I&T Governance and Risk Lead, the GRC specialist will support: Digital security awareness and culture activities including driving ethical phishing and e-learning campaigns. Specification and facilitation of cyber scenario simulations. Supplier security assurance activities. Provision of digital security and technology risk advice and guidance. Facilitate and support IT risk management processes and continuous improvement. The GRC Specialist … travel, ‘on-site’ visits in support of the business engagement outlined. About you Knowledge and experience working with information security standards and frameworks such as ISO, NIST, ISF SOGP, CyberEssentials, etc. Ability to communicate clearly and effectively across all management levels of the company, particularly when articulating complex IT concepts to non-IT stakeholders. Knowledge and experience More ❯
London, England, United Kingdom Hybrid / WFH Options
Scott Logic
end-user experience Establish, operate and govern common platforms for collaboration, DevOps tooling, data management and business applications (e.g., Finance, HR, CRM) across all entities Own the group-wide cyber‐security posture: set policy, oversee risk assessments, incident response and third‐party vendor assurance in accordance with recognised standards such as ISO27001 and CyberEssentials Plus Develop … Data Expertise Deep understanding of software development lifecycles, DevOps and cloud‐native architectures Board‐level communication skills with experience influencing diverse stakeholder groups Fluent understanding of UK data protection, cyber standards and financial regulations Willingness to travel to other offices as required What you’ll get in return is: Hybrid working 25 days’ annual leave, rising to 30 days More ❯
end-user experience. Establish, operate, and govern common platforms for collaboration, DevOps tooling, data management, and business applications (e.g., Finance, HR, CRM) across all entities. Own the group-wide cyber security posture: set policy, oversee risk assessments, incident response, and third party vendor assurance in accordance with recognised standards such as ISO27001 and CyberEssentials Plus. Develop … transformation programmes. Deep understanding of software development lifecycles, DevOps, and cloud native architectures. Board level communication skills with experience influencing diverse stakeholder groups. Fluent understanding of UK data protection, cyber standards, and financial regulations. Willingness to travel to other offices as required. What you'll get in return: Hybrid working with 1 day a week in the office. More ❯
Leeds, Yorkshire, United Kingdom Hybrid / WFH Options
Scott Logic Ltd
end-user experience. Establish, operate, and govern common platforms for collaboration, DevOps tooling, data management, and business applications (e.g., Finance, HR, CRM) across all entities. Own the group-wide cyber security posture: set policy, oversee risk assessments, incident response, and third party vendor assurance in accordance with recognised standards such as ISO27001 and CyberEssentials Plus. Develop … transformation programmes. Deep understanding of software development lifecycles, DevOps, and cloud native architectures. Board level communication skills with experience influencing diverse stakeholder groups. Fluent understanding of UK data protection, cyber standards, and financial regulations. Willingness to travel to other offices as required. What you'll get in return: Hybrid working with 1 day a week in the office. More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
Scott Logic Ltd
end-user experience. Establish, operate, and govern common platforms for collaboration, DevOps tooling, data management, and business applications (e.g., Finance, HR, CRM) across all entities. Own the group-wide cyber security posture: set policy, oversee risk assessments, incident response, and third party vendor assurance in accordance with recognised standards such as ISO27001 and CyberEssentials Plus. Develop … transformation programmes. Deep understanding of software development lifecycles, DevOps, and cloud native architectures. Board level communication skills with experience influencing diverse stakeholder groups. Fluent understanding of UK data protection, cyber standards, and financial regulations. Willingness to travel to other offices as required. What you'll get in return: Hybrid working with 1 day a week in the office. More ❯
Newcastle Upon Tyne, Tyne And Wear, United Kingdom Hybrid / WFH Options
Scott Logic Ltd
end-user experience. Establish, operate, and govern common platforms for collaboration, DevOps tooling, data management, and business applications (e.g., Finance, HR, CRM) across all entities. Own the group-wide cyber security posture: set policy, oversee risk assessments, incident response, and third party vendor assurance in accordance with recognised standards such as ISO27001 and CyberEssentials Plus. Develop … transformation programmes. Deep understanding of software development lifecycles, DevOps, and cloud native architectures. Board level communication skills with experience influencing diverse stakeholder groups. Fluent understanding of UK data protection, cyber standards, and financial regulations. Willingness to travel to other offices as required. What you'll get in return: Hybrid working with 1 day a week in the office. More ❯
