Role Purpose NCC Group provides Information Assurance consultancy to help companies protect critical systems and information. We do this by defining security strategies, developing policies, conducting security maturity and risk assessments and implementing security solutions. We also provide security staff augmentation to clients so that our consultants may occupy security roles within the client environment in the short, medium … or long term. Our core consulting and implementation services include: Strategy & transformation On-demand virtual roles Data discovery and mapping Risk advisory and assurance Continuity/Resilience Data privacy and GDPR ISO 27001 & NIST CSF Supplier assurance PCI, PA & P2PE Incident response planning Card production audits Cyber security review SOC advisory & implementation XDR consulting & implementation Alongside our core services … we have a range of bespoke services to help organisations protect their systems and information: Risk Assessments Security Architecture Review Information Security Awareness and Training Programmes Information Security Policy Development Security Transformation Programmes We have a fantastic new opportunity to join our Consulting & Implementation division for a Senior Consultant. The ideal candidate will have commercial experience within the information More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Deloitte LLP
following: Shape the development of technology control management including scoping, development of and testing ServiceNow tools for ITRM processes in DT to allow for an effective, efficient and adaptable risk governance capability and contribute to its continuous improvement. Direct control development across DT, driving a consistent approach utilising the IRM capabilities within ServiceNow. Deliver the DT control library architecture … and control data management. Secure commitment from member firms and stakeholders in the global firm to participate in the Technology Standards and Maturity Assessment with the objective to assess the member firm's overall IT capability/maturity and to help them establish their own priorities. Keep abreast of new and emerging technologies being deployed and ensure riskassessment processes are appropriately applied and advise on decisions with technology risk impacts as new activities and other change management/transformational initiatives. Leverage available technical resources/tools to research; expand technology risk knowledge to enhance work product, to remain up to date on member firms and line of businesses hot topics while sharing the More ❯
Manchester, England, United Kingdom Hybrid / WFH Options
Deloitte LLP
following: Shape the development of technology control management including scoping, development of and testing ServiceNow tools for ITRM processes in DT to allow for an effective, efficient and adaptable risk governance capability and contribute to its continuous improvement. Direct control development across DT, driving a consistent approach utilising the IRM capabilities within ServiceNow. Deliver the DT control library architecture … and control data management. Secure commitment from member firms and stakeholders in the global firm to participate in the Technology Standards and Maturity Assessment with the objective to assess the member firm’s overall IT capability/maturity and to help them establish their own priorities. Keep abreast of new and emerging technologies being deployed and ensure riskassessment processes are appropriately applied and advise on decisions with technology risk impacts as new activities and other change management/transformational initiatives. Leverage available technical resources/tools to research; expand technology risk knowledge to enhance work product, to remain up to date on member firms and line of businesses hot topics while sharing the More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Deloitte LLP
audits. Understand technology controls, testing of controls, and supporting evidence to meet SOC 2 Trust Service Criteria. Understand technology controls that impact on-premises and cloud technology, operational risk to the Deloitte Technology organization as well as related laws, regulations, and industry standards, specifically related to internal and cloud technology solutions. Assess technology and operational risks related to internal … Manage audit findings; identify and track remediation activities to meet target dates for closure, and track/report progress. Work with the appropriate Information Security, Office of General Counsel, Risk Management, and leadership to determine scope of SOC 2 audits. Develop and recommend appropriate information security policies, standards, procedures, checklists, and guidelines using generally recognized security concepts tailored to … accounting or equivalent educational or professional experience and/or qualifications. Proven directly related experience in the following: managing information technology audits, assessments, remediation management, creating, leading, and managing riskassessment programs. Experience with SSAE 18 SOC 2 and various other industry standard frameworks such as: NIST, HITRUST, CSA, CCM. Experience leading IT internal audit, external audits, and More ❯
Manchester, England, United Kingdom Hybrid / WFH Options
Deloitte LLP
