it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

108 jobs found

Email me jobs like this
Refine Search
Current Search
group it auditor
Gold Group
Quality Assurance Engineer
Gold Group Portsmouth, Hampshire
Role: Quality Assurance Engineer Location: Portsmouth Salary: 40,000 - 45,000 depending on experience Quality Assurance Engineer needed in Portsmouth to join our client, an established marine engineering firm working on cutting edge systems within the marine industry. The QA team provides assurance that Quality requirements are being met so that our outputs deliver the capability our customers demand and rely on. You will have the opportunity to develop and enhance your skills and knowledge, with the potential to lead into more senior positions within a global business. What the role of the Quality Assurance Engineer entails: Some of the main duties of the Quality Assurance Engineer will include: Working as a fully contributory member of the Quality team Undertaking specific complex Quality Assurance activities across the whole group Having an awareness of Customer Quality conditions Supporting the management of non-conformance resolution and corrective actions with suppliers, key stakeholders and process owners The ability to analyse data effectively resulting in themes and corrective actions Contributing in working groups ensuring deliverables are achieved and Learning from Experience (LfE) is captured and applied Supporting departmental reviews and liaise with the customer when required The ability to produce written reports and presentations ensuring accuracy and clarity of meaning What experience you need to be the successful Quality Assurance Engineer: NC or HNC qualified in an appropriate technical discipline or equivalent Quality experience Quality professional, lead/internal auditor status or equivalent experience Understanding and application of ISO 9001 / EN9100 standards Understanding of Business Management Systems, the Operational Framework and Operational Assurance process Export requirements knowledge (for example International Traffic in Arms Regulations (ITAR Benefits: Enhanced Pension scheme- up to 16% combined Flexible working pattern including flexible start and finish times 25 holiday days plus bank holidays- 26 days after 5 years' service/ 27 days after 10 years' service Early finish on Fridays Shared Incentive Plan Employee Assistance Programme Cycle to Work Scheme Life Assurance (you and your spouse/ partner)- 6 x salary Ill Health Income Protection/ Private Medical Insurance- 50% of salary This role is subject to UK Security Clearance restrictions. Candidates would need to have lived & worked in the UK for 5+ years and be eligible to obtain BPSS as a minimum. This really is a fantastic opportunity for a Quality Assurance Engineer to progress their career. If you are interested please apply as soon as possible as this position will be filled quickly so don't miss out! Services advertised by Gold Group are those of an Agency and/or an Employment Business. We will contact you within the next 14 days if you are selected for interview. For a copy of our privacy policy please visit our website.
18/06/2026
Full time
Role: Quality Assurance Engineer Location: Portsmouth Salary: 40,000 - 45,000 depending on experience Quality Assurance Engineer needed in Portsmouth to join our client, an established marine engineering firm working on cutting edge systems within the marine industry. The QA team provides assurance that Quality requirements are being met so that our outputs deliver the capability our customers demand and rely on. You will have the opportunity to develop and enhance your skills and knowledge, with the potential to lead into more senior positions within a global business. What the role of the Quality Assurance Engineer entails: Some of the main duties of the Quality Assurance Engineer will include: Working as a fully contributory member of the Quality team Undertaking specific complex Quality Assurance activities across the whole group Having an awareness of Customer Quality conditions Supporting the management of non-conformance resolution and corrective actions with suppliers, key stakeholders and process owners The ability to analyse data effectively resulting in themes and corrective actions Contributing in working groups ensuring deliverables are achieved and Learning from Experience (LfE) is captured and applied Supporting departmental reviews and liaise with the customer when required The ability to produce written reports and presentations ensuring accuracy and clarity of meaning What experience you need to be the successful Quality Assurance Engineer: NC or HNC qualified in an appropriate technical discipline or equivalent Quality experience Quality professional, lead/internal auditor status or equivalent experience Understanding and application of ISO 9001 / EN9100 standards Understanding of Business Management Systems, the Operational Framework and Operational Assurance process Export requirements knowledge (for example International Traffic in Arms Regulations (ITAR Benefits: Enhanced Pension scheme- up to 16% combined Flexible working pattern including flexible start and finish times 25 holiday days plus bank holidays- 26 days after 5 years' service/ 27 days after 10 years' service Early finish on Fridays Shared Incentive Plan Employee Assistance Programme Cycle to Work Scheme Life Assurance (you and your spouse/ partner)- 6 x salary Ill Health Income Protection/ Private Medical Insurance- 50% of salary This role is subject to UK Security Clearance restrictions. Candidates would need to have lived & worked in the UK for 5+ years and be eligible to obtain BPSS as a minimum. This really is a fantastic opportunity for a Quality Assurance Engineer to progress their career. If you are interested please apply as soon as possible as this position will be filled quickly so don't miss out! Services advertised by Gold Group are those of an Agency and/or an Employment Business. We will contact you within the next 14 days if you are selected for interview. For a copy of our privacy policy please visit our website.
Spencer Rose Ltd
Security Compliance & GRC Specialist
Spencer Rose Ltd
Job Title: Security Compliance & GRC Specialist Up to £70,000 per annum Remote, with occassional office presence in London About the Role We are seeking an experienced and proactive Security Compliance & GRC Specialist to lead and strengthen our information security, governance, risk, and compliance initiatives across the organisation. This role will be instrumental in maintaining and maturing our Information Security Management System (ISMS), supporting successful audits and certifications, and embedding a strong culture of security compliance across the business. The successful candidate will work closely with the SVP of Compliance, Security, IT, Product Development, and wider business stakeholders to ensure compliance requirements are met while enabling business growth and operational efficiency. Security Compliance & GRC Specialist Key Responsibilities Support and maintain all ISMS policies in partnership with the SVP of Compliance. Ensure effective implementation of ISMS policies, standards, and related security controls across the organisation. Regularly assess ISMS controls to ensure ongoing compliance, identify improvement opportunities, and drive continuous enhancement initiatives. Mature and develop compliance testing frameworks and operational risk assessment processes. Collect, analyse, and mitigate operational security and compliance risks/exposures. Lead the organisation through internal and external audits, ensuring continued certification and audit success. Manage audit findings through to remediation and closure to support future audit and recertification activities. Maintain compliance knowledge bases and provide on-demand guidance and expertise to teams across the business. Remove complexity and operational barriers that impact security, product development, and business controls. Balance business enablement with compliance and security requirements in a practical and risk-based manner. Mentor Security, IT teams, and control owners in aligning controls with business processes, risk management, and continuous improvement initiatives. Monitor and advise on emerging regulatory and compliance requirements. Security Compliance & GRC Specialist About the Role We are seeking an experienced and proactive Security Compliance & GRC Specialist to lead and mature our information security compliance programme. This role will be responsible for maintaining and enhancing our ISMS framework, supporting audits and certifications, driving continuous improvement across security and compliance controls, and embedding a strong culture of security awareness throughout the organisation. Working closely with the Heads of Functions of Compliance, IT, Security, Product and other business stakeholders, you will act as a trusted advisor and subject matter expert on governance, risk and compliance activities across the business. Key Responsibilities Support and maintain all ISMS policies and frameworks in partnership with the SVP of Compliance. Ensure the effective implementation and ongoing management of ISMS policies, standards and related compliance initiatives. Regularly assess compliance controls to ensure ongoing adherence, operational effectiveness and continuous improvement. Drive the development and maturation of compliance testing frameworks. Identify, analyse and mitigate operational and compliance risks across the organisation. Lead and coordinate successful internal and external audits, ensuring all audit findings are effectively managed through to closure. Maintain compliance knowledge bases and provide on-demand guidance and support to teams across the business. Remove complexity and barriers that hinder effective security, product development and operational controls. Partner with stakeholders to balance business enablement with strong compliance and security posture. Support Security, IT and control owners in aligning risks, controls and business processes. Monitor and advise on emerging regulatory and compliance requirements. Champion and embed a strong culture of security compliance and continuous improvement. Develop, implement and maintain security policies, standards and awareness materials. Deliver internal security and compliance training programmes. Collaborate with IT and technical teams to ensure security best practices are Embedded within systems, applications and infrastructure. Manage GRC tooling, reporting and compliance metrics. Support customer, client and sales-related security and compliance activities as required. Skills & Experience Essential Proven experience in Information Security, Governance, Risk & Compliance (GRC), or related roles. Strong understanding of ISMS frameworks and standards such as ISO 27001, SOC 2, GDPR and related security controls. Experience managing audits, certifications and remediation programmes. Knowledge of risk management methodologies and compliance assessment processes. Familiarity with security policies, standards and awareness programmes. Strong stakeholder management and communication skills. Ability to simplify complex compliance and security concepts for technical and non-technical audiences. Experience working cross-functionally with Security, IT, Engineering, Product and business teams. Strong analytical, organisational and problem-solving capabilities. Desirable Experience with GRC platforms and compliance tooling. Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor or Lead Implementer. Experience in fast-paced or high-growth environments. Knowledge of additional regulatory frameworks and customer security requirements. Personal Attributes Collaborative and approachable Proactive and solutions-focused Strong attention to detail Commercially minded with a pragmatic approach to compliance Passionate about security, governance and continuous improvement Comfortable influencing at all levels of the organisation We invite individuals from underrepresented groups to apply for any of our roles and are committed to supporting accessibility needs.
18/06/2026
Full time
Job Title: Security Compliance & GRC Specialist Up to £70,000 per annum Remote, with occassional office presence in London About the Role We are seeking an experienced and proactive Security Compliance & GRC Specialist to lead and strengthen our information security, governance, risk, and compliance initiatives across the organisation. This role will be instrumental in maintaining and maturing our Information Security Management System (ISMS), supporting successful audits and certifications, and embedding a strong culture of security compliance across the business. The successful candidate will work closely with the SVP of Compliance, Security, IT, Product Development, and wider business stakeholders to ensure compliance requirements are met while enabling business growth and operational efficiency. Security Compliance & GRC Specialist Key Responsibilities Support and maintain all ISMS policies in partnership with the SVP of Compliance. Ensure effective implementation of ISMS policies, standards, and related security controls across the organisation. Regularly assess ISMS controls to ensure ongoing compliance, identify improvement opportunities, and drive continuous enhancement initiatives. Mature and develop compliance testing frameworks and operational risk assessment processes. Collect, analyse, and mitigate operational security and compliance risks/exposures. Lead the organisation through internal and external audits, ensuring continued certification and audit success. Manage audit findings through to remediation and closure to support future audit and recertification activities. Maintain compliance knowledge bases and provide on-demand guidance and expertise to teams across the business. Remove complexity and operational barriers that impact security, product development, and business controls. Balance business enablement with compliance and security requirements in a practical and risk-based manner. Mentor Security, IT teams, and control owners in aligning controls with business processes, risk management, and continuous improvement initiatives. Monitor and advise on emerging regulatory and compliance requirements. Security Compliance & GRC Specialist About the Role We are seeking an experienced and proactive Security Compliance & GRC Specialist to lead and mature our information security compliance programme. This role will be responsible for maintaining and enhancing our ISMS framework, supporting audits and certifications, driving continuous improvement across security and compliance controls, and embedding a strong culture of security awareness throughout the organisation. Working closely with the Heads of Functions of Compliance, IT, Security, Product and other business stakeholders, you will act as a trusted advisor and subject matter expert on governance, risk and compliance activities across the business. Key Responsibilities Support and maintain all ISMS policies and frameworks in partnership with the SVP of Compliance. Ensure the effective implementation and ongoing management of ISMS policies, standards and related compliance initiatives. Regularly assess compliance controls to ensure ongoing adherence, operational effectiveness and continuous improvement. Drive the development and maturation of compliance testing frameworks. Identify, analyse and mitigate operational and compliance risks across the organisation. Lead and coordinate successful internal and external audits, ensuring all audit findings are effectively managed through to closure. Maintain compliance knowledge bases and provide on-demand guidance and support to teams across the business. Remove complexity and barriers that hinder effective security, product development and operational controls. Partner with stakeholders to balance business enablement with strong compliance and security posture. Support Security, IT and control owners in aligning risks, controls and business processes. Monitor and advise on emerging regulatory and compliance requirements. Champion and embed a strong culture of security compliance and continuous improvement. Develop, implement and maintain security policies, standards and awareness materials. Deliver internal security and compliance training programmes. Collaborate with IT and technical teams to ensure security best practices are Embedded within systems, applications and infrastructure. Manage GRC tooling, reporting and compliance metrics. Support customer, client and sales-related security and compliance activities as required. Skills & Experience Essential Proven experience in Information Security, Governance, Risk & Compliance (GRC), or related roles. Strong understanding of ISMS frameworks and standards such as ISO 27001, SOC 2, GDPR and related security controls. Experience managing audits, certifications and remediation programmes. Knowledge of risk management methodologies and compliance assessment processes. Familiarity with security policies, standards and awareness programmes. Strong stakeholder management and communication skills. Ability to simplify complex compliance and security concepts for technical and non-technical audiences. Experience working cross-functionally with Security, IT, Engineering, Product and business teams. Strong analytical, organisational and problem-solving capabilities. Desirable Experience with GRC platforms and compliance tooling. Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor or Lead Implementer. Experience in fast-paced or high-growth environments. Knowledge of additional regulatory frameworks and customer security requirements. Personal Attributes Collaborative and approachable Proactive and solutions-focused Strong attention to detail Commercially minded with a pragmatic approach to compliance Passionate about security, governance and continuous improvement Comfortable influencing at all levels of the organisation We invite individuals from underrepresented groups to apply for any of our roles and are committed to supporting accessibility needs.
Quality Manager
enerpac Cramlington, Northumberland
Overview Enerpac Tool Group Corp. is a premier industrial tools, services, technology and solutions provider serving a broad and diverse set of customers in more than 100 countries. The Company makes complex, often hazardous jobs possible safely and efficiently. Enerpac Tool Group's businesses are global leaders in high pressure hydraulic tools, controlled force products, and solutions for precise positioning of heavy loads that help customers safely and reliably tackle some of the most challenging jobs around the world. The Company was founded in 1910 and is headquartered in Milwaukee, Wisconsin. Enerpac Tool Group common stock trades on the NYSE under the symbol EPAC. To unleash the power of diversity within our business we will continuously seek out new ways to empower teams to reach their full potential. Removing barriers to inclusion and championing a better workplace for us all. For further information on Enerpac Tool Group and its businesses, visit the Company's website at Summary - basic function of the role We are seeking an experienced Quality Manager to join our team on a permanent basis, supporting our team in Cramlington, onsite 5 days per week. The Quality Manager is responsible for the strategic planning, development, implementation, and ongoing management of Enerpac UK's Quality Management System (QMS). This role ensures compliance with quality policies, procedures, and standards at site, regional, and global levels, while driving continuous improvement initiatives to strengthen the effectiveness and maturity of the QMS across the organisation. Job Duties and Responsibilities Develop, maintain, and continuously improve the QMS; creating and updating documentation to reflect operational changes, site specific needs, and industry best practices. Establish and monitor strategic quality objectives and performance targets; lead site initiatives to address underperformance and improve key performance indicators. Ensure ISO 9001 requirements are clearly communicated, understood, and consistently applied throughout the organisation. Lead and contribute to regional management reviews to drive continuous improvement of the QMS. Ensure supplier, internal, and customer quality issues are accurately reported and managed within the Qualityze system. Oversee the timely closure of all product quality non conformances and corrective and preventive actions (CAPAs). Maintain effective communication channels to report progress on non conformance resolution to internal and external stakeholders. Act as the escalation point for customer quality non conformances. Serve as Qualityze system administrator and contribute to software enhancements that improve business efficiency. Actively promote safety awareness and continuous improvement, identifying opportunities to drive change, increase efficiency, and deliver results while maintaining compliance. Represent the company professionally at all times, adhering to company policies, procedures, and safety standards; serve as a role model and ambassador for health and safety excellence. Effectively influence, develop, and train employees to strengthen a culture of quality and continuous improvement. Skills and Competencies Strong working knowledge of APQP, PPAP, MSA, FMEA, Control Plans, SPC, and 8D methodologies. Excellent verbal and written communication skills, with the ability to engage effectively at all organisational levels. Demonstrated strong problem solving and analytical skills. Outstanding facilitation, training, communication, and presentation abilities; positive, persuasive, and motivating leadership style. Proficient report writing and presentation skills using Microsoft Office applications. Self motivated, well organized, and an effective time manager with a collaborative team oriented approach. Assertive yet diplomatic, with a strong understanding of business and commercial priorities. Proven ability to work cross functionally and within global, multicultural teams. Capable of managing multiple priorities under tight deadlines. Education and Experience Minimum of 5 years' experience implementing quality systems, with a proven ability to develop, train, and coach employees in a quality driven environment. Extensive experience managing ISO 9001 systems, including Lead Auditor experience or certification. ISO 9001 Internal Auditor certification or willingness to obtain Lead Auditor certification. Work Benefits Engagement with Employee Resource Groups which can provide leadership and networking opportunities. Competitive salary, performance incentives, and benefits package. Community Outreach programs embedded in the Company's culture.
18/06/2026
Full time
Overview Enerpac Tool Group Corp. is a premier industrial tools, services, technology and solutions provider serving a broad and diverse set of customers in more than 100 countries. The Company makes complex, often hazardous jobs possible safely and efficiently. Enerpac Tool Group's businesses are global leaders in high pressure hydraulic tools, controlled force products, and solutions for precise positioning of heavy loads that help customers safely and reliably tackle some of the most challenging jobs around the world. The Company was founded in 1910 and is headquartered in Milwaukee, Wisconsin. Enerpac Tool Group common stock trades on the NYSE under the symbol EPAC. To unleash the power of diversity within our business we will continuously seek out new ways to empower teams to reach their full potential. Removing barriers to inclusion and championing a better workplace for us all. For further information on Enerpac Tool Group and its businesses, visit the Company's website at Summary - basic function of the role We are seeking an experienced Quality Manager to join our team on a permanent basis, supporting our team in Cramlington, onsite 5 days per week. The Quality Manager is responsible for the strategic planning, development, implementation, and ongoing management of Enerpac UK's Quality Management System (QMS). This role ensures compliance with quality policies, procedures, and standards at site, regional, and global levels, while driving continuous improvement initiatives to strengthen the effectiveness and maturity of the QMS across the organisation. Job Duties and Responsibilities Develop, maintain, and continuously improve the QMS; creating and updating documentation to reflect operational changes, site specific needs, and industry best practices. Establish and monitor strategic quality objectives and performance targets; lead site initiatives to address underperformance and improve key performance indicators. Ensure ISO 9001 requirements are clearly communicated, understood, and consistently applied throughout the organisation. Lead and contribute to regional management reviews to drive continuous improvement of the QMS. Ensure supplier, internal, and customer quality issues are accurately reported and managed within the Qualityze system. Oversee the timely closure of all product quality non conformances and corrective and preventive actions (CAPAs). Maintain effective communication channels to report progress on non conformance resolution to internal and external stakeholders. Act as the escalation point for customer quality non conformances. Serve as Qualityze system administrator and contribute to software enhancements that improve business efficiency. Actively promote safety awareness and continuous improvement, identifying opportunities to drive change, increase efficiency, and deliver results while maintaining compliance. Represent the company professionally at all times, adhering to company policies, procedures, and safety standards; serve as a role model and ambassador for health and safety excellence. Effectively influence, develop, and train employees to strengthen a culture of quality and continuous improvement. Skills and Competencies Strong working knowledge of APQP, PPAP, MSA, FMEA, Control Plans, SPC, and 8D methodologies. Excellent verbal and written communication skills, with the ability to engage effectively at all organisational levels. Demonstrated strong problem solving and analytical skills. Outstanding facilitation, training, communication, and presentation abilities; positive, persuasive, and motivating leadership style. Proficient report writing and presentation skills using Microsoft Office applications. Self motivated, well organized, and an effective time manager with a collaborative team oriented approach. Assertive yet diplomatic, with a strong understanding of business and commercial priorities. Proven ability to work cross functionally and within global, multicultural teams. Capable of managing multiple priorities under tight deadlines. Education and Experience Minimum of 5 years' experience implementing quality systems, with a proven ability to develop, train, and coach employees in a quality driven environment. Extensive experience managing ISO 9001 systems, including Lead Auditor experience or certification. ISO 9001 Internal Auditor certification or willingness to obtain Lead Auditor certification. Work Benefits Engagement with Employee Resource Groups which can provide leadership and networking opportunities. Competitive salary, performance incentives, and benefits package. Community Outreach programs embedded in the Company's culture.
Head of Compliance New London
Arqit Limited
Arqit is a global pioneer in post-quantum cryptography: we provide a proven defence against both current cyber dangers and impending quantum threats. Our global team describe Arqit as providing a positive, inclusive and high-performing working environment, where employees feel that managers care about the success and well-being of their teams, individuals feel valued as employees and teams achieve more than they thought possible, together. We have brought together a world-leading team of pioneers in engineering and cryptography, and we now have an opportunity for a Head of Compliance to lead our compliance function. As a key member of the Operations team, you will ensure our company adheres to regulatory standards, industry best practices, and internal policies. This includes overseeing our SOX controls, ISO27001 certification, risk management framework, GDPR compliance, export controls, and internal auditing processes. You will play a crucial role in maintaining the integrity of our operations as we continue to grow and expand globally. You will join our talented team, located conveniently close to Westminster, St James Park and Victoria stations, with considerable flexibility around working from home. As part of a dynamic, innovative team, you will make a significant impact by shaping and enhancing our compliance landscape. If you're passionate about compliance, risk management, and data protection, and want to contribute to a forward-thinking cybersecurity company, we'd love to hear from you! What you will be doing ISO27001 Compliance & Internal Auditing: Lead and maintain ISO27001 certification, including internal audits, risk assessments, and continuous improvement initiatives Conduct regular internal audits, identify areas for improvement, and implement corrective actions Develop, implement, and manage the company's risk management framework Identify, assess, and mitigate compliance risks across all business functions Collaborate with leadership to align risk management practices with company objectives Data Protection & GDPR: Support the company's compliance with GDPR and other data privacy regulations Conduct data protection impact assessments (DPIAs) and ensure privacy by design and default across products and services Export Control: Work with the Legal department and VP Operations to create and maintain an effective framework to monitor compliance with export licenses Develop a robust system to maintain evidentiary documents and policies to support regulatory audits Work with Operations, Legal and Finance to create an effective program for KYC/B screening Regulatory Compliance & Governance: Work with relevant departments to ensure regular review and maintenance of company policies, procedures and training to ensure adherence to legal and regulatory requirements Prepare and present reports as necessary to senior management, the Board or Audit Committee SOX: Work with the Group Financial Controller to support the company's compliance with SOX. Perform testing of the SOX controls on a quarterly and annual basis. What we're looking for Proven experience in a senior compliance role, ideally within a software, cybersecurity, or technology company In-depth knowledge of ISO27001, GDPR, SOX Experience conducting internal audits and managing risk frameworks Some knowledge and/or experience of export control regulations and licensing requirements, specifically as they may relate to cryptography or information security systems Strong understanding of UK, EU, US, and international regulatory environments as they apply to the business Exceptional communication and stakeholder management skills Relevant certifications such as CISM, CISSP, ISO27001 Lead Auditor/Implementer, or similar are highly desirable Ability to work independently while collaborating across departments Please note, the ability to work in the UK without restrictions is ESSENTIAL; there may also be a need for UK security clearance in future.
18/06/2026
Full time
Arqit is a global pioneer in post-quantum cryptography: we provide a proven defence against both current cyber dangers and impending quantum threats. Our global team describe Arqit as providing a positive, inclusive and high-performing working environment, where employees feel that managers care about the success and well-being of their teams, individuals feel valued as employees and teams achieve more than they thought possible, together. We have brought together a world-leading team of pioneers in engineering and cryptography, and we now have an opportunity for a Head of Compliance to lead our compliance function. As a key member of the Operations team, you will ensure our company adheres to regulatory standards, industry best practices, and internal policies. This includes overseeing our SOX controls, ISO27001 certification, risk management framework, GDPR compliance, export controls, and internal auditing processes. You will play a crucial role in maintaining the integrity of our operations as we continue to grow and expand globally. You will join our talented team, located conveniently close to Westminster, St James Park and Victoria stations, with considerable flexibility around working from home. As part of a dynamic, innovative team, you will make a significant impact by shaping and enhancing our compliance landscape. If you're passionate about compliance, risk management, and data protection, and want to contribute to a forward-thinking cybersecurity company, we'd love to hear from you! What you will be doing ISO27001 Compliance & Internal Auditing: Lead and maintain ISO27001 certification, including internal audits, risk assessments, and continuous improvement initiatives Conduct regular internal audits, identify areas for improvement, and implement corrective actions Develop, implement, and manage the company's risk management framework Identify, assess, and mitigate compliance risks across all business functions Collaborate with leadership to align risk management practices with company objectives Data Protection & GDPR: Support the company's compliance with GDPR and other data privacy regulations Conduct data protection impact assessments (DPIAs) and ensure privacy by design and default across products and services Export Control: Work with the Legal department and VP Operations to create and maintain an effective framework to monitor compliance with export licenses Develop a robust system to maintain evidentiary documents and policies to support regulatory audits Work with Operations, Legal and Finance to create an effective program for KYC/B screening Regulatory Compliance & Governance: Work with relevant departments to ensure regular review and maintenance of company policies, procedures and training to ensure adherence to legal and regulatory requirements Prepare and present reports as necessary to senior management, the Board or Audit Committee SOX: Work with the Group Financial Controller to support the company's compliance with SOX. Perform testing of the SOX controls on a quarterly and annual basis. What we're looking for Proven experience in a senior compliance role, ideally within a software, cybersecurity, or technology company In-depth knowledge of ISO27001, GDPR, SOX Experience conducting internal audits and managing risk frameworks Some knowledge and/or experience of export control regulations and licensing requirements, specifically as they may relate to cryptography or information security systems Strong understanding of UK, EU, US, and international regulatory environments as they apply to the business Exceptional communication and stakeholder management skills Relevant certifications such as CISM, CISSP, ISO27001 Lead Auditor/Implementer, or similar are highly desirable Ability to work independently while collaborating across departments Please note, the ability to work in the UK without restrictions is ESSENTIAL; there may also be a need for UK security clearance in future.
Strategic Initiatives Program Lead - Senior Vice President
Citigroup Inc. City, Belfast
Citi Belfast is one of the largest employers in Northern Ireland with a diverse and talented team of over 4000 people from over 68 different nationalities across our four Belfast offices. We are the only global investment bank operating in Northern Ireland. Every day, our local experts interact with global teams in over 100 countries developing and supporting next generation technology solutions for the enterprise and delivering critical services to the bank and its customers, to make sure we are a stronger and safer organization for our clients. You will have a truly global reach, which will provide you with new experiences and development opportunities right here in Belfast's iconic Titanic Quarter. The successful candidate will lead key strategic initiatives in support of enterprise strategy and resilience, ensuring Citi's critical business services maintain operational resilience in alignment with regulatory requirements and business objectives. Driving strategic vision, governance, and organizational change across technology teams to embed resiliency principles into application design, recovery capabilities, and operational practices; this role is accountable for establishing and maintaining a robust resiliency framework that protects critical business services, minimizes client impact, and ensures compliance with global regulatory standards. Strategic Leadership & Vision Lead strategic initiatives in support of enterprise strategy and resilience across all technology organizations, ensuring alignment with business priorities, regulatory requirements, and industry best practices. Provide executive leadership for the resiliency program, overseeing the workstreams to drive progress. Establish strategic partnerships with senior technology leaders, business executives, Enterprise Resilience, Risk Management, and regulatory stakeholders to drive resiliency transformation. Champion organizational change to embed resiliency first thinking into application development, architecture decisions, and operational practices. Governance & Regulatory Compliance Ensure compliance with regulatory requirements for operational resilience across all jurisdictions, including MAS, OCC, PRA, and other regulatory mandates. Oversee the Enterprise Criticality Framework, ensuring accurate framework to identification of Enterprise Critical Applications (ECAs) and alignment with Critical Business Services (CBS). Support engagement with regulators and auditors on resiliency matters, providing evidence of program effectiveness and compliance. Drive resolution of regulatory findings and Corrective Action Plans (CAPs) related to application resiliency and recovery capabilities. Program Oversight & Accountability Provide executive oversight and accountability for the resiliency program, ensuring delivery of strategic initiatives and achievement of annual targets. Monitor program health, risks, and performance metrics, making strategic decisions to optimize outcomes and resource allocation. Support budget and resource allocation across resiliency initiatives, balancing strategic priorities with operational constraints. Technology & Platform Strategy Drive the strategic direction for resiliency platforms and tools, including One Touch Recovery (OTR), ServiceNow BCM, and emerging technologies. Champion investment in automation, API integration, and self service capabilities to scale resiliency practices across the enterprise. Stakeholder Management & Communication Communicate resiliency strategy, progress, and risks to executive committees and governance forums. Build consensus and drive decision making across diverse stakeholder groups with competing priorities. Represent technology resiliency in enterprise wide business continuity and crisis management forums. Key Qualifications Progressive technology leadership experience in large, complex organizations. Senior leadership roles managing large teams and strategic programs. Experience in resiliency, disaster recovery, business continuity, or operational risk management. Proven track record leading enterprise wide transformation initiatives in highly regulated industries. Experience managing responses to regulators and navigating complex compliance requirements. Deep understanding of application architecture, distributed systems, and cloud technologies. Knowledge of disaster recovery, business continuity, and operational resilience frameworks. Familiarity with SRE principles, chaos engineering, and automated recovery practices. Understanding of regulatory requirements for operational resilience in financial services. Experience with enterprise platforms, APIs, and system integration strategies. Experience managing program budgets and resources. BS degree in Computer Science, Engineering, or equivalent field required. Leadership Competencies Strategic thinking and ability to translate business objectives into technology strategies. Strong executive presence with ability to influence and drive change across organizational boundaries. Exceptional communication skills with ability to articulate complex technical concepts to business and executive audiences. Strong business and financial acumen. What we'll provide you By joining Citi, you will not only be part of a business casual workplace with a hybrid working model (up to 2 days working at home per week), but also receive a competitive base salary (which is annually reviewed), and enjoy a whole host of additional benefits such as: 27 days annual leave (plus bank holidays) A discretionary annual performance related bonus Private Medical Care & Life Insurance Employee Assistance Program Pension Plan Paid Parental Leave Special discounts for employees, family, and friends Access to an array of learning and development resources Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review. Accessibility at Citi. View Citi's EEO Policy Statement and the Know Your Rights poster.
18/06/2026
Full time
Citi Belfast is one of the largest employers in Northern Ireland with a diverse and talented team of over 4000 people from over 68 different nationalities across our four Belfast offices. We are the only global investment bank operating in Northern Ireland. Every day, our local experts interact with global teams in over 100 countries developing and supporting next generation technology solutions for the enterprise and delivering critical services to the bank and its customers, to make sure we are a stronger and safer organization for our clients. You will have a truly global reach, which will provide you with new experiences and development opportunities right here in Belfast's iconic Titanic Quarter. The successful candidate will lead key strategic initiatives in support of enterprise strategy and resilience, ensuring Citi's critical business services maintain operational resilience in alignment with regulatory requirements and business objectives. Driving strategic vision, governance, and organizational change across technology teams to embed resiliency principles into application design, recovery capabilities, and operational practices; this role is accountable for establishing and maintaining a robust resiliency framework that protects critical business services, minimizes client impact, and ensures compliance with global regulatory standards. Strategic Leadership & Vision Lead strategic initiatives in support of enterprise strategy and resilience across all technology organizations, ensuring alignment with business priorities, regulatory requirements, and industry best practices. Provide executive leadership for the resiliency program, overseeing the workstreams to drive progress. Establish strategic partnerships with senior technology leaders, business executives, Enterprise Resilience, Risk Management, and regulatory stakeholders to drive resiliency transformation. Champion organizational change to embed resiliency first thinking into application development, architecture decisions, and operational practices. Governance & Regulatory Compliance Ensure compliance with regulatory requirements for operational resilience across all jurisdictions, including MAS, OCC, PRA, and other regulatory mandates. Oversee the Enterprise Criticality Framework, ensuring accurate framework to identification of Enterprise Critical Applications (ECAs) and alignment with Critical Business Services (CBS). Support engagement with regulators and auditors on resiliency matters, providing evidence of program effectiveness and compliance. Drive resolution of regulatory findings and Corrective Action Plans (CAPs) related to application resiliency and recovery capabilities. Program Oversight & Accountability Provide executive oversight and accountability for the resiliency program, ensuring delivery of strategic initiatives and achievement of annual targets. Monitor program health, risks, and performance metrics, making strategic decisions to optimize outcomes and resource allocation. Support budget and resource allocation across resiliency initiatives, balancing strategic priorities with operational constraints. Technology & Platform Strategy Drive the strategic direction for resiliency platforms and tools, including One Touch Recovery (OTR), ServiceNow BCM, and emerging technologies. Champion investment in automation, API integration, and self service capabilities to scale resiliency practices across the enterprise. Stakeholder Management & Communication Communicate resiliency strategy, progress, and risks to executive committees and governance forums. Build consensus and drive decision making across diverse stakeholder groups with competing priorities. Represent technology resiliency in enterprise wide business continuity and crisis management forums. Key Qualifications Progressive technology leadership experience in large, complex organizations. Senior leadership roles managing large teams and strategic programs. Experience in resiliency, disaster recovery, business continuity, or operational risk management. Proven track record leading enterprise wide transformation initiatives in highly regulated industries. Experience managing responses to regulators and navigating complex compliance requirements. Deep understanding of application architecture, distributed systems, and cloud technologies. Knowledge of disaster recovery, business continuity, and operational resilience frameworks. Familiarity with SRE principles, chaos engineering, and automated recovery practices. Understanding of regulatory requirements for operational resilience in financial services. Experience with enterprise platforms, APIs, and system integration strategies. Experience managing program budgets and resources. BS degree in Computer Science, Engineering, or equivalent field required. Leadership Competencies Strategic thinking and ability to translate business objectives into technology strategies. Strong executive presence with ability to influence and drive change across organizational boundaries. Exceptional communication skills with ability to articulate complex technical concepts to business and executive audiences. Strong business and financial acumen. What we'll provide you By joining Citi, you will not only be part of a business casual workplace with a hybrid working model (up to 2 days working at home per week), but also receive a competitive base salary (which is annually reviewed), and enjoy a whole host of additional benefits such as: 27 days annual leave (plus bank holidays) A discretionary annual performance related bonus Private Medical Care & Life Insurance Employee Assistance Program Pension Plan Paid Parental Leave Special discounts for employees, family, and friends Access to an array of learning and development resources Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review. Accessibility at Citi. View Citi's EEO Policy Statement and the Know Your Rights poster.
Head of Security (CISO)
ClearCourse Partnership LLP
Head of Security (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Head of Security (CISO) to lead and evolve our group-wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Qualifications Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Benefits Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
18/06/2026
Full time
Head of Security (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Head of Security (CISO) to lead and evolve our group-wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Qualifications Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Benefits Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
ISACA Instructor (part-time)
BPP Holdings Thurleigh, Bedfordshire
Firebrand Training Ltd, a part of Lyceum Education Group, is a leading provider of accelerated IT training. We specialize in delivering high quality, intensive training programmes that help professionals achieve their certification goals faster. As an ISACA Accredited Training Organisation, we are committed to providing world class training and professional development opportunities for cybersecurity professionals. We are seeking a knowledgeable and dedicated ISACA Cyber Trainer to join our team on a part time basis (30 hours per week). The ideal candidate will have a strong background in cybersecurity, extensive experience with ISACA certifications, and a passion for teaching. You will develop and deliver comprehensive training programmes that prepare students for ISACA certification exams and equip them with the skills needed to excel in the cybersecurity field. Why work for Firebrand? Firebrand offers competitive benefits and a supportive environment for professional growth. Universal access to our courses - including professional qualifications and full degrees. Hybrid working options that allow you to balance time between our centres and your home. Generous annual leave entitlement (30 days) and a rewards package that includes retail discounts and more. Group Personal Pension Plan, dedicated private healthcare and dental plans. What you'll be doing The role involves developing and delivering training programmes focused on ISACA certifications such as CISM, CISA, CRISC, and CGEIT. You will: Develop, organise and conduct training programmes in the field of cybersecurity. Create and update course materials, including textbooks, workbooks, handouts and digital resources. Deliver training sessions in various formats - in person, online and blended learning. Assess trainees' knowledge, skills and abilities, providing feedback and coaching. Stay current with the latest developments in cybersecurity and incorporate them into the curriculum. Conduct practical exercises and role play scenarios to provide hands on experience. Monitor and evaluate the effectiveness of training programmes and make adjustments as needed. Maintain relationships with external vendors and stakeholders to enhance training programmes. Support students throughout their certification journey, offering guidance and assistance. What we're looking for To be successful in this role you will need to have a proven track record in the following areas: ISACA Certified Information Security Manager (CISM) ISACA Certified in Risk and Information Systems Control (CRISC) ISACA Certified Data Privacy Solutions Engineer (CDPSE) ISACA Certified in the Governance of Enterprise IT (CGEIT) Certified ISO27001 Lead Implementor Certified ISO27001 Lead Auditor Proven experience as a cybersecurity trainer or instructor. Proven relevant industry experience. Strong knowledge of cybersecurity principles, practices and frameworks. Excellent communication and presentation skills. Ability to create engaging, interactive learning environments. Experience with various training delivery methods - in person, online and blended. Strong organisational and time management skills. Commitment to continuous professional development and staying current with industry trends. Please note that the successful candidate will be required to undergo an Enhanced DBS and Academic/Qualification check. Firebrand, part of Lyceum Education Group, actively promotes equality of opportunity for all candidates and welcomes applications from a wide range of backgrounds. All applicants will be considered on the basis of their skills, qualifications and experience. Successful candidates will also undergo a DBS check in accordance with our safer recruitment practices.
17/06/2026
Full time
Firebrand Training Ltd, a part of Lyceum Education Group, is a leading provider of accelerated IT training. We specialize in delivering high quality, intensive training programmes that help professionals achieve their certification goals faster. As an ISACA Accredited Training Organisation, we are committed to providing world class training and professional development opportunities for cybersecurity professionals. We are seeking a knowledgeable and dedicated ISACA Cyber Trainer to join our team on a part time basis (30 hours per week). The ideal candidate will have a strong background in cybersecurity, extensive experience with ISACA certifications, and a passion for teaching. You will develop and deliver comprehensive training programmes that prepare students for ISACA certification exams and equip them with the skills needed to excel in the cybersecurity field. Why work for Firebrand? Firebrand offers competitive benefits and a supportive environment for professional growth. Universal access to our courses - including professional qualifications and full degrees. Hybrid working options that allow you to balance time between our centres and your home. Generous annual leave entitlement (30 days) and a rewards package that includes retail discounts and more. Group Personal Pension Plan, dedicated private healthcare and dental plans. What you'll be doing The role involves developing and delivering training programmes focused on ISACA certifications such as CISM, CISA, CRISC, and CGEIT. You will: Develop, organise and conduct training programmes in the field of cybersecurity. Create and update course materials, including textbooks, workbooks, handouts and digital resources. Deliver training sessions in various formats - in person, online and blended learning. Assess trainees' knowledge, skills and abilities, providing feedback and coaching. Stay current with the latest developments in cybersecurity and incorporate them into the curriculum. Conduct practical exercises and role play scenarios to provide hands on experience. Monitor and evaluate the effectiveness of training programmes and make adjustments as needed. Maintain relationships with external vendors and stakeholders to enhance training programmes. Support students throughout their certification journey, offering guidance and assistance. What we're looking for To be successful in this role you will need to have a proven track record in the following areas: ISACA Certified Information Security Manager (CISM) ISACA Certified in Risk and Information Systems Control (CRISC) ISACA Certified Data Privacy Solutions Engineer (CDPSE) ISACA Certified in the Governance of Enterprise IT (CGEIT) Certified ISO27001 Lead Implementor Certified ISO27001 Lead Auditor Proven experience as a cybersecurity trainer or instructor. Proven relevant industry experience. Strong knowledge of cybersecurity principles, practices and frameworks. Excellent communication and presentation skills. Ability to create engaging, interactive learning environments. Experience with various training delivery methods - in person, online and blended. Strong organisational and time management skills. Commitment to continuous professional development and staying current with industry trends. Please note that the successful candidate will be required to undergo an Enhanced DBS and Academic/Qualification check. Firebrand, part of Lyceum Education Group, actively promotes equality of opportunity for all candidates and welcomes applications from a wide range of backgrounds. All applicants will be considered on the basis of their skills, qualifications and experience. Successful candidates will also undergo a DBS check in accordance with our safer recruitment practices.
Information Security & Compliance Officer
PEI Group
About The Role We are seeking an Information Security & Compliance Officer to support and strengthen our organisation's security and compliance posture. This role is responsible for coordinating security activities across the business, supporting compliance initiatives, managing third party risk, and acting as the internal liaison with our outsourced Security Operations Centre (SOC) and Virtual CISO. The successful candidate will help implement security governance, risk management, and compliance frameworks while ensuring security best practices are embedded across the organisation. This role is ideal for someone with experience in security operations, governance, risk, and compliance (GRC) who enjoys working across teams to improve organisational security maturity. Key Responsibilities Security Operations Oversight Act as the primary internal liaison with the outsourced SOC provider Monitor and coordinate responses to alerts generated through Microsoft Sentinel and Microsoft Defender Support incident response coordination and internal communications Track remediation of security vulnerabilities and incidents Governance, Risk & Compliance Support the implementation and maintenance of security frameworks such as: ISO 27001 Cyber Essentials Plus NIST / CIS frameworks Maintain and develop security policies, standards, and procedures Conduct risk assessments and track remediation actions Coordinate internal and external security audits Coordinate with other governance teams to ensure alignment around key initiatives Third Party Risk Management (TPRM) Lead the rollout and ongoing management of a Third Party Risk Management programme Perform vendor security assessments and due diligence Maintain vendor risk registers and track remediation activities Work with procurement and legal teams to embed security requirements into supplier onboarding Security Governance & Awareness Support security awareness and training initiatives across the organisation Work with IT and engineering teams to ensure security best practices are followed Maintain risk registers and compliance documentation Provide reporting and metrics on security posture to leadership Security Projects & Initiatives Support compliance initiatives and security improvement programmes Work with the virtual CISO to implement strategic security improvements Assist with policy development and control implementation Help coordinate vulnerability management and remediation programmes Provide input into client security questionnaires and audits where appropriate About You Skills & Experience 3-5 years experience in information security, IT security, or compliance Understanding of security governance, risk, and compliance (GRC) Experience with Microsoft security tooling (Sentinel, Defender, or Microsoft Security stack) Familiarity with security frameworks (ISO 27001, NIST, CIS, Cyber Essentials) Experience working with third party vendors or supplier risk assessments Strong communication and stakeholder management skills Ability to translate security requirements into practical business processes Desirable Experience working with outsourced SOC providers Knowledge of Third Party Risk Management (TPRM) programmes Experience supporting ISO 27001 certification or audits Certifications such as: ISO 27001 Lead Implementer / Lead Auditor CISSP CISM Security+ Key Competencies Strong organisational and documentation skills Ability to manage multiple compliance initiatives simultaneously Analytical thinking and risk assessment capability Collaborative approach to working across technical and non technical teams Proactive mindset with a focus on continuous improvement What Success Looks Like Establish a structured Third Party Risk Management programme Improve visibility and reporting of security risks Strengthen security governance processes Develop ISO 27001 implementation roadmap and compliance processes to ensure group compliance can evolve to a recognised standard within the next months. Improve collaboration between internal teams, the SOC provider, and the virtual CISO Equal Opportunity We value diverse talent and welcome applications from everyone - regardless of background. We are an equal opportunity employer and our inclusive culture at PEI is reflected in every stage of the recruitment journey. Please inform us at initial stages of the recruitment process if you require any reasonable adjustments and we can accommodate this. PEI supports flexible working arrangements, and we welcome career returners.
16/06/2026
Full time
About The Role We are seeking an Information Security & Compliance Officer to support and strengthen our organisation's security and compliance posture. This role is responsible for coordinating security activities across the business, supporting compliance initiatives, managing third party risk, and acting as the internal liaison with our outsourced Security Operations Centre (SOC) and Virtual CISO. The successful candidate will help implement security governance, risk management, and compliance frameworks while ensuring security best practices are embedded across the organisation. This role is ideal for someone with experience in security operations, governance, risk, and compliance (GRC) who enjoys working across teams to improve organisational security maturity. Key Responsibilities Security Operations Oversight Act as the primary internal liaison with the outsourced SOC provider Monitor and coordinate responses to alerts generated through Microsoft Sentinel and Microsoft Defender Support incident response coordination and internal communications Track remediation of security vulnerabilities and incidents Governance, Risk & Compliance Support the implementation and maintenance of security frameworks such as: ISO 27001 Cyber Essentials Plus NIST / CIS frameworks Maintain and develop security policies, standards, and procedures Conduct risk assessments and track remediation actions Coordinate internal and external security audits Coordinate with other governance teams to ensure alignment around key initiatives Third Party Risk Management (TPRM) Lead the rollout and ongoing management of a Third Party Risk Management programme Perform vendor security assessments and due diligence Maintain vendor risk registers and track remediation activities Work with procurement and legal teams to embed security requirements into supplier onboarding Security Governance & Awareness Support security awareness and training initiatives across the organisation Work with IT and engineering teams to ensure security best practices are followed Maintain risk registers and compliance documentation Provide reporting and metrics on security posture to leadership Security Projects & Initiatives Support compliance initiatives and security improvement programmes Work with the virtual CISO to implement strategic security improvements Assist with policy development and control implementation Help coordinate vulnerability management and remediation programmes Provide input into client security questionnaires and audits where appropriate About You Skills & Experience 3-5 years experience in information security, IT security, or compliance Understanding of security governance, risk, and compliance (GRC) Experience with Microsoft security tooling (Sentinel, Defender, or Microsoft Security stack) Familiarity with security frameworks (ISO 27001, NIST, CIS, Cyber Essentials) Experience working with third party vendors or supplier risk assessments Strong communication and stakeholder management skills Ability to translate security requirements into practical business processes Desirable Experience working with outsourced SOC providers Knowledge of Third Party Risk Management (TPRM) programmes Experience supporting ISO 27001 certification or audits Certifications such as: ISO 27001 Lead Implementer / Lead Auditor CISSP CISM Security+ Key Competencies Strong organisational and documentation skills Ability to manage multiple compliance initiatives simultaneously Analytical thinking and risk assessment capability Collaborative approach to working across technical and non technical teams Proactive mindset with a focus on continuous improvement What Success Looks Like Establish a structured Third Party Risk Management programme Improve visibility and reporting of security risks Strengthen security governance processes Develop ISO 27001 implementation roadmap and compliance processes to ensure group compliance can evolve to a recognised standard within the next months. Improve collaboration between internal teams, the SOC provider, and the virtual CISO Equal Opportunity We value diverse talent and welcome applications from everyone - regardless of background. We are an equal opportunity employer and our inclusive culture at PEI is reflected in every stage of the recruitment journey. Please inform us at initial stages of the recruitment process if you require any reasonable adjustments and we can accommodate this. PEI supports flexible working arrangements, and we welcome career returners.
Information Security Officer
Aareon AG Manchester, Lancashire
Aareon is Europe's established provider of SaaS solutions for the real estate industry and a pioneer of the sector's digital future.With its software solutions, Aareon connects people, processes, and properties-bringing the industry closer together. With the Aareon Property Management System, based on intelligent software solutions, the company enables the efficient management and maintenance of residential and commercial properties and creates digital experiences for all stakeholders.As a reliable and innovative partner, Aareon is committed to progress, positive change, and sustainable living and working spaces for everyone.We value a working environment in which diversity and flexibility are appreciated, cooperation in partnership and mutual support in the team are a matter of course and learning is perceived as an opportunity.Become part of our international team! Become part of ! We are looking forward to meeting YOU!Salary: £70,000-£80,000 per year (depending on experience)Work Location: Hybrid London or ManchesterHours per week: 37.5Contract Type: Permanent, full-timeAbout the RoleAareon UK builds software that housing providers and property professionals rely on every day. As our product set grows, security and data protection matter more than ever. We're hiring a UK Security Officer to take ownership of security across the UK business.This is a senior role covering security across applications, platforms, infrastructure, and engineering. You'll also act as the UK Information Security Officer, helping protect customer data, maintain compliance, and keep security practical in day-to-day delivery.You'll be the main UK contact for the Group Security Operations Centre in Germany, making sure group direction works in practice for the UK business. You'll own the UK security programme, build on what is already in place, and help bring more consistency across our UK brands.Team & ScopeThis is initially an individual contributor role with strong matrix influence across teams. It works alongside CloudOps, IT, Legal, Compliance and Engineering.What You'll Be Responsible For1. Developing and running the UK security strategySet and deliver a clear UK security strategy that aligns with group direction while working for the UK business. You'll turn group guidance into practical local plans, set priorities, and help leadership make sensible investment decisions. A key part of the role is bringing more consistency across our UK brands. You'll also help shape and manage the UK security budget, making sure investment is focused on the right risks, controls, and priorities.2. Governance, risk and complianceOwn and improve our UK security governance. That includes the ISMS, policies, risk management, and the controls needed to meet our obligations. You'll make sure we stay on top of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and any relevant customer or sector requirements. You'll also support audits, due diligence, customer assurance activity, and third-party risk management, helping coordinate evidence, maintain assurance readiness, and improve how we manage security obligations across the UK business.3. Security operations, vulnerability management and incident supportHelp oversee day-to-day security operations for the UK, working closely with CloudOps and the Group SOC. You'll support and coordinate security incidents when they happen, making sure the right people are involved and that follow-up actions are properly seen through. You won't always lead incidents, but you will provide clear security ownership. You'll also own penetration testing and vulnerability management, helping teams make sensible, risk-based decisions about remediation, sequencing, and technical debt.4. Security in engineering and platform deliveryWork with engineering, architecture, product, platform, and DevOps teams to make sure security is built into how we design, build, and run systems. This includes secure coding, design reviews, threat modelling, DevSecOps practices, and cloud security. The role is about working with existing technical experts to make good, pragmatic, well-informed security decisions.5. Policy, awareness and cross-functional workingKeep our security and quality policies and standards up to date, practical, and usable. Support security awareness through clear guidance, communication, and training where needed, while aligning with group-led activity where that is handled centrally. You'll work across engineering, product, IT, data, legal, compliance, HR and operations to keep security visible and joined up across the business.6. Resilience, disaster recovery and business continuityWork with technical and business teams to strengthen disaster recovery strategy and business continuity planning across the UK estate. You'll help make sure recovery expectations are clear, plans are practical, risks are understood, and resilience is tested in a proportionate way.7. Customer assurance and commercial security supportSupport customer and commercial security activity where needed, including security questionnaires, due diligence responses, and clear explanations of our controls and approach. You'll help sales, account teams, and leadership respond consistently and credibly to customer security queries without turning the role into a pure compliance function.8. Reporting and Group alignmentTrack useful security measures and report clearly to UK leadership and the Group CISO/SOC. You'll use metrics and dashboards to show risk, progress, and where attention is needed. You'll also act as the main UK link into the Group SOC.9. AI securityHelp the business stay on top of AI-related security risks, including staff use of AI tools, AI in products, agentic workflows, and the changing risks that come with new models and external tooling.About YouYou are an experienced security leader who combines sound judgement with practical delivery. You can work comfortably with senior stakeholders, but you're also happy getting into the detail when needed. You know how to explain security clearly, make risk visible, and help teams take sensible action. You're collaborative, pragmatic, and credible. You know when to push, when to guide, and how to work through trade-offs without losing sight of the bigger picture. You're comfortable operating across a complex organisation and working with different teams, brands, and levels of technical maturity.You will be a great fit if you:can work well with both technical teams and senior business stakeholdersare practical and delivery-minded, not theoreticalare comfortable owning security outcomes while working through otherscan influence without creating unnecessary frictioncare about building a strong security culture, not just implementing controlsstay current on emerging technology and risk, including AISkills & ExperienceEssentialStrong experience in a senior cyber or information security role in a technology-led businessA solid grasp of security governance, risk management, and control frameworksGood working knowledge of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and similar standardsBroad technical understanding across cloud, infrastructure, application security, and secure deliveryExperience of incident response, vulnerability management, and penetration testing follow-upAbility to communicate clearly with both technical and non-technical audiencesComfortable setting priorities, balancing risk, and working in a fast-moving environmentDesirableRelevant certifications such as CISSP, CISM, or CISAExperience in SaaS, proptech, housing, or another data-sensitive software environmentExperience working with group functions, auditors, regulators, or external security partnersExperience working across multiple brands, business units, or countriesFamiliarity with AI security issues across internal use, product use, and evolving external toolingÜber unsWerde Teil von Aareon und digitalisiere gemeinsam mit uns die europäische Immobilienwirtschaft.Warum wir?Wir legen Wert auf eine Arbeitsumgebung, in der Vielfalt und Flexibilität geschätzt werden, partnerschaftliche Zusammenarbeit und gegenseitige Unterstützung im Team selbstverständlich sind und Lernen als Chance wahrgenommen wird. Unsere Lösungen adressieren die großen Herausforderungen unserer Zeit: Klimawandel, Wohnungsknappheit und Fachkräftemangel. Entdecke die Vielfalt von !Kontakt aufnehmenWar noch nicht das Richtige dabei? Dann sende hier eine Initiativbewerbung an unser Recruiting Team!Start
16/06/2026
Full time
Aareon is Europe's established provider of SaaS solutions for the real estate industry and a pioneer of the sector's digital future.With its software solutions, Aareon connects people, processes, and properties-bringing the industry closer together. With the Aareon Property Management System, based on intelligent software solutions, the company enables the efficient management and maintenance of residential and commercial properties and creates digital experiences for all stakeholders.As a reliable and innovative partner, Aareon is committed to progress, positive change, and sustainable living and working spaces for everyone.We value a working environment in which diversity and flexibility are appreciated, cooperation in partnership and mutual support in the team are a matter of course and learning is perceived as an opportunity.Become part of our international team! Become part of ! We are looking forward to meeting YOU!Salary: £70,000-£80,000 per year (depending on experience)Work Location: Hybrid London or ManchesterHours per week: 37.5Contract Type: Permanent, full-timeAbout the RoleAareon UK builds software that housing providers and property professionals rely on every day. As our product set grows, security and data protection matter more than ever. We're hiring a UK Security Officer to take ownership of security across the UK business.This is a senior role covering security across applications, platforms, infrastructure, and engineering. You'll also act as the UK Information Security Officer, helping protect customer data, maintain compliance, and keep security practical in day-to-day delivery.You'll be the main UK contact for the Group Security Operations Centre in Germany, making sure group direction works in practice for the UK business. You'll own the UK security programme, build on what is already in place, and help bring more consistency across our UK brands.Team & ScopeThis is initially an individual contributor role with strong matrix influence across teams. It works alongside CloudOps, IT, Legal, Compliance and Engineering.What You'll Be Responsible For1. Developing and running the UK security strategySet and deliver a clear UK security strategy that aligns with group direction while working for the UK business. You'll turn group guidance into practical local plans, set priorities, and help leadership make sensible investment decisions. A key part of the role is bringing more consistency across our UK brands. You'll also help shape and manage the UK security budget, making sure investment is focused on the right risks, controls, and priorities.2. Governance, risk and complianceOwn and improve our UK security governance. That includes the ISMS, policies, risk management, and the controls needed to meet our obligations. You'll make sure we stay on top of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and any relevant customer or sector requirements. You'll also support audits, due diligence, customer assurance activity, and third-party risk management, helping coordinate evidence, maintain assurance readiness, and improve how we manage security obligations across the UK business.3. Security operations, vulnerability management and incident supportHelp oversee day-to-day security operations for the UK, working closely with CloudOps and the Group SOC. You'll support and coordinate security incidents when they happen, making sure the right people are involved and that follow-up actions are properly seen through. You won't always lead incidents, but you will provide clear security ownership. You'll also own penetration testing and vulnerability management, helping teams make sensible, risk-based decisions about remediation, sequencing, and technical debt.4. Security in engineering and platform deliveryWork with engineering, architecture, product, platform, and DevOps teams to make sure security is built into how we design, build, and run systems. This includes secure coding, design reviews, threat modelling, DevSecOps practices, and cloud security. The role is about working with existing technical experts to make good, pragmatic, well-informed security decisions.5. Policy, awareness and cross-functional workingKeep our security and quality policies and standards up to date, practical, and usable. Support security awareness through clear guidance, communication, and training where needed, while aligning with group-led activity where that is handled centrally. You'll work across engineering, product, IT, data, legal, compliance, HR and operations to keep security visible and joined up across the business.6. Resilience, disaster recovery and business continuityWork with technical and business teams to strengthen disaster recovery strategy and business continuity planning across the UK estate. You'll help make sure recovery expectations are clear, plans are practical, risks are understood, and resilience is tested in a proportionate way.7. Customer assurance and commercial security supportSupport customer and commercial security activity where needed, including security questionnaires, due diligence responses, and clear explanations of our controls and approach. You'll help sales, account teams, and leadership respond consistently and credibly to customer security queries without turning the role into a pure compliance function.8. Reporting and Group alignmentTrack useful security measures and report clearly to UK leadership and the Group CISO/SOC. You'll use metrics and dashboards to show risk, progress, and where attention is needed. You'll also act as the main UK link into the Group SOC.9. AI securityHelp the business stay on top of AI-related security risks, including staff use of AI tools, AI in products, agentic workflows, and the changing risks that come with new models and external tooling.About YouYou are an experienced security leader who combines sound judgement with practical delivery. You can work comfortably with senior stakeholders, but you're also happy getting into the detail when needed. You know how to explain security clearly, make risk visible, and help teams take sensible action. You're collaborative, pragmatic, and credible. You know when to push, when to guide, and how to work through trade-offs without losing sight of the bigger picture. You're comfortable operating across a complex organisation and working with different teams, brands, and levels of technical maturity.You will be a great fit if you:can work well with both technical teams and senior business stakeholdersare practical and delivery-minded, not theoreticalare comfortable owning security outcomes while working through otherscan influence without creating unnecessary frictioncare about building a strong security culture, not just implementing controlsstay current on emerging technology and risk, including AISkills & ExperienceEssentialStrong experience in a senior cyber or information security role in a technology-led businessA solid grasp of security governance, risk management, and control frameworksGood working knowledge of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and similar standardsBroad technical understanding across cloud, infrastructure, application security, and secure deliveryExperience of incident response, vulnerability management, and penetration testing follow-upAbility to communicate clearly with both technical and non-technical audiencesComfortable setting priorities, balancing risk, and working in a fast-moving environmentDesirableRelevant certifications such as CISSP, CISM, or CISAExperience in SaaS, proptech, housing, or another data-sensitive software environmentExperience working with group functions, auditors, regulators, or external security partnersExperience working across multiple brands, business units, or countriesFamiliarity with AI security issues across internal use, product use, and evolving external toolingÜber unsWerde Teil von Aareon und digitalisiere gemeinsam mit uns die europäische Immobilienwirtschaft.Warum wir?Wir legen Wert auf eine Arbeitsumgebung, in der Vielfalt und Flexibilität geschätzt werden, partnerschaftliche Zusammenarbeit und gegenseitige Unterstützung im Team selbstverständlich sind und Lernen als Chance wahrgenommen wird. Unsere Lösungen adressieren die großen Herausforderungen unserer Zeit: Klimawandel, Wohnungsknappheit und Fachkräftemangel. Entdecke die Vielfalt von !Kontakt aufnehmenWar noch nicht das Richtige dabei? Dann sende hier eine Initiativbewerbung an unser Recruiting Team!Start
Quality Manager Liverpool University Hospitals NHS Foundation Trust
Career Choices Dewis Gyrfa Ltd
Quality Manager Liverpool University Hospitals NHS Foundation Trust Employer: Liverpool University Hospitals NHS Foundation Trust Location: Liverpool, L14 3LB Pay: Contract Type: Permanent Hours: Full time Disability Confident: No Closing Date: 23/04/2026 About this job Liverpool University Hospitals NHS Foundation Trust Sterile Services Department. are recruiting an experienced, dynamic and self-motivated Quality Manager to implement and manage the Quality management system ISO13485 for the decontamination and reprocessing of Surgical Instruments from its Central Sterile Services department located at the Broadgreen Hospital site. Working under the management of the Sterile Services Manager and in conjunction with the Surgical Instrument Manager, you will be involved in all aspects of managing and maintaining our ISO13485 accreditation to our customers at Broadgreen Hospital, Royal Liverpool and Aintree Hospital sites along with the University Dental Hospital. You must have previous knowledge and experience in surgical instrument reprocessing at a supervisory role or above in a Sterile services Department or similar medical devices manufacturing environment operating to ISO13485 including undertaking internal quality audits and experience with external notified body visits. Your number one priority is ensuring that the quality system of the department is rigorously maintained. To monitor and review, implement and procedures and other work instructions, for the receipt, sort, disassemble, decontamination, packing, sterilisation, storage and despatch of surgical instruments in compliance with ISO 13485 and the Medical Devices Regulations (MDR) 2017-745 Communicate and implement revisions in working procedures with SSD staff and monitor staff production against the implemented QMS procedures and through an established internal quality audit programme. Attend external notified body audits in conjunction with the SSD manger. Provide notified body auditors with QMS driven documentation and validation reports on request. There is also a requirement to attend unannounced notified body visits as they occur. Liverpool University Hospitals NHS Foundation Trust comprises Aintree University Hospital, Broadgreen Hospital & Royal Liverpool University Hospital. We are part of NHS University Hospitals of Liverpool Group, formed on 1 Nov 2024 from the coming together of LUHFT and Liverpool Women's NHS Foundation Trust. The Group was born from a shared aim to improve the care we provide our patients. UHLG is one of the largest employers in the region, with over 16,800 colleagues dedicated to caring for our communities from birth and beyond. For the 630,000 people across Merseyside, we are their local NHS. We provide general and emergency hospital care, alongside highly specialised regional services for more than two million people in the North West. Aintree University Hospitalis the single receiving site for adult major trauma patients in Cheshire and Merseyside and hosts a number of regional services including an award-winning stroke facility.Broadgreen Hospitalis home to elective surgical, diagnostic and treatment services, together with specialist patient rehabilitation.Liverpool Women's Hospitalspecialises in the health of women and babies, delivering over 7,200 babies in the UK's largest single site maternity hospital each year. TheRoyal Liverpool University Hospitalis the largest hospital in the country to provide inpatients with 100% single bedrooms and focuses on complex planned care and specialist services. For roles at Liverpool Women's, visit theircareers page. To monitor and review, implement and procedures and other work instructions, for the receipt, sort, disassemble, decontamination, packing, sterilisation, storage and despatch of surgical instruments in compliance with ISO 13485 and the Medical Devices Regulations (MDR) 2017-745 Communicate and implement revisions in working procedures with SSD staff and monitor staff production against the implemented QMS procedures and through an established internal quality audit programme. Monitor cleaning schedules and the cleanroom environment. Equipment validation and testing schedules to ensure ongoing compliance. In conjunction with the SSD manager, undertake quarterly customer satisfaction survey for all customers and provide feedback and data analysis to rectify any issues and to ensue all customer expectations and agreed KPI are met. Following internal audits, and any change in the procedures, meet with all SSD staff to go though and manage changes and training required. Conduct ad-hoc "toolbox" talks providing leadership and feedback following in incident led changes. Attend QMS related, Decontamination, Customer, SSD Staff and Team Leader meetings providing feedback and support following activities or audits and support a culture of change within SSD and SSD users. Attend external notified body audits in conjunction with the SSD manger. Provide notified body auditors with QMS driven documentation and validation reports on request. There is also a requirement to attend unannounced notified body visits as they occur. Previously knowledge and daily use of IT based Instrument Tracking and Traceability operating systems would be a significant advantage. The Department operates the Healthedge system across all sites. Demonstrate a comprehensive understanding of Health Technical Memorandum HTM 01-01 and other relevant standards pertaining to Sterile Service Departments Effective communication, responding to telephone calls or emails from service users on a range of different instrument and production queries, and providing investigation and feedback following complaints requiring further monitoring and feedback. Attend Quarterly Trust Decontamination Assurance Group meetings. Adhere to all Trust and departmental quality standards. Act professionally and with dignity and as an inspirational role model to staff at all times. Due to working across multiple sites, a driving licence and access to a vehicle would be an advantage. However, hospital inter site transport services are available free to all staff. To work flexibility over 37.5 hours per week and at different hours as required to undertake audits and attend meetings across all shift patterns. Take responsibility for your own learning needs and professional conduct. Take on board training deemed necessary to attain/maintain competency including trust mandatory training. This advert closes on Tuesday 7 Apr 2026 Jobs are provided by the Find a Job Service from the Department for Work and Pensions (DWP).
