Liverpool, England, United Kingdom Hybrid / WFH Options
S&W
Job Description What will you be doing? S&W Group is looking for an experienced Information Security Risk Professional with expertise in security compliance and assurance, ISO 27001 implementation, PMO (project management office), risk assessments, supply chain and working on other governance, risk and compliance projects within a team. You’ll be highly motivated, pro-active and … Chain Analyst, you’ll verify that third parties meet the minimum-security requirements to protect our organisation from a supply chain related attack or incident. You’ll apply relevant risk mitigations and deal with multiple stakeholders to ensure end to end treatment is applied. You’ll also be part of our PMO and governance and compliance processes and will … the business remains compliant to regulatory frameworks and good practice standards. This role works within the Information Security Team and collaborates with other teams such as Privacy, Legal, Group Risk, Infrastructure, SecOps and Procurement, providing you with great opportunities for stakeholder engagement – it’s a great time to join us at S&W. This role is a permanent position More ❯
birkenhead, north west england, united kingdom Hybrid / WFH Options
S&W
Job Description What will you be doing? S&W Group is looking for an experienced Information Security Risk Professional with expertise in security compliance and assurance, ISO 27001 implementation, PMO (project management office), risk assessments, supply chain and working on other governance, risk and compliance projects within a team. You’ll be highly motivated, pro-active and … Chain Analyst, you’ll verify that third parties meet the minimum-security requirements to protect our organisation from a supply chain related attack or incident. You’ll apply relevant risk mitigations and deal with multiple stakeholders to ensure end to end treatment is applied. You’ll also be part of our PMO and governance and compliance processes and will … the business remains compliant to regulatory frameworks and good practice standards. This role works within the Information Security Team and collaborates with other teams such as Privacy, Legal, Group Risk, Infrastructure, SecOps and Procurement, providing you with great opportunities for stakeholder engagement – it’s a great time to join us at S&W. This role is a permanent position More ❯
old swan, north west england, united kingdom Hybrid / WFH Options
S&W
Job Description What will you be doing? S&W Group is looking for an experienced Information Security Risk Professional with expertise in security compliance and assurance, ISO 27001 implementation, PMO (project management office), risk assessments, supply chain and working on other governance, risk and compliance projects within a team. You’ll be highly motivated, pro-active and … Chain Analyst, you’ll verify that third parties meet the minimum-security requirements to protect our organisation from a supply chain related attack or incident. You’ll apply relevant risk mitigations and deal with multiple stakeholders to ensure end to end treatment is applied. You’ll also be part of our PMO and governance and compliance processes and will … the business remains compliant to regulatory frameworks and good practice standards. This role works within the Information Security Team and collaborates with other teams such as Privacy, Legal, Group Risk, Infrastructure, SecOps and Procurement, providing you with great opportunities for stakeholder engagement – it’s a great time to join us at S&W. This role is a permanent position More ❯
warrington, cheshire, north west england, united kingdom Hybrid / WFH Options
S&W
Job Description What will you be doing? S&W Group is looking for an experienced Information Security Risk Professional with expertise in security compliance and assurance, ISO 27001 implementation, PMO (project management office), risk assessments, supply chain and working on other governance, risk and compliance projects within a team. You’ll be highly motivated, pro-active and … Chain Analyst, you’ll verify that third parties meet the minimum-security requirements to protect our organisation from a supply chain related attack or incident. You’ll apply relevant risk mitigations and deal with multiple stakeholders to ensure end to end treatment is applied. You’ll also be part of our PMO and governance and compliance processes and will … the business remains compliant to regulatory frameworks and good practice standards. This role works within the Information Security Team and collaborates with other teams such as Privacy, Legal, Group Risk, Infrastructure, SecOps and Procurement, providing you with great opportunities for stakeholder engagement – it’s a great time to join us at S&W. This role is a permanent position More ❯
