with business objectives. Key Duties/Responsibilities Strategy & Planning Develop and implement cybersecurity strategies aligned with organisational goals and industry standards. Identify and deploy cybersecurity solutions that balance cost, risk, and organisational needs. Create and execute security roadmaps, ensuring alignment with Agile project delivery methodologies. Work with the Global Information Security Officer to participate in the design and architecture … lifecycle. Team Management Lead and manage an outsourced Security Operations Centre (SOC) team and Cyber Security Analysts. Collaborate with internal teams and external vendors to optimise cybersecurity operations. Compliance & Risk Management Plan and conduct annual PCI DSS compliance assessments in collaboration with qualified security assessors, maintaining and communicating cybersecurity risk registers to business stakeholders. Perform third-party riskMore ❯
multidisciplinary delivery environments. Responsibilities Lead or support integrating cybersecurity assurance activities into engineering and programme delivery for marine and defence projects. Develop, review, and maintain cybersecurity assurance artefacts, including risk assessments, assurance cases, control matrices, and evidence submissions. Ensure alignment with applicable defence and industry standards and other MOD-aligned frameworks. Engage with engineering and project teams to ensure … governance. Liaise with client representatives, suppliers, and accreditation authorities to support the assurance lifecycle and manage stakeholder expectations. Support the preparation for and participation in technical reviews, audits, and risk acceptance activities. Contribute to delivering security risk management processes, threat modelling sessions, and security design assessments. Provide subject matter expertise on assurance requirements for secure communications, supply chain … on the programme needs. Evidence of ongoing professional development aligned with cybersecurity assurance, defence sector standards, and engineering-led delivery models. Essential skills Strong understanding of cybersecurity assurance principles, risk management, and regulatory compliance in defence or safety-critical environments. Proven ability to produce and review assurance artefacts, including security management plans, risk registers, assurance cases, and audit More ❯
Hatfield, England, United Kingdom Hybrid / WFH Options
Eisai EMEA
/or CISSP or other relevant certification is highly desirable ISO 27001:2022 Lead Implementer/Auditor certification is highly desirable Demonstratable experience in an Information Security, IT Governance, Risk and Compliance based role, including maintaining and continually improving an ISO 27001 compliant management system. Experience of information security management and/or security awareness. Good knowledge of industry … NIS2, AI Act etc. and their practical application in a corporate environment to ensure all elements of integrity, availability and confidentiality are adhered to. Extensive experience conducting information security risk assessments, reporting risks Experience of developing, implementing, managing, and maintaining Information Security policies, guidance, & procedures. Experience of risk management and maintaining risk registers. Knowledge & experience of risk … England, United Kingdom 3 weeks ago Cyber Security Manager - Tesco Mobile Ireland Cyber Security Manager - Tesco Mobile Ireland London, England, United Kingdom 1 week ago Senior Director of Governance, Risk, Compliance & Privacy London, England, United Kingdom 1 week ago London, England, United Kingdom 2 days ago Security Analyst, Security Operations and Incident Response London, England, United Kingdom 1 week More ❯
multidisciplinary delivery environments. Responsibilities Lead or support integrating cybersecurity assurance activities into engineering and programme delivery for marine and defence projects. Develop, review, and maintain cybersecurity assurance artefacts, including risk assessments, assurance cases, control matrices, and evidence submissions. Ensure alignment with applicable defence and industry standards and other MOD-aligned frameworks. Engage with engineering and project teams to ensure … governance. Liaise with client representatives, suppliers, and accreditation authorities to support the assurance lifecycle and manage stakeholder expectations. Support the preparation for and participation in technical reviews, audits, and risk acceptance activities. Contribute to delivering security risk management processes, threat modelling sessions, and security design assessments. Provide subject matter expertise on assurance requirements for secure communications, supply chain … on the programme needs. Evidence of ongoing professional development aligned with cybersecurity assurance, defence sector standards, and engineering-led delivery models. Essential Skills Strong understanding of cybersecurity assurance principles, risk management, and regulatory compliance in defence or safety-critical environments. Proven ability to produce and review assurance artefacts, including security management plans, risk registers, assurance cases, and audit More ❯
