Senior Cyber Risk Management Analyst

3 weeks ago


London, Greater London, United Kingdom Pearson Full time

Position: Senior Cyber Risk Management Analyst

Company: Pearson

About Pearson:

At Pearson, our mission is to 'add life to a lifetime of learning,' enabling individuals to achieve their envisioned futures. We create dynamic and impactful learning experiences tailored for real-world application. Established in 1844, Pearson has continually evolved to meet the demands of a changing market, with over 20,000 dedicated employees focused on delivering high-quality, digital-first, and sustainable educational resources.

About the Chief Information Security Office:

The Chief Information Security Office (CISO) at Pearson is tasked with developing and maintaining the overarching vision, strategy, and program aimed at safeguarding the confidentiality, integrity, and availability of our information assets and technologies against various threats and vulnerabilities. Our structure comprises four essential pillars: Security Operations, Security Engineering and Architecture, Posture Management, and Governance, Risk, and Compliance.

Role Overview:

As a vital member of the Governance, Risk, and Compliance pillar within CISO, you will forge strong partnerships across all CISO pillars and with key stakeholders throughout Pearson's Digital and Technology sectors and Business Divisions. Your contributions will drive the innovation and evolution of Pearson's Security Risk and Compliance program, emphasizing third-party vendor and supply chain risk management. This includes the development and execution of a comprehensive risk management framework, thorough due diligence on third-party practices, and ongoing monitoring.

Key Responsibilities:

  • Conduct timely security evaluations of third-party suppliers, accurately documenting results and initiating appropriate assurance actions.
  • Assist in producing high-quality, informative reports regarding third-party assurance evaluations.
  • Provide expert advice to stakeholders on minimum Information/Cyber Security requirements for vendor assessments.
  • Collaborate with procurement, legal, and other teams to ensure vendor contracts encompass necessary security and compliance stipulations.
  • Engage in the collection of Key Risk Indicators (KRIs) and Management Information reporting concerning third-party cyber risks and evaluations.
  • Support management with internal reporting, including updates for steering committees and senior management.
  • Develop metrics to demonstrate compliance with security frameworks.
  • Assist internal stakeholders with information security projects related to third parties.
  • Support the broader cyber risk function in third-party/vendor risk assessments.
  • Contribute to the global team's efforts in enhancing the program, addressing current and future improvements for greater efficiency.
  • Provide management support and engage with the wider information security community.
  • Develop expertise in third-party security requirements relevant to Pearson.
  • Stay informed about the latest cyber threats, attack vectors, and industry best practices in third-party risk management.

Essential Skills & Experience:

  • Experience in the Cyber Security domain, particularly in Governance, Risk, Compliance, and Assurance.
  • Relevant professional qualifications in cyber security (e.g., CISSP, CISM, CRISC, CCSP, ISO 27001 LA/LI).
  • Proven expertise with established information security management frameworks, such as ISO/IEC 27001/2, NIST 800-53, NIST CSF, and CIS benchmarks.
  • Experience in translating data privacy legal and regulatory requirements into information security terms (e.g., GDPR, CCPA, HIPAA).
  • Strong verbal and written communication skills, capable of engaging diverse audiences, including technologists, executives, and business stakeholders.
  • Experience in designing, implementing, and managing systems and assurance frameworks.
  • Analytical mindset with strong problem-solving abilities.
  • High level of initiative, reliability, and thought leadership.

Desirable Skills & Experience:

  • Master's degree in information security or a related field, such as Information Technology.
  • Experience conducting internal audits against recognized standards and frameworks (e.g., ISO 27001, ISO 22301).
  • Experience in organizations of similar size or in consulting roles.
  • Knowledge of relevant legal and regulatory requirements, particularly in the US, UK, and EU.
  • Experience with Payment Card Industry Data Security Standards (PCI DSS) compliance in eCommerce is advantageous.

Benefits:

  • 25 days of annual leave, increasing with service; options for annual leave trading.
  • Annual bonus opportunities.
  • Generous pension plan contributions.
  • Comprehensive life, medical, and dental insurance options.
  • Stock/share purchase options available.
  • Flexible working arrangements and family care leave policies.
  • Employee wellbeing assistance programs.
  • Opportunities for professional development and training.

Commitment to Diversity:

At Pearson, we celebrate the strength of an inclusive culture and a sense of belonging. We foster an environment where differences are valued, and opportunities are equitable and accessible.

Application Process:

We appreciate your interest in a career with Pearson. Please submit your updated CV and, if desired, a cover letter in English. For any questions or further information, feel free to reach out.

Join Us:

Discover how Pearson is recognized as one of the most innovative education companies, dedicated to transforming learning experiences.


  • Business Analyst

    3 weeks ago


    London, Greater London, United Kingdom AXA Group Full time

    Senior Business Analyst - Global Financial Lines & Cyber Underwriting AXA XL is at the forefront of underwriting solutions in Financial Lines and Cyber insurance, catering to a diverse range of clients. This position presents an exceptional opportunity for a Senior Business Analyst to elevate their career within the Global Financial Lines & Cyber...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    Senior SOC Analyst – Remote / Hybrid OpportunityLT Harper - Cyber Security Recruitment is seeking a highly skilled Cyber Security Operations Centre (SOC) Consultant to join our team. As a leading cyber security recruitment agency, we specialise in Offensive & Defensive Security and are undergoing a period of significant growth within the UK.This is an...


  • London, Greater London, United Kingdom CornerStone - Risk, Cyber & Security Full time

    Job Description**About CornerStone - Risk, Cyber & Security**We are a leading, award-winning, independent international Security Risk Consultancy, and we are now seeking a highly skilled Business Development Manager to join our growing team. Our company culture is built upon innovation, teamwork, taking ownership, and supporting each other. We invest in our...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    About the Role:LT Harper - Cyber Security Recruitment is seeking an experienced Cyber Security Risk Management Leader to join our team. As a key member of our organization, you will be responsible for overseeing the development, implementation, and continuous improvement of our information security risk management framework.Key Responsibilities:Design and...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    About the Role:LT Harper - Cyber Security Recruitment is seeking an experienced Cyber Security Risk Management Leader to join our team. As a key member of our organization, you will be responsible for overseeing the development, implementation, and continuous improvement of our information security risk management framework.Key Responsibilities:Design and...


  • London, Greater London, United Kingdom Lorien Full time

    Job OverviewCyber Risk Product AnalystLocation: Remote/HybridCompensation: Competitive Salary (Dependent on Experience)About the Company: Our client is a leading global insurance provider specializing in innovative risk solutions. They are seeking a Cyber Risk Product Analyst with a strong background in underwriting and cyber risk management.Key...


  • London, Greater London, United Kingdom CornerStone - Risk, Cyber & Security Full time

    About CornerStone - Risk, Cyber & SecurityCornerStone is a leading, award-winning, independent international Security Risk Consultancy, and we are now seeking a Business Development Manager to join our growing team. We are looking for an individual who enjoys working in a fast-paced, collaborative environment that is built upon innovation, teamwork, taking...


  • London, Greater London, United Kingdom CornerStone - Risk, Cyber & Security Full time

    About CornerStone - Risk, Cyber & SecurityCornerStone is a leading, award-winning, independent international Security Risk Consultancy, and we are now seeking a Business Development Manager to join our growing team. We are looking for an individual who enjoys working in a fast-paced, collaborative environment that is built upon innovation, teamwork, taking...


  • London, Greater London, United Kingdom KDR Talent Solutions Full time £50,000 - £65,000

    About the RoleKDR Talent Solutions is seeking a highly skilled Cyber Security Risk Analyst to join our team. As a key member of our organization, you will be responsible for evaluating cyber security controls, conducting risk assessments, and collaborating with cross-functional teams to ensure the security and integrity of our systems.Key...