16/06/2026
Full time
Quality Manager Liverpool University Hospitals NHS Foundation Trust Employer: Liverpool University Hospitals NHS Foundation Trust Location: Liverpool, L14 3LB Pay: Contract Type: Permanent Hours: Full time Disability Confident: No Closing Date: 23/04/2026 About this job Liverpool University Hospitals NHS Foundation Trust Sterile Services Department. are recruiting an experienced, dynamic and self-motivated Quality Manager to implement and manage the Quality management system ISO13485 for the decontamination and reprocessing of Surgical Instruments from its Central Sterile Services department located at the Broadgreen Hospital site. Working under the management of the Sterile Services Manager and in conjunction with the Surgical Instrument Manager, you will be involved in all aspects of managing and maintaining our ISO13485 accreditation to our customers at Broadgreen Hospital, Royal Liverpool and Aintree Hospital sites along with the University Dental Hospital. You must have previous knowledge and experience in surgical instrument reprocessing at a supervisory role or above in a Sterile services Department or similar medical devices manufacturing environment operating to ISO13485 including undertaking internal quality audits and experience with external notified body visits. Your number one priority is ensuring that the quality system of the department is rigorously maintained. To monitor and review, implement and procedures and other work instructions, for the receipt, sort, disassemble, decontamination, packing, sterilisation, storage and despatch of surgical instruments in compliance with ISO 13485 and the Medical Devices Regulations (MDR) 2017-745 Communicate and implement revisions in working procedures with SSD staff and monitor staff production against the implemented QMS procedures and through an established internal quality audit programme. Attend external notified body audits in conjunction with the SSD manger. Provide notified body auditors with QMS driven documentation and validation reports on request. There is also a requirement to attend unannounced notified body visits as they occur. Liverpool University Hospitals NHS Foundation Trust comprises Aintree University Hospital, Broadgreen Hospital & Royal Liverpool University Hospital. We are part of NHS University Hospitals of Liverpool Group, formed on 1 Nov 2024 from the coming together of LUHFT and Liverpool Women's NHS Foundation Trust. The Group was born from a shared aim to improve the care we provide our patients. UHLG is one of the largest employers in the region, with over 16,800 colleagues dedicated to caring for our communities from birth and beyond. For the 630,000 people across Merseyside, we are their local NHS. We provide general and emergency hospital care, alongside highly specialised regional services for more than two million people in the North West. Aintree University Hospitalis the single receiving site for adult major trauma patients in Cheshire and Merseyside and hosts a number of regional services including an award-winning stroke facility.Broadgreen Hospitalis home to elective surgical, diagnostic and treatment services, together with specialist patient rehabilitation.Liverpool Women's Hospitalspecialises in the health of women and babies, delivering over 7,200 babies in the UK's largest single site maternity hospital each year. TheRoyal Liverpool University Hospitalis the largest hospital in the country to provide inpatients with 100% single bedrooms and focuses on complex planned care and specialist services. For roles at Liverpool Women's, visit theircareers page. To monitor and review, implement and procedures and other work instructions, for the receipt, sort, disassemble, decontamination, packing, sterilisation, storage and despatch of surgical instruments in compliance with ISO 13485 and the Medical Devices Regulations (MDR) 2017-745 Communicate and implement revisions in working procedures with SSD staff and monitor staff production against the implemented QMS procedures and through an established internal quality audit programme. Monitor cleaning schedules and the cleanroom environment. Equipment validation and testing schedules to ensure ongoing compliance. In conjunction with the SSD manager, undertake quarterly customer satisfaction survey for all customers and provide feedback and data analysis to rectify any issues and to ensue all customer expectations and agreed KPI are met. Following internal audits, and any change in the procedures, meet with all SSD staff to go though and manage changes and training required. Conduct ad-hoc "toolbox" talks providing leadership and feedback following in incident led changes. Attend QMS related, Decontamination, Customer, SSD Staff and Team Leader meetings providing feedback and support following activities or audits and support a culture of change within SSD and SSD users. Attend external notified body audits in conjunction with the SSD manger. Provide notified body auditors with QMS driven documentation and validation reports on request. There is also a requirement to attend unannounced notified body visits as they occur. Previously knowledge and daily use of IT based Instrument Tracking and Traceability operating systems would be a significant advantage. The Department operates the Healthedge system across all sites. Demonstrate a comprehensive understanding of Health Technical Memorandum HTM 01-01 and other relevant standards pertaining to Sterile Service Departments Effective communication, responding to telephone calls or emails from service users on a range of different instrument and production queries, and providing investigation and feedback following complaints requiring further monitoring and feedback. Attend Quarterly Trust Decontamination Assurance Group meetings. Adhere to all Trust and departmental quality standards. Act professionally and with dignity and as an inspirational role model to staff at all times. Due to working across multiple sites, a driving licence and access to a vehicle would be an advantage. However, hospital inter site transport services are available free to all staff. To work flexibility over 37.5 hours per week and at different hours as required to undertake audits and attend meetings across all shift patterns. Take responsibility for your own learning needs and professional conduct. Take on board training deemed necessary to attain/maintain competency including trust mandatory training. This advert closes on Tuesday 7 Apr 2026 Jobs are provided by the Find a Job Service from the Department for Work and Pensions (DWP).
Information Security Officer
Aareon UK
Aareon is Europe's established provider of SaaS solutions for the real estate industry. With its software solutions Aareon connects people, processes, and properties, enabling efficient management of residential and commercial properties and creating digital experiences for all stakeholders. Salary: £70,000 £80,000 per year (depending on experience) Work Location: Hybrid London or Manchester Hours per week: 37.5 Contract Type: Permanent, full time About the Role As Aareon UK's Product division continues to grow, security and data protection grow in importance. The UK Security Officer will own security across the UK business, acting as the UK Information Security Officer, protecting customer data, maintaining compliance and keeping security practical in day to day delivery. The role is a senior, individual contributor position with strong matrix influence across CloudOps, IT, Legal, Compliance and Engineering. Team & Scope This role will collaborate closely with CloudOps, IT, Legal, Compliance and Engineering to align security strategy with group direction and UK business needs. What You'll Be Responsible For Develop and run the UK security strategy, turning group guidance into local plans, setting priorities and shaping the UK security budget. Own and improve UK security governance, maintaining ISO 27001, ISO 9001, Cyber Essentials, GDPR and other relevant requirements, and supporting audits and third party risk management. Oversee day to day security operations, coordinate incidents with CloudOps and the Group SOC, and own penetration testing and vulnerability management. Ensure security is built into engineering and platform delivery through secure coding, design reviews, threat modelling, DevSecOps practices and cloud security. Maintain and update security and quality policies, support awareness programmes, and keep security visible across engineering, product, IT, data, legal, compliance, HR and operations. Drive resilience and business continuity, strengthening disaster recovery strategy and ensuring practical plans and testing. Support customer and commercial security activities, including questionnaires, due diligence responses and providing clear explanations of controls. Track security metrics, report to UK leadership and the Group CISO/SOC, and act as the main UK link to the Group SOC. Lead AI related security, monitoring risks from staff use of AI tools, AI in products, agentic workflows and evolving external tooling. About You You are an experienced security leader who combines sound judgement with practical delivery. You are comfortable working with senior stakeholders and detailed tasks alike, can clearly explain security, make risk visible, and help teams take sensible action. You are collaborative, pragmatic, credible, and able to influence across a complex organisation with varying brands and technical maturity. Skills & Experience Essential Strong experience in a senior cyber or information security role in a technology led business. Solid grasp of security governance, risk management and control frameworks. Good working knowledge of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and similar standards. Broad technical understanding across cloud, infrastructure, application security and secure delivery. Experience in incident response, vulnerability management and penetration testing follow up. Excellent communication skills with both technical and non technical audiences. Ability to set priorities, balance risk and work in a fast moving environment. Desirable Relevant certifications such as CISSP, CISM or CISA. Experience in SaaS, proptech, housing or another data sensitive software environment. Experience working with group functions, auditors, regulators or external security partners. Experience across multiple brands, business units or countries. Familiarity with AI security issues across internal use, product use and evolving external tooling. Become part of Aareon and digitise the European property industry together with us. We value diversity, flexibility, partnership and learning opportunities.
16/06/2026
Full time
Aareon is Europe's established provider of SaaS solutions for the real estate industry. With its software solutions Aareon connects people, processes, and properties, enabling efficient management of residential and commercial properties and creating digital experiences for all stakeholders. Salary: £70,000 £80,000 per year (depending on experience) Work Location: Hybrid London or Manchester Hours per week: 37.5 Contract Type: Permanent, full time About the Role As Aareon UK's Product division continues to grow, security and data protection grow in importance. The UK Security Officer will own security across the UK business, acting as the UK Information Security Officer, protecting customer data, maintaining compliance and keeping security practical in day to day delivery. The role is a senior, individual contributor position with strong matrix influence across CloudOps, IT, Legal, Compliance and Engineering. Team & Scope This role will collaborate closely with CloudOps, IT, Legal, Compliance and Engineering to align security strategy with group direction and UK business needs. What You'll Be Responsible For Develop and run the UK security strategy, turning group guidance into local plans, setting priorities and shaping the UK security budget. Own and improve UK security governance, maintaining ISO 27001, ISO 9001, Cyber Essentials, GDPR and other relevant requirements, and supporting audits and third party risk management. Oversee day to day security operations, coordinate incidents with CloudOps and the Group SOC, and own penetration testing and vulnerability management. Ensure security is built into engineering and platform delivery through secure coding, design reviews, threat modelling, DevSecOps practices and cloud security. Maintain and update security and quality policies, support awareness programmes, and keep security visible across engineering, product, IT, data, legal, compliance, HR and operations. Drive resilience and business continuity, strengthening disaster recovery strategy and ensuring practical plans and testing. Support customer and commercial security activities, including questionnaires, due diligence responses and providing clear explanations of controls. Track security metrics, report to UK leadership and the Group CISO/SOC, and act as the main UK link to the Group SOC. Lead AI related security, monitoring risks from staff use of AI tools, AI in products, agentic workflows and evolving external tooling. About You You are an experienced security leader who combines sound judgement with practical delivery. You are comfortable working with senior stakeholders and detailed tasks alike, can clearly explain security, make risk visible, and help teams take sensible action. You are collaborative, pragmatic, credible, and able to influence across a complex organisation with varying brands and technical maturity. Skills & Experience Essential Strong experience in a senior cyber or information security role in a technology led business. Solid grasp of security governance, risk management and control frameworks. Good working knowledge of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and similar standards. Broad technical understanding across cloud, infrastructure, application security and secure delivery. Experience in incident response, vulnerability management and penetration testing follow up. Excellent communication skills with both technical and non technical audiences. Ability to set priorities, balance risk and work in a fast moving environment. Desirable Relevant certifications such as CISSP, CISM or CISA. Experience in SaaS, proptech, housing or another data sensitive software environment. Experience working with group functions, auditors, regulators or external security partners. Experience across multiple brands, business units or countries. Familiarity with AI security issues across internal use, product use and evolving external tooling. Become part of Aareon and digitise the European property industry together with us. We value diversity, flexibility, partnership and learning opportunities.
