growth businesses that fuel the economy - and directly advise the owners and management teams leading them. We'll broaden your horizons The Quality and Risk Management Team (QRM) provides leadership, guidance, and tools to help partners and staff manage quality and risk matters. The team is comprised of … identify and draw attention to opportunities for enhancing our delivery and providing additional services to organisations we work with. Role Purpose The Third Party Risk Manager is responsible for implementation of the BDO third party security framework. This includes assessing the information security risks of our 3rd parties , by … that security controls are implemented within the supply chain lifecycle at BDO Co-ordinates the BDO supplier and supply chain information security due supplier riskassessment framework and due diligence procedure and delivery of service to sta keholders Supports risk-based planning for supplier information security due More ❯
automated loyalty solutions in the US and a game changing payment acceptance solution with patent pending. We are seeking an experienced and dynamic Senior Risk and Compliance Manager at Paynetics UK. This role is critical in driving the development and management of our enterprise-wide risk program, covering … operational, compliance, financial crime, financial, and strategic risks. To excel in this role, you will bring: Proven experience in risk management within banking or payments. Deep working knowledge of risk management frameworks for FCA-regulated firms (experience with payments or e-money is a strong advantage). Strong … the ability to balance accuracy and speed in execution. A willingness to get hands dirty , delivering pragmatic, actionable outcomes. What you'll do: Develop Risk framework - this includes risk events, development of a framework for the timely identification and reporting of major operational and security incidents , the development More ❯
Principal Accountabilities: Risk identification: Develop and implement risk identification strategies; this will involve working with multiple teams to design solutions, educate and support risk identification exercises; Create and maintain a risk taxonomy and reference library to support technology risk identification and assessment, collaborating with … various risk type stakeholders; Understand business and technology service business criticality and dependencies, by working with various teams and supporting our Operational Resilience Manager to conduct business impact and vulnerability assessments. Riskassessment and evaluation Coordinate periodic Risk Control Self-Assessment exercises, control testing and … dives, working cross-function to create and maintain a transparent view of all technology risks; Monitor and review internal and external technology issues and risk events, and create and maintain a knowledge base to support continuous organisational learning and improvements; Support the Third Party Risk & Assurance Specialist with More ❯
london, south east england, united kingdom Hybrid / WFH Options
Spencer Rose
Cyber Security Risk Specialist - VP Docklands, London (Hybrid) £100,000 - £110,000 per annum + annual discretionary bonus On behalf of a Leading financial services organisation, I am seeking a highly experienced Cyber Security Risk Specialist at VP level. The individual will be part of the security function … that is responsible for security governance, risk and assurance, to ensure the organisations security posture is robust, compliant against the security policy, standards and controls. In particular I am seeking someone with an extensive background in managing Security Control testing. The company operate a hybrid work policy and therefore … such as NIST CSF and NIST 800-53. Act as an advisor to colleagues across the organisation on best security practice. Conduct regular risk assessments and maintain risk register in RSA Archer. Identify assess and prioritize security risk across the organisation's information assets and environments. More ❯
london, south east england, united kingdom Hybrid / WFH Options
CLS Group
dollars’ worth of currency flows through our systems each day. Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies. We deliver huge efficiencies and savings for our clients … over 96% on average, so clients can put their capital and resources to better use. CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX … environment in which everyone is encouraged to be open and forward-thinking. Job information: Functional title - AVP, IT Security Specialist Department – Security Governance and Risk Management Corporate level – Associate Vice President Report to – Director of Security Location - London, onsite 2 days per week About the role: The individual will More ❯
Job title: Lead Cyber Risk Analyst Location: Frimley or Preston - We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: £65,000 dependent on skills and experience What you'll be doing: Lead on developing riskassessment and analysis methodologies; developing leading approaches to assessing technology such as AI, traditional IT systems and cyber risk in the supply chain Conduct impact modelling to assess potential financial, operational and reputational impacts to the company in the event of a major cyber incident Develop and … present strategic risk reports to senior management, providing clear insights and recommendations Collaborate across the Group to lead risk analysis efforts and provide subject matter expertise (SME) guidance to different sectors Work closely with other cybersecurity teams to understand threat landscapes, vulnerabilities, and impact assessments Stay abreast of More ❯
Milton Keynes, Buckinghamshire, United Kingdom Hybrid / WFH Options
TieTalent