Sphere Recruitment Specialists - Permanent, Contract and Interim Recruitment
value projects across multiple industries. Managing the full project lifecycle – from planning and scoping through to delivery and reporting. Creating and maintaining detailed documentation including project plans, RAID logs, risk registers, and status updates. Coordinating with cross-functional teams and stakeholders to ensure aligned and timely delivery. Supporting business development activities such as RFPs, tenders, and proposal writing. Facilitating More ❯
Watford, England, United Kingdom Hybrid / WFH Options
Essential Employment
Senior Cybersecurity Risk Analyst (Remote) needed, £28.49ph PAYE – Reference: RQ1548059 Role Overview We are looking for a highly skilled and technically proficient Senior Cybersecurity Risk Analyst to join our team on an interim basis. This role is critical in identifying, assessing, and managing information security risks across the organization. The ideal candidate will have a strong technical background … the ability to translate threats into business risks, and experience working in fast-paced environments. Key Responsibilities – Conduct in-depth security risk assessments across systems, applications, and infrastructure. – Identify and evaluate technical and operational risks, vulnerabilities, and control gaps. – Translate complex technical threats into clear, actionable business risks. – Maintain and update the Cybersecurity Risk Register. – Produce detailed risk … the Security Operations Centre (SOC). – Support compliance with relevant standards (e.g. ISO 27001, NIST, UK GDPR). – Review security aspects of tenders and conduct third-party/vendor risk assessments to ensure alignment with organisational security requirements. – Perform additional security-related tasks as directed by the Head of Information Security You will Ideally have – – Proven experience in technical More ❯
Watford, Hertfordshire, South East, United Kingdom Hybrid / WFH Options
Hays
Role Overview We're looking for an experienced Senior Cyber Risk Analyst to join a purpose-driven organisation on a part-time basis . In this role, you'll take the lead in strengthening the organisation's security posture by driving forward incident response, vulnerability management, and compliance initiatives. You'll be a key player in embedding security best … Work 7-hour days, 3 days a week Act as a trusted advisor on information security matters, supporting projects, solution development, and change initiatives with expert guidance. Perform regular risk evaluations to uncover and address potential security gaps. Lead the end-to-end management of security incidents, ensuring swift and effective resolution. Design and deliver engaging training sessions to … Essentials Plus, ISO 27001, and PCI DSS. What you'll need to succeed Willingness to work 7-hour days, 3 days a week Demonstrated expertise in conducting technical security risk assessments and developing threat models. Comprehensive knowledge of core cybersecurity domains, including network, endpoint, and cloud security. Skilled at translating technical vulnerabilities into business-relevant language for diverse audiences. More ❯
Employment Type: Part Time, Work From Home
Salary: £28.49 - £36.98 per hour + £36.98 p/h via Umbrella (Inside IR35)
Newport, Gwent, Wales, United Kingdom Hybrid / WFH Options
Reed Technology
This role is crucial in ensuring IT risks are identified, measured, and actively managed to protect the organisation from potential impacts. You will develop and implement IT policies, conduct risk assessments, and ensure compliance with regulatory requirements while driving improvements in IT governance processes. Key Accountabilities * Identify, evaluate, and manage IT risks across infrastructure, data protection, and lifecycle management. … Own and maintain the IT riskregister, ensuring mitigation plans are in place. * Align risk management frameworks with industry standards (ISO27001, NIST, CIS Critical Controls). * Lead IT audits, coordinate fieldwork, and track findings to ensure timely resolution. * Develop and implement IT policies, procedures, and security awareness initiatives. * Act as an SME, providing guidance on IT governance … compliance, and risk mitigation strategies. Required Skills & Qualifications * Proven experience in IT risk management, security governance, and compliance. * Strong knowledge of ISO27001, GDPR, PCI-DSS, and cybersecurity frameworks. * Experience in IT audit coordination and risk assessment methodologies. * Excellent communication and stakeholder management skills. * Desirable - Certifications such as CRISC, CISA, CISM, or CISSP Benefits * 10% discretionary performance related More ❯
adheres to best practices and legislation in data protection, information security, quality management, environmental compliance and industry-specific security standards. The ideal candidate will have experience in compliance management, risk assessment, audits, security frameworks and policy implementation. They will need to work across teams such as IT, Operations, Finance, Delivery and Engineering to ensure robust governance, risk management … and compliance Information security and Cyber Essentials Plus Oversee Cyber Essentials Plus compliance ensuring security controls are in place Work closely with the IT team to assess vulnerabilities, manage risk and implement cyber security policies Work with the Head of IT to manage incident response planning and ensure security incidents are managed in line with best practices Data protection … Assessments (DPIAs) Implement processes around Data Subject Access Requests (DSARs) and breach management Ensure compliance with any client and third-party data processing agreements (DPAs) and data retention rules Risk management and policy development Review, update, maintain and enforce policies and procedures related to: Information security Data protection Environmental sustainability Business continuity Incident response Supplier security assessment Maintain a More ❯
adheres to best practices and legislation in data protection, information security, quality management, environmental compliance and industry-specific security standards. The ideal candidate will have experience in compliance management, risk assessment, audits, security frameworks and policy implementation. They will need to work across teams such as IT, Operations, Finance, Delivery and Engineering to ensure robust governance, risk management … and compliance Information security and Cyber Essentials Plus Oversee Cyber Essentials Plus compliance ensuring security controls are in place Work closely with the IT team to assess vulnerabilities, manage risk and implement cyber security policies Work with the Head of IT to manage incident response planning and ensure security incidents are managed in line with best practices Data protection … Assessments (DPIAs) Implement processes around Data Subject Access Requests (DSARs) and breach management Ensure compliance with any client and third-party data processing agreements (DPAs) and data retention rules Risk management and policy development Review, update, maintain and enforce policies and procedures related to: Information security Data protection Environmental sustainability Business continuity Incident response Supplier security assessment Maintain a More ❯
Belfast, Northern Ireland, United Kingdom Hybrid / WFH Options
McLaughlin & Harvey
Harvey's IT environment and enterprise applications, you will be responsible for the operational management of the Company's Information Security Management System and ensuring that our IT governance, risk management, and compliance measures are effective and implemented. The role will support the implementation and maintenance of security controls across the group, aligned with our cyber security policy, group … are as secure as possible. Create and maintain security documents (policies, standards, baselines, guidelines, and procedures). Maintain & improve Business Continuity and Disaster Recovery plans. Contribute to the IT riskregister and mitigation plans. Ensure Endpoint security compliance, including Mobile Device Management. Organise audits, external and internal vulnerability scans, web, infrastructure and application penetration tests and ensure remediation … effectively with technical and non-technical colleagues at all levels in the organisation. Essential Previous experience within a cyber/information security role. Strong knowledge and understanding of security risk assessment, including security testing principles and tools. Network, operating system, application and organisational security concepts. An investigative and analytical nature with a focus on ensuring the organisation is as More ❯
