Talent.com
Al Rayan Bank
Senior Cyber Security Risk ManagerAl Rayan Bank • Greater London, England, UK
No longer accepting applications
Senior Cyber Security Risk Manager

Senior Cyber Security Risk Manager

Al Rayan Bank • Greater London, England, UK
27 days ago
Job type
  • Full-time
Job description

The Senior Cyber Security Risk Manager will sit within the 2nd Line of Defence Risk team and be responsible for providing independent advice, support, guidance, testing, reporting, and challenge to the bank’s information security activities and control environment.

Key Responsibilities

  • Manage and maintain cyber/IS policies, standards, and governance processes to set clear expectations for managing cyber/IS risks, in close liaison with 1st line teams to ensure alignment of expectations, deliverables and proportionate outcomes based upon a changing threat landscape.
  • Provide independent second‑line oversight and challenge to cyber/IS threats, exposures, risks and controls across infrastructure, cloud services, applications, digital banking services, and third‑party providers.
  • Review, support and challenge risk and control assessments, security exceptions, penetration testing outcomes, vulnerability management activities, and remediation plans.
  • Provide second‑line oversight over the management of cyber/IS incidents, including escalation and reporting internally and externally.
  • Provide cyber/IS risk input into existing risk governance, committee and reporting structures to ensure alignment with the bank’s Risk Management Framework and Risk Appetite Statement.
  • Coordinate and support assurance over cyber/IS risk, including execution of assurance reviews, commissioning of third‑party assurance reviews, and managing regulatory and audit engagements relating to cyber/IS risk.
  • Assist with cyber/IS maturity assessments and benchmarking activities (e.g., CQUEST maturity questionnaire).
  • Support security awareness and security culture initiatives across the organisation, including phishing tests, social engineering susceptibility and red team security tests.

AI Governance & Emerging Technology Risk

  • Review the use of Artificial Intelligence and Generative AI solutions across the organisation in collaboration with IT colleagues.
  • Support the establishment and enhancement of the bank’s AI governance and risk management framework.
  • Assess risks relating to AI adoption, such as data leakage, bias, explainability, model misuse, and third‑party AI dependencies.
  • Provide second‑line oversight and challenge regarding AI‑related controls, policies, and risk assessments.
  • Support alignment with emerging frameworks (e.g., NIST AI Risk Management Framework) and relevant regulatory guidance.

Qualifications & Experience

  • Relevant professional certifications such as CISM, CISSP, CRISC, or CISA.
  • Significant experience in cybersecurity risk or information security governance within financial services.
  • Knowledge of security accreditations and standards, including NIST, CIS, DPA, ISO 207001, Cyber Essentials Plus, and UK regulatory expectations from PRA and/or FCA.
  • Strong understanding of Second Line of Defence responsibilities and regulated banking environments.
  • Demonstrable experience in process improvement and implementation, including behavioural change.
  • Experience providing challenge and oversight to technology and security teams.
  • Ability to communicate effectively with senior stakeholders and non‑technical audiences.

Knowledge & Skills

  • Ability to build positive relationships with senior executives, cyber security SMEs and across the wider organisation to instil a cyber security culture.
  • Demonstrable SME level expertise in information security risk management processes, frameworks, and procedures within regulated Financial Services environments.
  • Knowledge of application, infrastructure and networking security controls and systems covering physical, procedural and IT technical areas.
  • Ability to understand complex technical systems or solutions and document them for non‑technical readers.
  • Ability to identify risks and provide pragmatic advice on mitigation using agreed risk management methodology.
  • Willingness and ability to collaborate with other Risk colleagues and the first line to align risk processes across a regulated or complex business.
  • Ability to build relationships and work collaboratively with IT and key third‑party security suppliers for effective process delivery and improvement.

Behavioural Competencies

  • Trusted to do the right thing – act with total integrity, put the customer first, and keep promises.
  • Empowered to own – embrace change, take responsibility, and ask for help when needed.
  • Able to deliver – draw on strengths, show resilience, and foster a no‑blame, no‑ego mindset.
  • Motivated to succeed – pursue growth opportunities, celebrate success, and maintain enthusiasm for the role.

Conduct

  • Act with integrity.
  • Act with due skill, care and diligence.
  • Be open and co‑operative with regulators.
  • Pay due regard to the interests of customers and colleagues and treat them fairly.
  • Observe proper standards of market conduct.
  • Act to deliver good outcomes for retail customers.

This is a fantastic opportunity to join our growing bank where you can make a significant impact and advance your career in a diverse, ethical environment.

Empowering your career, together we’ll deliver banking you can believe in.

#J-18808-Ljbffr

Create a job alert for this search

Senior Cyber Security Risk Manager • Greater London, England, UK

Similar jobs

Cyber Security BISO: Strategic Risk Partner for Growth

ElsevierGreater London, England, GB
Full-time

Elsevier is hiring a Cyber Security Business Information Officer (BISO) in the Greater London area.This role focuses on managing security risk, providing expertise in security initiatives, and fost... Show more

 • Promoted

Third Party Cyber Risk Lead

Tokio Marine HCC InternationalGreater London, England, GB
Permanent

Reporting to the Cyber Governance Manager in the Business Information Security Office, you will own and mature TMHCC International’s third‑party cyber risk management processes, streamlining proces... Show more

 • Promoted

Senior Cyber and Technology Risk Manager

Pay.UKGreater London, England, GB
Permanent

Senior Cyber and Technology Risk Manager - Permanent, London.This role serves as the 2nd line cyber and technology risk expert, shaping and maintaining our risk frameworks to protect the organisati... Show more

 • Promoted

Vice President, Cyber Risk BA Team Lead

MUFG Bank, LtdGreater London, England, United Kingdom
Full-time

Vice President, Cyber Risk BA Team LeadApplylocations: Londontime type: Full timeposted on: Posted Todayjob requisition id: 10076966-WD**Do you want your voice heard and your actions to cou... Show more

 • Promoted • New!

