incident management approaches Experience in high-level written communication, with a track record of drafting executive reports, regulatory papers and strategic communications Essential Extensive experience in cyber and technology risk management, covering areas such as technology governance, riskassessment, change management, incident handling, disaster recovery, business continuity, outsourcing and data governance Solid understanding of financial markets, with … expertise in identifying key technology risks and developing effective management strategies Strategic awareness of global regulatory frameworks for technology and cyber risk, as well as operational resilience Ability to remain composed under pressure, analysing incidents swiftly with high attention to detail Strong verbal communication skills, including clear and effective presentations to internal and external audiences Proven interpersonal and influencing … skills, with confidence, credibility and the ability to engage effectively with diverse stakeholders, including senior executives within organizations and regulatory bodies Experience in project management, including planning, risk mitigation, issue resolution and budget oversight Commitment to high-quality work standards, with a proactive approach to problem-solving and constructive challenge Our Values & Diversity We are proud to be an More ❯
a Product Security Engineer to help shape the security architecture of next-generation defence and technology systems. This is a high-impact role where your expertise in threat modelling, riskassessment, and secure-by-design engineering will drive innovation and resilience from day one. What You’ll Be Doing: Leading product risk assessments and driving security improvements … weeks ago Bristol, England, United Kingdom 3 weeks ago Bristol, England, United Kingdom 2 weeks ago Greater Bristol Area, United Kingdom 3 days ago Senior or Principal Security Consultant (Risk Management) Bristol, England, United Kingdom 1 day ago South Gloucestershire, England, United Kingdom 2 days ago Greater Bristol Area, United Kingdom 1 day ago Greater Bristol Area, United Kingdom More ❯
and optimize Collinson’s internal payment systems while managing key external partnerships with PSPs, Acquirers, payment orchestration, fraud prevention, and observability providers . In addition, you will oversee payment risk and fraud management , ensuring regulatory compliance and enhancing payment security. Leading a high-performing product team , you will drive innovation, alignment with market needs, and seamless execution , leveraging data … and alternative payment method (APM) providers . Collaborate with orchestration platforms to streamline global payment routing, retries, and conversion optimization . Integrate with fraud prevention providers , implementing real-time riskassessment and fraud mitigation tools. Work with observability partners to ensure real-time monitoring, reporting, and payment analytics for proactive issue resolution. Payment Risk & Fraud Management Oversee … payment security, fraud prevention, and risk mitigation strategies across all payment channels. Ensure compliance with PCI DSS, PSD2, Strong Customer Authentication (SCA), AML, and cross-border payment regulations . Optimize authorization rates while reducing fraud, chargebacks, and transaction failures. Analytics & Optimization Utilize payment data and insights to optimize transaction success rates and reduce costs. Develop A/B testing More ❯
to secure State Street’s digital footprint. As a Product/Platform Jr. Security Architect on the Security Architecture Governance Engineering (SAGE) team, you will focus on supporting security riskassessment of in-house developed applications, cloud platforms, and vendor solutions. You will help define the reference architectures, security technical standards, and enforce their adherence enterprise-wide. What … you will be responsible for: Support comprehensive risk assessments, threat modelling, and vulnerability analysis to identify potential security gaps and develop mitigation strategies. Perform Application Architecture security reviews, documenting riskassessment findings and proposing remediation. Help shift security left by having tollgates in place for security testing to be done early in SDLC (Software Development Lifecycle) and More ❯
Birmingham, England, United Kingdom Hybrid / WFH Options
Ampa Holdings LLP
across the group and the compliance officer for legal practice (COLP). The CIO team is responsible for Change (Business and Technology), Technology Operations, Applications, Information Security, Resilience and Risk across all our group companies and brands. What you will be doing: The role holder will be responsible for identifying, evaluating and reporting on legal and regulatory, IT, and … cybersecurity risk to information assets, as well as key business risks, while supporting and advancing business objectives. You will also embed knowledge and best practice on risk avoidance and information security and working with the COLP and other relevant post holders, ensure the group is in line with statutory, regulatory and industry compliance standards/guidelines as appropriate. … objectives and regulatory requirements. Work closely with other departments, including our brands and group services to ensure security initiatives are integrated into all aspects of the firm's operations. Risk Management: Identify, assess, and mitigate information security risks. Conduct regular risk assessments and assurance to ensure the firm's security posture remains robust. Policy and Procedure Development: Develop More ❯
