Now hiring

Group Information Security Risk Analyst @ Arrow Global Group

Manchester, England, GBOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

The Group Information Security Risk Analyst will play a key role within Arrow's Group Information Security Function by maintaining the Information Security Risk Framework, delivering high-quality risk assessments and reporting, engaging with stakeholders to drive remediation activities, and ensuring a proportionate and risk-based approach is applied across a diverse range of business sectors. The role will also support wider Information Security activities including third-party security assurance, due diligence reviews, responses to security questionnaires, audit activities, and security awareness initiatives as required. Conduct information security risk assessments across Arrow Global Group and portfolio companies using recognised risk assessment methodologies and frameworks. Produce high-quality risk assessment reports, management summaries, and recommendations for both technical and non-technical stakeholders. Track and monitor remediation actions arising from assessments, audits, incidents, and reviews, ensuring timely resolution of identified risks. Work closely with stakeholders to ensure recommendations are understood, agreed, and appropriately implemented. Escalate significant, overdue, or unresolved information security risks through appropriate governance channels. Support the ongoing development, maintenance, and improvement of the Group Information Security Risk Framework. Assess the effectiveness of information security controls and identify opportunities for improvement. Apply recognised security frameworks and standards including ISO27001, NIST Cybersecurity Framework, CIS Controls, PCI-DSS, and other relevant best practices in a proportionate and risk-based manner. Liaise with Cyber Security, IT, Business Continuity, Data Protection, Risk, Compliance, and Internal Audit teams to ensure security requirements are appropriately reflected within assessment activities. Support third-party security assurance activities, including supplier security reviews, due diligence assessments, and ongoing monitoring of third-party risks. Contribute to governance reporting through the preparation of metrics, risk dashboards, management information, and committee papers. Maintain awareness of emerging threats, vulnerabilities, regulatory developments, Artificial Intelligence (AI) risks, and industry best practices.

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores