and the security of private equity backing. It's an inspiring time to join the team! Looking for a self-starting highly motivated and detail-orientated Information Security Governance, Risk, and Compliance (GRC) Analyst to support the design, implementation, and ongoing improvement of our information security governance and risk management framework. This role is essential in ensuring the … organisation proactively manages information security risk across its employees, technologies, vendors, and operations and adheres to the regulatory and security standards pertinent to financial services while providing visibility to key stakeholders. Job Responsibilities Support the development, maintenance, and enforcement of information security policies, procedures, and standards Conduct risk assessments on technology systems, third-party vendors, and new services. … implemented and effective Assist in preparing for and responding to regulatory audits and compliance reviews (e.g., NIST CSF, ISO 27001, DORA, GDPR. ITGC) Maintain and update the information security riskregister with appropriate scenarios and control frameworks Conduct regular control testing, evaluation and reporting findings to stakeholders Stay current on changes in regulations, industry standards, and emerging risks More ❯
Watford, Hertfordshire, United Kingdom Hybrid / WFH Options
Essential Employment
Senior Cybersecurity Risk Analyst (Remote) needed, £28.49ph PAYE - Reference: RQ Role Overview We are looking for a highly skilled and technically proficient Senior Cybersecurity Risk Analyst to join our team on an interim basis. This role is critical in identifying, assessing, and managing information security risks across the organization. The ideal candidate will have a strong technical background … the ability to translate threats into business risks, and experience working in fast-paced environments. Key Responsibilities - Conduct in-depth security risk assessments across systems, applications, and infrastructure. - Identify and evaluate technical and operational risks, vulnerabilities, and control gaps. - Translate complex technical threats into clear, actionable business risks. - Maintain and update the Cybersecurity Risk Register. - Produce detailed risk … the Security Operations Centre (SOC). - Support compliance with relevant standards (e.g. ISO 27001, NIST, UK GDPR). - Review security aspects of tenders and conduct third-party/vendor risk assessments to ensure alignment with organisational security requirements. - Perform additional security-related tasks as directed by the Head of Information Security You will Ideally have - - Proven experience in technical More ❯
Watford, Hertfordshire, South East, United Kingdom Hybrid / WFH Options
Hays
Role Overview We're looking for an experienced Senior Cyber Risk Analyst to join a purpose-driven organisation on a part-time basis . In this role, you'll take the lead in strengthening the organisation's security posture by driving forward incident response, vulnerability management, and compliance initiatives. You'll be a key player in embedding security best … Work 7-hour days, 3 days a week Act as a trusted advisor on information security matters, supporting projects, solution development, and change initiatives with expert guidance. Perform regular risk evaluations to uncover and address potential security gaps. Lead the end-to-end management of security incidents, ensuring swift and effective resolution. Design and deliver engaging training sessions to … Essentials Plus, ISO 27001, and PCI DSS. What you'll need to succeed Willingness to work 7-hour days, 3 days a week Demonstrated expertise in conducting technical security risk assessments and developing threat models. Comprehensive knowledge of core cybersecurity domains, including network, endpoint, and cloud security. Skilled at translating technical vulnerabilities into business-relevant language for diverse audiences. More ❯
Employment Type: Part Time, Work From Home
Salary: £28.49 - £36.98 per hour + £36.98 p/h via Umbrella (Inside IR35)
such as malware infections, phishing attempts, denial-of-service attacks, data breaches, etc. Liaise with stakeholders in relation to cyber security issues and provide recommendations. Maintain an information security riskregister and assist with internal and external audits relating to information security. Conducting security awareness training and education for staff and users on best practices and emerging trends … in cyber security. Use vulnerability management to improve Infinigate’s security landscape. Performing risk assessments and vulnerability scans to identify and mitigate potential threats to the network, devices, applications, and data. Complete security audits of company solutions. Implementing and maintaining security policies, standards, procedures, and best practices to ensure compliance with regulatory and industry requirements. Researching and evaluating new More ❯
City of London, Greater London, UK Hybrid / WFH Options
Infinigate Group
such as malware infections, phishing attempts, denial-of-service attacks, data breaches, etc. Liaise with stakeholders in relation to cyber security issues and provide recommendations. Maintain an information security riskregister and assist with internal and external audits relating to information security. Conducting security awareness training and education for staff and users on best practices and emerging trends … in cyber security. Use vulnerability management to improve Infinigate’s security landscape. Performing risk assessments and vulnerability scans to identify and mitigate potential threats to the network, devices, applications, and data. Complete security audits of company solutions. Implementing and maintaining security policies, standards, procedures, and best practices to ensure compliance with regulatory and industry requirements. Researching and evaluating new More ❯