Coalition is the world's first Active Insurance provider designed to help prevent digital risk before it strikes. Founded in 2017, Coalition combines comprehensive insurance coverage and innovative cybersecurity tools to help businesses manage and mitigate potential cyberattacks. Opportunities to make an impact with bold thinking are real-and happening daily at Coalition. About the role As a Senior … responsible for measuring, understanding, and helping optimize Coalition's underwriting. You will perform statistical analysis to provide data-driven insights. You will help us understand and improve our cyber risk selection and reduction, pricing and automation in order to grow our revenue in a safe and efficient manner. Responsibilities Analyze diverse datasets including claims data, cybersecurity risk signals … and underwriting databases to extract meaningful patterns and insights Large scale data analysis with the objective of producing valuable risk signals to be used for underwriting or risk evaluation of organizations Develop and refine statistical and machine learning models to assess cybersecurity risks with applications to underwriting and pricing. Create comprehensive reports on underwriting efficiency metrics and riskMore ❯
private investment grade, asset based lending, public investment grade and high yield, sustainable resources, infrastructure debt, collateralized loan obligations, direct lending and opportunistic credit. We seek to generate attractive risk-adjusted returns for institutional and individual investors by offering companies capital needed to strengthen and grow their businesses. BXCI is also a leading provider of investment management services for … integrating large datasets from various sources into the Intex models to ensure accurate calculations Deal Structuring Support Collaborating with deal structuring teams to analyze potential transaction structures, assess credit risk and calculate key metrics RiskAssessment Utilizing Intex models to perform comprehensive risk analysis on structured products Reporting and Analytics Generating detailed reports and presentations for … B.S. or higher degree in Computer Science, Engineering, Mathematics, Physics or other quantitative disciplines Creative and entrepreneurial individual who enjoys working on a wide variety of projects including designing risk and return models for highly illiquid and alternative investments Experience modeling asset risk and return metrics Exposure to insurance capital management and actuarial science a plus Strong programming More ❯
own and optimize Collinson’s internal payment systems while managing key external partnerships with PSPs, Acquirers, payment orchestration, fraud prevention, and observability providers. In addition, you will oversee payment risk and fraud management, ensuring regulatory compliance and enhancing payment security. Key Responsibilities Payments Strategy & Execution • Define and execute a comprehensive payments strategy, balancing consumer experience, revenue optimization, and compliance. … Mastercard, Amex), and alternative payment method (APM) providers. • Collaborate with orchestration platforms to streamline global payment routing, retries, and conversion optimization. • Integrate with fraud prevention providers, implementing real-time riskassessment and fraud mitigation tools. • Work with observability partners to ensure real-time monitoring, reporting, and payment analytics for proactive issue resolution. Payment Risk & Fraud Management • Oversee … payment security, fraud prevention, and risk mitigation strategies across all payment channels. • Ensure compliance with PCI DSS, PSD2, Strong Customer Authentication (SCA), AML, and cross-border payment regulations. • Optimize authorization rates while reducing fraud, chargebacks, and transaction failures. Analytics & Optimization • Utilize payment data and insights to optimize transaction success rates and reduce costs. • Develop A/B testing frameworks More ❯