colleagues from across Projects and Programme Delivery. Your Responsibilities include: Managing the whole life project delivery process for our client sponsors. Applying strong commercial acumen in project, contract, and risk management, ensuring delivery of high-quality projects to time and budget. Working collaboratively with our suppliers, client representatives, technical specialists, and other partners to deliver successful outcomes. Monitoring and … forecasting expenditure, ensuring compliance with EA guidance. Using project management tools to aid development and maintenance of business cases, programmes, trackers and risk registers. Administering contracts with supply chain in accordance with framework policy. Making project decisions supported by the Project Executive and informed by technical leads whilst following governance procedures, project assurance and legislation. Everyone that joins us … on incident response can be found within your candidate pack. The team The Innovation Delivery Group (IDG) specialises in delivering complex national projects and programmes that drive innovation, manage risk, and support Environment Agency’s 2025 action plan. The group is part of Projects and Programme Delivery (PPD) within the Flood and Coastal Risk Management (FCRM) directorate. The More ❯
Newport, Gwent, Wales, United Kingdom Hybrid / WFH Options
Reed Technology
IT Risk & Compliance Manager Location: Newport Job Type: Full-time, Hybrid (1 day per week) Salary: 60 - 70K plus benefits We are seeking an IT Risk & Compliance Manager to join our client's IT team. This role is crucial in ensuring IT risks are identified, measured, and actively managed to protect the organisation from potential impacts. You will … develop and implement IT policies, conduct risk assessments, and ensure compliance with regulatory requirements while driving improvements in IT governance processes. Key Accountabilities * Identify, evaluate, and manage IT risks across infrastructure, data protection, and lifecycle management. * Own and maintain the IT riskregister, ensuring mitigation plans are in place. * Align risk management frameworks with industry standards … fieldwork, and track findings to ensure timely resolution. * Develop and implement IT policies, procedures, and security awareness initiatives. * Act as an SME, providing guidance on IT governance, compliance, and risk mitigation strategies. Required Skills & Qualifications * Proven experience in IT risk management, security governance, and compliance. * Strong knowledge of ISO27001, GDPR, PCI-DSS, and cybersecurity frameworks. * Experience in IT More ❯
Rogerstone, Gwent, United Kingdom Hybrid / WFH Options
Reed Technology
IT Risk & Compliance Manager Location: Newport Job Type: Full-time, Hybrid (1 day per week) Salary: 60 - 70K plus benefits We are seeking an IT Risk & Compliance Manager to join our client's IT team. This role is crucial in ensuring IT risks are identified, measured, and actively managed to protect the organisation from potential impacts. You will … develop and implement IT policies, conduct risk assessments, and ensure compliance with regulatory requirements while driving improvements in IT governance processes. Key Accountabilities Identify, evaluate, and manage IT risks across infrastructure, data protection, and lifecycle management. Own and maintain the IT riskregister, ensuring mitigation plans are in place. Align risk management frameworks with industry standards … fieldwork, and track findings to ensure timely resolution. Develop and implement IT policies, procedures, and security awareness initiatives. Act as an SME, providing guidance on IT governance, compliance, and risk mitigation strategies. Required Skills & Qualifications Proven experience in IT risk management, security governance, and compliance. Strong knowledge of ISO27001, GDPR, PCI-DSS, and cybersecurity frameworks. Experience in IT More ❯
escalation routes, and RAG-rate accordingly Ensure accurate and timely reporting to internal governance structures Coordinate project documentation, audit trails, and evidence for funding compliance Maintain and update programme risk registers, working with Finance, Assurance and Delivery teams Lead on monthly SPOC site visits and implementation checks with stakeholders Contribute to wider programme planning, communications, procurement, and evaluation activity … in project or programme management, ideally within energy, construction, regeneration, or public services A clear understanding of grant-funded programme delivery, monitoring and compliance Strong skills in stakeholder engagement, risk management, and financial forecasting Experience in analysing performance data and presenting recommendations Excellent interpersonal and communication skills across technical and non-technical audiences Ability to manage competing priorities and … a week spent in the office. How to apply . Applying for a role with WMCA is straight forward. Follow these steps to get started. Create your Careers Account. Register with your name, email address, and a password. Build your Profile. Upload your CV to help populate your career and education details. Write your Supporting Statement. Make sure to More ❯
