Aberdeen, Aberdeenshire, United Kingdom Hybrid/Remote Options
Orion Group
a current opportunity for a Senior InfoSec Advisor (IRM Manager) on a 12 month PAYE contract basis. The position will be based in Aberdeen and will have a 3 / 2 hybrid working pattern Key ResponsibilitiesRisk Assessment & Secure by Design Perform structured IT and information security risk assessments and threat modelling for new IT platforms, systems, and applications and … for material changes. Provide security architecture advice (patterns, guardrails) aligned to NIST CSF /ISO27001 and company standards. Define and agree control selection (prevent / detect / correct) proportionate to risk, including identity, data and platform controls. Conduct IT control walkthroughs to validate design and operating effectiveness; document evidence and issues. LOD2 … systems; define test scopes, frequency and metrics. Track high-risk deviations and risk acceptances; drive remediation and report residual risk to the CISO, CIO and business risk owners. OT / ICS Security Own the LOD2 assurance plan across OT sites against the OT security standard, deciding the order and frequency of assessments aligned to risk and risk appetite. Provide More ❯
Aberdeen, City of Aberdeen, United Kingdom Hybrid/Remote Options
Orion Group
a current opportunity for a Senior InfoSec Advisor (IRM Manager) on a 12 month PAYE contract basis. The position will be based in Aberdeen and will have a 3 / 2 hybrid working pattern Key ResponsibilitiesRisk Assessment & Secure by Design Perform structured IT and information security risk assessments and threat modelling for new IT platforms, systems, and applications and … for material changes. Provide security architecture advice (patterns, guardrails) aligned to NIST CSF /ISO27001 and company standards. Define and agree control selection (prevent / detect / correct) proportionate to risk, including identity, data and platform controls. Conduct IT control walkthroughs to validate design and operating effectiveness; document evidence and issues. LOD2 … systems; define test scopes, frequency and metrics. Track high-risk deviations and risk acceptances; drive remediation and report residual risk to the CISO, CIO and business risk owners. OT / ICS Security Own the LOD2 assurance plan across OT sites against the OT security standard, deciding the order and frequency of assessments aligned to risk and risk appetite. Provide More ❯
to meet GDPR and regulatory requirements. * Prevent configuration drift and maintain parity with production where required. * Governance & Compliance * Ensure compliance with Digital Operational Resilience Act ICT change management, ISO27001, and internal audit requirements. * Maintain documentation and evidence for regulatory inspections and audits. * Conduct risk assessments for releases and environment changes; implement mitigation plans. Stakeholder Engagement … Proven ability to drive large-scale cultural and technological change across diverse and sometimes conflicting product and operations teams. Technical Acumen: Strategic understanding of modern software architecture (microservices), CI / CD toolchains, DevOps principles, and large-scale environment virtualisation / containerisation technologies (e.g., Kubernetes). Regulatory Knowledge: Understanding of compliance requirements related to IT Release or Change Management … practices, such as DORA, FCA / PRA, ISO standards). Methodologies: Experience with scaled agile frameworks (e.g., SAFe) and other SDLC methodologies Job Offer Daily rate of £869 a day inside IR35. Opportunity to contribute to high-impact projects within the financial services industry. Be part of a professional and supportive technology team. If you are ready More ❯
delivering complex cyber advisory projects in consulting environments, with demonstrable success engaging senior stakeholders. Recognised professional qualifications (e.g., CISSP, CISM, CCSP, ISO27001 Lead Auditor / Implementer, MSc Information Security). Outstanding strategic, analytical, and leadership skills; credible communicator able to distil technical concepts for executive audiences. Track record of building client trust, managing relationships More ❯
AD / Entra ID . Working knowledge of Azure Sentinel (SIEM) and KQL. Solid understanding of patch management and endpoint security. Previous involvement in Cyber Essentials Plus or ISO27001 accreditation. Clear communication skills, able to engage technical and non-technical stakeholders. Why Join You'll be stepping into a critical transformation phase where your input genuinely shapes the business. More ❯