City of London, London, Billingsgate, United Kingdom Hybrid / WFH Options
Just IT Training Limited
site access * Liaise with service providers (cleaning, HVAC, alarms, etc.) Strategic and Operational Delivery * Develop and manage annual plans for IT and Facilities * Identify risks and maintain the operational riskregister * Report on projects and performance to senior leadership * Contribute to continuous improvement across systems and services ________________________________________ Candidate Profile Essential: * Educated to degree level and Microsoft Certified * Significant More ❯
AVP, IT Security Specialist - RSA Archer, NIST, GRC - London - Hybrid Join a leading security governance and risk team as an AVP, IT Security Specialist . You'll play a key role in ensuring robust security controls, compliance, and continuous risk reduction across a regulated enterprise environment. Key Responsibilities: Maintain and evolve security policy, standards, procedures, and frameworks Align … security practices with NIST CSF, NIST 800-53 and other industry standards Advise business and technology teams on information security best practices Conduct regular risk assessments and maintain a riskregister in RSA Archer Identify, assess, and prioritize cybersecurity risks across assets and environments Track remediation efforts and ensure ongoing risk reduction to acceptable levels Support … development of cybersecurity risk management strategies and reporting Represent security during internal and external audits and assessments Run lessons-learned forums and improve control effectiveness Produce detailed assurance reporting, metrics, and dashboards for stakeholders Key Skills & Experience: Minimum 2 years' experience in Information or Cyber Security, ideally in financial services Solid understanding of security risk management principles and More ❯
Bridgwater, Somerset, South West, United Kingdom Hybrid / WFH Options
Walsh Employment
party providers Promoting a culture of collaboration, transparency, and service excellence Key Deliverables End-to-end IT service governance and assurance Up-to-date licensing schedules , cost controls, and risk registers Effective reporting on service metrics , issues, and compliance gaps Coordination of risk management , change control, and continuous improvement Delivery of reliable, secure, and scalable IT services aligned More ❯
Facilitate workshops, meetings, and sprint planning sessions to ensure alignment and progress toward project goals. Maintain clear communication with senior leadership, providing updates on project milestones, risks, and budget. Risk and Issue Management Identify, track, and resolve risks, dependencies, and issues throughout the project lifecycle, ensuring minimal disruption to ongoing operations. Develop and maintain risk registers and mitigation More ❯
Facilitate workshops, meetings, and sprint planning sessions to ensure alignment and progress toward project goals. Maintain clear communication with senior leadership, providing updates on project milestones, risks, and budget. Risk and Issue Management Identify, track, and resolve risks, dependencies, and issues throughout the project lifecycle, ensuring minimal disruption to ongoing operations. Develop and maintain risk registers and mitigation More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Parser
Facilitate workshops, meetings, and sprint planning sessions to ensure alignment and progress toward project goals. Maintain clear communication with senior leadership, providing updates on project milestones, risks, and budget. Risk and Issue Management Identify, track, and resolve risks, dependencies, and issues throughout the project lifecycle, ensuring minimal disruption to ongoing operations. Develop and maintain risk registers and mitigation More ❯
Milton Keynes, Buckinghamshire, United Kingdom Hybrid / WFH Options
Digital Appointments
Lead and manage the full lifecycle of IT projects, from initiation and planning through to execution, monitoring, controlling, and closure. Develop and maintain comprehensive project documentation, including project plans, risk registers, issue logs, and progress reports. Effectively manage project budgets, timelines, resources, and scope, ensuring projects are delivered on time and within budget. Build and maintain strong relationships with More ❯
Senior Cybersecurity Risk Analyst (Interim) Fully Remote | 3-Month Contract | £260/day (Inside IR35 via umbrella) We’re working with a leading UK charity who are looking to bring in a Senior Cybersecurity Risk Analyst to support during a critical period. This is a hands-on, technically focused interim contract — ideal for someone with strong experience in … risk assessment, threat modelling, and stakeholder communication. You’ll be working closely with IT, SOC, and business teams to identify and manage technical risks, translate vulnerabilities into business impact, and support the Head of Information Security with day-to-day risk oversight. What You’ll Be Doing: Carrying out technical security risk assessments across infrastructure, applications, and … suppliers. Translating threats into clear, business-aligned risk narratives . Maintaining and updating the Cybersecurity RiskRegister . Supporting SOC escalations and incident investigations. Reviewing third-party security posture and assessing vendor risk during tenders. Producing risk reports and presenting findings to technical and non-technical stakeholders. What We’re Looking For: Strong hands-on More ❯
