KEYSTONE CYBER

Home Disciplines Information security & risk

INFORMATION SECURITY & RISK

Information security and risk recruitment

Risk roles attract more unsuitable applications than any other security discipline, because the vocabulary is easy to learn and the work is hard to fake. We screen for people who can quantify an exposure and get a decision made, not people who can populate a register.

What we place

SECURITY RISK MANAGER
Owns the risk process end to end: identification, assessment, treatment decisions and the reporting that goes to a committee.
INFORMATION SECURITY OFFICER
The embedded second-line role in banks, insurers and asset managers. Challenge, oversight and assurance rather than delivery.
THIRD-PARTY RISK
Supplier assessment, contractual security terms and the concentration risk nobody wants to own.
SECURITY ASSURANCE
Control testing and evidence, client due diligence responses, and the audit interface.
POLICY & STANDARDS
Writes the documents people can actually follow, and maintains them against ISO 27001, NIST CSF and regulatory expectations.
RESILIENCE & CONTINUITY
Business continuity, disaster recovery and operational resilience — increasingly regulated, particularly in the UK.

How we screen

We ask candidates to describe a risk they escalated that the business chose to accept. Good risk professionals are comfortable with that outcome and can explain how they documented and monitored it. Weaker candidates treat every accepted risk as a failure, which makes them difficult to place in a commercial environment.

We also test technical literacy. A risk manager who cannot interrogate a control owner will be told whatever is convenient, and the register will slowly detach from reality. We are looking for enough depth to ask the second question.

The market, honestly

Supply is broad and quality is uneven. Many candidates arrive from audit, compliance or IT governance, and the good ones translate well; the rest bring process without judgement. In South Africa, POPIA has pulled a lot of generalist compliance people towards security titles. In the UK, DORA and operational resilience have done the same for resilience roles.

Because the field overlaps heavily with GRC, we establish early whether you want certification-led compliance work or genuine risk decision support. They attract different candidates and the interview loop should differ accordingly.

A risk register is not a deliverable. If the role exists to produce one, say so — some strong candidates will still want it, and the ones who would resent it will self-select out.

Where we recruit

Cape Town and Johannesburg across South Africa, and London and the wider United Kingdom.

Common questions

How is this different from your GRC page?

GRC leans towards frameworks, audit and certification. This page covers risk assessment, assurance and second-line oversight — the roles judged on decisions rather than on evidence packs. Many employers need a blend, and we scope which.

Do you place second-line Information Security Officer roles?

Yes. Regulated financial services in both markets hire them steadily, and the screen is different: independence, challenge and committee credibility matter more than hands-on tooling.

Do you recruit third-party and supply chain risk specialists?

Yes, and demand has grown sharply. The scarce skill is not questionnaire administration; it is negotiating security terms and making a proportionate call on a critical supplier.

Are audit or compliance backgrounds suitable for cyber risk roles?

Often, with honest scoping. Internal audit and privacy backgrounds transfer well into assurance and third-party risk. They transfer less well into roles that require arguing technical control design.

Related disciplines

Talk to us about your search

A short conversation is usually enough to tell you whether we can help.