Aviva
Cyber Security Specialist

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Title: Security Specialist
Duration: 6 Months
Inside IR35
This is a contract opportunity for someone who is an experienced cyber security professional with a strong understanding of security governance, risk management, and project delivery. This role would suit someone who can quickly integrate into a complex organisation, provide expert security guidance to stakeholders, and proactively identify and manage cyber security risks across projects and business initiatives.
You'll be confident working independently, engaging with technical and non-technical stakeholders, and influencing security-related decisions to ensure risks are appropriately managed and mitigated.
Key Responsibilities
- Support security risk management decisions across projects, programmes, and business change initiatives by identifying potential cyber security risks and recommending appropriate controls.
- Review and assess technical designs to identify security vulnerabilities, weaknesses, and compliance gaps.
- Provide expert guidance on Aviva security processes, including penetration testing, business impact assessments, and security assurance activities.
- Deliver consultancy and advice on security governance frameworks, including Security Fundamentals, TPISA processes, and related security standards.
- Provide cyber security input throughout the project lifecycle to ensure security requirements are embedded from inception through delivery.
- Produce management information reports, dashboards, and metrics that provide visibility of security risks and remediation activities.
- Create and deliver security awareness and training materials to improve security culture and promote best practices.
- Engage with internal teams, third-party suppliers, and business partners to encourage and maintain strong security practices.
- Ensure security findings are accurately documented, tracked, and managed, with appropriate remediation plans or risk acceptances in place.
- Develop concise and effective materials that clearly articulate cyber security risks, options, recommendations, and business impacts for stakeholders and leadership teams.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Skills and Experience
- Demonstrable experience in cyber security, information security, or security risk management roles within complex enterprise environments.
- Strong understanding of security governance, security assurance, and risk management frameworks.
- Experience reviewing technical solutions, architectures, and designs from a security perspective.
- Knowledge of penetration testing processes, vulnerability management, and security assessment methodologies.
- Experience supporting projects and change initiatives by providing pragmatic security advice and risk-based recommendations.
- Strong stakeholder management skills with the ability to communicate technical security concepts to both technical and non-technical audiences.
- Experience creating management reports, security metrics, presentations, and awareness materials.
- Proven ability to manage multiple priorities and deliver outcomes in a fast-paced environment.
- Experience working with third-party suppliers and managing security considerations within external partnerships.
- Excellent written and verbal communication skills, including the ability to present findings, recommendations, and risk assessments to senior stakeholders.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Please ensure that you attach an up-to-date CV to your application.
We’re inclusive and welcome everyone. We want applications from all backgrounds and experiences. Excited but not sure you tick every box? Even if you don't, we would still encourage you to apply. We also consider all forms of flexible working, including part-time and job shares.
We flex locations, hours, and working patterns to suit our customers, business, and you. Most of our people are smart working, spending at least 50% of their time in our offices every week, combining the benefits of flexibility with time together with colleagues.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location