and-run drivers and paid over £400 million in compensation to support victims rebuild their lives. We're looking for a professional and inspiring Risk Management Leader to come and join our team. As a member of the Information Security - Governance Risk and Compliance team (InfoSec GRC), you … ll maintain the confidentiality, availability and integrity of MIB's information and information systems. This will primarily be achieved through identification and recommendation of risk mitigation treatment plans and as a subject matter specialist to support the needs of the organisation. This will be delivered by: Supporting the ongoing … Information Security strategy to business objectives Maintaining robust governance processes in the delivery of MIB's Information security responsibilities Operating an effective information security risk management capability that assesses and reduces risk to an acceptable level Implementing and operating an ongoing information security compliance programme that delivers assurance More ❯
Cantor Fitzgerald’s Global Information Security team is seeking a Governance, Risk, and Compliance (GRC) Lead with expertise on managing cyber risk, ensuring compliance with regulatory requirements, and maintaining corporate controls. This role will be primarily responsible for leading efforts related to third-party risk management, client … diligence, awareness training, and regulatory compliance. The ideal candidate will have a strong grasp of cybersecurity threats and hands-on experience. Key Responsibilities Governance Risk and Compliance Advise project teams, application owners, infrastructure services, and other IT teams on information security controls, such as access management, incident handling, business … mitigation recommendations. Continuously improve policies and procedures related to controls and operational processes. Develop and deliver precise and timely metrics and reports. Third-Party Risk Management: Conduct risk assessments of new and existing third-party vendors to ensure compliance with company policies and regulatory requirements. This includes reviewing More ❯
london, south east england, united kingdom Hybrid / WFH Options
OFS
Credit Risk Analyst | United Kingdom | Hybrid | Contract Location: United Kingdom (Hybrid) Contract Type: 6-Month Contract (Potential Extension) Salary: £500-£700 per day About the Role A leading Fintech Banking company is seeking a skilled Credit Risk Analyst for an initial 6-month contract, with the possibility of … extension. This role will involve credit riskassessment, data analysis, and working with Python and SQL to drive business insights. Key Responsibilities Conduct credit risk analysis to support business lending decisions Develop and optimize risk models using Python and SQL Work closely with stakeholders to provide … data-driven insights Support regulatory and risk reporting Key Requirements Strong experience in Credit Risk Analysis Proficiency in Python and SQL Experience in business lending Ability to work in a fast-paced Fintech environment Why Join? Opportunity to work with an innovative Fintech Banking firm Hybrid work model More ❯
Winchester, Hampshire, United Kingdom Hybrid / WFH Options
Deloitte LLP
make and action we take, guiding us to deliver impact how and where it matters most. Connect to your opportunity As a Technology Controls - Risk & Compliance Senior Consultant, you will be responsible for driving the day-to-day Technology Controls activities to effectively identify regulatory, legal, privacy and other … compliance risk exposures. This position plays a crucial role in ensuring quality, data protection and security matters related to our innovative audit products and solutions, environments, and frameworks, throughout the software development lifecycle (SDLC). This exciting and challenging role invites you to drive quality as part of the … SDLC process and ideate ways to creatively solve challenges around legal, risk, regulatory and privacy matters. This role will utilize established risk and control frameworks to ensure that development, hosting, deployment and other risk decisions around our audit products and solutions comply with existing firm policies, professional More ❯
industry and business imperative focus including business-related IT and OT challenges and cybersecurity, business applications, systems, and business process integration solutions Experience with riskassessment, especially cyber risk is preferred Additional Information The Team Business Value Consulting is a strategic, consultative team and is a critical More ❯
london, south east england, United Kingdom Hybrid / WFH Options
IPS Group
resilience framework that meets DORA standards and other recognised guidelines (e.g. ISO 22301, ISO 27001, NIST). Draft internal controls, policies, training content, and riskassessment methodologies. Contribute to core DORA workstreams such as ICT risk management, scenario-based testing, and oversight of third-party providers. Stakeholder … and support a smooth transition into standard business processes. Training & Culture Develop and deliver resilience-focused training across various teams. Promote best practices in risk and continuity planning. Embed a culture of awareness, accountability, and continuous improvement. What We’re Looking For: A degree in Risk Management, Cyber … Solid understanding of UK and EU regulatory frameworks, with hands-on experience relating to DORA. Demonstrable experience conducting regulatory gap analyses, resilience testing, and risk assessments. Strong organisational skills and the ability to manage competing priorities in a deadline-driven environment. Excellent interpersonal and stakeholder management skills, particularly in More ❯
