Are you ready to lead the response to the most critical cybersecurity and fraud threats facing the business
We're looking for a Cybersecurity Incident Risk Manager to take ownership of high-impact cybersecurity incidents from identification through resolution. In this role, you will lead incident risk management efforts, assess and mitigate financial, operational, regulatory, and reputational risks, and coordinate cross-functional response activities during critical security events.
As the central point of leadership during major incidents, you will partner with technical teams, business stakeholders, regulators, law enforcement agencies, and external partners to ensure threats are contained, investigated, and resolved effectively. If you thrive under pressure, exercise sound risk judgement, and are passionate about strengthening organisational resilience, this is your opportunity to make a meaningful impact.
What You Will Do:
Lead Incident Risk Management
- Own the end-to-end management of high-priority cybersecurity and fraud incidents, ensuring risks are identified, assessed, prioritised, mitigated, and resolved effectively.
- Evaluate the financial, operational, regulatory, legal, and reputational impact of cybersecurity incidents and provide risk-based recommendations to business and executive leaders.
- Serve as the incident lead during critical security events, driving coordination, escalation, decision-making, and stakeholder communication.
- Ensure appropriate containment, eradication, recovery, and post-incident activities are executed in line with organisational and regulatory requirements.
Drive Incident Response & Investigations
- Lead investigations into cybersecurity intrusions, cybercrime, fraud incidents, account compromise, insider threats, and other high-impact security events.
- Apply investigative methodologies and forensic techniques to determine root causes, threat actor activities, impact, and exposure.
- Coordinate response efforts across Security Operations, Technology, Fraud, Legal, Compliance, Risk, and Business teams.
- Oversee post-incident reviews and lessons learned exercises to strengthen organisational resilience and improve future response effectiveness.
Manage Digital Evidence & Regulatory Engagement
- Identify, collect, analyse, preserve, and manage digital evidence in accordance with forensic, legal, and regulatory standards.
- Maintain comprehensive documentation and chain-of-custody records to support investigations and legal proceedings.
- Represent the organisation during engagements with regulators, law enforcement agencies, external counsel, and industry partners.
- Act as a company representative, complainant, or subject matter expert in cybercrime and fraud-related investigations or litigation when required.
Strengthen Organisational Resilience
- Contribute to the development, testing, and continuous improvement of incident response plans, crisis management procedures, and cyber incident playbooks.
- Identify recurring risks, threat patterns, and process gaps and drive remediation initiatives across the organisation.
- Support cyber crisis simulations, tabletop exercises, and incident readiness assessments.
- Produce executive-level incident reports, risk assessments, and recommendations for leadership and governance committees.
What You Need to Succeed:
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Digital Forensics, Information Technology, Criminal Justice, or a related field.
- Significant experience in Incident Risk Management, Cybersecurity Incident Response, Cybercrime Investigations, Fraud Operations, Digital Forensics, or Security Operations.
- Proven experience managing complex cybersecurity incidents involving financial loss, customer impact, regulatory exposure, or significant business disruption.
- Strong understanding of cyber threat actors, attack techniques, fraud schemes, and emerging cybersecurity risks.
- Experience conducting investigations, forensic analysis, and evidence preservation activities.
- Demonstrated ability to assess business risk and make sound decisions during high-pressure situations.
- Excellent stakeholder management and communication skills, including the ability to present technical risks to senior executives and non-technical audiences.
- Experience working with regulators, legal teams, law enforcement agencies, and external service providers.
- Strong analytical, investigative, and problem-solving capabilities.
Preferred Qualifications
- Experience within financial services, fintech, digital banking, e-commerce, telecommunications, or other highly regulated industries.
- Knowledge of cyber risk management frameworks, regulatory compliance requirements, and incident governance practices.
- Hands-on experience with security monitoring, threat intelligence, digital forensics, and fraud investigation platforms.
- Experience supporting legal proceedings or regulatory investigations involving cybersecurity-related matters.