business units, as requested, when a business disruption occurs and assist with recovery efforts Help Maintain the internal Business Continuity Management Website and network shared drive Participate in vendor risk management program on behalf of the BC in the Business Continuity review and evaluation in the vendor risk management program Co-assist the global emergency notification system to … and gathering timelines, data points and action items, and following up with responsible parties for close-out of assigned action items. Collaborate with various teams, including Facilities, IT, Operations, Risk as well as BCP stakeholders within each line of business at the firm ; Work closely with development teams who own/maintain BC related software and platforms. Perform other … V-Lookups, etc.) Excellent interpersonal and communication skills (written, verbal, presentation) Demonstrated skill in development of working relationships with key contacts both inside and outside the organization Understand Operational Risk in the Finance sector. Proven ability to work independently and manage multiple project initiatives, and as part of a team Ability to coordinate and implement Business Continuity strategies and More ❯
leadership initiatives Participating in a 24x7 on-call rota Required Skills and Qualifications Proven experience in security roles, ideally in areas such as security operations, vulnerability management, security assurance, risk management, or project consultancy A proactive attitude and enthusiasm for cybersecurity, with a desire to learn Understanding of riskassessment frameworks and methodologies Strong communication skills, capable More ❯
best, so we are always in search of the best people to join our ever-growing talented team. Responsibilities: Design and maintain a robust technology control testingframework aligned with risk management standards (e.g.,NIST, ISO 27001, COBIT, ITIL). Develop and update testing methodologies, ensuring theyaddress key risks related to IT infrastructure, cybersecurity,cloud services, and software development. Establish … and maintain control testing policies andprocedures that align with regulatory and internalgovernance requirements. Ensure the control testing framework integrates seamlesslywith the broader Operational Risk Management Framework(ORMF). Maintain a comprehensive control library, mapping controlsto risks and business objectives. Plan and execute detailed control testing activities acrossIT operations, systems, and processes, including: - Cybersecurity controls (e.g., firewalls, encryption, accessmanagement). … Data protection controls (e.g., GDPR compliance, databackups). - Incident management processes and disaster recoverytesting. Test both the design and operating effectiveness of ITcontrols. Prioritise control testing activities based on risk assessments, focusing on high-risk areas such as paymentsystems, customer data protection, and regulatoryreporting. Document and communicate control deficiencies torelevant stakeholders. Work with technology teams to develop, track More ❯
Advisor Location: Leek Wootton Salary: £48,894.00 - £54,879.00 Permanent Full time Job Purpose: To provide professional guidance and specialist advice with regard to all information assurance, security and risk matters and ensure development and implementation of all necessary policies, procedures and processes to achieve compliance with national codes of connection for Police information systems and the SYAP. To … compliance checks to ensure the physical and data security protection of all information systems and information assets. Ensuring compliance with information security requirements, national guidance, standards, policies, and information risk management, covering both the Force and relevant Suppliers and 3rd parties To identify information security and assurance requirements creating RiskAssessment Reports and/or reviewing other … of this post, as required Special conditions: Regular travel throughout Warwickshire Person Specification: Knowledge: A Levels, or equivalent, qualification. To hold a recognised information security, data protection or information risk qualification qualification (e.g Certified Information Security Manager (CISM), CISSP, GCRC, CRISC, DP PDP, BCS etc) Sound practical knowledge of current Information Security Cyber and Assurance Management standards and best More ❯
Advisor Location: Leek Wootton Salary: £48,894.00 - £54,879.00 Permanent Full time Job Purpose: To provide professional guidance and specialist advice with regard to all information assurance, security and risk matters and ensure development and implementation of all necessary policies, procedures and processes to achieve compliance with national codes of connection for Police information systems and the SYAP. To … compliance checks to ensure the physical and data security protection of all information systems and information assets. Ensuring compliance with information security requirements, national guidance, standards, policies, and information risk management, covering both the Force and relevant Suppliers and 3rd parties To identify information security and assurance requirements creating RiskAssessment Reports and/or reviewing other … of this post, as required Special conditions: Regular travel throughout Warwickshire Person Specification: Knowledge: A Levels, or equivalent, qualification. To hold a recognised information security, data protection or information risk qualification qualification (e.g Certified Information Security Manager (CISM), CISSP, GCRC, CRISC, DP PDP, BCS etc) Sound practical knowledge of current Information Security Cyber and Assurance Management standards and best More ❯