Operational Resilience Manager
Benefact Group plc Bradley Stoke, Gloucestershire
Working hours: 35 hours per week, Monday to Friday Duration: Permanent Location: Gloucester Job Ref: 204987 About the role Benefact Group are looking for a Operational Resilience Manager to join our Gloucester office. To lead the ongoing evolution, optimisation and practical application of the company's Operational Resilience framework. This role ensures the organisation is prepared to prevent, respond to, recover and learn from disruptive incidents, in compliance with regulatory requirements and alignment with industry best practices. This includes aligning to the spirit and direction of FCA/PRA expectations across a multi-entity group. Why join us? Join a collaborative and inclusive culture that's committed to making a difference and building a more sustainable future. Ranked amongst the UK's 15 Best Big Companies to Work For in 2025, we offer fantastic career and development opportunities within a rapidly growing, innovative Group - where all profits go to charity and good causes. What you'll be doing Lead the ongoing evolution of the Operational Resilience framework, ensuring alignment with regulatory standards, horizon scanning and organisational strategy. Own and run the annual Operational Resilience cycle ensuring outputs are robust, evidenced and ready for Board, Audit and Regulatory scrutiny, including the review and documentation of Important Business Services, Impact Tolerances and end to end service mapping and analysis. Design and deliver advanced resilience testing programmes; including severe but plausible scenario tests, and crisis simulations to assess and strengthen resilience capabilities. Ensure that exercises are challenging, well documented and drive change. Coordinate incident response and post incident reviews, providing clear insights and ensuring lessons learned translate into measurable improvements. Build strong relationships with service owners and enhance capability and organisation wide resilience awareness through training, guidance and expert support. Provide constructive challenge and expert guidance to stakeholders across the organisation. What you'll need to have Proven experience in leading Operational Resilience functions within general insurance or financial services (Business Continuity & Crisis Management desirable). Deep understanding of Operational Resilience principles and methodologies Familiarity with IT resilience concepts including cyber security, data protection and technology recovery Experience of crisis management and incident response during disruption events Experience in/ capable of working and communicating with colleagues at all levels, including Senior Management, using knowledge, experience and credibility to influence and lead change Strong analytical and project management capabilities Degree in Risk Management, Business, IT, or related field Professional certifications such as CBCI, MBCI, ISO 22301 Lead Implementer or Auditor. Ability to travel occasionally & willingness to participate in out of hours crisis response as required What makes you stand out Strong knowledge of UK regulatory requirements (FCA, PRA, Solvency II) Experience working with third party risk and supply chain resilience Insurance qualifications What we offer A competitive salary - let's discuss it Hybrid working Group Personal Pension - up to 12% employer contribution Generous annual bonus scheme: on target bonus between 7.5% and 30% 28 days annual leave plus bank holidays, and a holiday buy and sell scheme An array of health and wellbeing benefits, including private healthcare, income protection and life assurance £200 annual personal grant to a charity of your choice Encouraged to take at least one volunteering day per year Employee Assistance Programme Full study support to gain professional qualifications Access to virtual GP Enhanced maternity and paternity pay Hear from the hiring manager "This is a key opportunity to lead and continuously enhance the organisation's Operational Resilience framework, ensuring we can withstand, respond to and recover from disruption while meeting evolving regulatory expectations. You'll play a central role in strengthening resilience capabilities across the business, shaping strategy, influencing senior leaders to develop a more robust and resilient organisation." About us Benefact Group is a unique international financial services Group made up of over 30 businesses. We are owned by a charity and have been the 3rd largest UK corporate donor over a decade , having given away £250 million since 2014. We have ambitious plans to become the UK's number one corporate donor, with strategic objectives in place to double the Group's size. We believe it's essential to attract, empower, grow and reward talented people, offering fantastic opportunities for career and personal development. Our giving ethos, 135-year history and the diversity of what we do, has enabled us to build a culture of kindness, great ambition, and of passionate people driven to do better and be better. At Benefact Group, we are committed to creating an inclusive culture and building an environment where each and every one of us feels valued and respected. We are a community made up of people with a range of different backgrounds, abilities, perspectives, beliefs and interests and we value the strength this brings to us as a Group. We welcome applications from everyone. If you need any additional support during the recruitment process, then please let us know. Directory of Social Change's UK Guides to Company Giving 2017-26
16/06/2026
Full time
Working hours: 35 hours per week, Monday to Friday Duration: Permanent Location: Gloucester Job Ref: 204987 About the role Benefact Group are looking for a Operational Resilience Manager to join our Gloucester office. To lead the ongoing evolution, optimisation and practical application of the company's Operational Resilience framework. This role ensures the organisation is prepared to prevent, respond to, recover and learn from disruptive incidents, in compliance with regulatory requirements and alignment with industry best practices. This includes aligning to the spirit and direction of FCA/PRA expectations across a multi-entity group. Why join us? Join a collaborative and inclusive culture that's committed to making a difference and building a more sustainable future. Ranked amongst the UK's 15 Best Big Companies to Work For in 2025, we offer fantastic career and development opportunities within a rapidly growing, innovative Group - where all profits go to charity and good causes. What you'll be doing Lead the ongoing evolution of the Operational Resilience framework, ensuring alignment with regulatory standards, horizon scanning and organisational strategy. Own and run the annual Operational Resilience cycle ensuring outputs are robust, evidenced and ready for Board, Audit and Regulatory scrutiny, including the review and documentation of Important Business Services, Impact Tolerances and end to end service mapping and analysis. Design and deliver advanced resilience testing programmes; including severe but plausible scenario tests, and crisis simulations to assess and strengthen resilience capabilities. Ensure that exercises are challenging, well documented and drive change. Coordinate incident response and post incident reviews, providing clear insights and ensuring lessons learned translate into measurable improvements. Build strong relationships with service owners and enhance capability and organisation wide resilience awareness through training, guidance and expert support. Provide constructive challenge and expert guidance to stakeholders across the organisation. What you'll need to have Proven experience in leading Operational Resilience functions within general insurance or financial services (Business Continuity & Crisis Management desirable). Deep understanding of Operational Resilience principles and methodologies Familiarity with IT resilience concepts including cyber security, data protection and technology recovery Experience of crisis management and incident response during disruption events Experience in/ capable of working and communicating with colleagues at all levels, including Senior Management, using knowledge, experience and credibility to influence and lead change Strong analytical and project management capabilities Degree in Risk Management, Business, IT, or related field Professional certifications such as CBCI, MBCI, ISO 22301 Lead Implementer or Auditor. Ability to travel occasionally & willingness to participate in out of hours crisis response as required What makes you stand out Strong knowledge of UK regulatory requirements (FCA, PRA, Solvency II) Experience working with third party risk and supply chain resilience Insurance qualifications What we offer A competitive salary - let's discuss it Hybrid working Group Personal Pension - up to 12% employer contribution Generous annual bonus scheme: on target bonus between 7.5% and 30% 28 days annual leave plus bank holidays, and a holiday buy and sell scheme An array of health and wellbeing benefits, including private healthcare, income protection and life assurance £200 annual personal grant to a charity of your choice Encouraged to take at least one volunteering day per year Employee Assistance Programme Full study support to gain professional qualifications Access to virtual GP Enhanced maternity and paternity pay Hear from the hiring manager "This is a key opportunity to lead and continuously enhance the organisation's Operational Resilience framework, ensuring we can withstand, respond to and recover from disruption while meeting evolving regulatory expectations. You'll play a central role in strengthening resilience capabilities across the business, shaping strategy, influencing senior leaders to develop a more robust and resilient organisation." About us Benefact Group is a unique international financial services Group made up of over 30 businesses. We are owned by a charity and have been the 3rd largest UK corporate donor over a decade , having given away £250 million since 2014. We have ambitious plans to become the UK's number one corporate donor, with strategic objectives in place to double the Group's size. We believe it's essential to attract, empower, grow and reward talented people, offering fantastic opportunities for career and personal development. Our giving ethos, 135-year history and the diversity of what we do, has enabled us to build a culture of kindness, great ambition, and of passionate people driven to do better and be better. At Benefact Group, we are committed to creating an inclusive culture and building an environment where each and every one of us feels valued and respected. We are a community made up of people with a range of different backgrounds, abilities, perspectives, beliefs and interests and we value the strength this brings to us as a Group. We welcome applications from everyone. If you need any additional support during the recruitment process, then please let us know. Directory of Social Change's UK Guides to Company Giving 2017-26
Information Security Officer
Aareon AG
Aareon is Europe's established provider of SaaS solutions for the real estate industry and a pioneer of the sector's digital future.With its software solutions, Aareon connects people, processes, and properties-bringing the industry closer together. With the Aareon Property Management System, based on intelligent software solutions, the company enables the efficient management and maintenance of residential and commercial properties and creates digital experiences for all stakeholders.As a reliable and innovative partner, Aareon is committed to progress, positive change, and sustainable living and working spaces for everyone.We value a working environment in which diversity and flexibility are appreciated, cooperation in partnership and mutual support in the team are a matter of course and learning is perceived as an opportunity.Become part of our international team! Become part of ! We are looking forward to meeting YOU!Salary: £70,000-£80,000 per year (depending on experience)Work Location: Hybrid London or ManchesterHours per week: 37.5Contract Type: Permanent, full-timeAbout the RoleAareon UK builds software that housing providers and property professionals rely on every day. As our product set grows, security and data protection matter more than ever. We're hiring a UK Security Officer to take ownership of security across the UK business.This is a senior role covering security across applications, platforms, infrastructure, and engineering. You'll also act as the UK Information Security Officer, helping protect customer data, maintain compliance, and keep security practical in day-to-day delivery.You'll be the main UK contact for the Group Security Operations Centre in Germany, making sure group direction works in practice for the UK business. You'll own the UK security programme, build on what is already in place, and help bring more consistency across our UK brands.Team & ScopeThis is initially an individual contributor role with strong matrix influence across teams. It works alongside CloudOps, IT, Legal, Compliance and Engineering.What You'll Be Responsible For1. Developing and running the UK security strategySet and deliver a clear UK security strategy that aligns with group direction while working for the UK business. You'll turn group guidance into practical local plans, set priorities, and help leadership make sensible investment decisions. A key part of the role is bringing more consistency across our UK brands. You'll also help shape and manage the UK security budget, making sure investment is focused on the right risks, controls, and priorities.2. Governance, risk and complianceOwn and improve our UK security governance. That includes the ISMS, policies, risk management, and the controls needed to meet our obligations. You'll make sure we stay on top of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and any relevant customer or sector requirements. You'll also support audits, due diligence, customer assurance activity, and third-party risk management, helping coordinate evidence, maintain assurance readiness, and improve how we manage security obligations across the UK business.3. Security operations, vulnerability management and incident supportHelp oversee day-to-day security operations for the UK, working closely with CloudOps and the Group SOC. You'll support and coordinate security incidents when they happen, making sure the right people are involved and that follow-up actions are properly seen through. You won't always lead incidents, but you will provide clear security ownership. You'll also own penetration testing and vulnerability management, helping teams make sensible, risk-based decisions about remediation, sequencing, and technical debt.4. Security in engineering and platform deliveryWork with engineering, architecture, product, platform, and DevOps teams to make sure security is built into how we design, build, and run systems. This includes secure coding, design reviews, threat modelling, DevSecOps practices, and cloud security. The role is about working with existing technical experts to make good, pragmatic, well-informed security decisions.5. Policy, awareness and cross-functional workingKeep our security and quality policies and standards up to date, practical, and usable. Support security awareness through clear guidance, communication, and training where needed, while aligning with group-led activity where that is handled centrally. You'll work across engineering, product, IT, data, legal, compliance, HR and operations to keep security visible and joined up across the business.6. Resilience, disaster recovery and business continuityWork with technical and business teams to strengthen disaster recovery strategy and business continuity planning across the UK estate. You'll help make sure recovery expectations are clear, plans are practical, risks are understood, and resilience is tested in a proportionate way.7. Customer assurance and commercial security supportSupport customer and commercial security activity where needed, including security questionnaires, due diligence responses, and clear explanations of our controls and approach. You'll help sales, account teams, and leadership respond consistently and credibly to customer security queries without turning the role into a pure compliance function.8. Reporting and Group alignmentTrack useful security measures and report clearly to UK leadership and the Group CISO/SOC. You'll use metrics and dashboards to show risk, progress, and where attention is needed. You'll also act as the main UK link into the Group SOC.9. AI securityHelp the business stay on top of AI-related security risks, including staff use of AI tools, AI in products, agentic workflows, and the changing risks that come with new models and external tooling.About YouYou are an experienced security leader who combines sound judgement with practical delivery. You can work comfortably with senior stakeholders, but you're also happy getting into the detail when needed. You know how to explain security clearly, make risk visible, and help teams take sensible action. You're collaborative, pragmatic, and credible. You know when to push, when to guide, and how to work through trade-offs without losing sight of the bigger picture. You're comfortable operating across a complex organisation and working with different teams, brands, and levels of technical maturity.You will be a great fit if you:can work well with both technical teams and senior business stakeholdersare practical and delivery-minded, not theoreticalare comfortable owning security outcomes while working through otherscan influence without creating unnecessary frictioncare about building a strong security culture, not just implementing controlsstay current on emerging technology and risk, including AISkills & ExperienceEssentialStrong experience in a senior cyber or information security role in a technology-led businessA solid grasp of security governance, risk management, and control frameworksGood working knowledge of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and similar standardsBroad technical understanding across cloud, infrastructure, application security, and secure deliveryExperience of incident response, vulnerability management, and penetration testing follow-upAbility to communicate clearly with both technical and non-technical audiencesComfortable setting priorities, balancing risk, and working in a fast-moving environmentDesirableRelevant certifications such as CISSP, CISM, or CISAExperience in SaaS, proptech, housing, or another data-sensitive software environmentExperience working with group functions, auditors, regulators, or external security partnersExperience working across multiple brands, business units, or countriesFamiliarity with AI security issues across internal use, product use, and evolving external toolingÜber unsWerde Teil von Aareon und digitalisiere gemeinsam mit uns die europäische Immobilienwirtschaft.Warum wir?Wir legen Wert auf eine Arbeitsumgebung, in der Vielfalt und Flexibilität geschätzt werden, partnerschaftliche Zusammenarbeit und gegenseitige Unterstützung im Team selbstverständlich sind und Lernen als Chance wahrgenommen wird. Unsere Lösungen adressieren die großen Herausforderungen unserer Zeit: Klimawandel, Wohnungsknappheit und Fachkräftemangel. Entdecke die Vielfalt von !Kontakt aufnehmenWar noch nicht das Richtige dabei? Dann sende hier eine Initiativbewerbung an unser Recruiting Team!Start
16/06/2026
Full time
Aareon is Europe's established provider of SaaS solutions for the real estate industry and a pioneer of the sector's digital future.With its software solutions, Aareon connects people, processes, and properties-bringing the industry closer together. With the Aareon Property Management System, based on intelligent software solutions, the company enables the efficient management and maintenance of residential and commercial properties and creates digital experiences for all stakeholders.As a reliable and innovative partner, Aareon is committed to progress, positive change, and sustainable living and working spaces for everyone.We value a working environment in which diversity and flexibility are appreciated, cooperation in partnership and mutual support in the team are a matter of course and learning is perceived as an opportunity.Become part of our international team! Become part of ! We are looking forward to meeting YOU!Salary: £70,000-£80,000 per year (depending on experience)Work Location: Hybrid London or ManchesterHours per week: 37.5Contract Type: Permanent, full-timeAbout the RoleAareon UK builds software that housing providers and property professionals rely on every day. As our product set grows, security and data protection matter more than ever. We're hiring a UK Security Officer to take ownership of security across the UK business.This is a senior role covering security across applications, platforms, infrastructure, and engineering. You'll also act as the UK Information Security Officer, helping protect customer data, maintain compliance, and keep security practical in day-to-day delivery.You'll be the main UK contact for the Group Security Operations Centre in Germany, making sure group direction works in practice for the UK business. You'll own the UK security programme, build on what is already in place, and help bring more consistency across our UK brands.Team & ScopeThis is initially an individual contributor role with strong matrix influence across teams. It works alongside CloudOps, IT, Legal, Compliance and Engineering.What You'll Be Responsible For1. Developing and running the UK security strategySet and deliver a clear UK security strategy that aligns with group direction while working for the UK business. You'll turn group guidance into practical local plans, set priorities, and help leadership make sensible investment decisions. A key part of the role is bringing more consistency across our UK brands. You'll also help shape and manage the UK security budget, making sure investment is focused on the right risks, controls, and priorities.2. Governance, risk and complianceOwn and improve our UK security governance. That includes the ISMS, policies, risk management, and the controls needed to meet our obligations. You'll make sure we stay on top of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and any relevant customer or sector requirements. You'll also support audits, due diligence, customer assurance activity, and third-party risk management, helping coordinate evidence, maintain assurance readiness, and improve how we manage security obligations across the UK business.3. Security operations, vulnerability management and incident supportHelp oversee day-to-day security operations for the UK, working closely with CloudOps and the Group SOC. You'll support and coordinate security incidents when they happen, making sure the right people are involved and that follow-up actions are properly seen through. You won't always lead incidents, but you will provide clear security ownership. You'll also own penetration testing and vulnerability management, helping teams make sensible, risk-based decisions about remediation, sequencing, and technical debt.4. Security in engineering and platform deliveryWork with engineering, architecture, product, platform, and DevOps teams to make sure security is built into how we design, build, and run systems. This includes secure coding, design reviews, threat modelling, DevSecOps practices, and cloud security. The role is about working with existing technical experts to make good, pragmatic, well-informed security decisions.5. Policy, awareness and cross-functional workingKeep our security and quality policies and standards up to date, practical, and usable. Support security awareness through clear guidance, communication, and training where needed, while aligning with group-led activity where that is handled centrally. You'll work across engineering, product, IT, data, legal, compliance, HR and operations to keep security visible and joined up across the business.6. Resilience, disaster recovery and business continuityWork with technical and business teams to strengthen disaster recovery strategy and business continuity planning across the UK estate. You'll help make sure recovery expectations are clear, plans are practical, risks are understood, and resilience is tested in a proportionate way.7. Customer assurance and commercial security supportSupport customer and commercial security activity where needed, including security questionnaires, due diligence responses, and clear explanations of our controls and approach. You'll help sales, account teams, and leadership respond consistently and credibly to customer security queries without turning the role into a pure compliance function.8. Reporting and Group alignmentTrack useful security measures and report clearly to UK leadership and the Group CISO/SOC. You'll use metrics and dashboards to show risk, progress, and where attention is needed. You'll also act as the main UK link into the Group SOC.9. AI securityHelp the business stay on top of AI-related security risks, including staff use of AI tools, AI in products, agentic workflows, and the changing risks that come with new models and external tooling.About YouYou are an experienced security leader who combines sound judgement with practical delivery. You can work comfortably with senior stakeholders, but you're also happy getting into the detail when needed. You know how to explain security clearly, make risk visible, and help teams take sensible action. You're collaborative, pragmatic, and credible. You know when to push, when to guide, and how to work through trade-offs without losing sight of the bigger picture. You're comfortable operating across a complex organisation and working with different teams, brands, and levels of technical maturity.You will be a great fit if you:can work well with both technical teams and senior business stakeholdersare practical and delivery-minded, not theoreticalare comfortable owning security outcomes while working through otherscan influence without creating unnecessary frictioncare about building a strong security culture, not just implementing controlsstay current on emerging technology and risk, including AISkills & ExperienceEssentialStrong experience in a senior cyber or information security role in a technology-led businessA solid grasp of security governance, risk management, and control frameworksGood working knowledge of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and similar standardsBroad technical understanding across cloud, infrastructure, application security, and secure deliveryExperience of incident response, vulnerability management, and penetration testing follow-upAbility to communicate clearly with both technical and non-technical audiencesComfortable setting priorities, balancing risk, and working in a fast-moving environmentDesirableRelevant certifications such as CISSP, CISM, or CISAExperience in SaaS, proptech, housing, or another data-sensitive software environmentExperience working with group functions, auditors, regulators, or external security partnersExperience working across multiple brands, business units, or countriesFamiliarity with AI security issues across internal use, product use, and evolving external toolingÜber unsWerde Teil von Aareon und digitalisiere gemeinsam mit uns die europäische Immobilienwirtschaft.Warum wir?Wir legen Wert auf eine Arbeitsumgebung, in der Vielfalt und Flexibilität geschätzt werden, partnerschaftliche Zusammenarbeit und gegenseitige Unterstützung im Team selbstverständlich sind und Lernen als Chance wahrgenommen wird. Unsere Lösungen adressieren die großen Herausforderungen unserer Zeit: Klimawandel, Wohnungsknappheit und Fachkräftemangel. Entdecke die Vielfalt von !Kontakt aufnehmenWar noch nicht das Richtige dabei? Dann sende hier eine Initiativbewerbung an unser Recruiting Team!Start
VodafoneThree - Security Assurance Lead Newbury, United Kingdom Security Assurance
Vodafone Group Plc Newbury, Berkshire
VodafoneThree - Security Assurance LeadNewbury, United KingdomApply NowFind out how well you match with this jobRequisition ID281222Date posted06/11/2026 Location: Newbury + Hybrid Salary: Excellent basic salary plus bonus and Vodafone benefits Working Hours: Full time 37.5 hours per week - Monday to Friday Hybrid We believe that through collaboration and connection with our colleagues we can achieve great things. Our hybrid working approach allows our people to work both in the office and at home, providing the flexibility and resources you need to succeed in your role. We don't require you to be in on specific days; instead, we ask people to come into the office 2-3 days each week, for at least 8 days per month. You should work with your line manager to understand what their expectations are for you, your specific role and your team. Who We Are We're here to build a network the UK can count on - one that connects people, places and potential. Because no matter where you live, what your background is, or how you get online - we think everyone deserves the same chance to stay connected, and with VodafoneThree, that future's being built - today. We're creating more than the UK's best network. We're helping close the digital divide, empower communities and drive meaningful progress. We believe that everyone should feel they belong. Whoever you are and whatever your story, there's space for you here. We're building a workplace where different perspectives are welcomed, voices are heard, and everyone feels safe to show up as themselves. You'll join a team that genuinely cares - about each other, about our customers, and about the future we're building. From day one, you'll be welcomed, valued and encouraged to bring your whole self to work. Why VodafoneThree Join us and you'll be at the heart of change. That means building responsibly, investing sustainably and creating opportunities that last. We're not just expanding connectivity; we're reimagining what a connected nation looks like. With £11bn invested in 5G and digital infrastructure, your work will directly power businesses, services, and communities across the country. You'll work on real challenges, with real impact, across every corner of the country. Wherever you join us, whatever your role, you'll be helping to build a future that works better for everyone. We move at pace, because what we're building matters - and we're learning as we go. We're proud of the progress we've made, but we're just getting started. Join us at the heart of our business in Corporate, one of the central support functions that underpin our business and keep us moving forward. We provide centralised support, expertise and guidance across our UK and Group operations, continuing to build on our success and trailblazing the way to our next stage of digital growth. What you'll do Work closely with teams across the business to build strong relationships and make sure everyone is accountable for security controls. This helps us meet regulatory and certification requirements, while keeping Vodafone and our customers safe from threats that could impact the security or reliability of our services. Help support both internal and external security audits and testing, making sure we're meeting customer expectations and legal security requirements. Clearly report on how our security controls are performing based on audit and testing results. Keep track of remediation activity and follow up with control owners to ensure security issues are addressed. Analyse security risks so gaps are properly recorded, owned, and actively managed. Assess the impact of changes to customer security frameworks, legal requirements, or industry standards. Respond to internal questions and requests related to security assurance. Encourage teams to adopt security best practices and continuously improve our overall security posture. Work with teams to strengthen security controls as new threats emerge and evolve. Build and maintain strong working relationships with internal stakeholders. Who you are Comfortable using Governance, Risk and Compliance (GRC) tools to manage and track security activities. Strong background in risk management, balancing business priorities with security requirements. Experience conducting or supporting security audits and testing activities. Actively working towards (or keen to achieve) a recognised security qualification such as ISO 27001 / 42001 / 27017 / 27701 auditor, CISM, CISSP, COBIT, CISA, CGEIT, or an equivalent.Responsibilities & delivery Maintain a clear RACI for security control ownership, helping hold stakeholders accountable for compliance. Produce and share security compliance KPIs and KRIs with key stakeholders to drive visibility and action. Make sure security certifications stay up to date and that external security milestones and deadlines are met. Support or carry out security audits and testing to demonstrate compliance with mandatory security controls. Worried that you don't meet all the desired criteria exactly? We know that everyone is unique, with multiple aspects to their identity and different experiences behind them. We are passionate about Inclusion for All and creating a workplace where everyone can thrive, whatever their personal or professional background. If you're excited about this role but your experience doesn't align exactly with every part of the job description, we encourage you to apply as you may be the right candidate for this role or another role, and our recruitment team can help you see how your skills fit in. We believe that everyone has valuable contributions to make. As a Disability Confident Employer, we actively encourage individuals with disabilities to apply for positions within our team. Through the 'Offer an Interview' scheme, we aim to offer interviews to a fair and proportionate number of applicants with disabilities who best meet the essential criteria for our vacancies. If you would like to participate in the scheme, you will have the opportunity to indicate this on your application. What we offer We care about our people's success by offering great pay, bonuses, up to 28 days off plus bank holidays, and paid time for charity work. You can personalise our benefits for you and your family, like discounts, vouchers, a pension plan and loads more. We help with your career through our amazing learning tools and top-notch parental leave policies. Need to Know We are regulated by the Financial Conduct Authority and all offers of employment for this role are subject to background checks, including criminal (DBS) and financial checks to meet the regulators standards. If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, a sign language interpreter, or assistive technology, please refer to the Accessibility section of our Careers website () for guidance. We use AI in different parts of our business to boost innovation, improve efficiency, and create new opportunities. We know many candidates use AI to fine-tune their CVs or prepare for interviews, but what we really care about is your unique experiences and achievements. During the interview, we want you to rely on your own knowledge and skills to show us who you really are-your personality, creativity, and abilities. Above all, we're looking for authenticity and can't wait to get to know the real you.
