Cyber Security Analyst within the Cyber Security Governance, Risk and Compliance team. Supporting effective management and oversight of cyber risk at Heathrow Airport.
Responsibilities
support the day-to-day oversight and management of cyber risk across the organisation
ensure that cyber risks are effectively identified, assessed, documented and managed in accordance with Heathrow’s policies, enterprise risk framework and recognised industry best practice
strengthen cyber risk management practices, ensuring that risks are properly identified, assessed and treated in line with Heathrow policies and recognised industry standards
contribute to the development and continuous improvement of cyber risk policies, standards and frameworks
help mature and drive effective cyber risk management practices across the business
support the delivery of Heathrow’s third-party risk management programme
compile and analyse data for management reporting and metrics
maintain a comprehensive and current understanding of Cyber Security and Information Security threats.
Requirements
Proven experience operating in cyber risk roles. Experience in mixed IT/OT environments would be advantageous.
Relevant risk, assurance and/or cyber leadership certifications, such as CISSP, CISM, C-RISC, CISA, ISO 27001 Lead Auditor / Lead Implementor would be advantageous
Knowledge and understanding of key Information Security controls/processes
Experience applying Cyber Risk Management frameworks (e.g. ISO 27005, NIST Risk Management Framework, etc) in complex operational environments
Understanding of cyber security standards and frameworks, in particular ISO 27001, NIST Cybersecurity Framework v2.0, and the NCSC Cyber Assessment Framework
Understanding of the UK regulatory landscape for cyber security and resilience, including the Network and Information Systems Regulations 2018.
Knowledge and experience of relevant aviation security frameworks (e.g. CAP1753) would be advantageous.
Industrial Security Analyst ensuring compliance with federal security regulations and administering security programs for classified materials. Collaborating with internal and external stakeholders in a high - profile setting.
Staff Cybersecurity Analyst responsible for safeguarding cloud assets and leading security assessments for Southern Glazer’s. Collaborating with teams to develop cloud security policies and addressing cybersecurity incidents.
Senior Threat Intelligence Analyst working with Bupa's cybersecurity team. Focused on threat management and defensive strategies to enhance cyber security posture.
Senior Information Security Analyst at Field Nation leading SOC 2 and ISO 27001 compliance programs. Collaborating with teams to embed security and leverage AI in GRC workflows.
Analista de Ciberseguridad en CRG Solutions responsable de monitorear amenazas y gestionar vulnerabilidades en la organización. Identificación de riesgos y mejora continua de la postura de seguridad.
Compliance & Information Security Analyst at beqom managing GRC and TPRM functions. Overseeing client governance, risk, and compliance requests, and vendor due diligence at a SaaS company.
Senior Technical Expert in Cyber Defense Center at ZEISS analyzing global cyber threats. Collaborating with SOC, CIRT, and ensuring proactive defense strategies.
Information Security Analyst focusing on vulnerability research and data analysis at Flexera. Involves analyzing, verifying vulnerabilities, and maintaining high - quality content standards.
Oversee the testing lifecycle and provide cyber security solutions at Xcel Energy. Engage in various testing techniques and collaborate with teams to enhance quality practices.