Skip to main content
AfterDuty

Group Information Security Risk Analyst

Arrow Global Group · Manchester, Greater Manchester

Type
Full-time
Posted
Yesterday

Overview

Your operational risk assessment and incident command experience transfer to information security risk management.

About this role

Description

The Group Information Security Risk Analyst will play a key role within Arrow's Group Information Security Function by maintaining the Information Security Risk Framework, delivering high-quality risk assessments and reporting, engaging with stakeholders to drive remediation activities, and ensuring a proportionate and risk-based approach is applied across a diverse range of business sectors.

The role will also support wider Information Security activities including third-party security assurance, due diligence reviews, responses to security questionnaires, audit activities, and security awareness initiatives as required.

  • Conduct information security risk assessments across Arrow Global Group and portfolio companies using recognised risk assessment methodologies and frameworks.
  • Produce high-quality risk assessment reports, management summaries, and recommendations for both technical and non-technical stakeholders.
  • Track and monitor remediation actions arising from assessments, audits, incidents, and reviews, ensuring timely resolution of identified risks.
  • Work closely with stakeholders to ensure recommendations are understood, agreed, and appropriately implemented.
  • Escalate significant, overdue, or unresolved information security risks through appropriate governance channels.
  • Support the ongoing development, maintenance, and improvement of the Group Information Security Risk Framework.
  • Assess the effectiveness of information security controls and identify opportunities for improvement.
  • Apply recognised security frameworks and standards including ISO27001, NIST Cybersecurity Framework, CIS Controls, PCI-DSS, and other relevant best practices in a proportionate and risk-based manner.
  • Liaise with Cyber Security, IT, Business Continuity, Data Protection, Risk, Compliance, and Internal Audit teams to ensure security requirements are appropriately reflected within assessment activities.
  • Support third-party security assurance activities, including supplier security reviews, due diligence assessments, and ongoing monitoring of third-party risks.
  • Contribute to governance reporting through the preparation of metrics, risk dashboards, management information, and committee papers.
  • Maintain awareness of emerging threats, vulnerabilities, regulatory developments, Artificial Intelligence (AI) risks, and industry best practices.

About you*

  • Educated to degree level in Information Security, Cyber Security, Computer Science, Information Systems, Risk Management, Business Management, or equivalent levels of experience.
  • A minimum of 5 years' proven experience within Information Security, Cyber Security, IT Risk, or related disciplines.
  • Strong understanding of Information Security Risk Management principles and methodologies.
  • Experience conducting risk assessments, control reviews, audits, or assurance activities.
  • Technical knowledge of information security frameworks and standards including ISO27001, NIST Cybersecurity Framework, CIS Controls, DORA, PCI-DSS, and related security practices.
  • Strong communicator with positive influencing and interpersonal skills.
  • Ability to synthesise complex technical and business information and present findings in a clear and concise manner.
  • Effective prioritisation and organisational skills with the ability to manage multiple competing priorities.
  • Strong analytical and problem-solving skills.
  • Experience producing professional reports and management presentations.
  • Understanding of cloud technologies and associated information security risks.
  • Awareness of Artificial Intelligence (AI), associated risks, governance considerations, and emerging industry developments.

About Arrow Global Group

Great talent comes in many forms, and we’re committed to building a diverse and inclusive team. Whilst a number of our roles do require specific qualifications and experience, and industry knowledge, we also value potential, unique perspectives, and transferable skills. If you’re excited about this opportunity but don’t meet every requirement, we’d still love to hear from you.

We occasionally collaborate with recruitment agencies to fill niche or specialist roles. However, we do not accept agency terms or pay fees for speculative CVs submitted directly to our hiring managers or outside our Applicant Tracking System.

If you are a recruitment agency interested in partnering with us for candidate supply, please reach out to recruitment@arrowglobal.net

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Manchester

Why this fits a police background

  • Intelligence & OSINT
  • Incident command & response
  • Risk & threat assessment
  • Working to legislation & regulation

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • NMC Cyber Incident Responder

    Police Digital Service · Manchester

    Full-time

    Your cybercrime and digital evidence experience translates directly into incident response and threat analysis.

    Posted 6 days ago

  • £50,000 – £100,000Estimated

    Multiple eDV-Cleared Technical Roles – National Security If you already hold active eDV clearance and are considering what else is happening across the National Security technology market, I'm currently supporting multiple opportunities across a range of engineering-led organisations.

    Posted 6 days ago

  • NMC Cyber Incident Responder

    National Enabling Programmes (a programme of the Police Digital Service) · Manchester

    Full-time

    Your incident command and threat assessment experience transfers directly to managing cyber incidents.

    Posted 7 days ago

  • Incident Response Analyst

    AXA UK · Manchester

    Full-time

    Your incident command experience and evidence handling skills transfer directly to cyber incident response and digital forensics.

    Posted 13 days ago