Information Risk Analyst
- AI
- Penetration Testing
- Risk Management Framework
- Risk Management
Job Title
Information Risk AnalystDepartment
Business Risk-BG-UKOverview of Department
Information risk helps protect the firm, its clients and its information while supporting the responsible use of technology and innovation. The Information Risk team provides specialist oversight, advice and challenge across information and cyber security, technology, data privacy, artificial intelligence (AI) and other emerging technologies.
Purpose of Role
As Information Risk Analyst, you will assist with the identification, analysis, monitoring and reporting of information risks in line with the firm's risk appetite. You will work with departments across the firm to build effective relationships and support a trusted-adviser approach, contributing to clear risk insight and proportionate challenge.The role offers broad exposure to information risk and practical assurance activity. You will support the team on key governance and reporting activities, contribute to penetration testing, security and cyber resilience exercises and other assurance work, while applying technical knowledge to support information security risk assessments and control reviews and developing your understanding of AI and other emerging technology risks.
Responsibilities
Information risk analysis and oversight
- Support the analysis of information risks, including AI and other emerging technologies, information and cyber security, technology and data privacy risks in accordance with the risk management framework.
- Assist in developing the quality and efficiency of risk analysis and monitoring, including the associated risk management framework, policies and procedures.
- Support the identification, assessment, monitoring and reporting of risks arising from the firm's adoption and use of AI and other emerging technologies, in line with the firm's risk appetite and governance frameworks.
Assurance and technical support
- Assist with the execution of the information risk assurance programme, including penetration testing, security and cyber resilience exercises, and other assurance activities across infrastructure, cloud services, applications, identity and access, data flows and third parties.
- Apply technical knowledge to provide support and cover for the Information Risk team on information security risk assessments and control reviews, as required.
- Use information and evidence to support well-reasoned conclusions, escalating issues and seeking specialist input where appropriate.
Governance, collaboration and stakeholder support
- Assist in reporting to relevant committees and internal or external boards on information risk matters.
- Collaborate with the wider Business Risk Department and other departments on risk management activities, contributing to wider risk activity across the Department.
- Manage and respond to internal and external queries, providing clear and timely information and drawing on specialist support where needed.
Future capability
- Develop technical knowledge and practical understanding across information security and technology risk, building confidence in engaging with technical colleagues and translating complex issues into clear risk insight.
- Build knowledge of AI and other emerging technologies and their risk implications, contributing ideas to improve how information risk is assessed, monitored, assured and communicated.
What success looks like
- High-quality analysis:Information risks are assessed clearly and proportionately, with evidence used to support well-reasoned conclusions and appropriate escalation.
- Practical technical contribution:Technical knowledge is applied effectively to support information security risk assessments and control reviews while recognising when specialist input is required.
- Clear governance and reporting:Committee, board and stakeholder reporting is accurate, concise and timely, and internal and external queries are handled professionally.
- Trusted relationships:Colleagues across Business Risk and the wider firm see the role as collaborative, curious and constructive, with appropriate challenge provided when needed.
- Effective assurance support:Penetration testing, security and cyber resilience exercises, and other assurance activities are supported efficiently, with findings and actions captured accurately.
- Growing future capability:Knowledge develops across information security, technology, data privacy, AI and emerging technologies, enabling the role to take on broader responsibility over time.
Your knowledge and experience
- Information security, technology or other related risk qualifications are preferred.
- Applied knowledge of information security and/or technology, with an interest in developing this capability further in a risk-management environment.
- Awareness of current information security and technology trends and an ability to consider their potential risk implications, including developments in AI and other emerging technologies.
- Ability to analyse information and evidence, form clear conclusions and communicate effectively with both technical and non-technical stakeholders. Experience can have been gained through employment, study or other relevant practical exposure.
The type of candidate that we're looking for
We are looking for someone who is curious, analytical and keen to build their career in a broad and evolving area of risk. This role offers exposure to a wide range of information risks, including information and cyber security, technology, data privacy, AI and other emerging technologies, as well as the opportunity to contribute to assurance activity such as penetration testing and cyber resilience exercises. You will enjoy getting underneath an issue, understanding how risks and controls work in practice, and using information and evidence to form clear, well-reasoned conclusions. Some technical knowledge of information security or technology would be valuable, as well as an interest in developing this capability to become comfortable engaging with technical colleagues and translating complex issues into clear risk insights.
The role involves working with colleagues across Business Risk and the wider firm, so you will need to be a confident communicator who can build strong relationships, ask thoughtful questions and provide constructive challenge. You should be proactive, organised and willing to take ownership, with an interest in how new technologies such as AI are changing the firm and the risks and opportunities they create. We would particularly value someone who is keen to learn, broaden their experience and contribute ideas for improving how we assess, monitor and report risk. This would suit an individual who wants a role combining risk analysis, stakeholder engagement, emerging technology and practical assurance experience, with plenty of opportunity to develop their knowledge and responsibilities over time.
Critical skills
- Nurture relationships
- Adaptability
- Openness & discernment
- Team working
Closing Date
October 13, 2026Should you choose to use AI tools to support your application, we ask that you do this thoughtfully. We encourage you to ensure your application reflects your own voice, experience, and motivations. We value authenticity and want to understand your individual strengths and perspectives.
At Baillie Gifford, we are committed to fostering an inclusive and respectful culture in which each of our colleagues can thrive and develop. We believe that our clients are best served by a diverse workforce with the experiences, ideas and perspectives that this brings.
If you are currently working at Baillie Gifford as an employee or contractor please apply to this job from the firm's Workday internal career site.
Information Risk Analyst ยท Baillie Gifford Co