system design, deployment, and ongoing operations. Define cybersecurity requirements within the client's environment, including rail-specific systems, legacy OT, and modern industrial platforms. Support developing and delivering security risk assessments, threat models, and control frameworks following the relevant standards. Contribute to the production and review of assurance artefacts, including security cases, risk registers, control implementation evidence, and … depth understanding of operational technology (OT) environments, including SCADA systems, field devices, industrial protocols, and control network architectures. Firm grounding in cybersecurity principles for critical infrastructure, including threat modelling, risk analysis, defence-in-depth, and zero-trust architectures. Demonstrated ability to define, implement, and assure security controls across complex OT/IT systems within large engineering or infrastructure programmes. … safety standards. Strong communication and stakeholder engagement skills, with the ability to liaise confidently across engineering, programme delivery, assurance, and regulatory audiences. Ability to produce high-quality documentation, including risk assessments, technical guidance, assurance artefacts, and audit-ready deliverables. Familiarity with UK cybersecurity regulations and sector guidance, including the NIS Regulations, CNI expectations, and industry-specific frameworks. Capable of More ❯
system design, deployment, and ongoing operations. Define cybersecurity requirements within the client's environment, including rail-specific systems, legacy OT, and modern industrial platforms. Support developing and delivering security risk assessments, threat models, and control frameworks following the relevant standards. Contribute to the production and review of assurance artefacts, including security cases, risk registers, control implementation evidence, and … depth understanding of operational technology (OT) environments, including SCADA systems, field devices, industrial protocols, and control network architectures. Firm grounding in cybersecurity principles for critical infrastructure, including threat modelling, risk analysis, defence-in-depth, and zero-trust architectures. Demonstrated ability to define, implement, and assure security controls across complex OT/IT systems within large engineering or infrastructure programmes. … safety standards. Strong communication and stakeholder engagement skills, with the ability to liaise confidently across engineering, programme delivery, assurance, and regulatory audiences. Ability to produce high-quality documentation, including risk assessments, technical guidance, assurance artefacts, and audit-ready deliverables. Familiarity with UK cybersecurity regulations and sector guidance, including the NIS Regulations, CNI expectations, and industry-specific frameworks. Capable of More ❯
being a key partner in the design of success factors, solutions, and compliance. Implement the Technology Strategy & Innovation for your area of responsibility Organize outputs aligned to the Technology risk strategy, internal controls, and budget of internal resourcing and partnerships to assure Technology Compliance to best practice and regulatory compliance (including but not limited to data protection compliance (e.g. … ESG, Cyber laws). Manage and coordinate a Zero data or Technology loss approach, internal controls, and budget of internal resourcing and partnerships to manage and optimize the Cyber Risk landscape. Drive a proactive, predictive, and continuous improvement Cyber Risks managed environment. Drive the Information Technology Security Programme across the SBV landscape to protect its applications and supporting infrastructure … alignment with organizational readiness. Implement the Design for your Area of Responsibility Design and manage a roadmap for information security related to internal controls, compliance, regulatory, and a proactive risk mitigation plan for the Technology department. Design, implement, and monitor a comprehensive enterprise information security and IT risk management program in alignment with the Technology Risk strategy. More ❯
various team members in the Information Technology department to ensure that systems and networks are always designed, developed, deployed, and managed with an emphasis on strong, effective security and risk management controls. The Cyber Security Analyst leads the firm's vulnerability management program, manages the annual cybersecurity assessments and penetration tests, and researches and reports on emerging threats to … help the firm take pre-emptive risk mitigation steps. Effectively correlates and analyzes security events within UFP's systems environment to proactively detect threats and mitigate attacks before they occur. Cyber Security Analyst Duties and Responsibilities: Studies evolving threats and other industry developments related to cyber security. Researches/evaluates emerging cyber security threats and ways to manage them. … users. Liaises with stakeholders in relation to cyber security issues and provides future recommendations. Generates reports for both technical and non-technical staff and stakeholders. Maintains an information security riskregister and assists with internal and external audits relating to information security. Creates and conducts employee training programs related to cyber security. Monitors and mitigates 'phishing' emails and More ❯