Bristol, England, United Kingdom Hybrid / WFH Options
Scott Logic Ltd
end-user experience. Establish, operate, and govern common platforms for collaboration, DevOps tooling, data management, and business applications (e.g., Finance, HR, CRM) across all entities. Own the group-wide cyber‐security posture: set policy, oversee risk assessments, incident response, and third‐party vendor assurance in accordance with recognised standards such as ISO27001 and CyberEssentials Plus. Develop … transformation programmes. Deep understanding of software development lifecycles, DevOps, and cloud‐native architectures. Board‐level communication skills with experience influencing diverse stakeholder groups. Fluent understanding of UK data protection, cyber standards, and financial regulations. Willingness to travel to other offices as required. What you’ll get in return: Hybrid working with 1 day a week in the office. More ❯
and introduce efficiencies throughout the organisation. Key Responsibilities Lead and manage internal IT systems, infrastructure, and information security practices. Oversee compliance with recognised standards such as GDPR , ISO27001:2022 , CyberEssentials , and SOC2 Type II . Coordinate audit readiness, compile evidence, liaise with auditors, and address any gaps or risks. Collaborate with engineering teams to embed secure coding … onboarding/offboarding processes, and device compliance using SSO/SCIM and MDM platforms. Conduct third-party risk reviews and manage SaaS vendor compliance. Monitor and respond to evolving cyber threats, providing advice to senior stakeholders. Ideal Profile 5+ years of experience in enterprise IT or information security — ideally within SaaS , B2B , or fast-paced environments. Deep knowledge of More ❯
lead on IT and business transformation projects. Monitoring system performance, capacity, and availability - and planning smart enhancements. Supporting compliance with SOx, audit and security standards such as ISO27001 and Cyber Essentials. Investigating and resolving incidents, supporting users, and ensuring root cause analysis is actioned. Mentoring junior colleagues and shaping the multi-year IT strategy with your SAP expertise. What … business requirements into robust, scalable solutions Excellent communication and stakeholder engagement skills A degree in an IT-related field (or equivalent experience) Nice to have: Familiarity with UK GOV CyberEssentials, NIST, and ISO27001 Experience of working in regulated industries Passion for innovation, mentoring and continuous improvement What makes you stand out: You're a critical thinker, a More ❯
Resolve support tickets in our ticketing system within a timely manner. • Be the primary IT contact for our Bristol Office • Ensure Compliance and Security standards are met (ISO 27001, CyberEssentials) • Undertake administrative procedures such as account creation & deletion within Active Directory. • Proactively seek to improve the IT environment. • Install and configure hardware (firewalls, switches, servers etc...) • Utilise More ❯
business needs Capacity management Basic hardware maintenance of servers and PCs Significant experience of the following will be beneficial: Microsoft Exchange Server IT security frameworks such as ISO 27001, CyberEssentials DevOps tools and processes, including Team Foundation Server and containerization Free on-site gym 5% contributory pension Annual Team Tour 33 days holiday If you are interested More ❯
London, England, United Kingdom Hybrid / WFH Options
Hamilton Barnes Associates Limited
MSP. Strong technical knowledge across Microsoft 365, Windows OS, networking (LAN/WAN/VPN), and security protocols. Experience managing IT policies, compliance, and accreditations (e.g. GDPR, ISO 27001, CyberEssentials). Strong troubleshooting skills with the ability to step into technical issues when required. Excellent communication and leadership skills, able to work with all levels of the More ❯
department coordination Configure and maintain software, hardware, cloud services, and security policies (AD, Group Policy, MFA, Conditional Access) Drive improvements in service delivery, system performance, and security compliance (NIST, CyberEssentials) Support strategic IT projects and platform upgrades (including CI/CD pipelines and Azure maturity planning Manage service requests and incidents via Cherwell (or similar ITSM platforms More ❯
department coordination Configure and maintain software, hardware, cloud services, and security policies (AD, Group Policy, MFA, Conditional Access) Drive improvements in service delivery, system performance, and security compliance (NIST, CyberEssentials) Support strategic IT projects and platform upgrades (including CI/CD pipelines and Azure maturity planning Manage service requests and incidents via Cherwell (or similar ITSM platforms More ❯
