This program plays a central role in the bank's digital transformation. The team operates in an Agile setup, offering a collaborative and forward-thinking environment. The role combines riskassessment, advisory, and data governance with a focus on privacy and regulatory compliance. Function description Riskassessment & governance Conduct Data Protection Impact Assessments (DPIAs) in various … data analytics, data governance, BI, reporting) Languages Dutch: fluent English: fluent French: optional Experience First professional experience in a similar role, or strong interest in data privacy, data quality, risk management or digital ethics Good development skills (technical or analytical background preferred) Soft skills Team player and proactive mindset Strong analytical and synthesis skills Excellent communication and stakeholder management More ❯
to ensure systems are secure, compliant, and properly configured according to federal regulations. Additionally, in this position you will: Strengthen Our Defense: Perform Security Technical Implementation (STIG) review, Self-Assessment, and participate in Assessment & Authorizations testing to ensure our system stay secure and compliant. Shape Security Policy: use your expertise to apply a comprehensive range of cybersecurity policies … security standards. Participate in incident response activities, including identifying, reporting, and helping to resolve security incidents. Contribute to the development and delivery of security awareness training for staff. Drive Risk Management: Perform risk analysis for system changes, contribute to the Risk Management Framework process and recommend security solutions to address any identify gaps. Maintain Security Documentation: Ensure … all system documentation is up to date. POAMs: Manage and Maintain Plans of actions and milestones, by tracking remediation efforts, validating closure evidence, prioritizing and communicating risk, and ensuring timely. Oversee Configuration Management: Manage changes to security-relevant software, hardware, and firmware to maintain system security. Basic Qualifications: As a requirement of this position, all candidates must be a More ❯
to ensure systems are secure, compliant, and properly configured according to federal regulations. Additionally, in this position you will: Strengthen Our Defense: Perform Security Technical Implementation (STIG) review, Self-Assessment, and participate in Assessment & Authorizations testing to ensure our system stay secure and compliant. Shape Security Policy: use your expertise to apply a comprehensive range of cybersecurity policies … security standards. Participate in incident response activities, including identifying, reporting, and helping to resolve security incidents. Contribute to the development and delivery of security awareness training for staff. Drive Risk Management: Perform risk analysis for system changes, contribute to the Risk Management Framework process and recommend security solutions to address any identify gaps. Maintain Security Documentation: Ensure … all system documentation is up to date. POAMs: Manage and Maintain Plans of actions and milestones, by tracking remediation efforts, validating closure evidence, prioritizing and communicating risk, and ensuring timely. Oversee Configuration Management: Manage changes to security-relevant software, hardware, and firmware to maintain system security. Basic Qualifications: As a requirement of this position, all candidates must be a More ❯
flows, and functional specifications. Act as a liaison between business, IT, and cybersecurity teams to ensure alignment of objectives. Support the design and implementation of asset management tools, vulnerability assessment platforms, and reporting dashboards. Ensure compliance with industry standards, regulations, and best practices in asset and vulnerability management. Facilitate workshops, stakeholder meetings, and presentations to drive decision-making and … Analyst, ideally within the utilities, energy, or critical infrastructure sectors. Someone who has worn many hats in IT - an all-rounder Asset Management Expertise: Familiarity with asset lifecycle management, riskassessment, and associated tools or platforms. Vulnerability Management Knowledge: Experience in vulnerability identification, tracking, and remediation processes. Technical Understanding: Knowledge of cybersecurity frameworks (e.g., NIST, ISO 27001) and … and process maps. Stakeholder Engagement: Proven ability to build relationships and influence stakeholders at all levels. Tool Proficiency: Experience with tools such as ServiceNow, Power BI, JIRA, or vulnerability assessment platforms is highly desirable. Communication Skills: Excellent verbal and written communication, with the ability to present complex information clearly. Education: Bachelor's degree in Business Administration, Information Technology, or More ❯