16/06/2026
Full time
VodafoneThree - Security Assurance LeadNewbury, United KingdomApply NowFind out how well you match with this jobRequisition ID281222Date posted06/11/2026 Location: Newbury + Hybrid Salary: Excellent basic salary plus bonus and Vodafone benefits Working Hours: Full time 37.5 hours per week - Monday to Friday Hybrid We believe that through collaboration and connection with our colleagues we can achieve great things. Our hybrid working approach allows our people to work both in the office and at home, providing the flexibility and resources you need to succeed in your role. We don't require you to be in on specific days; instead, we ask people to come into the office 2-3 days each week, for at least 8 days per month. You should work with your line manager to understand what their expectations are for you, your specific role and your team. Who We Are We're here to build a network the UK can count on - one that connects people, places and potential. Because no matter where you live, what your background is, or how you get online - we think everyone deserves the same chance to stay connected, and with VodafoneThree, that future's being built - today. We're creating more than the UK's best network. We're helping close the digital divide, empower communities and drive meaningful progress. We believe that everyone should feel they belong. Whoever you are and whatever your story, there's space for you here. We're building a workplace where different perspectives are welcomed, voices are heard, and everyone feels safe to show up as themselves. You'll join a team that genuinely cares - about each other, about our customers, and about the future we're building. From day one, you'll be welcomed, valued and encouraged to bring your whole self to work. Why VodafoneThree Join us and you'll be at the heart of change. That means building responsibly, investing sustainably and creating opportunities that last. We're not just expanding connectivity; we're reimagining what a connected nation looks like. With £11bn invested in 5G and digital infrastructure, your work will directly power businesses, services, and communities across the country. You'll work on real challenges, with real impact, across every corner of the country. Wherever you join us, whatever your role, you'll be helping to build a future that works better for everyone. We move at pace, because what we're building matters - and we're learning as we go. We're proud of the progress we've made, but we're just getting started. Join us at the heart of our business in Corporate, one of the central support functions that underpin our business and keep us moving forward. We provide centralised support, expertise and guidance across our UK and Group operations, continuing to build on our success and trailblazing the way to our next stage of digital growth. What you'll do Work closely with teams across the business to build strong relationships and make sure everyone is accountable for security controls. This helps us meet regulatory and certification requirements, while keeping Vodafone and our customers safe from threats that could impact the security or reliability of our services. Help support both internal and external security audits and testing, making sure we're meeting customer expectations and legal security requirements. Clearly report on how our security controls are performing based on audit and testing results. Keep track of remediation activity and follow up with control owners to ensure security issues are addressed. Analyse security risks so gaps are properly recorded, owned, and actively managed. Assess the impact of changes to customer security frameworks, legal requirements, or industry standards. Respond to internal questions and requests related to security assurance. Encourage teams to adopt security best practices and continuously improve our overall security posture. Work with teams to strengthen security controls as new threats emerge and evolve. Build and maintain strong working relationships with internal stakeholders. Who you are Comfortable using Governance, Risk and Compliance (GRC) tools to manage and track security activities. Strong background in risk management, balancing business priorities with security requirements. Experience conducting or supporting security audits and testing activities. Actively working towards (or keen to achieve) a recognised security qualification such as ISO 27001 / 42001 / 27017 / 27701 auditor, CISM, CISSP, COBIT, CISA, CGEIT, or an equivalent.Responsibilities & delivery Maintain a clear RACI for security control ownership, helping hold stakeholders accountable for compliance. Produce and share security compliance KPIs and KRIs with key stakeholders to drive visibility and action. Make sure security certifications stay up to date and that external security milestones and deadlines are met. Support or carry out security audits and testing to demonstrate compliance with mandatory security controls. Worried that you don't meet all the desired criteria exactly? We know that everyone is unique, with multiple aspects to their identity and different experiences behind them. We are passionate about Inclusion for All and creating a workplace where everyone can thrive, whatever their personal or professional background. If you're excited about this role but your experience doesn't align exactly with every part of the job description, we encourage you to apply as you may be the right candidate for this role or another role, and our recruitment team can help you see how your skills fit in. We believe that everyone has valuable contributions to make. As a Disability Confident Employer, we actively encourage individuals with disabilities to apply for positions within our team. Through the 'Offer an Interview' scheme, we aim to offer interviews to a fair and proportionate number of applicants with disabilities who best meet the essential criteria for our vacancies. If you would like to participate in the scheme, you will have the opportunity to indicate this on your application. What we offer We care about our people's success by offering great pay, bonuses, up to 28 days off plus bank holidays, and paid time for charity work. You can personalise our benefits for you and your family, like discounts, vouchers, a pension plan and loads more. We help with your career through our amazing learning tools and top-notch parental leave policies. Need to Know We are regulated by the Financial Conduct Authority and all offers of employment for this role are subject to background checks, including criminal (DBS) and financial checks to meet the regulators standards. If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, a sign language interpreter, or assistive technology, please refer to the Accessibility section of our Careers website () for guidance. We use AI in different parts of our business to boost innovation, improve efficiency, and create new opportunities. We know many candidates use AI to fine-tune their CVs or prepare for interviews, but what we really care about is your unique experiences and achievements. During the interview, we want you to rely on your own knowledge and skills to show us who you really are-your personality, creativity, and abilities. Above all, we're looking for authenticity and can't wait to get to know the real you.
Citi
Change Management Business Analyst
Citi City, Belfast
Are you looking for a career move that will put you at the heart of a global financial institution? By Joining Citi, you will become part of a global organisation whose mission is to serve as a trusted partner to our clients by responsibly providing financial services that enable growth and economic progress. Team Overview SMBIC Data and Regulatory Operations Group is a global team operating in over 20 countries, providing essential support to key business lines including Markets, Services, and Wealth Management. We provide an array of services to enable client lifecycle transactions; from relationship establishment, supporting the data demands surrounding instruments and delivering non-financial reporting to our regulators. Regulatory Operations Change Team The Regulatory Operations Change Team, within SMBIC Data and Regulatory Operations, is responsible for the execution of regulatory change initiatives, including: Implementation of new regulations and changes to existing regulations Remediate issues noted by regulators and auditors Build controls strategic framework What you'll do This role is to support the delivery of the new transaction reporting regime in South Africa. The candidate will be working on the project until Q2 2027 and then supporting the daily activities post project completion. Provide business analyst and project management support for the execution of upcoming regulations, including data gathering, documentation, and stakeholder communication. Support the development of training materials and communication plans. Work closely with business functions (e.g., Operations, Middle Office, Front Office, Technology, Compliance, Legal and Finance) to gather information and support the execution of change initiatives. Assist with the preparation of materials for Business Execution and Transformation teams on topics relating to program oversight, risk monitoring, financial and administrative reporting. Support the governance of program / projects including the scheduling and preparation of materials for steering committee and working groups. Identify potential project risks and escalate them to the Senior Change Manager or Change Management Lead. Ensure that the workstreams/projects meet requirements and are to the appropriate quality, on time and within budget, in accordance with the program plan and governance. What we need from you Financial services experience, with exposure to global markets trading and investment banking operations preferred. Basic knowledge of capital markets products, including cash securities, exchange traded derivatives, and OTC derivative products. Basic knowledge of regulatory reporting regulations - MiFID II/MiFIR, EMIR, CFTC, SEC, CSA, CAT, ASIC, MAS, SFTR etc. Experience in supporting the implementation of projects, operational process change and improvement. Project experience working within business management, middle office, compliance, legal and/or technology. Experience in collecting, defining, and documenting business requirements, test plans and other project management artifacts. Strong communication and interpersonal skills. Strong Microsoft Office skills; including Visio and Project. Competencies Execution/delivery focus with a willingness to learn and contribute to change management processes. Strong organizational skills. Ability to handle changing priorities and manage multiple tasks simultaneously. Excellent oral and written communication skills and ability to communicate effectively with stakeholders. Ability to work under pressure and manage tight deadlines or unexpected changes in expectations or requirements. A basic knowledge of the techniques for planning, monitoring, and controlling programs and resources. Ability to create and deliver presentations to management, effectively communicating program status, risks, and opportunities. Ability to quickly grasp and master new concepts/requirements and related product/functional knowledge. Ability to learn/understand some technical implications of system design. Ability to work independently, multi-task, and take ownership of various parts of a project or initiative. Excellent analytical and problem solving skills, with the ability to identify root causes and develop effective solutions to complex challenges. Bachelor's/University degree is required. What we can offer you By joining Citi Belfast, you will not only be part of a business casual workplace with a hybrid working model (up to 2 days working at home per week), but also receive a competitive base salary (which is annually reviewed), and enjoy a whole host of additional benefits such as: Generous holiday allowance starting at 27 days plus bank holidays; increasing with tenure. A discretionary annual performance related bonus. Private medical insurance packages to suit your personal circumstances. Employee Assistance Program. Pension Plan. Paid Parental Leave. Special discounts for employees, family, and friends. Access to an array of learning and development resources. Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi. View Citi's EEO Policy Statement and the Know Your Rights poster.
16/06/2026
Full time
Are you looking for a career move that will put you at the heart of a global financial institution? By Joining Citi, you will become part of a global organisation whose mission is to serve as a trusted partner to our clients by responsibly providing financial services that enable growth and economic progress. Team Overview SMBIC Data and Regulatory Operations Group is a global team operating in over 20 countries, providing essential support to key business lines including Markets, Services, and Wealth Management. We provide an array of services to enable client lifecycle transactions; from relationship establishment, supporting the data demands surrounding instruments and delivering non-financial reporting to our regulators. Regulatory Operations Change Team The Regulatory Operations Change Team, within SMBIC Data and Regulatory Operations, is responsible for the execution of regulatory change initiatives, including: Implementation of new regulations and changes to existing regulations Remediate issues noted by regulators and auditors Build controls strategic framework What you'll do This role is to support the delivery of the new transaction reporting regime in South Africa. The candidate will be working on the project until Q2 2027 and then supporting the daily activities post project completion. Provide business analyst and project management support for the execution of upcoming regulations, including data gathering, documentation, and stakeholder communication. Support the development of training materials and communication plans. Work closely with business functions (e.g., Operations, Middle Office, Front Office, Technology, Compliance, Legal and Finance) to gather information and support the execution of change initiatives. Assist with the preparation of materials for Business Execution and Transformation teams on topics relating to program oversight, risk monitoring, financial and administrative reporting. Support the governance of program / projects including the scheduling and preparation of materials for steering committee and working groups. Identify potential project risks and escalate them to the Senior Change Manager or Change Management Lead. Ensure that the workstreams/projects meet requirements and are to the appropriate quality, on time and within budget, in accordance with the program plan and governance. What we need from you Financial services experience, with exposure to global markets trading and investment banking operations preferred. Basic knowledge of capital markets products, including cash securities, exchange traded derivatives, and OTC derivative products. Basic knowledge of regulatory reporting regulations - MiFID II/MiFIR, EMIR, CFTC, SEC, CSA, CAT, ASIC, MAS, SFTR etc. Experience in supporting the implementation of projects, operational process change and improvement. Project experience working within business management, middle office, compliance, legal and/or technology. Experience in collecting, defining, and documenting business requirements, test plans and other project management artifacts. Strong communication and interpersonal skills. Strong Microsoft Office skills; including Visio and Project. Competencies Execution/delivery focus with a willingness to learn and contribute to change management processes. Strong organizational skills. Ability to handle changing priorities and manage multiple tasks simultaneously. Excellent oral and written communication skills and ability to communicate effectively with stakeholders. Ability to work under pressure and manage tight deadlines or unexpected changes in expectations or requirements. A basic knowledge of the techniques for planning, monitoring, and controlling programs and resources. Ability to create and deliver presentations to management, effectively communicating program status, risks, and opportunities. Ability to quickly grasp and master new concepts/requirements and related product/functional knowledge. Ability to learn/understand some technical implications of system design. Ability to work independently, multi-task, and take ownership of various parts of a project or initiative. Excellent analytical and problem solving skills, with the ability to identify root causes and develop effective solutions to complex challenges. Bachelor's/University degree is required. What we can offer you By joining Citi Belfast, you will not only be part of a business casual workplace with a hybrid working model (up to 2 days working at home per week), but also receive a competitive base salary (which is annually reviewed), and enjoy a whole host of additional benefits such as: Generous holiday allowance starting at 27 days plus bank holidays; increasing with tenure. A discretionary annual performance related bonus. Private medical insurance packages to suit your personal circumstances. Employee Assistance Program. Pension Plan. Paid Parental Leave. Special discounts for employees, family, and friends. Access to an array of learning and development resources. Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi. View Citi's EEO Policy Statement and the Know Your Rights poster.
Information Security Officer
Aareon Group
Information Security OfficerApplyremote type: Hybridlocations: London: Manchestertime type: Full timeposted on: Posted 2 Days Agojob requisition id: JR101673Aareon is Europe's established provider of SaaS solutions for the real estate industry and a pioneer of the sector's digital future. With its software solutions, Aareon connects people, processes, and properties-bringing the industry closer together. With the Aareon Property Management System, based on intelligent software solutions, the company enables the efficient management and maintenance of residential and commercial properties and creates digital experiences for all stakeholders. As a reliable and innovative partner, Aareon is committed to progress, positive change, and sustainable living and working spaces for everyone.We value a working environment in which diversity and flexibility are appreciated, cooperation in partnership and mutual support in the team are a matter of course and learning is perceived as an opportunity.Become part of our international team! Become part of ! We are looking forward to meeting YOU! Salary: £70,000-£80,000 per year (depending on experience) Work Location: Hybrid London or Manchester Hours per week: 37.5 Contract Type: Permanent, full-time About the Role Aareon UK builds software that housing providers and property professionals rely on every day. As our product set grows, security and data protection matter more than ever. We're hiring a UK Security Officer to take ownership of security across the UK business.This is a senior role covering security across applications, platforms, infrastructure, and engineering. You'll also act as the UK Information Security Officer, helping protect customer data, maintain compliance, and keep security practical in day-to-day delivery.You'll be the main UK contact for the Group Security Operations Centre in Germany, making sure group direction works in practice for the UK business. You'll own the UK security programme, build on what is already in place, and help bring more consistency across our UK brands. Team & Scope This is initially an individual contributor role with strong matrix influence across teams. It works alongside CloudOps, IT, Legal, Compliance and Engineering. What You'll Be Responsible For 1. Developing and running the UK security strategy Set and deliver a clear UK security strategy that aligns with group direction while working for the UK business. You'll turn group guidance into practical local plans, set priorities, and help leadership make sensible investment decisions. A key part of the role is bringing more consistency across our UK brands. You'll also help shape and manage the UK security budget, making sure investment is focused on the right risks, controls, and priorities. 2. Governance, risk and compliance Own and improve our UK security governance. That includes the ISMS, policies, risk management, and the controls needed to meet our obligations. You'll make sure we stay on top of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and any relevant customer or sector requirements. You'll also support audits, due diligence, customer assurance activity, and third-party risk management, helping coordinate evidence, maintain assurance readiness, and improve how we manage security obligations across the UK business. 3. Security operations, vulnerability management and incident support Help oversee day-to-day security operations for the UK, working closely with CloudOps and the Group SOC. You'll support and coordinate security incidents when they happen, making sure the right people are involved and that follow-up actions are properly seen through. You won't always lead incidents, but you will provide clear security ownership. You'll also own penetration testing and vulnerability management, helping teams make sensible, risk-based decisions about remediation, sequencing, and technical debt. 4. Security in engineering and platform delivery Work with engineering, architecture, product, platform, and DevOps teams to make sure security is built into how we design, build, and run systems. This includes secure coding, design reviews, threat modelling, DevSecOps practices, and cloud security. The role is about working with existing technical experts to make good, pragmatic, well-informed security decisions. 5. Policy, awareness and cross-functional working Keep our security and quality policies and standards up to date, practical, and usable. Support security awareness through clear guidance, communication, and training where needed, while aligning with group-led activity where that is handled centrally. You'll work across engineering, product, IT, data, legal, compliance, HR and operations to keep security visible and joined up across the business. 6. Resilience, disaster recovery and business continuity Work with technical and business teams to strengthen disaster recovery strategy and business continuity planning across the UK estate. You'll help make sure recovery expectations are clear, plans are practical, risks are understood, and resilience is tested in a proportionate way. 7. Customer assurance and commercial security support Support customer and commercial security activity where needed, including security questionnaires, due diligence responses, and clear explanations of our controls and approach. You'll help sales, account teams, and leadership respond consistently and credibly to customer security queries without turning the role into a pure compliance function. 8. Reporting and Group alignment Track useful security measures and report clearly to UK leadership and the Group CISO/SOC. You'll use metrics and dashboards to show risk, progress, and where attention is needed. You'll also act as the main UK link into the Group SOC. 9. AI security Help the business stay on top of AI-related security risks, including staff use of AI tools, AI in products, agentic workflows, and the changing risks that come with new models and external tooling. About You You are an experienced security leader who combines sound judgement with practical delivery. You can work comfortably with senior stakeholders, but you're also happy getting into the detail when needed. You know how to explain security clearly, make risk visible, and help teams take sensible action. You're collaborative, pragmatic, and credible. You know when to push, when to guide, and how to work through trade-offs without losing sight of the bigger picture. You're comfortable operating across a complex organisation and working with different teams, brands, and levels of technical maturity. You will be a great fit if you: can work well with both technical teams and senior business stakeholders are practical and delivery-minded, not theoretical are comfortable owning security outcomes while working through others can influence without creating unnecessary friction care about building a strong security culture, not just implementing controls stay current on emerging technology and risk, including AI Skills & Experience Essential Strong experience in a senior cyber or information security role in a technology-led business A solid grasp of security governance, risk management, and control frameworks Good working knowledge of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and similar standards Broad technical understanding across cloud, infrastructure, application security, and secure delivery Experience of incident response, vulnerability management, and penetration testing follow-up Ability to communicate clearly with both technical and non-technical audiences Comfortable setting priorities, balancing risk, and working in a fast-moving environment Desirable Relevant certifications such as CISSP, CISM, or CISA Experience in SaaS, proptech, housing, or another data-sensitive software environment Experience working with group functions, auditors, regulators, or external security partners Experience working across multiple brands, business units, or countries Familiarity with AI security issues across internal use, product use, and evolving external tooling About UsBecome part of Aareon and digitise the European property industry together with us. Why work here?We value a working environment where diversity and flexibility are valued, working in partnership and supporting each other as a team is a matter of course, and learning is perceived as an opportunity. Our solutions address the major challenges of our time: climate change, housing shortages and skills shortages. Discover the diversity of !
