St. Albans, Hertfordshire, United Kingdom Hybrid / WFH Options
Deloitte LLP
five shared values lead every decision wemake and action we take, guiding us to deliver impact how and where it mattersmost . Connect to your opportunity The Technical Cyber RiskAssessment Manager will be responsible for the following: Develop an understanding of Deloitte's global line of business and its priorities, becoming an advocate for addressing cyber risk. … Demonstrate familiarity with the Three Lines of Defense (3LOD) model. Possess knowledge of risk management practices and the ability to conduct technical risk assessments. Work with the Global Technology Infrastructure team to integrate system cybersecurity assessments into their processes to ensure consistent implementation of security controls. Work with the Cybersecurity Architecture team and apply reference architectures for security … reported threats at peer organizations, and overall cybersecurity threats in the internet ecosystem and you will notify leadership of potential or existing threats and assist in the development of risk mitigating strategies of these items. Monitor security blogs, articles, and reports and remain current on related laws, regulations, and industry standards to keep up to date on the latest More ❯
Reading, Berkshire, United Kingdom Hybrid / WFH Options
Deloitte LLP
five shared values lead every decision wemake and action we take, guiding us to deliver impact how and where it mattersmost . Connect to your opportunity The Technical Cyber RiskAssessment Manager will be responsible for the following: Develop an understanding of Deloitte's global line of business and its priorities, becoming an advocate for addressing cyber risk. … Demonstrate familiarity with the Three Lines of Defense (3LOD) model. Possess knowledge of risk management practices and the ability to conduct technical risk assessments. Work with the Global Technology Infrastructure team to integrate system cybersecurity assessments into their processes to ensure consistent implementation of security controls. Work with the Cybersecurity Architecture team and apply reference architectures for security … reported threats at peer organizations, and overall cybersecurity threats in the internet ecosystem and you will notify leadership of potential or existing threats and assist in the development of risk mitigating strategies of these items. Monitor security blogs, articles, and reports and remain current on related laws, regulations, and industry standards to keep up to date on the latest More ❯
Guildford, Surrey, United Kingdom Hybrid / WFH Options
Deloitte LLP
five shared values lead every decision wemake and action we take, guiding us to deliver impact how and where it mattersmost . Connect to your opportunity The Technical Cyber RiskAssessment Manager will be responsible for the following: Develop an understanding of Deloitte's global line of business and its priorities, becoming an advocate for addressing cyber risk. … Demonstrate familiarity with the Three Lines of Defense (3LOD) model. Possess knowledge of risk management practices and the ability to conduct technical risk assessments. Work with the Global Technology Infrastructure team to integrate system cybersecurity assessments into their processes to ensure consistent implementation of security controls. Work with the Cybersecurity Architecture team and apply reference architectures for security … reported threats at peer organizations, and overall cybersecurity threats in the internet ecosystem and you will notify leadership of potential or existing threats and assist in the development of risk mitigating strategies of these items. Monitor security blogs, articles, and reports and remain current on related laws, regulations, and industry standards to keep up to date on the latest More ❯
Guildford, Surrey, United Kingdom Hybrid / WFH Options
Sycurio
driving the attainment and maintenance of the ISO27001, PCI-DSS, and SOC2 compliance. They are the subject matter expert on all things regarding security and compliance, owning the information risk management processes. They are the thought leader on all matters within the security and compliance domain such that the company remains secure against the ever-changing security threat and … external auditors to achieve positive outcomes. Expert in information security with strong communication and stakeholder management skills. Experience in managing security incidents and leading incident response. Experience with security assessment tools and vulnerability management. Strong vendor management and third-party riskassessment experience. Skills: Strong understanding of cloud security principles and best practices, particularly in AWS. Solid More ❯
deliver greener and smarter rail solutions. About the team The successful candidate will be joining the Fleet function, a small multi-disciplinary team that supports corporate and project governance, risk management and audits of Train Operating Companies, suppliers and internal Porterbrook processes. The team is part of the Operations Directorate reporting to the Chief Operating Officer. Key Responsibilities Role … security best practice. Responsibilities Specific Management of the Fleet cyber security strategy in line with TS 50701 & IEC 62443-3-2 Introduce, then keep updated, a cyber security baseline assessment for each fleet platform Cyber security riskassessment of asset modifications Promotion of cyber security best practice throughout our engineering teams Supporting our customers with their cyber … resilient to cyber failure/compromise, working in collaboration with the supply chain Ensure that the Management of Change Procedure and all changes take full account of cyber security risk Determine Fleet cyber security requirements for both new train procurement and existing fleet upgrades General Engagement with industry bodies on emerging cyber security guidance Supplier/product assessmentMore ❯
