subject matter expert to deliver threat reporting and agree technical remediation plans Work closely in collaboration with IT & peers/stakeholders to plan and deliver vulnerability remediation based on riskassessment and business risk profile Create and deliver usable metrics which visualise the overall vulnerability and risk trend as well as overall vulnerability management progress Troubleshoot More ❯
days at 23:59 BST. The Vacancy POSITION OVERVIEW: This role sits within the 2nd Line of defence, where you will lead and support the business, managing cyber risk and information protection positions effectively. Protecting the business from security threats, by identifying risks and developing appropriate risk migration plans. Providing senior leadership with independent assurance of their cyber … risk and information protection posture. The role will work collaboratively with 1st Line cyber team to ensure business assurance plans are shared and the requirements of 2nd Line are understood. You will also take the lead in delivering a defined list of cyber assurance reviews, projects, and initiatives as well as achieving the cyber assurance and compliance related objectives. … You will also help shape the City cyber security strategy for data security, monitoring and reporting, risk and threat assessment, incident response, business continuity and disaster recovery. PRINCIPAL TASKS AND RESPONSIBILITIES Monitor & Review Contribute and maintain the current information security risk management framework, articulate risk in business terms, identify appropriate mitigation measures and drive their delivery More ❯
Edinburgh, Scotland, United Kingdom Hybrid / WFH Options
Gespreksleider Jacobs
department. They lead the security engagement for all projects ensuring that the department's security design standards are adhered to. This challenging role incorporates aspects of security architecture, cyber risk management and cyber security policy. As a Principal Security Architect, you will also provide an 'out-reach' to advise on security requirements and solutions to enable technical teams to … DBT to identify new opportunities for exploiting emerging technologies and support the development of architectures, patterns and approaches to support their safe use in accordance with the department's risk appetites. At all times your goal is to help ensure delivery of systems that meet the desired business outcomes with security decisions and controls being proportionate to the risk appetite. You will build effective partnerships with diverse teams across multiple locations and technologies and effectively communicate security and risk implications across technical and non-technical stakeholders. You will manage the Security Architecture team, covering critical review architecture referencing NCSC (National Cyber Security Centre ) guidelines and to guide and mentor others throughout DBT. Main responsibilities You will: Interact More ❯
Easter Howgate, Midlothian, United Kingdom Hybrid / WFH Options
Leonardo UK Ltd
This is an exciting opportunity to be part of significant programmes, during which you will ensure that products meet the highest standards, in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger team of consultants, engineers and product domain specialists. Your work at Leonardo UK will see you … and detailed system and security designs as they pertain to the cyber domain. Decomposing cyber and security requirements down to the system control level. Conducting cyber and information security riskassessment activities including threat modelling, vulnerability analysis and analysis of mitigations. Scoping and managing security verification & validation activities and remedial action plans. Coordinating with product engineers, system architects More ❯
This is an exciting opportunity to be part of significant programmes, during which you will ensure that products meet the highest standards, in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger team of consultants, engineers and product domain specialists. Your work at Leonardo UK will see you … and detailed system and security designs as they pertain to the cyber domain. Decomposing cyber and security requirements down to the system control level. Conducting cyber and information security riskassessment activities including threat modelling, vulnerability analysis and analysis of mitigations. Scoping and managing security verification & validation activities and remedial action plans. Coordinating with product engineers, system architects More ❯
Join to apply for the Risk & Compliance Analyst role at Skyscanner Join to apply for the Risk & Compliance Analyst role at Skyscanner We are looking for a Risk and Compliance Analyst to join our growing Risk and Compliance team and play a pivotal role in supporting the organisation's risk management and compliance efforts. This … across the business, including Legal, Finance, Security, and operational teams, to devise and support action plans that protect our business, increase trust, and ensure compliance with evolving governance and risk standards. As part of this role, you will play a key role in the implementation of a Governance, Risk, and Compliance (GRC) tool, which will centralise and streamline … our risk management and compliance processes. You will collaborate with cross-functional teams to define requirements, configure workflows, and ensure the tool aligns with organisational needs. This includes managing data migration, conducting testing to validate functionality, and providing training and support to end-users. By helping embed the GRC tool into our day-to-day operations, you will enable More ❯
