Information Security Risk & Assurance Specialist - easyJet - London, UK
(2023-08 - 2026-04)
Currently responsible for delivering comprehensive information security risk and assurance activities at easyJet. Oversee ISO 27001-aligned risk assessments, reengineer security standards and policies to build effective control frameworks and manage the security posture of 300+ critical third-party suppliers. Lead efforts in supplier assurance, incident response, and regulatory compliance while embedding security controls into project lifecycles.
Collaborate with cross-functional teams to design and implement mitigation strategies, produce risk reports for senior stakeholders, and foster a security-conscious culture across the organization.
- Initiated and led a comprehensive risk assessment in alignment with the new EASA Part-IS regulation, using existing business-area risk registers as a baseline. Developed and mapped cyber risk scenarios to operational safety risks, collaborating with multiple operational teams to identify vulnerabilities within critical systems. Reviewed existing controls, identified areas lacking coverage, and implemented targeted control measures to ensure compliance and strengthen aviation safety and cyber res
- Led third-party incident response activities, assessing risk exposure to support management decision-making, defining reconnection criteria, and ensuring remediation actions were evidenced and formally signed off.
- Led ISO 27001-aligned information security risk assessments across strategic projects, facilitating workshops with business stakeholders to identify, analyse and evaluate risks against the organisation's risk appetite, enabling informed risk treatment and governance decisions.
- Manage a portfolio of 300+ third-party suppliers by applying tailored assurance strategies and continuous risk reviews, enhancing performance and minimizing service delivery risks.
- Develop and implement comprehensive information security risk frameworks to ensure regulatory compliance, reduce vulnerabilities, and drive operational efficiency.
- Design and maintain assurance methodologies aligned to supplier risk profiles, business priorities, and industry regulations.
- Conduct project assurance activities across all IT and business initiatives to identify security risks early and ensure mitigation plans are integrated into project lifecycles.
- Evaluate existing security controls and introduce new technical or procedural measures based on findings from risk assessments, threat trends, and internal audits.
- Lead incident response initiatives by identifying root causes, reducing resolution time, and implementing automated containment strategies to prevent recurrence.
- Deliver expert training on cybersecurity best practices; tailor awareness programs to specific business processes, resulting in a 20% increase in compliance and risk awareness.
- Promote a security-first culture by engaging stakeholders and leading awareness campaigns on current threats, regulatory requirements, and organizational policies.
- Identify and prioritize vulnerabilities in systems, networks, and applications; work closely with IT teams to ensure timely and effective remediation.
- Develop, review, and maintain security policies and procedures in line with ISO 27001, NIST, and SOC2 standards, collaborating cross-functionally to ensure adoption.
- Maintain real-time documentation of third-party security postures, including access, data handling, and critical service risks.
- Provide risk reporting and insights to senior leadership and Risk Forum, using dashboards and presentations to explain findings and propose mitigation strategies.
- Monitor emerging threats, regulatory changes, and industry trends to continuously evolve risk mitigation strategies and supplier assurance controls.
- Build strong relationships across Legal, Procurement, and IT to align cross-functional risk management strategies with business goals.
AVP, Technology/Cyber Risk Oversight & Operational Resilience - MUFG - London, UK
(2022-07 - 2023-08)
Provided second-line oversight for technology and cyber risk at MUFG, with a focus on strengthening operational resilience, control effectiveness, and regulatory compliance across the EMEA region. Delivered independent risk challenge, conducted deep-dive assessments, and supported the rollout of enterprise risk frameworks to the First Line of Defense. Played a key role in third-party risk management, control attestations, and stress testing of critical systems, while aligning risk oversight with regulatory expectations and organizational resilience objectives.
- Developed and enhanced second-line defense capabilities by assessing and strengthening Tech and Cyber controls, contributing to a 15% improvement in operational resilience across EMEA.
- Evaluated and challenged IT and Cloud controls submitted to the PRA, addressing critical vulnerabilities and significantly improving audit compliance.
- Delivered second-line challenge across risk assessments, key risk indicators (KRIs), incident reviews, and control assurance to ensure effective first-line risk management.
- Tracked and reported on technology and cyber risks, ensuring timely resolution of vulnerabilities and integrating KPIs/KRIs to improve operational visibility.
- Conducted deep-dive risk assessments within critical departments, embedding lessons learned and enhancing future risk mitigation strategies.
- Contributed to the design and rollout of strategic risk management frameworks to the First Line of Defense, aligning with enterprise risk objectives.
- Oversaw third-party risk processes by ensuring accurate mapping of critical services, strengthening third-party service reliability.
- Identified key business applications and led stress testing activities, mitigating system vulnerabilities and enhancing operational resilience.
- Collaborated with Technology teams to complete annual control attestations, validating effectiveness of tech-owned controls and improving audit readiness.
- Led and supported risk-informed enhancements and project initiatives, enabling the successful rollout of resilience initiatives across EMEA.
- Delivered independent risk challenge and oversight on new product launches, system implementations, and material change programs.
- Ensured evolving regulatory requirements were effectively understood and translated into actionable plans for implementation across business units.
Assurance Consultant - CAPITA - London, UK
(2021-07 - 2022-07)
Provided risk assurance support, focusing on vulnerability management, audit readiness, and third-party risk. Delivered ISO 27001-aligned risk assessments, improved incident response readiness, and led targeted phishing awareness initiatives. Ensured high remediation rates, audit compliance, and policy enforcement to support a stronger cybersecurity posture across critical infrastructure and sensitive environments.
- Maintained and updated the enterprise security risk register, tracking issue resolution and presenting findings to the Security Governance Board to enhance oversight and expedite remediation.
- Assessed the effectiveness of security controls and implemented policy enhancements that reduced non-compliance and improved overall security posture.
- Conducted ISO/IEC 27001-aligned security risk assessments for critical infrastructure, identifying vulnerabilities and executing mitigation strategies.
- Tracked and resolved non-conformities identified during internal audits, achieving a 95% remediation rate and reducing resolution timelines for critical issues.
- Monitored scheduled and ad-hoc vulnerability scans using tools such as Nessus, ensuring 100% remediation of critical/high-risk vulnerabilities within 30 days.
- Developed and maintained security incident response and data breach procedures, reducing incident response times and ensuring alignment with regulatory SLAs.
- Led phishing simulation and cybersecurity awareness campaigns, which reduced phishing incident rates and increased employee engagement in security training by 25%.
- Implemented targeted cyber awareness programs based on campaign outcomes, reducing phishing test failure rates by 30%.
- Completed comprehensive third-party due diligence and annual customer audit questionnaires, resulting in a 100% audit pass rate and strengthening vendor compliance.
- Conducted and tracked third-party security risk assessments, improving compliance posture and reducing risk exposure among high-risk suppliers.
Risk & Compliance Analyst - F8 Networks - London, UK
(2020-07 - 2021-07)
Delivered risk and compliance oversight at F8 Networks, with a focus on GRC process improvement, awareness training, and third-party risk management. Implemented KRIs and standardized documentation workflows, leading to more effective reporting and stronger compliance in technology projects. Contributed to zero-issue audits and drove a measurable improvement in stakeholder response and audit readiness.
- Managed GRC service queue, resolving 95% of escalated tickets within SLA and improving stakeholder satisfaction and compliance responsiveness.
- Developed and implemented KRIs to enhance risk reporting and support strategic decision-making