offices (and 10 delivery centers) across four continents. Job Overview We are seeking a highly skilled and detail-oriented Python Data Engineer to join our dynamic audit and risk technology team. Based fully onsite in our Birmingham office , you will play a critical role in designing, developing, and maintaining data solutions that support audit, riskassessment, and … skills, and the ability to collaborate effectively with cross-functional teams. Key Responsibilities Data Modeling & Architecture Design, develop, and maintain logical and physical data models to support audit and riskassessment activities. Utilize data modeling tools (e.g., Erwin, Visio, Lucidchart ) to create and maintain models that reflect business and technical requirements. Data Engineering & Pipelines Build, optimize, and maintain … on relational and NoSQL platforms. Analytics & Reporting Develop and implement reporting and analytics using Python, SQL, and Tableau . Create interactive dashboards that clearly present insights, audit findings, and risk assessments. Collaboration & Analysis Work closely with auditors, stakeholders, and IT teams to gather data requirements and ensure technical solutions align with audit objectives. Perform comprehensive data analysis, validation, and More ❯
providing strategic guidance on delivery timelines and client priorities. Expert Advisory & Consulting Post-Adaptation Strategy: Deliver high-level consulting and advice on post-adaptation strategies, helping clients transition from riskassessment to actionable, long-term resilience plans. Regulatory Guidance: Serve as an expert on emerging sustainability regulations, including TCFD, CSRD, and IFRS S2, guiding clients through compliance related … to physical risk. Physical RiskAssessment: Oversee or conduct high-level physical risk assessments, scenario modeling, and vulnerability analysis for clients. Product Co-Development Product Input: Leverage deep client needs and market expertise to co-develop the next generation of our SaaS product. Translating Expertise: Translate client challenges and emerging market needs into clear, functional requirements for More ❯
think innovatively, and listen to each other and customers in meaningful ways. Moody's is transforming how the world sees risk. As a global leader in ratings and integrated riskassessment, we're advancing AI to move from insight to action-enabling intelligence that not only understands complexity but responds to it. We decode risk to unlock … into actions, and uphold trust through integrity. The Director, Tech Advisory is a senior leader within Moody's Insurance Business Unit, responsible for shaping the future of insurance analytics, risk management, and workflow transformation. You will lead a high performing team of technical architects, specialists, and developers, delivering innovative solutions that redefine client risk workflows and unlock new … and market innovators - you will design and demonstrate cutting edge architectures, proof of concept analytics, and migration strategies that help clients realize the full potential of Moody's Intelligent Risk Platform (IRP) and broader risk and data offerings. This is both a strategic and hands on role: you will champion best practices, enforce technical and architectural standards, and More ❯
team and work on client and internal projects. Key Skills and Experience: 7+ years in Cyber Security roles Defence Experience: A solid background in working on defence-related projects. RiskAssessment and Architecture: Proven experience in creating riskassessment and architecture documentation. Penetration Testing Processes: A comprehensive understanding of pen testing procedures, including reporting, triaging, and More ❯
team and work on client and internal projects. Key Skills and Experience: 7+ years in Cyber Security roles Defence Experience: A solid background in working on defence-related projects. RiskAssessment and Architecture: Proven experience in creating riskassessment and architecture documentation. Penetration Testing Processes: A comprehensive understanding of pen testing procedures, including reporting, triaging, and More ❯
team and work on client and internal projects. Key Skills and Experience: 7+ years in Cyber Security roles Defence Experience: A solid background in working on defence-related projects. RiskAssessment and Architecture: Proven experience in creating riskassessment and architecture documentation. Penetration Testing Processes: A comprehensive understanding of pen testing procedures, including reporting, triaging, and More ❯
team and work on client and internal projects. Key Skills and Experience: 7+ years in Cyber Security roles Defence Experience: A solid background in working on defence-related projects. RiskAssessment and Architecture: Proven experience in creating riskassessment and architecture documentation. Penetration Testing Processes: A comprehensive understanding of pen testing procedures, including reporting, triaging, and More ❯
team and work on client and internal projects. Key Skills and Experience: 7+ years in Cyber Security roles Defence Experience: A solid background in working on defence-related projects. RiskAssessment and Architecture: Proven experience in creating riskassessment and architecture documentation. Penetration Testing Processes: A comprehensive understanding of pen testing procedures, including reporting, triaging, and More ❯