Strategic Cyber Security Leader | Risk & Defense

Praxis TechGreater London, England, GB
Full-time

Chelsea Football Club in London seeks a strategic leader for Information and Cyber Security to shape the security vision, embed governance, and reduce risk across football and commercial operations... Show more

 • Promoted

Hybrid Cyber Security Manager: Risk & Provider Oversight

Yolk Recruitment LtdLondon, England, GB
Full-time

A leading recruitment agency is seeking a Cyber Security Manager to oversee third party providers and ensure effective cyber security practices.The role includes responsibility for risk management ... Show more

 • Promoted

Cyber Risk Manager - Active Security Clearance Required

Solirius ReplyGreater London, England, GB
Permanent

Solirius Reply, part of the Reply Group, is a technology consultancy and digital transformation partner that helps organisations solve complex challenges through strategy, design, engineering, and ... Show more

 • Promoted

Principal Cyber Security Governance & Risk Leader

Government Digital ServiceGreater London, England, United Kingdom
Full-time

The Government Digital Service (GDS) is the digital centre of government.We are responsible for setting, leading and delivering the vision for a modern digital government.Our priorities are to driv... Show more

 • Promoted • New!

Cyber Security Manager

Top RecruitGreater London, England, GB
Full-time

Join a leading Corporate Management Business.Lead on Cyber Security across the business.Top Recruit has partnered with a leading corporate travel management business.They are seeking an experienced... Show more

 • Promoted

Senior Network Security Specialist

The London Metal Exchange LimitedGreater London, England, United Kingdom
Permanent

Senior Network Security Specialist**Shift Pattern:**Standard 40 Hour Week (United Kingdom)**Scheduled Weekly Hours:**40**Corporate Grade:**D - Assistant Vice President**Reporting Line:**(UK Divisio... Show more

 • Promoted • New!

Senior Cyber Risk & Security Leader (Hybrid)

Spirit UK LtdGreater London, England, GB
Full-time

A leading cybersecurity firm is seeking an experienced Cyber Risk & Security Manager to lead cyber risk assessments and drive strategic improvements.The ideal candidate will have over 10 years of e... Show more

 • Promoted

Senior Director, Enterprise Risk Management

AirwallexGreater London, England, United Kingdom
Full-time

Airwallex is the only unified payments and financial platform for global businesses.Powered by our unique combination of proprietary infrastructure and software, we empower over 200,000 businesses ... Show more

 • Promoted

Senior Manager – Application Security

MiroGreater London, England, United Kingdom
Full-time

The Senior Manager of Application Security leads a global team responsible for embedding security into Miro’s Software Development Lifecycle (SDLC)—from concept to code to customer impact.This team... Show more

 • Promoted

Global Cyber Security and Compliance Director

KentGreater London, England, United Kingdom
Permanent

We are a future‑focused company in the energy sector committed to responsible energy solutions.Our core beliefs include playing big, embracing emotional agility, driving performance, and infinite t... Show more

 • Promoted • New!

Sr Director Product Security - Cybersecurity

NablaGreater London, England, United Kingdom
Full-time

The Product Security team at NielsenIQ is dedicated to enhancing business application security and making product teams accountable throughout the software development lifecycle.It not only protect... Show more

 • Promoted

Senior Cyber Security Consultant

ArupGreater London, England, United Kingdom
Full-time

Arup’s purpose, shared values and collaborative approach has set us apart for over 80 years, guiding how we shape a better world.This role supports the delivery of Cybersecurity Advisory Services a... Show more

 • Promoted • New!

Cyber Security Manager

ElixirrGreater London, England, GB
Full-time

Elixirr International plc is a global consulting firm with a bold ambition: to become the best consulting firm in the world.Founded in 2009 to challenge a declining industry standard, we’ve grown f... Show more

 • Promoted

Director of Tech Risk, Cyber & Resilience

JobtailorGreater London, England, United Kingdom
Full-time

Jobtailor is seeking a senior Technology Risk leader to oversee the Technology Risk & Operational Resilience across DSM, FX and Risk Intelligence within a regulated financial services context.You w... Show more

 • Promoted

Senior Cyber Security Engineer

Tradeweb MarketsGreater London, England, United Kingdom
Full-time

Tradeweb is a global leader in electronic trading across asset classes.As financial markets become increasingly interconnected, our technology enables efficient, multi‑asset trading on a global sca... Show more

 • Promoted • New!

Cyber Security Associate Director

RSM UKGreater London, England, United Kingdom
Permanent

We are searching for an experienced Cyber Security Associate Director.As an Associate Director within Technology and Cyber Risk Assurance, you’ll be responsible for advising our clients on cyber se... Show more