We are looking for an experienced technology leader to support strategic direction for our technology services, someone who is values driven and supports our mission, people and front-line services.
This is a senior leadership role with responsibility for the delivery, resilience and continuous improvement of the organisation’s technology estate including workplace technology, infrastructure, networks, IT service management and will involve working with third-party suppliers.
Working closely with the IT Manager, you’ll provide day-to-day operational oversight while also leading technology projects and improvement programmes that modernise systems, strengthen resilience and embed best practice. You’ll act as a trusted point of contact for technology change across the organisation — listening to colleagues, understanding their needs and translating them into practical, effective solutions.
You will also support with the procurement and management of IT goods and services, ensuring strong supplier performance, value for money and responsible use of resources. Providing a responsive, customer-focused IT service is central to this role. You’ll ensure high-quality advice, effective support and timely resolution of issues for colleagues across the organisation.
The role requires a strong background and understanding of IT, as well as of our organisations key priorities, challenges, creativity, and pragmatism. You should be able to apply best practice from across the technology sector, adapting for our not-for-profit organisation where value for money, resource management, and effective frontline services are essential.
This varied role will include specific responsibility for:
Working with colleagues to understand organisational needs, challenges, and opportunities, and translating these into clear, evidence-based technology requirements
Lead the mobilisation of new technology products and services across their full lifecycle, from identification and business case development through to implementation, adoption, optimisation, and retirement
Ensure product and service roadmaps are aligned with organisational priorities, user needs, and available resources
Oversee change management and user adoption activities to ensure new products and services are embedded effectively across the organisation
Balance strategic oversight with hands-on involvement to ensure successful delivery and ongoing value from technology investments
Lead and deliver technology projects and continuous improvement programmes to modernise systems and strengthen organisational resilience - translating organisational needs into practical and well-evidenced technology solutions
Lead on cyber security, including security controls, patch management, system updates, risk identification and mitigation
Lead and support the organisation in achieving and maintaining Cyber Essentials Plus accreditation
Ensure strong cyber security practices are embedded and consistently applied across the organisation
Ensure infrastructure, applications and devices are proactively monitored, secure, compliant, and well maintained
Apply technology best practice in a pragmatic way, adapted to the needs and constraints of a not-for-profit organisation
We will support your ongoing professional development with access to training and membership of professional networks.
We can offer full time (37.5 hours) or part-time hours, subject to a minimum of 30 hours, with the expectation of some flexibility to attend evening meetings and undertake national travel. The post will be based in our Head Office in Stockport. Our offices are readily accessible on public transport as we are based in in the centre of Stockport close to the mainline train station.
For more information about this role please do not hesitate to contact Tracey Cornhill by email to Tracey.Cornhill@creativesupport.co.uk
Vacancy Reference Number: 84299
Applications for this role must be submitted via the Creative Support website using the above vacancy reference number
Benefits of working with Creative Support include a probationary bonus, pension contributions, free life assurance, 38 days Leave and company paid enhanced DBS.
We are a passionate, inclusive, and anti-racist organization - Stonewall Diversity Champion, Disability Confident Employer who have recently received Investors in People Gold award.
Applications are reviewed as they are received, we do not provide feedback for unsuccessful applications. We can only accept applications from candidates who are located in and eligible to work within the UK – This post will not be open to Sponsorship and we are unable to accept applicants with Skilled Worker Visas .
30/01/2026
Full time
We are looking for an experienced technology leader to support strategic direction for our technology services, someone who is values driven and supports our mission, people and front-line services.
This is a senior leadership role with responsibility for the delivery, resilience and continuous improvement of the organisation’s technology estate including workplace technology, infrastructure, networks, IT service management and will involve working with third-party suppliers.
Working closely with the IT Manager, you’ll provide day-to-day operational oversight while also leading technology projects and improvement programmes that modernise systems, strengthen resilience and embed best practice. You’ll act as a trusted point of contact for technology change across the organisation — listening to colleagues, understanding their needs and translating them into practical, effective solutions.
You will also support with the procurement and management of IT goods and services, ensuring strong supplier performance, value for money and responsible use of resources. Providing a responsive, customer-focused IT service is central to this role. You’ll ensure high-quality advice, effective support and timely resolution of issues for colleagues across the organisation.
The role requires a strong background and understanding of IT, as well as of our organisations key priorities, challenges, creativity, and pragmatism. You should be able to apply best practice from across the technology sector, adapting for our not-for-profit organisation where value for money, resource management, and effective frontline services are essential.
This varied role will include specific responsibility for:
Working with colleagues to understand organisational needs, challenges, and opportunities, and translating these into clear, evidence-based technology requirements
Lead the mobilisation of new technology products and services across their full lifecycle, from identification and business case development through to implementation, adoption, optimisation, and retirement
Ensure product and service roadmaps are aligned with organisational priorities, user needs, and available resources
Oversee change management and user adoption activities to ensure new products and services are embedded effectively across the organisation
Balance strategic oversight with hands-on involvement to ensure successful delivery and ongoing value from technology investments
Lead and deliver technology projects and continuous improvement programmes to modernise systems and strengthen organisational resilience - translating organisational needs into practical and well-evidenced technology solutions
Lead on cyber security, including security controls, patch management, system updates, risk identification and mitigation
Lead and support the organisation in achieving and maintaining Cyber Essentials Plus accreditation
Ensure strong cyber security practices are embedded and consistently applied across the organisation
Ensure infrastructure, applications and devices are proactively monitored, secure, compliant, and well maintained
Apply technology best practice in a pragmatic way, adapted to the needs and constraints of a not-for-profit organisation
We will support your ongoing professional development with access to training and membership of professional networks.
We can offer full time (37.5 hours) or part-time hours, subject to a minimum of 30 hours, with the expectation of some flexibility to attend evening meetings and undertake national travel. The post will be based in our Head Office in Stockport. Our offices are readily accessible on public transport as we are based in in the centre of Stockport close to the mainline train station.
For more information about this role please do not hesitate to contact Tracey Cornhill by email to Tracey.Cornhill@creativesupport.co.uk
Vacancy Reference Number: 84299
Applications for this role must be submitted via the Creative Support website using the above vacancy reference number
Benefits of working with Creative Support include a probationary bonus, pension contributions, free life assurance, 38 days Leave and company paid enhanced DBS.
We are a passionate, inclusive, and anti-racist organization - Stonewall Diversity Champion, Disability Confident Employer who have recently received Investors in People Gold award.
Applications are reviewed as they are received, we do not provide feedback for unsuccessful applications. We can only accept applications from candidates who are located in and eligible to work within the UK – This post will not be open to Sponsorship and we are unable to accept applicants with Skilled Worker Visas .
Salary and Employment Details Salary: £80,000 DOE Full Time Permanent Who we are SubSea Craft is a fast growing, privately-funded, UK-based innovative maritime technology company specialising in next-generation, high-performance watercraft and systems. We operate at the intersection of advanced engineering, cutting-edge design, and user-centric innovation, delivering safe, effective, and enabling solutions for both commercial and defence applications. What we offer Pension Contribution - Pension scheme with the option to contribute via salary sacrifice. Annual Bonus Scheme - Eligibility to participate in the company's annual discretionary bonus scheme, linked to individual and company performance. Life Assurance and Critical Illness Cover - Comprehensive protection including Life Assurance (4x salary) and Critical Illness Coverage. Annual Leave - 25 days of annual leave plus bank holidays. Christmas Leave - A Christmas shutdown is typically observed. Wellbeing Day - An additional Wellbeing Day each year to focus on personal health and wellbeing. Family Leave - Enhanced maternity and paternity pay. Private Healthcare - Access to comprehensive private healthcare coverage to support physical and mental wellbeing. Professional Development - Commitment to ongoing learning and career growth, supported by training programmes and access to LinkedIn Learning. Flexible Working - Opportunities for flexible working arrangements to promote work-life balance. Inclusive Culture - A professional environment that values diversity, innovation, and collaboration. Role Summary The Physical and Digital Security Manager is responsible for developing, implementing and continuously improving the organisation's protective, physical, information and cyber security arrangements, ensuring security risks are effectively managed in support of business objectives, contractual obligations and regulatory requirements. The role provides leadership across physical security, information security governance, cyber resilience and personnel security, including oversight of the Information Security Management System (ISMS), management of security risks and incidents, and assurance that appropriate controls are in place to protect people, assets, information and operations. The role acts as the company's subject matter lead for security matters, working cross-functionally with internal stakeholders, external partners and relevant authorities to support a robust and proportionate security posture across the organisation. Responsibilities Security Strategy and Governance - develop and implement the organisation's security strategy, policies and procedures aligned to business objectives, risk appetite and legal, regulatory and contractual obligations. Risk Management - lead identification, assessment and treatment of risks across physical, personnel, information and cyber security domains. Physical and Protective Security - maintain and continuously improve the integrity of physical security arrangements across company facilities, assets and operations. Information Security Management - implement, manage and continuously improve the organisation's Information Security Management System (ISMS), ensuring security policies and procedures are maintained, communicated and embedded. Cyber Security - conduct vulnerability, threat and risk assessments, ensuring appropriate mitigation measures are implemented to address identified cyber threats and weaknesses. Technology Security Oversight - oversee the security of the technological estate, including security assurance and oversight of internal IT team, outsourced IT and managed service providers. Personnel Security and Vetting - manage personnel security vetting activities, including sponsorship, submissions, renewals and liaison with United Kingdom Security Vetting where required. Third-Party and Supply Chain Security - evaluate and assure suppliers and third parties against security requirements and contractual obligations. Incident Response and Resilience - lead and coordinate response to security incidents, including containment, investigation, recovery and lessons learned. Project and Change Support - provide security subject matter expertise into company projects and change initiatives, ensuring security risks are considered throughout the project lifecycle. Training and Security Culture - promote and support security awareness and training across the organisation to strengthen security culture and compliance. Compliance and Assurance - ensure appropriate policies, controls and processes support compliance with applicable legal, regulatory and contractual security requirements. Performance Reporting - develop and monitor security performance metrics and KPIs, providing assurance and reporting to senior leadership and the board. Data Protection - support compliance with data protection obligations, including response to data incidents and data subject requests. Qualifications and Experience - Required Proven experience (5+ years) in security management spanning digital, cyber, information and/or protective security environments. Experience managing security risks across both physical and digital security domains. Strong understanding of information security principles, threats, vulnerabilities and mitigating controls. Experience implementing or operating security frameworks such as ISO/IEC 27001, NIST and relevant regulatory frameworks including GDPR. Knowledge of National Cyber Security Centre guidance, including the 14 Cloud Security Principles. Experience overseeing incident response, security assurance and third party security management. Experience overseeing or coordinating penetration testing, vulnerability assessments and remediation activities, including interpretation of findings and management of corrective actions. Experience delivering security reporting and assurance to senior stakeholders. Strong project management capability, including management of multiple initiatives simultaneously. Excellent communication, interpersonal and written skills. Ability to work effectively across functions and influence stakeholders at all levels. Eligible to obtain and maintain Security Check (SC) Clearance. Qualifications and Experience - Desirable Current SC clearance (or higher). Experience administering personnel vetting applications through United Kingdom Security Vetting. Experience operating within defence, national security, critical infrastructure or similarly regulated environments. Understanding of protective security guidance from National Protective Security Authority and National Cyber Security Centre. Eligibility for Developed Vetting where required to support specific programmes. Bachelor's degree in Information Security, Computer Science, Engineering Management or related discipline. Professional certifications such as: ISC 2 CISSP ISACA CISM ISO27001 Lead Auditor / Implementer NIST Foundation or Practitioner CCSP Chartered Security Professional (CSyP) Note Due to the nature of work undertaken at SubSea Craft, the selected candidate must be capable of meeting the security requirements of the position, which would include as a minimum existing right to live and work in the UK, Baseline Personnel Security Standard (BPSS), with UK National security clearance required for certain roles. Values Our people are our greatest asset, we continually strive to provide an excellent working environment to enable our team to do their best work. We have an agile professional workforce: we are founded on the belief that our people are valued and our business is trusted, inclusive and commercially adept. What we expect from you Teamwork, mutual respect and collaboration Initiative and independent working Honesty and integrity Business and commercial awareness Agility, adaptability and continuous development Commitment to Inclusion We are committed to building an inclusive, diverse workplace where everyone can thrive. If you require any support or adjustments to interact with us, please let us know.
