The Role
We're looking for a Cyber Security Risk Analyst to support the Cyber Security team in maintaining ITV's cyber security risk management processes, reporting and tooling.
You will help ensure key risks are documented, kept up to date and reported appropriately to different levels and audiences across the organisation. You'll play an important role in maintaining ITV's Supplier Cyber Risk assurance process, engaging with both external suppliers and internal stakeholders involved in identifying and remediating risk.
You will also support the Studios business by assessing risk within our Studio Labels and Productions, and contribute to the development and maintenance of core group-level security policies, technical standards and guidelines.
Working closely with the wider Cyber Security team, you'll help embed risk management into day-to-day operations and support the measurement and reporting of key risk indicators to identify trends and emerging security insights.
The team
This role sits within ITV's Cyber Security team and reports into the Head of Security Risk.
The Cyber Security function is responsible for protecting ITV's technology estate, supporting the business in managing cyber risk effectively, and ensuring our security processes, policies and controls remain robust, proportionate and aligned to ITV's risk appetite.
Responsibilities:
- Maintain and improve ITV's Cyber Risk capability for the benefit of the Cyber Security team and wider ITV.
- Carry out risk assessments for ITV suppliers, engaging with business and supplier stakeholders to remediate and reduce risk within ITV's risk appetite and tolerance.
- Conduct and support risk assessments for the ITV Studios business, including entity-level material controls and individual Studio productions.
- Support the ongoing risk analysis of new and existing cloud applications used within ITV, helping to manage whitelisted applications and reduce the use of high-risk applications.
- Regularly maintain Cyber Security documentation including policies, standards, guidelines and processes; identify gaps and establish new standards and processes where required, driving continual improvement and automation where possible.
- Provide analysis and report on insights into risk trends and emerging threats.
Skills you'll need (minimum criteria)
- At least 1+ year of experience in a similar Cyber Security or Technology Risk role, with exposure to risk assessment, reporting and stakeholder engagement.
- Understanding of Cyber Risk and how it applies to different environments and services.
- Knowledge of security control frameworks.
- Hands-on technical experience, particularly involving Cloud and collaboration applications.
- Ability to map and embed process workflows into supporting systems and processes.
Other things we're looking for (key criteria)
- Degree in Computer Science or a technical/engineering-based subject.
- GIAC or SANS related qualification.
- CISSP or equivalent certification.
- Qualification in risk management (BCS, SANS or equivalent).