  • London, Greater London, United Kingdom KDR Talent Solutions Full time £50,000 - £65,000

    About the RoleKDR Talent Solutions is seeking a highly skilled Cyber Security Risk Analyst to join our team. As a key member of our organization, you will be responsible for evaluating cyber security controls, conducting risk assessments, and collaborating with cross-functional teams to ensure the security and integrity of our systems.Key...


  • London, Greater London, United Kingdom KDR Talent Solutions Full time £50,000 - £65,000

    Job Title: Information Security Analyst ContractJob Type: ContractIndustry: Financial ServicesLocation: Remote (Hybrid)Job Description:KDR Talent Solutions is seeking an experienced Information Security Analyst to join our client, a leading re-insurance company listed on the FTSE 250. As a key member of the Information Security team, you will be responsible...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    Job OverviewLT Harper - Cyber Security Recruitment is seeking a highly skilled Cyber Risk Advisory Consultant to join our team. As a Cyber Risk Advisory Consultant, you will be responsible for providing expert advice to clients on managing and mitigating cyber risks.Key Responsibilities:Lead engagements and provide current knowledge of the cyber threat...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    We are currently working with a leading global company, boasting a workforce of over 50,000 employees worldwide.To increase your chances of success, we recommend reviewing the following overview of this role before applying.Our client is seeking a seasoned Cyber Security Risk Manager to oversee the development, implementation, and continuous improvement of...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    We are currently working with a leading global company, boasting a workforce of over 50,000 employees worldwide.To increase your chances of success, we recommend reviewing the following overview of this role before applying.Our client is seeking a seasoned Cyber Security Risk Manager to oversee the development, implementation, and continuous improvement of...


  • London, Greater London, United Kingdom Pearson Full time

    Position: Senior Cyber Risk Management Analyst Company: Pearson About Pearson: At Pearson, our mission is to 'add life to a lifetime of learning', enabling individuals to achieve their aspirations. We focus on creating engaging and impactful educational experiences. Established in 1844, Pearson has evolved alongside the educational landscape, employing over...


  • London, Greater London, United Kingdom BlueVoyant Full time

    About the RoleWe are seeking a highly skilled Cyber Risk Analyst I to join our team at BlueVoyant. As a Cyber Risk Analyst I, you will play a critical role in helping our clients understand their cyber risk profiles and develop strategies to mitigate those risks.Key ResponsibilitiesProduce high-quality reports that help clients understand their cyber risk...


  • London, Greater London, United Kingdom BlueVoyant Full time

    About the RoleWe are seeking a highly skilled Cyber Risk Analyst I to join our team at BlueVoyant. As a Cyber Risk Analyst I, you will play a critical role in helping our clients understand their cyber risk profiles and develop strategies to mitigate those risks.Key ResponsibilitiesProduce high-quality reports that help clients understand their cyber risk...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    We are currently working with a leading global enterprise, boasting a workforce of over 50,000 employees worldwide.They are seeking a seasoned Cyber Security Risk Manager to oversee the development, implementation, and continuous improvement of their information security risk management framework. This individual will be responsible for identifying potential...


  • London, Greater London, United Kingdom LT Harper - Cyber Security Recruitment Full time

    We are currently working with a leading global enterprise, boasting a workforce of over 50,000 employees worldwide.They are seeking a seasoned Cyber Security Risk Manager to oversee the development, implementation, and continuous improvement of their information security risk management framework. This individual will be responsible for identifying potential...

  • Senior Analyst

    3 weeks ago


    London, Greater London, United Kingdom AXA Group Full time

    Senior Business Analyst - Global Financial Lines & Cyber Underwriting Location: Flexible AXA XL is a leader in the underwriting of Financial Lines and Cyber insurance, catering to a diverse range of clients. As the demand for Financial Lines remains strong and Cyber insurance continues to expand, this position presents substantial opportunities for the...