Cyber Risk and Compliance Analyst
Who we are
Since 1843, The Economist Group has championed independence, excellence and openness, helping people understand and tackle the critical challenges shaping the world. Today, we are building on that legacy as a global media and information-services company powered by digital innovation, analytical rigour and evidence-based insight.
Across our three businesses -The Economist, Economist Enterprise and Economist Education - we deliver trusted analysis and insights to individuals and organisations in more than 170 countries. United by a shared purpose to drive progress, we empower decision-makers to make sense of change and chart a course through an increasingly complex world.
As a colleague, you will be part of a culture that values ideas, encourages ownership and holds itself to high standards. We invest in people who are curious, thoughtful and adaptable, whether they are launching new products, reporting on global events or harnessing emerging technologies such as AI to improve how we work. Here, fresh thinking is taken seriously, ambition is matched by integrity, and great work is recognised. Working across disciplines, geographies and perspectives, we are united by a commitment to innovation, excellence and creating meaningful impact.
The Information Security team operates the Information Security Program and is responsible for the standard of information security across the Group. We define and implement our security strategy and mitigation activities across our brands. We work with business units to ensure that the confidentiality, integrity and availability risks that they are exposed to are clearly understood and appropriately managed.
The Cyber Security Analyst is a member of the Information Security team and the job holder is responsible for establishing, implementing, monitoring, reviewing and improving a suitable set of controls to protect our information assets and ensure the business objectives of the organisation.
Responsibilities:
- Conduct risk assessments to identify potential vulnerabilities and threats to the organization's information systems, networks, and data.
- Develop and implement risk management strategies and policies to mitigate identified risks.
- Monitor and evaluate the effectiveness of risk management strategies and policies.
- Ensure compliance with applicable regulatory and legal requirements, as well as industry standards and best practices.
- Develop and maintain an effective vendor risk management program.
- Conduct vendor risk assessments and evaluate vendors' compliance with applicable security requirements.
- Work closely with third-party vendors to ensure their adherence to our organization's security policies and standards.
- Identify and address any security gaps or vulnerabilities in the vendor management process.
- Ensure that all vendor contracts contain appropriate security requirements.
- Develop and deliver training to employees on cyber security and risk management best practices.
Requirements:
- Bachelor's degree in Cyber Security, Information Technology or related field.
- At least 5 years of experience in risk and compliance, with a focus on cyber security.
- Strong knowledge of cyber security regulations, standards and best practices, including NIST, ISO and PCI.
- Experience in developing and implementing effective risk management strategies and policies.
- Experience in conducting vendor risk assessments and managing vendor relationships.
- Excellent analytical and problem-solving skills.
- Excellent communication and interpersonal skills.
- Ability to work independently and as part of a team
#LI-Hybrid
Working Arrangements
The majority of our roles operate on a hybrid working pattern, with 3+ days office attendance required.
AI usage for your application
We are an innovative organisation that encourages the use of technology. We recognise that candidates may utilise AI tools to support with their job application process. However, it is essential that all information you provide truthfully and accurately reflects your own experience, skills, and qualifications.
What we offer
Our benefits package is designed to support your wellbeing, growth, and work-life balance. It includes a highly competitive pension or 401(k) plan, private health insurance, and 24/7 access to counselling and wellbeing resources through our Employee Assistance Program.
We also offer a range of lifestyle benefits, including our Work From Anywhere program, which allows you to work from any location where you have the legal right to do so for up to 25 days per year. In addition, we provide generous annual and parental leave, as well as dedicated days off for volunteering and even for moving home.
You will also be given free access to all The Economist content, including an online subscription, our range of apps, podcasts and more.
Job Details
Experience
Senior · 5+ yrs