30/05/2026
Full time
Salary and Employment Details Salary: £80,000 DOE Full Time Permanent Who we are SubSea Craft is a fast growing, privately-funded, UK-based innovative maritime technology company specialising in next-generation, high-performance watercraft and systems. We operate at the intersection of advanced engineering, cutting-edge design, and user-centric innovation, delivering safe, effective, and enabling solutions for both commercial and defence applications. What we offer Pension Contribution - Pension scheme with the option to contribute via salary sacrifice. Annual Bonus Scheme - Eligibility to participate in the company's annual discretionary bonus scheme, linked to individual and company performance. Life Assurance and Critical Illness Cover - Comprehensive protection including Life Assurance (4x salary) and Critical Illness Coverage. Annual Leave - 25 days of annual leave plus bank holidays. Christmas Leave - A Christmas shutdown is typically observed. Wellbeing Day - An additional Wellbeing Day each year to focus on personal health and wellbeing. Family Leave - Enhanced maternity and paternity pay. Private Healthcare - Access to comprehensive private healthcare coverage to support physical and mental wellbeing. Professional Development - Commitment to ongoing learning and career growth, supported by training programmes and access to LinkedIn Learning. Flexible Working - Opportunities for flexible working arrangements to promote work-life balance. Inclusive Culture - A professional environment that values diversity, innovation, and collaboration. Role Summary The Physical and Digital Security Manager is responsible for developing, implementing and continuously improving the organisation's protective, physical, information and cyber security arrangements, ensuring security risks are effectively managed in support of business objectives, contractual obligations and regulatory requirements. The role provides leadership across physical security, information security governance, cyber resilience and personnel security, including oversight of the Information Security Management System (ISMS), management of security risks and incidents, and assurance that appropriate controls are in place to protect people, assets, information and operations. The role acts as the company's subject matter lead for security matters, working cross-functionally with internal stakeholders, external partners and relevant authorities to support a robust and proportionate security posture across the organisation. Responsibilities Security Strategy and Governance - develop and implement the organisation's security strategy, policies and procedures aligned to business objectives, risk appetite and legal, regulatory and contractual obligations. Risk Management - lead identification, assessment and treatment of risks across physical, personnel, information and cyber security domains. Physical and Protective Security - maintain and continuously improve the integrity of physical security arrangements across company facilities, assets and operations. Information Security Management - implement, manage and continuously improve the organisation's Information Security Management System (ISMS), ensuring security policies and procedures are maintained, communicated and embedded. Cyber Security - conduct vulnerability, threat and risk assessments, ensuring appropriate mitigation measures are implemented to address identified cyber threats and weaknesses. Technology Security Oversight - oversee the security of the technological estate, including security assurance and oversight of internal IT team, outsourced IT and managed service providers. Personnel Security and Vetting - manage personnel security vetting activities, including sponsorship, submissions, renewals and liaison with United Kingdom Security Vetting where required. Third-Party and Supply Chain Security - evaluate and assure suppliers and third parties against security requirements and contractual obligations. Incident Response and Resilience - lead and coordinate response to security incidents, including containment, investigation, recovery and lessons learned. Project and Change Support - provide security subject matter expertise into company projects and change initiatives, ensuring security risks are considered throughout the project lifecycle. Training and Security Culture - promote and support security awareness and training across the organisation to strengthen security culture and compliance. Compliance and Assurance - ensure appropriate policies, controls and processes support compliance with applicable legal, regulatory and contractual security requirements. Performance Reporting - develop and monitor security performance metrics and KPIs, providing assurance and reporting to senior leadership and the board. Data Protection - support compliance with data protection obligations, including response to data incidents and data subject requests. Qualifications and Experience - Required Proven experience (5+ years) in security management spanning digital, cyber, information and/or protective security environments. Experience managing security risks across both physical and digital security domains. Strong understanding of information security principles, threats, vulnerabilities and mitigating controls. Experience implementing or operating security frameworks such as ISO/IEC 27001, NIST and relevant regulatory frameworks including GDPR. Knowledge of National Cyber Security Centre guidance, including the 14 Cloud Security Principles. Experience overseeing incident response, security assurance and third party security management. Experience overseeing or coordinating penetration testing, vulnerability assessments and remediation activities, including interpretation of findings and management of corrective actions. Experience delivering security reporting and assurance to senior stakeholders. Strong project management capability, including management of multiple initiatives simultaneously. Excellent communication, interpersonal and written skills. Ability to work effectively across functions and influence stakeholders at all levels. Eligible to obtain and maintain Security Check (SC) Clearance. Qualifications and Experience - Desirable Current SC clearance (or higher). Experience administering personnel vetting applications through United Kingdom Security Vetting. Experience operating within defence, national security, critical infrastructure or similarly regulated environments. Understanding of protective security guidance from National Protective Security Authority and National Cyber Security Centre. Eligibility for Developed Vetting where required to support specific programmes. Bachelor's degree in Information Security, Computer Science, Engineering Management or related discipline. Professional certifications such as: ISC 2 CISSP ISACA CISM ISO27001 Lead Auditor / Implementer NIST Foundation or Practitioner CCSP Chartered Security Professional (CSyP) Note Due to the nature of work undertaken at SubSea Craft, the selected candidate must be capable of meeting the security requirements of the position, which would include as a minimum existing right to live and work in the UK, Baseline Personnel Security Standard (BPSS), with UK National security clearance required for certain roles. Values Our people are our greatest asset, we continually strive to provide an excellent working environment to enable our team to do their best work. We have an agile professional workforce: we are founded on the belief that our people are valued and our business is trusted, inclusive and commercially adept. What we expect from you Teamwork, mutual respect and collaboration Initiative and independent working Honesty and integrity Business and commercial awareness Agility, adaptability and continuous development Commitment to Inclusion We are committed to building an inclusive, diverse workplace where everyone can thrive. If you require any support or adjustments to interact with us, please let us know.
Systems Engineer (Exchange) page is loaded Systems Engineer (Exchange)locations: UK - London ( St Botolph )time type: Full timeposted on: Posted Todayjob requisition id: 2026-395Job Title: Systems EngineerReporting to: Lead Systems EngineerPosition Type: Permanent, 35 hours per weekHybridOverview: Why Standing still is not an option in the current world of Insurance. TMHCC are one of the world's leading Specialty Insurers. With deep expertise in our chosen lines of business, our unparalleled track record and a solid balance sheet, TMHCC evaluates and manages risk like no one else in the industry. Looking beyond profit, empowering our people and delivering on our commitments are at the core of our customer values, and so is a desire to grow and provide creative and innovative solutions to our clients.Job Purpose:The Infrastructure Collaboration Engineering team is looking to hire a technical person with expertise in M365, with a focus on Exchange, OneDrive, Teams and Entra ID. In this role, you will work as a technical lead and subject matter expert in designing, architecting, implementing, operating, and maintaining access management solutions using M365 and Entra ID.Key Responsibilities: Exchange Design, implement, and configure Exchange Online environments, including mailbox setup, migration from on-premises Exchange, and hybrid configurations. Manage user mailboxes, distribution groups, shared mailboxes, and resource mailboxes. Perform day-to-day administration using the Microsoft 365 admin center and PowerShell. Implement and manage security features such as anti-phishing, anti-spam, and malware protection. Ensure compliance with organizational policies and regulatory requirements using features like retention policies, eDiscovery, and data loss prevention (DLP). Monitor Exchange Online health and performance using tools like Microsoft 365 Service Health and Message Trace. Troubleshoot mail flow issues, connectivity problems, and resolve service incidents. Provide technical support to end-users for Exchange Online-related issues, including mailbox access, email delivery, and calendar synchronization. Educate users on best practices and new features. Plan and execute mailbox migrations from legacy systems (such as Exchange Server or other email platforms) to Exchange Online, ensuring minimal disruption and data integrity. Integrate Exchange Online with other Microsoft 365 services (such as Teams, SharePoint, and OneDrive) and third-party applications as required. Utilize PowerShell and other automation tools to streamline administrative tasks, generate reports, and enforce organizational policies. Stay updated with the latest Exchange Online features, best practices, and Microsoft roadmap changes. Proactively recommend and implement improvements to enhance service reliability and user experience. OneDrive Migrate legacy file storage systems to OneDrive for Business, ensuring data integrity and minimal downtime. Oversee storage quotas, user access, and sharing settings to maintain organizational standards. Implement and enforce security policies, including Data Loss Prevention (DLP), encryption, and access controls. Ensure compliance with industry regulations and internal governance standards for data storage and sharing. Monitor for and respond to security incidents related to OneDrive usage. Provide tier 2/3 support for OneDrive-related issues, coordinating with Microsoft support as necessary. Develop and deliver training materials, workshops, or webinars to promote OneDrive adoption. Integrate OneDrive with other M365 services (e.g., Teams, SharePoint) to streamline workflows. Leverage Power Automate or similar tools to automate routine tasks and processes related to file management. Collaborate with developers and IT teams to enable custom integrations as needed. MS Teams Plan, deploy, and configure Microsoft Teams environments according to business requirements, including tenant setup, policies, and integrations. Oversee day-to-day administration of Teams, managing users, groups, channels, and permissions. Monitor usage and maintain system health. Implement and manage security protocols, data governance, and compliance policies to protect organizational data and ensure regulatory adherence. Integrate Teams with other Microsoft 365 services (such as SharePoint, Exchange, OneDrive) and third-party applications to enhance collaboration and workflow automation. Provide technical support to end-users, resolve issues, and handle escalations related to Teams functionality, connectivity, and performance. Utilize reporting tools to monitor usage, analyze trends, and provide actionable insights for continuous improvement. Stay current with Microsoft Teams updates, new features, and best practices; implement changes and communicate impacts to stakeholders. Work closely with IT teams, business units, and external partners to align Teams capabilities with organizational goals and strategies. Maintain thorough documentation of configurations, procedures, troubleshooting steps, and change management activities. Entra ID Proven expert knowledge of Azure Entra ID capabilities such as Conditional Access Policies, Privileged Identity Manager and Application Registrations. Strong understanding of PIM and the assignment of roles / IAM permissions on Management Groups, Subscriptions and Resources, aligned with Just-in-Time access principles Azure Infrastructure Management to include user accounts, groups, conditional policies, Intune management, mobile device management, and endpoint security. Strong understanding of App registration, Enterprise Apps, SPN's and managed identities with the understanding of least privileged administration when it comes to MS Graph API allocation of permissions. Strong understanding of multifactor authentication, SSPR and WHfB, ensuring secure privileged authentication workflows Strong PowerShell scripting Skills, automation, and scheduling skills when working with data in Azure Good understanding of Intune polices management and autopilot. An individual that stays abreast of the latest Entra ID features, best practices, and security trends, and make recommendations for continuous improvement. Competencies Planning • Follow work plans, established timelines, and predefined goals for assigned work.• Meet commitments on deadlines. Communication • Communicate activities, results, and observations with employees and management as appropriate. Cost Management • Identify areas for improvement in existing business practices.• Perform work thoroughly in a cost-efficient manner and at a high productivity level. Business Controls and Policies • Comply with all corporate policies and procedures.• Report any breakdowns in controls to management.• Conduct all activities in a safe manner. People Management • No people management responsibility. Other • Having knowledge and experience with SharePoint is beneficial.• Demonstrating expertise and familiarity with Rubrik is an asset.• Microsoft and Azure certification are highly beneficial.Tokio Marine HCC is a leading specialty insurance group with offices in the United States, the United Kingdom, Europe, and other locations. With the strength and stability that comes from being a member of the Tokio Marine group, and more than forty years of growth, profitability, and stability, we offer important insurance products that most people do not even know exist.The Tokio Marine HCC Group of companies is an equal opportunity employer. Please visit for more information about our companies.
