Fetcham, Surrey, United Kingdom Hybrid / WFH Options
Hays Technology
IT Risk and Policy (GRC) Analyst Permanent - Up to 38k + strong benefits Location: Hybrid - Leatherhead Your new company A leading construction and development company in Surrey is currently looking for an IT Risk and Policy (GRC) Analyst to come in and support the existing IT Risk & Policy Manager with the day-to-day tasks involved with … role is full-time, with a hybrid working pattern, usually around 2/3 days a week in the office. Your new role You will be supporting the IT Risk & Policy Manager across a broad variety of work, with the ability to gain a lot of different experience across multiple areas. The Analyst is responsible for managing IT risks … and governance aspects, with a focus on standards and regulations, whilst ensuring collaboration across the business to ensure strong IT practices are put in place. Ensuring that all IT risk and IT audit actions are highlighted, monitored, and escalated where appropriate. Maintaining the suite of IT policies and procedures. Providing support to the Privacy Team in ensuring GDPR compliance. More ❯
threat intelligence feeds, or monitoring tools. Performance Monitoring and Reporting Define and monitor key security performance indicators (KPIs). Produce regular security reports for senior management and boards. Track risk registers, exceptions, and remediation actions related to security. Stakeholder Engagement and Leadership Act as the senior security point of contact for internal and external stakeholders. Provide advice and consultancy More ❯
threat intelligence feeds, or monitoring tools. Performance Monitoring and Reporting Define and monitor key security performance indicators (KPIs). Produce regular security reports for senior management and boards. Track risk registers, exceptions, and remediation actions related to security. Stakeholder Engagement and Leadership Act as the senior security point of contact for internal and external stakeholders. Provide advice and consultancy More ❯
security health checks Provide expert advice and guidance on all cyber security related matters and ensure the wider technology teams are engaged and supported Manage and drive the security riskregister Ensure our suppliers and vendors are appropriately assessed against our security controls frameworks and comply with our security standards and any certification claims Promote a culture of … Excellent written and verbal communication skills with the ability to translate technical speak into easy to understand noncomplex language Able to engage with senior leaders to promote, and enable risk based decision making Working Hours 09.00 - 17.30 Monday- Friday Apply for this position Full Name Email Phone Upload CV/Resume Allowed Type(s): .pdf, .doc, .docx By using … this form you agree with the storage and handling of your data by this website. Register with us and one of our experienced iPeople recruits will let you know when the perfect job becomes available. Do you know someone you think would be perfect for one of our job vacancies? Subscribe to get notifications when new job openings are More ❯
Construction Cloud (ACC) and SharePoint for document control, mark-ups, and collaboration with PMO teams. Reporting: Produce weekly progress reports, track blockers, and provide clear next steps and recommendations. Risk Management: Maintain a project riskregister and trace all risks back to cost and time impacts. Compliance & Safety: Ensure adherence to all safety standards and regulatory requirements. More ❯
East Sussex, England, United Kingdom Hybrid / WFH Options
Areti Group | B Corp™
infrastructure scalability, performance, and data integrity. Maintain compliance with IT governance, cybersecurity, and data protection policies (e.g. ISO 27001, GDPR). Produce and maintain project documentation — including project plans, risk registers, and change logs. Manage stakeholder communication, status reporting, and escalation processes. Support system upgrades, migrations, and integrations with enterprise systems (e.g. ERP, asset management, or field service tools More ❯
brighton, south east england, united kingdom Hybrid / WFH Options
Areti Group | B Corp™
infrastructure scalability, performance, and data integrity. Maintain compliance with IT governance, cybersecurity, and data protection policies (e.g. ISO 27001, GDPR). Produce and maintain project documentation — including project plans, risk registers, and change logs. Manage stakeholder communication, status reporting, and escalation processes. Support system upgrades, migrations, and integrations with enterprise systems (e.g. ERP, asset management, or field service tools More ❯
SLAs, quality gates, secure access, and code ownership. Manage engineering/infrastructure budgets and provide strategic oversight for FinOps practices, unit economics tracking, and the maintenance of a transparent riskregister and remediation plans. Execution and delivery Lead disciplined engineering execution across distributed in-house and outsourced teams. Champion 24/7/365 platform operations with SLAs … capacity planning, incident response and post-mortems Implement structured software release governance, migration frameworks, and robust QA practices. Drive predictable delivery (quarterly planning, dependency/risk management, quality gates). Establish and enforce best-in-class DevOps, trunk-based, CI/CD, and monitoring standards. Sponsor the adoption of secure SDLC, threat modelling, vulnerability management, identity/authorisation, privacy … management, and privacy by design. Ability to partner with product and legal teams on security trade-offs and customer due diligence. Skilled in agile delivery, quarterly planning, dependency/risk management, and quality assurance. Ability to drive predictable delivery, manage technical debt, and continuously improve engineering velocity. Strong financial acumen: managing engineering/cloud budgets, AWS FinOps, and tracking More ❯
