Cybersecurity Risk Management Expert

1 week ago


London, Greater London, United Kingdom Vallum Associates Full time

Vallum Associates seeks a seasoned Cybersecurity Risk Management Expert to bolster our defenses and ensure the integrity of our digital presence. In this pivotal role, you will leverage your expertise in Attack Surface Management to mitigate potential threats and protect our organization's assets.

This position demands a profound understanding of cybersecurity principles, complemented by extensive experience with ASM tools and the ability to communicate complex security concepts to both technical and non-technical stakeholders.

Key Responsibilities:

  • Attack Surface Analysis and Assessment
  • Regularly assess the organization's attack surface, encompassing network, cloud, and application assets.
  • Employ ASM tools (e.g., RiskIQ, Expanse, CyCognito) and threat intelligence to identify internet-facing assets and evaluate their susceptibility to potential threats.
  • Conduct continuous asset discovery to identify shadow IT, misconfigured services, and third-party risks.
  • Document all exposed assets to maintain an accurate inventory of the digital footprint across the organization.
  • Risk Evaluation and Mitigation
  • Evaluate the security posture of identified assets and prioritize risks based on potential impact and likelihood of exploitation.
  • Collaborate with IT, DevOps, and Security Operations teams to address high-risk exposures through configuration changes, access controls, or network segmentation.
  • Offer recommendations for securing exposed assets, reducing the attack surface, and mitigating identified vulnerabilities.
  • Ensure asset owners are informed of ASM findings and provide actionable guidance for risk mitigation.
  • Monitoring and Threat Intelligence Integration
  • Continuously monitor the attack surface for changes and newly discovered assets.
  • Integrate threat intelligence to identify and assess the relevance of emerging threats to the organization's digital assets.
  • Stay current on new attack techniques, tools, and threat actor activities that could impact the organization's attack surface.
  • Establish alerting and response protocols for identified high-risk exposures.
  • Reporting and Communication
  • Develop and deliver clear, actionable reports on attack surface findings, risk assessments, and remediation progress.
  • Effectively communicate risks and recommendations to technical and non-technical stakeholders, including executive leadership.
  • Create metrics and dashboards to provide visibility into the organization's attack surface and ASM program effectiveness.
  • Security Program Development and Continuous Improvement
  • Assist in developing and enhancing the Attack Surface Management program, including establishing standards for asset discovery and risk management.
  • Develop processes and workflows to automate attack surface discovery, monitoring, and assessment.
  • Provide training and awareness sessions to teams on reducing the attack surface and mitigating risks.
  • Identify opportunities to enhance security policies and procedures based on ASM findings and emerging best practices.

Required Qualifications:

  • Education: Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field. Equivalent experience may be considered.
  • Experience:
  • Minimum of [3-5] years of experience in cybersecurity, with a focus on Attack Surface Management, Threat Intelligence, Vulnerability Management, or related fields.
  • Hands-on experience with ASM tools (e.g., RiskIQ, Expanse, CyCognito) and asset discovery methodologies.
  • Familiarity with vulnerability management processes and tools, along with an understanding of network and cloud security principles.
  • Experience working in large-scale enterprise environments, including cloud (AWS, Azure, GCP) and hybrid infrastructures.
  • Certifications (preferred): CISSP, CISM, OSCP, CEH, CompTIA CySA+, or relevant security certifications.


  • London, Greater London, United Kingdom Risk Ledger Ltd Full time

    Risk Ledger Ltd is a company that prioritizes the security of global supply chains. To achieve this mission, we are building the world's first network of connected organisations working together to improve security defenses.The network is built on trust, allowing increased transparency and sharing of data across organisations and industries. This collective...


  • London, Greater London, United Kingdom ServiceNow Full time

    Cybersecurity Risk Management ExpertWe are seeking a highly skilled Cybersecurity Risk Management Expert to join our team. In this role, you will be responsible for identifying and mitigating potential security risks, as well as participating in the on-call rotation.Estimated Salary: $160,000 - $220,000 per yearAbout the RoleYou will work closely with teams...


  • London, Greater London, United Kingdom Audit & Risk Recruitment Full time

    Cybersecurity threats are increasingly prevalent, making it essential for organisations to have robust IT risk management and control frameworks in place. As a Cybersecurity Risk Officer, you will play a critical role in identifying, assessing, and mitigating IT-related risks within our client organisation.You will be responsible for developing and...


  • London, Greater London, United Kingdom Qube Research & Technologies Limited Full time

    Become a Cybersecurity ExpertWe are looking for a talented Cybersecurity Risk Mitigation Expert to join our team at Qube Research & Technologies Limited.This role involves leading the global vulnerability management programme, identifying, assessing, and mitigating vulnerabilities in systems, networks, and applications.The successful candidate will stay...


  • London, Greater London, United Kingdom CornerStone - Risk, Cyber & Security Full time

    We are seeking a highly skilled Cybersecurity Solutions Expert to join our team at CornerStone. As a key member of our cybersecurity division, you'll play a vital role in designing and implementing security solutions for our clients. With a competitive salary of £65,000 per annum, plus benefits, you'll have the opportunity to develop your career in a...


