About this role
Information Security Risk Manager
We are partnering with leading commodities firm, hiring an Information Security Risk Manager to take ownership of a critical second line security risk remit in a highly regulated trading environment.
This is not a hands-on engineering role. It suits a seasoned GRC / second line security professional who can operate with autonomy, engage senior stakeholders credibly, and translate technical issues into clear business risk decisions.
The Role
You’ll own a broad information security risk area, working with senior stakeholders and business owners across the company to ensure risk is understood, assessed, and managed proportionately.
You’ll be expected to
- Lead from a second line / GRC perspective, focusing on risk, policy, control effectiveness, governance, and regulatory alignment
- Assess security issues in terms of business impact, risk appetite, and resilience, not just technical severity
- Work directly with heads of department, relationship owners, infrastructure leads, and senior leadership
- Translate technical incidents, vendor alerts, and security concerns into clear, calm, commercially grounded recommendations
- Support risk assessments, audits, policy and procedure development, and broader operational resilience activity
- Contribute to a small but visible team with exposure to board, risk committee, and executive discussions
We’re looking for someone who brings
- Strong experience in information security risk, GRC, or second line security
- The credibility and gravitas to manage senior stakeholders and challenge constructively where needed
- A calm, measured approach — someone who can cut through noise rather than escalate drama
- Confidence working autonomously and taking ownership of an area without close management
- Strong communication skills, with the ability to frame security in business risk language
- Experience across areas such as risk, policy, audit, controls, governance, third-party risk, operational resilience, or related disciplines
- A solid security foundation; certifications such as CISSP plus broader GRC-oriented qualifications are helpful
Environment
You’ll be joining a business with
- A complex, regulated operating environment
- Significant third-party and vendor exposure
- Close interaction between security, operational resilience, third-party risk, and governance
- Strong executive visibility and a genuine seat at the table for risk and security conversations
Why join?
- High-autonomy role with real ownership
- Strong exposure to senior leadership and key decision-makers
- Opportunity to shape how security risk is understood and managed in the business
- Join a collaborative team where your opinion will be heard and valued
For more information, please contact oliver.wood@twentyai.com
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in London →Why this fits a police background — match score 69/100
- Risk & threat assessment
- Working to legislation & regulation
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |