VP, IT Security Risk - RSAArcher, NIST, GRC - London - Hybrid A strategic opportunity for a VP-level Information & Cyber Security professional to join a growing security governanceandrisk team. Drive enterprise-level cyber risk management, compliance, and security posture enhancement in a highly regulated environment. Key Responsibilities: Own and maintain security policies, standards, procedures , and … NIST 800-53 , and industry regulations Act as a trusted security advisor to business and technical stakeholders Lead and conduct detailed risk assessments , maintaining the risk register in RSAArcher Identify and evaluate information security risks; support remediation and treatment strategies Track and monitor risk remediation through life cycle to acceptable closure Contribute to organization-wide … reporting and metrics to key stakeholders Key Skills & Experience: 5+ years in Information/Cyber Security , with 2+ years focused on security risk Strong background in GRC tools - RSAArcher strongly preferred Deep understanding of security risk management , taxonomy, and control frameworks Strong attention to detail with expert-level documentation and reporting ability Ability to communicate More ❯
AVP, IT Security Specialist - RSAArcher, NIST, GRC - London - Hybrid Join a leading security governanceandrisk team as an AVP, IT Security Specialist . You'll play a key role in ensuring robust security controls, compliance, and continuous risk reduction across a regulated enterprise environment. Key Responsibilities: Maintain and evolve security policy, standards, procedures, and … CSF, NIST 800-53 and other industry standards Advise business and technology teams on information security best practices Conduct regular risk assessments and maintain a risk register in RSAArcher Identify, assess, and prioritize cybersecurity risks across assets and environments Track remediation efforts and ensure ongoing risk reduction to acceptable levels Support development of cybersecurity risk … Experience: Minimum 2 years' experience in Information or Cyber Security, ideally in financial services Solid understanding of security risk management principles and taxonomy Working knowledge of GRC platforms - RSAArcher preferred Familiarity with NIST CSF , NIST 800-53 , ISO 27001 , SOC 1 & 2 Good written and verbal communication skills for technical and non-technical stakeholders Strong More ❯
Organisation, experience with planning, data reporting, information and updates Strong ability to work with others to drive forward security objectives. Meticulous attention to detail. Experience with GRC tools (RSAArcher preferred) Desired qualifications/certifications: Ideally a Master's Degree in Infromation Security, CICA/CRISC/CISM/Data Analysis NIST CSF, ISO27001, SOC More ❯
Organisation, experience with planning, data reporting, information and updates Strong ability to work with others to drive forward security objectives. Meticulous attention to detail. Experience with GRC tools (RSAArcher preferred) Desired qualifications/certifications: Ideally a Master's Degree in Infromation Security, CICA/CRISC/CISM/Data Analysis NIST CSF, ISO27001, SOC More ❯
Organisation, experience with planning, data reporting, information and updates Strong ability to work with others to drive forward security objectives. Meticulous attention to detail. Experience with GRC tools (RSAArcher preferred) Desired qualifications/certifications: Ideally a Master's Degree in Infromation Security, CICA/CRISC/CISM/Data Analysis NIST CSF, ISO27001, SOC More ❯
Experience: Experience in Information security risk management, governance, and compliance. Proven leadership in enterprise risk management and security governance frameworks. Hands-on exposure to GRC tools (e.g., OnSpring, Archer, ServiceNow, or similar). Background knowledge of risk assessment methodologies and security frameworks such as ISO 27001, NIST, and CIS. Experience managing and directing enterprise-wide Information Security riskMore ❯
evaluation methodologies (e.g., calculating inherent vs. residual risk). Excellent technical writing and documentation skills. Experience communicating with both technical and non-technical stakeholders. Mandatory experience with NIST andRSAArcher platforms. Preferred Qualifications: Bachelor’s degree in Information Security, Cybersecurity, or related field. Professional certifications such as CISSP, CISA, CRISC, or CISM. Familiarity with other governance, risk, andcompliance (GRC) tools. More ❯
evaluation methodologies (e.g., calculating inherent vs. residual risk). Excellent technical writing and documentation skills. Experience communicating with both technical and non-technical stakeholders. Mandatory experience with NIST andRSAArcher platforms. Preferred Qualifications: Bachelor’s degree in Information Security, Cybersecurity, or related field. Professional certifications such as CISSP, CISA, CRISC, or CISM. Familiarity with other governance, risk, andcompliance (GRC) tools. More ❯
evaluation methodologies (e.g., calculating inherent vs. residual risk). Excellent technical writing and documentation skills. Experience communicating with both technical and non-technical stakeholders. Mandatory experience with NIST andRSAArcher platforms. Preferred Qualifications: Bachelor’s degree in Information Security, Cybersecurity, or related field. Professional certifications such as CISSP, CISA, CRISC, or CISM. Familiarity with other governance, risk, andcompliance (GRC) tools. More ❯
and periodic review schedule. Prepare presentations and materials for senior stakeholders, risk committees, and internal governance forums, clearly articulating risk posture and control health. Collaborate with second line riskandcompliance functions to maintain alignment of methodologies and remediation of findings. Qualifications and Experience: Minimum5- 7 years of experience in operational risk, business controls, or first line risk management, ideally … II, DORA, NIST) related to operational resilience and technology risk in EU/UK financial markets. Proficiency in Microsoft Excel, PowerPoint and Word; experience using GRC platforms (e.g., Archer) and data visualization/reporting tools (e.g., Power BI, Tableau). Strong interpersonal and communication skills, with the ability to influence and collaborate effectively across business and technical functions. More ❯
London, England, United Kingdom Hybrid / WFH Options
developrec
technical findings into business language Proficient in both automated and manual testing techniques for security controls Desirable Experience Experience with tools such as SailPoint, Rapid7, Wiz.io, Microsoft Defender, RSAArcher, and ServiceNow Familiarity with automation and data analytics tools (Excel, Tableau, Alteryx, PowerBI) Agile methodology experience, ideally with Jira and Kanban boards Background in a Big More ❯
Azure DevOps – London/Hybrid 6 month contract – SC Cleared We are looking for an SC cleared, experienced Azure DevOps Engineer with a strong background in Azure Infrastructure to develop and implement cloud-based solutions. Design and manage deployment andMore ❯
Azure DevOps – London/Hybrid 6 month contract – SC Cleared We are looking for an SC cleared, experienced Azure DevOps Engineer with a strong background in Azure Infrastructure to develop and implement cloud-based solutions. Design and manage deployment andMore ❯
Azure DevOps – London/Hybrid 6 month contract – SC Cleared We are looking for an SC cleared, experienced Azure DevOps Engineer with a strong background in Azure Infrastructure to develop and implement cloud-based solutions. Design and manage deployment andMore ❯