30/05/2026
Full time
Systems Engineer (Exchange) page is loaded Systems Engineer (Exchange)locations: UK - London ( St Botolph )time type: Full timeposted on: Posted Todayjob requisition id: 2026-395Job Title: Systems EngineerReporting to: Lead Systems EngineerPosition Type: Permanent, 35 hours per weekHybridOverview: Why Standing still is not an option in the current world of Insurance. TMHCC are one of the world's leading Specialty Insurers. With deep expertise in our chosen lines of business, our unparalleled track record and a solid balance sheet, TMHCC evaluates and manages risk like no one else in the industry. Looking beyond profit, empowering our people and delivering on our commitments are at the core of our customer values, and so is a desire to grow and provide creative and innovative solutions to our clients.Job Purpose:The Infrastructure Collaboration Engineering team is looking to hire a technical person with expertise in M365, with a focus on Exchange, OneDrive, Teams and Entra ID. In this role, you will work as a technical lead and subject matter expert in designing, architecting, implementing, operating, and maintaining access management solutions using M365 and Entra ID.Key Responsibilities: Exchange Design, implement, and configure Exchange Online environments, including mailbox setup, migration from on-premises Exchange, and hybrid configurations. Manage user mailboxes, distribution groups, shared mailboxes, and resource mailboxes. Perform day-to-day administration using the Microsoft 365 admin center and PowerShell. Implement and manage security features such as anti-phishing, anti-spam, and malware protection. Ensure compliance with organizational policies and regulatory requirements using features like retention policies, eDiscovery, and data loss prevention (DLP). Monitor Exchange Online health and performance using tools like Microsoft 365 Service Health and Message Trace. Troubleshoot mail flow issues, connectivity problems, and resolve service incidents. Provide technical support to end-users for Exchange Online-related issues, including mailbox access, email delivery, and calendar synchronization. Educate users on best practices and new features. Plan and execute mailbox migrations from legacy systems (such as Exchange Server or other email platforms) to Exchange Online, ensuring minimal disruption and data integrity. Integrate Exchange Online with other Microsoft 365 services (such as Teams, SharePoint, and OneDrive) and third-party applications as required. Utilize PowerShell and other automation tools to streamline administrative tasks, generate reports, and enforce organizational policies. Stay updated with the latest Exchange Online features, best practices, and Microsoft roadmap changes. Proactively recommend and implement improvements to enhance service reliability and user experience. OneDrive Migrate legacy file storage systems to OneDrive for Business, ensuring data integrity and minimal downtime. Oversee storage quotas, user access, and sharing settings to maintain organizational standards. Implement and enforce security policies, including Data Loss Prevention (DLP), encryption, and access controls. Ensure compliance with industry regulations and internal governance standards for data storage and sharing. Monitor for and respond to security incidents related to OneDrive usage. Provide tier 2/3 support for OneDrive-related issues, coordinating with Microsoft support as necessary. Develop and deliver training materials, workshops, or webinars to promote OneDrive adoption. Integrate OneDrive with other M365 services (e.g., Teams, SharePoint) to streamline workflows. Leverage Power Automate or similar tools to automate routine tasks and processes related to file management. Collaborate with developers and IT teams to enable custom integrations as needed. MS Teams Plan, deploy, and configure Microsoft Teams environments according to business requirements, including tenant setup, policies, and integrations. Oversee day-to-day administration of Teams, managing users, groups, channels, and permissions. Monitor usage and maintain system health. Implement and manage security protocols, data governance, and compliance policies to protect organizational data and ensure regulatory adherence. Integrate Teams with other Microsoft 365 services (such as SharePoint, Exchange, OneDrive) and third-party applications to enhance collaboration and workflow automation. Provide technical support to end-users, resolve issues, and handle escalations related to Teams functionality, connectivity, and performance. Utilize reporting tools to monitor usage, analyze trends, and provide actionable insights for continuous improvement. Stay current with Microsoft Teams updates, new features, and best practices; implement changes and communicate impacts to stakeholders. Work closely with IT teams, business units, and external partners to align Teams capabilities with organizational goals and strategies. Maintain thorough documentation of configurations, procedures, troubleshooting steps, and change management activities. Entra ID Proven expert knowledge of Azure Entra ID capabilities such as Conditional Access Policies, Privileged Identity Manager and Application Registrations. Strong understanding of PIM and the assignment of roles / IAM permissions on Management Groups, Subscriptions and Resources, aligned with Just-in-Time access principles Azure Infrastructure Management to include user accounts, groups, conditional policies, Intune management, mobile device management, and endpoint security. Strong understanding of App registration, Enterprise Apps, SPN's and managed identities with the understanding of least privileged administration when it comes to MS Graph API allocation of permissions. Strong understanding of multifactor authentication, SSPR and WHfB, ensuring secure privileged authentication workflows Strong PowerShell scripting Skills, automation, and scheduling skills when working with data in Azure Good understanding of Intune polices management and autopilot. An individual that stays abreast of the latest Entra ID features, best practices, and security trends, and make recommendations for continuous improvement. Competencies Planning • Follow work plans, established timelines, and predefined goals for assigned work.• Meet commitments on deadlines. Communication • Communicate activities, results, and observations with employees and management as appropriate. Cost Management • Identify areas for improvement in existing business practices.• Perform work thoroughly in a cost-efficient manner and at a high productivity level. Business Controls and Policies • Comply with all corporate policies and procedures.• Report any breakdowns in controls to management.• Conduct all activities in a safe manner. People Management • No people management responsibility. Other • Having knowledge and experience with SharePoint is beneficial.• Demonstrating expertise and familiarity with Rubrik is an asset.• Microsoft and Azure certification are highly beneficial.Tokio Marine HCC is a leading specialty insurance group with offices in the United States, the United Kingdom, Europe, and other locations. With the strength and stability that comes from being a member of the Tokio Marine group, and more than forty years of growth, profitability, and stability, we offer important insurance products that most people do not even know exist.The Tokio Marine HCC Group of companies is an equal opportunity employer. Please visit for more information about our companies.
Junior Solutions Architect, Tax Transformation Office, London Location: London Other locations: Primary Location Only Date: Mar 12, 2026 Requisition ID: At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. The opportunity EY Tax is a market leader, renowned for delivering sustainable growth and empowering our people to shape their own careers. Our diverse, collaborative team advises on high-profile transactions, combining technical expertise, innovation and a genuine focus on continuous development. Join us to work on challenging, multi-country projects in a supportive, dynamic environment where your impact truly matters. EY's UK Financial Services Tax (UKFS) is expanding its Transformation Office to accelerate the adoption of AI and technology across all Tax sub-service lines (SSLs). This role will be pivotal in driving strategic initiatives, managing AI enablement, and supporting innovation across our Tax practice. As a Solution Architect, you will design and deliver cloud native and AI enabled solutions that modernise tax processes and scale innovation across the firm. You'll partner with business stakeholders, product managers, business analysts and programme managers to translate complex needs into robust solution leveraging GenAI and ML where it creates measurable value. Your key responsibilities Design and implement AI agents and multi agent systems; using agent orchestration frameworks such as LangGraph, Semantic Kernal (or similar); establish standards for agent lifecycle, observability, governance, and safety. Provide technical direction across solution design, coding standards, DevOps and CI/CD; contribute hands on development when needed. Architect patterns and guardrails for Power Apps/Automate/BI; integrate with Azure services, data sources and enterprise controls. Work directly with business stakeholders to shape requirements, roadmaps and success measures; proactively manage risks, trade offs and delivery plans. Produce high quality architecture artefacts (views, decisions, runbooks); curate reusable patterns and reference implementations across service lines. Collaborate with product managers, BAs, programme managers and engineering teams and citizen developers. Provide clear, timely updates to leadership on progress, risks, dependencies and opportunities. Skills and attributes for success What we look for Strong experience with Microsoft Azure, Kubernetes, and cloud native architecture. Proficiency in one of Python, .NET, or Java. Proficiency in one of the database systems Practical experience applying GenAI/LLM capabilities and machine learning. Experience building AI agents and multi agent systems; orchestration using LangGraph or similar frameworks. Experience with Microsoft Power Platform (Power Apps, Power Automate, Power BI) is beneficial. API design, messaging, event streaming; data pipelines, vector stores/embeddings; security (identity, secrets, role based access). CI/CD, infrastructure as code, automated testing, observability, and reliability engineering. Strong experience in business stakeholder management. Proven track record managing multiple concurrent projects and priorities. Comfortable working with product managers, BAs, programme managers and business stakeholders; excellent communication and documentation skills. Curiosity, pragmatism, and a bias for measurable impact. Ideally, you'll also have Experience working with EY Fabric and CT platforms. Knowledge of UK tax data/processes and common source systems. What we offer you At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more . Are you ready to shape your future with confidence? Apply today. To help create the best experience during the recruitment process, please describe any disability-related adjustments or accommodations you may need. EY Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories. Select how often (in days) to receive an alert: EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
30/05/2026
Full time
Junior Solutions Architect, Tax Transformation Office, London Location: London Other locations: Primary Location Only Date: Mar 12, 2026 Requisition ID: At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. The opportunity EY Tax is a market leader, renowned for delivering sustainable growth and empowering our people to shape their own careers. Our diverse, collaborative team advises on high-profile transactions, combining technical expertise, innovation and a genuine focus on continuous development. Join us to work on challenging, multi-country projects in a supportive, dynamic environment where your impact truly matters. EY's UK Financial Services Tax (UKFS) is expanding its Transformation Office to accelerate the adoption of AI and technology across all Tax sub-service lines (SSLs). This role will be pivotal in driving strategic initiatives, managing AI enablement, and supporting innovation across our Tax practice. As a Solution Architect, you will design and deliver cloud native and AI enabled solutions that modernise tax processes and scale innovation across the firm. You'll partner with business stakeholders, product managers, business analysts and programme managers to translate complex needs into robust solution leveraging GenAI and ML where it creates measurable value. Your key responsibilities Design and implement AI agents and multi agent systems; using agent orchestration frameworks such as LangGraph, Semantic Kernal (or similar); establish standards for agent lifecycle, observability, governance, and safety. Provide technical direction across solution design, coding standards, DevOps and CI/CD; contribute hands on development when needed. Architect patterns and guardrails for Power Apps/Automate/BI; integrate with Azure services, data sources and enterprise controls. Work directly with business stakeholders to shape requirements, roadmaps and success measures; proactively manage risks, trade offs and delivery plans. Produce high quality architecture artefacts (views, decisions, runbooks); curate reusable patterns and reference implementations across service lines. Collaborate with product managers, BAs, programme managers and engineering teams and citizen developers. Provide clear, timely updates to leadership on progress, risks, dependencies and opportunities. Skills and attributes for success What we look for Strong experience with Microsoft Azure, Kubernetes, and cloud native architecture. Proficiency in one of Python, .NET, or Java. Proficiency in one of the database systems Practical experience applying GenAI/LLM capabilities and machine learning. Experience building AI agents and multi agent systems; orchestration using LangGraph or similar frameworks. Experience with Microsoft Power Platform (Power Apps, Power Automate, Power BI) is beneficial. API design, messaging, event streaming; data pipelines, vector stores/embeddings; security (identity, secrets, role based access). CI/CD, infrastructure as code, automated testing, observability, and reliability engineering. Strong experience in business stakeholder management. Proven track record managing multiple concurrent projects and priorities. Comfortable working with product managers, BAs, programme managers and business stakeholders; excellent communication and documentation skills. Curiosity, pragmatism, and a bias for measurable impact. Ideally, you'll also have Experience working with EY Fabric and CT platforms. Knowledge of UK tax data/processes and common source systems. What we offer you At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more . Are you ready to shape your future with confidence? Apply today. To help create the best experience during the recruitment process, please describe any disability-related adjustments or accommodations you may need. EY Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories. Select how often (in days) to receive an alert: EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