digital estate, encompassing enterprise IT, operational technology (OT), and research platforms. This role sits within the Information & Cyber Security Group and provides subject matter expertise in security architecture, cyber risk governance, and assurance frameworks. This is a cross-functional role with both advisory and hands-on responsibilities, focusing on security assurance, risk management and supporting architecture reviews, vulnerability … management, risk assessments, cyber defence posture, driving technical assurance, and embedding risk-aligned security controls across IT and OT systems and secure-by-design practices. You will work across hybrid environments including cloud, infrastructure, applications, and OT systems. You will be responsible for designing and advising on security architecture patterns, reviewing and maintaining risk registers, leading assurance … Cyber Essentials (CE and CE+) while supporting the secure operation of core services. The role requires strong stakeholder engagement, technical depth, and a sound understanding of UK-specific cyber risk frameworks. You will help shape and maintain a secure posture across UKAEA. A degree in Cybersecurity, Information Technology, or a STEM subject (or equivalent experience). Essential o Security More ❯
Work with technical teams to document and manage project assumptions and dependencies Ensure requirements are managed, recorded, and signed off in the designated tool for the project Maintain a riskregister and validate contingency costs against identified threats and opportunities Identify and deliver opportunities for project expansion with the Account team Job Requirements: Extensive experience in managing a More ❯
East Midlands, England, United Kingdom Hybrid / WFH Options
Rayner Personnel
make sure everyone is aligned. Collaborate with teams across the business (and directly with customers) to bring clarity, focus, and momentum. Build and manage detailed project plans, timelines, and risk registers. Run engaging project sessions — from kick-offs and stand-ups to retrospectives and reviews. Report progress and insights clearly to senior leadership, keeping communication sharp and transparent. Coordinate More ❯
data, and operations across a growing organisation. Key responsibilities:* Design and implement security policies and procedures aligned with ISO 27001, NIST, and other recognised frameworks. * Manage the information security riskregister and lead internal and external audits. * Oversee incident response, including investigation, containment, and recovery. * Conduct vendor security assessments and review contractual security requirements. * Lead day-to-day More ❯
ideal for someone who thrives in a fast-paced, multi-contract environment. Key Responsibilities Lead delivery of MOD projects across multiple contracts, producing and maintaining high-quality documentation (PMPs, risk registers, schedules). Maintain oversight of all active projects, ensuring alignment with contractual scopes and internal service readiness. Act as a key contact for technical issue resolution and service More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Sanderson
Cyber Security Lead to drive cybersecurity across a family of independent specialist schools. You will take ownership of protecting staff, students, and data, coordinating with multiple MSPs, managing cyber risk, monitoring threats, and embedding robust security practices across the organisation. Key Responsibilities: Act as the central point for all cybersecurity matters and incident response. Maintain the cybersecurity riskregister and lead Cyber Essentials certification. Oversee Microsoft 365 and Google Workspace security, including vulnerability management, patching, MFA, and email security. Coordinate security audits, penetration tests, and third-party application reviews. Manage and monitor MSP performance, ensuring consistent security standards. Promote cybersecurity awareness, provide guidance, and support staff training. Report on cyber incidents, risks, and improvements to senior More ❯
london, south east england, united kingdom Hybrid / WFH Options
Undisclosed
and maintaining strong stakeholder relationships. Role purpose/summary : Deliver infrastructure projects from initiation to implementation, ensuring compliance with financial services standards. Develop and maintain project plans, budgets, and risk registers. Coordinate technical teams to produce clear, achievable designs and recovery documentation. Liaise with business stakeholders to capture requirements and provide guidance on best practices. Manage third-party vendors More ❯
slough, south east england, united kingdom Hybrid / WFH Options
Undisclosed