audits. Understand technology controls, testing of controls, and supporting evidence to meet SOC 2 Trust Service Criteria. Understand technology controls that impact on-premises and cloud technology, operational risk to the Deloitte Technology organization as well as related laws, regulations, and industry standards, specifically related to internal and cloud technology solutions. Assess technology and operational risks related to internal … Manage audit findings; identify and track remediation activities to meet target dates for closure, and track/report progress. Work with the appropriate Information Security, Office of General Counsel, Risk Management, and leadership to determine scope of SOC 2 audits. Develop and recommend appropriate information security policies, standards, procedures, checklists, and guidelines using generally recognized security concepts tailored to … accounting or equivalent educational or professional experience and/or qualifications. Proven directly related experience in the following: managing information technology audits, assessments, remediation management, creating, leading, and managing riskassessment programs. Experience with SSAE 18 SOC 2 and various other industry standard frameworks such as: NIST, HITRUST, CSA, CCM. Experience leading IT internal audit, external audits, and More ❯
Salford, England, United Kingdom Hybrid / WFH Options
Department for Business and Trade
Head of Cyber Governance, Risk and Compliance Join to apply for the Head of Cyber Governance, Risk and Compliance role at Department for Business and Trade Head of Cyber Governance, Risk and Compliance 1 day ago Be among the first 25 applicants Join to apply for the Head of Cyber Governance, Risk and Compliance role at … of the global economy! The Department for Business and Trade ("DBT") and Inspire People are partnering together to bring you an exciting opportunity for the Head of Cyber Governance, Risk and Compliance playing a pivotal role in shaping the success of the Cyber function and service. Salary between £71,738 to £93,864 (including allowances) plus excellent Civil Service … on location and technical skills as assessed at interview. Flexible, hybrid working from London, Cardiff, Darlington, Belfast, Birmingham, Salford and Edinburgh. About the role As Head of Cyber Governance, Risk and Compliance (GRC) you will be playing a pivotal role in shaping the success of the Cyber function and service by ensuring that cyber security risks are monitored and More ❯
our infrastructure. Oversee the deployment of security solutions, working closely with internal teams to strengthen our defences. Collaborate with external security partners to ensure high-quality support and proactive risk management. Regularly report on security metrics and provide insights to senior management. Conduct thorough risk assessments and ensure compliance with industry standards and regulatory requirements. What We’re … approach. Key qualifications include: Professional certification such as CISSP, CISM, or similar. Significant experience in cybersecurity management, ideally within a medium-to-large organisation. Extensive knowledge of security technologies, riskassessment, and vulnerability management. Hands-on experience with security monitoring tools and incident response. Familiarity with compliance standards such as ISO 27001, GDPR, and NIST frameworks. Strong analytical More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Capgemini
role Vulnerability Management Understand the Vulnerability Management end to end process and reporting and Have working experience of Vulnerability Management tools Conduct vulnerability analysis and create impact assessments including riskassessment of vulnerability reports and impact risks to service Collate conclusions and recommendations and Identify and communicate current and emerging information security threats Assess current technology architecture for … of your working reality. We have built an inclusive and welcoming environment, for everyone. Your skills and experience Strong understanding of vulnerability management frameworks and tools. Experience in conducting risk assessments and interpreting vulnerability reports. Familiarity with audit processes, compliance standards, and security governance. Skilled in delivering security training and awareness programs. Effective communicator with the ability to present More ❯
Manchester, England, United Kingdom Hybrid / WFH Options
Capgemini
role Vulnerability Management Understand the Vulnerability Management end to end process and reporting and Have working experience of Vulnerability Management tools Conduct vulnerability analysis and create impact assessments including riskassessment of vulnerability reports and impact risks to service Collate conclusions and recommendations and Identify and communicate current and emerging information security threats Assess current technology architecture for … of your working reality. We have built an inclusive and welcoming environment, for everyone. Your skills and experience Strong understanding of vulnerability management frameworks and tools. Experience in conducting risk assessments and interpreting vulnerability reports. Familiarity with audit processes, compliance standards, and security governance. Skilled in delivering security training and awareness programs. Effective communicator with the ability to present More ❯
Manchester, England, United Kingdom Hybrid / WFH Options
Penguin Recruitment
and uphold project quality across all stages of delivery. Key Responsibilities Ensure projects meet PAS 2035 requirements and demonstrate a working knowledge of PAS 2030. Oversee retrofit works from assessment through to implementation. Review and assure the quality of Retrofit Assessments and Designs. Provide expert input on improvement strategies and survey needs. Conduct desktop reviews and site visits, producing … support CPD initiatives. Contribute to research, knowledge-sharing, and marketing efforts. Essential Qualifications & Skills BSc (Hons) in Building Surveying (or similar discipline) Level 5 Diploma in Retrofit Coordination and RiskAssessment Level 3 Award in Energy Efficiency and Retrofit of Traditional Buildings Strong knowledge of retrofit standards and associated risk management Excellent interpersonal and communication skills Proven More ❯