Location: UK, Remote ? Contract Type: Inside IR35 Responsibilities ?️ Acting as the primary security lead for the Digitalisation programme and associated digital solutions ? Producing and presenting monthly security governance reports, risk registers, and security cases ️ Leading risk assessments, managing mitigation controls, and contributing to DPIAs ? Supporting HMG Secure-by-Design assurance across the entire delivery lifecycle ?️ Feeding into control … frameworks such as GovAssure, NCSC CAF, ISO27001 Requirements: ? In-depth knowledge of NIST, ISO27001, ISO27701, NCSC, and Cabinet Office security best practices Proven track record across full security lifecycle: risk management, governance, incidents, pen testing ?️ Experience working in the UK Public Sector, ideally with the NHS/NHSE and government design principles ️ Hands-on experience in Agile/DevOps More ❯
Location: UK, Remote ? Contract Type: Inside IR35 Responsibilities ?️ Acting as the primary security lead for the Digitalisation programme and associated digital solutions ? Producing and presenting monthly security governance reports, risk registers, and security cases ️ Leading risk assessments, managing mitigation controls, and contributing to DPIAs ? Supporting HMG Secure-by-Design assurance across the entire delivery lifecycle ?️ Feeding into control … frameworks such as GovAssure, NCSC CAF, ISO27001 Requirements: ? In-depth knowledge of NIST, ISO27001, ISO27701, NCSC, and Cabinet Office security best practices Proven track record across full security lifecycle: risk management, governance, incidents, pen testing ?️ Experience working in the UK Public Sector, ideally with the NHS/NHSE and government design principles ️ Hands-on experience in Agile/DevOps More ❯
Location: UK, Remote ? Contract Type: Inside IR35 Responsibilities ?️ Acting as the primary security lead for the Digitalisation programme and associated digital solutions ? Producing and presenting monthly security governance reports, risk registers, and security cases ️ Leading risk assessments, managing mitigation controls, and contributing to DPIAs ? Supporting HMG Secure-by-Design assurance across the entire delivery lifecycle ?️ Feeding into control … frameworks such as GovAssure, NCSC CAF, ISO27001 Requirements: ? In-depth knowledge of NIST, ISO27001, ISO27701, NCSC, and Cabinet Office security best practices Proven track record across full security lifecycle: risk management, governance, incidents, pen testing ?️ Experience working in the UK Public Sector, ideally with the NHS/NHSE and government design principles ️ Hands-on experience in Agile/DevOps More ❯
Location: UK, Remote ? Contract Type: Inside IR35 Responsibilities ?️ Acting as the primary security lead for the Digitalisation programme and associated digital solutions ? Producing and presenting monthly security governance reports, risk registers, and security cases ️ Leading risk assessments, managing mitigation controls, and contributing to DPIAs ? Supporting HMG Secure-by-Design assurance across the entire delivery lifecycle ?️ Feeding into control … frameworks such as GovAssure, NCSC CAF, ISO27001 Requirements: ? In-depth knowledge of NIST, ISO27001, ISO27701, NCSC, and Cabinet Office security best practices Proven track record across full security lifecycle: risk management, governance, incidents, pen testing ?️ Experience working in the UK Public Sector, ideally with the NHS/NHSE and government design principles ️ Hands-on experience in Agile/DevOps More ❯
Bridgwater, Somerset, South West, United Kingdom Hybrid / WFH Options
Walsh Employment
party providers Promoting a culture of collaboration, transparency, and service excellence Key Deliverables End-to-end IT service governance and assurance Up-to-date licensing schedules , cost controls, and risk registers Effective reporting on service metrics , issues, and compliance gaps Coordination of risk management , change control, and continuous improvement Delivery of reliable, secure, and scalable IT services aligned More ❯
Bridgwater, England, United Kingdom Hybrid / WFH Options
ZipRecruiter
party providers Promoting a culture of collaboration, transparency, and service excellence Key Deliverables End-to-end IT service governance and assurance Up-to-date licensing schedules , cost controls, and risk registers Effective reporting on service metrics , issues, and compliance gaps Coordination of risk management , change control, and continuous improvement Delivery of reliable, secure, and scalable IT services aligned More ❯