Senior Security Analyst - Product-Based Risk Assessment (PBRA)
Quick Overview
Job Description
Senior Cyber Security Risk & Assurance Consultant - Product Risk (PBRA) (CONTRACTOR) - London Duration: 1 year contract Hybrid Working - 8 days onsite per month - the rest is remote working About the Team The Product-Based Risk Assessment (PBRA) service conducts recurring security assessments of applications, services, and technologies to identify emerging threats, evaluate control effectiveness, and drive remediation that strengthens The clients cyber resilience.
The team supports business and technology stakeholders by assessing cyber security risks and ensuring alignment with The Banks security standards and risk appetite.
Key Accountabilities Product-Based Risk Assessments Lead end-to-end Product-Based Risk Assessments (PBRA) for critical applications, platforms, and technology services.<br />Analyse application architectures, business processes, information flows, and supporting infrastructure.<br />Identify and assess cyber threats, vulnerabilities, control weaknesses, and potential business impacts.<br />Evaluate the design and effectiveness of security controls using clients security frameworks and standards.<br />Assess residual risks and propose actionable remediation plans.Security Risk Analysis Perform security risk assessments using recognised methodologies and industry frameworks.<br />Evaluate risks related to infrastructure, software, cloud services, networks, third-party integrations, and information assets.<br />Contribute to threat modelling and attack surface analysis activities.<br />Support technology-focused assessments such as cloud, AI, and emerging technology evaluations.Stakeholder Engagement Act as the primary security assessment contact for business and IT stakeholders.<br />Facilitate workshops, interviews, and assessment review sessions.<br />Challenge assumptions and provide expert security guidance to delivery and operations teams.<br />Build trusted relationships across CISO, CTO, Architecture, Risk Management, and Engineering teams.Reporting & Governance Produce high-quality assessment reports, risk summaries, and executive-level communications.<br />Present findings and recommendations to senior management and governance bodies.<br />Track remediation plans and risk treatment activities through closure.<br />Support internal and external audit activities as required.Continuous Improvement Contribute to the evolution of the PBRA service, methodologies, tools, and operating model.<br />Help drive the transition toward data-enabled and automated security assessment capabilities.<br />Identify opportunities to improve efficiency, consistency, and risk coverage across assessments.<br />Support knowledge sharing and mentoring of junior analysts.Required Skills & Experience Technical Skills Strong understanding of cybersecurity principles, controls, and risk management practices.<br />Knowledge of application security, cloud security, infrastructure security, and network security.<br />Experience conducting security assessments, threat modelling, or risk analyses.<br />Familiarity with industry frameworks and standards such as:
NIST Cyber Security Framework<br />ISO 27001<br />CIS Controls<br />Secure Controls Framework (SCF)<br />DORA<br />ANSSI EBIOS RM<br />OWASPProfessional Experience Minimum 7 years of experience in Information Security, Cyber Risk, Security Assurance, or Security Architecture.<br />Experience leading complex security assessments across large technology environments.<br />Experience working with senior business and technology stakeholders.<br />Strong report-writing and presentation skills.Personal Competencies Strong analytical and critical-thinking capabilities.<br />Excellent communication and stakeholder management skills.<br />Ability to challenge constructively and influence decision-making.<br />Self-driven with strong ownership and accountability.<br />Pragmatic, risk-based mindset.<br />Comfortable operating in a complex, regulated environment.Please do send across to me the most up to date CV to *Rates depend on experience and client requirements
Similar jobs
- AP
Network Security Solutions Engineer
NewAmtis Professional Ltd
Oxford, Oxfordshire🇬🇧£47k/yrRemote2 minutes agoTechnology - DT
Cyber Security Engineer
NewDCV Technologies Limited
Tring, Hertfordshire🇬🇧On-site12 minutes agoAzureVMwareTechnology - AD
Cyber Incident Response Specialist
NewAdecco
Warwick, Warwickshire🇬🇧Hybrid13 minutes agoStakeholder ManagementTechnology - GS
Life Safety Systems Engineer
NewGanymede Solutions
London🇬🇧£40k - £45k/yrRemote15 minutes agoTechnology - CO
Security Operations Engineer
NewComputappoint
United Kingdom🇬🇧On-site18 minutes agoTechnology - AM
Security Consultant
Anson Mccade
UK, UK🇬🇧£45k/yrOn-site2 months agoAWSEncryptionAzureTechnology