Group Information Security Risk Analyst

Posted 2 Days Ago
Be an Early Applicant
Manchester, Greater Manchester, England, GBR
Hybrid
Senior level
Fintech • Professional Services • Real Estate • Financial Services
The Role
Conduct information security risk assessments, evaluate controls, produce reports and dashboards, track remediation, and escalate unresolved risks. Maintain the Group Information Security Risk Framework and apply ISO 27001, NIST, CIS, PCI DSS, and DORA standards. Support third-party security assurance, supplier due diligence, audits, questionnaires, governance reporting, and security awareness initiatives while collaborating with security, IT, risk, compliance, and audit stakeholders.
Summary Generated by Built In
The Group Information Security Risk Analyst will play a key role within Arrow's Group Information Security Function by maintaining the Information Security Risk Framework, delivering high-quality risk assessments and reporting, engaging with stakeholders to drive remediation activities, and ensuring a proportionate and risk-based approach is applied across a diverse range of business sectors.
The role will also support wider Information Security activities including third-party security assurance, due diligence reviews, responses to security questionnaires, audit activities, and security awareness initiatives as required.

About the role
  • Conduct information security risk assessments across Arrow Global Group and portfolio companies using recognised risk assessment methodologies and frameworks.
  • Produce high-quality risk assessment reports, management summaries, and recommendations for both technical and non-technical stakeholders.
  • Track and monitor remediation actions arising from assessments, audits, incidents, and reviews, ensuring timely resolution of identified risks.
  • Work closely with stakeholders to ensure recommendations are understood, agreed, and appropriately implemented.
  • Escalate significant, overdue, or unresolved information security risks through appropriate governance channels.
  • Support the ongoing development, maintenance, and improvement of the Group Information Security Risk Framework.
  • Assess the effectiveness of information security controls and identify opportunities for improvement.
  • Apply recognised security frameworks and standards including ISO27001, NIST Cybersecurity Framework, CIS Controls, PCI-DSS, and other relevant best practices in a proportionate and risk-based manner.
  • Liaise with Cyber Security, IT, Business Continuity, Data Protection, Risk, Compliance, and Internal Audit teams to ensure security requirements are appropriately reflected within assessment activities.
  • Support third-party security assurance activities, including supplier security reviews, due diligence assessments, and ongoing monitoring of third-party risks.
  • Contribute to governance reporting through the preparation of metrics, risk dashboards, management information, and committee papers.
  • Maintain awareness of emerging threats, vulnerabilities, regulatory developments, Artificial Intelligence (AI) risks, and industry best practices.


About you
  • Educated to degree level in Information Security, Cyber Security, Computer Science, Information Systems, Risk Management, Business Management, or equivalent levels of experience.
  • A minimum of 5 years' proven experience within Information Security, Cyber Security, IT Risk, or related disciplines.
  • Strong understanding of Information Security Risk Management principles and methodologies.
  • Experience conducting risk assessments, control reviews, audits, or assurance activities.
  • Technical knowledge of information security frameworks and standards including ISO27001, NIST Cybersecurity Framework, CIS Controls, DORA, PCI-DSS, and related security practices.
  • Strong communicator with positive influencing and interpersonal skills.
  • Ability to synthesise complex technical and business information and present findings in a clear and concise manner.
  • Effective prioritisation and organisational skills with the ability to manage multiple competing priorities.
  • Strong analytical and problem-solving skills.
  • Experience producing professional reports and management presentations.
  • Understanding of cloud technologies and associated information security risks.
  • Awareness of Artificial Intelligence (AI), associated risks, governance considerations, and emerging industry developments.

About
Great talent comes in many forms, and we’re committed to building a diverse and inclusive team. Whilst a number of our roles do require specific qualifications and experience, and industry knowledge, we also value potential, unique perspectives, and transferable skills. If you’re excited about this opportunity but don’t meet every requirement, we’d still love to hear from you.  We occasionally collaborate with recruitment agencies to fill niche or specialist roles. However, we do not accept agency terms or pay fees for speculative CVs submitted directly to our hiring managers or outside our Applicant Tracking System. If you are a recruitment agency interested in partnering with us for candidate supply, please reach out to [email protected]

Skills Required

  • Degree in Information Security, Cyber Security, Computer Science, Information Systems, Risk Management, Business Management, or equivalent experience
  • At least 5 years of experience in Information Security, Cyber Security, IT Risk, or related disciplines
  • Strong understanding of Information Security Risk Management principles and methodologies
  • Experience conducting risk assessments, control reviews, audits, or assurance activities
  • Technical knowledge of ISO 27001, NIST Cybersecurity Framework, CIS Controls, DORA, PCI DSS, and related security practices
  • Strong communication, influencing, and interpersonal skills
  • Ability to synthesize complex technical and business information clearly
  • Effective prioritization and organizational skills
  • Strong analytical and problem-solving skills
  • Experience producing professional reports and management presentations
  • Understanding of cloud technologies and associated information security risks
  • Awareness of Artificial Intelligence risks, governance, and industry developments

Arrow Global Group Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Arrow Global Group and has not been reviewed or approved by Arrow Global Group.

  • Healthcare Strength Company‑funded private medical insurance, a 24/7 Employee Assistance Programme, an annual company‑funded cancer screening, and a healthcare cash plan are part of the core offer. These provisions indicate robust health coverage that extends beyond basic care.
  • Leave & Time Off Breadth Annual leave starts at 25 days with options to buy or sell days, alongside carers, faith/cultural, study, and life‑event leave plus paid volunteering time. These options broaden time‑away flexibility and support different life circumstances.
  • Flexible Benefits A flexible benefits platform offers gym and hotel discounts, cycle‑to‑work, dental insurance, a retail discount card, and a gadget scheme, with some options employee‑funded. Flexibility to tailor add‑ons can increase perceived value across varied needs.

Arrow Global Group Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
Year Founded: 2005

What We Do

Arrow Global is a leading European vertically integrated alternative asset manager specializing in private credit and real estate. Founded in 2005, it acquires and manages loan and real estate portfolios, delivering risk-adjusted returns for global investors.

Similar Jobs

McCain Foods Logo McCain Foods

Accountant

Food • Retail • Agriculture • Manufacturing
In-Office
Leeds, West Yorkshire, England, GBR
20000 Employees
Hybrid
London, Greater London, England, GBR
289097 Employees

Akeneo Logo Akeneo

Software Engineer

eCommerce • Information Technology • Marketing Tech • Software
Hybrid
3 Locations
400 Employees

Navan Logo Navan

Controller

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
London, Greater London, England, GBR
3300 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account