technical knowledge with approximately 8 years of experience within the industry. Working experience with common security/technology risk frameworks, for instance, ISO 27000, NIST, CIS Critical Security Controls, COBIT, and IIA GTAGs. Working experience with regulatory standards/requirements (US, UK) ie, GDPR, BCBS 239, FFIEC 101, 3402, CHAP. Working experience and/or knowledge of Security domains including More ❯
London, South East, England, United Kingdom Hybrid/Remote Options
QBE Management Services (UK) Limited
a related discipline, ideally within a global organisation. Background in Financial Services and ability to navigate complex federated structures like QBE’s operating model. Working knowledge of NIST, ISO, COBITand other risk management frameworks Advanced Excel (including VBA), Power BI, and SharePoint proficiency; experience with GRC tools such as Archer for data extraction and reporting. Skilled in presenting to More ❯
Frameworks and Taxonomy Leadership: Design, implement, and continuously enhance risk management frameworks and taxonomies, ensuring clarity, consistency, and alignment with regulatory, legal, and industry standards (e.g., NIST, ISO 27000, COBIT). Controls Uplift & Transformation: Lead and execute cross-functional initiatives to uplift and transform technology controls, ensuring they are robust, effective, and future-ready. Stakeholder Engagement: Partner with product, engineering … to industry-leading practices and standards. Proven ability to design, implement, and operate risk management frameworks and taxonomies. Proficiency in regulatory, legal, and industry standards (e.g., NIST, ISO 27000, COBIT). Strong stakeholder management skills, with experience engaging product, engineering, and business teams. Excellent verbal and written communication skills, able to convey complex risk informationand standards to diverse audiences. More ❯
knowledge of PRA regulation. Good knowledge of Operational Resilience. Solid understanding of relevant legal, regulatory and security management frameworks requirements, such as PRA, CBEST, ISO/IEC 27001, ITIL, COBIT or equivalent. Experience with vendor and contract negotiations. Excellent communicator and stakeholder management skills. Ability to lead and motivate InfoSec teams to achieve goals. This is a great opportunity to … up-to-date CV which showcases your experience in the above areas. CISO, Cybersecurity, legacy, cloud, SaaS, PRA, financial services, insurance, operational resilience, CBEST, ISO/IEC 27001, ITIL, COBIT, information security, Head of Cyber, CIO More ❯