Automation & Finance Systems Manager - Tax page is loaded Automation & Finance Systems Manager - Taxlocations: London Cannon Street: Cambridge, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: R011301 AVEVA is creating software trusted by over 90% of leading industrial companies. Job title: Automation & Finance Systems Manager - Tax Location: London/Cambridge - Hybrid Reports to: International Tax Director The Job The Tax Automation & Systems Manager will play a key role in enhancing the efficiency, accuracy, and scalability of the tax function through process automation, technology enablement, and data management. This role does not require a tax background, but does require strong IT technical skills, an understanding of financial systems, and the ability to translate business needs into technical solutions.The ideal candidate will partner closely with the tax, finance and IT teams to identify automation opportunities, streamline workflows, improve data quality, and support systems used for compliance, reporting, and analytics. Responsibilities 1. Process Automation & Improvement Serve as project manager role for key tax departmental technology initiatives. Identify automation opportunities within the tax function (e.g., data extraction, reconciliations, report generation, workflow management). Design, build, test, and maintain automated solutions using tools such as Power Automate, Power Query, Alteryx, UIPath, Python, or similar platforms. Map and document current vs. future-state processes, including controls and data flows. Drive continuous improvement and standardization across tax processes. 2. Systems & Data Management Perform risk assessments for new tax processes or system changes. Support the configuration, maintenance, and optimisation of tax-relevant systems (e.g., ERP modules, tax determination engines (e.g. Onesource), consolidation systems, tax reporting tools, document management platforms). Develop and maintain data pipelines to ensure clean, structured, and reliable data for tax calculations and reporting. Collaborate with IT and Finance Systems teams to coordinate system updates, integrations, enhancements and controls. Troubleshoot data issues and conduct root cause analysis. 3. Reporting & Analytics Provide proactive tax intelligence through the building of dashboards, visualisations, and automated reports for the tax team (e.g., Power BI, Tableau). Support data preparation for compliance, audit, provision, and management reporting processes. Ensure accuracy, consistency, and completeness of tax related data flowing from financial systems. 4. Stakeholder Collaboration Work closely with Tax, Finance, Accounting, and IT teams to understand requirements and deliver technology solutions. Translate complex business needs into clear technical specifications. Provide training and support to tax team members on new tools, processes, controls and documentation standards. 5. Governance & Controls Lead tax data governance, ensuring data integrity, validation rules and audit trails across tax sensitive accounts. Design, document, and test controls over tax data, calculations, and reporting. Ensure that automated solutions follow internal controls, security guidelines, and audit requirements. Maintain documentation of systems, workflows, and automation logic. Support the tax function during system related audits or reviews. Skills & Qualifications Required Experience with financial systems such as SAP, Oracle, Workday, or equivalent ERP/reporting tools. Strong process automation skills using platforms such as Power Query, Power Automate, Alteryx, UIPath, Python, or similar. Solid understanding of data structures, data quality, and system integrations. Proficiency in Power BI or another reporting/visualisation tool. Ability to analyse business processes and implement scalable, efficient solutions. Strong communication skills, especially when working with non technical stakeholders. Excellent problem-solving abilities and attention to detail. Preferred (Nice to Have) Experience working with tax or finance functions. Exposure to tax-specific applications (e.g., ONESOURCE, Vertex, Longview, Avalara). Familiarity with SQL or other database tools. Knowledge of financial controls and audit processes. UK Benefits include: Flexible benefits fund, emergency leave days, adoption leave, 28 days annual leave (plus bank holidays), pension, life cover, private medical insurance, parental leave, education assistance program.It's possible we're hiring for this position in multiple countries, in which case the above benefits apply to the primary location. Specific benefits vary by country, but our packages are similarly comprehensive.Find out more: Hybrid working By default, employees are expected to be in their local AVEVA office three days a week, but some positions are fully office-based. Roles supporting particular customers or markets are sometimes remote. Hiring process Find out more: About AVEVA AVEVA is a global leader in industrial software with more than 6,500 employees in over 40 countries. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life - such as energy, infrastructure, chemicals, and minerals - safely, efficiently, and more sustainably.We are committed to embedding sustainability and inclusion into our operations, our culture, and our core business strategy. Learn more about how we are progressing against our ambitious 2030 targets: out more: requires all successful applicants to undergo and pass a drug screening and comprehensive background check before they start employment. Background checks will be conducted in accordance with local laws and may, subject to those laws, include proof of educational attainment, employment history verification, proof of work authorization, criminal records, identity verification, credit check. Certain positions dealing with sensitive and/or third-party personal data may involve additional background check criteria.AVEVA is an Equal Opportunity Employer. We are committed to being an exemplary employer with an inclusive culture, developing a workplace environment where all our employees are treated with dignity and respect. We value diversity and the expertise that people from different backgrounds bring to our business. AVEVA provides reasonable accommodation to applicants with disabilities where appropriate. If you need reasonable accommodation for any part of the application and hiring process, please notify your recruiter. Determinations on requests for reasonable accommodation will be made on a case-by-case basis.
30/05/2026
Full time
Automation & Finance Systems Manager - Tax page is loaded Automation & Finance Systems Manager - Taxlocations: London Cannon Street: Cambridge, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: R011301 AVEVA is creating software trusted by over 90% of leading industrial companies. Job title: Automation & Finance Systems Manager - Tax Location: London/Cambridge - Hybrid Reports to: International Tax Director The Job The Tax Automation & Systems Manager will play a key role in enhancing the efficiency, accuracy, and scalability of the tax function through process automation, technology enablement, and data management. This role does not require a tax background, but does require strong IT technical skills, an understanding of financial systems, and the ability to translate business needs into technical solutions.The ideal candidate will partner closely with the tax, finance and IT teams to identify automation opportunities, streamline workflows, improve data quality, and support systems used for compliance, reporting, and analytics. Responsibilities 1. Process Automation & Improvement Serve as project manager role for key tax departmental technology initiatives. Identify automation opportunities within the tax function (e.g., data extraction, reconciliations, report generation, workflow management). Design, build, test, and maintain automated solutions using tools such as Power Automate, Power Query, Alteryx, UIPath, Python, or similar platforms. Map and document current vs. future-state processes, including controls and data flows. Drive continuous improvement and standardization across tax processes. 2. Systems & Data Management Perform risk assessments for new tax processes or system changes. Support the configuration, maintenance, and optimisation of tax-relevant systems (e.g., ERP modules, tax determination engines (e.g. Onesource), consolidation systems, tax reporting tools, document management platforms). Develop and maintain data pipelines to ensure clean, structured, and reliable data for tax calculations and reporting. Collaborate with IT and Finance Systems teams to coordinate system updates, integrations, enhancements and controls. Troubleshoot data issues and conduct root cause analysis. 3. Reporting & Analytics Provide proactive tax intelligence through the building of dashboards, visualisations, and automated reports for the tax team (e.g., Power BI, Tableau). Support data preparation for compliance, audit, provision, and management reporting processes. Ensure accuracy, consistency, and completeness of tax related data flowing from financial systems. 4. Stakeholder Collaboration Work closely with Tax, Finance, Accounting, and IT teams to understand requirements and deliver technology solutions. Translate complex business needs into clear technical specifications. Provide training and support to tax team members on new tools, processes, controls and documentation standards. 5. Governance & Controls Lead tax data governance, ensuring data integrity, validation rules and audit trails across tax sensitive accounts. Design, document, and test controls over tax data, calculations, and reporting. Ensure that automated solutions follow internal controls, security guidelines, and audit requirements. Maintain documentation of systems, workflows, and automation logic. Support the tax function during system related audits or reviews. Skills & Qualifications Required Experience with financial systems such as SAP, Oracle, Workday, or equivalent ERP/reporting tools. Strong process automation skills using platforms such as Power Query, Power Automate, Alteryx, UIPath, Python, or similar. Solid understanding of data structures, data quality, and system integrations. Proficiency in Power BI or another reporting/visualisation tool. Ability to analyse business processes and implement scalable, efficient solutions. Strong communication skills, especially when working with non technical stakeholders. Excellent problem-solving abilities and attention to detail. Preferred (Nice to Have) Experience working with tax or finance functions. Exposure to tax-specific applications (e.g., ONESOURCE, Vertex, Longview, Avalara). Familiarity with SQL or other database tools. Knowledge of financial controls and audit processes. UK Benefits include: Flexible benefits fund, emergency leave days, adoption leave, 28 days annual leave (plus bank holidays), pension, life cover, private medical insurance, parental leave, education assistance program.It's possible we're hiring for this position in multiple countries, in which case the above benefits apply to the primary location. Specific benefits vary by country, but our packages are similarly comprehensive.Find out more: Hybrid working By default, employees are expected to be in their local AVEVA office three days a week, but some positions are fully office-based. Roles supporting particular customers or markets are sometimes remote. Hiring process Find out more: About AVEVA AVEVA is a global leader in industrial software with more than 6,500 employees in over 40 countries. Our cutting-edge solutions are used by thousands of enterprises to deliver the essentials of life - such as energy, infrastructure, chemicals, and minerals - safely, efficiently, and more sustainably.We are committed to embedding sustainability and inclusion into our operations, our culture, and our core business strategy. Learn more about how we are progressing against our ambitious 2030 targets: out more: requires all successful applicants to undergo and pass a drug screening and comprehensive background check before they start employment. Background checks will be conducted in accordance with local laws and may, subject to those laws, include proof of educational attainment, employment history verification, proof of work authorization, criminal records, identity verification, credit check. Certain positions dealing with sensitive and/or third-party personal data may involve additional background check criteria.AVEVA is an Equal Opportunity Employer. We are committed to being an exemplary employer with an inclusive culture, developing a workplace environment where all our employees are treated with dignity and respect. We value diversity and the expertise that people from different backgrounds bring to our business. AVEVA provides reasonable accommodation to applicants with disabilities where appropriate. If you need reasonable accommodation for any part of the application and hiring process, please notify your recruiter. Determinations on requests for reasonable accommodation will be made on a case-by-case basis.
