Risk Assessment Jobs in Scotland

1 to 25 of 75 Risk Assessment Jobs in Scotland

Threat and Vulnerability Analyst

Glasgow, Scotland, United Kingdom
University of Glasgow
subject matter expert to deliver threat reporting and agree technical remediation plans Work closely in collaboration with IT & peers/stakeholders to plan and deliver vulnerability remediation based on risk assessment and business risk profile Create and deliver usable metrics which visualise the overall vulnerability and risk trend as well as overall vulnerability management progress Troubleshoot More ❯
Posted:

Information Security Manager

Glasgow, Scotland, United Kingdom
City Facilities Management Holdings Ltd
days at 23:59 BST. The Vacancy POSITION OVERVIEW: This role sits within the 2nd Line of defence, where you will lead and support the business, managing cyber risk and information protection positions effectively. Protecting the business from security threats, by identifying risks and developing appropriate risk migration plans. Providing senior leadership with independent assurance of their cyber … risk and information protection posture. The role will work collaboratively with 1st Line cyber team to ensure business assurance plans are shared and the requirements of 2nd Line are understood. You will also take the lead in delivering a defined list of cyber assurance reviews, projects, and initiatives as well as achieving the cyber assurance and compliance related objectives. … You will also help shape the City cyber security strategy for data security, monitoring and reporting, risk and threat assessment, incident response, business continuity and disaster recovery. PRINCIPAL TASKS AND RESPONSIBILITIES Monitor & Review Contribute and maintain the current information security risk management framework, articulate risk in business terms, identify appropriate mitigation measures and drive their delivery More ❯
Posted:

Principal Security Architect

Edinburgh, Scotland, United Kingdom
Hybrid / WFH Options
Gespreksleider Jacobs
department. They lead the security engagement for all projects ensuring that the department's security design standards are adhered to. This challenging role incorporates aspects of security architecture, cyber risk management and cyber security policy. As a Principal Security Architect, you will also provide an 'out-reach' to advise on security requirements and solutions to enable technical teams to … DBT to identify new opportunities for exploiting emerging technologies and support the development of architectures, patterns and approaches to support their safe use in accordance with the department's risk appetites. At all times your goal is to help ensure delivery of systems that meet the desired business outcomes with security decisions and controls being proportionate to the risk appetite. You will build effective partnerships with diverse teams across multiple locations and technologies and effectively communicate security and risk implications across technical and non-technical stakeholders. You will manage the Security Architecture team, covering critical review architecture referencing NCSC (National Cyber Security Centre ) guidelines and to guide and mentor others throughout DBT. Main responsibilities You will: Interact More ❯
Posted:

Principal Security Consultant

Easter Howgate, Midlothian, United Kingdom
Hybrid / WFH Options
Leonardo UK Ltd
This is an exciting opportunity to be part of significant programmes, during which you will ensure that products meet the highest standards, in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger team of consultants, engineers and product domain specialists. Your work at Leonardo UK will see you … and detailed system and security designs as they pertain to the cyber domain. Decomposing cyber and security requirements down to the system control level. Conducting cyber and information security risk assessment activities including threat modelling, vulnerability analysis and analysis of mitigations. Scoping and managing security verification & validation activities and remedial action plans. Coordinating with product engineers, system architects More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Principal Security Consultant

Edinburgh, United Kingdom
Hybrid / WFH Options
leonardo company
This is an exciting opportunity to be part of significant programmes, during which you will ensure that products meet the highest standards, in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger team of consultants, engineers and product domain specialists. Your work at Leonardo UK will see you … and detailed system and security designs as they pertain to the cyber domain. Decomposing cyber and security requirements down to the system control level. Conducting cyber and information security risk assessment activities including threat modelling, vulnerability analysis and analysis of mitigations. Scoping and managing security verification & validation activities and remedial action plans. Coordinating with product engineers, system architects More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Risk & Compliance Analyst

