as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or CISA (Certified Information Systems Auditor) are highly desirable. Strong knowledge of security frameworks (e.g., ISO 27001, COBIT), security technologies, tools, and best practices across EU, UK, and USA Proficiency in risk management processes, vulnerability assessments, and incident response strategies. Current technical and hands-on experience with security More ❯
as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or CISA (Certified Information Systems Auditor) are highly desirable. Strong knowledge of security frameworks (e.g., ISO 27001, COBIT), security technologies, tools, and best practices across EU, UK, and USA Proficiency in risk management processes, vulnerability assessments, and incident response strategies. Current technical and hands-on experience with security More ❯
data models and reporting frameworks. Ensure alignment of analytics and reporting outputs with enterprise risk management andcontrol frameworks. Strong knowledge of risk management frameworks (e.g., NIST, ISO 27001, COBIT) andcontrol environments. Deep understanding of IT general controls, cyber security principles, andtechnology risk domains. Proven experience in risk analytics, data visualization, and reporting (e.g., using Power BI, Tableau More ❯
information security management, with a focus on ISO 27001 compliance. In-depth knowledge of ISO 27001 standards and best practices , as well as other relevant security frameworks (e.g., NIST, COBIT). Strong technical understanding of modern IT and cloud environments, including the ability to assess third-party platforms, suppliers, and software for security risks. Proven experience in developing and implementing More ❯
information security management, with a focus on ISO 27001 compliance. In-depth knowledge of ISO 27001 standards and best practices , as well as other relevant security frameworks (e.g., NIST, COBIT). Strong technical understanding of modern IT and cloud environments, including the ability to assess third-party platforms, suppliers, and software for security risks. Proven experience in developing and implementing More ❯
degree or relevant industry qualifications (e.g., CISA, CRISC, CISM) Strong academic background and mathematical acumen Experience with industry standard IT risk management frameworks (e.g., NIST, ISO 27001, Cyber Essentials, COBIT, COSO) 10+ years' experience in the IT Risk sector (Risk Management, External Audit, Internal Audit), preferably with a strong understanding of the insurance industry Excellent Microsoft Office skills, in particular More ❯
/or existing IT General Controls from across access, change, and operations domains drawing on experience to do so independently and/or with minimal support. Working knowledge of COBIT/ITIL Frameworks Comfortable performing IT Risk Assessments across a variety of IT domains. Strong analytical and problem-solving skills, being able to decipher sometimes complex information, analyse and report More ❯
develop action plans, identify owners and track through to completion. Requirements: Technology Knowledge: Work towards a detailed understanding of Technologyand cyber risk frameworks (e.g. NIST/ISO27001/COBIT/ITIL). SSSDLC Expertise: Understanding of the Secure Software/System Development Lifecycle, including secure design, development, testing, and deployment practices. Process Documentation: Experience in drafting, updating, and maintaining More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Adecco
develop action plans, identify owners and track through to completion. Requirements: Technology Knowledge: Work towards a detailed understanding of Technologyand cyber risk frameworks (e.g. NIST/ISO27001/COBIT/ITIL). SSSDLC Expertise: Understanding of the Secure Software/System Development Lifecycle, including secure design, development, testing, and deployment practices. Process Documentation: Experience in drafting, updating, and maintaining More ❯
technologyrelated regulations e.g. Ops Res, GDPR, DORA, SOx etc Demonstrate experience of technology risk profiling, assessments, scenarios, metrics and reporting. Demonstrate knowledge of Risk Frameworks and certifications including Cobit, NIST, ISO27001 Financial services experience 5+ (not exclusively Insurance) Demonstrate a level of seniority - this is a new role and will require the candidate to plan and implement the IT More ❯
from time to time. What we're looking for: Qualified to degree level or time served experience. CISA, CRISC or similar professional qualifications but training will be provided ITIL, COBIT, SOX knowledge - Desirable 2-3 years of experience working within an IT control testing programme Experience working in an external audit team within a Big 4 or similar corporate environment More ❯
bolton, greater manchester, north west england, united kingdom
JSS Search
technologyrelated regulations e.g. Ops Res, GDPR, DORA, SOx etc Demonstrate experience of technology risk profiling, assessments, scenarios, metrics and reporting. Demonstrate knowledge of Risk Frameworks and certifications including Cobit, NIST, ISO27001 Financial services experience 5+ (not exclusively Insurance) Demonstrate a level of seniority - this is a new role and will require the candidate to plan and implement the IT More ❯
warrington, cheshire, north west england, united kingdom
JSS Search