We're a global engineering, management, and development consultancy. Our purpose is to improve society by considering social outcomes in everything we do, relentlessly focusing on excellence and digital innovation, transforming our clients' businesses, our communities and employee opportunities. A fundamental part of this is respecting each person's differences and striving to meet their needs. We are proud to be a one of Glassdoor's top employers to work for in the UK, as well as being recognised as a Top Inclusive Company in the UK. About thebusinessunit Mott MacDonald's support services are the driving force behind our organisation enabling us to run efficiently and effectively. The team works collaboratively to offer specialist advice, best practice and technology to all areas of our business specifically designed for our global reach. Overview of role Are you ready to shape the future of our cloud and infrastructure services? Join us as a Cloud Platform Specialist and become a driving force behind our Microsoft Cloud-first strategy, while ensuring seamless integration with our third party cloud platforms supporting a dynamic organisation. Reporting to the Compute & Storage Manager, you'll be a key member of the Compute and Storage Team, advising on standards, strategy, and delivering service improvements across our compute and storage platforms. You'll tackle complex problems, lead transformative projects, and champion operational excellence in a dynamic, collaborative environment. Success in this role requires deep collaboration across infrastructure, service delivery, applications, and security to champion service excellence and drive continuous improvement. You will work closely with cross functional teams to align operational and project activities with strategic goals and ensure a seamless experience for our internal customers. This role is a key contributor to our broader business objectives enhancing operational resilience, enabling digital transformation, and optimising service performance. You will be instrumental in shaping a high performing, customer focused IT function that supports innovation and growth across the organisation. We are committed to building a culture of inclusion, wellbeing, and professional development. As a visible leader, you will foster an environment where people feel empowered, supported, and inspired to deliver their best. Key Responsibilities Contribute to the development and refinement of technical standards and best practices for compute and storage platforms, including Azure and Windows Server. Contribute to and support project delivery, including cloud migrations, infrastructure upgrades, automation initiatives, and service enhancements, ensuring alignment with strategic objectives and operational requirements. Provide operational 4th line support for both cloud and on premise infrastructure, ensuring environments are current, secure, and optimized. Act as a technical escalation point for complex incidents, problems, and changes, driving resolution and continuous improvement. Support identity management and access control (Active Directory, Entra ID, RBAC), ensuring robust authentication and authorization across all platforms. Monitor, analyze, and optimize cost, performance and capacity of compute and storage services, proactively identifying and addressing issues. Participate in and contribute to strategic projects, such as cloud migrations, automation initiatives, and service enhancements. Maintain and update technical documentation, including infrastructure diagrams, solution designs, procedures, and knowledge articles. Collaborate with cross functional teams (infrastructure, applications, security, service delivery) to align operational activities with business goals. Ensure compliance with security policies and audit requirements, supporting regular reviews and implementing necessary controls. Mentor and support operations teams, sharing expertise and fostering a culture of learning and operational excellence. Key Performance Indicators Stakeholder satisfaction with project outcomes Quality of root cause analysis and problem resolution Timely delivery of project milestones and technical change initiatives Quality and accuracy of technical documentation produced Continual service improvements Infrastructure availability and mean time between failures Service continuity test success Candidate Specification Proven experience providing advanced technical support and problem resolution for complex compute and storage environments, including Azure, AD, Entra and on premises Windows Server. Strong technical leadership with the ability to collaborate across teams, drive alignment, and support service excellence in distributed environments. Strategic contributor with a track record of influencing operational planning, transformation initiatives, and continuous service improvement. Skilled in stakeholder engagement and communication, able to advise, negotiate, and manage expectations across all levels of the organization. Demonstrated capability in risk identification, escalation management, and effective decision making under pressure. Commitment to operational maturity and service evolution through data driven insights, innovation, and process optimization. Professional certification in Azure Experience operating within complex, matrixed organisations and managing global teams. Experience with Microsoft cloud cost optimisation Cloud performance engineering (capacity planning, performance tuning) Knowledge of containerisation platforms (e.g. Kubernetes) We are actively recruiting a diverse workforce that is reflective of the communities we serve. We recognise that differences in ability, skills and experience are a strength and encourage applications from people of all backgrounds. UK Immigration Mott MacDonald Ltd. are not currently offering sponsorship to candidates under the Skilled Worker visa route in the UK. This decision is as a consequence of the changes made to the Skilled Worker route by the UK Government in April 2024. We continue to welcome applications from candidates who are eligible for alternative immigration routes in the UK, that do not require sponsorship as a Skilled Worker now or in future. At Mott MacDonald, we believe it makes business sense for you and your manager to choose how you can work most effectively to meet your client, team, and personal commitments. We offer a hybrid working policy that embraces your well being, flexibility, and trust. Equality, diversity, and inclusion We put equality, diversity, and inclusion at the heart of our business, seeking to promote fair employment procedures and practices to ensure equal opportunities for all. We encourage individual expression in our workplace and are committed to creating an inclusive environment where everyone feels they can contribute. Accessibility We want you to perform your best at every stage in the recruitment process. If you are disabled or need any support to enable you to apply or attend an interview, please contact us at and we will talk to you about how we can support you. Benefits Health and wellbeing Private medical insurance for all UK colleagues. Health cash plan to support you with every day health costs and treatments. Access to Peppy, providing free support from menopause experts for all UK colleagues. A variety of wellbeing support is available through our comprehensive wellbeing program, including access for you and your family. Ability to flex your salary to opt into a wide range of health benefits, many of which can be extended to your family too. Financial wellbeing We match employee pension contributions between 4.5% and 7%. Life assurance equal up to 4 x your basic salary, with an option to increase the level of cover to 6 x your salary. Our income protection scheme provides a financial benefit, as well as absence and return to work support due to long term illness or injury. Flexible benefits, including increased life assurance cover, critical illness insurance, payroll saving and will writing. As an independently owned business we share the financial success of the business with all our colleagues in various ways including annual bonus schemes. Lifestyle A minimum of days holiday each year, inclusive of public holidays and dependent on level, with the ability to buy or sell leave through our flexible benefits programme. Holiday entitlement increased to a minimum of 35 days after 5 years' service. Variety of employee saving schemes and discounts from high street retailers. Enhanced family and carers leave Enhanced family leave policies, including 26 weeks paid maternity and adoption leave, and two weeks paid paternity/partner leave. Our shared parental leave matches maternity leave meaning we pay up to 24 weeks at full pay. Up to five additional days leave are provided for those with significant caring responsibilities, two of which are paid. Learning and development Primary annual professional institution subscription. A broad range of opportunities to enhance both technical and soft skills through mentoring, formal training, and self development options. Networks, communities and social outcomes . click apply for full job details
30/05/2026
Full time
We're a global engineering, management, and development consultancy. Our purpose is to improve society by considering social outcomes in everything we do, relentlessly focusing on excellence and digital innovation, transforming our clients' businesses, our communities and employee opportunities. A fundamental part of this is respecting each person's differences and striving to meet their needs. We are proud to be a one of Glassdoor's top employers to work for in the UK, as well as being recognised as a Top Inclusive Company in the UK. About thebusinessunit Mott MacDonald's support services are the driving force behind our organisation enabling us to run efficiently and effectively. The team works collaboratively to offer specialist advice, best practice and technology to all areas of our business specifically designed for our global reach. Overview of role Are you ready to shape the future of our cloud and infrastructure services? Join us as a Cloud Platform Specialist and become a driving force behind our Microsoft Cloud-first strategy, while ensuring seamless integration with our third party cloud platforms supporting a dynamic organisation. Reporting to the Compute & Storage Manager, you'll be a key member of the Compute and Storage Team, advising on standards, strategy, and delivering service improvements across our compute and storage platforms. You'll tackle complex problems, lead transformative projects, and champion operational excellence in a dynamic, collaborative environment. Success in this role requires deep collaboration across infrastructure, service delivery, applications, and security to champion service excellence and drive continuous improvement. You will work closely with cross functional teams to align operational and project activities with strategic goals and ensure a seamless experience for our internal customers. This role is a key contributor to our broader business objectives enhancing operational resilience, enabling digital transformation, and optimising service performance. You will be instrumental in shaping a high performing, customer focused IT function that supports innovation and growth across the organisation. We are committed to building a culture of inclusion, wellbeing, and professional development. As a visible leader, you will foster an environment where people feel empowered, supported, and inspired to deliver their best. Key Responsibilities Contribute to the development and refinement of technical standards and best practices for compute and storage platforms, including Azure and Windows Server. Contribute to and support project delivery, including cloud migrations, infrastructure upgrades, automation initiatives, and service enhancements, ensuring alignment with strategic objectives and operational requirements. Provide operational 4th line support for both cloud and on premise infrastructure, ensuring environments are current, secure, and optimized. Act as a technical escalation point for complex incidents, problems, and changes, driving resolution and continuous improvement. Support identity management and access control (Active Directory, Entra ID, RBAC), ensuring robust authentication and authorization across all platforms. Monitor, analyze, and optimize cost, performance and capacity of compute and storage services, proactively identifying and addressing issues. Participate in and contribute to strategic projects, such as cloud migrations, automation initiatives, and service enhancements. Maintain and update technical documentation, including infrastructure diagrams, solution designs, procedures, and knowledge articles. Collaborate with cross functional teams (infrastructure, applications, security, service delivery) to align operational activities with business goals. Ensure compliance with security policies and audit requirements, supporting regular reviews and implementing necessary controls. Mentor and support operations teams, sharing expertise and fostering a culture of learning and operational excellence. Key Performance Indicators Stakeholder satisfaction with project outcomes Quality of root cause analysis and problem resolution Timely delivery of project milestones and technical change initiatives Quality and accuracy of technical documentation produced Continual service improvements Infrastructure availability and mean time between failures Service continuity test success Candidate Specification Proven experience providing advanced technical support and problem resolution for complex compute and storage environments, including Azure, AD, Entra and on premises Windows Server. Strong technical leadership with the ability to collaborate across teams, drive alignment, and support service excellence in distributed environments. Strategic contributor with a track record of influencing operational planning, transformation initiatives, and continuous service improvement. Skilled in stakeholder engagement and communication, able to advise, negotiate, and manage expectations across all levels of the organization. Demonstrated capability in risk identification, escalation management, and effective decision making under pressure. Commitment to operational maturity and service evolution through data driven insights, innovation, and process optimization. Professional certification in Azure Experience operating within complex, matrixed organisations and managing global teams. Experience with Microsoft cloud cost optimisation Cloud performance engineering (capacity planning, performance tuning) Knowledge of containerisation platforms (e.g. Kubernetes) We are actively recruiting a diverse workforce that is reflective of the communities we serve. We recognise that differences in ability, skills and experience are a strength and encourage applications from people of all backgrounds. UK Immigration Mott MacDonald Ltd. are not currently offering sponsorship to candidates under the Skilled Worker visa route in the UK. This decision is as a consequence of the changes made to the Skilled Worker route by the UK Government in April 2024. We continue to welcome applications from candidates who are eligible for alternative immigration routes in the UK, that do not require sponsorship as a Skilled Worker now or in future. At Mott MacDonald, we believe it makes business sense for you and your manager to choose how you can work most effectively to meet your client, team, and personal commitments. We offer a hybrid working policy that embraces your well being, flexibility, and