development and maintenance methods, tools and techniques. Be conversant with the organisation's IT strategy, policies and standards, and any industry regulations/constraints. Have a good appreciation of risk management, change management, configuration management, reliability and safety methods and the use of metrics. This post is a permanent full time post to meet the needs of the service. … strategic context, and develop technical roadmaps that incorporate innovative solutions to enhance business agility and efficiency. Leading the planning and organisation of complex tasks, including solution design, stakeholder engagement, riskassessment, and resource coordination, within business change programmes, adapting plans to evolving business or user needs, and ensuring appropriate technical resources are made available. Creating technical designs, and … make and guide architectural design, characterised by medium risk, impact, and complexity, ensuring solutions meet both business and technical requirements. Developing solution architecture governance and assurance to support quality, manage risks, and ensure consistent decisions across projects. Leading the communication of complicated, complex or risky architecture topics with technical and non-technical stakeholders. Evaluating, experimenting with, and integrating cutting More ❯
Nottingham, Nottinghamshire, United Kingdom Hybrid / WFH Options
Experian Group
equivalent demonstrable experience. 5+ years' of experience in Information Security or Information Technology 3+ years' experience performing IT Audit or security control testing. Knowledge of internal audit methodologies, including riskassessment, execution, and reporting. Proficiency in industry standards and frameworks (e.g., NIST 800-53, ISO 27001/27002). Familiarity with privacy regulations (e.g., GDPR, CCPA) and breach … PowerBI). Create queries and reports in RSA Archer and ServiceNow. Familiarity with Kanban boards and Jira. Desired Competencies Understanding of cybersecurity principles and organizational requirements. Experience applying governance, risk, and control principles. Experience in automated and manual testing of security controls. Experience facilitating meetings and conveying complex ideas. Data collection, validation, analysis, and interpretation. Experience Researching and applying More ❯
Newcastle Upon Tyne, United Kingdom Hybrid / WFH Options
Leonardo UK Ltd
This is an exciting opportunity to be part of significant programmes, during which you will ensure that products meet the highest standards, in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger team of consultants, engineers and product domain specialists. Your work at Leonardo UK will see you … and detailed system and security designs as they pertain to the cyber domain. Decomposing cyber and security requirements down to the system control level. Conducting cyber and information security riskassessment activities including threat modelling, vulnerability analysis and analysis of mitigations. Scoping and managing security verification & validation activities and remedial action plans. Coordinating with product engineers, system architects More ❯
Easter Howgate, Midlothian, United Kingdom Hybrid / WFH Options
Leonardo UK Ltd
This is an exciting opportunity to be part of significant programmes, during which you will ensure that products meet the highest standards, in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger team of consultants, engineers and product domain specialists. Your work at Leonardo UK will see you … and detailed system and security designs as they pertain to the cyber domain. Decomposing cyber and security requirements down to the system control level. Conducting cyber and information security riskassessment activities including threat modelling, vulnerability analysis and analysis of mitigations. Scoping and managing security verification & validation activities and remedial action plans. Coordinating with product engineers, system architects More ❯
Yeovil, Somerset, United Kingdom Hybrid / WFH Options
Leonardo UK Ltd
of a significant programme, during which you will ensure that the product and associated deliverables are as secure as reasonably practicable, and in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger consulting team, engineers and product domain specialists. Your work at Leonardo UK will see you take … and detailed system and security designs as they pertain to the cyber domain. Decomposing cyber and security requirements down to the system control level. Conducting cyber and information security riskassessment activities including threat modelling, vulnerability analysis and analysis of mitigations, including technical understanding. Scoping and managing security verification and validation activities and remedial action plans. Coordinating with More ❯
This is an exciting opportunity to be part of significant programmes, during which you will ensure that products meet the highest standards, in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger team of consultants, engineers and product domain specialists. Your work at Leonardo UK will see you … and detailed system and security designs as they pertain to the cyber domain. Decomposing cyber and security requirements down to the system control level. Conducting cyber and information security riskassessment activities including threat modelling, vulnerability analysis and analysis of mitigations. Scoping and managing security verification & validation activities and remedial action plans. Coordinating with product engineers, system architects More ❯
Swindon, Wiltshire, United Kingdom Hybrid / WFH Options
Zurich 56 Company Ltd
skills (Data Analytics, IT fundamentals, and GenAI), and Agile methods, and serve as a role model for delivering change. What will you be doing? Input into the overall UK riskassessment and audit planning and, determining the right auditscope, key risks to be addressed and most suitable audit techniques and approaches alongside the Audit Director Keeping the business … Security and new technologies, such as Robotics and Artificial Intelligence. Experience in third-party, outsourcing and project management auditing. Strong understanding and applicability of audit and/or business risk management and control processes. Proven record of working with and influencing executive/senior stakeholders, verbally and through written reports. Demonstrated success in business, functional and people management. Excellent More ❯
foundations across platforms, data, and business applications. Our passion lies in using technology to solve business problems, working closely with clients to help achieve their goals. About the role: RiskAssessment: Assist in identifying, assessing, and prioritising risks across the organisation. Conduct risk assessments to evaluate the likelihood and potential impact of risks on business operations and … Identify and document control deficiencies, compliance gaps, and areas for improvement. Collaborate with stakeholders to develop actionable recommendations and corrective action plans. Documentation and Reporting: Maintain accurate documentation of risk assessments, compliance reviews, control testing activities, and remediation efforts. Prepare regular reports for management and stakeholders. Policy and Procedure Development: Assist in developing and maintaining risk management, compliance … and control-related policies, procedures, and guidelines, ensuring alignment with regulatory requirements and industry best practices. Vendor Risk Management Support: Assist in assessing and managing risks associated with third-party vendors and service providers, evaluating controls and contractual adherence. Continuous Improvement: Identify opportunities to enhance risk management, compliance, and control processes. Recommend and implement improvements to strengthen the More ❯
Chorley, England, United Kingdom Hybrid / WFH Options
TVS Supply Chain Solutions UK & Europe
system certified to ISO27001 and a business continuity management system certified to ISO22301 across several UK sites. The successful candidate will have a working knowledge of ISO standards, understand risk management and be able to communicate effectively at all levels. Main Duties & Responsibilities: Support the maintenance, development and continual improvement of ISBC Management System Coordinate and assist in internal … compliance Track and follow up on corrective and preventive actions resulting from audits or incidents Maintain documentation, records, and registers in accordance with ISO standards Assist in managing the riskassessment and treatment processes Monitor compliance with policies, procedures, and controls Support incident management and business continuity testing activities Organise and deliver awareness training and communication efforts related … that day-to-day operations of systems run smoothly and in line with compliance obligations Knowledge, Skills, Experience and Qualifications: Understanding of ISO 27001 and ISO 22301 frameworks, including risk management Strong organisational and documentation skills Experience with internal audit, compliance review, or policy implementation Effective written and verbal communication skills, especially for reporting, training and stakeholder coordination Analytical More ❯
South East London, England, United Kingdom Hybrid / WFH Options
Sarafin Partners
an experienced professional to work with their offices around the world to support cyber security initiatives. The successful candidate will possess strong analytical skills, an understanding of security administration, risk management and identity access management solutions. The main focus of the role will include: Performance of system security administration on designated technology platforms in accordance with the defined policies … are maintained To succeed in this role, the individual will need: Exceptional communication skills (both written and verbal) At least 18 months experience of working with cybersecurity principles, including riskassessment and management, threat and vulnerability management, incident response, and identity and access management Experience in developing, documenting and maintaining security procedures Knowledge of network infrastructure, including routers More ❯
advocate internal and external policy to shape the development of new laws and regulations consistent with company objectives. Develop and implement a compliance monitoring system. Coordinate a company-wide riskassessment process to identify potential risks and control solutions. Monitor actions to identify emerging risks and close gaps. Create internal partnerships with key stakeholders to influence and align … expertise, processes and networks together to solve the post-trade challenges of global financial markets. OSTTRA operates cross-asset post-trade processing networks, providing a proven suite of Credit Risk, Trade Workflow and Optimisation services. Together these solutions streamline post-trade workflows, enabling firms to connect to counterparties and utilities, manage credit risk, reduce operational risk and More ❯
Cambridge, Cambridgeshire, United Kingdom Hybrid / WFH Options
Jagex Limited
of enhanced respect and consideration for financial process and control. Driving change across the organisation on business controls and financial processes to ensure appropriate, pragmatic governance, commercial awareness and riskassessment Prepare and present board materials to appropriate sub-committees (Risk/Audit etc) Manage, develop and coach a team of 3 direct reports (9 including indirect … reports) Prepare and deliver training to finance and the wider organisation to increase commercial and financial risk awareness Financial performance and analysis Oversee the monthly management accounts process ensuring they are produced accurately and on time, including review by the Finance Leadership Team, Executive and Board. Prepare the summary for the monthly board pack prior to CFO review and … controls and processes to ensure they are appropriate to the operational needs of the organisation and aligned with the business strategy Ensure compliance with regulatory requirements and accounting standards Risk Management and Statutory Reporting Identify and mitigate financial risks and ensure adherence to corporate governance policies Lead the completion of external audit and tax deliverables, ensuring timely sign off More ❯
Easter Howgate, Midlothian, United Kingdom Hybrid / WFH Options
Leonardo UK Ltd
This is an exciting opportunity to be part of significant programmes, during which you will ensure that products meet the highest standards, in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger team of consultants, engineers and product domain specialists. Your work at Leonardo UK will see you … and security designs as they pertain to the cyber domain. Experience working with cyber and security requirements down to the system control level. Experience conducting cyber and information security riskassessment activities including threat modelling, vulnerability analysis and analysis of mitigations. Scoping and managing security verification & validation activities and remedial action plans. Experience working with product engineers, system More ❯
TN1, Royal Tunbridge Wells, Kent, United Kingdom Hybrid / WFH Options
Town & Country Housing Group
Excellent problem-solving, analytical, and decision-making abilities. *Ability to manage multiple projects in a fast-paced environment. *Detail-oriented with strong organizational and time management skills. *Proficiency in riskassessment and conflict resolution. *Adaptability to new technologies and evolving business requirements. *Strong negotiation and influencing skills. Required Behaviours *Ability to support the strategic vision and goals of More ❯
Newcastle upon Tyne, United Kingdom Hybrid / WFH Options
NHS Business Services Authority
the team as the primary resource for advice. Efficiently manage the workload of personnel, ensuring timely completion of tasks and continuous improvement. Ensure continued compliance with NCSC, DHSC Cyber Assessment Framework, and HM Government Cyber security strategy. Develop, maintain, and promote security procedures and standards in line with NHSBSA requirements. Implement, monitor, and report on agreed service levels, KPIs … 6. Ensure that all controls are in place to ensure continued compliance with the National Cyber Security Centre (NCSC) an the Department of Health and Social Care (DHSC) Cyber Assessment Framework (CAF)and continued adherence to HM Government Cyber security strategy and NCSC standards and best practice. 7. Supports the strategic direction of the Cyber security operation function by … 7.Hands on experience with the design of ICT security mitigation measures to meet Information Security work-based assessments. Desirable 1.Cloud Security & monitoring 2.Development of a security architecture design 3.Risk assessment and balancing security risks with business requirements. Qualifications Essential 1.A degree level qualification or equivalent experience in Cyber Security. 2.A Professional Certification or qualification in Information Security (CISA, CISMP More ❯
Maidenhead, Berkshire, United Kingdom Hybrid / WFH Options
Wireless Logic Group
PE-backed group Treasury Management Systems (TMS): Demonstrable ability to personally manage operational treasury responsibilities Financial Modeling: Advanced skills in financial modeling, including cash flow forecasting, investment analysis, and risk assessment. Data Analysis & Visualization: Ability to analyze large datasets, identify trends, and create insightful reports using tools like Excel, and potentially PowerBI, or Tableau. Advanced Excel skills essential Foreign … Exchange (FX) Management: Knowledge of FX trading platforms and risk management tools. Debt Management: Experience with debt management systems and tools. Highly Self-Sufficient - thrives in a standalone role with full ownership Strong Communicator: Communicates clearly and confidently with senior stakeholders Banking Platforms: Experience with online banking platforms and electronic funds transfer systems. What Will Make You Shine at More ❯
