strategy and roadmap, ensuring our security posture meets the requirements of the NHS Data Security and Protection Toolkit (DSPT), Cyber Essentials Plus, ISO 27001:2022, and other relevant frameworks. Risk Management: Lead the information security risk management program, including the identification, assessment, mitigation, and monitoring of risks across all systems and operations. Policy and Governance: Support and … creation and enforcement of security policies, standards, and procedures. Incident Response: Develop, implement, and manage the security incident response plan. Leadership: Provide strong leadership and mentorship to the governance, risk, and compliance team. Essential Requirements: Extensive security leadership: Proven experience (10+ years) in a senior information security role, with significant experience in a CISO or equivalent position within a … sector experience: In-depth knowledge and practical experience with UK healthcare security standards and regulations, including demonstrable expertise with the NHS Data Security and Protection Toolkit (DSPT), Digital Technology Assessment Criteria (DTAC) and NCSC CAF. ISO 27001:2022 implementation & maintenance: Hands-on experience with the successful implementation, certification, and ongoing maintenance of an ISO 27001 Information Security Management System More ❯
BA1, Bath, Bath and North East Somerset, Somerset, United Kingdom
YT Technologies
strategy and roadmap, ensuring our security posture meets the requirements of the NHS Data Security and Protection Toolkit (DSPT), Cyber Essentials Plus, ISO 27001:2022, and other relevant frameworks. Risk Management: Lead the information security risk management program, including the identification, assessment, mitigation, and monitoring of risks across all systems and operations. Policy and Governance: Support and … creation and enforcement of security policies, standards, and procedures. Incident Response: Develop, implement, and manage the security incident response plan. Leadership: Provide strong leadership and mentorship to the governance, risk, and compliance team. Essential Requirements: Extensive security leadership: Proven experience (10+ years) in a senior information security role, with significant experience in a CISO or equivalent position within a … sector experience: In-depth knowledge and practical experience with UK healthcare security standards and regulations, including demonstrable expertise with the NHS Data Security and Protection Toolkit (DSPT), Digital Technology Assessment Criteria (DTAC) and NCSC CAF. ISO 27001:2022 implementation & maintenance: Hands-on experience with the successful implementation, certification, and ongoing maintenance of an ISO 27001 Information Security Management System More ❯
to our internal and external customer experience, contributing to our purpose of Making You Happier About Money. We’re seeking someone with a deep understanding of IT change management, riskassessment, and stakeholder coordination to safeguard the bank's interests, maintain internal governance and compliance with regulatory standards. What you’ll be doing Protecting live operational service through … addressed. Interrogating ITSM tools (Service Now) to produce relevant MI reporting to exec level. Ensuring that policies, procedures and standards are always followed, and activities are within regulatory and risk requirements. Developing risk mitigation strategies, creating and maintaining team Controls, fulfilling Audit requirements as part of a continuous service improvement plan. Communicating effectively with all levels of the More ❯
to our internal and external customer experience, contributing to our purpose of Making You Happier About Money. We’re seeking someone with a deep understanding of IT change management, riskassessment, and stakeholder coordination to safeguard the bank's interests, maintain internal governance and compliance with regulatory standards. What you’ll be doing Protecting live operational service through … addressed. Interrogating ITSM tools (Service Now) to produce relevant MI reporting to exec level. Ensuring that policies, procedures and standards are always followed, and activities are within regulatory and risk requirements. Developing risk mitigation strategies, creating and maintaining team Controls, fulfilling Audit requirements as part of a continuous service improvement plan. Communicating effectively with all levels of the More ❯
Kingswood, Gloucestershire, UK Hybrid / WFH Options
Virgin Money
to our internal and external customer experience, contributing to our purpose of Making You Happier About Money. We’re seeking someone with a deep understanding of IT change management, riskassessment, and stakeholder coordination to safeguard the bank's interests, maintain internal governance and compliance with regulatory standards. What you’ll be doing Protecting live operational service through … addressed. Interrogating ITSM tools (Service Now) to produce relevant MI reporting to exec level. Ensuring that policies, procedures and standards are always followed, and activities are within regulatory and risk requirements. Developing risk mitigation strategies, creating and maintaining team Controls, fulfilling Audit requirements as part of a continuous service improvement plan. Communicating effectively with all levels of the More ❯
compliance reviews to evaluate the effectiveness of information security controls, creating detailed compliance reports and remediation plans. Operate compliance tools in line with formal procedures. Maintain the Security And Risk Tracking (SART) and Exceptions process. Collaborate with business stakeholders to agree, implement, and manage security controls for key business systems and processes. Coordinate security inventories, scheduled team activities, actions … as Security+, CEH, or CySA+. Familiarity with basic security principles and practices. Knowledge of a range of technical security controls and their operations Familiarity with compliance and audit tools, riskassessment methodologies, and security technologies. Broad ranging analyst skills acquired while working on diverse IT and/or business projects. Proven experience in performing IT/Cyber security … control assessment reviews. Experience working with Information security frameworks and compliance standards (e.g. ISO27001, Cyber Essentials Plus, NIST, SOC2 and PCI-DSS). Strong interest in Information security and technology, and motivated to learn new technologies. Robert Half Ltd acts as an employment business for temporary positions and an employment agency for permanent positions. Robert Half is committed to More ❯
certification artefact production aligned to EASA and UK CAA expectations. Lead the development and review of cybersecurity documentation, including the PSecAC (Airworthiness Security Process Plan), PASRA (Preliminary Aircraft Security RiskAssessment), ASAM (Aircraft Security Architecture Model), and Security Verification Methods. Provide input into the AWSP frameworks, including the tailoring of compliance checklists, activity outcomes, and document templates. Ensure … traceability between security risk assessments, controls, and compliance objectives across the aircraft systems and software architecture. Coordinate the development of cybersecurity methods and processes, contributing to their alignment with recognised standards. Engage with DAG's internal stakeholders, including engineering, safety, and systems integration teams, to embed cybersecurity into the design and certification lifecycle. Act as the primary technical interface … cybersecurity engineering principles in the context of safety-critical systems and regulated environments. Demonstrated experience leading the development of cybersecurity assurance artefacts for certification programmes. Practical understanding of airworthiness risk modelling, threat identification, attack surface reduction, and aircraft-level threat scenarios. Ability to produce certification-ready documentation aligned to EASA/UK CAA guidance, including traceability to compliance objectives. More ❯
certification artefact production aligned to EASA and UK CAA expectations. Lead the development and review of cybersecurity documentation, including the PSecAC (Airworthiness Security Process Plan), PASRA (Preliminary Aircraft Security RiskAssessment), ASAM (Aircraft Security Architecture Model), and Security Verification Methods. Provide input into the AWSP frameworks, including the tailoring of compliance checklists, activity outcomes, and document templates. Ensure … traceability between security risk assessments, controls, and compliance objectives across the aircraft systems and software architecture. Coordinate the development of cybersecurity methods and processes, contributing to their alignment with recognised standards. Engage with DAG's internal stakeholders, including engineering, safety, and systems integration teams, to embed cybersecurity into the design and certification lifecycle. Act as the primary technical interface … cybersecurity engineering principles in the context of safety-critical systems and regulated environments. Demonstrated experience leading the development of cybersecurity assurance artefacts for certification programmes. Practical understanding of airworthiness risk modelling, threat identification, attack surface reduction, and aircraft-level threat scenarios. Ability to produce certification-ready documentation aligned to EASA/UK CAA guidance, including traceability to compliance objectives. More ❯
certification artefact production aligned to EASA and UK CAA expectations. Lead the development and review of cybersecurity documentation, including the PSecAC (Airworthiness Security Process Plan), PASRA (Preliminary Aircraft Security RiskAssessment), ASAM (Aircraft Security Architecture Model), and Security Verification Methods. Provide input into the AWSP frameworks, including the tailoring of compliance checklists, activity outcomes, and document templates. Ensure … traceability between security risk assessments, controls, and compliance objectives across the aircraft systems and software architecture. Coordinate the development of cybersecurity methods and processes, contributing to their alignment with recognised standards. Engage with DAG's internal stakeholders, including engineering, safety, and systems integration teams, to embed cybersecurity into the design and certification lifecycle. Act as the primary technical interface … cybersecurity engineering principles in the context of safety-critical systems and regulated environments. Demonstrated experience leading the development of cybersecurity assurance artefacts for certification programmes. Practical understanding of airworthiness risk modelling, threat identification, attack surface reduction, and aircraft-level threat scenarios. Ability to produce certification-ready documentation aligned to EASA/UK CAA guidance, including traceability to compliance objectives. More ❯
certification artefact production aligned to EASA and UK CAA expectations. Lead the development and review of cybersecurity documentation, including the PSecAC (Airworthiness Security Process Plan), PASRA (Preliminary Aircraft Security RiskAssessment), ASAM (Aircraft Security Architecture Model), and Security Verification Methods. Provide input into the AWSP frameworks, including the tailoring of compliance checklists, activity outcomes, and document templates. Ensure … traceability between security risk assessments, controls, and compliance objectives across the aircraft systems and software architecture. Coordinate the development of cybersecurity methods and processes, contributing to their alignment with recognised standards. Engage with DAG's internal stakeholders, including engineering, safety, and systems integration teams, to embed cybersecurity into the design and certification lifecycle. Act as the primary technical interface … cybersecurity engineering principles in the context of safety-critical systems and regulated environments. Demonstrated experience leading the development of cybersecurity assurance artefacts for certification programmes. Practical understanding of airworthiness risk modelling, threat identification, attack surface reduction, and aircraft-level threat scenarios. Ability to produce certification-ready documentation aligned to EASA/UK CAA guidance, including traceability to compliance objectives. More ❯
Bristol, Avon, England, United Kingdom Hybrid / WFH Options
Adecco
Product Owner who thrives on driving innovation in complex, data-rich environments? Want to work at the cutting edge of insurance technology with a team shaping the future of riskassessment and underwriting? We're working with a fast-growing, tech-led business looking for a Product Owner to join a collaborative and high-performing team. This role More ❯
Gloucestershire, South West, United Kingdom Hybrid / WFH Options
Nextech Group Limited
cybersecurity technologies and initiatives. Role Overview As a Project Engineer, you will lead and implement IT projects for a diverse client base, with a strong focus on secure infrastructure, risk mitigation, and cybersecurity best practices . You'll work closely with clients, internal teams, and vendors to ensure projects are delivered efficiently, securely, and to the highest standards. Key … Microsoft technologies, networking, cloud platforms, and security tools. Hands-on experience implementing and managing cybersecurity solutions. Experience managing IT projects and coordinating multiple stakeholders. Excellent troubleshooting, problem-solving, and riskassessment skills. Strong communication skills, able to explain technical and security concepts to non-technical stakeholders. Ability to work independently and manage multiple projects concurrently. Benefits Salary up More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
Strata Construction Consulting
whom you will be expected to provide guidance and support as appropriate What you need to succeed Knowledge of, and experience in highway design, drainage strategy and design, flood riskassessment and management, utility design and planning as well as a good working knowledge of the Development Industry The ability to produce infrastructure masterplans, site appraisals, technical reports More ❯
The Custard Factory, Gibb Street, Birmingham, England
Dole PLC
recommendations for improvements Development Lifecycle Participation: Engage in testing activities throughout the software development lifecycle Collaborate with developers and business teams to understand requirements Provide input on test planning, riskassessment, and product quality Learning & Professional Development: Complete apprenticeship training modules and assessments Shadow experienced testers and participate in team knowledge sharing Develop understanding of software testing tools More ❯
with IMOS MRP 145 Safety manager. Administration of HSE-T and Authorisations records, ensuring the currency of personnel within the database. The production and publication of safety related documents (RiskAssessment, Safe Systems of Work, Meeting Minutes, etc.). The production and publication of IMOS working instructions ensuring document configuration management applied through document lifecycles. Conducting ergonomic training More ❯
197-205 HIGH STREET, PONDERS END, ENFIELD, England
FIRST RUNG LIMITED
information system. Understand and report error queries raised by the ESFA once returns have been submitted. Understand PDSAT reports and supporting the notification of senior management of any identified risk indicators. Keep track of incentive payments and contributions that are due. Send monthly report to finance so that employers can be paid and invoices in respect of contributions can … on file and renewed certificates are secured from employers within one month of expiry date. To ensure all live placements and apprenticeship employers have a valid health and safety Risk Assessment. Produce and circulate apprenticeship handovers to centre teams and assessors once all documentation has been complete. Provide administrative support to MI and Data officer and centre teams when More ❯