trust. Equality, diversity, and inclusion We put equality, diversity, and inclusion at the heart of our business, seeking to promote fair employment procedures and practices to ensure equal opportunities for all. We encourage individual expression in our workplace and are committed to creating an inclusive environment where everyone feels they can contribute. Accessibility We want you to perform your best at every stage in the recruitment process. If you are disabled or need any support to enable you to apply or attend an interview, please contact us at and we will talk to you about how we can support you. Benefits Health and wellbeing Private medical insurance for all UK colleagues. Health cash plan to support you with every day health costs and treatments. Access to Peppy, providing free support from menopause experts for all UK colleagues. A variety of wellbeing support is available through our comprehensive wellbeing program, including access for you and your family. Ability to flex your salary to opt into a wide range of health benefits, many of which can be extended to your family too. Financial wellbeing We match employee pension contributions between 4.5% and 7%. Life assurance equal up to 4 x your basic salary, with an option to increase the level of cover to 6 x your salary. Our income protection scheme provides a financial benefit, as well as absence and return to work support due to long term illness or injury. Flexible benefits, including increased life assurance cover, critical illness insurance, payroll saving and will writing. As an independently owned business we share the financial success of the business with all our colleagues in various ways including annual bonus schemes. Lifestyle A minimum of days holiday each year, inclusive of public holidays and dependent on level, with the ability to buy or sell leave through our flexible benefits programme. Holiday entitlement increased to a minimum of 35 days after 5 years' service. Variety of employee saving schemes and discounts from high street retailers. Enhanced family and carers leave Enhanced family leave policies, including 26 weeks paid maternity and adoption leave, and two weeks paid paternity/partner leave. Our shared parental leave matches maternity leave meaning we pay up to 24 weeks at full pay. Up to five additional days leave are provided for those with significant caring responsibilities, two of which are paid. Learning and development Primary annual professional institution subscription. A broad range of opportunities to enhance both technical and soft skills through mentoring, formal training, and self development options. Networks, communities and social outcomes . click apply for full job details
The Pipeline Group (TPG) provides our clients with end-to-end Pipeline Generation services that help B2B tech companies scale pipeline fast and reliably through our SDR-as-a-Service model. We combine superstar SDR talent, purpose-built proprietary technology, industry-leading SDR training, rigorous management & quality control layers, world-class data services, integrations and more to offer all-in-one Pipeline Generation to our clients. TPG has been named in the Inc. 5000 Top Fastest-Growing Privately Held Companies in the US for five consecutive years and we're growing faster every single year. Our clients work with us because we've cracked the formula for creating world-class SDRs and putting up industry leading pipeline generation numbers. No guesswork. Just results. OUR CULTURE At TPG, performance and accountability are our culture. We thrive on results-driven by excellence, collaboration, and integrity. Our people-first mindset supports not only clients but our teammates. Your wins are our collective wins. Your growth is our mission. Our vision is to be the world's most effective virtual sales workforce-a place where high-performing remote SDRs, program managers, and operational leaders come together to generate extraordinary ROI. ABOUT OUR ROLE The Director of IT will lead the strategy, architecture, security posture, and operational management of The Pipeline Group's global IT infrastructure. This role will oversee enterprise systems, security, device management, vendor relationships, and compliance initiatives. The Director of IT will be responsible for implementing and maintaining secure, scalable systems that support TPG's remote-first workforce. The ideal candidate combines technical leadership, cybersecurity expertise, compliance knowledge, and vendor management experience. Key Responsibilities IT Infrastructure & Operations Own and manage the company's global IT infrastructure supporting a distributed workforce. Oversee provisioning, management, and lifecycle of company hardware including laptops and endpoint devices. Implement and maintain endpoint security, monitoring, and device management solutions. Ensure secure, reliable access to corporate systems and applications across the organization. Security & Compliance Lead security initiatives and ensure adherence to industry security standards and best practices. Work with external compliance and audit vendors to document processes, implement controls, and pass audits. Establish and maintain internal security policies, procedures, and controls. Monitor systems for vulnerabilities and implement remediation plans. Security Technology Deployment Lead the implementation and management of key enterprise security platforms including: AuthID - Biometric identity verification for secure authentication VMware Carbon Black - Endpoint detection and response (EDR) Responsibilities include: Deployment and configuration across the organization Policy management and enforcement Monitoring and incident response Integration with existing systems Manage relationships with technology vendors for hardware, software, security platforms, and IT services. Evaluate and select new technology partners as needed. Negotiate contracts, pricing, and service agreements. Ensure vendors meet security and compliance standards. Develop a long-term IT strategy aligned with TPG's growth and global workforce model. Evaluate new technologies that improve security, productivity, and operational efficiency. Standardize IT processes, tools, and support systems across the organization. Identity & Access Management Implement strong authentication and access controls across all systems. Manage role-based access controls and least-privilege access models. Ensure proper onboarding and offboarding procedures for system access. Establish and maintain an incident response framework. Investigate and respond to security incidents. Conduct risk assessments and implement mitigation strategies. Required Qualifications 8+ years of experience in IT leadership roles Experience managing IT infrastructure for distributed or remote-first organizations Hands on experience implementing endpoint security, IAM, and enterprise security platforms Strong experience managing IT vendors and security providers Knowledge of endpoint detection and response (EDR), zero trust architecture, and identity security Experience managing device fleets and endpoint management systems Strong understanding of cybersecurity frameworks and best practices Preferred Experience Experience working with compliance auditors or managed security providers Experience in SaaS, technology, or data-driven companies Experience supporting remote global teams Key Success Metrics Secure and scalable IT infrastructure supporting global operations Reduced security risk and improved compliance posture High employee satisfaction with IT systems and support Leadership & Culture The Director of IT will play a critical role in ensuring TPG's systems are secure, scalable, and reliable as the company continues to grow globally. This role requires someone who can combine technical expertise with strategic thinking and strong operational leadership. WHAT TPG PROVIDES FOR OUR TEAM MEMBERS Permanent Remote Work Model - No commuting. Work from wherever you're most productive. Competitive Compensation DOE. Mental Health Support - 3 Paid Mental Health Days per year Community Impact - 1 Paid Volunteer Day per year. Unlimited PTO - Take the time you need (after 90 days). Company-Provided Home Office Equipment - Laptop, desk, chair, etc. Independent Contractor Arrangement - This role will start as an independent contractor. The Pipeline Group is an EOE/Affirmative Action Minority/Female employer, and we welcome all to apply. We consider candidates regardless of race/color, religion, sex (including pregnancy, childbirth and related conditions), national origin/ethnicity, age, disability (intellectual, mental and physical), veteran status, marital status, ancestry, sexual orientation, gender identity and gender expression, genetic information, citizenship or any other personal characteristics protected by law. Please note we are not able to offer sponsorship of visas at this time. An offer of employment for this role will be contingent upon the successful completion of a background check. Internet Requirement: This is a fully remote role which requires a reliable high-speed internet connection with a minimum of 100 Mbps download, which will need to be verified.
30/05/2026
Full time
The Pipeline Group (TPG) provides our clients with end-to-end Pipeline Generation services that help B2B tech companies scale pipeline fast and reliably through our SDR-as-a-Service model. We combine superstar SDR talent, purpose-built proprietary technology, industry-leading SDR training, rigorous management & quality control layers, world-class data services, integrations and more to offer all-in-one Pipeline Generation to our clients. TPG has been named in the Inc. 5000 Top Fastest-Growing Privately Held Companies in the US for five consecutive years and we're growing faster every single year. Our clients work with us because we've cracked the formula for creating world-class SDRs and putting up industry leading pipeline generation numbers. No guesswork. Just results. OUR CULTURE At TPG, performance and accountability are our culture. We thrive on results-driven by excellence, collaboration, and integrity. Our people-first mindset supports not only clients but our teammates. Your wins are our collective wins. Your growth is our mission. Our vision is to be the world's most effective virtual sales workforce-a place where high-performing remote SDRs, program managers, and operational leaders come together to generate extraordinary ROI. ABOUT OUR ROLE The Director of IT will lead the strategy, architecture, security posture, and operational management of The Pipeline Group's global IT infrastructure. This role will oversee enterprise systems, security, device management, vendor relationships, and compliance initiatives. The Director of IT will be responsible for implementing and maintaining secure, scalable systems that support TPG's remote-first workforce. The ideal candidate combines technical leadership, cybersecurity expertise, compliance knowledge, and vendor management experience. Key Responsibilities IT Infrastructure & Operations Own and manage the company's global IT infrastructure supporting a distributed workforce. Oversee provisioning, management, and lifecycle of company hardware including laptops and endpoint devices. Implement and maintain endpoint security, monitoring, and device management solutions. Ensure secure, reliable access to corporate systems and applications across the organization. Security & Compliance Lead security initiatives and ensure adherence to industry security standards and best practices. Work with external compliance and audit vendors to document processes, implement controls, and pass audits. Establish and maintain internal security policies, procedures, and controls. Monitor systems for vulnerabilities and implement remediation plans. Security Technology Deployment Lead the implementation and management of key enterprise security platforms including: AuthID - Biometric identity verification for secure authentication VMware Carbon Black - Endpoint detection and response (EDR) Responsibilities include: Deployment and configuration across the organization Policy management and enforcement Monitoring and incident response Integration with existing systems Manage relationships with technology vendors for hardware, software, security platforms, and IT services. Evaluate and select new technology partners as needed. Negotiate contracts, pricing, and service agreements. Ensure vendors meet security and compliance standards. Develop a long-term IT strategy aligned with TPG's growth and global workforce model. Evaluate new technologies that improve security, productivity, and operational efficiency. Standardize IT processes, tools, and support systems across the organization. Identity & Access Management Implement strong authentication and access controls across all systems. Manage role-based access controls and least-privilege access models. Ensure proper onboarding and offboarding procedures for system access. Establish and maintain an incident response framework. Investigate and respond to security incidents. Conduct risk assessments and implement mitigation strategies. Required Qualifications 8+ years of experience in IT leadership roles Experience managing IT infrastructure for distributed or remote-first organizations Hands on experience implementing endpoint security, IAM, and enterprise security platforms Strong experience managing IT vendors and security providers Knowledge of endpoint detection and response (EDR), zero trust architecture, and identity security Experience managing device fleets and endpoint management systems Strong understanding of cybersecurity frameworks and best practices Preferred Experience Experience working with compliance auditors or managed security providers Experience in SaaS, technology, or data-driven companies Experience supporting remote global teams Key Success Metrics Secure and scalable IT infrastructure supporting global operations Reduced security risk and improved compliance posture High employee satisfaction with IT systems and support Leadership & Culture The Director of IT will play a critical role in ensuring TPG's systems are secure, scalable, and reliable as the company continues to grow globally. This role requires someone who can combine technical expertise with strategic thinking and strong operational leadership. WHAT TPG PROVIDES FOR OUR TEAM MEMBERS Permanent Remote Work Model - No commuting. Work from wherever you're most productive. Competitive Compensation DOE. Mental Health Support - 3 Paid Mental Health Days per year Community Impact - 1 Paid Volunteer Day per year. Unlimited PTO - Take the time you need (after 90 days). Company-Provided Home Office Equipment - Laptop, desk, chair, etc. Independent Contractor Arrangement - This role will start as an independent contractor. The Pipeline Group is an EOE/Affirmative Action Minority/Female employer, and we welcome all to apply. We consider candidates regardless of race/color, religion, sex (including pregnancy, childbirth and related conditions), national origin/ethnicity, age, disability (intellectual, mental and physical), veteran status, marital status, ancestry, sexual orientation, gender identity and gender expression, genetic information, citizenship or any other personal characteristics protected by law. Please note we are not able to offer sponsorship of visas at this time. An offer of employment for this role will be contingent upon the successful completion of a background check. Internet Requirement: This is a fully remote role which requires a reliable high-speed internet connection with a minimum of 100 Mbps download, which will need to be verified.