technologyrelated regulations e.g. Ops Res, GDPR, DORA, SOx etc Demonstrate experience of technology risk profiling, assessments, scenarios, metrics and reporting. Demonstrate knowledge of Risk Frameworks and certifications including Cobit, NIST, ISO27001 Financial services experience 5+ (not exclusively Insurance) Demonstrate a level of seniority - this is a new role and will require the candidate to plan and implement the IT More ❯
were looking for: 5+ years in tech risk, IT audit, cyber/digital resilience (FS sector) Strong knowledge of FCA/PRA Operational Resilience, DORA, ISO/NIST/COBIT Experience managing multi-workstream projects & producing board-level deliverables Excellent communicator with proven leadership skills Professional certifications (CISA, CRISC, CISM etc.) and cloud/AI knowledge are a bonus. This More ❯
regulations across UK and EU such as DORA, ECB’s EBA, PRA andrelated standards Informationand Cyber Security Frameworks and industry Standards (e.g., NIST/ISO 27001/COBIT/ITIL) Experience creating and delivering presentations and concise writing skills to produce clear documentation (security policy, senior management posture reports) Excellent inter-personal communication skills, able to liaise with More ❯
regulations across UK and EU such as DORA, ECB’s EBA, PRA andrelated standards Informationand Cyber Security Frameworks and industry Standards (e.g., NIST/ISO 27001/COBIT/ITIL) Experience creating and delivering presentations and concise writing skills to produce clear documentation (security policy, senior management posture reports) Excellent inter-personal communication skills, able to liaise with More ❯
Required 10+ years of experience in IT Risk, Internal/External Audit, or Risk Management (preferably within insurance). Strong understanding of industry frameworks such as NIST, ISO 27001, COBIT, or COSO. Proven ability to work independently while managing senior-level stakeholder relationships. Demonstrable experience with global regulatory environments (e.g., PRA/FCA, BMA, CBI). Strong analytical, verbal, andMore ❯
party regulations across UK and EU such as ECB's EBA, DORA andrelated standards Informationand Cyber Security Frameworks and industry Standards (e.g., NIST/ISO 27001/COBIT/ITIL) Experience creating and delivering presentations and concise writing skills to produce clear documentation (security policy, senior management posture reports) Excellent inter-personal communication skills, able to liaise with More ❯
party regulations across UK and EU such as ECB's EBA, DORA andrelated standards Informationand Cyber Security Frameworks and industry Standards (e.g., NIST/ISO 27001/COBIT/ITIL) Experience creating and delivering presentations and concise writing skills to produce clear documentation (security policy, senior management posture reports) Excellent inter-personal communication skills, able to liaise with More ❯
Ideally, you will also have: Knowledge of or certification in structured methodologies and a familiarity with industry standards such as ITIL for Infrastructure, Systems Development Life Cycle methods andCOBITfor IT Governance. What we offer you We will fuel your ambition and potential with future-focused skills development that equips you with state-of-the-art methodologies andtechnologyMore ❯
working within an ERP environment where ITGCs, and access/application controls are subject to routine audits Solid understanding of IT risk management principles , andcontrol frameworks (e.g., SOX, COBIT, COSO). Proven track record of handling or advising on secure and compliant solutions within large-scale Oracle Cloud ERP implementations. Hands-on experience with user access provisioning, SoD frameworks More ❯
sectors (eg, pharmaceuticals). IT Process Knowledge: Solid understanding of common IT processes, structures, and departmental functions. Risk Framework Proficiency: Working knowledge of recognized Risk Management Frameworks (eg, NIST, COBIT preferred). Stakeholder Engagement: Proven ability to communicate and influence effectively at all levels, including senior IT management. Data & Reporting Skills: Experience in developing risk dashboards, analytics, and performance metrics. More ❯
through to completion. The successful It Risk Management Specialist will have: Technology Knowledge: Work towards a detailed understanding of Technologyand cyber risk frameworks (e.g. NIST/ISO27001/COBIT/ITIL). SSSDLC Expertise: Understanding of the Secure Software/System Development Lifecycle, including secure design, development, testing, and deployment practices. Process Documentation: Experience in drafting, updating, and maintaining More ❯
assessment and risk assessment The ability to influence senior leaders and collaborate across business, technology, and vendor teams Relevant qualifications and ideally certifications such as CISSP, CRISC, CGEIT, CISM, COBIT, SABSA, TOGAF (Security), or equivalent. You'll join our Digital Security and Risk Team - a close-knit group of passionate professionals who thrive on collaboration, creativity, and making a real More ❯
Surrey, England, United Kingdom Hybrid / WFH Options
Sanderson
regulated industry. Experience in large, complex enterprise environments (e.g., multiple sites, technologies). Hands-on leadership in technical InfoSec initiatives. Strong understanding and implementation of control frameworks (NIST CSF, COBIT). Ability to run threat intelligence and vulnerability assessments. Experience collaborating with 2nd and 3rd line governance teams (e.g., audit, compliance). Strong stakeholder engagement and influencing skills. Reasonable Adjustments More ❯