
Technology Risk Management Analyst
- Windsor, Berkshire
- Permanent
- Full-time
- Assist in implementing the Technology Risk and Controls framework, ensuring timely assessment and treatment of security risks.
- Ensure Technology risks are either mitigated or accepted in accordance with the risk appetite.
- Collaborate with IT teams to identify and assess Technology risks, including Cyber and InfoSec risks.
- Conduct periodic Technology risk assessments of key services, third parties, and regulatory commitments, and monitor remediation plans.
- Assess and classify services based on their Confidentiality, Integrity, and Availability.
- Use the output from Technology risk assessments to identify control gaps and weaknesses, providing strategic direction to improve control efficacy.
- Work with IT/OT teams to understand key Technology risks and agree on actions to mitigate or monitor and enhance controls.
- Produce quarterly IT Risk submissions for business units and collaborate with Group-level risk functions on Technology risk.
- Inform senior leadership of risks and recommendations in non-technical terms, considering cost/benefit, to ensure the security of Information Systems.
- Preferred active certification from ISACA in one of the following domains:
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Strong knowledge of Technology risk and control assessment methods.
- Proficient in Information Security technologies, such as identity and access management, encryption, and multi-factor authentication.
- Understanding of power utilities, retail energy, and oil & gas industry trends and emerging threats is useful but not essential.
- Ability to leverage external networks to understand emerging Cyber Security threats and events.
- Knowledge of internal and/or external regulatory policies, standards, procedures, and controls (e.g., COBIT, COSO, NIST, ISO27xx).
- Capability to understand business visions and strategy, anticipate associated risks from an Information Technology perspective, and facilitate business objectives while managing Technology risk exposure; acting as a trusted Technology risk advisor to the business.