Role Security Lead - DV Cleared Engagement UK Public Sector - Oracle ERP Managed Service Duration Length of the managed service contract Location UK only. Hybrid with attendance at client locations across the UK. Some client secure-area work required Security clearance DV (Developed Vetting) and UK Nationality - MANDATORY. Pre-cleared candidates strongly preferred Reports to Account / Engagement Director Key interfaces Client security lead, client Information & Security function, client Security Operations Centre, internal Service Delivery Manager, Incident Manager, third-party software vendor 1. Role purpose The Security Lead is our accountable security owner for the managed service. The role leads on, and has day-to-day operational responsibility for, service security - working in collaboration with the client's Information & Security function, the client Security Operations Centre (SOC), the internal delivery team, and the third-party software vendor. This is a contractually-named DV-cleared key role and is a PASS/FAIL requirement under the Conditions of Participation. 2. Context The service processes HR, Finance and Project data including OFFICIAL-SENSITIVE personal and financial data of UK civil servants and locally-engaged staff across a large international footprint. The contractual security regime spans UK Government security policy, NCSC HMG IAS5, GDPR/DPA 2018, PCI-DSS where applicable, and the client's Cyber Security Incident Response Plan. The SOC is operated 24 7 by the client and the Supplier is required to integrate, report into and support it. 3. Key accountabilities 3.1 Day-to-day security leadership • Lead and own day-to-day operational responsibility for service security across OPERATE and DEVELOP. • Advise the client on security status and matters; identify and address risks; continuously maintain and improve the security posture. • Act as the authoritative security voice in the client's Design Authority and Enterprise Architecture forums for security-impacting changes. 3.2 Clearance, vetting and access • Own the clearance pipeline: ensure all Supplier staff who hold, process or discuss client data are SC-cleared UK Nationals as a minimum, and that the named DV roles plus all 'full administrator' staff are DV-cleared UK Nationals. • Manage client-sponsored SC and DV applications from the start of Transition, conducting reasonable diligence checks in advance. • Oversee joiner/mover/leaver, privileged access management (PAM), role-based access control (RBAC), and the monthly audit report on RBAC and environment access. 3.3 Security operations and SOC integration • Provide the required reports to the client SOC in agreed format and frequency. • Support the SOC in resolving security incidents; document security use cases with the SOC; implement, maintain and support those SOC infrastructure components hosted within the cloud infrastructure. • Co-ordinate response to security incidents with the client's Cyber Security Incident Response Plan and ensure the Incident Manager and Service Delivery Manager are informed and aligned. 3.4 Assurance, audit and compliance • Treat information security issues, weaknesses or deficiencies identified by the client as Security Incidents under the client's Cyber Security Incident Response Plan. • Provide client auditors with access to security documentation, configurations of security-enforcing technologies, standards and procedures. • Collaborate with the client to plan and conduct annual PenTest and regular Disaster Recovery exercises. • Ensure GDPR / DPA 2018 obligations are met; oversee data retention, secure disposal, lawful processing, and Data Protection Impact Assessments where required. 3.5 Technical security controls • Define, document, agree and maintain Standard Operating Procedures for system administration and maintenance, with procedural controls per user role. • Ensure authorisation controls prevent extraction of information assets without legitimate need. • Ensure only client-issued devices are used to connect to the service in delivery. • Maintain a data back-up policy aligned to Business Impact Assessment and the client's retention policy. • Enforce removable-media scanning, network segregation, least-privilege access, location-based access controls, and unique user IDs. • Ensure all Supplier work on the service is conducted exclusively from within the UK from client-approved secure areas. 3.6 Communications and notification • Maintain regular communication with the client throughout the contract. • Promptly notify the client of any changes to directors, key security personnel, business ownership (including acquisitions) or physical operating locations. • Report any major security breaches within the Supplier's own ICT estate to the client. 4. Essential experience and skills • Substantial experience as an accountable security owner on a UK Central Government managed-service contract handling OFFICIAL-SENSITIVE data. • Deep working knowledge of NCSC HMG IAS5, NCSC Cyber Assessment Framework (CAF), Cyber Essentials Plus, ISO/IEC 27001, GDPR and DPA 2018. • Hands-on experience integrating with a UK Government SOC, including SIEM reporting, security use case design and incident response co-ordination. • Practical experience of Oracle Cloud security - OCI IAM, vault, network security, audit, PAM - and Oracle SaaS application security (HCM/ERP/EPM RBAC, segregation of duties, data masking). • Experience commissioning and overseeing PenTesting, vulnerability management, and Disaster Recovery exercises in a UK Government context. • Proven experience leading UK Government clearance pipelines: SC and DV sponsorship, due diligence, joiner/mover/leaver workflows. • Strong written communication for government-grade audit, assurance and governance reporting. • Comfortable as a named security accountable individual in formal governance and contractual reporting. 5. Essential clearance and eligibility • DV clearance and UK Nationality - contractually mandatory (PASS/FAIL). Pre-cleared candidates strongly preferred. Candidates without current DV may be considered only if SC-cleared with a credible DV application route through client sponsorship at the start of Transition. • Willing and able to work exclusively from within the UK. • Willing to attend client secure areas across the UK as required. 6. Desirable • CISSP, CISM, CCP (CESG Certified Professional) IA Architect / IA Auditor / SIRA, or equivalent senior security certifications. • Oracle Cloud Security certifications (OCI Security Professional, Oracle Cloud Identity & Security Architect). • Prior experience of an Oracle ERP-on-OCI security model at scale (HCM, ERP, EPM, VBCS, BI/Analytics). • Familiarity with UK Government security operating context, including overseas-network considerations, locally-engaged staff data, and HMG personnel security policy. • Experience supporting PCI-DSS compliance where payment card data is in scope. 7. Personal attributes • Authoritative without being abrasive - able to say 'no' to delivery pressure and explain why in business terms. • Detail-oriented on policy, controls and evidence; pragmatic on operational trade-offs. • Comfortable owning a named, individually-accountable role under public-sector contractual scrutiny. • Visible collaborator with client security counterparts, third-party vendors, and internal service leadership. 8. Key performance indicators • 100% of in-scope staff hold valid SC or DV clearance, with no operational delivery delayed by clearance gaps. • SOC reporting delivered in agreed format and frequency, with zero material reporting failures. • Annual PenTest and DR exercises completed on plan, with remediation tracked to closure. • Zero Category 1 information security breaches attributable to Supplier controls. • Monthly RBAC and environment-access audit reports delivered on time, with audit findings closed within agreed SLAs. • Clean external audit outcomes (internal audit, GIAA, or comparable).
30/05/2026
Full time
Role Security Lead - DV Cleared Engagement UK Public Sector - Oracle ERP Managed Service Duration Length of the managed service contract Location UK only. Hybrid with attendance at client locations across the UK. Some client secure-area work required Security clearance DV (Developed Vetting) and UK Nationality - MANDATORY. Pre-cleared candidates strongly preferred Reports to Account / Engagement Director Key interfaces Client security lead, client Information & Security function, client Security Operations Centre, internal Service Delivery Manager, Incident Manager, third-party software vendor 1. Role purpose The Security Lead is our accountable security owner for the managed service. The role leads on, and has day-to-day operational responsibility for, service security - working in collaboration with the client's Information & Security function, the client Security Operations Centre (SOC), the internal delivery team, and the third-party software vendor. This is a contractually-named DV-cleared key role and is a PASS/FAIL requirement under the Conditions of Participation. 2. Context The service processes HR, Finance and Project data including OFFICIAL-SENSITIVE personal and financial data of UK civil servants and locally-engaged staff across a large international footprint. The contractual security regime spans UK Government security policy, NCSC HMG IAS5, GDPR/DPA 2018, PCI-DSS where applicable, and the client's Cyber Security Incident Response Plan. The SOC is operated 24 7 by the client and the Supplier is required to integrate, report into and support it. 3. Key accountabilities 3.1 Day-to-day security leadership • Lead and own day-to-day operational responsibility for service security across OPERATE and DEVELOP. • Advise the client on security status and matters; identify and address risks; continuously maintain and improve the security posture. • Act as the authoritative security voice in the client's Design Authority and Enterprise Architecture forums for security-impacting changes. 3.2 Clearance, vetting and access • Own the clearance pipeline: ensure all Supplier staff who hold, process or discuss client data are SC-cleared UK Nationals as a minimum, and that the named DV roles plus all 'full administrator' staff are DV-cleared UK Nationals. • Manage client-sponsored SC and DV applications from the start of Transition, conducting reasonable diligence checks in advance. • Oversee joiner/mover/leaver, privileged access management (PAM), role-based access control (RBAC), and the monthly audit report on RBAC and environment access. 3.3 Security operations and SOC integration • Provide the required reports to the client SOC in agreed format and frequency. • Support the SOC in resolving security incidents; document security use cases with the SOC; implement, maintain and support those SOC infrastructure components hosted within the cloud infrastructure. • Co-ordinate response to security incidents with the client's Cyber Security Incident Response Plan and ensure the Incident Manager and Service Delivery Manager are informed and aligned. 3.4 Assurance, audit and compliance • Treat information security issues, weaknesses or deficiencies identified by the client as Security Incidents under the client's Cyber Security Incident Response Plan. • Provide client auditors with access to security documentation, configurations of security-enforcing technologies, standards and procedures. • Collaborate with the client to plan and conduct annual PenTest and regular Disaster Recovery exercises. • Ensure GDPR / DPA 2018 obligations are met; oversee data retention, secure disposal, lawful processing, and Data Protection Impact Assessments where required. 3.5 Technical security controls • Define, document, agree and maintain Standard Operating Procedures for system administration and maintenance, with procedural controls per user role. • Ensure authorisation controls prevent extraction of information assets without legitimate need. • Ensure only client-issued devices are used to connect to the service in delivery. • Maintain a data back-up policy aligned to Business Impact Assessment and the client's retention policy. • Enforce removable-media scanning, network segregation, least-privilege access, location-based access controls, and unique user IDs. • Ensure all Supplier work on the service is conducted exclusively from within the UK from client-approved secure areas. 3.6 Communications and notification • Maintain regular communication with the client throughout the contract. • Promptly notify the client of any changes to directors, key security personnel, business ownership (including acquisitions) or physical operating locations. • Report any major security breaches within the Supplier's own ICT estate to the client. 4. Essential experience and skills • Substantial experience as an accountable security owner on a UK Central Government managed-service contract handling OFFICIAL-SENSITIVE data. • Deep working knowledge of NCSC HMG IAS5, NCSC Cyber Assessment Framework (CAF), Cyber Essentials Plus, ISO/IEC 27001, GDPR and DPA 2018. • Hands-on experience integrating with a UK Government SOC, including SIEM reporting, security use case design and incident response co-ordination. • Practical experience of Oracle Cloud security - OCI IAM, vault, network security, audit, PAM - and Oracle SaaS application security (HCM/ERP/EPM RBAC, segregation of duties, data masking). • Experience commissioning and overseeing PenTesting, vulnerability management, and Disaster Recovery exercises in a UK Government context. • Proven experience leading UK Government clearance pipelines: SC and DV sponsorship, due diligence, joiner/mover/leaver workflows. • Strong written communication for government-grade audit, assurance and governance reporting. • Comfortable as a named security accountable individual in formal governance and contractual reporting. 5. Essential clearance and eligibility • DV clearance and UK Nationality - contractually mandatory (PASS/FAIL). Pre-cleared candidates strongly preferred. Candidates without current DV may be considered only if SC-cleared with a credible DV application route through client sponsorship at the start of Transition. • Willing and able to work exclusively from within the UK. • Willing to attend client secure areas across the UK as required. 6. Desirable • CISSP, CISM, CCP (CESG Certified Professional) IA Architect / IA Auditor / SIRA, or equivalent senior security certifications. • Oracle Cloud Security certifications (OCI Security Professional, Oracle Cloud Identity & Security Architect). • Prior experience of an Oracle ERP-on-OCI security model at scale (HCM, ERP, EPM, VBCS, BI/Analytics). • Familiarity with UK Government security operating context, including overseas-network considerations, locally-engaged staff data, and HMG personnel security policy. • Experience supporting PCI-DSS compliance where payment card data is in scope. 7. Personal attributes • Authoritative without being abrasive - able to say 'no' to delivery pressure and explain why in business terms. • Detail-oriented on policy, controls and evidence; pragmatic on operational trade-offs. • Comfortable owning a named, individually-accountable role under public-sector contractual scrutiny. • Visible collaborator with client security counterparts, third-party vendors, and internal service leadership. 8. Key performance indicators • 100% of in-scope staff hold valid SC or DV clearance, with no operational delivery delayed by clearance gaps. • SOC reporting delivered in agreed format and frequency, with zero material reporting failures. • Annual PenTest and DR exercises completed on plan, with remediation tracked to closure. • Zero Category 1 information security breaches attributable to Supplier controls. • Monthly RBAC and environment-access audit reports delivered on time, with audit findings closed within agreed SLAs. • Clean external audit outcomes (internal audit, GIAA, or comparable).