15/06/2026
Full time
Information Security OfficerApplyremote type: Hybridlocations: London: Manchestertime type: Full timeposted on: Posted 2 Days Agojob requisition id: JR101673Aareon is Europe's established provider of SaaS solutions for the real estate industry and a pioneer of the sector's digital future. With its software solutions, Aareon connects people, processes, and properties-bringing the industry closer together. With the Aareon Property Management System, based on intelligent software solutions, the company enables the efficient management and maintenance of residential and commercial properties and creates digital experiences for all stakeholders. As a reliable and innovative partner, Aareon is committed to progress, positive change, and sustainable living and working spaces for everyone.We value a working environment in which diversity and flexibility are appreciated, cooperation in partnership and mutual support in the team are a matter of course and learning is perceived as an opportunity.Become part of our international team! Become part of ! We are looking forward to meeting YOU! Salary: £70,000-£80,000 per year (depending on experience) Work Location: Hybrid London or Manchester Hours per week: 37.5 Contract Type: Permanent, full-time About the Role Aareon UK builds software that housing providers and property professionals rely on every day. As our product set grows, security and data protection matter more than ever. We're hiring a UK Security Officer to take ownership of security across the UK business.This is a senior role covering security across applications, platforms, infrastructure, and engineering. You'll also act as the UK Information Security Officer, helping protect customer data, maintain compliance, and keep security practical in day-to-day delivery.You'll be the main UK contact for the Group Security Operations Centre in Germany, making sure group direction works in practice for the UK business. You'll own the UK security programme, build on what is already in place, and help bring more consistency across our UK brands. Team & Scope This is initially an individual contributor role with strong matrix influence across teams. It works alongside CloudOps, IT, Legal, Compliance and Engineering. What You'll Be Responsible For 1. Developing and running the UK security strategy Set and deliver a clear UK security strategy that aligns with group direction while working for the UK business. You'll turn group guidance into practical local plans, set priorities, and help leadership make sensible investment decisions. A key part of the role is bringing more consistency across our UK brands. You'll also help shape and manage the UK security budget, making sure investment is focused on the right risks, controls, and priorities. 2. Governance, risk and compliance Own and improve our UK security governance. That includes the ISMS, policies, risk management, and the controls needed to meet our obligations. You'll make sure we stay on top of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and any relevant customer or sector requirements. You'll also support audits, due diligence, customer assurance activity, and third-party risk management, helping coordinate evidence, maintain assurance readiness, and improve how we manage security obligations across the UK business. 3. Security operations, vulnerability management and incident support Help oversee day-to-day security operations for the UK, working closely with CloudOps and the Group SOC. You'll support and coordinate security incidents when they happen, making sure the right people are involved and that follow-up actions are properly seen through. You won't always lead incidents, but you will provide clear security ownership. You'll also own penetration testing and vulnerability management, helping teams make sensible, risk-based decisions about remediation, sequencing, and technical debt. 4. Security in engineering and platform delivery Work with engineering, architecture, product, platform, and DevOps teams to make sure security is built into how we design, build, and run systems. This includes secure coding, design reviews, threat modelling, DevSecOps practices, and cloud security. The role is about working with existing technical experts to make good, pragmatic, well-informed security decisions. 5. Policy, awareness and cross-functional working Keep our security and quality policies and standards up to date, practical, and usable. Support security awareness through clear guidance, communication, and training where needed, while aligning with group-led activity where that is handled centrally. You'll work across engineering, product, IT, data, legal, compliance, HR and operations to keep security visible and joined up across the business. 6. Resilience, disaster recovery and business continuity Work with technical and business teams to strengthen disaster recovery strategy and business continuity planning across the UK estate. You'll help make sure recovery expectations are clear, plans are practical, risks are understood, and resilience is tested in a proportionate way. 7. Customer assurance and commercial security support Support customer and commercial security activity where needed, including security questionnaires, due diligence responses, and clear explanations of our controls and approach. You'll help sales, account teams, and leadership respond consistently and credibly to customer security queries without turning the role into a pure compliance function. 8. Reporting and Group alignment Track useful security measures and report clearly to UK leadership and the Group CISO/SOC. You'll use metrics and dashboards to show risk, progress, and where attention is needed. You'll also act as the main UK link into the Group SOC. 9. AI security Help the business stay on top of AI-related security risks, including staff use of AI tools, AI in products, agentic workflows, and the changing risks that come with new models and external tooling. About You You are an experienced security leader who combines sound judgement with practical delivery. You can work comfortably with senior stakeholders, but you're also happy getting into the detail when needed. You know how to explain security clearly, make risk visible, and help teams take sensible action. You're collaborative, pragmatic, and credible. You know when to push, when to guide, and how to work through trade-offs without losing sight of the bigger picture. You're comfortable operating across a complex organisation and working with different teams, brands, and levels of technical maturity. You will be a great fit if you: can work well with both technical teams and senior business stakeholders are practical and delivery-minded, not theoretical are comfortable owning security outcomes while working through others can influence without creating unnecessary friction care about building a strong security culture, not just implementing controls stay current on emerging technology and risk, including AI Skills & Experience Essential Strong experience in a senior cyber or information security role in a technology-led business A solid grasp of security governance, risk management, and control frameworks Good working knowledge of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and similar standards Broad technical understanding across cloud, infrastructure, application security, and secure delivery Experience of incident response, vulnerability management, and penetration testing follow-up Ability to communicate clearly with both technical and non-technical audiences Comfortable setting priorities, balancing risk, and working in a fast-moving environment Desirable Relevant certifications such as CISSP, CISM, or CISA Experience in SaaS, proptech, housing, or another data-sensitive software environment Experience working with group functions, auditors, regulators, or external security partners Experience working across multiple brands, business units, or countries Familiarity with AI security issues across internal use, product use, and evolving external tooling About UsBecome part of Aareon and digitise the European property industry together with us. Why work here?We value a working environment where diversity and flexibility are valued, working in partnership and supporting each other as a team is a matter of course, and learning is perceived as an opportunity. Our solutions address the major challenges of our time: climate change, housing shortages and skills shortages. Discover the diversity of !
Information Security Officer
Aareon Group Manchester, Lancashire
Information Security OfficerApplyremote type: Hybridlocations: London: Manchestertime type: Full timeposted on: Posted 2 Days Agojob requisition id: JR101673Aareon is Europe's established provider of SaaS solutions for the real estate industry and a pioneer of the sector's digital future. With its software solutions, Aareon connects people, processes, and properties-bringing the industry closer together. With the Aareon Property Management System, based on intelligent software solutions, the company enables the efficient management and maintenance of residential and commercial properties and creates digital experiences for all stakeholders. As a reliable and innovative partner, Aareon is committed to progress, positive change, and sustainable living and working spaces for everyone.We value a working environment in which diversity and flexibility are appreciated, cooperation in partnership and mutual support in the team are a matter of course and learning is perceived as an opportunity.Become part of our international team! Become part of ! We are looking forward to meeting YOU! Salary: £70,000-£80,000 per year (depending on experience) Work Location: Hybrid London or Manchester Hours per week: 37.5 Contract Type: Permanent, full-time About the Role Aareon UK builds software that housing providers and property professionals rely on every day. As our product set grows, security and data protection matter more than ever. We're hiring a UK Security Officer to take ownership of security across the UK business.This is a senior role covering security across applications, platforms, infrastructure, and engineering. You'll also act as the UK Information Security Officer, helping protect customer data, maintain compliance, and keep security practical in day-to-day delivery.You'll be the main UK contact for the Group Security Operations Centre in Germany, making sure group direction works in practice for the UK business. You'll own the UK security programme, build on what is already in place, and help bring more consistency across our UK brands. Team & Scope This is initially an individual contributor role with strong matrix influence across teams. It works alongside CloudOps, IT, Legal, Compliance and Engineering. What You'll Be Responsible For 1. Developing and running the UK security strategy Set and deliver a clear UK security strategy that aligns with group direction while working for the UK business. You'll turn group guidance into practical local plans, set priorities, and help leadership make sensible investment decisions. A key part of the role is bringing more consistency across our UK brands. You'll also help shape and manage the UK security budget, making sure investment is focused on the right risks, controls, and priorities. 2. Governance, risk and compliance Own and improve our UK security governance. That includes the ISMS, policies, risk management, and the controls needed to meet our obligations. You'll make sure we stay on top of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and any relevant customer or sector requirements. You'll also support audits, due diligence, customer assurance activity, and third-party risk management, helping coordinate evidence, maintain assurance readiness, and improve how we manage security obligations across the UK business. 3. Security operations, vulnerability management and incident support Help oversee day-to-day security operations for the UK, working closely with CloudOps and the Group SOC. You'll support and coordinate security incidents when they happen, making sure the right people are involved and that follow-up actions are properly seen through. You won't always lead incidents, but you will provide clear security ownership. You'll also own penetration testing and vulnerability management, helping teams make sensible, risk-based decisions about remediation, sequencing, and technical debt. 4. Security in engineering and platform delivery Work with engineering, architecture, product, platform, and DevOps teams to make sure security is built into how we design, build, and run systems. This includes secure coding, design reviews, threat modelling, DevSecOps practices, and cloud security. The role is about working with existing technical experts to make good, pragmatic, well-informed security decisions. 5. Policy, awareness and cross-functional working Keep our security and quality policies and standards up to date, practical, and usable. Support security awareness through clear guidance, communication, and training where needed, while aligning with group-led activity where that is handled centrally. You'll work across engineering, product, IT, data, legal, compliance, HR and operations to keep security visible and joined up across the business. 6. Resilience, disaster recovery and business continuity Work with technical and business teams to strengthen disaster recovery strategy and business continuity planning across the UK estate. You'll help make sure recovery expectations are clear, plans are practical, risks are understood, and resilience is tested in a proportionate way. 7. Customer assurance and commercial security support Support customer and commercial security activity where needed, including security questionnaires, due diligence responses, and clear explanations of our controls and approach. You'll help sales, account teams, and leadership respond consistently and credibly to customer security queries without turning the role into a pure compliance function. 8. Reporting and Group alignment Track useful security measures and report clearly to UK leadership and the Group CISO/SOC. You'll use metrics and dashboards to show risk, progress, and where attention is needed. You'll also act as the main UK link into the Group SOC. 9. AI security Help the business stay on top of AI-related security risks, including staff use of AI tools, AI in products, agentic workflows, and the changing risks that come with new models and external tooling. About You You are an experienced security leader who combines sound judgement with practical delivery. You can work comfortably with senior stakeholders, but you're also happy getting into the detail when needed. You know how to explain security clearly, make risk visible, and help teams take sensible action. You're collaborative, pragmatic, and credible. You know when to push, when to guide, and how to work through trade-offs without losing sight of the bigger picture. You're comfortable operating across a complex organisation and working with different teams, brands, and levels of technical maturity. You will be a great fit if you: can work well with both technical teams and senior business stakeholders are practical and delivery-minded, not theoretical are comfortable owning security outcomes while working through others can influence without creating unnecessary friction care about building a strong security culture, not just implementing controls stay current on emerging technology and risk, including AI Skills & Experience Essential Strong experience in a senior cyber or information security role in a technology-led business A solid grasp of security governance, risk management, and control frameworks Good working knowledge of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and similar standards Broad technical understanding across cloud, infrastructure, application security, and secure delivery Experience of incident response, vulnerability management, and penetration testing follow-up Ability to communicate clearly with both technical and non-technical audiences Comfortable setting priorities, balancing risk, and working in a fast-moving environment Desirable Relevant certifications such as CISSP, CISM, or CISA Experience in SaaS, proptech, housing, or another data-sensitive software environment Experience working with group functions, auditors, regulators, or external security partners Experience working across multiple brands, business units, or countries Familiarity with AI security issues across internal use, product use, and evolving external tooling About UsBecome part of Aareon and digitise the European property industry together with us. Why work here?We value a working environment where diversity and flexibility are valued, working in partnership and supporting each other as a team is a matter of course, and learning is perceived as an opportunity. Our solutions address the major challenges of our time: climate change, housing shortages and skills shortages. Discover the diversity of !
15/06/2026
Full time
Information Security OfficerApplyremote type: Hybridlocations: London: Manchestertime type: Full timeposted on: Posted 2 Days Agojob requisition id: JR101673Aareon is Europe's established provider of SaaS solutions for the real estate industry and a pioneer of the sector's digital future. With its software solutions, Aareon connects people, processes, and properties-bringing the industry closer together. With the Aareon Property Management System, based on intelligent software solutions, the company enables the efficient management and maintenance of residential and commercial properties and creates digital experiences for all stakeholders. As a reliable and innovative partner, Aareon is committed to progress, positive change, and sustainable living and working spaces for everyone.We value a working environment in which diversity and flexibility are appreciated, cooperation in partnership and mutual support in the team are a matter of course and learning is perceived as an opportunity.Become part of our international team! Become part of ! We are looking forward to meeting YOU! Salary: £70,000-£80,000 per year (depending on experience) Work Location: Hybrid London or Manchester Hours per week: 37.5 Contract Type: Permanent, full-time About the Role Aareon UK builds software that housing providers and property professionals rely on every day. As our product set grows, security and data protection matter more than ever. We're hiring a UK Security Officer to take ownership of security across the UK business.This is a senior role covering security across applications, platforms, infrastructure, and engineering. You'll also act as the UK Information Security Officer, helping protect customer data, maintain compliance, and keep security practical in day-to-day delivery.You'll be the main UK contact for the Group Security Operations Centre in Germany, making sure group direction works in practice for the UK business. You'll own the UK security programme, build on what is already in place, and help bring more consistency across our UK brands. Team & Scope This is initially an individual contributor role with strong matrix influence across teams. It works alongside CloudOps, IT, Legal, Compliance and Engineering. What You'll Be Responsible For 1. Developing and running the UK security strategy Set and deliver a clear UK security strategy that aligns with group direction while working for the UK business. You'll turn group guidance into practical local plans, set priorities, and help leadership make sensible investment decisions. A key part of the role is bringing more consistency across our UK brands. You'll also help shape and manage the UK security budget, making sure investment is focused on the right risks, controls, and priorities. 2. Governance, risk and compliance Own and improve our UK security governance. That includes the ISMS, policies, risk management, and the controls needed to meet our obligations. You'll make sure we stay on top of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and any relevant customer or sector requirements. You'll also support audits, due diligence, customer assurance activity, and third-party risk management, helping coordinate evidence, maintain assurance readiness, and improve how we manage security obligations across the UK business. 3. Security operations, vulnerability management and incident support Help oversee day-to-day security operations for the UK, working closely with CloudOps and the Group SOC. You'll support and coordinate security incidents when they happen, making sure the right people are involved and that follow-up actions are properly seen through. You won't always lead incidents, but you will provide clear security ownership. You'll also own penetration testing and vulnerability management, helping teams make sensible, risk-based decisions about remediation, sequencing, and technical debt. 4. Security in engineering and platform delivery Work with engineering, architecture, product, platform, and DevOps teams to make sure security is built into how we design, build, and run systems. This includes secure coding, design reviews, threat modelling, DevSecOps practices, and cloud security. The role is about working with existing technical experts to make good, pragmatic, well-informed security decisions. 5. Policy, awareness and cross-functional working Keep our security and quality policies and standards up to date, practical, and usable. Support security awareness through clear guidance, communication, and training where needed, while aligning with group-led activity where that is handled centrally. You'll work across engineering, product, IT, data, legal, compliance, HR and operations to keep security visible and joined up across the business. 6. Resilience, disaster recovery and business continuity Work with technical and business teams to strengthen disaster recovery strategy and business continuity planning across the UK estate. You'll help make sure recovery expectations are clear, plans are practical, risks are understood, and resilience is tested in a proportionate way. 7. Customer assurance and commercial security support Support customer and commercial security activity where needed, including security questionnaires, due diligence responses, and clear explanations of our controls and approach. You'll help sales, account teams, and leadership respond consistently and credibly to customer security queries without turning the role into a pure compliance function. 8. Reporting and Group alignment Track useful security measures and report clearly to UK leadership and the Group CISO/SOC. You'll use metrics and dashboards to show risk, progress, and where attention is needed. You'll also act as the main UK link into the Group SOC. 9. AI security Help the business stay on top of AI-related security risks, including staff use of AI tools, AI in products, agentic workflows, and the changing risks that come with new models and external tooling. About You You are an experienced security leader who combines sound judgement with practical delivery. You can work comfortably with senior stakeholders, but you're also happy getting into the detail when needed. You know how to explain security clearly, make risk visible, and help teams take sensible action. You're collaborative, pragmatic, and credible. You know when to push, when to guide, and how to work through trade-offs without losing sight of the bigger picture. You're comfortable operating across a complex organisation and working with different teams, brands, and levels of technical maturity. You will be a great fit if you: can work well with both technical teams and senior business stakeholders are practical and delivery-minded, not theoretical are comfortable owning security outcomes while working through others can influence without creating unnecessary friction care about building a strong security culture, not just implementing controls stay current on emerging technology and risk, including AI Skills & Experience Essential Strong experience in a senior cyber or information security role in a technology-led business A solid grasp of security governance, risk management, and control frameworks Good working knowledge of ISO 27001, ISO 9001, Cyber Essentials, GDPR, and similar standards Broad technical understanding across cloud, infrastructure, application security, and secure delivery Experience of incident response, vulnerability management, and penetration testing follow-up Ability to communicate clearly with both technical and non-technical audiences Comfortable setting priorities, balancing risk, and working in a fast-moving environment Desirable Relevant certifications such as CISSP, CISM, or CISA Experience in SaaS, proptech, housing, or another data-sensitive software environment Experience working with group functions, auditors, regulators, or external security partners Experience working across multiple brands, business units, or countries Familiarity with AI security issues across internal use, product use, and evolving external tooling About UsBecome part of Aareon and digitise the European property industry together with us. Why work here?We value a working environment where diversity and flexibility are valued, working in partnership and supporting each other as a team is a matter of course, and learning is perceived as an opportunity. Our solutions address the major challenges of our time: climate change, housing shortages and skills shortages. Discover the diversity of !
VodafoneThree - Security Assurance Lead Newbury, United Kingdom Security Assurance Posted 17 ho ...
Vodafone Group Plc Newbury, Berkshire
VodafoneThree - Security Assurance LeadNewbury, United KingdomApply NowFind out how well you match with this jobRequisition ID281222Date posted06/11/2026 Location: Newbury + Hybrid Salary: Excellent basic salary plus bonus and Vodafone benefits Working Hours: Full time 37.5 hours per week - Monday to Friday Hybrid We believe that through collaboration and connection with our colleagues we can achieve great things. Our hybrid working approach allows our people to work both in the office and at home, providing the flexibility and resources you need to succeed in your role. We don't require you to be in on specific days; instead, we ask people to come into the office 2-3 days each week, for at least 8 days per month. You should work with your line manager to understand what their expectations are for you, your specific role and your team. Who We Are We're here to build a network the UK can count on - one that connects people, places and potential. Because no matter where you live, what your background is, or how you get online - we think everyone deserves the same chance to stay connected, and with VodafoneThree, that future's being built - today. We're creating more than the UK's best network. We're helping close the digital divide, empower communities and drive meaningful progress. We believe that everyone should feel they belong. Whoever you are and whatever your story, there's space for you here. We're building a workplace where different perspectives are welcomed, voices are heard, and everyone feels safe to show up as themselves. You'll join a team that genuinely cares - about each other, about our customers, and about the future we're building. From day one, you'll be welcomed, valued and encouraged to bring your whole self to work. Why VodafoneThree Join us and you'll be at the heart of change. That means building responsibly, investing sustainably and creating opportunities that last. We're not just expanding connectivity; we're reimagining what a connected nation looks like. With £11bn invested in 5G and digital infrastructure, your work will directly power businesses, services, and communities across the country. You'll work on real challenges, with real impact, across every corner of the country. Wherever you join us, whatever your role, you'll be helping to build a future that works better for everyone. We move at pace, because what we're building matters - and we're learning as we go. We're proud of the progress we've made, but we're just getting started. Join us at the heart of our business in Corporate, one of the central support functions that underpin our business and keep us moving forward. We provide centralised support, expertise and guidance across our UK and Group operations, continuing to build on our success and trailblazing the way to our next stage of digital growth. What you'll do Work closely with teams across the business to build strong relationships and make sure everyone is accountable for security controls. This helps us meet regulatory and certification requirements, while keeping Vodafone and our customers safe from threats that could impact the security or reliability of our services. Help support both internal and external security audits and testing, making sure we're meeting customer expectations and legal security requirements. Clearly report on how our security controls are performing based on audit and testing results. Keep track of remediation activity and follow up with control owners to ensure security issues are addressed. Analyse security risks so gaps are properly recorded, owned, and actively managed. Assess the impact of changes to customer security frameworks, legal requirements, or industry standards. Respond to internal questions and requests related to security assurance. Encourage teams to adopt security best practices and continuously improve our overall security posture. Work with teams to strengthen security controls as new threats emerge and evolve. Build and maintain strong working relationships with internal stakeholders. Who you are Comfortable using Governance, Risk and Compliance (GRC) tools to manage and track security activities. Strong background in risk management, balancing business priorities with security requirements. Experience conducting or supporting security audits and testing activities. Actively working towards (or keen to achieve) a recognised security qualification such as ISO 27001 / 42001 / 27017 / 27701 auditor, CISM, CISSP, COBIT, CISA, CGEIT, or an equivalent.Responsibilities & delivery Maintain a clear RACI for security control ownership, helping hold stakeholders accountable for compliance. Produce and share security compliance KPIs and KRIs with key stakeholders to drive visibility and action. Make sure security certifications stay up to date and that external security milestones and deadlines are met. Support or carry out security audits and testing to demonstrate compliance with mandatory security controls. Worried that you don't meet all the desired criteria exactly? We know that everyone is unique, with multiple aspects to their identity and different experiences behind them. We are passionate about Inclusion for All and creating a workplace where everyone can thrive, whatever their personal or professional background. If you're excited about this role but your experience doesn't align exactly with every part of the job description, we encourage you to apply as you may be the right candidate for this role or another role, and our recruitment team can help you see how your skills fit in. We believe that everyone has valuable contributions to make. As a Disability Confident Employer, we actively encourage individuals with disabilities to apply for positions within our team. Through the 'Offer an Interview' scheme, we aim to offer interviews to a fair and proportionate number of applicants with disabilities who best meet the essential criteria for our vacancies. If you would like to participate in the scheme, you will have the opportunity to indicate this on your application. What we offer We care about our people's success by offering great pay, bonuses, up to 28 days off plus bank holidays, and paid time for charity work. You can personalise our benefits for you and your family, like discounts, vouchers, a pension plan and loads more. We help with your career through our amazing learning tools and top-notch parental leave policies. Need to Know We are regulated by the Financial Conduct Authority and all offers of employment for this role are subject to background checks, including criminal (DBS) and financial checks to meet the regulators standards. If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, a sign language interpreter, or assistive technology, please refer to the Accessibility section of our Careers website () for guidance. We use AI in different parts of our business to boost innovation, improve efficiency, and create new opportunities. We know many candidates use AI to fine-tune their CVs or prepare for interviews, but what we really care about is your unique experiences and achievements. During the interview, we want you to rely on your own knowledge and skills to show us who you really are-your personality, creativity, and abilities. Above all, we're looking for authenticity and can't wait to get to know the real you.