Developing a framework for governance as well as developing Cyber Security and Information Security Management systems Analysing Cyber Security controls, commenting on an architecture proposal and conducting Threat and Risk assessments Cyber Security requirements analysis and tailoring them to the client’s needs Understanding business and technical requirements and translating them into tangible actions What we will be looking … ideally in Automotive/Road or Rail Team leadership skills and early career professionals development Government Frameworks Writing proposals in collaboration with the sales team Threat modelling, Vulnerability analysis, Risk matrix modelling Security Policy and governance Cloud Security including OT in the Cloud Incident Management frameworks, Security incident analysis, digital forensics, crisis management, SOC operations and supporting tools We … are looking for someone who has sound practical knowledge on the use and application of riskassessment methodologies in systems and software development (including Agile and ITIL process and V-model) and combining them for optimal solutions. If your career has given you the opportunity to author and publish technical reports, advise clients, work with formal security frameworks More ❯
training when available, supported by Capita. What we’re looking for: Technical Knowledge: Understanding of energy systems, building materials, and construction techniques Level 5 Diploma in Retrofit Coordination and Risk Management together with the necessary skills and knowledge to manage retrofit projects in compliance with the PAS 2035 standard. You should hold at least 12 credits at Level … in a built environment subject You need to demonstrate competencies in areas such as project management and riskassessment, as defined by PAS 2035 . A minimum of 2 years of experience working on retrofit or energy efficiency projects is required in non-domestic retrofitting or energy audits to an approved standard. About Capita Public Service Capita Public More ❯
your projects are delivered to budget, programme, technical standards and legal requirements. What you need to succeed: Knowledge of, and experience in highway design, drainage strategy and design, flood riskassessment and management, utility design and planning as well as a good working knowledge of the Development Industry An appreciation of hydraulics, hydrology, geotechnics and building structures is More ❯
your projects are delivered to budget, programme, technical standards and legal requirements. What you need to succeed: Knowledge of, and experience in highway design, drainage strategy and design, flood riskassessment and management, utility design and planning as well as a good working knowledge of the Development Industry An appreciation of hydraulics, hydrology, geotechnics and building structures is More ❯
Assistant Infrastructure Engineer to join their Civil Team based in Manchester. This exciting role will offer candidates the opportunity to join a friendly team of Engineers to complete Flood Risk, Environmental and Drainage Projects for Residential Development Projects, Distilleries, Energy Plants, Retail and Healthcare Projects for Housing Developers, Local Authorities and Private Sector Clients. As an Assistant Infrastructure Engineer … you will be required to complete technical work including; -Flood Risk Assessments for flood zone 1,2 and 3. -Flood Consequence Assessments. -Access road and pavement design. -Drainage Strategy for Planning Applications and Drainage Design using Microdrainage and Causeway Flow. This role offers a competitive salary, substantial benefits package, company benefits and career progression. It is essential that applicants … design or drainage strategies and design using Microdrainage or Flow. It is essential for applicants to reside locally and have a keen interest in Civil Engineering, Road Designs, Flood Risk Assessments or Flood Consequence Assessments. If this role is of interest to you or if you are searching for other roles relating to Drainage Engineering/Flood RiskMore ❯
Manchester, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
a global multi-billion-pound business in Belfast to seek a Vulnerability and Penetration Testing Engineer for their Belfast Centre team. The role involves providing security architecture, vulnerability, and risk assessment. We are open to candidates who may be interested in working on a remote contract with occasional trips to the Belfast Head Office. Responsibilities: Thoroughly evaluate proposed and … current solutions to ensure compliance with established standards for secure system design, including ISMS Policy, client contracts, regulatory expectations, and professional obligations. Architect, implement, and support assessment solutions necessary for protecting the firm's assets. Continuously evaluate relevant products, tools, scripts, and techniques to improve assessment capabilities. 3+ years in a pen test role. Excellent knowledge of Vulnerability … and best practices, including WhiteHat/Ethical Hacking requirements. Experience with automated tools such as Nessus, Appscan, Burp Suite, Nipper, and Trustwave. Deep understanding of the difference between vulnerability assessment and penetration testing regarding scope, objectives, and deliverables. Working knowledge of information security frameworks such as ISO27001, NIST, and CIS. If this opportunity interests you, apply today. Note: No More ❯
