Marks and Spencer Logo

Marks and Spencer

Security Risk Specialist

Posted Yesterday
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in United Kingdom
Mid level
Remote or Hybrid
Hiring Remotely in United Kingdom
Mid level
Implement and support the cybersecurity risk assessment framework, processes, and vendor tooling. Prepare cybersecurity risk reports for governance forums, review risk appetite statements, develop risk training, and help embed risk assessment into business and technology change. Coach and mentor Cyber Risk Analysts and Associates while collaborating with Governance, Risk & Compliance stakeholders.
The summary above was generated by AI

Summary

We are seeking an experienced Security Risk Specialist to ensure that the M&S security posture remains within organisational tolerance levels. You will be supporting the implementation of M&S’ cybersecurity risk assessment framework and related processes, working with the wider Governance, Risk & Compliance team to embed cybersecurity risk assessment practices into M&S business and technology change activities. You will also support the creation of risk statements and scenarios, helping business stakeholders assess and understand the impact of security risk.

You will report to the Security Risk Principal and provide leadership and support to a growing team of analysts and associates.

What you'll do

  • Delivery of M&S’ new cybersecurity risk assessment framework and supporting processes to ensure protection of the organisation’s systems and data underpinning key business processes. This will also include supporting the review of M&S risk appetite statements.
  • Implement vendor tooling to support M&S’ new cybersecurity risk assessment framework.
  • Draft comprehensive cybersecurity risk reports for governance forums that provide insights into M&S’ risk posture and top cybersecurity risks.
  • Support the creation of training on the identification and mitigation of cybersecurity risks.
  • Coach and mentor Cyber Risk Analysts and Associates, helping them progress against their personal development plans.

Who you are

  • Strong knowledge of cybersecurity risk management and governance, including experience with recognised frameworks such as NIST CSF.
  • At least three years’ relevant cybersecurity risk experience, ideally gained across sectors such as retail or financial services.
  • Awareness of attacker tactics, techniques and procedures, with the ability to analyse problems and identify root causes.
  • Strong organisational and time-management skills, with the ability to manage multiple stakeholders and meet deadlines.
  • Experience building capability in cybersecurity risk processes, methods and tools, driving consistent adoption and effective use.

What’s in it for you? 

Working at M&S means being part of something bigger - helping to deliver quality, value and service to millions of customers every day. We’re inclusive, fast-moving and always evolving, with a strong sense of purpose and a focus on doing the right thing.

Here are just a few of the benefits that make working here even more rewarding:

  • 20% colleague discount on all M&S products and many third-party brands for you and someone in your household, available once you’ve completed your probation

  • Competitive holiday allowance with the option to buy more

  • Discretionary bonus schemes linked to your performance and ours

  • Strong pension and life assurance to help plan for the future

  • Tailored induction and training to support your development from day one

  • Exclusive perks and savings through our M&S Choices portal

  • Market-leading family policies, including parental, adoption and neonatal leave

  • 24/7 wellbeing support, including virtual GP access and mental health services

  • One paid volunteer day a year to support a cause that matters to you

Everyone’s welcome 

We are ambitious about the future of retail. We’re disrupting, innovating and leading the industry into a more conscientious, inspiring digital era. We’re transforming how we work together and offering our most exciting opportunities yet. Marks & Spencer strives to be an inclusive organisation, trusted and admired by our colleagues, customers and suppliers. Join us and make change happen.

 

We are committed to building diverse and representative teams, where everyone can bring their whole selves to work and be at their best. We support each other and work together to win together.

 

If you feel you'd benefit from any support or reasonable adjustments during any stage of the recruitment process, please don’t hesitate to let us know when completing your application. This information will be picked up by our team, so we can try and put steps in place to help you be at your best through this process.

#LI-hybrid #LI-CC1 #hybridrole

Similar Jobs

2 Hours Ago
Easy Apply
Remote
United Kingdom
Easy Apply
Senior level
Senior level
Cloud • Security • Software • Cybersecurity • Automation
Design and evolve high-scale backend capabilities for GitLab’s container registry. Drive architecture, performance, reliability, security, APIs, testing, and operational readiness. Mentor engineers, influence technical direction, participate in incident response, and collaborate asynchronously across product, infrastructure, data, frontend, and security teams. Integrate and evaluate agentic AI systems in production engineering workflows while promoting responsible and effective use.
Top Skills: AIAPIsBackend ArchitectureContainer RegistryData SystemsDevOpsDevsecopsModular MonolithsSystems Programming
3 Hours Ago
Remote or Hybrid
Mid level
Mid level
Cloud • Software
Designs, deploys, and operates highly available, secure, multi-region cloud platforms. Responsibilities include managing AWS and Kubernetes services, automating production operations, improving reliability and scalability, participating in 24x7 incident response, and developing tooling for deployment, testing, failure recovery, and platform security. The role collaborates with application engineering teams and requires Linux administration, Python or Go development, container security, and CI/CD automation experience.
Top Skills: ArgocdAWSCi/CdCncfDastDnsGoHTTPKubernetesLinuxOpentelemetryPrometheusPythonSastService MeshTcp/IpUnix
4 Hours Ago
In-Office or Remote
Junior
Junior
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Conduct outbound prospecting and qualify leads in the DACH strategic market through cold calls, personalized emails, and research. Build pipeline, convert meetings, handle objections, communicate product value, and collaborate with sales, marketing, partner, and operations teams. Use Salesforce, Gong, Outreach, LinkedIn Navigator, and AI to improve prospecting effectiveness. The role requires fluent English and German, strong communication skills, accountability, adaptability, and 1–2 years of SDR or inside sales experience preferred.
Top Skills: Artificial IntelligenceGongLinkedin NavigatorOutreachSalesforce

What you need to know about the Edinburgh Tech Scene

From traditional pubs and centuries-old universities to sleek shopping malls and glass-paneled office buildings, Edinburgh's architecture reflects its unique blend of history and modernity. But the fusion of past and future isn't just visible in its buildings; it's also shaping the city's economy. Named the United Kingdom's leading technology ecosystem outside of London, Edinburgh plays host to major global companies like Apple and Adobe, as well as a growing number of innovative startups in fields like cybersecurity, finance and healthcare.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account