Global Technology Officer (GTO) to attest compliance with the Global IT Risk Management Framework and legal entity regulatory requirements. • Design and implement IT risk controls, mitigation strategies, and remediation plans. • Establish IT risk management policies and procedures, ensure their implementation. • Define key risk indicators (KRIs), key performance indicators (KPIs) and SLAs for IT risk management. • Test critical applications More ❯
Newcastle Upon Tyne, Tyne and Wear, England, United Kingdom Hybrid / WFH Options
Virgin Money
help you interpret how industry trends, regulations, and the threat landscape can affect our business. You've got experience in scoping penetration tests, conducting risk assessments, and overseeing remediation plans. You're skilled at influencing, communicating, and collaborating with senior management and stakeholders. You're well-versed in Cloud Service models like IaaS, PaaS, and SaaS and the More ❯
growth of their Security Function. Key Responsibilities: Support the planning and completion of compliance reviews to evaluate the effectiveness of information security controls, creating detailed compliance reports and remediation plans. Operate compliance tools in line with formal procedures. Maintain the Security And Risk Tracking (SART) and Exceptions process. Collaborate with business stakeholders to agree, implement, and manage security More ❯
to others. Develop and maintain security subject matter expertise Envision and help develop new insurance and cyber risk-service offerings that can be offered to existing clients. Devise remediation plans for new cyber clients and industry groups. Expand AIG's offering to encompass all aspects of risk management: how to avoid, prevent, mitigate, legally transfer, and financially insure More ❯
cost, and increase test efficiency. Introduce best practices for environment lifecycle management, aligned with ITIL and DevOps principles. Conduct regular environment health, audit, and risk assessments with clear remediation plans. Strategic People Leadership Lead a Logistics and Commissioning team, with responsibility for performance, career development, upskilling in cloud/DevOps, and succession planning. Mentor team members to transition More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Revybe IT Recruitment Ltd
working with Azure Solid knowledge of Microsoft Azure security tools and configurations. Experience deploying and managing WAF solutions . Networking experience - Cisco Demonstrated expertise in security audits and remediation planning. Ability to analyse and mitigate vulnerabilities from security reports. Excellent problem-solving and communication skills. Contract Details Type: Inside IR35 Duration: 6 Months Location: Fully Remote Day Rate More ❯
Defender and Prisma Cloud. Expertise with SAST & SCA systems such as Snyk and Checkmarx, including policy management. Ability to develop Threat Models as part of risk assessment, including remediation plans (preferred). Experience with DAST systems such as OpenZAP and Qualys DAST, ideally with HTTP APIs (preferred). Knowledge of API security models, including OAuth2 and Zero Trust More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Revybe IT Recruitment Ltd
working with Azure Solid knowledge of Microsoft Azure security tools and configurations. Experience deploying and managing WAF solutions . Networking experience - Cisco Demonstrated expertise in security audits and remediation planning. Ability to analyse and mitigate vulnerabilities from security reports. Excellent problem-solving and communication skills. Contract Details Type: Inside IR35 Duration: 6 Months Location: Fully Remote Day Rate More ❯
incidents and trends to identify root causes and recommend governance improvements. Work with operations teams to define KPIs and SLAs for infrastructure performance and stability. Document and track remediation plans for recurring production issues. Evergreening : Maintain inventory of infrastructure assets and track lifecycle milestones. Support planning and execution of technology refresh programs to ensure systems remain current and More ❯
level and third-party/vendor risk assessments. Analyse and document inherent and residual risks, providing clear recommendations. Produce detailed technical reports highlighting findings, control gaps, and proposed remediation plans. Drive remediation Perform periodic and ad-hoc risk assessments in line with organisational policies. The Security Risk Analyst is required onsite in London, once a week. More ❯
level and third-party/vendor risk assessments. Analyse and document inherent and residual risks, providing clear recommendations. Produce detailed technical reports highlighting findings, control gaps, and proposed remediation plans. Drive remediation Perform periodic and ad-hoc risk assessments in line with organisational policies. The Security Risk Analyst is required onsite in London, once a week. More ❯
level and third-party/vendor risk assessments. Analyse and document inherent and residual risks, providing clear recommendations. Produce detailed technical reports highlighting findings, control gaps, and proposed remediation plans. Drive remediation Perform periodic and ad-hoc risk assessments in line with organisational policies. The Security Risk Analyst is required onsite in London, once a week. More ❯
