City of London, London, United Kingdom Hybrid / WFH Options
EML
by curiosity, and focused on doing things better every day. At EML, you won’t be asked to fit in — we’ll help you stand out. The Team The Risk & Compliance team at EML believes in rolling up their sleeves and getting things done. At EML, we don't subscribe to ivory tower compliance – the organisation seeks a hands … on leader who will engage across the organisation and understand the practical impacts and outcomes of their work. The Risk & Compliance team at EML is divided into two overarching teams: Country Risk & Compliance – hold broad responsibilities within their countries/regions and where applicable hold designated titles (such as SMF or PCF designations). They are supported in … global team of specialists but maintain ultimate decision-making authority and control via oversight of all parts of programmes and activities that impact on their country/region. Global Risk & Compliance – narrowly focussed specific functions or areas, providing deep subject matter expertise, framework design and execution support and standardisation across the group in the areas of Regulatory Compliance, RiskMore ❯
london, south east england, united kingdom Hybrid / WFH Options
EML
by curiosity, and focused on doing things better every day. At EML, you won’t be asked to fit in — we’ll help you stand out. The Team The Risk & Compliance team at EML believes in rolling up their sleeves and getting things done. At EML, we don't subscribe to ivory tower compliance – the organisation seeks a hands … on leader who will engage across the organisation and understand the practical impacts and outcomes of their work. The Risk & Compliance team at EML is divided into two overarching teams: Country Risk & Compliance – hold broad responsibilities within their countries/regions and where applicable hold designated titles (such as SMF or PCF designations). They are supported in … global team of specialists but maintain ultimate decision-making authority and control via oversight of all parts of programmes and activities that impact on their country/region. Global Risk & Compliance – narrowly focussed specific functions or areas, providing deep subject matter expertise, framework design and execution support and standardisation across the group in the areas of Regulatory Compliance, RiskMore ❯
slough, south east england, united kingdom Hybrid / WFH Options
EML
by curiosity, and focused on doing things better every day. At EML, you won’t be asked to fit in — we’ll help you stand out. The Team The Risk & Compliance team at EML believes in rolling up their sleeves and getting things done. At EML, we don't subscribe to ivory tower compliance – the organisation seeks a hands … on leader who will engage across the organisation and understand the practical impacts and outcomes of their work. The Risk & Compliance team at EML is divided into two overarching teams: Country Risk & Compliance – hold broad responsibilities within their countries/regions and where applicable hold designated titles (such as SMF or PCF designations). They are supported in … global team of specialists but maintain ultimate decision-making authority and control via oversight of all parts of programmes and activities that impact on their country/region. Global Risk & Compliance – narrowly focussed specific functions or areas, providing deep subject matter expertise, framework design and execution support and standardisation across the group in the areas of Regulatory Compliance, RiskMore ❯
london (city of london), south east england, united kingdom Hybrid / WFH Options
EML
by curiosity, and focused on doing things better every day. At EML, you won’t be asked to fit in — we’ll help you stand out. The Team The Risk & Compliance team at EML believes in rolling up their sleeves and getting things done. At EML, we don't subscribe to ivory tower compliance – the organisation seeks a hands … on leader who will engage across the organisation and understand the practical impacts and outcomes of their work. The Risk & Compliance team at EML is divided into two overarching teams: Country Risk & Compliance – hold broad responsibilities within their countries/regions and where applicable hold designated titles (such as SMF or PCF designations). They are supported in … global team of specialists but maintain ultimate decision-making authority and control via oversight of all parts of programmes and activities that impact on their country/region. Global Risk & Compliance – narrowly focussed specific functions or areas, providing deep subject matter expertise, framework design and execution support and standardisation across the group in the areas of Regulatory Compliance, RiskMore ❯
in moving to the beautiful county of Derbyshire, we can provide a generous relocation package of up to £8,000 and the key duties are: Provide psychiatric assessments, including assessment of risk to self and others. Manage patients under the care of the CAMHS Crisis and Liaison pathway including riskassessment and management. Liaison with community More ❯