organization's environment. This role focuses on ensuring compliance with security standards and controls, developing, maintain and monitor against a consolidated remediation roadmap to drive improvements that reduce security risk to an acceptable level. The individual will oversee security risk reduction reporting, maintaining strong security risk practices and rigour within the team and be a security champion … driving a positive risk culture across the organisation. The position will require close collaboration with technical, operational, compliance and audit teams to create a secure and compliant technology environment. Develop, maintain security remediation oversight, and conduct reviews across all my client's environments, services, and assets, ensuring compliance with industry standards (e.g., CIS, NIST, ISO 27001, SOC 1/… and controls and align security risks. Oversee the remediation review lifecycle, testing of evidence related to remediation plans, producing regular reporting at relevant levels confirming direction of travel of risk improvement or decline. Collaborate with security and IT teams on monitoring vulnerability and patch management progress against standards and controls guidelines, with oversight of remediation and timing to reduce More ❯
insights, and identify opportunities to integrate improvements and new features into the user flow and product roadmap. Advocate for user needs while balancing business requirements and technical feasibility. Innovation & Risk Management: Drive innovation by identifying emerging technologies and trends that may affect the product landscape. Proactively manage product risks, ensuring that potential roadblocks are identified and mitigated early in … and innovative approach to overcoming product challenges and seizing new opportunities. Data-Driven Decision Making: Comfortable with data analysis and making decisions based on KPIs, metrics, and performance analytics. Risk Management: Experience in riskassessment and mitigation strategies, ensuring smooth product delivery and minimizing potential disruptions. About S&P Global Ratings S&P Global Ratings is the … securities. We offer an independent view of the market built on a unique combination of broad perspective and local insight. We provide our opinions and research about relative credit risk; market participants gain independent information to help support the growth of transparent, liquid debt markets worldwide. S&P Global Ratings is a division of S&P Global (NYSE: SPGI More ❯
responsibilities include, but are not limited to: • Analyze complex datasets using statistical and machine learning techniques to extract insights and patterns. • Develop predictive models for forecasting, anomaly detection, and risk assessment. • Collaborate with SMEs to understand domain-specific data and requirements for analysis. • Implement data mining and exploratory data analysis techniques to uncover hidden trends and correlations. • Perform data … and creating data driven solutions for decision making. • Experience analyzing complex datasets using statistical and machine learning techniques to extract insights and patterns. • Experience developing forecasts, anomaly detection and risk assessments. • Excellent written and verbal communications. • Experience with stakeholder collaboration management, and briefings. • Advanced ability to evaluate and synthesize multiple sources of information to creatively inform decision options that More ❯
a company that simplifies and enhances financial opportunities using state-of-the-art technology. About the Position Interactive Brokers (U.K.) Limited, based in central London, is looking for a RiskAssessment Analyst to join our New Accounts department. We seek applicants with a keen attention to detail to join our Enhanced Due Diligence process. If you have experience … public domain searches for negative information about applicants and associated entities. Provide advice on issues and escalations to other New Accounts Teams to address difficult applications and independently recommend risk-based decisions to AML. Responsible for timely escalations of suspected financial crime to AML; Work closely with other New Account Teams and AML to review and evaluate all financial … concentration in Finance, Law, Accounting, or Information Systems, etc. Minimum of 2 years' experience and familiarity, preferably gained in brokerage or corporate banking environment, with onboarding or reviewing high-risk client relationships and carrying out EDD. Excellent written and oral communication skills in English. Strong research, investigatory, and problem-solving skills. Ability to make risk-based recommendations and More ❯
