Change Recruitment
Senior Information Risk Manager

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Senior Information Risk Manager
Cyber Security | Technology Risk | People Leadership
Office attendance: typically four days per week in Edinburgh City Centre
If you have the technical depth to challenge cyber security specialists and the judgement to explain risk clearly to senior leaders, this role offers both scope and room to grow.
We are recruiting an Information Risk Senior Manager to lead a specialist team within an established risk function.
The organisation is expanding its use of AI and other technologies and you will help it move forward with confidence by making sure security risks are understood, controls are tested and decisions are based on evidence.
The role offers a potential path towards broader information security leadership for someone who wants to build on strong technical experience.
The opportunity
You will lead a team covering information security risk, technology risk, data protection and emerging technology. The team already has experienced specialists. Your contribution will be to bring stronger technical challenge across cyber security and technology while setting priorities and developing the people around you.
This is a risk oversight role with close involvement in practical security decisions. You will need to understand how technology works, ask searching questions of operational teams and judge whether proposed controls will work in practice.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Key responsibilities
- Lead and coach the Information Risk team, creating clear priorities across a broad portfolio of work.
- Direct an assurance programme covering areas such as penetration testing, cyber resilience, cloud services, applications, access controls and third parties.
- Challenge security findings and proposed actions, working closely with technical and operational specialists.
- Maintain effective risk frameworks and policies, including arrangements supporting ISO 27001.
- Assess the security implications of technology change and AI adoption.
- Support cyber incident preparation and response, then use lessons learned to strengthen controls.
- Present clear advice and reporting to senior stakeholders and governance forums.
About you
You will bring substantial experience in cyber security, information security or technology risk. You should be able to discuss technical issues credibly with security specialists, while explaining their business impact to people without a technical background.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Experience using NIST or a comparable structured security framework is important. You will also understand how to scope assurance work, assess the evidence it produces and decide where further action is needed.
You may already lead a team or be ready to take on broader leadership responsibility. Either way, you will be proactive, collaborative and comfortable making balanced decisions when the answer is not straightforward. Relevant experience could come from financial services, professional services or another organisation with complex technology and risk requirements.
Why consider this role?
You will inherit an experienced team, have meaningful influence over the approach to emerging technology risk and gain exposure to senior decision makers. There is also scope to develop towards a more senior information security leadership role over time.
The working pattern is typically four days per week in the office, with some flexibility discussed on a case by case basis.
For a confidential discussion, apply or contact us directly on either scott.maxwell@changerecruitmentgroup.com or Mitesh.Fatnani@Change-Digital.co.uk
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London