insights, and identify opportunities to integrate improvements and new features into the user flow and product roadmap. Advocate for user needs while balancing business requirements and technical feasibility. Innovation & Risk Management: Drive innovation by identifying emerging technologies and trends that may affect the product landscape. Proactively manage product risks, ensuring that potential roadblocks are identified and mitigated early in … and innovative approach to overcoming product challenges and seizing new opportunities. Data-Driven Decision Making: Comfortable with data analysis and making decisions based on KPIs, metrics, and performance analytics. Risk Management: Experience in riskassessment and mitigation strategies, ensuring smooth product delivery and minimizing potential disruptions. About S&P Global Ratings S&P Global Ratings is the … securities. We offer an independent view of the market built on a unique combination of broad perspective and local insight. We provide our opinions and research about relative credit risk; market participants gain independent information to help support the growth of transparent, liquid debt markets worldwide. S&P Global Ratings is a division of S&P Global (NYSE: SPGI More ❯
IT Governance Officer The successful candidate will serve as the subject matter expert on the IT operational riskassessment, controls and governance (“IT GRC”). Sitting within the IT team and acting as the first line of defence. You will closely partner with internal IT teams, Business OPC, Central IT OPC and other control functions to strengthen IT … operational processes. Key experience required IT Operational Permanent Control (OPC) Assessment Group Cybersecurity Assessment IT Audits Client Due Diligence Questionnaire and Security clauses The successful candidate will have strong and relevant experience in IT governance and operational risk management in a similar sized organisation. Knowledge of external certifications and the ability to audit the organisation’s conformance More ❯
customer at Camp Roberts in San Miguel, California. Job Responsibilities include: Supports our Army customer by providing a critical cybersecurity role by ensuring continuous monitoring in accordance with DoD Risk Management Framework (RMF), and through system monitoring and analysis support for the detection of cyber incidents and provides recommendations on how to correct findings. This role combines the duties … systems, ensuring full compliance with RMF, DoDI 8510.01, and NIST SP 800-53 security control baselines. Manage and maintain all RMF-related documentation including System Security Plans (SSPs), Security Assessment Reports (SARs), RiskAssessment Reports (RARs), and Plan of Action and Milestones (POA&Ms). Conduct security control assessments and facilitate ongoing authorization (ATO/ATC) activities. More ❯
technical expert responsible for implementing, managing, and maintaining comprehensive cybersecurity operations across Marine Corps University's complex IT infrastructure. This role combines strategic oversight with direct technical execution of Risk Management Framework (RMF) processes, security tool administration, and daily cybersecurity operations while ensuring compliance with DoD directives throughout the MCU environment. In this position you will: Responsible for developing … maintaining comprehensive cybersecurity strategies across all MCU network environments. Execute hands-on configuration of security policies, technical controls, and procedural frameworks to ensure full compliance with DoD Information Assurance Risk Management Framework (DIARMF) standards and Marine Corps cybersecurity directives. Author detailed security assessment reports, System Security Plans (SSPs), and RiskAssessment Reports (RARs) for multiple Authority … four years in senior-level positions managing complex DoD information systems and RMF processes. Active advanced security certification such as CISSP, CASP+ CE or CISM Expert-level proficiency with Risk Management Framework (RMF) processes including System Security Plan (SSP) development, Control Correlation Bridge (CCB) implementation, and Continuity of Operations Planning (COOP) documentation. Proven leadership capabilities with experience managing technical More ❯
Safety (Energized Electrical Work, Arc Flash, NPFA 70E) Control of Hazardous Energy (Lockout/Tagout), including familiarity of EU-OSHA Occupational Noise Exposure & Control Heat Stress & Illness Prevention Exposure Assessment (Industrial Hygiene) Emergency Response Planning Working at Heights Confined Space Entry Heavy Material Handling Powered Industrial Trucks (Forklifts) Construction-Related Risks (Cranes/Rigging, Trenching/Shoring, Mobile Elevated … Work Platforms (MEWPs), etc.) Fire/Life Safety Hazardous Substances Handling WasteManagement Ergonomics Spill Prevention Control and Countermeasures (SPCC) RiskAssessment and Mitigation methodology 3rdParty Safety Supplier Management Essential Job Functions Implement health and safety standards and principles, policies, and practices including but not limited to; safety management systems, training, risk assessments, assist with industrial hygiene assessments … Being accountable for EHS performance metrics and implementation of annual improvement plans. Periodically inspecting, auditing, andreviewing safe work practices to ensure compliance with regulations and company policies. Conduct workplace risk/exposure assessments for various classes of hazards. Supporting incident investigations and root cause analysis, so that corrective and preventive actions can be identified, communicated globally, and implemented. Conducting More ❯
support our Army customer in San Antonio, Texas Job Responsibilities include: Supports our Army customer by providing a critical cybersecurity role by ensuring continuous monitoring in accordance with DoD Risk Management Framework (RMF), and through system monitoring and analysis support for the detection of cyber incidents and provides recommendations on how to correct findings. This role combines the duties … systems, ensuring full compliance with RMF, DoDI 8510.01, and NIST SP 800-53 security control baselines. Manage and maintain all RMF-related documentation including System Security Plans (SSPs), Security Assessment Reports (SARs), RiskAssessment Reports (RARs), and Plan of Action and Milestones (POA&Ms). Conduct security control assessments and facilitate ongoing authorization (ATO/ATC) activities. More ❯
