Fareham, England, United Kingdom Hybrid / WFH Options
Zurich Insurance Company
risks in the UK business and develop the Audit Plan with the support of the Audit Director and Audit Leads. The role will include to present regular updates to Management and relevant Committees, and you will report to the Audit Director, UK. You will also play a role in implementing and driving our strategic priorities, co-create a leading … skills (Data Analytics, IT fundamentals, and GenAI), and Agile methods, and serve as a role model for delivering change. What will you be doing? Input into the overall UK risk assessment and audit planning and, determining the right auditscope, key risks to be addressed and most suitable audit techniques and approaches alongside the Audit Director Keeping the business safe … the quality of outcomes Guiding, coaching, and supervising the work of the team throughout the audit engagement Oversee the performance and development of IT audit team members assigned (career management responsibilities). Influencing IT and Operations senior leaders through strong relationships and insights and acting as a strategic partner for the Audit Director. Identifying themes and trends, systemic/ More ❯
Southampton, Hampshire, United Kingdom Hybrid / WFH Options
Aztec
We can consider hybrid or fully remote work in the UK. We're looking for a self-motivated and driven individual with a passion for technology riskmanagement who is looking for an exciting role as a technology risk subject matter expert within the second line of defence (2LoD) Chief Risk Office. You will provide expertise … advice and independent challenge around the Technology risk and control environment and play a crucial role in developing the technology risk strategy to protect Aztec from technology-related threats while enabling business growth and innovation. This role offers the successful candidate extensive opportunities for development and the opportunity to apply their knowledge of technology risk at a … senior level within a financial services environment. Key responsibilities: Development and delivery of Aztec's technology risk strategy in line with the ERMF and the Chief Risk Office roadmap, regulatory requirements and industry best practice, such as COBIT5/ITIL. Ensure that key strategic risks and controls associated with cloud infrastructure, AI, data management, and wider digital More ❯
Southampton, Hampshire, United Kingdom Hybrid / WFH Options
NICE
CSOC) activities, including incident monitoring and response. How will you make an impact? Internal Audit Execution: Conduct internal audits to evaluate and enhance IT controls, compliance with standards, and riskmanagement processes. Audit Preparation: Assist internal control owners in scoping appropriate evidence and preparing for external audits. Gap Assessments: Facilitate and/or conduct internal gap assessments and … of compliance processes. Audit Findings: Identify control deficiencies and work with stakeholders to recommend cost-effective, value-added remediation actions. Compliance Reporting: Draft audit reports and present findings to management during status updates and closing meetings. External Audit Coordination: Collaborate with external audit teams to streamline processes and provide requested documentation and evidence. Security Monitoring: Use tools such as … implementing recommendations to improve the security posture. Policy and Procedure Development: Assist in creating and refining cybersecurity policies and operational procedures to align with audit and compliance objectives. Vulnerability Management: Support the tracking and remediation of vulnerabilities in coordination with IT and Security Operations teams. Have you got what it takes? Strong expertise in audit and compliance frameworks, including More ❯
Southampton, England, United Kingdom Hybrid / WFH Options
Zurich Insurance
Join to apply for the IT Risk Manager role at Zurich Insurance 4 days ago Be among the first 25 applicants Join to apply for the IT Risk Manager role at Zurich Insurance Get AI-powered advice on this job and more exclusive features. Working hours: This role is available on a part-time, job-share or full … June The opportunity: This is an opportunity to join the UK IT and Operations team, reporting to the Head of IT Service Delivery, where you will collaborate with the management team, bursting with ideas on how to move our UK business forward. You will be asked to drive change and improve on a set of already well-established IT … Controls and an IT RiskManagement Framework to allow senior IT management, business functions and 3rd party service providers to demonstrate they are managing and safeguarding company assets, data, and operations. Your ideas will be heard. You will collaborate and influence IT management, the IT Governance and Controls Manager and other governance colleagues to gather data More ❯
Farnborough, England, United Kingdom Hybrid / WFH Options
Ultra
systems operating within the electromagnetic spectrum. The opportunity to travel internationally to work directly with customers may occur. A Project Manager is needed to manage key client projects. Project management responsibilities include the coordination and completion of projects on time within budget and within scope. Set deadlines, assign responsibilities, and monitor and summarize progress of project. Prepare reports for … upper management regarding status of project. The successful candidate will work directly with clients to ensure deliverables fall within the applicable scope and budget. He or she will coordinate with other departments to ensure all aspects of each project are delivered. Key Responsibilities: Perform riskmanagement to minimise potential risks. Ensure that all projects are delivered on … a detailed project plan to monitor and track progress. Manage changes to the project scope, project schedule, and project costs using appropriate verification techniques. Measures performance using appropriate project management tools and techniques. Report and escalate to management as needed. Manage the relationship with the client and relevant stakeholders. Establish and maintain relationships with third parties/vendors. More ❯