Edinburgh, Scotland, United Kingdom
Skyscanner
Join to apply for the Risk & Compliance Analyst role at Skyscanner Join to apply for the Risk & Compliance Analyst role at Skyscanner We are looking for a Risk and Compliance Analyst to join our growing Risk and Compliance team and play a pivotal role in supporting the organisation's risk management and compliance efforts. This … across the business, including Legal, Finance, Security, and operational teams, to devise and support action plans that protect our business, increase trust, and ensure compliance with evolving governance and risk standards. As part of this role, you will play a key role in the implementation of a Governance, Risk, and Compliance (GRC) tool, which will centralise and streamline … our risk management and compliance processes. You will collaborate with cross-functional teams to define requirements, configure workflows, and ensure the tool aligns with organisational needs. This includes managing data migration, conducting testing to validate functionality, and providing training and support to end-users. By helping embed the GRC tool into our day-to-day operations, you will enable More ❯
Posted:

Cyber Security Consultant - GRC

Scotland, United Kingdom
Sword Group
foundations across platforms, data, and business applications. Our passion lies in using technology to solve business problems, working closely with clients to help achieve their goals. About the role: Risk Assessment: Assist in identifying, assessing, and prioritising risks across the organisation. Conduct risk assessments to evaluate the likelihood and potential impact of risks on business operations and … Identify and document control deficiencies, compliance gaps, and areas for improvement. Collaborate with stakeholders to develop actionable recommendations and corrective action plans. Documentation and Reporting: Maintain accurate documentation of risk assessments, compliance reviews, control testing activities, and remediation efforts. Prepare regular reports for management and stakeholders. Policy and Procedure Development: Assist in developing and maintaining risk management, compliance … and control-related policies, procedures, and guidelines, ensuring alignment with regulatory requirements and industry best practices. Vendor Risk Management Support: Assist in assessing and managing risks associated with third-party vendors and service providers, evaluating controls and contractual adherence. Continuous Improvement: Identify opportunities to enhance risk management, compliance, and control processes. Recommend and implement improvements to strengthen the More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Cyber Security Consultant - GRC

Aberdeen, Scotland, United Kingdom
Sword Group
foundations across platforms, data, and business applications. Our passion lies in using technology to solve business problems, working closely with clients to help achieve their goals. About the role: Risk Assessment: Assist in identifying, assessing, and prioritising risks across the organisation. Conduct risk assessments to evaluate the likelihood and potential impact of risks on business operations and … Identify and document control deficiencies, compliance gaps, and areas for improvement. Collaborate with stakeholders to develop actionable recommendations and corrective action plans. Documentation and Reporting: Maintain accurate documentation of risk assessments, compliance reviews, control testing activities, and remediation efforts. Prepare regular reports for management and stakeholders. Policy and Procedure Development: Assist in developing and maintaining risk management, compliance … and control-related policies, procedures, and guidelines, ensuring alignment with regulatory requirements and industry best practices. Vendor Risk Management Support: Assist in assessing and managing risks associated with third-party vendors and service providers, evaluating controls and contractual adherence. Continuous Improvement: Identify opportunities to enhance risk management, compliance, and control processes. Recommend and implement improvements to strengthen the More ❯
Posted:

Threat and Vulnerability Specialist

Glasgow, Scotland, United Kingdom
University of Glasgow
matter expert to deliver threat reporting and agree technical remediation plans. 7. Work closely in collaboration with IT & peers/stakeholders to plan and deliver vulnerability remediation based on risk assessment and business risk profile. 8. Create and deliver usable metrics which visualise the overall vulnerability and risk trend as well as overall vulnerability management progress. More ❯
Posted:

Senior Security Consultant

Easter Howgate, Midlothian, United Kingdom
Hybrid / WFH Options
Leonardo UK Ltd
This is an exciting opportunity to be part of significant programmes, during which you will ensure that products meet the highest standards, in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger team of consultants, engineers and product domain specialists. Your work at Leonardo UK will see you … and security designs as they pertain to the cyber domain. Experience working with cyber and security requirements down to the system control level. Experience conducting cyber and information security risk assessment activities including threat modelling, vulnerability analysis and analysis of mitigations. Scoping and managing security verification & validation activities and remedial action plans. Experience working with product engineers, system More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Senior Security Consultant