LLC (DI) is searching for a full-time Assistant Information System Security Officer (AISSO) to work in Washington, DC. The Assistant Information System Security Officer (AISSO) will provide comprehensive Risk Management Framework (RMF) support across various systems and environments, under the guidance of the ISSO and in alignment with DoD cybersecurity standards. Responsibilities: - Collaborate in the development and refinement … of Systems Engineering Risk Management Plans that comply with DoDI 8510.01 and current DoD RMF policies. - Support the creation and ongoing maintenance of Plan of Action and Milestones (POA&Ms) to address identified cybersecurity gaps, ensuring alignment with applicable STIGs. - Assist in performing Risk Assessments using tools like ACAS, Nessus, and SCAP, and generate thorough RiskAssessment Reports (RARs). - Contribute to the preparation, review, and organization of Assessment and Authorization (A&A) packages ensuring completeness, consistency, and accuracy across documentation sets. - Maintain and update entries in eMASS and deliver other cybersecurity-related documentation in MS Office or Visio formats. - Coordinate with Red and Blue Teams on vulnerability assessments and incident response activities. - Assist with More ❯
data. THE OPPORTUNITY As an ISSO Level 2, you'll be instrumental in transforming traditional security architectures to Zero Trust models while maintaining continuous security authorization under the NIST Risk Management Framework. You'll work with cutting-edge security tools including LatteArt, ScanBoy, Biscotti, Sear, and Exacta, ensuring our defense systems remain resilient against evolving cyber threats. This position … Leadership • Provide comprehensive System Security Plan (SSP) lifecycle support from initial development through continuous monitoring • Master and apply specialized security applications including LatteArt, ScanBoy, Biscotti, Sear, and Exacta • Lead Risk Management Framework (RMF) processes ensuring compliance with NIST standards and DoD directives • Develop and maintain Certification and Accreditation (C&A) packages for classified information systems • Prepare RiskAssessment … Maintain day-to-day security operations for multiple information systems processing classified data • Evaluate and implement security solutions meeting stringent requirements for classified information processing • Perform continuous vulnerability and risk assessments supporting ongoing authorization activities • Manage configuration control for security-relevant hardware, software, and firmware • Assess security impacts of system changes and coordinate remediation efforts Technical Security Management • Administer More ❯
ensure compliance with all associated controls and responsibilities in the day-to-day performance of their duties. Individuals working in departments that are considered to be in the high-risk category will be required to undergo advanced training based on their role and level of access. Individuals with access to modify data and the configuration baseline will require further … Data Environment Repository (SPIDER) Navy Data Environment (NDE) Open Architecture Retrieval System (OARS) Configuration Data Managers Database-Open Architecture (CDMD-OA) Configuration Management Professional (CMPro) Navy Tool for Interoperability RiskAssessment (NTIRA) Assured Compliance Assessment Solution (ACAS) Enterprise Mission Assurance Support Service (eMASS) Federal Information Security Management Act (FISMA) database Vulnerability Remediation Asset Manager (VRAM) Xacta Information … Assurance (IA) Manager and NSERC DoD Information Technology Portfolio Repository-DON (DITPR-DON) DON Application Database Management System (DADMS) Microsoft Visio, PEO C4I Risk Exchange Online Server Tool and Office Suite & Jira Online Tool Excellent organizational skills with the ability to identify, prioritize, and execute tasks to meet project deadlines consistently. DESIRED Knowledge of and practical experience with submarine More ❯
one mind, and one purpose, we can accomplish our mission and be an organization anyone would be proud to be a part of. POSITION SUMMARY Aleut is seeking an Assessment and Authorization (A&A) Assessor for Software/SaaS/Hardware to work with the United States Air Force Academy (USAFA) RMF team. This position requires personnel to work … Air Force, and USAFA cybersecurity policies and control requirements. Perform evaluations of acquisition requests and technical artifacts in accordance with AFI 17-101 and USAFA local procedures, assessing potential risk to mission systems, data confidentiality, and operational integrity. Coordinate with requestors, cybersecurity stakeholders, and acquisition personnel to gather relevant information and provide timely written recommendations for system integration or … risk-based rejection. Develop, maintain, and annually review a Standard Operating Procedure (SOP) for all assessment types to ensure consistent evaluation standards and alignment with evolving Air Force and DoD policies. Complete and document Privacy Impact Assessments (PIAs) (e.g., DD Form 2930) as required, in collaboration with system owners and in compliance with AFI 33-332, Air Force More ❯