LEAD IT RISK & CONTROL WHAT IS THE OPPORTUNITY? "The Lead IT Risk Controls Analyst is a subject-area specialist with specialized training, methods and analytic techniques to create recommendations and directions for cyber risk mitigation in a complex technical environment. Focus areas of security assessment by the Lead ITRC Security Analyst includes third party security and … overall security program effectiveness in mitigating risk. The ITRC Analyst's goal to create actionable information for IT and business leadership, and to provide objective assessment of cyber security risks for auditors, regulators and external parties. This requires routinely authoring detailed reports and gathering metrics ensure stakeholders receive accurate and complete information. The Lead ITRC tkeeps abreast of external … cyber security trends, technologies and cyber risk management approaches, and often works with other teams on cyber risk-related initiatives to provide subject-matter recommendations and guidance to achieve a posture within the bank's overall risk appetite. The Lead ITRC serves as an expert area of specialization. This role is a working lead that provides functional More ❯
LEAD IT RISK & CONTROL WHAT IS THE OPPORTUNITY? "The Lead IT Risk Controls Analyst is a subject-area specialist with specialized training, methods and analytic techniques to create recommendations and directions for cyber risk mitigation in a complex technical environment. Focus areas of security assessment by the Lead ITRC Security Analyst includes third party security and … overall security program effectiveness in mitigating risk. The ITRC Analyst's goal to create actionable information for IT and business leadership, and to provide objective assessment of cyber security risks for auditors, regulators and external parties. This requires routinely authoring detailed reports and gathering metrics ensure stakeholders receive accurate and complete information. The Lead ITRC tkeeps abreast of external … cyber security trends, technologies and cyber risk management approaches, and often works with other teams on cyber risk-related initiatives to provide subject-matter recommendations and guidance to achieve a posture within the bank's overall risk appetite. The Lead ITRC serves as an expert area of specialization. This role is a working lead that provides functional More ❯
LEAD IT RISK & CONTROL WHAT IS THE OPPORTUNITY? "The Lead IT Risk Controls Analyst is a subject-area specialist with specialized training, methods and analytic techniques to create recommendations and directions for cyber risk mitigation in a complex technical environment. Focus areas of security assessment by the Lead ITRC Security Analyst includes third party security and … overall security program effectiveness in mitigating risk. The ITRC Analyst's goal to create actionable information for IT and business leadership, and to provide objective assessment of cyber security risks for auditors, regulators and external parties. This requires routinely authoring detailed reports and gathering metrics ensure stakeholders receive accurate and complete information. The Lead ITRC tkeeps abreast of external … cyber security trends, technologies and cyber risk management approaches, and often works with other teams on cyber risk-related initiatives to provide subject-matter recommendations and guidance to achieve a posture within the bank's overall risk appetite. The Lead ITRC serves as an expert area of specialization. This role is a working lead that provides functional More ❯
Head of Cyber Governance, Risk and Complience Join to apply for the Head of Cyber Governance, Risk and Complience role at Gespreksleider Jacobs Head of Cyber Governance, Risk and Complience 1 day ago Be among the first 25 applicants Join to apply for the Head of Cyber Governance, Risk and Complience role at Gespreksleider Jacobs Join … of the global economy! The Department for Business and Trade ('DBT') and Inspire People are partnering together to bring you an exciting opportunity for the Head of Cyber Governance, Risk and Compliance playing a pivotal role in shaping the success of the Cyber function and service. Salary between £71,738 to £93,864 (including allowances) plus excellent Civil Service … on location and technical skills as assessed at interview. Flexible, hybrid working from London, Cardiff, Darlington, Belfast, Birmingham, Salford and Edinburgh. About The Role As Head of Cyber Governance, Risk and Compliance (GRC) you will be playing a pivotal role in shaping the success of the Cyber function and service by ensuring that cyber security risks are monitored and More ❯
Charlton, England, United Kingdom Hybrid / WFH Options
Gespreksleider Jacobs
Head of Cyber Governance, Risk and Complience Join to apply for the Head of Cyber Governance, Risk and Complience role at Gespreksleider Jacobs Head of Cyber Governance, Risk and Complience 1 day ago Be among the first 25 applicants Join to apply for the Head of Cyber Governance, Risk and Complience role at Gespreksleider Jacobs Join … of the global economy! The Department for Business and Trade ('DBT') and Inspire People are partnering together to bring you an exciting opportunity for the Head of Cyber Governance, Risk and Compliance playing a pivotal role in shaping the success of the Cyber function and service. Salary between £71,738 to £93,864 (including allowances) plus excellent Civil Service … skills you will need for this opportunity Simply read the full description below to get a complete picture of candidate requirements. About The Role As Head of Cyber Governance, Risk and Compliance (GRC) you will be playing a pivotal role in shaping the success of the Cyber function and service by ensuring that cyber security risks are monitored and More ❯
leading provider of operations management consulting services with a purpose of saving lives and creating a sustainable future. dss + enables companies to build organisational and human capabilities, manage risk, improve operations, achieve sustainability goals and operate more responsibly. By leveraging its DuPont heritage, deep industry and management expertise and diverse team, dss + consultants are on the ground … required to make their vision a reality, in a practical actionable way. What will you do? As a Senior Operations Consultant with expertise on Process Hazard Analysis (PHA) and RiskAssessment & Management, you will lead specific workstreams within a wider Process Safety Management (PSM)/Operational Risk Management (ORM) transformation program, aiming at identifying, designing, and implementing … effective solutions within the area of expertise. You will provide subject matter expertise and lead project teams to help clients establishing and implementing robust RiskAssessment and Process Hazard Analysis programs and, in particular, building organizational capabilities to sustain performance. The ideal candidate must have strong expertise and proven experience in PHA and RiskAssessment Programs More ❯
processing activities comply with global privacy laws and regulations. This role involves collaborating with cross-functional teams to integrate privacy by design into all systems and processes, managing privacy risk, and ensuring our organization's adherence to data protection standards. Key Responsibilities: Design, implement, and manage comprehensive privacy frameworks and strategies to safeguard personal data and ensure compliance with … relevant privacy laws and regulations (e.g., GDPR, CCPA, HIPAA). Conduct privacy impact assessments (PIAs) and risk assessments to identify potential privacy risks. Develop and implement strategies to mitigate these risks and address vulnerabilities. Ensure adherence to international and local privacy regulations, standards, and industry best practices. Monitor changes in privacy laws and adjust policies and practices as necessary. … address and resolve issues. Provide support for privacy-related operational activities (e.g., consent collection, fulfilling data subject access requests, etc.). Maintain comprehensive documentation of privacy-related activities, including risk assessments, compliance audits, and policy updates. Prepare reports for management and regulatory bodies as needed. Serve as a subject matter expert by providing advice on privacy-related projects and More ❯
City of London, London, United Kingdom Hybrid / WFH Options
IPS Group
Assist in establishing a comprehensive resilience framework that meets DORA standards and other recognised guidelines (e.g. ISO 22301, ISO 27001, NIST). Draft internal controls, policies, training content, and riskassessment methodologies. Contribute to core DORA workstreams such as ICT risk management, scenario-based testing, and oversight of third-party providers. Stakeholder Engagement Coordinate workshops and sessions … operational leads. Monitor implementation progress and support a smooth transition into standard business processes. Training & Culture Develop and deliver resilience-focused training across various teams. Promote best practices in risk and continuity planning. Embed a culture of awareness, accountability, and continuous improvement. What We’re Looking For: A degree in Risk Management, Cyber Security, Information Technology, or a … resilience, cybersecurity, or regulatory roles. Solid understanding of UK and EU regulatory frameworks, with hands-on experience relating to DORA. Demonstrable experience conducting regulatory gap analyses, resilience testing, and risk assessments. Strong organisational skills and the ability to manage competing priorities in a deadline-driven environment. Excellent interpersonal and stakeholder management skills, particularly in regulated settings. Desirable Attributes: Relevant More ❯
Assist in establishing a comprehensive resilience framework that meets DORA standards and other recognised guidelines (e.g. ISO 22301, ISO 27001, NIST). Draft internal controls, policies, training content, and riskassessment methodologies. Contribute to core DORA workstreams such as ICT risk management, scenario-based testing, and oversight of third-party providers. Stakeholder Engagement Coordinate workshops and sessions … operational leads. Monitor implementation progress and support a smooth transition into standard business processes. Training & Culture Develop and deliver resilience-focused training across various teams. Promote best practices in risk and continuity planning. Embed a culture of awareness, accountability, and continuous improvement. What We’re Looking For: A degree in Risk Management, Cyber Security, Information Technology, or a … resilience, cybersecurity, or regulatory roles. Solid understanding of UK and EU regulatory frameworks, with hands-on experience relating to DORA. Demonstrable experience conducting regulatory gap analyses, resilience testing, and risk assessments. Strong organisational skills and the ability to manage competing priorities in a deadline-driven environment. Excellent interpersonal and stakeholder management skills, particularly in regulated settings. Desirable Attributes: Relevant More ❯