Edinburgh, Scotland, United Kingdom
Hybrid / WFH Options
Leonardo SpA
This is an exciting opportunity to be part of significant programmes, during which you will ensure that products meet the highest standards, in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger team of consultants, engineers and product domain specialists. Your work at Leonardo UK will see you … and security designs as they pertain to the cyber domain. Experience working with cyber and security requirements down to the system control level. Experience conducting cyber and information security risk assessment activities including threat modelling, vulnerability analysis and analysis of mitigations. Scoping and managing security verification & validation activities and remedial action plans. Experience working with product engineers, system More ❯
Posted:

Strategic Business Analyst

Edinburgh, Scotland, United Kingdom
M&GPrudential
ensuring alignment with corporate objectives. Support the Head of Strategy and Business Analysis with the development of comprehensive business cases, which include solution options, the cost/benefit case, risk assessment and indicative timelines. Support the Head of Strategy and Business Analysis with the documentation of detailed technology roadmaps and delivery plans to achieve the proposed strategies. Documentation More ❯
Posted:

Resilience Framework Lead

Glasgow, Scotland, United Kingdom
Barclays
to deliver a robust resilience control environment (this includes but is not limited to development of a framework for business response planning and scenario testing). Knowledge of operational risk management and control frameworks, e.g. operational resilience, crisis management, workforce and third-party resilience. Stakeholder management, interpersonal and communication skills e.g. engagement with industry contacts and heads of resilience. … Some other highly valued skills may include: Knowledge of operational resilience within the financial services sector. Experience of working within a risk and controls environment. Knowledge of operational resilience regulatory requirements. This role will be based in Glasgow or Knutsford. Purpose of the role To assess the integrity and effectiveness of the bank's internal control framework to support … the mitigation of risk and protection of the bank's operational, financial, and reputational risk. Accountabilities Collaboration with various stakeholders across the bank and business units to improve overall control effectiveness through detailed documentation of control assessments, procedures, and findings. Identification and investigation of potential weaknesses and issues within internal controls to promote continuous improvement and risk mitigation More ❯
Posted:

Principal Engineer- Product Safety

Glasgow
BAE Systems
commensurate with skills and experience What you'll be doing: Planning, execution and reporting or product safety activities Process facilitation and specialist process guidance for HazID, analysis and risk management Defining the safety argument and articulation of the safety case Management of the hazard log, information set and assurance evidence Specific analysis in support of the risk assessment Taking responsibility for product safety assessment against major subsystems or key complex technologies Your Skills and Experiences Essential: Practitioner knowledge and hands on experience of the HazID processes e.g. Functional Failure Analysis, hazard assessment and risk management. Experience leading a technical team Hands on experience creating a safety argument for a complex product Strong communication and … processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These More ❯
Employment Type: Permanent
Posted:

Information Security GRC Specialist

Moodiesburn, Scotland, United Kingdom
SARIA Food & Pharma
to the development, implementation and maintenance of internal governance frameworks, including policies, standards and procedures Maintaining compliance with relevant laws, regulations and industry standards (e.g. GDPR), through collaboration with risk owners in Legal, HR and other relevant departments Monitoring and reporting on the ongoing performance and effectiveness of the divisional ISMS, including the development and tracking of appropriate KPIs … Audit team on the development, implementation and operation of ITGCs Supporting the implementation of ISO27001 controls and perform regular control audits to monitor compliance Developing and managing a security risk framework, aligning with the enterprise risk management approach Coordinating the performance of regular business impact assessments (BIAs) and the recording of results and updates Contributing to the design … and implementation of information security process and control improvements Mentoring other members of the Information security team and promote risk management best practices across IT Supporting the development and delivery of compliance training and awareness, fostering a culture of risk awareness and accountability across the organisation Providing advice to stakeholders on IT risk and compliance topics About More ❯
Posted:

Information Security GRC Specialist

Moodiesburn, North Lanarkshire, UK
SARIA Food & Pharma
to the development, implementation and maintenance of internal governance frameworks, including policies, standards and procedures Maintaining compliance with relevant laws, regulations and industry standards (e.g. GDPR), through collaboration with risk owners in Legal, HR and other relevant departments Monitoring and reporting on the ongoing performance and effectiveness of the divisional ISMS, including the development and tracking of appropriate KPIs … Audit team on the development, implementation and operation of ITGCs Supporting the implementation of ISO27001 controls and perform regular control audits to monitor compliance Developing and managing a security risk framework, aligning with the enterprise risk management approach Coordinating the performance of regular business impact assessments (BIAs) and the recording of results and updates Contributing to the design … and implementation of information security process and control improvements Mentoring other members of the Information security team and promote risk management best practices across IT Supporting the development and delivery of compliance training and awareness, fostering a culture of risk awareness and accountability across the organisation Providing advice to stakeholders on IT risk and compliance topics About More ❯
Posted:

Consultant / Senior Consultant - Analytics & Insights

Glasgow, Scotland, United Kingdom
Hybrid / WFH Options
Capgemini
using frontend BI tools to create dashboards and interactive visual reports such as Power BI, Tableau, Qlik, Looker etc. Experience in UX design, requirements gathering, data-driven decision-making, risk assessment, KPI framework development, or value tracking and value analysis Experience in ingestion, integration, data engineering, data quality and observability, dataset identification Experience in high-level architecture, solution More ❯
Posted:

Project Manager

Glasgow, Scotland, United Kingdom
University of Glasgow
strengthen relationships with the commercial partner, providing both strategic oversight and operational management of the project. Reporting to Professor Stefan Siebert, the post holder will lead on project planning, risk assessment, and coordination of multidisciplinary teams. They will also support broader University partnership activities as required. Team members will include: amongst others, Clinical research fellows, Study nurses, Laboratory More ❯
Posted:

Applied AI/ML Software Engineer III - Risk Technology

Glasgow, Scotland, United Kingdom
ZipRecruiter
Description Job Description We have an exciting and rewarding opportunity for you to take your AI/ML career to the next level while making a significant impact on risk technology solutions. As an Applied AI/ML Software Engineer III at JPMorgan Chase within the Risk Technology team, you serve as a key contributor in researching, developing … and implementing innovative Generative AI solutions that transform our risk assessment capabilities. You are responsible for turning cutting-edge AI research into practical applications that enhance operational efficiencies and integrate with our existing risk calculation frameworks, supporting the firm's business objectives in an ever-evolving technological landscape. Our Risk Technology team relies on innovative thinkers … like you to develop cutting-edge AI solutions that enhance our risk assessment and management capabilities across our network. Your efforts will directly impact how we identify, measure, and mitigate risks across all divisions of JPMorgan Chase. You'll be part of a forward-thinking team specifically built to explore and implement emerging AI technologies that address complex More ❯
Posted:

Global Data Protection Officer

Edinburgh, United Kingdom
FNZ (UK) Ltd
Officer Apply locations London - United Kingdom, Edinburgh WRS - United Kingdom Time type: Full time Posted on: Posted 4 Days Ago Job requisition id: REQ-13864 Role Description The Global Risk and Compliance division (GR&C) exists to enable the FNZ Group to safely achieve its strategic objectives and protect value; to support the growth and delivery of services and … regulators, and stakeholders across regions and business units to align data privacy strategies with the firm's strategic objectives and evolving regulatory landscape. This role will collaborate with governance, risk, and compliance (GRC) specialists and analytics experts to ensure effective oversight, reporting, and continuous improvement of the firm's data protection position. Reporting directly to the Group Enterprise Compliance … and standards, ensuring alignment with local data privacy regulatory obligations and industry best practices across Europe, the UK, North America, and APAC. Establish privacy governance objectives and key privacy risk indicators (KPIs/KRIs) that align with the firm's risk appetite and compliance requirements. Implement systems and processes to monitor, identify, and mitigate data protection risks across More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Assistant Asset Engineer