foundations across platforms, data, and business applications. Our passion lies in using technology to solve business problems, working closely with clients to help achieve their goals. About the role: RiskAssessment: Assist in identifying, assessing, and prioritising risks across the organisation. Conduct risk assessments to evaluate the likelihood and potential impact of risks on business operations and … Identify and document control deficiencies, compliance gaps, and areas for improvement. Collaborate with stakeholders to develop actionable recommendations and corrective action plans. Documentation and Reporting: Maintain accurate documentation of risk assessments, compliance reviews, control testing activities, and remediation efforts. Prepare regular reports for management and stakeholders. Policy and Procedure Development: Assist in developing and maintaining risk management, compliance … and control-related policies, procedures, and guidelines, ensuring alignment with regulatory requirements and industry best practices. Vendor Risk Management Support: Assist in assessing and managing risks associated with third-party vendors and service providers, evaluating controls and contractual adherence. Continuous Improvement: Identify opportunities to enhance risk management, compliance, and control processes. Recommend and implement improvements to strengthen the More ❯
foundations across platforms, data, and business applications. Our passion lies in using technology to solve business problems, working closely with clients to help achieve their goals. About the role: RiskAssessment: Assist in identifying, assessing, and prioritising risks across the organisation. Conduct risk assessments to evaluate the likelihood and potential impact of risks on business operations and … Identify and document control deficiencies, compliance gaps, and areas for improvement. Collaborate with stakeholders to develop actionable recommendations and corrective action plans. Documentation and Reporting: Maintain accurate documentation of risk assessments, compliance reviews, control testing activities, and remediation efforts. Prepare regular reports for management and stakeholders. Policy and Procedure Development: Assist in developing and maintaining risk management, compliance … and control-related policies, procedures, and guidelines, ensuring alignment with regulatory requirements and industry best practices. Vendor Risk Management Support: Assist in assessing and managing risks associated with third-party vendors and service providers, evaluating controls and contractual adherence. Continuous Improvement: Identify opportunities to enhance risk management, compliance, and control processes. Recommend and implement improvements to strengthen the More ❯
matter expert to deliver threat reporting and agree technical remediation plans. 7. Work closely in collaboration with IT & peers/stakeholders to plan and deliver vulnerability remediation based on riskassessment and business risk profile. 8. Create and deliver usable metrics which visualise the overall vulnerability and risk trend as well as overall vulnerability management progress. More ❯
Easter Howgate, Midlothian, United Kingdom Hybrid / WFH Options
Leonardo UK Ltd
This is an exciting opportunity to be part of significant programmes, during which you will ensure that products meet the highest standards, in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger team of consultants, engineers and product domain specialists. Your work at Leonardo UK will see you … and security designs as they pertain to the cyber domain. Experience working with cyber and security requirements down to the system control level. Experience conducting cyber and information security riskassessment activities including threat modelling, vulnerability analysis and analysis of mitigations. Scoping and managing security verification & validation activities and remedial action plans. Experience working with product engineers, system More ❯
Edinburgh, Scotland, United Kingdom Hybrid / WFH Options
Leonardo SpA
This is an exciting opportunity to be part of significant programmes, during which you will ensure that products meet the highest standards, in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger team of consultants, engineers and product domain specialists. Your work at Leonardo UK will see you … and security designs as they pertain to the cyber domain. Experience working with cyber and security requirements down to the system control level. Experience conducting cyber and information security riskassessment activities including threat modelling, vulnerability analysis and analysis of mitigations. Scoping and managing security verification & validation activities and remedial action plans. Experience working with product engineers, system More ❯
ensuring alignment with corporate objectives. Support the Head of Strategy and Business Analysis with the development of comprehensive business cases, which include solution options, the cost/benefit case, riskassessment and indicative timelines. Support the Head of Strategy and Business Analysis with the documentation of detailed technology roadmaps and delivery plans to achieve the proposed strategies. Documentation More ❯
to deliver a robust resilience control environment (this includes but is not limited to development of a framework for business response planning and scenario testing). Knowledge of operational risk management and control frameworks, e.g. operational resilience, crisis management, workforce and third-party resilience. Stakeholder management, interpersonal and communication skills e.g. engagement with industry contacts and heads of resilience. … Some other highly valued skills may include: Knowledge of operational resilience within the financial services sector. Experience of working within a risk and controls environment. Knowledge of operational resilience regulatory requirements. This role will be based in Glasgow or Knutsford. Purpose of the role To assess the integrity and effectiveness of the bank's internal control framework to support … the mitigation of risk and protection of the bank's operational, financial, and reputational risk. Accountabilities Collaboration with various stakeholders across the bank and business units to improve overall control effectiveness through detailed documentation of control assessments, procedures, and findings. Identification and investigation of potential weaknesses and issues within internal controls to promote continuous improvement and risk mitigation More ❯
