Business Resilience Risk Analyst Contract: Inside IR35 Location: Sheffield - 3 days per week We're looking for a Business Resilience Risk Analyst to join a first-line-of-defence team, focusing on Business Resilience Risk and Business Recovery technologies. The role will involve reviewing and assessing controls, ensuring they meet required standards and metrics, and working with stakeholders to identify and address resilience risks across critical technology and recovery services. Key Responsibilities Review and assess Business Resilience and Business Recovery controls against required standards and metrics. Support the assessment of technology resilience and recovery capabilities across critical services. Identify control gaps and risks that could impact business recovery and continuity. Work with technology and business stakeholders to understand recovery arrangements, dependencies and resilience requirements. Coordinate multiple teams to ensure actions, risks and controls are effectively managed. Develop into a subject matter expert across Business Resilience Risk and Business Recovery technologies. Essential Experience 3-5 years' experience within Risk & Controls, Business Resilience, Operational Resilience or Technology Risk. Good understanding of business continuity, resilience and technology recovery controls. Experience assessing controls, identifying risks and managing remediation activity. Strong stakeholder management and coordination skills, with the ability to work across multiple teams. Good understanding of technology concepts and how they support business recovery and resilience. Strong communication and organisational skills. Desirable Experience with Business Recovery technologies, disaster recovery or technology resilience. Knowledge of recovery strategies, backup, replication, failover and recovery testing. Experience within a financial services environment. Background in technology controls, IAM/IDAM, SDLC or infrastructure risk. Understanding of how emerging technologies, including AI, may impact business resilience and recovery. This is an opportunity for someone with a strong Risk & Controls or Business Resilience foundation to develop deeper expertise in Business Resilience Risk and become an SME in Business Recovery technologies and controls.
28/08/2026
Contractor
Business Resilience Risk Analyst Contract: Inside IR35 Location: Sheffield - 3 days per week We're looking for a Business Resilience Risk Analyst to join a first-line-of-defence team, focusing on Business Resilience Risk and Business Recovery technologies. The role will involve reviewing and assessing controls, ensuring they meet required standards and metrics, and working with stakeholders to identify and address resilience risks across critical technology and recovery services. Key Responsibilities Review and assess Business Resilience and Business Recovery controls against required standards and metrics. Support the assessment of technology resilience and recovery capabilities across critical services. Identify control gaps and risks that could impact business recovery and continuity. Work with technology and business stakeholders to understand recovery arrangements, dependencies and resilience requirements. Coordinate multiple teams to ensure actions, risks and controls are effectively managed. Develop into a subject matter expert across Business Resilience Risk and Business Recovery technologies. Essential Experience 3-5 years' experience within Risk & Controls, Business Resilience, Operational Resilience or Technology Risk. Good understanding of business continuity, resilience and technology recovery controls. Experience assessing controls, identifying risks and managing remediation activity. Strong stakeholder management and coordination skills, with the ability to work across multiple teams. Good understanding of technology concepts and how they support business recovery and resilience. Strong communication and organisational skills. Desirable Experience with Business Recovery technologies, disaster recovery or technology resilience. Knowledge of recovery strategies, backup, replication, failover and recovery testing. Experience within a financial services environment. Background in technology controls, IAM/IDAM, SDLC or infrastructure risk. Understanding of how emerging technologies, including AI, may impact business resilience and recovery. This is an opportunity for someone with a strong Risk & Controls or Business Resilience foundation to develop deeper expertise in Business Resilience Risk and become an SME in Business Recovery technologies and controls.
AI Risk & Controls Analyst Contract: Inside IR35 Location: Sheffield - 3 days per week We're looking for a Risk & Controls professional to join a first-line-of-defence team focused on controls within the AI space. This is an opportunity to develop into an SME in AI Controls, assessing how AI impacts existing controls and how effective controls can help mitigate the risks associated with AI. Key Responsibilities Review and assess controls against required metrics and standards. Support the development and maturity of controls across the AI landscape. Assess the impact of AI on existing controls and identify potential gaps. Consider how controls can mitigate risks when AI systems do not behave as expected. Coordinate across multiple stakeholders and teams to drive control-related activities forward. Build expertise in AI Controls and become a subject matter expert over time. Essential Experience 3-5 years' experience in Risk & Controls, ideally within a financial services environment. Good understanding of controls and control frameworks. Strong stakeholder management and coordination skills, with the ability to bring multiple teams together. Ability to understand and engage with controls across areas such as SDLC, Cryptography and IAM/IDAM. Strong communication and organisational skills. Good understanding of AI and its potential impact on risk and controls. Desirable Previous experience working with AI Controls or AI risk. Understanding of Agentic AI and the types of controls required around autonomous AI systems. Stronger background in IDAM/IAM with an interest in developing further within Risk & Controls. You don't need to be an established Controls SME - this role is ideal for someone with a solid controls foundation who can grow into an SME position within the AI space.