team and work on client and internal projects. Key Skills and Experience: 7+ years in Cyber Security roles Defence Experience: A solid background in working on defence-related projects. RiskAssessment and Architecture: Proven experience in creating riskassessment and architecture documentation. Penetration Testing Processes: A comprehensive understanding of pen testing procedures, including reporting, triaging, and More ❯
exciting role, your key focus will be to ensure that customer, business unit and legal requirements for raw materials and supplier quality assurance are achieved, that quality, safety and risk evaluation systems are in place, monitored and corrective actions completed. You will lead and motivate the raw material technologists ensuring role activities are delivered to a high standard and … the business or a new supplier/material to be introduced into the business has full/current approval status Ensure that all raw material specifications are reviewed and risk assessed to the outlined frequency and include requirements for quality and technical purposes relevant to Bakkavor. You will support the site riskassessment process through liaising with … appropriate and necessary corrective action & to follow up and monitor completion of actions. Will compile monthly internal KPI's for the site Raw Materials team for example: % active specifications, riskassessment status, supplier approval & raw material specification review. Understand the sites Customer requirements in regards raw material controls, microbiological specifications and processing parameters and effectively communicates these to More ❯
exciting role, your key focus will be to ensure that customer, business unit and legal requirements for raw materials and supplier quality assurance are achieved, that quality, safety and risk evaluation systems are in place, monitored and corrective actions completed. You will lead and motivate the raw material technologists ensuring role activities are delivered to a high standard and … the business or a new supplier/material to be introduced into the business has full/current approval status Ensure that all raw material specifications are reviewed and risk assessed to the outlined frequency and include requirements for quality and technical purposes relevant to Bakkavor. You will support the site riskassessment process through liaising with … appropriate and necessary corrective action & to follow up and monitor completion of actions. Will compile monthly internal KPI's for the site Raw Materials team for example: % active specifications, riskassessment status, supplier approval & raw material specification review. Understand the sites Customer requirements in regards raw material controls, microbiological specifications and processing parameters and effectively communicates these to More ❯
Cambridge, England, United Kingdom Hybrid / WFH Options
Hays
About the role As a Risk Manager, you will be taking a lead on cybersecurity and third-party cyber risk management, risk quantification and post-incident reviews. You will be translating insights into action and helping to drive data-driven, and risk informed decisions. You will be playing a critical role in embedding and operating within … the ServiceNow IRM tool, contributing to the development and embedding of a new risk management framework. Tell me more, tell me more... Our client is currently looking for a new recruit in joining their Team, please read on! You can also ask our friendly recruitment team any questions you may have about the role, between 09.00am till 17.00pm Monday … to Friday. Shifts: Monday to Friday (37.5 hours) Must Haves: ServiceNow IRM experience Previously worked in a technical, large-scale environment such as semiconductors. Hands on experience with riskassessment methodologies. Deep knowledge of security technologies and control frameworks such as ISO 27001, NIST CSF and NIST SP800-53. Strong stakeholder management skills Proven ability to embed frameworks More ❯
cambridge, east anglia, united kingdom Hybrid / WFH Options
Hays
About the role As a Risk Manager, you will be taking a lead on cybersecurity and third-party cyber risk management, risk quantification and post-incident reviews. You will be translating insights into action and helping to drive data-driven, and risk informed decisions. You will be playing a critical role in embedding and operating within … the ServiceNow IRM tool, contributing to the development and embedding of a new risk management framework. Tell me more, tell me more... Our client is currently looking for a new recruit in joining their Team, please read on! You can also ask our friendly recruitment team any questions you may have about the role, between 09.00am till 17.00pm Monday … to Friday. Shifts: Monday to Friday (37.5 hours) Must Haves: ServiceNow IRM experience Previously worked in a technical, large-scale environment such as semiconductors. Hands on experience with riskassessment methodologies. Deep knowledge of security technologies and control frameworks such as ISO 27001, NIST CSF and NIST SP800-53. Strong stakeholder management skills Proven ability to embed frameworks More ❯