City of London, London, England, United Kingdom Hybrid / WFH Options
IPS Group
Assist in establishing a comprehensive resilience framework that meets DORA standards and other recognised guidelines (e.g. ISO 22301, ISO 27001, NIST). Draft internal controls, policies, training content, and riskassessment methodologies. Contribute to core DORA workstreams such as ICT risk management, scenario-based testing, and oversight of third-party providers. Stakeholder Engagement Coordinate workshops and sessions … operational leads. Monitor implementation progress and support a smooth transition into standard business processes. Training & Culture Develop and deliver resilience-focused training across various teams. Promote best practices in risk and continuity planning. Embed a culture of awareness, accountability, and continuous improvement. What We’re Looking For: A degree in Risk Management, Cyber Security, Information Technology, or a … resilience, cybersecurity, or regulatory roles. Solid understanding of UK and EU regulatory frameworks, with hands-on experience relating to DORA. Demonstrable experience conducting regulatory gap analyses, resilience testing, and risk assessments. Strong organisational skills and the ability to manage competing priorities in a deadline-driven environment. Excellent interpersonal and stakeholder management skills, particularly in regulated settings. Desirable Attributes: Relevant More ❯
Birmingham, Staffordshire, United Kingdom Hybrid / WFH Options
MN Climate Innovation Finance Authority (MNCIFA)
Job Description: Job Title Information Technology (IT) Auditor - Investment Banking Location Birmingham Corporate Title Assistant Vice President The Group Audit (GA) function takes a proactive, risk-based and independent approach to assist the Bank's business and infrastructure functions to identify key control weaknesses. You will be joining the global GA Investment Banking Application & Innovation Technology team reporting into … the effectiveness of internal IT controls supporting Innovation and Investment Banking areas including Fixed Income & Currencies, Electronic Trading, Origination and Advisory in accordance with GA methodology and the established riskassessment framework Conduct technology assessments, continuous monitoring and complete all work assignments on a timely basis - including planned audits, finding validations, and ad-hoc projects Prepare, coordinate and … and audit management, facilitate tracking and closure validation of findings Stay abreast of business/industry changes and their effect on the team's audit plan, GA methodology and risk assessments Pro-actively develop and maintain professional working relationships with colleagues, the business and respective support areas. Contribute to departmental projects and initiatives Your skills and experience Experience in More ❯
Verisk Analytics is a multinational data and analytics riskassessment company and a leading source of information about insurance risk. To serve our clients, we draw upon our vast experience in data management and predictive modelling to offer decision analytics to the insurance industry through underwriting to claims management in personal lines, commercial lines, and the London market. … In underwriting we create sophisticated risk models to assist insurers with risk selection and accurate pricing. Our range of models is broad spanning residential and commercial property perils, motor insurance, SME business covers, travel, pet and health insurance. To feed our risk models we source many diverse datasets covering high resolution weather data, property attributes, business activities … and manage cases more effectively. Role Purpose Verisk are looking for a Data Scientist to support the development of various data science models to support the development of our risk management products. The International Analytics Team is a dynamic and exciting place to work: our projects are extremely varied and include developing supervised machine learning models, unsupervisedclustering type models More ❯