commensurate with skills and experience What you'll be doing: Planning, execution and reporting or product safety activities Process facilitation and specialist process guidance for HazID, analysis and risk management Defining the safety argument and articulation of the safety case Management of the hazard log, information set and assurance evidence Specific analysis in support of the riskassessment Taking responsibility for product safety assessment against major subsystems or key complex technologies Your Skills and Experiences Essential: Practitioner knowledge and hands on experience of the HazID processes e.g. Functional Failure Analysis, hazard assessment and risk management. Experience leading a technical team Hands on experience creating a safety argument for a complex product Strong communication and … processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These More ❯
to the development, implementation and maintenance of internal governance frameworks, including policies, standards and procedures Maintaining compliance with relevant laws, regulations and industry standards (e.g. GDPR), through collaboration with risk owners in Legal, HR and other relevant departments Monitoring and reporting on the ongoing performance and effectiveness of the divisional ISMS, including the development and tracking of appropriate KPIs … Audit team on the development, implementation and operation of ITGCs Supporting the implementation of ISO27001 controls and perform regular control audits to monitor compliance Developing and managing a security risk framework, aligning with the enterprise risk management approach Coordinating the performance of regular business impact assessments (BIAs) and the recording of results and updates Contributing to the design … and implementation of information security process and control improvements Mentoring other members of the Information security team and promote risk management best practices across IT Supporting the development and delivery of compliance training and awareness, fostering a culture of risk awareness and accountability across the organisation Providing advice to stakeholders on IT risk and compliance topics About More ❯
to the development, implementation and maintenance of internal governance frameworks, including policies, standards and procedures Maintaining compliance with relevant laws, regulations and industry standards (e.g. GDPR), through collaboration with risk owners in Legal, HR and other relevant departments Monitoring and reporting on the ongoing performance and effectiveness of the divisional ISMS, including the development and tracking of appropriate KPIs … Audit team on the development, implementation and operation of ITGCs Supporting the implementation of ISO27001 controls and perform regular control audits to monitor compliance Developing and managing a security risk framework, aligning with the enterprise risk management approach Coordinating the performance of regular business impact assessments (BIAs) and the recording of results and updates Contributing to the design … and implementation of information security process and control improvements Mentoring other members of the Information security team and promote risk management best practices across IT Supporting the development and delivery of compliance training and awareness, fostering a culture of risk awareness and accountability across the organisation Providing advice to stakeholders on IT risk and compliance topics About More ❯
Glasgow, Scotland, United Kingdom Hybrid / WFH Options
Capgemini
using frontend BI tools to create dashboards and interactive visual reports such as Power BI, Tableau, Qlik, Looker etc. Experience in UX design, requirements gathering, data-driven decision-making, riskassessment, KPI framework development, or value tracking and value analysis Experience in ingestion, integration, data engineering, data quality and observability, dataset identification Experience in high-level architecture, solution More ❯
strengthen relationships with the commercial partner, providing both strategic oversight and operational management of the project. Reporting to Professor Stefan Siebert, the post holder will lead on project planning, riskassessment, and coordination of multidisciplinary teams. They will also support broader University partnership activities as required. Team members will include: amongst others, Clinical research fellows, Study nurses, Laboratory More ❯
Description Job Description We have an exciting and rewarding opportunity for you to take your AI/ML career to the next level while making a significant impact on risk technology solutions. As an Applied AI/ML Software Engineer III at JPMorgan Chase within the Risk Technology team, you serve as a key contributor in researching, developing … and implementing innovative Generative AI solutions that transform our riskassessment capabilities. You are responsible for turning cutting-edge AI research into practical applications that enhance operational efficiencies and integrate with our existing risk calculation frameworks, supporting the firm's business objectives in an ever-evolving technological landscape. Our Risk Technology team relies on innovative thinkers … like you to develop cutting-edge AI solutions that enhance our riskassessment and management capabilities across our network. Your efforts will directly impact how we identify, measure, and mitigate risks across all divisions of JPMorgan Chase. You'll be part of a forward-thinking team specifically built to explore and implement emerging AI technologies that address complex More ❯