Southampton, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
implement corrective actions, and ensure compliance with industry regulations (GDPR, HIPAA). DevOps Integration : Collaborate with development, operations, and IT teams to integrate security practices into the DevOps lifecycle. RiskManagement : Conduct risk assessments and develop mitigation strategies to minimize security risks. Security Guidance : Provide expert advice on cloud security best practices to internal teams. Experience & Qualifications More ❯
Southampton, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
assurance engagement teams across the GT network Review of data and evidence obtained in the field, including reviews for completeness, consistency and clarity. Evaluate cybersecurity risks and advise on risk mitigation activities. Engagement with compliance colleagues, Technology and Business leaders, including the delivery of reporting material and presentations. Tracking and coordination of follow up remediation cycles for those firms … written, with the ability to initiate and lead conversations with senior stakeholders Ability to prioritise and manage a varying workload Experience with using GRC solutions as part of a riskmanagement programme. Understanding of cyber security best practices including knowledge of the general cyber threat landscape and common security controls architecture. Due to the global scope of the More ❯
Portsmouth, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
assurance engagement teams across the GT network Review of data and evidence obtained in the field, including reviews for completeness, consistency and clarity. Evaluate cybersecurity risks and advise on risk mitigation activities. Engagement with compliance colleagues, Technology and Business leaders, including the delivery of reporting material and presentations. Tracking and coordination of follow up remediation cycles for those firms … written, with the ability to initiate and lead conversations with senior stakeholders Ability to prioritise and manage a varying workload Experience with using GRC solutions as part of a riskmanagement programme. Understanding of cyber security best practices including knowledge of the general cyber threat landscape and common security controls architecture. Due to the global scope of the More ❯
Hook, England, United Kingdom Hybrid / WFH Options
Elanco
need for new skillsets and competencies and create plans to address them. Collaborate with product, design, and business teams to define and execute engineering priorities. Partner with engineering demand management to ensure optimal resource alignment, third-party partnerships, and delivery capacity across product portfolios. Engage externally to understand market trends in engineering and SaaS platforms and prepare your team … for these changes. Team Development and Talent Management Lead the design and scaling of a modern engineering organization, cultivating a culture of craftsmanship, learning, and shared ownership. Develop and implement staffing plans to build and maintain a high-calibre engineering team. Carry out all elements of employee supervision, such as performance management, development coaching, learning plan oversight, task … within and across teams. Support a culture that values cross-functional collaboration, shared ownership, and a strong focus on customer outcomes. Operational Oversight and Governance Partner with Engineering demand management supporting incoming demand with Engineering resource. Support Engineering Demand Management with product governance discussions ensuring the right engineering talent is deployed to support product needs. Implement Engineering governance More ❯
Basingstoke, Hampshire, United Kingdom Hybrid / WFH Options
CBSbutler Ltd
The company: Global IT Consultancy delivering digital transformation to Defence and National Security end clients. Overview: As Security Assurance Consultant is part of the Security Assurance Team (SAT), providing riskmanagement and assurance of programme artefacts. Responsibilities and Tasks Support delivery of secure Releases and Features aligned with the relevant legacy or NIST assurance processes through Security Assurance … stories agreed with nominated team Scrum Master Create security assurance case for releases, including risk assessments and mitigations for identified defects and vulnerabilities Liaise with Testers, Security Architects and Engineers to ensure smooth assurance process and timely delivery of contribution to assurance cases. Define Penetration Test and IT Health Check (ITHC) scope for relevant team Liaise with Joint Design … documentation; including RMADS, CoCo, RAR, SSP, POAM, OSMP (including SyOps). Knowledge, Experience and Capabilities Cyber Security Assurance ISO27001 NIST 800-53 series MOD Secure by Design Information assurance Riskmanagement High quality of written and verbal communication skills Experience of working in Secure environments (Highly desirable) Experience in Safe Agile methods (Desirable More ❯
Basingstoke, Hampshire, United Kingdom Hybrid / WFH Options
CBSbutler Holdings Limited trading as CBSbutler