wrap and technical metrics for performance review. Person specification This role may be suitable for someone with previous experience in data analysis, Microsoft Azure, IT service management, information management, risk management and/or governance and data protection. You’ll Need: Experience in supporting and coaching colleagues. Acute attention to detail. Great organisation, timekeeping and prioritisation skills. Able to … against these behaviours during the selection process: Making Effective Decisions Managing a Quality Service Technical skills We'll assess you against these technical skills during the selection process: Information riskassessment and risk management Threat understanding Legal and regulatory environment and compliance Protective security Alongside your salary of £36,530, Ministry of Defence contributes £10,582 towards … of technical ability. Interviews We’ll assess you against these behaviours and technical skills during the interview process: Behaviours Making effective decisions Managing a quality service Technical Skills Information riskassessment and risk management Threat understanding Legal and regulatory environment and compliance Protective security The Government Security Profession Career Framework and the Vulnerability Management professional role used More ❯
more exclusive features. About Salary: £48,894.00 - £54,879.00 Permanent Full time Job Purpose To provide professional guidance and specialist advice with regard to all information assurance, security and risk matters and ensure development and implementation of all necessary policies, procedures and processes to achieve compliance with national codes of connection for Police information systems and the SYAP. About … Advisor Location: Leek Wootton Salary: £48,894.00 - £54,879.00 Permanent Full time Job Purpose To provide professional guidance and specialist advice with regard to all information assurance, security and risk matters and ensure development and implementation of all necessary policies, procedures and processes to achieve compliance with national codes of connection for Police information systems and the SYAP. To … compliance checks to ensure the physical and data security protection of all information systems and information assets. Ensuring compliance with information security requirements, national guidance, standards, policies, and information risk management, covering both the Force and relevant Suppliers and 3rd parties To identify information security and assurance requirements creating RiskAssessment Reports and/or reviewing other More ❯
Role Purpose NCC Group provides Information Assurance consultancy to help companies protect critical systems and information. We do this by defining security strategies, developing policies, conducting security maturity and risk assessments and implementing security solutions. We also provide security staff augmentation to clients so that our consultants may occupy security roles within the client environment in the short, medium … or long term. Our core consulting and implementation services include: On-demand virtual roles Data discovery and mapping Risk advisory and assurance Continuity/Resilience Data privacy and GDPR ISO 27001 & NIST CSF PCI, PA & P2PE Cyber security review SOC advisory & implementation XDR consulting & implementation Alongside our core services, we have a range of bespoke services to help organisations … conduct of documentation reviews, assessing technical solutions and systems as well as presenting information and advice to senior business partners. Translate the technical and non-technical findings from an assessment or exercise into relevant, actionable remediation road maps for customers. Responsible for adhering to all internal policy and procedures in relation to security and quality best practice. Ability to More ❯
London, England, United Kingdom Hybrid / WFH Options
Coalition, Inc
Get AI-powered advice on this job and more exclusive features. About us Coalition is the world's first Active Insurance provider designed to help prevent digital risk before it strikes. Founded in 2017, Coalition combines comprehensive insurance coverage and innovative cybersecurity tools to help businesses manage and mitigate potential cyberattacks. Opportunities to make an impact with bold thinking … responsible for measuring, understanding, and helping optimize Coalition’s underwriting. You will perform statistical analysis to provide data-driven insights. You will help us understand and improve our cyber risk selection and reduction, pricing and automation in order to grow our revenue in a safe and efficient manner. Responsibilities Analyze diverse datasets including claims data, cybersecurity risk signals … and underwriting databases to extract meaningful patterns and insights Large scale data analysis with the objective of producing valuable risk signals to be used for underwriting or risk evaluation of organizations Develop and refine statistical and machine learning models to assess cybersecurity risks with applications to underwriting and pricing. Create comprehensive reports on underwriting efficiency metrics and riskMore ❯