London, England, United Kingdom Hybrid / WFH Options
Creatify
Senior Cybersecurity Risk Analyst (Interim) Fully Remote | 3-Month Contract | £260/day (Inside IR35 via umbrella) We’re working with a leading UK charity who are looking to bring in a Senior Cybersecurity Risk Analyst to support during a critical period. This is a hands-on, technically focused interim contract — ideal for someone with strong experience in … risk assessment, threat modelling, and stakeholder communication. You’ll be working closely with IT, SOC, and business teams to identify and manage technical risks, translate vulnerabilities into business impact, and support the Head of Information Security with day-to-day risk oversight. What You’ll Be Doing: Carrying out technical security risk assessments across infrastructure, applications, and … suppliers. Translating threats into clear, business-aligned risk narratives . Maintaining and updating the Cybersecurity RiskRegister . Supporting SOC escalations and incident investigations. Reviewing third-party security posture and assessing vendor risk during tenders. Producing risk reports and presenting findings to technical and non-technical stakeholders. What We’re Looking For: Strong hands-on More ❯
SEO, CRO, accessibility, and performance. Manage scope, costs, and timelines of workstreams. Collaborate with the PMO Analyst and Resources Manager to align resource allocation with project milestones. Maintain a riskregister and monitor delivery progress. Adhere to ISO standards to oversee quality and security of solutions delivered. Work with Sales & Client Services teams to identify new opportunities and … scope potential projects. Participate in pre-sales activities, including scoping, proposals, tenders, and client pitches. Review Statements of Work (SoWs) for accurate scoping and risk management. Engage actively in the CACI delivery community by sharing best practices, mentoring others, and continually improving delivery processes. Skills & Experience Experience delivering web-related projects for large government agencies or similar organizations, following … Laravel or equivalent). Experience managing software workstreams in an agile environment. Strong stakeholder engagement skills, capable of handling difficult situations and resolving conflicts. Commercial awareness, including budget tracking, risk management, and forecasting. Ability to build and lead high-performing teams with clear communication and collaboration. Eligibility for security clearance, requiring UK citizenship and residence in the UK for More ❯
Chelmsford, Essex, South East, United Kingdom Hybrid / WFH Options
Keystream Group Limited
councils response to critical cyber incidents, coordinating resolution efforts and informing senior stakeholders. Collaborate with security architects and technical teams to shape and implement cyber security policies, ensuring theyre risk-appropriate and business-friendly. Manage cyber security risks by embedding them into the corporate riskregister and advising on appropriate mitigation strategies. Oversee the planning and execution … thinking with a focus on continuous improvement, service excellence, and innovation. Experience managing teams (of varying experience, including apprentices), budgets and suppliers, and working in a high-profile, high-risk environment. Why Join ECC? At ECC, youll be part of a collaborative and ambitious organisation that values creativity, innovation, and excellence. Youll have the opportunity to make a real More ❯
Northampton, Northamptonshire, United Kingdom Hybrid / WFH Options
Schools Choice
patching, firewall configuration reviews and SIEM alerting. Hold our partners/suppliers to account for spend, performance and behaviour, including diversity within their teams. Maintain and input to the riskregister in the technology service, documenting details of any or all risks and their progress to remediation or mitigation. Manage staff performance appropriately by providing constructive feedback and More ❯
Northampton, Northamptonshire, United Kingdom Hybrid / WFH Options
Opus People Solutions Ltd
patching, firewall configuration reviews and SIEM alerting. Hold our partners/suppliers to account for spend, performance and behaviour, including diversity within their teams. Maintain and input to the riskregister in the technology service, documenting details of any or all risks and their progress to remediation or mitigation. Manage staff performance appropriately by providing constructive feedback and More ❯
Leeds, Yorkshire, United Kingdom Hybrid / WFH Options
IDHL Group
stakeholders and colleagues to prioritise delivery Liaise with internal specialist teams and clients to agree scope of work, timeframes, and costs Create and communicate project plans Develop supporting documentation & risk registers Work with lead developers to ensure task estimates are available and monitor progress against estimates Run stand-up meetings with the production team Ensure work is completed to More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
IDHL Group
stakeholders and colleagues to prioritise delivery Liaise with internal specialist teams and clients to agree scope of work, timeframes, and costs Create and communicate project plans Develop supporting documentation & risk registers Work with lead developers to ensure task estimates are available and monitor progress against estimates Run stand-up meetings with the production team Ensure work is completed to More ❯