functions on all aspects of information security ie and/or classified information assets, materials and/or equipment are subject to an acceptable risk management regime. Key Accountabilities: Provide analysis of risks to information systems in order to inform risk owners and project managers to allow effective … and quality and be a great team player. Key Responsibilities: Work with functions, projects and the supply chain to assess the sources of Information Risk and make recommendations on how these are to be managed. Provide the project lead for maintaining awareness and industry best practice in Information Assurance … and Information Risk Management. Determine how the overall security architecture applies to projects under consideration and advise project solution architects on security requirements. Review high and low level solution designs for compliance with overall security architecture, achievement of security requirements and overall efficacy of the security features and tools. More ❯
maintenance of the ISO27001; PCI-DSS and SOC2 compliance. They are the subject matter of all things regarding security and compliance, owning the information risk management processes. They are the thought leader on all matters within the security and compliance domain such that the company remains secure against the … outcomes Expert in information security with strong communication and stakeholder management skills Experience in managing security incidents and leading incident response Experience with security assessment tools and vulnerability management Strong vendor management and third-party riskassessment experience Skills : Strong understanding of cloud security principles and best More ❯
Guildford, Surrey, United Kingdom Hybrid / WFH Options
Sycurio
of the ISO27001, PCI-DSS, and SOC2 compliance. They are the subject matter expert on all things regarding security and compliance, owning the information risk management processes. They are the thought leader on all matters within the security and compliance domain such that the company remains secure against the … outcomes. Expert in information security with strong communication and stakeholder management skills. Experience in managing security incidents and leading incident response. Experience with security assessment tools and vulnerability management. Strong vendor management and third-party riskassessment experience. Skills: Strong understanding of cloud security principles and best More ❯
Care, Pension +More... This role requires a Lead Architect or above level candidate with a deep understanding of Trading platforms, portfolio management systems, and risk management architecture, transformation and modernization with an understanding of regulatory compliance processes and technical adherence to FCA/PRA regulations. Experience ensuring COCON compliance … quality metrics. Regular audit reports for regulatory and internal reviews. Collaborating with Technology Delivery teams to create and maintain technology roadmaps Dependency matrices and risk assessments. Quarterly roadmap review presentations for stakeholders. Agile architecture + training. Metrics on technical debt reduction and architecture adoption. Build an architecture runway (e.g. … Platforms Proprietary or third-party systems like Charles River or Bloomberg Terminal integrations for trade execution and settlement. Portfolio Management Tools like BlackRock Aladdin. Risk Management: Solutions like MSCI RiskMetrics or in-house tools for real-time riskassessment (e.g., Value-at-Risk calculations). CLIENT More ❯
Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
Connexa
Act as a liaison between technical teams, procurement, and senior stakeholders. Provide strategic guidance on procurement scrutiny and governance in the public sector. Support riskassessment, change management, and business case development. Process Improvement & Knowledge Sharing Drive continuous improvement by identifying efficiencies and best practices in procurement processes. … management tools (DOORS, Dimensions RM, Power BI). Understanding of MOD procurement methods and public sector scrutiny. Analytical & Communication Skills: Strong data analysis, performance assessment, and reporting capabilities. Excellent written and verbal communication skills, with experience producing technical documentation. Ability to persuade, challenge, and negotiate effectively with senior stakeholders. More ❯
Canterbury, Kent, United Kingdom Hybrid / WFH Options
Applicable Limited
of Work (SOW), and supporting presales activities. They must ensure accurate input into the forecasts for the team's project portfolio. Any projects that risk falling behind schedule require prior approval from the Director of the Customer Success Centre of Excellence (COE) for any changes to revenue timing. Moreover … communication between Functional and IT teams. Manage expectations and ensure alignment with business objectives. Conduct stakeholder meetings and provide regular updates on transition progress. Risk & Compliance Management Identify and mitigate risks associated with the transition. Ensure compliance with industry regulations and security standards, ISO 27001, ITIL, GDPR. Conduct impact … service agreements (MSAs) and SLAs. Project Management Skills Proficiency in project management methodologies and documentation. Ability to manage multiple complex transitions with multiple stakeholders. Riskassessment and mitigation planning expertise. Soft Skills Strong communication and negotiation skills. Problem-solving and decision-making abilities. Leadership and stakeholder management experience. More ❯
london (city of london), south east england, united kingdom Hybrid / WFH Options
Sarafin Partners