The company: Global IT Consultancy delivering digital transformation to Defence and National Security end clients. Overview: As Security Assurance Consultant is part of the Security Assurance Team (SAT), providing riskmanagement and assurance of programme artefacts. Responsibilities and Tasks Support delivery of secure Releases and Features aligned with the relevant legacy or NIST assurance processes through Security Assurance … stories agreed with nominated team Scrum Master Create security assurance case for releases, including risk assessments and mitigations for identified defects and vulnerabilities Liaise with Testers, Security Architects and Engineers to ensure smooth assurance process and timely delivery of contribution to assurance cases. Define Penetration Test and IT Health Check (ITHC) scope for relevant team Liaise with Joint Design … documentation; including RMADS, CoCo, RAR, SSP, POAM, OSMP (including SyOps). Knowledge, Experience and Capabilities Cyber Security Assurance ISO27001 NIST 800-53 series MOD Secure by Design Information assurance Riskmanagement High quality of written and verbal communication skills Experience of working in Secure environments (Highly desirable) Experience in Safe Agile methods (Desirable More ❯
Southampton, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
depth technical understanding. You will be expected to cover the initiation through to the design and implementation, across several of the skills and technologies below: Microsoft Sentinel Tenable Vulnerability Management (Or similar technology) Azure update Manager/Other Patching technologies Qualifications: Microsoft Security Certifications (eg SC200) Pen Testing/Related Certifications DESIRED KNOWLEDGE, SKILLS & EXPERIENCE The ability to demonstrate … significant value to your application. Training and development in these technologies/solutions may be provided if required. Microsoft Intune (Focused on Security, not the full suite) Privileged Access Management (PAM) Tooling Cloud Email Security Solutions Certs KEY COMPETENCIES REQUIRED FOR ROLE In line with our company values every employee must be able to demonstrate the following qualities: Autonomy … Integrity Quality Focus – Concern for quality, being attentive to detail and willing to try to improve one’s own performance. Understanding and adherence to quality procedures. Decision Taking and RiskManagement – Willingness to take difficult decisions and have confidence in your decision making and attitude to risk and impact. Respect Communication – Clarity and confidence in written and More ❯
Fareham, Hampshire, United Kingdom Hybrid / WFH Options
Matchtech
such as system tests, development tests, component tests, integration tests, and flight tests Generate work products conforming to all technical and quality requirements through robust configuration control and change management processes Assist in compiling plans, estimates, task lists, and riskmanagement plans in support of programme objectives Work with customers, other engineering disciplines, and internal departments throughout More ❯
Southampton, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
the team and support and advise their clients on implementation and enablement of Microsoft Purview and associated M365 and Azure Technologies including end-to-end data governance, compliance, and riskmanagement solutions. The Role As part of a Team you will be working on a range of Microsoft Purview capabilities such as Data Loss Prevention (DLP), Information Protection … IP), Insider RiskManagement (IRM), and Data Lifecycle Management to deploying and optimising Purview solutions for data discovery, classification, and regulatory compliance. Design and deploying Microsoft Purview solutions across Microsoft 365 and Azure platforms to meet organisational data governance and compliance objectives. Assess customer environments and requirements to deliver tailored Microsoft Purview configurations, policies, and controls. Support … and design deployments of Purview features such as eDiscovery, Information Protection, Data Loss Prevention, Communication Compliance and Information Barriers. Advising on and implementing best practices for Insider RiskManagement and regulatory compliance using Purview's advanced tools. Work with C-level stakeholders, compliance, and information governance teams to align technical solutions with business policies and regulatory requirements. Integrate More ❯
Basingstoke, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
team and support and advise their clients on the implementation and enablement of Microsoft Purview and associated M365 and Azure Technologies, including end-to-end data governance, compliance, and riskmanagement solutions. The Role As part of a team, you will work on a range of Microsoft Purview capabilities such as Data Loss Prevention (DLP), Information Protection (IP … Insider RiskManagement (IRM), and Data Lifecycle Management, deploying and optimizing Purview solutions for data discovery, classification, and regulatory compliance. Design and deploy Microsoft Purview solutions across Microsoft 365 and Azure platforms to meet organizational data governance and compliance objectives. Assess customer environments and requirements to deliver tailored Microsoft Purview configurations, policies, and controls. Support and design … deployments of Purview features such as eDiscovery, Information Protection, Data Loss Prevention, Communication Compliance, and Information Barriers. Advise on and implement best practices for Insider RiskManagement and regulatory compliance using Purview's advanced tools. Work with C-level stakeholders, compliance, and information governance teams to align technical solutions with business policies and regulatory requirements. Integrate Microsoft Purview More ❯
Portsmouth, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
