Orbis Corporation
Information Security Risk Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Information Security Risk Analyst
Everything we do exists to find alpha, investment value the market has overlooked. We believe technology is a genuine source of that edge and core to how we find and act on conviction. Because of this, we are modernising our core platform, investing in our data, and building AI solutions that help us achieve alpha for our clients.
Protecting that edge – our data, our platforms and the trust our clients place in us – is fundamental. As an Information Security Risk Analyst in our Security team, reporting to the Security Manager, you will play a critical part in how we do this: identifying, assessing and tracking information security risk across our technology estate, data and third parties, and turning it into clear, evidence-based decisions for the business.
We are home to world-class talent, and we’re looking for more of it to help define what our investment edge looks like next. You will thrive at Orbis if you enjoy solving challenging problems alongside motivated people.
Why Orbis?
- Culture: We are committed to our Core Values. We encourage intellectual curiosity and individualism as well as collaboration across different areas of the business. We seek to hear our people’s voices, whether quiet or loud. Sharing ideas and challenging the status quo are commonplace.
- Autonomy: While guidance and support are provided, team members own their work and projects.
- Growth opportunities: We support our people in continuous learning and development.
- Agile environment: We are committed to providing a work environment that balances the needs of our clients; the needs of our teams; and the personal needs, commitments, and interests of our people.
- Philanthropy: Our people can contribute to society in a unique and personal way, through various philanthropy opportunities and programmes.
What will your responsibilities be?
- Assess security risk. Carry out risk assessments of new systems, changes, projects and emerging technology – including AI tools and integrations – and turn findings into practical recommendations.
- Manage third-party security risk. Run security due diligence on suppliers and cloud services, and monitor their risk over the life of the relationship.
- Assess controls. Review the design and operation of security controls against recognised frameworks (e.g. ISO 27001, NIST CSF), identify gaps, and track remediation through to closure.
- Maintain the Information Security Risk Register. Identify, assess and record security risks across our systems, data and suppliers, with clear ownership, treatment plans and escalation paths.
- Produce and analyse key risk indicators (KRIs). Collect and report security KRIs monthly, working with security operations and engineering to turn threat, vulnerability and incident data into business risk and to call out trends and systemic weaknesses.
- Support security governance. Prepare materials for risk forums and senior management, manage policy exceptions and risk acceptances, and make sure decisions and actions are recorded and followed up.
- Benchmark our maturity. Participate in information security maturity assessments against recognised frameworks, and help turn the results into a prioritised improvement roadmap. Keep our framework current.
- Maintain security policies, standards and procedures. Monitor regulatory requirements (e.g. FCA, DORA, GDPR), and support internal and external audits.
- Support client due diligence. Respond to client and prospect security questionnaires and due diligence requests.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
About you
We care as much about how you think as what you’ve done. Alongside experience, we look for intellectual curiosity and a growth mindset: you learn continuously and apply what you learn to deliver better outcomes. You have deep, hands-on experience in information security and a genuine interest in risk – how threats, vulnerabilities and controls combine to affect the business. Experience with our specific tools is an asset rather than a necessity. Just as important is the flexibility to pick up whatever the problem needs – a technical deep-dive with engineers, or a clear conversation with the business. Communication, judgement and problem-solving matter as much as technical knowledge.
What you will gain
- Breadth and influence. The opportunity to shape how security risk is understood across a firm where technology is central to the investment edge, working directly with engineers, investment teams and senior management.
- Investment and industry knowledge. A practical understanding of investment management and financial services.
- Governance exposure. Experience presenting risk directly to senior management and board-level forums, and shaping how an FCA-regulated asset manager responds to DORA and evolving regulation.
- AI risk and AI-enabled analysis. Experience assessing the security risk of AI tools, agents and integrations, and using AI to automate risk analysis and reporting.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Your qualifications & experience
- 5+ years of experience in information security, IT risk, audit or GRC, with a track record of running risk processes independently.
- Bachelor’s degree in information security, computer science or a related field, or equivalent professional experience.
- Security risk assessment experience, including maintaining a risk register, assessing controls and tracking remediation.
- Good technical understanding across core technology domains such as infrastructure, networks, cloud, identity and applications.
- Working knowledge of security frameworks (ISO 27001, NIST CSF or similar) and experience applying regulatory requirements such as FCA, DORA and GDPR.
- Relevant certifications (e.g. CISM, CRISC, CISSP, ISO 27001 Lead Implementer/Auditor) are strongly preferred.
- Strong interpersonal and communication skills – you’ll present findings to both technical and business audiences.
How to apply
Please submit your CV and a short covering note.
The Company
We are a global firm with offices across eight countries, over 400 employees and more than $50 billion in assets under management. But those numbers don’t define Orbis. It’s our values, how we do things day by day, and how we add value for our clients that define us. Our investment philosophy is fundamental, long-term and contrarian. As contrarian investors, we aim to take a different perspective, and this filters into everything we do. To invest differently, you need to think differently. This is encouraged by having teams of people with different backgrounds, experiences and ways of thinking.
Find out more about us at www.orbis.com.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location