to the architecture community of practice. Ability to design integrated digital solutions. Qualifications BS/MS degree in Computer Science, Engineering, or a related subject. TOGAF certification. CISSP or CyberEssentials is an advantage. Cloud certifications are an advantage. Essential Skills Good client-facing and communication skills. Proven capability to clearly and persuasively present complex information to senior More ❯
applications. As a specialist in secure technology solutions, all successful candidates will be subject to pre-employment checks, so we can ensure compliance with our ISO27001 (Information Security) and CyberEssentials Plus certifications. We are committed to using any personal information you may give us in a secure and proper manner, for more information please see our privacy More ❯
are used and secured against security audit controls Experience working with Global GRC tools and processes Extensive knowledge of at least 2 or more of the following compliance frameworks CyberEssentials plus, C5, NIST 800-53, PCI, SOC, ISO 27x Excellent written, verbal communication and presentation skills Big 4 Experience or Management Consulting Experience preferred Willingness to wear More ❯
Birmingham, England, United Kingdom Hybrid / WFH Options
Kerv Digital for Digital Transformation
databases, web APIs, etc Microsoft Fabric exposure Data Governance tools (e.g. Microsoft Purview) Master Data Management tools (e.g. CluedIn) Appreciation of information security standards such as ISO27001, PCI-DSS, CyberEssentials Azure Infrastructure and Networking Azure DevOps, Git, ARM/Bicep, and building CI/CD pipelines Desirable experience: Integration to D365 and working knowledge of Microsoft Common More ❯
internal and external functions Managing risk reporting and the risk register Supporting on audits and bolstering the ISMS methodology for ISO27001 certifications Contributing towards security policy creation Assisting with cyber security awareness Completing security risk assessments accurately and in a timely manner Managing and engaging with internal and external stakeholders on security questionnaires Advising on risk mitigation Advising on … contemporary threats and cyber trends to enhance the organisation's security Completing all of the above in line with the organisation's risk strategy, appetite, and framework. What we're looking for: Practical knowledge of various information security and risk frameworks and standards such as ISO27001, NIST, Cyber Essentials. GRC experience is essential (risk awareness, identification, articulation and … mitigation). Whilst this role won't see you utilising technical cyber security tools in your day-to-day, an understanding of technical cyber (threat, vulnerability, network security) is crucial, and prior practical experience is ideal. Excellent communication skills, ability to work at pace and deal with complex works, and a go-getter personality are all essential criteria More ❯
internal and external functions Managing risk reporting and the risk register Supporting on audits and bolstering the ISMS methodology for ISO27001 certifications Contributing towards security policy creation Assisting with cyber security awareness Completing security risk assessments accurately and in a timely manner Managing and engaging with internal and external stakeholders on security questionnaires Advising on risk mitigation Advising on … contemporary threats and cyber trends to enhance the organisation's security Completing all of the above in line with the organisation's risk strategy, appetite, and framework. What we're looking for: Practical knowledge of various information security and risk frameworks and standards such as ISO27001, NIST, Cyber Essentials. GRC experience is essential (risk awareness, identification, articulation and … mitigation). Whilst this role won't see you utilising technical cyber security tools in your day-to-day, an understanding of technical cyber (threat, vulnerability, network security) is crucial, and prior practical experience is ideal. Excellent communication skills, ability to work at pace and deal with complex works, and a go-getter personality are all essential criteria More ❯
internal and external functions Managing risk reporting and the risk register Supporting on audits and bolstering the ISMS methodology for ISO27001 certifications Contributing towards security policy creation Assisting with cyber security awareness Completing security risk assessments accurately and in a timely manner Managing and engaging with internal and external stakeholders on security questionnaires Advising on risk mitigation Advising on … contemporary threats and cyber trends to enhance the organisation's security Completing all of the above in line with the organisation's risk strategy, appetite, and framework. What we're looking for: Practical knowledge of various information security and risk frameworks and standards such as ISO27001, NIST, Cyber Essentials. GRC experience is essential (risk awareness, identification, articulation and … mitigation). Whilst this role won't see you utilising technical cyber security tools in your day-to-day, an understanding of technical cyber (threat, vulnerability, network security) is crucial, and prior practical experience is ideal. Excellent communication skills, ability to work at pace and deal with complex works, and a go-getter personality are all essential criteria More ❯
