Teneo
Cybersecurity Risk and Compliance Associate

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
The Role
Teneo is looking for a Cybersecurity Risk and Compliance Associate to help turn our cybersecurity strategy into measurable outcomes. You will join the Information Security and Risk team and play an important role in strengthening assurance, improving risk visibility and supporting delivery of priority security initiatives across our global business.
Working with colleagues across Security, IT, Legal, Procurement and the wider business, you will help keep controls effective and audit-ready, support the timely remediation of risk and provide credible assurance to clients and auditors. This is a varied role with the opportunity to build experience across security governance, compliance, third-party risk and programme delivery.
Responsibilities
Security assurance, compliance and audit readiness
- Support risk and controls assessments, including control walkthroughs, evidence gathering, gap analysis and remediation tracking.
- Coordinate evidence and actions for external audits and compliance assessments, including ISO 27001, SOC 2 and Cyber Essentials.
- Maintain clear, reusable control documentation and audit evidence so assurance activity is efficient, consistent and audit-ready.
- Track risk-treatment actions, owners and deadlines, validate closure evidence and escalate delivery concerns when needed.
Governance, reporting and insight
- Help create and maintain security policies, standards, procedures and control descriptions, supporting review, approval and adoption across the business.
- Maintain security metrics, dashboards and action trackers covering audit findings, remediation, risk exceptions, third-party risk and other priority indicators.
- Bring structure to complex inputs and turn evidence, data and stakeholder feedback into clear reporting and practical recommendations.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Third-party risk and client assurance
- Support client security due diligence by coordinating accurate responses, evidence packs and control narratives with relevant internal teams.
- Assist with third-party risk assessments, including scoping, evidence review, findings, remediation and follow-up.
- Help improve TPRM playbooks, templates and reporting, and support the integration of risk review into vendor onboarding, renewal and change processes.
Cybersecurity programme and operational risk support
- Support delivery of Teneo’s cybersecurity roadmap by tracking initiatives, dependencies, risks and stakeholder actions.
- Identify recurring control weaknesses and operational pain points, and help develop practical improvements through clearer ownership, better measurement and appropriate automation.
- Contribute to governance and assurance activities supporting vulnerability management, patching, access reviews, secure configuration and logging controls.
Requirements
- Relevant experience in technology risk, cybersecurity governance, compliance, audit support, third-party risk or a related field.
- Working knowledge of control-based assurance and common frameworks such as ISO 27001, SOC 2 or Cyber Essentials; familiarity with NIST is beneficial.
- Strong analytical and organisational skills, with the ability to manage evidence, actions and deadlines across several workstreams.
- Clear written and verbal communication skills, with confidence working collaboratively across technical and business teams.
- A practical, detail-oriented approach and the curiosity to identify improvements rather than simply administer existing processes.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
What We Can Offer
- Competitive salary (depending on experience)
- 28 days holiday
- Discretionary bonus
- Annual salary review
- Pension (with company contribution: 5% of annual salary)
- Extensive investment in personal development & learning
- Enhanced maternity and paternity leave (depending on length of service) and shared parental leave
- Private medical insurance
- Group Income protection
- Life assurance
- Cycle to work schemes
- Season ticket loans
- Regular social, cultural and charitable activities
- Flexible working with office laptop and phone provided
About Teneo
Teneo is the global CEO advisory firm. We partner with our clients globally to do great things for a better future.
Drawing upon our global team and expansive network of senior advisors, we provide advisory services across our five business segments on a stand-alone or fully integrated basis to help our clients solve complex business challenges. Our clients include a significant number of the Fortune 100 and FTSE 100, as well as other corporations, financial institutions and organisations.
Our full range of advisory services includes strategic communications, investor relations, financial transactions and restructuring, management consulting, physical and cyber risk, organisational design, board and executive search, geopolitics and government affairs, corporate governance and ESG.
The firm has more than 2,000 employees located in 50+ offices around the world.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location