Reports to: Team Leader, Analytics, Claims and Underwriting Solutions (International) Location: London/Hybrid Business Description Verisk Analytics is a multinational data and analytics riskassessment company and a leading source of information about insurance risk. To serve our clients, we draw upon our vast experience in data management and predictive modelling to offer decision analytics to the … insurance industry through underwriting to claims management in personal lines, commercial lines, and the London market. In underwriting we create sophisticated risk models to assist insurers with risk selection and accurate pricing. Our range of models is broad spanning residential and commercial property perils, motor insurance, SME business covers, travel, pet and health insurance. To feed our risk … and manage cases more effectively. Role Purpose Verisk are looking for a Data Scientist to support the development of various data science models to support the development of our risk management products. The International Analytics Team is a dynamic and exciting place to work: our projects are extremely varied and include developing supervised machine learning models, unsupervised clustering type More ❯
Ensure that protection and detection capabilities are acquired or developed using the IS security engineering approach and are consistent with organization-level cybersecurity architecture. • Participate in an information security riskassessment during the Security Assessment and Authorization process. • Participate in the development or modification of the computer environment cybersecurity program plans and requirements. • Recognize a possible security … violation and take appropriate action to report the incident, as required • Ensure plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc. • Provide technical documents, incident reports, and findings from computer examinations, summaries, and other situational awareness information to higher headquarters • Develop and maintain RMF Assess and Authorize documentation … required to achieve an Authority to Operate (ATO). Prepare and maintain information systems ATO record on the Navy's Enterprise Mission Assurance Support Service (eMASS) • Run vulnerability assessment tools; ACAS vulnerability scanner, Security Content Automation Protocol (SCAP), STIG Viewe • Manage system/network vulnerabilities using the Vulnerability Remediation and Assets Manager (VRAM) Qualifications/Requirements: • MUST be a More ❯
The Security Engineer III participates in all aspects of information systems and network security including intrusion detection, incident response, vulnerability assessment, application security and compliance with the corporate information security policy. Primarily be responsible for implementing, operating and improving security technologies including DLP, Antivirus, IPS/IDS, End Point Protection, Database Activity Monitoring, Web Application Firewall and processes. Essential … security implementations, monitoring, and enforcement - Investigates, recommends, evaluates, deploys and integrates operational security tools and techniques to improve our ability to protect corporate assets and infrastructure - Participate in technical risk assessments and security exposure analyses of systems, networks and business applications - Analyze network security elements and overall network security architectural designs to ensure secure and optimal system and network …/procedures - Evaluate, implement, tune and operate Security Solutions such as IPS, Vulnerability scanning tools, encryption capabilities, etc. - Monitor and recommend improvements of security technologies and their various reports - Risk Management/Security Audit/Assessment Support/Ad-hoc support - Support security audit/assessment related activities and compliance reviews# - Performs other task, duties and projects More ❯
our customers. About the role As an Onboarding Analyst at Equals Group, you will be an integral part of a dedicated team responsible for conducting KYC checks and performing risk assessments on new business and personal customer applications You will collaborate closely with the Compliance and Risk departments to ensure that new customers are onboarded within the firm … s risk appetite framework while adhering to AML regulations and other relevant compliance requirements In this fast-paced environment, you will need to take initiative, think critically, and act quickly to ensure customers are onboarded smoothly while mitigating potential risks. About you We believe that certain skills are essential in order to be successful in this role and these … out individual interviews for shortlisted candidates and assess who is best suited for the role after we have discussed everything with you. Responsibilities Conduct Customer Due Diligence (CDD) and risk assessments on new business and personal customer applications, ensuring compliance with AML regulations Verify and validate the accuracy of customer information and supporting documentation, including identification, corporate structures, and More ❯
An exciting opportunity has arisen for an experienced Regulatory Oversight/Risk and Control Specialist to join a global financial institution, supporting enterprise-wide compliance with key market abuse regulations. This role sits within the first line of defence in the Markets business and plays a pivotal part in overseeing critical regulatory frameworks including: UK/EU Market Abuse … Code 78o(g) (Material Non-Public Information) Key Responsibilities Drive strategic compliance initiatives across market abuse regulations. Lead remediation efforts on market manipulation, insider trading, and securities fraud. Oversee riskassessment and mapping aligned with RCSA methodology. Develop and monitor risk metrics for complex business environments. Strengthen and enhance control frameworks to meet regulatory standards. Provide expert … advisory to business units on market abuse compliance. Support governance forums with reporting, insights, and remediation tracking. Essential criteria Strong background in regulatory, compliance, or risk & control roles within large financial institutions. Experience in one or more business units such as Markets, Banking, Wealth, or Services. Deep understanding of market abuse risks and controls, including trade surveillance and information More ❯