Caldecotte, Milton Keynes, Buckinghamshire, England, United Kingdom
Connells Group HQ
the effectiveness of the first line's data protection controls and overall compliance with data protection laws. This includes managing internal data protection audits, identifying gaps, and overseeing remediation plans. Advise on and monitor Data Protection Impact Assessments (DPIAs) for new projects, systems, and processes involving personal data. Maintain the Group's record of processing activities (ROPA). More ❯
Milton Keynes, Buckinghamshire, England, United Kingdom
VIQU IT Recruitment
level and third-party/vendor risk assessments. Analyse and document inherent and residual risks, providing clear recommendations. Produce detailed technical reports highlighting findings, control gaps, and proposed remediation plans. Drive remediation Perform periodic and ad-hoc risk assessments in line with organisational policies. The GRC Analyst is required onsite in London, once a week. Apply More ❯
Key Responsibilities of the Data Quality Analyst include: Deliver daily reports and enhance data governance controls Enforce data policies across ingestion, quality, and lifecycle management Maintain dashboards and remediation plans for data quality Collaborate with stakeholders to meet strategic data goals Apply governance frameworks and ensure accountability The successful Data Quality Analyst will have: Proficient in BI tools More ❯
clearly communicating progress, any issues that arise, and contributing to solution options. Key Outputs Requirements gathering and documentation. Process and data mappings. Bug/defect investigation, analysis and remediation plans. Progress updates to the wider programme team. Lawrence Harvey is acting as an Employment Business in regards to this position. Visit our website and follow us on Twitter More ❯
information risk. Validate the effectiveness of security controls and recommend improvements. Deliver security architecture for cloud and hybrid environments. Scope and review IT Health Checks (ITHC) and produce remediation plans. Conduct threat modelling, risk assessments, and design proportional controls. Produce security architecture artefacts including standards and blueprints. Travel to client sites (approx. 40-60%) as required for classified … HMG, NPSA, NCSC policies and guidance Cloud security (Azure, AWS), containerisation, KMS, WAFs Event-driven microservices, network infrastructure, IDS/IPS AI security (ISO42001 desirable), ITHC scoping and remediation Threat modelling (Kill Chain, attack trees), HLD/LLD reviews Certifications: SABSA, TOGAF, AWS/Azure Architect, CISSP, CISM. Working towards or holding CIISEC Full Membership or UK Cyber … Flexible Working: Remote-first with expected travel to site 2-3 days per week. Career Development: Continuous learning and professional growth. Benefits Package: Includes Private Health Care, Cash Back Plan, Buy/Sell Holiday Options, Life Assurance, and more. Interested? Submit your application to learn more about this exciting opportunity. Reasonable Adjustments: Respect and equality are core values to More ❯
the delivery of the security roadmap and a continuous improvement model for security. Ensure Information Security controls are operating effectively. Ensure where gaps are identified that these have remediation plans agreed and delivered. Ensure annual Security Awareness tests are completed and provide visibility/status updates for these. Ensure effective Information Security Awareness campaigns are defined and delivered … such as Confused.com, Go Compare and Compare the Market, via our broker partners. What we offer in return? A collaborative and fast paced work environment Private medical health care plan 28 days annual leave plus of Bank Holidays and the ability to buy holiday A benefit scheme that offers discounts and cashback on shopping, restaurants, travel and more Life More ❯
Salford, Greater Manchester, North West, United Kingdom Hybrid / WFH Options
Gerrard White
the delivery of the security roadmap and a continuous improvement model for security. Ensure Information Security controls are operating effectively. Ensure where gaps are identified that these have remediation plans agreed and delivered. Ensure annual Security Awareness tests are completed and provide visibility/status updates for these. Ensure effective Information Security Awareness campaigns are defined and delivered … such as Confused.com, Go Compare and Compare the Market, via our broker partners. What we offer in return? A collaborative and fast paced work environment Private medical health care plan 28 days annual leave plus of Bank Holidays and the ability to buy holiday A benefit scheme that offers discounts and cashback on shopping, restaurants, travel and more Life More ❯