team and support and advise their clients on the implementation and enablement of Microsoft Purview and associated M365 and Azure Technologies, including end-to-end data governance, compliance, and riskmanagement solutions. The Role As part of a team, you will work on a range of Microsoft Purview capabilities such as Data Loss Prevention (DLP), Information Protection (IP … Insider RiskManagement (IRM), and Data Lifecycle Management, deploying and optimizing Purview solutions for data discovery, classification, and regulatory compliance. Design and deploy Microsoft Purview solutions across Microsoft 365 and Azure platforms to meet organizational data governance and compliance objectives. Assess customer environments and requirements to deliver tailored Microsoft Purview configurations, policies, and controls. Support and design … deployments of Purview features such as eDiscovery, Information Protection, Data Loss Prevention, Communication Compliance, and Information Barriers. Advise on and implement best practices for Insider RiskManagement and regulatory compliance using Purview's advanced tools. Work with C-level stakeholders, compliance, and information governance teams to align technical solutions with business policies and regulatory requirements. Integrate Microsoft Purview More ❯
Southampton, England, United Kingdom Hybrid / WFH Options
Leonardo
ensure the availability of front-line capability wherever and whenever required. We are looking for an experienced product security practitioner with expertise in developing and maintaining robust product security management systems for defence and government customers. Within CS3, the term product can be used to include both in-service equipment, and the support solutions/services provided to customers … provide guidance in the design, implementation and maintenance of appropriate security controls. Provide security advice and support to product development teams, including in terms of:Deriving security requirementsUndertaking security risk assessments for productsPreparing security risk mitigation plansReview and approval of Security Management plans Security policy maintenance and monitoring Production of LoB security metrics Management of attendance … at external security forums Attendance and support to the Security Special Interest Group Lead security incident management teams during incident/crisis situations in conjunction with the Lead Product Security Engineer(s) The Chief Product Security Engineer has delegated authority within the independent Design Integrity function, responsible for the following elements: Security process maintenance and monitoring Security competence framework More ❯
Winchester, Hampshire, United Kingdom Hybrid / WFH Options
Evalian
years or more experience of working in data protection, preferably in a consultancy type role. You will require: Strong understanding of GDPR, DPA18 and PECR Strong understanding of information riskmanagement Strong understanding of information security practices Excellent report writing and verbal communication skills Strong analytical skills and ability to map challenges with solutions Strong work ethic and … be comfortable in a fast-paced environment Strong organisational and project management skills Ability to work independently, research and identify answers and solutions. You will also hold at least one recognised data protection qualification, such as: BCS/ISEB in Data Protection PDP Practitioner Certification in Data Protection IAPP CIPP/E, CIPM and/or CIPT GDPR Practitioner More ❯
Winchester, Hampshire, United Kingdom Hybrid / WFH Options
Deloitte LLP
AEO Certification programme, ensuring efficient execution and timely completion of certifications. Provide leadership and guidance to the UK Certification team, ensuring effective resource allocation and performance management. Oversee budget management and resource allocation for the programme. Stakeholder Management: Cultivate and manage relationships with key stakeholders across the UK, NSE, and globally, including senior leadership, service line leaders, and … mentor the UK Certification team, fostering a culture of collaboration, high performance, and continuous development. Provide coaching and guidance to team members, supporting their professional growth and career progression. RiskManagement & Compliance: Ensure compliance with all relevant regulations and internal policies, proactively identifying and mitigating potential risks to the programme. Connect to your skills and professional experience You … plans, translating vision into actionable steps and driving successful outcomes. Exceptional communication and influencing skills: Ability to communicate effectively with senior stakeholders, build consensus, and influence decisions. Strong stakeholder management skills: Experience navigating complex stakeholder landscapes and building strong relationships with diverse groups. Adaptability and resilience: you embrace challenges, are comfortable with ambiguity, and can effectively manage multiple workstreams More ❯
Southampton, Hampshire, United Kingdom Hybrid / WFH Options
Aztec
of the internal Technology team, you will serve as the strategic interface with assigned business units or jurisdictional areas for the purpose of business technology strategy development, business demand management, solution discovery, service, solution adoption, and risk management. Operating at an Associate Director level, you will perform a key role within a highly skilled team and should offer … and driving forward change and efficiencies. Develop and implement opportunities for operational efficiencies using analytical insight and work with the peers across the group on projects as required. Change Management & Adoption: ability to focus on the human side of change by building and delivering effective strategies for the adoption of new technology across the group. Working with business units … to leverage and make best use of existing capabilities where appropriate. Management and mentoring of staff. Skills, knowledge, expertise: The ideal candidate will have previous experience in a senior Tech business partnering role for a large and complex organisation. Strong ability to manage multiple priorities across different business lines and in multiple regions. Proven experience in understanding business requirements More ❯