Basildon, England, United Kingdom Hybrid / WFH Options
Leonardo UK Ltd
on deliverable artefacts. Form part of a wider Product IA and Security community across Leonardo Electronics UK, influencing corporate policies, processes and guidance. Generation of Security Management Plans, Security Risk Assessments, Security Design and Management Documentation, and risk Remediation Action Plans. Create artefacts, support Product Design Reviews and Product Security deliverable information (Product Integrity certificates, product security cases. … What you’ll bring You will have experience of owning a security risk management system for highly regulated products based on recognised frameworks. As well as this, you will have a good understanding of engineering development lifecycles and how product security specialism is aligned. Engineering degree with minimum 5 years’ experience in product security and CISSP, CISM or equivalent … qualification Practical experience of risk management frameworks (NIST SP800-37, ISO27001) Practical experience of riskassessment processes (NIST SP800-30 and ISO 27005) Practical experience of applying security controls (NIST SP800-53 and ISO27002) Practical experience of Secure by Design requirements (ISN 2023/09) Demonstrable experience of writing IA Technical Risk Assessments and the management More ❯
business units, as requested, when a business disruption occurs and assist with recovery efforts Help Maintain the internal Business Continuity Management Website and network shared drive Participate in vendor risk management program on behalf of the BC in the Business Continuity review and evaluation in the vendor risk management program Co-assist the global emergency notification system to … and gathering timelines, data points and action items, and following up with responsible parties for close-out of assigned action items. Collaborate with various teams, including Facilities, IT, Operations, Risk as well as BCP stakeholders within each line of business at the firm ; Work closely with development teams who own/maintain BC related software and platforms. Perform other … V-Lookups, etc.) Excellent interpersonal and communication skills (written, verbal, presentation) Demonstrated skill in development of working relationships with key contacts both inside and outside the organization Understand Operational Risk in the Finance sector. Proven ability to work independently and manage multiple project initiatives, and as part of a team Ability to coordinate and implement Business Continuity strategies and More ❯
Bristol, England, United Kingdom Hybrid / WFH Options
Cyber UK
Recruitment Service (AFRS). Delivered through a partnership of the MOD, Serco, and our consortium of partners, this service will provide end-to-end support from candidate attraction to assessment, onboarding, and Phase 1 training. Our team brings together best-in-class integrated technology and specialist partners to offer a holistic recruitment and skills solution for the UK Armed … responsibilities of the role: Engage with key industry partners and suppliers to ensure ongoing compliance with MOD standards (e.g., Secure By Design, DefStan 05-138). Conduct information security riskassessment and management using recognized frameworks such as NIST SP800. Perform information security assurance activities and manage incidents. Establish and manage internal and external Security Working Groups. Support … Design, JSP 440, and DefStan 05-138/DCPP. ISO27001 Lead Implementer/Auditor, CISSP or CISM. Strong understanding of data protection compliance and relevant privacy certifications. Proficiency in risk management using recognised frameworks like NIST. Experience in creating and delivering security awareness training. Ability to work effectively with stakeholders to support contract and business unit needs. Clear communication More ❯
related compliance (e.g. ISO/IEC 27001 and SOC 2 certification). What you'll be doing Develop, implement and monitor a strategic, comprehensive enterprise information security and IT risk management program. Work directly with the business units to facilitate riskassessment and risk management processes. Develop and enhance an information security management framework. Manage the … and standards across all technology projects, systems and services. Provide leadership to the enterprise's information security organization. Partner with business stakeholders across the company to raise awareness of risk management concerns. Assist with the overall business technology planning, providing a current knowledge and future vision of technology, data and systems. Developing internal data and reporting strategies and systems. … related projects. What you'll bring to the team Degree in business administration or a technology-related field required. Professional security management certification. Extensive experience in a combination of risk management, information security and IT jobs. Knowledge of common regulatory and information security management frameworks, such as ISO/IEC 27001, NIST, SOC 2 and GDPR. Excellent written and More ❯