An exciting opportunity has arisen for an experienced Regulatory Oversight/Risk and Control Specialist to join a global financial institution, supporting enterprise-wide compliance with key market abuse regulations. This role sits within the first line of defence in the Markets business and plays a pivotal part in overseeing critical regulatory frameworks including: UK/EU Market Abuse … Code 78o(g) (Material Non-Public Information) Key Responsibilities Drive strategic compliance initiatives across market abuse regulations. Lead remediation efforts on market manipulation, insider trading, and securities fraud. Oversee riskassessment and mapping aligned with RCSA methodology. Develop and monitor risk metrics for complex business environments. Strengthen and enhance control frameworks to meet regulatory standards. Provide expert … advisory to business units on market abuse compliance. Support governance forums with reporting, insights, and remediation tracking. Essential criteria Strong background in regulatory, compliance, or risk & control roles within large financial institutions. Experience in one or more business units such as Markets, Banking, Wealth, or Services. Deep understanding of market abuse risks and controls, including trade surveillance and information More ❯
Implementing and development of the DHS IT security standards • Gathering and organizing technical information about the lab's mission goals and needs, existing security products, and ongoing programs • Performing risk analyses which also includes riskassessment • Planning and leading major technology assignments • Evaluating performance results and recommends major changes affecting short-term project growth and success - Functioning More ❯
tracking and reporting to the Technology Leadership Team and the wider organization. Become fully embedded into our engineering teams and practices to: Lead threat modeling, vulnerability prioritization, and hold riskassessment exercises. Monitor zero-day threats and vulnerabilities, ensuring they are properly prioritized and resolved by responsible teams. Guide architectural security reviews to ensure resilient, secure systems in … Experience of solving complex information security concerns in both a technical and strategic role. Be able to work with teams that build platform components securely. You can effectively apply risk mitigation strategies that align with the business and deliver large-scale security projects and improvements. Experience leading and coaching teams to success. Influencing best practice security concepts with Engineering … influence the business and teams into their adoption over time. Possess excellent verbal and written communication skills to be effective across global diverse teams Learn more about the LexisNexis Risk team and how we work here We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or More ❯
City of London, London, England, United Kingdom Hybrid / WFH Options
Travelers Insurance Co. Ltd
array of industry-specific, combined property and casualty insurance solutions to customers. This includes SME solutions traded directly, Commercial Accounts traded via brokers, and Corporate Solutions to FTSE 350 Risk Managed companies. Are you a Senior Development Underwriter with strong technical underwriting knowledge of PI Cyber products? We are looking for a Senior Underwriter to join our Technology Underwriting … team, proactively seeking and managing new business submissions, quotes and bind renewal business. You will strategically partner with brokers to provide insurance solutions to customers, analysing and evaluating risk to achieve business goals. You are decisive, detail-oriented, and know how to build relationships internally and externally and negotiate terms to drive results. Your ability to independently assess complex … and retention of an assigned book of business primarily comprised of moderate to complex accounts across all our products. Underwrite and skillfully negotiate moderate to complex risks to minimise risk and maximise profitability, including Mid Term Adjustments (MTAs). Proactively manage your portfolio, ensuring key performance indicators are consistently achieved and you actively target new business and retention. Identify More ❯
internal teams, leadership, and external agencies to ensure full compliance with DoD and Air Force cybersecurity directives. Operating with a high degree of autonomy, the analyst advises leadership on risk mitigation strategies, drives security process improvements, and ensures operational readiness of systems at all classification levels. A constant focus on IT security vigilance, incident response, and COMSEC responsibilities is … certification and accreditation packages in accordance with DoD, AF, and intelligence community cybersecurity requirements, including RMF, NIST SP 800-53, ICD 503, and DoDI 8510.01. Analyze system vulnerabilities, interpret riskassessment results, and recommend remediation strategies to leadership. Oversee vulnerability scanning, patch management compliance, and configuration control processes across all AF TENCAP systems. Lead incident response efforts, coordinate More ❯