Group Information Security Risk Analyst
Arrow Global Group Manchester, Royaume-UniGroup Information Security Risk Analyst
Group Information Security Risk Analyst
Department: Governance & Risk
Employment Type: Permanent - Full Time
Location: Manchester, UK
Description
The Group Information Security Risk Analyst will play a key role within Arrow's Group Information Security Function by maintaining the Information Security Risk Framework, delivering high-quality risk assessments and reporting, engaging with stakeholders to drive remediation activities, and ensuring a proportionate and risk-based approach is applied across a diverse range of business sectors.
The role will also support wider Information Security activities including third-party security assurance, due diligence reviews, responses to security questionnaires, audit activities, and security awareness initiatives as required.
About the role
- Conduct information security risk assessments across Arrow Global Group and portfolio companies using recognised risk assessment methodologies and frameworks.
- Produce high-quality risk assessment reports, management summaries, and recommendations for both technical and non-technical stakeholders.
- Track and monitor remediation actions arising from assessments, audits, incidents, and reviews, ensuring timely resolution of identified risks.
- Work closely with stakeholders to ensure recommendations are understood, agreed, and appropriately implemented.
- Escalate significant, overdue, or unresolved information security risks through appropriate governance channels.
- Support the ongoing development, maintenance, and improvement of the Group Information Security Risk Framework.
- Assess the effectiveness of information security controls and identify opportunities for improvement.
- Apply recognised security frameworks and standards including ISO27001, NIST Cybersecurity Framework, CIS Controls, PCI-DSS, and other relevant best practices in a proportionate and risk-based manner.
- Liaise with Cyber Security, IT, Business Continuity, Data Protection, Risk, Compliance, and Internal Audit teams to ensure security requirements are appropriately reflected within assessment activities.
- Support third-party security assurance activities, including supplier security reviews, due diligence assessments, and ongoing monitoring of third-party risks.
- Contribute to governance reporting through the preparation of metrics, risk dashboards, management information, and committee papers.
- Maintain awareness of emerging threats, vulnerabilities, regulatory developments, Artificial Intelligence (AI) risks, and industry best practices.
About you
- Educated to degree level in Information Security, Cyber Security, Computer Science, Information Systems, Risk Management, Business Management, or equivalent levels of experience.
- A minimum of 5 years' proven experience within Information Security, Cyber Security, IT Risk, or related disciplines.
- Strong understanding of Information Security Risk Management principles and methodologies.
- Experience conducting risk assessments, control reviews, audits, or assurance activities.
- Technical knowledge of information security frameworks and standards including ISO27001, NIST Cybersecurity Framework, CIS Controls, DORA, PCI-DSS, and related security practices.
- Strong communicator with positive influencing and interpersonal skills.
- Ability to synthesise complex technical and business information and present findings in a clear and concise manner.
- Effective prioritisation and organisational skills with the ability to manage multiple competing priorities.
- Strong analytical and problem-solving skills.
- Experience producing professional reports and management presentations.
- Understanding of cloud technologies and associated information security risks.
- Awareness of Artificial Intelligence (AI), associated risks, governance considerations, and emerging industry developments.