  • London, Greater London, United Kingdom CFGI Full time

    About CFGI:CFGI is a unique financial consulting firm that assists CFOs through complex business scenarios. As an extension of your finance team, our experts deliver seamless support services.Technical Expertise:We build cybersecurity frameworks for clients aligned with laws and industry standards.We conduct risk assessments and maturity evaluations for...


  • London, Greater London, United Kingdom WPP Full time

    Job DescriptionWe are seeking a highly skilled Cybersecurity Risk Management Expert to join our team at WPP. The successful candidate will play a critical role in managing cybersecurity risk and protecting our organization from emerging threats.The estimated salary for this position is $160,000 - $220,000 per year, depending on experience.Main...


  • London, Greater London, United Kingdom RAW Search Full time

    We are seeking a highly experienced Cybersecurity Risk Manager to join our team at RAW Search.Estimated Salary: £90,000 - £120,000 per annum.About the PositionThis is an exciting opportunity to lead our Cybersecurity Risk Management initiatives as a seasoned expert.As a key member of our team, you will be responsible for conducting comprehensive gap...


  • London, Greater London, United Kingdom Initi8 Recruitment Full time

    Cybersecurity ExpertWe are seeking a skilled Cybersecurity Expert to join our IT and Cybersecurity team in London. This exciting role offers the opportunity to play a pivotal part in managing and enhancing our cybersecurity infrastructure.Key Responsibilities:Monitor and manage network traffic using industry-leading tools, ensuring robust perimeter...


  • London, Greater London, United Kingdom Ki Insurance Full time

    Job Title: Cybersecurity Governance ExpertCybersecurity Governance Expert at Ki InsuranceAbout UsKi is a leading global insurance tech company, known for providing innovative solutions to the insurance industry. Our team of experts is dedicated to delivering exceptional services that meet the evolving needs of our customers.About the RoleWe are seeking a...


  • London, Greater London, United Kingdom Refonte Learning AI Full time

    Cybersecurity Training & Internship ProgramAt Refonte AI, we're committed to helping you launch your career in cybersecurity. As a Cybersecurity Expert, you'll work on cutting-edge projects that include securing multi-cloud AI infrastructure, vulnerability management, and ethical hacking techniques.We offer a comprehensive training program that covers the...


  • London, Greater London, United Kingdom Marlin Selection Recruitment Full time

    Job Title: Cybersecurity Risk Management DirectorJob Description:The Cybersecurity Risk Management Director is responsible for leading the development and implementation of information security strategies that align with the business goals of our client, a private bank in London. This role requires expertise in risk management, cybersecurity governance, and...


  • London, Greater London, United Kingdom Alcumus Full time

    At Alcumus, we empower organisations to achieve their highest potential by providing software-led risk management solutions. As a Cybersecurity Risk Management Specialist, you will be responsible for helping clients manage and mitigate risks in the field of information security. With a strong background in IT and cybersecurity, you will lead audits and...


  • London, Greater London, United Kingdom Macquarie Bank Limited Full time

    We are a team of trusted advisors to senior management, technology, risk and compliance teams, legal, commercial and deal teams, clients and auditors, who need to understand cybersecurity risk for their business, their technology and their clients.As a trusted advisor, you will be analysing regulatory requirements and advising on cybersecurity contractual...


  • London, Greater London, United Kingdom Barclay Simpson Full time

    **Job Title:** Cybersecurity ExpertWe are seeking an experienced Cybersecurity Expert to join our team at Barclay Simpson. The ideal candidate will have a minimum of four years of related work experience, with a strong background in information security.The successful candidate will conduct thorough security assessments to measure the adequacy of existing...


  • London, Greater London, United Kingdom Refonte Learning AI Full time

    Cybersecurity Internship OverviewAt Refonte Learning AI, we are seeking a motivated and talented individual to join our DevSecOps & Cybersecurity Internship program. As part of our team, you will have the opportunity to work on real-world projects, apply security best practices, and collaborate with industry experts in cybersecurity and DevSecOps.Key...


  • London, Greater London, United Kingdom Refonte Technologies Full time

    Become an IT and Cybersecurity Expert with Refonte TechnologiesAs a pioneer in IT and educational technology, we empower professionals to build expertise in cutting-edge domains like digital marketing, data science, business analytics, cybersecurity, UI/UX design, web development, and app development. Our mission is to inspire innovation, excellence, and...


  • London, Greater London, United Kingdom Aon Corporation Full time

    About the RoleWe are seeking a Cybersecurity Risk Management Professional to join our team at Aon Corporation. This is an exciting opportunity to shape the future of cyber risk and security.In this role, you will be responsible for advising clients on managing cybersecurity risks and enhancing their cybersecurity maturity. You will lead quantification...


  • London, Greater London, United Kingdom TalentHawk Full time

    Role OverviewTalentHawk is hiring a Compliance and Risk Management Expert to join our team! As a key member of our risk management department, you will play a critical role in ensuring the cybersecurity compliance of our clients' suppliers and third-party partners.In this position, you will be responsible for reviewing and updating contractual cybersecurity...


  • London, Greater London, United Kingdom Onyx-Conseil Full time

    Onyx-Conseil is seeking a highly skilled Cybersecurity Expert for Enterprise to join our team in Central London. As a Senior Information Security Analyst, you will play a vital role in maintaining information security policies, architecture, and technical standards.Key ResponsibilitiesMaintain information security policies, architecture, and technical...