Glasgow, Scotland, United Kingdom
Network Rail
skills alongside a flexible and enthusiastic approach to working within a busy team. About The Role (External) Here are some of the duties your role will include: - Evaluate and risk assess examination reports for a varied asset portfolio in accordance with functional policy, systems and standards, to ensure their continued safety and performance. Determine, specify and prioritise actions to … address defects, risks, comments and other issues raised in these reports, in accordance with standards and functional policy, for inclusion in work plans. Schedule examinations, inspections, monitoring and assessment of assets. Oversee the development, implementation and handover of prioritised maintenance work items to enable the required outputs to be realised. Produce route specific and asset type management regimes. Develop … and any changes are agreed. Assist with the approval in principle of designs and support acceptance of detailed design certification. Determine and implement mitigation measures required following the structural assessment of the asset or where proposed management actions are deferred. Engage with internal and external stakeholders to ensure the optimal risk management solution is identified and implemented. Determine More ❯
Posted:

Senior/Principal Cable Route Engineer

Glasgow, Scotland, United Kingdom
Hybrid / WFH Options
Snc-Lavalin
to our clients’ offshore cable projects. You will act as Technical Lead for our offshore cable routing scopes of work, leading GIS-based route analysis and offshore Cable Burial Risk Assessment (CBRA) scopes of work. This will include mentoring of junior members of staff in these activities. You will take the lead in developing AtkinsRéalis’ offshore cable routing … enhancement activities. Acting as a champion for offshore cable routing within AtkinsRéalis’ Marine Geoscience team. Providing technical input to bids for subsea cable routing scopes. Input to Cable Burial Risk Assessments (CBRA) and Depth of Lowering Assessments. Routing of offshore and onshore cables using GIS-based analysis. GIS-based analysis of geophysical, geospatial, and geotechnical data and data management. … working as part of a multi-disciplinary team. Experience of offshore cable routing using ArcGIS, Makai Plan, or AutoCAD. Experience in analyzing geotechnical and geospatial data for Cable Burial Risk Assessments (CBRA), or Depth of Lowering (DoL) assessments. Excellent interpersonal and technical skills and the ability to work independently or as part of a team on subsea cables projects. More ❯
Posted:

Senior Information Security Analyst (Third-Party Due Diligence)

Edinburgh, Scotland, United Kingdom
Transamerica Corporation
Assisting with the review of responses to more complex client security onboarding and annual due diligence security reviews. Responding to business requests relating to Information Security. Supporting with security risk assessments. Assisting with development of Information Security procedures and processes. Maintaining currency with work undertaken by the overall InfoSec Team to understand how changes to systems, servers and applications … Security (Data Protection Act, Computer Misuse Act, SOX, FSA regulations) An up to date and current knowledge of Information Security; current business and industry issues and initiatives. Experience of risk assessment in a business environment, understanding and determining business impact, determining risk from vulnerability, recommending appropriate and cost-effective controls. Desirable - A relevant degree or qualification. Will More ❯
Posted:

Enterprise Security Architect

Edinburgh, Midlothian, Scotland, United Kingdom
HMRC
to this initiative and our collective success. Now is a great time to join us as we establish a team of outstanding people in the fields of Security Architecture, Risk Assessment and Testing who will create and run these new and improved technology services. This is a chance to work on services that matter and affect the lives … excellence, working collaboratively across government to deliver holistic, customer centric cyber security services. This includes consultancy support that continually evolves to emerging technologies and the ever-changing threat and risk landscape. It is an exciting time to be part of our active and encouraging Cybersecurity and Architecture communities, working within HMRC and across HMG. As an Enterprise Security Architect … and encouraging Cyber Security and Architecture communities, within HMRC and across government. You will collaborate and play a leading role with senior business and technical partners, to deliver appropriate risk based technical security advice and guidance.This enables the secure delivery of His Majestys Government solutions and services. You will engage at a strategic level, influencing policy and setting direction More ❯
Employment Type: Permanent
Salary: £80,000
Posted:

Project Delivery Manager

Helensburgh, Scotland, United Kingdom
ASVA: Association of Scottish Visitor Attractions
platform (SharePoint) ensuring all records and documentation is up to date. • Responsible for liaising with internal Legal and Procurement Teams on production of contract documentation including appointment of contractors, Risk Assessment Method Statements and other contractor H&S, legal and insurance documentation • Maintain a project task tracker, risk and issues log. • Deputise for the Project Director in More ❯
Posted:
Risk Assessment
Scotland
Median
£51,645