Manchester, England, United Kingdom Hybrid / WFH Options
Baily Garner
maintaining the highest standards of technical quality and client service. Key Responsibilities: Ensure compliance with PAS 2035 and understanding of PAS 2030 standards. Oversee and manage retrofit projects from assessment to delivery. Review and quality-check Retrofit Assessments and Designs. Provide expert advice on improvement measures and additional survey requirements. Conduct desktop analysis and site visits, producing detailed reports. … prepare minutes, and support CPD activities. Contribute to research, marketing, and knowledge-sharing initiatives. Essential Qualifications & Skills: BSc (Hons) in Building Surveying Level 5 Diploma in Retrofit Coordination and RiskAssessment Level 3 Award in Energy Efficiency and Retrofit of Traditional Buildings Strong understanding of retrofit standards and riskassessment Excellent communication and client care skills More ❯
Fluent in English - both written and spoken Demonstrable experience as a Security Architect or similar role Strong knowledge of security standards, protocols, and best practices Experience with threat modelling, riskassessment, and incident response Familiarity with security tools (e.g., Snyk, OWASP ZAP) Excellent communication and collaboration skills Self-learner and ability to execute tasks without supervision Ability to … maintain the highest level of professionalism Activities Assess and design secure system architectures Define and enforce security policies and best practices Conduct threat modelling and risk assessments Collaborate with development teams to ensure secure coding practices Review and recommend security tools and technologies Respond to security incidents and perform root cause analysis Acquired Experiences and Demonstrable Skills Potential skills More ❯
reliability Collaborate with product development, manufacturing, and design teams to debug and improve products Develop and maintain technical documentation related to quality and reliability Create predictive models for reliability riskassessment Conduct supplier audits of manufacturing processes and quality systems when required Provide training and support to teams on reliability and quality standards Experience Bachelor's degree in More ❯
to a high standard Highly experienced with relevant software and similar analytical tools. Good ability to check work produced by others Has a very good understanding of CDM and risk assessment. Substantially experienced in the management and communication of hazards and risks on projects and ensures appropriate risk mitigation and transference has been applied. Capable of acting as More ❯
categories that we operate in. Over time you will become a Subject Matter Expert in our products (if not already). The Spice and Herb sector is considered high risk by many customers and requires that supply chain assurance and integrity are the main priorities. Pulse flours are an exciting and emerging category being used in many more applications. … increase the efficiency and efficacy of systems and ways of working. Qualifications: Degree (ideally in a scientific subject) Food manufacturing HACCP level 3 or 4 VACCP/raw material riskassessment qualification Experience: 5+ years in a technical leadership position in the food industry, with specific experience of handling supplier and customer technical information. High level of regulatory More ❯
categories that we operate in. Over time you will become a Subject Matter Expert in our products (if not already). The Spice and Herb sector is considered high risk by many customers and requires that supply chain assurance and integrity are the main priorities. Pulse flours are an exciting and emerging category being used in many more applications. … increase the efficiency and efficacy of systems and ways of working. Qualifications: Degree (ideally in a scientific subject) Food manufacturing HACCP level 3 or 4 VACCP/raw material riskassessment qualification Experience: 5+ years in a technical leadership position in the food industry, with specific experience of handling supplier and customer technical information. High level of regulatory More ❯
issues. Engineering excellence is to be supported by: Review compliance with appropriate standards. (NR/L2/CIV/003, NR/L3/CIV/0063 etc) Use risk ID and evaluation methods (e.g. HAZOP, QRA etc.), as suitable, to evaluate and compare options. Assure (or undertake where applicable) the development of the selected single option. Assure (or … associated with asset protection on third party, major and minor projects, always with the customer in mind. Shall have a sound understanding of network rail's requirements regarding the riskassessment process including CSM-RA. Mace is an inclusive employer and welcomes interest from a diverse range of candidates. Even if you feel you do not fulfil all More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Mace Group
issues. Engineering excellence is to be supported by: Review compliance with appropriate standards. (NR/L2/CIV/003, NR/L3/CIV/0063 etc) Use risk ID and evaluation methods (e.g. HAZOP, QRA etc.), as suitable, to evaluate and compare options. Assure (or undertake where applicable) the development of the selected single option. Assure (or … associated with asset protection on third party, major and minor projects, always with the customer in mind. Shall have a sound understanding of network rail's requirements regarding the riskassessment process including CSM-RA. Mace is an inclusive employer and welcomes interest from a diverse range of candidates. Even if you feel you do not fulfil all More ❯