risk assessments, and collaborating with cross-functional teams to ensure the security and integrity of our systems.Key...


  • London, Greater London, United Kingdom KDR Talent Solutions Full time £50,000 - £65,000

    About the RoleKDR Talent Solutions is seeking a highly skilled Cyber Security Risk Analyst to join our team. As a key member of our organization, you will be responsible for evaluating cyber security controls, conducting risk assessments, and collaborating with cross-functional teams to ensure the security and integrity of our systems.Key...


  • London, Greater London, United Kingdom KDR Talent Solutions Full time £50,000 - £65,000

    Job Title: Information Security Analyst ContractJob Type: ContractIndustry: Financial ServicesLocation: Remote (Hybrid)Job Description:KDR Talent Solutions is seeking an experienced Information Security Analyst to join our client, a leading re-insurance company listed on the FTSE 250. As a key member of the Information Security team, you will be responsible...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    Job OverviewLT Harper - Cyber Security Recruitment is seeking a highly skilled Cyber Risk Advisory Consultant to join our team. As a Cyber Risk Advisory Consultant, you will be responsible for providing expert advice to clients on managing and mitigating cyber risks.Key Responsibilities:Lead engagements and provide current knowledge of the cyber threat...


  • London, Greater London, United Kingdom Pearson Full time

    Position: Senior Cyber Risk Management Analyst Company: Pearson About Pearson: At Pearson, our mission is to 'add life to a lifetime of learning,' enabling individuals to achieve their envisioned futures. We create dynamic and impactful learning experiences tailored for real-world application. Established in 1844, Pearson has continually evolved to meet the...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    We are currently working with a leading global company, boasting a workforce of over 50,000 employees worldwide.To increase your chances of success, we recommend reviewing the following overview of this role before applying.Our client is seeking a seasoned Cyber Security Risk Manager to oversee the development, implementation, and continuous improvement of...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    We are currently working with a leading global company, boasting a workforce of over 50,000 employees worldwide.To increase your chances of success, we recommend reviewing the following overview of this role before applying.Our client is seeking a seasoned Cyber Security Risk Manager to oversee the development, implementation, and continuous improvement of...


  • London, Greater London, United Kingdom Pearson Full time

    Position: Senior Cyber Risk Management Analyst Company: Pearson About Pearson: At Pearson, our mission is to 'add life to a lifetime of learning', enabling individuals to achieve their aspirations. We focus on creating engaging and impactful educational experiences. Established in 1844, Pearson has evolved alongside the educational landscape, employing over...


  • London, Greater London, United Kingdom BlueVoyant Full time

    About the RoleWe are seeking a highly skilled Cyber Risk Analyst I to join our team at BlueVoyant. As a Cyber Risk Analyst I, you will play a critical role in helping our clients understand their cyber risk profiles and develop strategies to mitigate those risks.Key ResponsibilitiesProduce high-quality reports that help clients understand their cyber risk...


  • London, Greater London, United Kingdom BlueVoyant Full time

    About the RoleWe are seeking a highly skilled Cyber Risk Analyst I to join our team at BlueVoyant. As a Cyber Risk Analyst I, you will play a critical role in helping our clients understand their cyber risk profiles and develop strategies to mitigate those risks.Key ResponsibilitiesProduce high-quality reports that help clients understand their cyber risk...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    We are currently working with a leading global enterprise, boasting a workforce of over 50,000 employees worldwide.They are seeking a seasoned Cyber Security Risk Manager to oversee the development, implementation, and continuous improvement of their information security risk management framework. This individual will be responsible for identifying potential...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    We are currently working with a leading global enterprise, boasting a workforce of over 50,000 employees worldwide.They are seeking a seasoned Cyber Security Risk Manager to oversee the development, implementation, and continuous improvement of their information security risk management framework. This individual will be responsible for identifying potential...