Aberdeen, Aberdeenshire, United Kingdom Hybrid / WFH Options
Orion Group
We have a current opportunity for a Senior InfoSec Advisor (IRM Manager) on a 12 month PAYE contract basis. The position will be based in Aberdeen and will have a 3/2 hybrid working pattern Key ResponsibilitiesRisk Assessment & Secure by Design Perform structured IT and informationsecurity risk assessments and threat modelling for new IT platforms, systems … and applications and for material changes. Provide security architecture advice (patterns, guardrails) aligned to NIST CSF/ISO 27001 and company standards. Define and agree control selection (prevent/detect/correct) proportionate to risk, including identity, data and platform controls. Conduct IT control walkthroughs to validate design and operating effectiveness; document evidence and issues. LOD2 Assurance & Critical Assets … test scopes, frequency and metrics. Track high-risk deviations and risk acceptances; drive remediation and report residual risk to the CISO, CIO and business risk owners. OT/ICS Security Own the LOD2 assurance plan across OT sites against the OT security standard, deciding the order and frequency of assessments aligned to risk and risk appetite. Provide OT More ❯
Aberdeen, City of Aberdeen, United Kingdom Hybrid / WFH Options
Orion Group
We have a current opportunity for a Senior InfoSec Advisor (IRM Manager) on a 12 month PAYE contract basis. The position will be based in Aberdeen and will have a 3/2 hybrid working pattern Key ResponsibilitiesRisk Assessment & Secure by Design Perform structured IT and informationsecurity risk assessments and threat modelling for new IT platforms, systems … and applications and for material changes. Provide security architecture advice (patterns, guardrails) aligned to NIST CSF/ISO 27001 and company standards. Define and agree control selection (prevent/detect/correct) proportionate to risk, including identity, data and platform controls. Conduct IT control walkthroughs to validate design and operating effectiveness; document evidence and issues. LOD2 Assurance & Critical Assets … test scopes, frequency and metrics. Track high-risk deviations and risk acceptances; drive remediation and report residual risk to the CISO, CIO and business risk owners. OT/ICS Security Own the LOD2 assurance plan across OT sites against the OT security standard, deciding the order and frequency of assessments aligned to risk and risk appetite. Provide OT More ❯
We have a current opportunity for a Senior InfoSec Advisor (IRM Manager) on a 12 month PAYE contract basis Key Responsibilities Discovery & Portfolio Shaping Run discovery with process owners; agree scope, outcomes and success measures; map AS-IS/TO-BE and identify simplification opportunities. Elicit and document requirements (user stories/use cases, acceptance criteria); maintain traceability into testing … Champion data quality, reconciliations and reporting enablement; maintain interface contracts and runbooks. Controls, Risk & Compliance Embed SoD, Joiner-Mover-Leaver and GDPR controls; maintain audit-ready evidence. Coordinate with Information Risk Management and Architecture on risk acceptance and remediation. Vendor & AMS Governance Act as day-to-day interface to AMS and ISVs: prioritise backlog, agree estimates/timelines; manage More ❯
We have a current opportunity for a Senior InfoSec Advisor (IRM Manager) on a 12 month PAYE contract basis Key Responsibilities Discovery & Portfolio Shaping Run discovery with process owners; agree scope, outcomes and success measures; map AS-IS/TO-BE and identify simplification opportunities. Elicit and document requirements (user stories/use cases, acceptance criteria); maintain traceability into testing … Champion data quality, reconciliations and reporting enablement; maintain interface contracts and runbooks. Controls, Risk & Compliance Embed SoD, Joiner-Mover-Leaver and GDPR controls; maintain audit-ready evidence. Coordinate with Information Risk Management and Architecture on risk acceptance and remediation. Vendor & AMS Governance Act as day-to-day interface to AMS and ISVs: prioritise backlog, agree estimates/timelines; manage More ❯