15/06/2026
Full time
VodafoneThree - Security Assurance LeadNewbury, United KingdomApply NowFind out how well you match with this jobRequisition ID281222Date posted06/11/2026 Location: Newbury + Hybrid Salary: Excellent basic salary plus bonus and Vodafone benefits Working Hours: Full time 37.5 hours per week - Monday to Friday Hybrid We believe that through collaboration and connection with our colleagues we can achieve great things. Our hybrid working approach allows our people to work both in the office and at home, providing the flexibility and resources you need to succeed in your role. We don't require you to be in on specific days; instead, we ask people to come into the office 2-3 days each week, for at least 8 days per month. You should work with your line manager to understand what their expectations are for you, your specific role and your team. Who We Are We're here to build a network the UK can count on - one that connects people, places and potential. Because no matter where you live, what your background is, or how you get online - we think everyone deserves the same chance to stay connected, and with VodafoneThree, that future's being built - today. We're creating more than the UK's best network. We're helping close the digital divide, empower communities and drive meaningful progress. We believe that everyone should feel they belong. Whoever you are and whatever your story, there's space for you here. We're building a workplace where different perspectives are welcomed, voices are heard, and everyone feels safe to show up as themselves. You'll join a team that genuinely cares - about each other, about our customers, and about the future we're building. From day one, you'll be welcomed, valued and encouraged to bring your whole self to work. Why VodafoneThree Join us and you'll be at the heart of change. That means building responsibly, investing sustainably and creating opportunities that last. We're not just expanding connectivity; we're reimagining what a connected nation looks like. With £11bn invested in 5G and digital infrastructure, your work will directly power businesses, services, and communities across the country. You'll work on real challenges, with real impact, across every corner of the country. Wherever you join us, whatever your role, you'll be helping to build a future that works better for everyone. We move at pace, because what we're building matters - and we're learning as we go. We're proud of the progress we've made, but we're just getting started. Join us at the heart of our business in Corporate, one of the central support functions that underpin our business and keep us moving forward. We provide centralised support, expertise and guidance across our UK and Group operations, continuing to build on our success and trailblazing the way to our next stage of digital growth. What you'll do Work closely with teams across the business to build strong relationships and make sure everyone is accountable for security controls. This helps us meet regulatory and certification requirements, while keeping Vodafone and our customers safe from threats that could impact the security or reliability of our services. Help support both internal and external security audits and testing, making sure we're meeting customer expectations and legal security requirements. Clearly report on how our security controls are performing based on audit and testing results. Keep track of remediation activity and follow up with control owners to ensure security issues are addressed. Analyse security risks so gaps are properly recorded, owned, and actively managed. Assess the impact of changes to customer security frameworks, legal requirements, or industry standards. Respond to internal questions and requests related to security assurance. Encourage teams to adopt security best practices and continuously improve our overall security posture. Work with teams to strengthen security controls as new threats emerge and evolve. Build and maintain strong working relationships with internal stakeholders. Who you are Comfortable using Governance, Risk and Compliance (GRC) tools to manage and track security activities. Strong background in risk management, balancing business priorities with security requirements. Experience conducting or supporting security audits and testing activities. Actively working towards (or keen to achieve) a recognised security qualification such as ISO 27001 / 42001 / 27017 / 27701 auditor, CISM, CISSP, COBIT, CISA, CGEIT, or an equivalent.Responsibilities & delivery Maintain a clear RACI for security control ownership, helping hold stakeholders accountable for compliance. Produce and share security compliance KPIs and KRIs with key stakeholders to drive visibility and action. Make sure security certifications stay up to date and that external security milestones and deadlines are met. Support or carry out security audits and testing to demonstrate compliance with mandatory security controls. Worried that you don't meet all the desired criteria exactly? We know that everyone is unique, with multiple aspects to their identity and different experiences behind them. We are passionate about Inclusion for All and creating a workplace where everyone can thrive, whatever their personal or professional background. If you're excited about this role but your experience doesn't align exactly with every part of the job description, we encourage you to apply as you may be the right candidate for this role or another role, and our recruitment team can help you see how your skills fit in. We believe that everyone has valuable contributions to make. As a Disability Confident Employer, we actively encourage individuals with disabilities to apply for positions within our team. Through the 'Offer an Interview' scheme, we aim to offer interviews to a fair and proportionate number of applicants with disabilities who best meet the essential criteria for our vacancies. If you would like to participate in the scheme, you will have the opportunity to indicate this on your application. What we offer We care about our people's success by offering great pay, bonuses, up to 28 days off plus bank holidays, and paid time for charity work. You can personalise our benefits for you and your family, like discounts, vouchers, a pension plan and loads more. We help with your career through our amazing learning tools and top-notch parental leave policies. Need to Know We are regulated by the Financial Conduct Authority and all offers of employment for this role are subject to background checks, including criminal (DBS) and financial checks to meet the regulators standards. If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, a sign language interpreter, or assistive technology, please refer to the Accessibility section of our Careers website () for guidance. We use AI in different parts of our business to boost innovation, improve efficiency, and create new opportunities. We know many candidates use AI to fine-tune their CVs or prepare for interviews, but what we really care about is your unique experiences and achievements. During the interview, we want you to rely on your own knowledge and skills to show us who you really are-your personality, creativity, and abilities. Above all, we're looking for authenticity and can't wait to get to know the real you.
Onsite Audio Visual Engineer
AVI-SPL
Description Job Summary The AVI-SPL Onsite Maintenance Engineer will provide on-site AV support at a designated customer location, working in close partnership with the customer, AVI-SPL management, Global Helpdesk, and the wider regional support team. While part of a distributed team, the senior engineer will operate both independently and as part of a team must be proactive, self-starting, and committed to delivering a world-class customer service experience. This person will be a senior engineer in the wider regional customer team based at the London campus. They will be responsible for preventative and break-fix maintenance on an AV estate which ranges from standard meeting rooms to complex auditoriums and broadcast solutions. They will providing service and repairs of audio visual and integrated conference room components / equipment. This role interfaces directly with the client daily and his / her responsibilities include maintaining daily functionality of all audio visual and integrated conference rooms. Essential Duties and Responsibilities Responsible for identifying defective or failed equipment and take ownership to resolution. Management of small projects work as defined in the scope of services. Interacting with client and providing technical reports. Highlighting to the client and team lead immediately any issues that may impact the client's multimedia estate. Work with client to support departments and Supplier Account Managers to provide proper resolution options. Plan and execute small projects from a technical point of view Interface with original equipment manufacturers, developers, engineers, and project managers to provide resolutions for highly complex systems Perform remote troubleshooting for local and regional offices. RMA Hardware in line with asset management guidelines. Complete familiarity with, and adherence to, standard business practices and procedures. Responsible for identifying defective or failed equipment and take ownership to resolution. Work with Customer support departments, AVI-SPL Global Helpdesk, AVI-SPL support teams and AVI-SPL Account Team to provide proper resolution options. Perform preventative maintenance tasks to help maintain customer spaces including but not limited to: testing/repairing cables, testing/repairing various hardware components. Adhere to and understand local safety standards for all site duties, eg Manual Handling, Working at Height, Health and Safety training. Other duties assigned as needed Skills and Abilities Provide technical leadership for the onsite maintenance team. Perform network troubleshooting to diagnose static and dynamic IP addressesEditsoftware code using audio mixer software to calibrate digital signal processor technology and eliminate echo and feedback. Gather and analyse system logs and system settings for codecs, control systems,mixers, and complex broadcast equipment as needed. Perform bench repairs on faulty hardware where possible. Excellent communication skills. Strong analytical and problem solving skills. Ability to prioritise tasks and be able to work under pressure. Able to take ownership and be accountable. Education and/or Experince Minimum of 3 years in an AV Service or engineering role. Proven experience in audio-visual support, ideally in a financial organisation environment. Strong technical knowledge of AV systems, signal flow, and troubleshooting techniques. Experience with video conferencing platforms (e.g., Zoom, Teams, Cisco and Creston). Ability to work independently in a customer-facing role with minimal supervision. Excellent communication and interpersonal skills. Relevant certifications (e.g., AVIXA CTS, Creston, Dante, Biamp, Cisco Collaboration Devices). Formal education in Electronics or related field preferred. Minimum of a High School Diploma or equivalent preferred. Basic IT network security & protocols. AVI-SPL is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, disability status, or membership in any other group protected by federal, state or local law
15/06/2026
Full time
Description Job Summary The AVI-SPL Onsite Maintenance Engineer will provide on-site AV support at a designated customer location, working in close partnership with the customer, AVI-SPL management, Global Helpdesk, and the wider regional support team. While part of a distributed team, the senior engineer will operate both independently and as part of a team must be proactive, self-starting, and committed to delivering a world-class customer service experience. This person will be a senior engineer in the wider regional customer team based at the London campus. They will be responsible for preventative and break-fix maintenance on an AV estate which ranges from standard meeting rooms to complex auditoriums and broadcast solutions. They will providing service and repairs of audio visual and integrated conference room components / equipment. This role interfaces directly with the client daily and his / her responsibilities include maintaining daily functionality of all audio visual and integrated conference rooms. Essential Duties and Responsibilities Responsible for identifying defective or failed equipment and take ownership to resolution. Management of small projects work as defined in the scope of services. Interacting with client and providing technical reports. Highlighting to the client and team lead immediately any issues that may impact the client's multimedia estate. Work with client to support departments and Supplier Account Managers to provide proper resolution options. Plan and execute small projects from a technical point of view Interface with original equipment manufacturers, developers, engineers, and project managers to provide resolutions for highly complex systems Perform remote troubleshooting for local and regional offices. RMA Hardware in line with asset management guidelines. Complete familiarity with, and adherence to, standard business practices and procedures. Responsible for identifying defective or failed equipment and take ownership to resolution. Work with Customer support departments, AVI-SPL Global Helpdesk, AVI-SPL support teams and AVI-SPL Account Team to provide proper resolution options. Perform preventative maintenance tasks to help maintain customer spaces including but not limited to: testing/repairing cables, testing/repairing various hardware components. Adhere to and understand local safety standards for all site duties, eg Manual Handling, Working at Height, Health and Safety training. Other duties assigned as needed Skills and Abilities Provide technical leadership for the onsite maintenance team. Perform network troubleshooting to diagnose static and dynamic IP addressesEditsoftware code using audio mixer software to calibrate digital signal processor technology and eliminate echo and feedback. Gather and analyse system logs and system settings for codecs, control systems,mixers, and complex broadcast equipment as needed. Perform bench repairs on faulty hardware where possible. Excellent communication skills. Strong analytical and problem solving skills. Ability to prioritise tasks and be able to work under pressure. Able to take ownership and be accountable. Education and/or Experince Minimum of 3 years in an AV Service or engineering role. Proven experience in audio-visual support, ideally in a financial organisation environment. Strong technical knowledge of AV systems, signal flow, and troubleshooting techniques. Experience with video conferencing platforms (e.g., Zoom, Teams, Cisco and Creston). Ability to work independently in a customer-facing role with minimal supervision. Excellent communication and interpersonal skills. Relevant certifications (e.g., AVIXA CTS, Creston, Dante, Biamp, Cisco Collaboration Devices). Formal education in Electronics or related field preferred. Minimum of a High School Diploma or equivalent preferred. Basic IT network security & protocols. AVI-SPL is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, disability status, or membership in any other group protected by federal, state or local law
Security Manager (14298)
Opsec Security Washington, Tyne And Wear
Site Security Manager As a partner to businesses and governments, Crane Authentication offers expertise and cutting edge innovations that protect and enhance products, secure identities, safeguard revenues and enforce compliance. Customers from different business sectors and levels of government trust our team of 1,250 people for their expertise in R&D, security design, engineering and data driven insights. We are an integral part of Crane NXT, a c$2 billion dollar business with over 5,000 associates. As part of our growth we are looking for an ISO 14298 Site Security Manager, where you will be part of a global best in class Operations team. Key Responsibilities Position Summary & Objective The ISO 14298 Security Manager is responsible for establishing, implementing, maintaining, and continually improving the site's Security Printing Management System (SPMS) compliant with ISO 14298:2021. The role ensures that security controls across people, processes, technology, and facilities effectively protect high value products and sensitive information throughout design, production, storage, and distribution. This position leads risk assessment, control design, certification readiness (including Intergraf certification where applicable), internal auditing, corrective and preventive actions, and stakeholder engagement to meet customer, regulatory, and company requirements. This role covers both Crane Authentications Washington manufacturing facility and an R&D laboratory in Leicester. Lead the site security program in alignment with ISO 14298 and company policies. Chair Security Management Reviews; track actions, KPIs, and improvements. Partner with Operations, Quality, EHS, IT, Legal/Compliance, and R&D to embed security into daily activity and change initiatives. Own SPMS documentation (policies, procedures, risks, records, secure forms) and ensure proper document control. Maintain all customer related security requirements. Lead periodic and project based risk assessments across physical, information, personnel, product, and supply chain domains. Complete internal inspections and drive corrective actions in line with the requirements of security standards. Provide support for Security Operations Centre personnel. Define and implement proportionate preventive, detective, and corrective controls. Manage perimeter, building, and access controls, visitor processes, CCTV, intrusion detection, and key/lock systems. Oversee personnel vetting, confidentiality requirements, and need to know permissions. Ensure end to end secure material handling (receiving, storage, WIP, reconciliation, destruction, dispatch). Oversee validated processes, change control, and documented approvals. Coordinate with IT/InfoSec to secure digital assets (design files, data, keys) via encryption, access control, backups, and controlled transfers; align with ISO 27001 where relevant. Plan and execute internal audits; manage external audits for ISO 14298 and customer requirements. Lead corrective/preventive actions and maintain certification evidence. Deliver training on security procedures and incident response; maintain competency records. Lead incident response, investigations, root cause analysis, reporting, and corrective/preventive actions. Assess and monitor security critical suppliers; ensure contractual and audit controls. Serve as primary contact for customer security requirements and audits. Manage security elements of business continuity and disaster recovery; ensure protection of assets and rapid recovery. Track KPIs and report performance to leadership; manage the security budget. Position Qualifications Education Professional certifications (e.g., ISO Management Systems, ISO 27001 Lead Implementer/Lead Auditor, ASIS CPP/PSP) advantageous. Experience Significant experience in security management within security printing, identity documents, banknote or product authentication industries, or highly regulated manufacturing. Proven track record implementing and maintaining management systems (ISO 14298, ISO 27001/9001) and leading audits/certifications. Demonstrated ability to design and operate end to end controls for secure materials, data, and processes. Knowledge, Skills, and Abilities Deep understanding of ISO 14298 requirements and practical implementation in a production environment. Strong knowledge of physical security, information security, supply chain security, and risk management techniques. Excellent leadership, coaching, communication, and stakeholder management skills; able to influence across functions. Analytical, data driven, and proficient with Microsoft 365 tools and security/incident management systems. Travel Requirements Regular travel to Leicester (10%) & limited travel to group sites for project support and knowledge sharing. What's in it for me? 25 days' annual leave plus national holidays. Life Insurance Company Pension Scheme. We value diversity at our company. Everyone who applies with the qualifications will receive consideration for employment without regard to age, colour, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by law. We receive a high number of applications, so apologies if we are unable to provide specific feedback. If we feel you are a fit for the role, we'll be in contact.
14/06/2026
Full time
Site Security Manager As a partner to businesses and governments, Crane Authentication offers expertise and cutting edge innovations that protect and enhance products, secure identities, safeguard revenues and enforce compliance. Customers from different business sectors and levels of government trust our team of 1,250 people for their expertise in R&D, security design, engineering and data driven insights. We are an integral part of Crane NXT, a c$2 billion dollar business with over 5,000 associates. As part of our growth we are looking for an ISO 14298 Site Security Manager, where you will be part of a global best in class Operations team. Key Responsibilities Position Summary & Objective The ISO 14298 Security Manager is responsible for establishing, implementing, maintaining, and continually improving the site's Security Printing Management System (SPMS) compliant with ISO 14298:2021. The role ensures that security controls across people, processes, technology, and facilities effectively protect high value products and sensitive information throughout design, production, storage, and distribution. This position leads risk assessment, control design, certification readiness (including Intergraf certification where applicable), internal auditing, corrective and preventive actions, and stakeholder engagement to meet customer, regulatory, and company requirements. This role covers both Crane Authentications Washington manufacturing facility and an R&D laboratory in Leicester. Lead the site security program in alignment with ISO 14298 and company policies. Chair Security Management Reviews; track actions, KPIs, and improvements. Partner with Operations, Quality, EHS, IT, Legal/Compliance, and R&D to embed security into daily activity and change initiatives. Own SPMS documentation (policies, procedures, risks, records, secure forms) and ensure proper document control. Maintain all customer related security requirements. Lead periodic and project based risk assessments across physical, information, personnel, product, and supply chain domains. Complete internal inspections and drive corrective actions in line with the requirements of security standards. Provide support for Security Operations Centre personnel. Define and implement proportionate preventive, detective, and corrective controls. Manage perimeter, building, and access controls, visitor processes, CCTV, intrusion detection, and key/lock systems. Oversee personnel vetting, confidentiality requirements, and need to know permissions. Ensure end to end secure material handling (receiving, storage, WIP, reconciliation, destruction, dispatch). Oversee validated processes, change control, and documented approvals. Coordinate with IT/InfoSec to secure digital assets (design files, data, keys) via encryption, access control, backups, and controlled transfers; align with ISO 27001 where relevant. Plan and execute internal audits; manage external audits for ISO 14298 and customer requirements. Lead corrective/preventive actions and maintain certification evidence. Deliver training on security procedures and incident response; maintain competency records. Lead incident response, investigations, root cause analysis, reporting, and corrective/preventive actions. Assess and monitor security critical suppliers; ensure contractual and audit controls. Serve as primary contact for customer security requirements and audits. Manage security elements of business continuity and disaster recovery; ensure protection of assets and rapid recovery. Track KPIs and report performance to leadership; manage the security budget. Position Qualifications Education Professional certifications (e.g., ISO Management Systems, ISO 27001 Lead Implementer/Lead Auditor, ASIS CPP/PSP) advantageous. Experience Significant experience in security management within security printing, identity documents, banknote or product authentication industries, or highly regulated manufacturing. Proven track record implementing and maintaining management systems (ISO 14298, ISO 27001/9001) and leading audits/certifications. Demonstrated ability to design and operate end to end controls for secure materials, data, and processes. Knowledge, Skills, and Abilities Deep understanding of ISO 14298 requirements and practical implementation in a production environment. Strong knowledge of physical security, information security, supply chain security, and risk management techniques. Excellent leadership, coaching, communication, and stakeholder management skills; able to influence across functions. Analytical, data driven, and proficient with Microsoft 365 tools and security/incident management systems. Travel Requirements Regular travel to Leicester (10%) & limited travel to group sites for project support and knowledge sharing. What's in it for me? 25 days' annual leave plus national holidays. Life Insurance Company Pension Scheme. We value diversity at our company. Everyone who applies with the qualifications will receive consideration for employment without regard to age, colour, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by law. We receive a high number of applications, so apologies if we are unable to provide specific feedback. If we feel you are a fit for the role, we'll be in contact.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board