Enterprise Security Risk Manager

Our client, a specialist investment management firm based in Edinburgh, is looking to appoint an Enterprise Security Risk Manager to join their team.


This role translates our client's security strategy into effective day-to-day assurance and risk management.

You will assess cyber risk, review technology and AI solutions, lead security investigations and control assurance, coordinate testing and regulatory activity, and provide expert security advice to Technology and the wider business.

You'll also represent the security function on key governance forums, including the Information Security Working Group, Third Party Oversight Working Group and Business Continuity Working Group.

Our client places a strong emphasis on client-first thinking, collaboration and integrity across the business.


A recognised cyber security qualification such as CISSP, CISM, CRISC or equivalent is desirable for this role.



Skills/Experience:



  • Strong practical experience of cyber risk assessment, security assurance and control evaluation

  • Experience reviewing security designs for technology change, software development and third-party solutions

  • Strong practical experience of the Microsoft 365 security stack, including Entra, Defender and Purview

  • Strong incident-triage, threat-hunting and investigation skills

  • Experience designing and interpreting penetration tests, attack simulations and security-control assurance

  • Good understanding of identity, endpoint, data-protection, mobile-device, email/web and cloud security controls

  • Experience of third-party and AI security due diligence, including data protection and supplier assurance

  • Working knowledge of regulatory frameworks, security standards, risk registers and audit processes

  • Strong communication, training and stakeholder-management skills across technical and non-technical audiences



Core Responsibilities:



  • Assess cyber risks, control strengths, security exceptions, threat-intelligence findings and attack paths

  • Review security designs for Technology, departmental and citizen-developed solutions before production use

  • Triage security incidents and lead threat hunting and investigations into data-protection, information-protection and insider-risk alerts

  • Design penetration tests and attack simulations, assess findings and drive remediation of material weaknesses

  • Review the effectiveness of endpoint, encryption, identity, conditional-access, mobile-device and web/email security controls

  • Perform security due diligence on third parties and AI providers, including data-use, model-training and data-residency controls

  • Produce the Cyber RCSA and undertake cyber-insurance, internal-audit and external-audit casework

  • Conduct regulatory and standards gap analyses and communicate relevant requirements across the firm

  • Design access-review processes, security management information and assurance reporting

  • Design and deliver phishing simulations, bespoke security training and targeted awareness activity

  • Lead monthly technical reviews with the SOC and challenge service quality and control effectiveness

  • Advise Technology and business teams on security risks and escalate material issues to the Head of Enterprise Security



Core-Asset Consulting is an equal opportunities recruiter and we welcome applications from everyone irrespective of age, disability, gender, gender identity or expression, race, colour, ethnic or national origin, sexual orientation, religion or belief, marital/civil partner status or pregnancy.



To apply for this vacancy applicants must be eligible to work in the UK in accordance with the Immigration, Asylum and Nationality Act 2006.



At Core-Asset, we're committed to protecting and respecting your privacy.

Our privacy statement explains when and why we collect personal information about people who engage with our services, how we use it, the conditions under which we may disclose it to others, and how we keep it secure.

We may change this policy from time to time, so please check this policy occasionally to ensure that you're happy with any changes.



By engaging with us (either by applying for a job we're advertising, registering through our website, or getting in touch with our business) you're agreeing to be bound by this policy.



Core-Asset Consulting is committed to protecting the privacy of our candidates, clients and website users.

For further information, please refer to our full Privacy Statement available on our website http://www.core-asset.co.uk/about-core-asset/privacy-statement



Core-Asset Consulting offers specialist recruitment services to asset management, accounting & finance, asset servicing, legal and the wider financial services sector in Scotland.




Share Job