control, identity and access governance, architecture, infrastructure, IT operations and information security. Working within the Controls & Governance (C&G) function, you will contribute to the assurance of control effectiveness, risk mitigation, and compliance with internal policies and regulatory requirements. This role is ideal for a solution-oriented individual with a keen eye for detail and a proactive mindset toward … risk management. The role will report directly to the IT Controls and Governance Manager and maintain close working relationships with internal functions including IT, Change, InfoSec, HR, Internal Audit, Risk, Compliance, Third Party Oversight, Business Application Owners and external audit partners and suppliers. Duties And Accountabilities Controls Testing & Monitoring Conduct regular testing of IT controls to assess design … and CIS Reporting & Analysis Evidence reviews Prepare detailed reports on control testing outcomes, including ratings and observations Support the development of dashboards and governance reports Track and monitor Key Risk Indicators (KRIs) and trends Onboarding of new controls for testing Conduct walkthroughs with control owners to understand policies and processes pertaining to a control Identify key evidence for controls More ❯
Nottingham, England, United Kingdom Hybrid / WFH Options
Capital One UK
Nottingham Trent House (95002), United Kingdom, Nottingham, Nottinghamshire Risk Remediation Assessor About the Role Capital One has a team of Information Security specialists who not only focus on security, but are relationship experts, riskassessment champions, and resolve complex information security issues related to Capital One’s third parties. The Cyber Third Party Risk Reduction (CTPRR … internal and external stakeholders to ensure third party engagements receive the necessary CTPRR due diligence; evaluate the effectiveness of the third party’s security environment and deliver a quality assessment report. It also supports ongoing security by working with the third parties to remediate any identified issues, enabling effective risk management in alignment with business tolerance and industry … requirements. Those that work for this team pragmatic and practical in your understanding of risk and security, but are also willing to know when to pull in experts and escalate. They challenge and innovate within their team to drive process improvements to elevate program efficiency. What you’ll do: Support kick-off, planning and scoping activities for cyber-focused More ❯
Bristol, England, United Kingdom Hybrid / WFH Options
Capital One UK
Nottingham Trent House (95002), United Kingdom, Nottingham, Nottinghamshire Risk Remediation Assessor About the Role Capital One has a team of Information Security specialists who not only focus on security, but are relationship experts, riskassessment champions, and resolve complex information security issues related to Capital One’s third parties. The Cyber Third Party Risk Reduction (CTPRR … internal and external stakeholders to ensure third party engagements receive the necessary CTPRR due diligence; evaluate the effectiveness of the third party’s security environment and deliver a quality assessment report. It also supports ongoing security by working with the third parties to remediate any identified issues, enabling effective risk management in alignment with business tolerance and industry … requirements. Those that work for this team pragmatic and practical in your understanding of risk and security, but are also willing to know when to pull in experts and escalate. They challenge and innovate within their team to drive process improvements to elevate program efficiency. What you’ll do: Support kick-off, planning and scoping activities for cyber-focused More ❯
ilkeston, midlands, united kingdom Hybrid / WFH Options
Capital One UK
Nottingham Trent House (95002), United Kingdom, Nottingham, Nottinghamshire Risk Remediation Assessor About the Role Capital One has a team of Information Security specialists who not only focus on security, but are relationship experts, riskassessment champions, and resolve complex information security issues related to Capital One’s third parties. The Cyber Third Party Risk Reduction (CTPRR … internal and external stakeholders to ensure third party engagements receive the necessary CTPRR due diligence; evaluate the effectiveness of the third party’s security environment and deliver a quality assessment report. It also supports ongoing security by working with the third parties to remediate any identified issues, enabling effective risk management in alignment with business tolerance and industry … requirements. Those that work for this team pragmatic and practical in your understanding of risk and security, but are also willing to know when to pull in experts and escalate. They challenge and innovate within their team to drive process improvements to elevate program efficiency. What you’ll do: Support kick-off, planning and scoping activities for cyber-focused More ❯
