Cyber Security Risk & Policy Manager
- Hiring from
- Probably Worldwide
- Work type
- Remote
- Posted
- Sep 25, 2026
Job Description
This is a remote position.
Role: Cyber Security Risk & Policy Manager
Type: 12 Month Contract (FTC)
Location: Remote (some travel to site)
**Valid SC Clearance is required**
Role Overview
Our client, a leading MSSP is seeking a Cyber Security Risk & Policy Manager to support one of their customers in overseeing the identification, assessment, and mitigation of cyber risks across the organisation. Acting as a bridge between technology, operations, compliance, and leadership, you will ensure cyber resilience aligns with regulatory requirements, business objectives, and organisational risk appetite.
Key Responsibilities
-
Risk Management: Develop, implement, and manage the enterprise cyber security risk management framework and maintain the Cyber Security Risk Register across its lifecycle.
-
Policy & Standards: Create, update, and align cyber security policies and standards with overall strategic business needs.
-
Regulatory Compliance: Support internal/external audits and compliance deliverables under the Security of Network and Information Systems (NIS) Regulations and NCSC CAF.
-
Stakeholder Engagement: Partner with IT, Digital, and Operational Technology (OT) teams to track risk mitigation programs, remove project bottlenecks, and embed security into system design.
-
Metrics & Reporting: Design and monitor cyber security risk metrics and KPIs to report on risk exposure and program effectiveness.
Key Requirements
-
Framework Expertise: Strong knowledge of recognised security standards and frameworks (e.g., ISO 27001, ISO 27005, NIST, CIS Controls, and NCSC CAF).
-
Sector Experience: Proven experience performing cyber security risk assessments within regulated environments or CNI (e.g., Energy/Utilities, Finance, Healthcare).
-
Technical Breadth: Strong background in core IT systems and architecture. Familiarity with operational technology (OT) or SCADA/ICS environments is highly desirable.
-
Delivery & Governance: Background in tracking multi-stream work programs, navigating regulatory compliance, and managing cross-functional stakeholders under pressure.
-
Qualifications: Relevant degree or professional certifications (e.g., CISM, CRISC, CISSP, ISO 27001 LA/LI) or equivalent practical experience.