Ipswich, Suffolk, United Kingdom Hybrid / WFH Options
Hays
Job Title: IT Compliance Specialist Key Responsibilities: Develop and implement IT compliance policies. Conduct internal audits (ISO27001, Cyber Essentials+). Identify and assess compliance risks. Prepare audit reports and recommend improvements. Provide compliance training to employees. Investigate and resolve compliance issues. Maintain compliance documentation. Collaborate with other departments for overall compliance. Ensure third-party vendor compliance. Work with the … Security Team on data protection. Qualifications: Strong understanding of IT systems and infrastructure. Knowledge of ITSM, ITIL, GDPR, ISO27001, Cyber Essentials+. Excellent analytical, problem-solving, communication, and interpersonal skills. Attention to detail and high ethical standards. Experience with compliance management tools. Benefits: Starting at 25 days holiday plus Bank Holidays. Private Healthcare, Pension Scheme, Profit Share, and Performance Bonus. More ❯
sub-region in security incident management. Manage remediation efforts, e.g., internal audit findings. Oversee cybersecurity compliance and conduct management. Cybersecurity Risk Management: Manage a cybersecurity risk committee to support cyber risk management. Track remediation of audit and compliance findings. Review cybersecurity metrics and lead remediation programs. Lead or sponsor cybersecurity initiatives. Coordinate with Data Privacy to ensure security controls … Broad cybersecurity knowledge and experience in large, complex environments. Solid understanding of domains like application security, vulnerability management, network and cloud security, incident management, physical security, supplier risk, and cyber awareness. Experience in effective cyber risk management. Ability to influence and build relationships with diverse stakeholders, including C-level executives. Exceptional communication skills for technical and non-technical … Regulatory management experience. Experience with compliance assurance and audits is desirable. Security certifications such as CISSP or CISM are advantageous. Experience with standards like Sarbanes Oxley (404), ISO27001, and Cyber Essentials+. How we support our colleagues We offer comprehensive benefits, promote diversity, and foster an inclusive, agile environment supporting wellbeing and work/life balance, including two "Global Wellbeing More ❯
implementing effective control regimes in large, complex environments. Solid understanding of domains including application security, vulnerability management, network and cloud security, security operations, physical security, supplier risk management, and cyber awareness. Experience in effective cyber risk management at a corporate level. Ability to foster partnerships and influence stakeholders up to C-level. Exceptional communication skills for diverse and … management experience. Experience with compliance assurance and audit practices is desirable. Security certifications such as CISSP or CISM are advantageous. Knowledge of standards like Sarbanes Oxley (404), ISO27001, and Cyber Essentials+. How we support our colleagues We offer a comprehensive benefits package, promote a diverse and inclusive environment, and support work/life balance through flexible working arrangements ('Smart More ❯
sub-region in the Security Incident Management process. • Remediation Management, e.g. Internal Audit findings. • Cybersecurity Compliance and Conduct management. Cybersecurity Risk Management: • Managing a Cybersecurity Risk committee to support cyber risk management. • Track remediation of Cybersecurity Audit and Compliance findings. • Review Cybersecurity Metrics and lead remediation programs within the region/sub-region. • Lead or Sponsor Cybersecurity initiatives within … complex corporate environment. Solid knowledge and understanding of Cybersecurity domains, including; application security, vulnerability management, network and cloud security, security operations (incident management), physical security, supplier risk management and cyber awareness. Experience of effective Cyber Risk Management within a large corporate environment. Fostering strong partnerships by influencing and building effective relations with diverse stakeholders at a range of … Experience of Compliance assurance and Audit practice is desirable. Security certification (CISSP,CISM) is an advantage. Understanding and experience of delivering compliance standards, including; Sarbanes Oxley (404), ISO27001 and Cyber Essentials+. How we support our colleagues In addition to our comprehensive benefits package, we encourage a diverse workforce. Plus, our agile, inclusive environment allows you to manage your wellbeing More ❯