Nailsea, England, United Kingdom Hybrid / WFH Options
Capital One UK
Nottingham Trent House (95002), United Kingdom, Nottingham, Nottinghamshire Risk Remediation Assessor About the Role Capital One has a team of Information Security specialists who not only focus on security, but are relationship experts, riskassessment champions, and resolve complex information security issues related to Capital One’s third parties. The Cyber Third Party Risk Reduction (CTPRR … internal and external stakeholders to ensure third party engagements receive the necessary CTPRR due diligence; evaluate the effectiveness of the third party’s security environment and deliver a quality assessment report. It also supports ongoing security by working with the third parties to remediate any identified issues, enabling effective risk management in alignment with business tolerance and industry … requirements. Those that work for this team pragmatic and practical in your understanding of risk and security, but are also willing to know when to pull in experts and escalate. They challenge and innovate within their team to drive process improvements to elevate program efficiency. What you’ll do: Support kick-off, planning and scoping activities for cyber-focused More ❯
long eaton, midlands, united kingdom Hybrid / WFH Options
Capital One UK
Nottingham Trent House (95002), United Kingdom, Nottingham, Nottinghamshire Risk Remediation Assessor About the Role Capital One has a team of Information Security specialists who not only focus on security, but are relationship experts, riskassessment champions, and resolve complex information security issues related to Capital One’s third parties. The Cyber Third Party Risk Reduction (CTPRR … internal and external stakeholders to ensure third party engagements receive the necessary CTPRR due diligence; evaluate the effectiveness of the third party’s security environment and deliver a quality assessment report. It also supports ongoing security by working with the third parties to remediate any identified issues, enabling effective risk management in alignment with business tolerance and industry … requirements. Those that work for this team pragmatic and practical in your understanding of risk and security, but are also willing to know when to pull in experts and escalate. They challenge and innovate within their team to drive process improvements to elevate program efficiency. What you’ll do: Support kick-off, planning and scoping activities for cyber-focused More ❯
nailsea, south west england, united kingdom Hybrid / WFH Options
Capital One UK
Nottingham Trent House (95002), United Kingdom, Nottingham, Nottinghamshire Risk Remediation Assessor About the Role Capital One has a team of Information Security specialists who not only focus on security, but are relationship experts, riskassessment champions, and resolve complex information security issues related to Capital One’s third parties. The Cyber Third Party Risk Reduction (CTPRR … internal and external stakeholders to ensure third party engagements receive the necessary CTPRR due diligence; evaluate the effectiveness of the third party’s security environment and deliver a quality assessment report. It also supports ongoing security by working with the third parties to remediate any identified issues, enabling effective risk management in alignment with business tolerance and industry … requirements. Those that work for this team pragmatic and practical in your understanding of risk and security, but are also willing to know when to pull in experts and escalate. They challenge and innovate within their team to drive process improvements to elevate program efficiency. What you’ll do: Support kick-off, planning and scoping activities for cyber-focused More ❯
portishead, south west england, united kingdom Hybrid / WFH Options
Capital One UK
Nottingham Trent House (95002), United Kingdom, Nottingham, Nottinghamshire Risk Remediation Assessor About the Role Capital One has a team of Information Security specialists who not only focus on security, but are relationship experts, riskassessment champions, and resolve complex information security issues related to Capital One’s third parties. The Cyber Third Party Risk Reduction (CTPRR … internal and external stakeholders to ensure third party engagements receive the necessary CTPRR due diligence; evaluate the effectiveness of the third party’s security environment and deliver a quality assessment report. It also supports ongoing security by working with the third parties to remediate any identified issues, enabling effective risk management in alignment with business tolerance and industry … requirements. Those that work for this team pragmatic and practical in your understanding of risk and security, but are also willing to know when to pull in experts and escalate. They challenge and innovate within their team to drive process improvements to elevate program efficiency. What you’ll do: Support kick-off, planning and scoping activities for cyber-focused More ❯