with their offices around the world to support cyber security initiatives. The successful candidate will possess strong analytical skills, an understanding of security administration, risk management and identity access management solutions. The main focus of the role will include: Performance of system security administration on designated technology platforms in … this role, the individual will need: Exceptional communication skills (both written and verbal) At least 18 months experience of working with cybersecurity principles, including riskassessment and management, threat and vulnerability management, incident response, and identity and access management Experience in developing, documenting and maintaining security procedures Knowledge More ❯
Epsom, Surrey, United Kingdom Hybrid / WFH Options
AtkinsRéalis
cable projects. You will act Technical Lead for our offshore cable routing scopes of work, leading GIS based route analysis and offshore Cable Burial RiskAssessment (CBRA) scopes of work. This will include mentoring of junior members of staff in these activities. You will take the lead in … champion for offshore cable routing within AtkinsRéalis' Marine Geoscience team. Providing technical input to bids for subsea cable routing scopes. Input to Cable Burial Risk Assessments (CBRA) and Depth of Lowering Assessments. Routing of offshore and onshore cables using GIS based analysis. GIS based analysis of geophysical, geospatial and … multi-disciplinary team. Experience of offshore cable routing using ArcGIS, Makai Plan or AutoCAD. Experience in analyzing geotechnical and geospatial data for Cable Burial Risk Assessments (CBRA), or Depth of Lowering (DoL) assessments. Excellent interpersonal and technical skills and the ability to work independently or as part of a More ❯
Milton Keynes, Buckinghamshire, South East, United Kingdom
Cyberteam
the potential to lead/evolve into IT Security, Penetration Testing, and Information Governance specialisations. Key Responsibilities: Conduct Cyber Essentials and Cyber Essentials Plus Assessment: Perform comprehensive assessments of organisations' cybersecurity practices, systems, and controls to ensure compliance to the Cyber Essentials Scheme Conduct in-depth vulnerability assessments to … identify potential security weaknesses. Verify the effectiveness of CE security controls through rigorous testing and analysis. Document CE and CE+ assessment findings, including detailed reports and recommendations. Provide Guidance and Recommendations: Offer advice and guidance to organisations on implementing and enhancing cybersecurity controls to become compliant to CE. Assist … the context of the Cyber Essentials and Cyber Essentials Plus frameworks. In-depth knowledge of cybersecurity principles, best practices, and industry standards. Familiarity with riskassessment methodologies and vulnerability analysis techniques. Excellent analytical and problem-solving skills, with the ability to identify and assess security risks. High levels More ❯
scale financial institutions. Key Responsibilities: Conduct regular vulnerability assessments and penetration tests across applications, infrastructure, and cloud environments. Analyse security threats and vulnerabilities, providing risk-based recommendations to remediate or mitigate risks. Work closely with security, IT, and development teams to prioritise and address security weaknesses. Maintain and enhance … vulnerability management processes, ensuring continuous monitoring and improvement. Perform vulnerability scanning, triage, and riskassessment across a broad range of systems, including cloud, on-prem, and hybrid environments. Coordinate with infrastructure and application teams to ensure timely and effective remediation. Collaborate with the Security Operations Centre (SOC) to More ❯
responsible for managing the digital asset services which includes client onboarding, creation and maintenance of governance rules, transaction processing, monitoring, reporting, staking and operations risk reporting. In the initial stages a high degree of project support and business analysis will be required. As part of an agile team, the … Experience: A graduate in a statistical or analytical degree, ideally sciences, engineering, business, economics or similar and able to demonstrate expertise in statistical analysis, riskassessment and process/workflow design. Industry experience in financial services in one or more of the following operations would be an advantage More ❯
london, south east england, united kingdom Hybrid / WFH Options
psd group
degree in Cybersecurity, IT, Information Security, or a related field Over 6 years of experience in cybersecurity, with a focus on implementing controls, governance, riskassessment, or architecture design Deep expertise in securing cloud environments, especially AWS (mandatory) Strong working knowledge of ISO 27001, CIS, NIST and other More ❯
in working with the Ministry of Defence (MOD). The ideal candidate must possess DV Clearance and have a deep understanding of secure systems, risk management, and cyber security best practices within a defence environment. RESPONSIBILITIES Provide technical cyber security consultancy to public and private sector clients. Perform security … penetration testing, and vulnerability management to protect critical systems. Design, implement, and maintain security architectures and frameworks aligned with government standards. Lead and support risk assessments, threat modelling, and incident response initiatives. Work closely with stakeholders to ensure compliance with NCSC and other relevant security policies. Develop and deliver … threat intelligence. Solid knowledge of security technologies such as SIEM, IDS/IPS, firewalls, and endpoint detection and response (EDR). Strong understanding of riskassessment methodologies and security governance frameworks. Excellent stakeholder engagement and communication skills, with the ability to convey technical information to non-technical audiences. More ❯