Swindon, Wiltshire, United Kingdom Hybrid / WFH Options
Zurich 56 Company Ltd
on how to move our UK business forward. You will be asked to drive change and improve on a set of already well-established IT Controls and an IT Risk Management Framework to allow senior IT management, business functions and 3rd party service providers to demonstrate they are managing and safeguarding company assets, data, and operations. Your ideas will … Controls Manager and other governance colleagues to gather data and collate, aggregate and interpret information to provide the Boards of Directors, Business Executives and other interested parties with an assessment of the UK IT Risk and Controls landscape. You will also manage multiple demands for IT risk-based information within Zurich, ensuring all reporting commitments are met. … alongside local and regional Group IT functions, Service Providers (through internal and external suppliers), and business functions to ensure that Zurich is proactive in the management of IT Operational Risk and Controls. The role is varied, interesting, and there are genuine opportunities to get stuck in and make a difference Many of our employees work flexibly in a variety More ❯
Reading, Berkshire, United Kingdom Hybrid / WFH Options
Deloitte LLP
following: Shape the development of technology control management including scoping, development of and testing ServiceNow tools for ITRM processes in DT to allow for an effective, efficient and adaptable risk governance capability and contribute to its continuous improvement. Direct control development across DT, driving a consistent approach utilising the IRM capabilities within ServiceNow. Deliver the DT control library architecture … and control data management. Secure commitment from member firms and stakeholders in the global firm to participate in the Technology Standards and Maturity Assessment with the objective to assess the member firm's overall IT capability/maturity and to help them establish their own priorities. Keep abreast of new and emerging technologies being deployed and ensure riskassessment processes are appropriately applied and advise on decisions with technology risk impacts as new activities and other change management/transformational initiatives. Leverage available technical resources/tools to research; expand technology risk knowledge to enhance work product, to remain up to date on member firms and line of businesses hot topics while sharing the More ❯
Leeds, Yorkshire, United Kingdom Hybrid / WFH Options
Deloitte LLP
following: Shape the development of technology control management including scoping, development of and testing ServiceNow tools for ITRM processes in DT to allow for an effective, efficient and adaptable risk governance capability and contribute to its continuous improvement. Direct control development across DT, driving a consistent approach utilising the IRM capabilities within ServiceNow. Deliver the DT control library architecture … and control data management. Secure commitment from member firms and stakeholders in the global firm to participate in the Technology Standards and Maturity Assessment with the objective to assess the member firm's overall IT capability/maturity and to help them establish their own priorities. Keep abreast of new and emerging technologies being deployed and ensure riskassessment processes are appropriately applied and advise on decisions with technology risk impacts as new activities and other change management/transformational initiatives. Leverage available technical resources/tools to research; expand technology risk knowledge to enhance work product, to remain up to date on member firms and line of businesses hot topics while sharing the More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Deloitte LLP
following: Shape the development of technology control management including scoping, development of and testing ServiceNow tools for ITRM processes in DT to allow for an effective, efficient and adaptable risk governance capability and contribute to its continuous improvement. Direct control development across DT, driving a consistent approach utilising the IRM capabilities within ServiceNow. Deliver the DT control library architecture … and control data management. Secure commitment from member firms and stakeholders in the global firm to participate in the Technology Standards and Maturity Assessment with the objective to assess the member firm's overall IT capability/maturity and to help them establish their own priorities. Keep abreast of new and emerging technologies being deployed and ensure riskassessment processes are appropriately applied and advise on decisions with technology risk impacts as new activities and other change management/transformational initiatives. Leverage available technical resources/tools to research; expand technology risk knowledge to enhance work product, to remain up to date on member firms and line of businesses hot topics while sharing the More ❯