28/08/2026
Contractor
AI Risk & Controls Analyst Contract: Inside IR35 Location: Sheffield - 3 days per week We're looking for a Risk & Controls professional to join a first-line-of-defence team focused on controls within the AI space. This is an opportunity to develop into an SME in AI Controls, assessing how AI impacts existing controls and how effective controls can help mitigate the risks associated with AI. Key Responsibilities Review and assess controls against required metrics and standards. Support the development and maturity of controls across the AI landscape. Assess the impact of AI on existing controls and identify potential gaps. Consider how controls can mitigate risks when AI systems do not behave as expected. Coordinate across multiple stakeholders and teams to drive control-related activities forward. Build expertise in AI Controls and become a subject matter expert over time. Essential Experience 3-5 years' experience in Risk & Controls, ideally within a financial services environment. Good understanding of controls and control frameworks. Strong stakeholder management and coordination skills, with the ability to bring multiple teams together. Ability to understand and engage with controls across areas such as SDLC, Cryptography and IAM/IDAM. Strong communication and organisational skills. Good understanding of AI and its potential impact on risk and controls. Desirable Previous experience working with AI Controls or AI risk. Understanding of Agentic AI and the types of controls required around autonomous AI systems. Stronger background in IDAM/IAM with an interest in developing further within Risk & Controls. You don't need to be an established Controls SME - this role is ideal for someone with a solid controls foundation who can grow into an SME position within the AI space.
ServiceNow Security Incident Response (SIR) Engineer - Contract Contract: Initial contract engagement Rate: £700 per/day Specialism: ServiceNow SIR | SecOps | Cyber Security | Incident Response (Remote working) We are looking for an experienced ServiceNow Security Incident Response (SIR) Engineer to join a major cyber security programme, helping to strengthen and automate the organisation's security incident response capability. Please note: Hands-on ServiceNow Security Incident Response (SIR) experience is an absolute requirement for this role. This is NOT a general ServiceNow Developer/Engineer position. Applicants without demonstrable ServiceNow SIR experience will not be considered. The Role Working at the intersection of ServiceNow engineering and cyber security operations , you will help design, configure, enhance and integrate ServiceNow SIR to support the end-to-end security incident life cycle - from initial detection and analysis through containment, remediation and recovery. You will work closely with SOC, Cyber Security, Incident Response and ServiceNow teams to ensure security incidents are captured, prioritised and managed through effective, automated workflows. Responsibilities will include: Configure, develop and enhance ServiceNow Security Incident Response (SIR) capabilities. Design and optimise security incident workflows covering detection, triage, investigation, containment, remediation and closure. Develop automation to accelerate incident handling and reduce manual intervention. Integrate ServiceNow SIR with third-party cyber security technologies and data sources. Configure incident prioritisation, categorisation, assignment and escalation processes. Support the ingestion and enrichment of security alerts and incidents within ServiceNow. Work closely with SOC and Cyber Incident Response teams to translate operational requirements into effective ServiceNow workflows. Identify opportunities to improve security response through workflow automation and orchestration. Troubleshoot SIR configuration, integration and workflow issues. Ensure appropriate documentation, governance and operational handover of implemented capabilities. Essential Experience To be considered, you MUST have: Strong, demonstrable hands-on experience with ServiceNow Security Incident Response (SIR) . Experience configuring and implementing SIR rather than simply using ServiceNow as an end user. Good understanding of the cyber security incident response life cycle . Experience designing and configuring security incident workflows within ServiceNow. Experience integrating ServiceNow with third-party cyber security platforms and tools. Strong understanding of workflow automation and incident orchestration. Ability to work effectively with SOC analysts, security engineers, incident responders and ServiceNow specialists. Strong problem-solving and troubleshooting capability. Excellent stakeholder communication skills. Highly Desirable ServiceNow SIR/Security Operations certification. Broader ServiceNow Security Operations (SecOps) experience. Experience integrating SIR with SIEM, SOAR, EDR or other security monitoring technologies. ServiceNow Scripting and development experience. Experience working within large, complex or regulated enterprise environments. Previous experience delivering ServiceNow security capabilities within financial services would be advantageous. The Key Requirement We want to be extremely clear about the profile required: You must be a ServiceNow Engineer/Consultant with genuine hands-on ServiceNow Security Incident Response (SIR) implementation experience. General ServiceNow ITSM, ITOM, CSM or platform development experience without SIR experience will not be sufficient . If you have designed, configured and implemented ServiceNow SIR within a complex enterprise cyber security environment, we would be very interested in speaking with you.