and maintaining strong stakeholder relationships. Role purpose/summary : Deliver infrastructure projects from initiation to implementation, ensuring compliance with financial services standards. Develop and maintain project plans, budgets, and risk registers. Coordinate technical teams to produce clear, achievable designs and recovery documentation. Liaise with business stakeholders to capture requirements and provide guidance on best practices. Manage third-party vendors More ❯
london (city of london), south east england, united kingdom Hybrid / WFH Options
Undisclosed
and maintaining strong stakeholder relationships. Role purpose/summary : Deliver infrastructure projects from initiation to implementation, ensuring compliance with financial services standards. Develop and maintain project plans, budgets, and risk registers. Coordinate technical teams to produce clear, achievable designs and recovery documentation. Liaise with business stakeholders to capture requirements and provide guidance on best practices. Manage third-party vendors More ❯
Leeds, West Yorkshire, England, United Kingdom Hybrid / WFH Options
Hays Specialist Recruitment Limited
project managers, helping to grow capability across the function. What you'll need to succeed Lead end-to-end delivery of large-scale transformation projects. Develop project scopes, plans, risk registers, and governance documentation. Apply Agile, MSP, or hybrid frameworks to ensure transparency and control. Manage resources, budgets, and interdependencies across workstreams. Integrate change management principles to support workforce More ❯
Lancaster, Lancashire, England, United Kingdom Hybrid / WFH Options
Butler Rose
to agreed timescales, budgets, and quality standards. Coordinate internal teams, suppliers, and third parties to ensure resources are effectively allocated. Maintain accurate project documentation, including action logs, progress updates, risk registers, and communication plans. Monitor and report on project progress, escalating issues or risks as needed. Schedule and attend internal and external meetings, recording and following up on key More ❯
Effectiveness (PUE) improvements, optimising cooling, power, and infrastructure for maximum efficiency. • Client Engagement & Service Delivery - Lead client tours, ensure service excellence, support project delivery, and maintain high client satisfaction. • Risk Management - Maintain an up-to-date RiskRegister, oversee all site inspections, ensure compliance with company procedures, and mitigate potential issues. • Capacity Optimisation - Manage and optimise space More ❯
Effectiveness (PUE) improvements, optimising cooling, power, and infrastructure for maximum efficiency. • Client Engagement & Service Delivery - Lead client tours, ensure service excellence, support project delivery, and maintain high client satisfaction. • Risk Management - Maintain an up-to-date RiskRegister, oversee all site inspections, ensure compliance with company procedures, and mitigate potential issues. • Capacity Optimisation - Manage and optimise space More ❯
Effectiveness (PUE) improvements, optimising cooling, power, and infrastructure for maximum efficiency. • Client Engagement & Service Delivery - Lead client tours, ensure service excellence, support project delivery, and maintain high client satisfaction. • Risk Management - Maintain an up-to-date RiskRegister, oversee all site inspections, ensure compliance with company procedures, and mitigate potential issues. • Capacity Optimisation - Manage and optimise space More ❯
security, GRC & PCI-DSS payments experience to join our client's growing Cyber Security team. They need somebody who has excellent knowledge in PCI-DSS along with good governance, risk and compliance experience and familiarity with other standards. Experience Required: At least 2-3 years in a Cyber security & GRC role Be a PCI-DSS expert around payments ISO … 27001and GDPR Knowledge of Risk Management, including risk identification, assessment, and mitigation techniques Good experience around Audits and compliance Any penetration testing experience would be a bonus You'll work closely with both internal and external stakeholders across Legal, Risk & Audit, Procurement, and IT to embed strong governance and maintain alignment with leading standards such as ISO … NIST CSF, GDPR, and other relevant regulations. Partner with internal teams to integrate governance and compliance into daily operations. Support policy reviews, updates, and communication across business units. Risk Management & Assurance Support risk identification, assessment, and treatment processes. Maintain risk registers and monitor remediation of control gaps and audit findings. Conduct risk assessments, control testing, and More ❯
security excellence. Salary - £65,000 per annum Location - South East Key Responsibilities - Act as the primary security advisor to clients or stakeholders - Lead regular security reviews and maintain the riskregister and exception process - Ensure services align with relevant security frameworks and demonstrate compliance through clear reporting and metrics - Own the organisation's security posture ensuring tools, processes More ❯
be the go-to person for audits, assessments, and compliance, and help shape the way the business manages security. In this role, you’ll manage policies, maintain the Cyber RiskRegister, and ensure all sites stay aligned while swiftly closing any gaps. In addition to lead third-party reviews, prepare the business for certifications, run engaging training sessions More ❯