This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Whitehall Resources are currently looking for a Cyber Risk Consultant based in Cheshire for an initial 7-month contract. The Lead Cyber Risk Consultant will spearhead the EOL risk assessment project, providing strategic direction and oversight. In this role, you will lead a comprehensive evaluation of cybersecurity risks associated with End-of-Life technologies across the bank and apply a new cyber risk methodology to assign risk ratings.
Job Responsibility:
Lead Risk Assessments: Plan and conduct a full stock assessment of EOL technologies within the bank
Risk Rating & Analysis: Oversee the analysis of identified vulnerabilities and weaknesses and produce risk ratings and reports
Residual Risk Reduction: Identify and recommend risk mitigation opportunities to reduce residual risk in legacy platforms and applications
Remediation Planning: Collaborate closely with technology owners and engineering teams to develop remediation plans and prioritize fixes or upgrades for EOL systems
Project Leadership & Coordination: Coordinate the efforts of the Cyber Risk Analysts, assigning tasks and monitoring progress
Stakeholder Engagement: Serve as the primary point of contact for stakeholders
Communicate risk findings and status updates
Transition to BAU: Ensure that remediation activities and improved risk practices are handed over smoothly to the permanent operational teams
Requirements:
Approximately 8-10+ years of experience in cybersecurity
Significant experience in cyber risk management or security consulting roles
Prior experience leading risk assessment projects or large-scale security consulting engagements
Deep knowledge of cyber risk management practices, including risk assessment methodologies and frameworks (e.g. NIST CSF, ISO 27005, FAIR)
Ability to identify, classify, and prioritize cybersecurity risks in a large enterprise environment
Strong understanding of IT infrastructure and applications, especially the challenges posed by End-of-Life technologies
Advanced analytical skills (“cyber analytics”), including proficiency with risk analysis tools or GRC platforms
Proven ability to lead a team or project in a cybersecurity context
Excellent organizational skills to manage multiple parallel workstreams
Exceptional communication skills, both written and verbal
Strong stakeholder management and negotiation skills
Adept at solving complex problems and devising risk mitigation strategies
Flexibility to work with both onshore and offshore teams
Industry-recognized certifications in cybersecurity/risk are highly desirable (e.g., CISSP, CISM, CRISC, CISA)
Familiarity with relevant security standards and regulations (e.g., ISO 27001, NIST cybersecurity framework, banking industry regulations)
Nice to have:
Experience in the banking or financial services sector is highly desirable
Certifications in cloud security or technical areas are a bonus (e.g., AWS/Azure security certifications)