27/08/2026
Contractor
ServiceNow Security Incident Response (SIR) Engineer - Contract Contract: Initial contract engagement Rate: £700 per/day Specialism: ServiceNow SIR | SecOps | Cyber Security | Incident Response (Remote working) We are looking for an experienced ServiceNow Security Incident Response (SIR) Engineer to join a major cyber security programme, helping to strengthen and automate the organisation's security incident response capability. Please note: Hands-on ServiceNow Security Incident Response (SIR) experience is an absolute requirement for this role. This is NOT a general ServiceNow Developer/Engineer position. Applicants without demonstrable ServiceNow SIR experience will not be considered. The Role Working at the intersection of ServiceNow engineering and cyber security operations , you will help design, configure, enhance and integrate ServiceNow SIR to support the end-to-end security incident life cycle - from initial detection and analysis through containment, remediation and recovery. You will work closely with SOC, Cyber Security, Incident Response and ServiceNow teams to ensure security incidents are captured, prioritised and managed through effective, automated workflows. Responsibilities will include: Configure, develop and enhance ServiceNow Security Incident Response (SIR) capabilities. Design and optimise security incident workflows covering detection, triage, investigation, containment, remediation and closure. Develop automation to accelerate incident handling and reduce manual intervention. Integrate ServiceNow SIR with third-party cyber security technologies and data sources. Configure incident prioritisation, categorisation, assignment and escalation processes. Support the ingestion and enrichment of security alerts and incidents within ServiceNow. Work closely with SOC and Cyber Incident Response teams to translate operational requirements into effective ServiceNow workflows. Identify opportunities to improve security response through workflow automation and orchestration. Troubleshoot SIR configuration, integration and workflow issues. Ensure appropriate documentation, governance and operational handover of implemented capabilities. Essential Experience To be considered, you MUST have: Strong, demonstrable hands-on experience with ServiceNow Security Incident Response (SIR) . Experience configuring and implementing SIR rather than simply using ServiceNow as an end user. Good understanding of the cyber security incident response life cycle . Experience designing and configuring security incident workflows within ServiceNow. Experience integrating ServiceNow with third-party cyber security platforms and tools. Strong understanding of workflow automation and incident orchestration. Ability to work effectively with SOC analysts, security engineers, incident responders and ServiceNow specialists. Strong problem-solving and troubleshooting capability. Excellent stakeholder communication skills. Highly Desirable ServiceNow SIR/Security Operations certification. Broader ServiceNow Security Operations (SecOps) experience. Experience integrating SIR with SIEM, SOAR, EDR or other security monitoring technologies. ServiceNow Scripting and development experience. Experience working within large, complex or regulated enterprise environments. Previous experience delivering ServiceNow security capabilities within financial services would be advantageous. The Key Requirement We want to be extremely clear about the profile required: You must be a ServiceNow Engineer/Consultant with genuine hands-on ServiceNow Security Incident Response (SIR) implementation experience. General ServiceNow ITSM, ITOM, CSM or platform development experience without SIR experience will not be sufficient . If you have designed, configured and implemented ServiceNow SIR within a complex enterprise cyber security environment, we would be very interested in speaking with you.
DevSecOps Consultant Sheffield (2-days per week onsite) Inside IR35 We're partnering with a leading financial services client to appoint a DevSecOps Consultant to drive secure engineering practices across large-scale, cloud-based platforms. This role is ideal for someone who has come from a hands-on DevSecOps Engineering background and has since transitioned into architecture, design and advisory, while still retaining strong technical depth. We're particularly looking for someone who brings a strong blend of Python development and orchestration experience alongside their DevSecOps expertise. Key Requirements: Proven background in hands-on DevSecOps Engineering, now operating in a design/architecture-focused role Strong Python development experience, with the ability to build automation and orchestration solutions Strong experience with orchestration and workflow automation across engineering, cloud and security platforms Strong experience across both AWS and GCP (essential) Deep understanding of CI/CD pipelines, build tools, artifact repositories, and developer platforms Expertise in secure software delivery, vulnerability management, and platform security Experience with threat modelling, security frameworks, and maturity assessments Strong knowledge of application security, network security, and cloud security principles Excellent stakeholder management and communication skills Desirable: Experience in financial services or regulated environments Knowledge of Kubernetes and container security Familiarity with supply chain security, SBOM, and secure development practices Experience with workflow/orchestration tooling and event-driven automation Relevant certifications (eg CISSP, CISM, CCSP) More details available on successful application.
27/08/2026
Contractor
DevSecOps Consultant Sheffield (2-days per week onsite) Inside IR35 We're partnering with a leading financial services client to appoint a DevSecOps Consultant to drive secure engineering practices across large-scale, cloud-based platforms. This role is ideal for someone who has come from a hands-on DevSecOps Engineering background and has since transitioned into architecture, design and advisory, while still retaining strong technical depth. We're particularly looking for someone who brings a strong blend of Python development and orchestration experience alongside their DevSecOps expertise. Key Requirements: Proven background in hands-on DevSecOps Engineering, now operating in a design/architecture-focused role Strong Python development experience, with the ability to build automation and orchestration solutions Strong experience with orchestration and workflow automation across engineering, cloud and security platforms Strong experience across both AWS and GCP (essential) Deep understanding of CI/CD pipelines, build tools, artifact repositories, and developer platforms Expertise in secure software delivery, vulnerability management, and platform security Experience with threat modelling, security frameworks, and maturity assessments Strong knowledge of application security, network security, and cloud security principles Excellent stakeholder management and communication skills Desirable: Experience in financial services or regulated environments Knowledge of Kubernetes and container security Familiarity with supply chain security, SBOM, and secure development practices Experience with workflow/orchestration tooling and event-driven automation Relevant certifications (eg CISSP, CISM, CCSP) More details available on successful application.