For more than a decade, Karthik Consulting has been a reliable and trusted advisor to our Government customers, providing independent and unbiased recommendations and solutions to mitigate risk and help solve IT issues. We bring the innovation, passion, and agility of the commercial sector to meet the unique challenges of this competitive space. Karthik Consulting is seeking Cybersecurity Specialist … Air Force (HAF). This includes, but is not limited to, activities related to governance, strategic planning, enterprise architecture, capability portfolio management, solutions analysis, solution implementation planning, performance and risk management, IT service management, systems engineering, innovative project management, data and analytics, training, program analysis, policy analysis, information technology analysis, and administrative technical support. Additionally, the candidate will offer … Speaking and presenting • Planning and project management • Analytical thinking and problem-solving skills • Cooperation and unity of purpose • Flexibility and ongoing education • Task management • Leadership and management skills • Adaptability • Riskassessment and management Experience • Demonstrated capability in performing comprehensive risk assessments to identify and address potential security threats across large-scale programs, ensuring the protection of critical More ❯
products and services in almost 100 countries, united by a promise to be forever caring. Our solutions provide a range of benefits, from infection prevention and protection of at-risk skin, to improved patient outcomes and reduced care costs. Convatec's revenues in 2023 were over $2 billion. The company is a constituent of the FTSE 100 Index (LSE … implement improvements in key processes for greater efficiency and data-driven decision making. Complaint Management: Support execution and maintain procedures for complaint activities such as product investigations, ad hoc risk reviews, return process, intake process and product monitoring across all franchises. Execute quality engineering activities for all post-market product surveillance, including collection, analysis, and evaluation of product safety … processes as needed. Present complaint trend analyses to stakeholders in a timely and accurate manner while supporting root cause investigations. Design & Development Support: Maintain a current understanding of product risk profiles and reportable product harms/malfunctions. Provide risk-based input to project teams and participate in design control activities, including failure mode identification and historical complaint analysis. More ❯
control systems. Understanding of release branching strategies (Git Flow, Trunk-Based Development). Automation & Deployment Tools: Familiarity with Ansible, Kubernetes, Docker, Helm, SCCM, or Puppet for deployment automation. Monitoring & Risk Management: Ability to assess release risks, implement rollback strategies, and monitor deployments using tools like Splunk, Prometheus, Datadog. Organizing and Scheduling Releases: Working with various agency groups to understand … tools, version control systems, and deployment automation. Project & Stakeholder Management Skills: Excellent communication & coordination skills to collaborate with cross-functional teams, vendors, and business leaders. Strong problem-solving and riskassessment abilities to identify deployment risks and develop mitigation plans. Experience with project management tools (e.g., Jira, ServiceNow, Confluence, Microsoft Project) for tracking releases. Ability to manage multiple More ❯
Amherst, Massachusetts, United States Hybrid / WFH Options
University of Massachusetts Amherst
capabilities that enable the full lifecycle management of UMass Amherst account identities, credentials, and entitlements according to security, privacy, and compliance requirements. This position will perform security analysis and riskassessment and improve security by setting policies and standards. This position requires deep knowledge in Governance, Risk, and Compliance (GRC), solid understanding of data security, academic business … the university. Prepares and delivers training material independently or via third party training partners. Interfaces with, and responds to, internal and state auditor's requests as needed. Performs security risk assessments/audits in accordance with established security policies and procedures. Researches, recommends, and promotes IT security policies and guidelines which focus on protecting confidentiality, integrity, and availability of More ❯
Easter Howgate, Midlothian, United Kingdom Hybrid / WFH Options
Leonardo UK Ltd
This is an exciting opportunity to be part of significant programmes, during which you will ensure that products meet the highest standards, in accordance with customer's requirements and risk appetite. You will be supported in this role as part of a larger team of consultants, engineers and product domain specialists. Your work at Leonardo UK will see you … and detailed system and security designs as they pertain to the cyber domain. Decomposing cyber and security requirements down to the system control level. Conducting cyber and information security riskassessment activities including threat modelling, vulnerability analysis and analysis of mitigations. Scoping and managing security verification & validation activities and remedial action plans. Coordinating with product engineers, system architects More ❯