London, England, United Kingdom Hybrid / WFH Options
Bridewell Consulting Limited
delivering and leading a range of data privacy projects. This could cover implementation of Data Privacy Frameworks aligned to legal requirements and standards, such as ISO27701 and NIST Privacy RiskAssessment Methodology. With Bridewell continuing to grow, you’ll build and manage a high performing team of Senior Consultants, Consultants and Junior Consultants, and Quality Assure other consultants … Practical experience of developing, maintaining and implementing Data Privacy Frameworks in a variety of organisations including during times of large-scale transformation. Practical experience of applying a range of risk management approaches, conducting risk assessments and being able to articulate risk effectively. Practical experience of providing independent support and advice on a wide variety of privacy issues. More ❯
security into the DNA of business operations. As a key member of the leadership team, you will be responsible for shaping our security roadmap, fostering a culture of proactive risk management, and ensuring our systems, data, and operations are safeguarded—without compromising agility or business delivery. Key Responsibilities: Strategic Leadership Define and execute the company’s overarching IT and … and improve our systems. Oversee threat modeling, vulnerability assessments, and incident response frameworks. Hands-on expertise in probing for security vulnerabilities in medium to large-scale organizations. Technology Governance & Risk Develop and maintain a unified and flexible control framework, working to integrate the requirements of global laws, standards, and regulations. Lead riskassessment efforts and ensure a … balance between protection and productivity. Partner with Legal, HR, Product, and Engineering teams to align technology risk with business initiatives. Innovation & Operational Excellence Drive continuous improvement in IT infrastructure and cloud security through emerging technologies and automation. Evaluate and adopt cutting-edge tools and methodologies for threat detection, response, and prevention. Manage the IT & Security budget, vendors, and tooling More ❯
Job Title: Director, UW Portfolio Leader: Global Risk Selection and Rating Department: Business Agility Operations Location: London Duration: Permanent About the Department & Team: The role will be responsible for Global Product ownership of GRS business objectives within the Underwriting Domain for Agile Products spanning the core capabilities of all RiskAssessment, Coverage, Rating and Pricing technology capability … to the quality and consistency of Digital Product and Portfolio Roadmaps, Maintaining healthy Backlogs, product Catalogues, Opportunities for reuse and resilience. • Ultimate decision maker for Priority calls for Global Risk Selection and Rating Products for Technology investments/trade-offs, though the investment appetite will be set by COOs. Skills and Experience: • Strong key stakeholder management and influencing skills … expectations. • Comfortable with making decisions with some level of uncertainty. • Strong communication skills, both written and verbal. About Liberty Specialty Markets (LSM) Liberty Specialty Markets is part of Global Risk Solutions and the broader Liberty Mutual Insurance Group, which is a leading global insurer. We offer a breadth of world-class insurance and reinsurance services to brokers and insureds More ❯
London, England, United Kingdom Hybrid / WFH Options
Blockchain.com
a time. As a Financial Crime Compliance Manager and Cayman Islands MLRO , you will be responsible for a number of elements of the Blockchain.com compliance program. This scope includes riskassessment, policy development and regulatory requirement analysis for the Group in addition to acting as the Money Laundering Reporting Officer for the Blockchain.com Cayman Islands entity. WHAT YOU … review and update AML/CTF processes to ensure effectiveness and compliance with changing regulations and best practices in the payment/e-money industry. Support reporting on compliance risk indicators and workflow metrics for consumption by senior management. Partner closely with cross-functional partners (Legal, Product, Business) to support the growth of the Institutional Business, in line with … Company goals and risk appetite. Conduct regular risk assessments to identify potential AML/CTF risks associated with Blockchain.com’s Cayman Islands entity. This includes evaluating customer profiles, transaction patterns, and the types of services offered. As the MLRO, oversee and manage regulatory reporting requirements (eg. SAR filings) to the Cayman Islands Financial Intelligence Unit. Manage the UK More ❯