assessments using automated scanning tools, manual testing techniques, and security best practices to identify vulnerabilities in systems, networks, and applications Managing the lifecycle of vulnerabilities from discovery to remediation, including vulnerability triage, prioritisation, tracking, and reporting Analysing the impact and severity of identified vulnerabilities based on factors such as the likelihood of exploitation, potential impact on the organisation … and existing security controls Collaborating with system administrators, developers, and other stakeholders to develop and implement effective remediation plans to address identified vulnerabilities in a timely manner Working closely with IT teams to ensure that security patches and updates are applied promptly to mitigate known vulnerabilities and reduce the organisation's exposure to security risks Generating detailed vulnerability More ❯
to interpret regulatory requirements (ISO27001, GDPR, DPAs) and translate them into technical controls, policies and run books. Audit & pen test lead - Coordinate external auditors, manage evidence collection, track remediation tickets and present technical posture to stakeholders. Threat & vulnerability management - Run container image scanning (Snyk), dependency SBOM generation and orchestrate patch cycles across clusters. Incident readiness - Own on call …/CD, Terraform and security policies. Shadow DPO on open compliance items to build context. Within three months, you will Lead the next quarterly vulnerability scan and deliver remediation plan. Introduce SBOM + container image scanning gates to GitHub Actions. Publish updated incident response runbook and run a tabletop drill. Within six months, you will Own technical track … budgets) or chaos engineering. This likely won't be the right role if you Prefer narrowly scoped, siloed security roles. Are uncomfortable owning end to end delivery-from Terraform plan to audit evidence pack. Don't meet every single expectation? Studies have shown that women and people of colour are less likely to apply to jobs unless they meet More ❯
to interpret regulatory requirements (ISO27001, GDPR, DPAs) and translate them into technical controls, policies and run books. Audit & pen test lead - Coordinate external auditors, manage evidence collection, track remediation tickets and present technical posture to stakeholders. Threat & vulnerability management - Run container image scanning (Snyk), dependency SBOM generation and orchestrate patch cycles across clusters. Incident readiness - Own on call …/CD, Terraform and security policies. Shadow DPO on open compliance items to build context. Within three months, you will Lead the next quarterly vulnerability scan and deliver remediation plan. Introduce SBOM + container image scanning gates to GitHub Actions. Publish updated incident response runbook and run a tabletop drill. Within six months, you will Own technical track … budgets) or chaos engineering. This likely won't be the right role if you Prefer narrowly scoped, siloed security roles. Are uncomfortable owning end to end delivery-from Terraform plan to audit evidence pack. Don't meet every single expectation? Studies have shown that women and people of colour are less likely to apply to jobs unless they meet More ❯
conducting a time limited review of the banks backlog of model findings and issues. The Business Analyst will be working with Model Owners and developers to consolidate into a plan of remediation actions to be reviewed and signed off by the banks Independent Model Validation and Model Risk governance teams. Key Experience Required: Strong analytical and organisational … skills Experience reviewing and consolidating model findings/issues Ability to work with Model Owners & Developers Familiarity with remediationplanning and validation processes Understanding of model governance frameworks More ❯
KPIs or CSATs to evidence high quality of service delivery Contribute to SLA breach monitoring, engaging with the Queue Manager and applying appropriate interventions to avoid breaches where needed Plan and execute Return-to-green plans where Managed Services are not operating within agreed parameters Prepare for and attend the Monthly Service Reviews, capturing actions and items relevant to … Microsoft Office suite, including Project and Visio Proven continuous improvement experience from a similar role, including project management Understanding quality service standards and applicable metrics Experience of designing remediation plans to address productivity and efficiency issues, and track record of following through to ensure closure Previous Managed Service Provider experience Knowledge on any cloud support projects will be More ❯
KPIs or CSATs to evidence high quality of service delivery Contribute to SLA Breach Monitoring engaging with the Queue Manager and applying appropriate interventions to avoid breaches where needed Plan and execute Return-to-green plans where Managed Services are not operating within agreed parameters Prepare for and attend the Monthly Service Reviews, capturing actions and items relevant to … Microsoft Office suite, including Project and Visio Proven continuous improvement experience from a similar role, including project management Understanding quality service standards and applicable metrics Experience of designing remediation plans to address productivity and efficiency issues, and track record of following through to ensure closure Previous Managed Service Provider experience Knowledge on any cloud support projects will be More ❯