Cyber Risk and Resilience Analyst at Cosasco in LOC Halma plc London
- Company: Cosasco
- Location: LOC Halma plc London
- Posted: Sep 24, 2026
- Type: Full-time
- Experience: 6+ years
Overview
Help grow a safer, cleaner, healthier future for everyone, every day. As cyber risks evolve, businesses face a complex and expanding threat landscape, making strategic risk management essential. We are seeking Our a talented Cyber Risk Analyst with a strong background in Cybersecurity Audit and Assu…
Job description
- Help grow a safer, cleaner, healthier future for everyone, every day.
- As cyber risks evolve, businesses face a complex and expanding threat landscape, making strategic risk management essential. We are seeking Our a talented Cyber Risk Analyst with a strong background in Cybersecurity Audit and Assurance to identify vulnerabilities within the organization and that of the organisation’s portfolio of companies around the world, to improve risk visibility, and implement effective risk mitigation. In this role, you will also be instrumental in ensuring the organization’s technology systems are secure, resilient, and aligned with acceptable risk thresholds.
Responsibilities
- Cyber Audit & Assurance
- • Conduct comprehensive audit assessments of IT infrastructure, cloud environments, application stacks, and third-party vendor systems to verify control effectiveness
- • Map internal control frameworks to industry standards and regulatory mandates (e.g., ISO 27001, NIST CSF, SOC 2, HIPAA, GDPR, PCI-DSS)
- • Act as the primary liaison between technical teams and external/internal auditors during annual cyber audits and regulatory examinations
- • Define, execute, and document technical audit test plans, sampling strategies, and evidence collection workflows to support internal assurance reviews
- Risk Assessment and Advisory
- • Work collaboratively with Technology, Audit, and Risk teams, and operating companies, to conduct thorough cybersecurity risk, audit and assurance assessments
- • Develop and sustain effective relationships with business and functional partners, offering guidance, risk oversight, and educational support
- • Identify and report on non-compliance with risk frameworks, ensuring that deviations are well-documented and visible.
- Mitigation and Support
- • Assist the Audit and Risk Teams in identifying and tracking mitigation actions for any technology and cybersecurity issues.
- • Compile and present regular security reports for stakeholders, summarizing the organization’s security status, incidents, and risk assessments.
- Threat Intelligence and Security Awareness
- • Monitor and stay informed about new cybersecurity threats, vulnerabilities, and trends in the industry.
- • Integrate this intelligence into the organization’s security strategy.
- • Foster an organization-wide security mindset by providing training and guidance on cybersecurity best practices.
Requirements
- • Relevant certifications in cybersecurity (such as CISM, CISSP, CRISC, or CISA) are preferred.
- • Strong experience in managing partnerships and fostering trust, with the ability to influence and work collaboratively with various stakeholders
- • Excellent communication skills, both verbal and written, with the ability to convey complex information effectively, particularly to executive and board-level audiences.
- • Outcome-driven, with a demonstrated ability to foster teamwork across functions.
- Technical and Analytical Proficiency
- • Solid understanding of operational risk management frameworks, including processes for identifying, assessing, and managing risk scenarios
- • Demonstrable experience with cyber assurance and audit risk assessment
- • Excellent knowledge of regulatory standards, frameworks, policies and procedures
- • Proficiency in various technology domains, including systems and software architecture, cloud platforms, networking, IoT, and integration technologies
- • Experience in consulting and change management, particularly in supporting technology-led transformations within an organization.
- • Curiosity and awareness of rapid developments in technology and security, with the ability to assess how emerging trends may impact the organization.
- • Ability to navigate complex global structures, advocating for and implementing new ideas and innovative solutions.
Skills
Required
- Cybersecurity Audit and Assurance
- Operational risk management frameworks
- Partnership management
- Teamwork
- Outcome-driven
Preferred
- Systems and software architecture
- Cloud platforms
- Networking
- IoT
- Integration technologies
- Consulting
- Change management
- Navigating complex global structures
About Cosasco
Halma is a global group of life-saving technology companies, focused on growing a safer, cleaner, healthier future for everyone, every day. Its purpose defines the three broad market areas where it operates: • Safety: protecting life as populations grow and protecting worker safety. • Environment: addressing the impacts of climate change, pollution and waste, protecting life-critical resources and supporting scientific research. • Health: meeting rising healthcare demand as growing populations age and lifestyles change. It employs over 7,000 people in more than 20 countries, with major operations in the UK, Mainland Europe, the USA and Asia Pacific. Halma is listed on the London Stock Exchange (LON: HLMA) and is a constituent of the FTSE 100 index. In January 2022, Halma was named one of Britain's Most Admired Companies by Management Today.