Reports To: Head of Cybersecurity
Job Summary:
The Cyber Risk Manager is responsible for overseeing a team identifying, assessing, and mitigating cybersecurity risks across the organization. This role involves managing a team developing and implementing risk management strategies, policies, and procedures to protect the organization's information assets and ensure compliance with relevant regulations and standards.
Key Responsibilities:
- Risk Assessment and Management:
- Manage projects conducting regular risk assessments and vulnerability assessments to identify potential threats and weaknesses.
- Monitor and report on the status of risk management activities and the effectiveness of controls.
- Policy and Procedure Development:
- Develop, review, and update cybersecurity policies, procedures, and guidelines.
- Ensure compliance with industry standards, regulatory requirements, and best practices.
- Incident Response and Management:
- Lead the response to cybersecurity incidents, including investigation, containment, and remediation.
- Develop and maintain incident response plans and conduct regular drills and exercises.
- Security Awareness and Training:
- Develop and deliver cybersecurity awareness and training programs for employees.
- Promote a culture of security awareness and ensure that all staff understand their role in protecting the organization’s information assets.
- Collaboration and Communication:
- Work closely with IT, legal, compliance, and other departments to ensure a cohesive approach to cybersecurity.
- Communicate cybersecurity risks and issues to senior management and other stakeholders.
- Continuous Improvement:
- Stay up-to-date with the latest cybersecurity trends, threats, and technologies.
- Continuously improve the organization’s cybersecurity posture by implementing new technologies and best practices.
Qualifications:
- Bachelor’s degree in Information Security, Computer Science, or a related field. A Master’s degree is a plus.
- Experience:
- At least 5 years of experience in cybersecurity, risk management, or a related field.
- Proven experience in conducting risk assessments and developing risk mitigation strategies.
- Skills:
- Strong understanding of cybersecurity frameworks and standards (e.g., ISO 27001).
- Excellent analytical and problem-solving skills.
- Strong communication and interpersonal skills.
- Ability to work independently and as part of a team.
Preferred Qualifications:
- Knowledge of cybersecurity tools and technologies (e.g., SIEM, firewalls, endpoint protection).
- Experience in a specific industry (e.g., finance, healthcare) with knowledge of relevant regulations (e.g., GDPR, HIPAA).