About Kerry
About the role
The ICT Security Analyst -Risk, supports and helps mature Kerry’s ICT Security governance, risk management, assurance and incident readiness activities.
The role has a strong focus on ICT risk management, ServiceNow Integrated Risk Management, risk assessment methodology, risk reporting, remediation tracking, security governance, policy and procedure maintenance, and coordination of risk-related stakeholder engagement across ICT and the wider business. The role reports to the ICT Security Manager.
This position requires active collaboration across ICT and business teams, with a strong emphasis on stakeholder engagement. The ideal candidate will bring strong reporting and presentation capabilities and thrive in a cross-functional environment. This is an excellent opportunity for a self-starter who can drive continuous improvement in risk management while building trusted relationships across the organisation.
Here at Kerry, we support a hybrid working model of 3 days in the Naas office and 2 days working remotely.
Key responsibilities
- Support the development, maintenance and continuous improvement of Kerry’s ICT risk management framework, including alignment with Kerry’s enterprise risk governance model.
- Support the optimisation and ongoing use of ServiceNow Integrated Risk Management, including risk visibility, KPIs/KRIs, remediation workflows and ownership tracking.
- Maintain and improve risk assessment methodology, risk assessment processes and supporting procedures to ensure risks are identified, assessed and recorded consistently.
- Conduct and coordinate ICT security risk assessments, including threat and risk assessments, advanced risk assessments and ad hoc risk identification activities.
- Support the creation, review and maintenance of risk statements, risk frameworks, entity scoping, risk registers, controls libraries and controls testing procedures.
- Track, review and report ICT risk issues, observations, exceptions and remediation tasks, ensuring ownership, due dates and remediation actions are visible and appropriately maintained.
- Prepare and support monthly and quarterly ICT risk reporting, including risk dashboards, risk metrics, KPI/KRI development and stakeholder updates.
- Support ICT risk governance forums by preparing agendas, meeting packs, status reporting, actions, decisions and escalations where required.
- Contribute to governance and policy activities, including policy and procedure reviews, updates, approval processes and alignment to Kerry’s ICT security governance needs.
- Support incident response readiness through defined and repeatable exercises, tabletop activity, incident response coordination drills, lessons learned and process improvement.
- Support BAU ICT Security activity including security incidents, software/security reviews, security monitoring inputs and engagement with relevant security tools and stakeholders.
- Work with internal audit, ICT stakeholders, system owners and business teams to review risk items, assign ownership, track remediation and support evidence-based closure of issues.
- Support security risk reviews of SaaS providers, third parties, applications, projects and technology changes, ensuring identified risks are documented and tracked through the ICT risk process.
- Maintain awareness of current cyber risks, regulatory expectations and control frameworks to support effective ICT risk assessment, risk treatment and governance.
Qualifications and skills
- Third-level qualification in IT, cyber security, information systems, risk management or equivalent professional experience would be a distinct advantage.
- Experience or strong working knowledge of ICT risk management, cyber security governance, compliance, audit support or information security assurance.
- Practical understanding of risk identification, risk assessment, risk treatment, control effectiveness and remediation tracking.
- Experience working with GRC or IRM tooling is desirable, particularly ServiceNow Integrated Risk Management.
- Familiarity with security control frameworks and regulatory drivers such as NIST CSF, ISO 27001 and NIS2 is desirable.
- Experience supporting or conducting security risk assessments, SaaS/security reviews, third-party reviews or project security assessments.
- Understanding of incident response processes, tabletop exercises or cyber incident readiness activities is desirable.
- Strong analytical and problem-solving skills, with the ability to translate technical risk information into clear business-facing outputs.
- Excellent written and verbal communication skills, including the ability to engage with ICT teams, risk owners, auditors and business stakeholders.
- Ability to manage multiple priorities, track actions through to closure and work effectively under pressure.
- Relevant cyber security, risk or audit certifications are desirable, for example CISM, ISO 27001 Lead Auditor, GIAC, CISSP, CRISC or equivalent.
At Kerry, we understand that everyone's career journey is unique, and that talent can be developed through many different experiences and pathways. We know that the ideal candidate may not tick every box on a job description, and that's okay. If you're excited about the opportunity and believe your skills, experience, and potential could make a positive impact, we encourage you to apply. We value diverse perspectives and are committed to creating an inclusive environment where people can learn, grow, and succeed.
Why Kerry?
In Kerry we benefit from the knowledge of our colleagues who bring a diverse range of cultures, backgrounds, lifestyles, and experiences. One team fostering an inclusive culture that, above all, inspires food and nourishes life. One culture where everyone brings their unique perspectives and experiences to help make us better, together. We are committed to nurturing an environment of positivity and inclusiveness, where everyone can be at their best, both personally and professionally.
Our recruitment, selection and assessment process are based on the skills and competencies of the specific roles and based entirely on merit. We are committed to and value Diversity and Inclusion in all recruitment processes within Kerry and do not discriminate based on gender, race, class, economic status, ethnic background, sexual orientation, age, political beliefs, veteran status, marital status or any other protected characteristic.
Please note: We do not accept CVs or candidate profiles from recruitment agencies where Kerry terms of business have not been signed. Additionally, we will not consider or agree to payment of any recruiter fee under these circumstances. This also applies to CVs or candidate profiles sent directly to any Kerry Hiring Managers.