Officer Apply locations London - United Kingdom, Edinburgh WRS - United Kingdom Time type: Full time Posted on: Posted 4 Days Ago Job requisition id: REQ-13864 Role Description The Global Risk and Compliance division (GR&C) exists to enable the FNZ Group to safely achieve its strategic objectives and protect value; to support the growth and delivery of services and … regulators, and stakeholders across regions and business units to align data privacy strategies with the firm's strategic objectives and evolving regulatory landscape. This role will collaborate with governance, risk, and compliance (GRC) specialists and analytics experts to ensure effective oversight, reporting, and continuous improvement of the firm's data protection position. Reporting directly to the Group Enterprise Compliance … and standards, ensuring alignment with local data privacy regulatory obligations and industry best practices across Europe, the UK, North America, and APAC. Establish privacy governance objectives and key privacy risk indicators (KPIs/KRIs) that align with the firm's risk appetite and compliance requirements. Implement systems and processes to monitor, identify, and mitigate data protection risks across More ❯
skills alongside a flexible and enthusiastic approach to working within a busy team. About The Role (External) Here are some of the duties your role will include: - Evaluate and risk assess examination reports for a varied asset portfolio in accordance with functional policy, systems and standards, to ensure their continued safety and performance. Determine, specify and prioritise actions to … address defects, risks, comments and other issues raised in these reports, in accordance with standards and functional policy, for inclusion in work plans. Schedule examinations, inspections, monitoring and assessment of assets. Oversee the development, implementation and handover of prioritised maintenance work items to enable the required outputs to be realised. Produce route specific and asset type management regimes. Develop … and any changes are agreed. Assist with the approval in principle of designs and support acceptance of detailed design certification. Determine and implement mitigation measures required following the structural assessment of the asset or where proposed management actions are deferred. Engage with internal and external stakeholders to ensure the optimal risk management solution is identified and implemented. Determine More ❯
Glasgow, Scotland, United Kingdom Hybrid / WFH Options
Snc-Lavalin
to our clients’ offshore cable projects. You will act as Technical Lead for our offshore cable routing scopes of work, leading GIS-based route analysis and offshore Cable Burial RiskAssessment (CBRA) scopes of work. This will include mentoring of junior members of staff in these activities. You will take the lead in developing AtkinsRéalis’ offshore cable routing … enhancement activities. Acting as a champion for offshore cable routing within AtkinsRéalis’ Marine Geoscience team. Providing technical input to bids for subsea cable routing scopes. Input to Cable Burial Risk Assessments (CBRA) and Depth of Lowering Assessments. Routing of offshore and onshore cables using GIS-based analysis. GIS-based analysis of geophysical, geospatial, and geotechnical data and data management. … working as part of a multi-disciplinary team. Experience of offshore cable routing using ArcGIS, Makai Plan, or AutoCAD. Experience in analyzing geotechnical and geospatial data for Cable Burial Risk Assessments (CBRA), or Depth of Lowering (DoL) assessments. Excellent interpersonal and technical skills and the ability to work independently or as part of a team on subsea cables projects. More ❯
Assisting with the review of responses to more complex client security onboarding and annual due diligence security reviews. Responding to business requests relating to Information Security. Supporting with security risk assessments. Assisting with development of Information Security procedures and processes. Maintaining currency with work undertaken by the overall InfoSec Team to understand how changes to systems, servers and applications … Security (Data Protection Act, Computer Misuse Act, SOX, FSA regulations) An up to date and current knowledge of Information Security; current business and industry issues and initiatives. Experience of riskassessment in a business environment, understanding and determining business impact, determining risk from vulnerability, recommending appropriate and cost-effective controls. Desirable - A relevant degree or qualification. Will More ❯
to this initiative and our collective success. Now is a great time to join us as we establish a team of outstanding people in the fields of Security Architecture, RiskAssessment and Testing who will create and run these new and improved technology services. This is a chance to work on services that matter and affect the lives … excellence, working collaboratively across government to deliver holistic, customer centric cyber security services. This includes consultancy support that continually evolves to emerging technologies and the ever-changing threat and risk landscape. It is an exciting time to be part of our active and encouraging Cybersecurity and Architecture communities, working within HMRC and across HMG. As an Enterprise Security Architect … and encouraging Cyber Security and Architecture communities, within HMRC and across government. You will collaborate and play a leading role with senior business and technical partners, to deliver appropriate risk based technical security advice and guidance.This enables the secure delivery of His Majestys Government solutions and services. You will engage at a strategic level, influencing policy and setting direction More ❯
platform (SharePoint) ensuring all records and documentation is up to date. • Responsible for liaising with internal Legal and Procurement Teams on production of contract documentation including appointment of contractors, RiskAssessment Method Statements and other contractor H&S, legal and insurance documentation • Maintain a project task tracker, risk and issues log. • Deputise for the Project Director in More ❯