processes to detect weaknesses or vulnerabilities and drive improvements. Conduct scenario analysis and stress testing to evaluate organizational preparedness for disruptions and assess capital requirements. Prepare and deliver detailed risk reports regularly and as needed for senior leadership, risk committees, and regulatory bodies, highlighting trends and control effectiveness. Maintain the riskregister, ensuring it is comprehensive … and aligned with the risk framework. Support reviews of the operational risk management framework to ensure industry and regulatory compliance. Assist in implementing and maintaining the governance framework to ensure regulatory and internal policy compliance. Requirements 3-5 years' experience in a 1st or 2nd line role within financial services, focusing on Operational Risk. Strong relationship-building skills. … Excellent written and verbal communication skills, with proficiency in Microsoft Office tools. Understanding of risk assessment methodologies and frameworks. Knowledge of Operational Risk capital requirement calculations or modeling. Excellent stakeholder management skills, with the ability to liaise across risk, compliance, and IT teams. What you will get in return: Competitive Salary: We reward your skills and talents More ❯
Job Description Description We have an exciting opportunity for a Risk Manager to join us on a permanent contract, based in Luton! (Hybrid Working) The IT Strategy & Architecture team provides leadership around easyJet's technology strategy, the evolution of our enterprise IT architecture, solution architectures for complex change, cybersecurity architecture, our federated technical architecture practice, and areas such as … end-to-end IT risk management. Reporting to the Head of IT Risk & Resilience, the Risk Manager is responsible for implementing, embedding and continuously improving easyJet's IT Risk Management practice. We work collaboratively with a broad range of colleagues and stakeholders at all levels (from the C-suite to the frontline) and focus on striking … a pragmatic balance between supporting in-flight initiatives and steering longer-term investment. What you'll be doing • Planning, designing and implementing the overall risk management process as part of the maturing IT Risk framework that is applied across easyJet IT. • Identifying, analysing and prioritising key areas of IT risk as well as articulating the impacts they More ❯
Leeds, England, United Kingdom Hybrid / WFH Options
SPG Resourcing
Project Manager with a strong consultancy background to lead and deliver complex Identity and Access Management (IAM) projects across enterprise-level environments. This role will involve managing change and risk frameworks, coordinating with internal and external stakeholders, and ensuring alignment with best practices (ITIL) and compliance with regulatory requirements (e.g., GDPR, SOX). Key Responsibilities: Lead the change management … IAM implementations across enterprise systems, ensuring minimal disruption and maximum adoption. Assess and mitigate risks associated with access management changes, ensuring secure, compliant, and effective solutions. Create and maintain risk registers, define controls, and track mitigation effectiveness through regular reporting. Develop and manage change management frameworks aligned with ITIL best practices to support technology and business transformation. Collaborate with … stakeholders to evaluate change impacts and secure alignment across business units. Monitor and ensure ongoing compliance with security policies, standards, and regulatory frameworks such as GDPR and SOX. Deliver risk assessments and change impact analyses to senior management and governance boards. Lead incident response and problem management activities related to IAM systems and service disruptions. Conduct and escalate commercial More ❯
visibility of dependencies and shared risks. Ensure project governance frameworks are adhered to, maintaining structured processes for approvals, escalations, and decision-making. Maintain up-to-date programme documentation, including risk registers, action logs, and workstream updates. Identify and drive continuous improvements in PMO processes to enhance programme delivery. Are you the right candidate? Proven experience in programme/project … PMO roles, ideally within a media, technology, or innovation-driven environment. Strong organisational and analytical skills, with the ability to track complex project dependencies across multiple workstreams. Experience in risk management, with the ability to identify and mitigate programme risks proactively. Exceptional stakeholder engagement and communication skills, ensuring senior leadership receives clear and concise updates. Experience in governance and … reasons and they will be given priority consideration ahead of other applicants. Priority consideration means for those employees seeking redeployment their application will be considered alongside anyone else at risk of redundancy, prior to any individuals being considered who are not at risk. Diversity matters at the BBC. We have a working environment where we value and respect every More ❯
Haywards Heath, Sussex, United Kingdom Hybrid / WFH Options
First Central Services
modelling or analysis Role model best practice, with focuses on efficiency and long term success Monitor the latest techniques and solutions being utilised in the wider industry Maintain departmental risk registers providing evidence and commentary for controls, updates for Mitigation Actions and maintaining control matrices and attestations. Comply with the requirements, and act in accordance with, the Group Code More ❯