Winchester, England, United Kingdom Hybrid / WFH Options
Arqiva Group
with senior stakeholders to align infrastructure priorities with business needs. Deliver on IT change projects, platform upgrades, and service improvement initiatives. Maintain high standards of security, compliance, and operational risk management. Skills Strong leadership experience managing infrastructure or platform teams in a mid–large organisation. Solid hands-on understanding of Microsoft technologies (AD, O365, Server OS) Linux platforms VMware More ❯
Havant, Hampshire, United Kingdom Hybrid / WFH Options
Reed Technology
month FTC (with likely extension to permanent) Salary: 50 - 53K plus benefits We are seeking a Cyber Security Specialist to lead the implementation of a new Information Security Management System (ISMS) and ensure compliance with security standards. This role is crucial in driving security improvements, managing risks, and maintaining regulatory compliance within a dynamic IT environment of circa … IT users. Key Accountabilities: * Lead the implementation of a new ISMS, ensuring alignment with industry security standards. * Develop and maintain cyber security policies, procedures, and riskmanagement frameworks. * Manage compliance with cyber security regulations, standards, and frameworks (ISO27001, CAF/eCAF, Cyber Essentials Plus). * Implement and manage security monitoring tools to detect and respond to security events. … Identify and assess security risks and vulnerabilities, developing mitigation strategies. * Support regular audits and assessments to ensure adherence to security policies. * Provide reporting on security incidents, compliance status, and risk assessments. * Collaborate with stakeholders to embed security into business processes and IT operations. Required Skills & Qualifications: * 3-5 years of experience in cyber security roles, with hands-on involvement More ❯
Havant, Hampshire, South East, United Kingdom Hybrid / WFH Options
Reed Technology
month FTC (with likely extension to permanent) Salary: 50 - 53K plus benefits We are seeking a Cyber Security Specialist to lead the implementation of a new Information Security Management System (ISMS) and ensure compliance with security standards. This role is crucial in driving security improvements, managing risks, and maintaining regulatory compliance within a dynamic IT environment of circa … IT users. Key Accountabilities: * Lead the implementation of a new ISMS, ensuring alignment with industry security standards. * Develop and maintain cyber security policies, procedures, and riskmanagement frameworks. * Manage compliance with cyber security regulations, standards, and frameworks (ISO27001, CAF/eCAF, Cyber Essentials Plus). * Implement and manage security monitoring tools to detect and respond to security events. … Identify and assess security risks and vulnerabilities, developing mitigation strategies. * Support regular audits and assessments to ensure adherence to security policies. * Provide reporting on security incidents, compliance status, and risk assessments. * Collaborate with stakeholders to embed security into business processes and IT operations. Required Skills & Qualifications: * 3-5 years of experience in cyber security roles, with hands-on involvement More ❯
Portsmouth, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
the team and support and advise clients on the implementation and enablement of Microsoft Purview and related M365 and Azure Technologies, including end-to-end data governance, compliance, and riskmanagement solutions. The Role You will work with various clients across different industries and collaborate closely with internal teams. Your key responsibility will be leading the delivery of … Microsoft Purview solutions, helping clients navigate complex data governance, compliance, and riskmanagement requirements. You will provide strategic and technical oversight, acting as both a trusted advisor and a hands-on leader. You will support team capability development and optimize existing deployments, designing scalable compliance architectures. Daily management activities for a team of Senior, Consultant, and Junior … and Azure. Design and deploy Purview features such as eDiscovery, Information Protection, Data Loss Prevention, Communication Compliance, and Information Barriers. Advise on and implement best practices for Insider RiskManagement and regulatory compliance using Purview's advanced tools. Support integration of Purview with Microsoft Entra ID, Exchange Online, SharePoint Online, Teams, and OneDrive. Assess and review customer cloud More ❯
Basingstoke, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
team and support and advise their clients on the implementation and enablement of Microsoft Purview and associated M365 and Azure Technologies, including end-to-end data governance, compliance, and riskmanagement solutions. The Role You will work across various clients in different industries, collaborating closely with internal teams. Your key responsibility will be leading the delivery of Microsoft … Purview solutions—helping clients navigate complex data governance, compliance, and riskmanagement requirements. You will provide strategic and technical oversight across projects, acting as both a trusted advisor and hands-on lead. You’ll support the development of team capabilities and service offerings within Microsoft Purview, audit, and optimize existing deployments, as well as design and implement scalable … and Azure. Design and deploy Purview features such as eDiscovery, Information Protection, Data Loss Prevention, Communication Compliance, and Information Barriers. Advise on and implement best practices for Insider RiskManagement and regulatory compliance using Purview’s advanced tools. Support the integration of Purview with Microsoft Entra ID, Exchange Online, SharePoint Online, Teams, and OneDrive. Assess and review customer More ❯