Job Description Purpose of the Role To manage the efficient delivery of large-scale technical projects and capabilities across the bank and collaborate with internal and external stakeholders to understand their needs and expectations throughout the software product lifecycle, adhering to agreed time, budget and quality requirements. Accountabilities Management of the delivery, resource allocation and improvement of complex technical project capabilities across the bank using Agile/Scrum methodologies for planning, stand ups, demos, retrospectives and the execution of sprints. Collaboration with customers and business teams to manage and implement customer trails to support the proposal of technically feasible solutions, and effort and timeline expectations. Collaboration with software engineers, quality teams, product managers and other engineering teams to deliver high quality products and features through the software project lifecycle aligned to the bank's objectives, regulation and security policies. Identification, assessment, and mitigation of risks associated with technical projects, to prepare the bank for potential challenges. Management of change requests and communication with stakeholders throughout the project lifecycle. Management of vendor relations involved in technical projects to ensure they deliver according to agreed terms. Stay abreast of the latest industry technology trends and technologies, to evaluate and adopt new approaches to improving delivery outcomes and to foster a culture of continuous learning, technical excellence and growth. Expectations To advise and influence decision making, contribute to policy development and take responsibility for operational effectiveness. Collaborate closely with other functions and business divisions. Lead a team performing complex tasks, using well developed professional knowledge and skills to deliver on work that impacts the whole business function. Set objectives and coach employees in pursuit of those objectives, appraisal of performance relative to objectives and determination of reward outcomes. Leadership Behaviours Listen and be authentic Energise and inspire Align across the enterprise Develop others All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship, and the Barclays Mindset to Empower, Challenge and Drive. Role Summary Join us as a Project Manager within Group Economic Crime COO at Barclays within the Case Management/Workflow portfolio. In this role you will manage a combination of legacy and green field case management projects, covering all aspects of delivery from project planning and creation, governance, risk & control, working with the scrum teams guiding and tracking delivery, financials, resource planning and producing status reports against milestones. Working within a medium sized UK and India team, the role holder will partner with change delivery teams to ensure key success criteria is met and monitor progress effectively through tools like Navigator and Jira. Qualifications A track record of creating and delivering complex projects (multiple delivery workstreams, data migration from legacy applications) within an Agile model. Previous experience with governance related activities such as project plan creation (using MS Project, Excel, PowerPoint) and tracking, resource forecasts, financials. Strong stakeholder management experience, including preparation of materials and presenting to stakeholders. Financial services or banking environment experience within a technology delivery team. Strong communication and influencing skills as well as analytical and problem solving skills. Agile certification or similar. Assessment on key critical skills such as risk and controls, change and transformation, business acumen, strategic thinking, digital and technology, and job specific technical skills. Location This role will be based in our Glasgow office. Barclays Culture Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. Our employees are self disciplined, hard working, curious, trustworthy, humble, and truthful. They make choices according to what is best for the team, they live for opportunities to collaborate and make a difference, and they make us the Top Workplace in the area.
30/05/2026
Full time
Job Description Purpose of the Role To manage the efficient delivery of large-scale technical projects and capabilities across the bank and collaborate with internal and external stakeholders to understand their needs and expectations throughout the software product lifecycle, adhering to agreed time, budget and quality requirements. Accountabilities Management of the delivery, resource allocation and improvement of complex technical project capabilities across the bank using Agile/Scrum methodologies for planning, stand ups, demos, retrospectives and the execution of sprints. Collaboration with customers and business teams to manage and implement customer trails to support the proposal of technically feasible solutions, and effort and timeline expectations. Collaboration with software engineers, quality teams, product managers and other engineering teams to deliver high quality products and features through the software project lifecycle aligned to the bank's objectives, regulation and security policies. Identification, assessment, and mitigation of risks associated with technical projects, to prepare the bank for potential challenges. Management of change requests and communication with stakeholders throughout the project lifecycle. Management of vendor relations involved in technical projects to ensure they deliver according to agreed terms. Stay abreast of the latest industry technology trends and technologies, to evaluate and adopt new approaches to improving delivery outcomes and to foster a culture of continuous learning, technical excellence and growth. Expectations To advise and influence decision making, contribute to policy development and take responsibility for operational effectiveness. Collaborate closely with other functions and business divisions. Lead a team performing complex tasks, using well developed professional knowledge and skills to deliver on work that impacts the whole business function. Set objectives and coach employees in pursuit of those objectives, appraisal of performance relative to objectives and determination of reward outcomes. Leadership Behaviours Listen and be authentic Energise and inspire Align across the enterprise Develop others All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship, and the Barclays Mindset to Empower, Challenge and Drive. Role Summary Join us as a Project Manager within Group Economic Crime COO at Barclays within the Case Management/Workflow portfolio. In this role you will manage a combination of legacy and green field case management projects, covering all aspects of delivery from project planning and creation, governance, risk & control, working with the scrum teams guiding and tracking delivery, financials, resource planning and producing status reports against milestones. Working within a medium sized UK and India team, the role holder will partner with change delivery teams to ensure key success criteria is met and monitor progress effectively through tools like Navigator and Jira. Qualifications A track record of creating and delivering complex projects (multiple delivery workstreams, data migration from legacy applications) within an Agile model. Previous experience with governance related activities such as project plan creation (using MS Project, Excel, PowerPoint) and tracking, resource forecasts, financials. Strong stakeholder management experience, including preparation of materials and presenting to stakeholders. Financial services or banking environment experience within a technology delivery team. Strong communication and influencing skills as well as analytical and problem solving skills. Agile certification or similar. Assessment on key critical skills such as risk and controls, change and transformation, business acumen, strategic thinking, digital and technology, and job specific technical skills. Location This role will be based in our Glasgow office. Barclays Culture Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. Our employees are self disciplined, hard working, curious, trustworthy, humble, and truthful. They make choices according to what is best for the team, they live for opportunities to collaborate and make a difference, and they make us the Top Workplace in the area.
About Us A career at Hitachi Rail will help create a legacy. With operations in every corner of the world, our work goes to the cutting edge of digital transformation and technology. From the multi cultural strength of our global organisation to the sustainable and innovative ways we work to bring people together, there's something for everyone to get stuck into. And that's where you come in. London, Greater London, United Kingdom (Hybrid) Our Opportunity We are currently looking for a Cyber Design Authority who will be the technical authority for all cybersecurity design activities across the SRS portfolio. You will provide strategic direction and expert oversight to ensure that all cyber practices, controls, and solutions meet required security standards, regulatory compliance, and operational effectiveness. You will be responsible for defining and implementing cybersecurity policies, standards, and governance frameworks, ensuring robust risk management, regulatory alignment, and assurance. This includes making certain that all technical, procedural, and operational controls are compliant and effectively aligned with business objectives. Working closely with security architects, engineers, SMEs, and delivery teams, you will drive a cohesive, proactive, and integrated approach to cybersecurity across SRS programmes and services. This is a hybrid role working a minimum of two days per week from our office in Canary Wharf. Key Responsibilities Analyse customer needs/requirements and assess solution architecture and technical choices. Ensure security solution compliance with customer needs, product policy, make team buy (MTB) strategy & applicable legislation, standards & regulations. Review technical security risks and opportunities and related mitigation plans throughout the bid or project. Ensure best trade off between customer requirements & product policy consistent with schedule, costs, MTB strategy & risks/ opportunities. Check the production and the maintenance/service aspects of the solution with the Production Process/Technology Manager (PPTM) and the Service Engineering Manager. Approve the technical specification and source selection of subsystems/products to be outsourced, by taking into account MTB policy, export restrictions and offset requirements. Check that the engineering environment for the solution is consistent with country/company instruction, and overall solution cost, technical risks & schedule. Ensure, with the support of engineering SMEs & safety stakeholders that solution design takes into account contract requirements and applicable security legislation, standards & regulations, and that related certification activities are performed correctly. Review and approve the completion of security specific integration, verification, validation and qualification results. Lead bid/project security engineering reviews and approve the security deliverables at each project decision milestone. Organise appropriate technical meetings and peer reviews together with the Engineering Delivery Manager and other technical stakeholders and experts, in order to perform the solution technical assessment and validation. Contribute to business strategy and product development as required. Interface with the client to define the solution. Keep abreast of technical, legislative and industry specific standards developments in security both within and outside of the company. Technical Skills and Experience Strong technical writing skills and excellent interpersonal communication skills. Expertise in cyber and information security solutions relevant to the company, e.g. urban signalling, mainline signalling, communication systems, integrated control systems, etc. Excellent understanding of risk assessment frameworks and compliance methodologies. Strong knowledge of business case development, resource planning, and effective budget management. Extensive experience across systems engineering lifecycle disciplines with a focus on security, including secure by design principles, requirements capture, modelling, analysis, system design, and independent verification and validation (IV&V). In depth knowledge and experience of full systems engineering lifecycles for large, complex systems. Expertise in industry specific security standards and legislation. Well proven technical/project experience in the development and application of security solutions to critical OT or IT control systems and/or safety critical systems. Additional Qualifications Mandatory: Qualified to Degree level (preferably Masters) in a relevant field, e.g. cyber security, networks, computer science, etc. Desirable: Certified or working towards a senior level security accreditation, such as CISSP, CISM, etc. Human Skills Proven track record of building and maintaining cross functional relationships to deliver outcomes that benefit both the immediate team and the wider business. Excellent presentation skills. Effective personal organisation and an ability to remain composed and focused under pressure. Demonstrated ability to lead, manage, mentor and coach a diverse team. Excellent problem solving ability, trade off skills and attention to detail. What to Expect We aim to complete a two stage interview process. The interviews will focus on technical and behavioural competencies. Reasonable adjustments are available with prior notice so please let the Talent Acquisition (TA) partner know if this would be necessary. To find out what reasonable adjustments are, and what might be available, your TA partner will be happy to discuss this with you. What We Can Offer We're committed to giving you opportunities to be your best. We believe in embracing the passion and potential of our people, and to achieve this we offer market leading training, development and experiences, along with the opportunity to be mentored and coached by some of the smartest minds in the industry. We hire from within as our first priority, so you'll have a myriad of opportunities within our diverse, global organisation. Flexibility Your health and well being matters to us and that's why we offer you the flexibility to do what's important to you; whether that's part time hours, job sharing, home working, or the ability to flex your start and finish times. Where possible, we support a working pattern that suits your lifestyle and helps you reach your ambitions. Equal Opportunity Statement At Hitachi Rail, there is a place for everyone. We welcome and value differences in background, age, gender, sexuality, family status, disability, race, nationality, ethnicity, religion, and world view. It is our commitment to create an inclusive environment - we are proud to be an equal opportunity employer. Security Clearance Some vacancies may require full Security Clearance which can require further evidence to be provided. For further details of the evidence required to apply for Baseline and Security Clearance please refer to the UK Government website.
30/05/2026
Full time
About Us A career at Hitachi Rail will help create a legacy. With operations in every corner of the world, our work goes to the cutting edge of digital transformation and technology. From the multi cultural strength of our global organisation to the sustainable and innovative ways we work to bring people together, there's something for everyone to get stuck into. And that's where you come in. London, Greater London, United Kingdom (Hybrid) Our Opportunity We are currently looking for a Cyber Design Authority who will be the technical authority for all cybersecurity design activities across the SRS portfolio. You will provide strategic direction and expert oversight to ensure that all cyber practices, controls, and solutions meet required security standards, regulatory compliance, and operational effectiveness. You will be responsible for defining and implementing cybersecurity policies, standards, and governance frameworks, ensuring robust risk management, regulatory alignment, and assurance. This includes making certain that all technical, procedural, and operational controls are compliant and effectively aligned with business objectives. Working closely with security architects, engineers, SMEs, and delivery teams, you will drive a cohesive, proactive, and integrated approach to cybersecurity across SRS programmes and services. This is a hybrid role working a minimum of two days per week from our office in Canary Wharf. Key Responsibilities Analyse customer needs/requirements and assess solution architecture and technical choices. Ensure security solution compliance with customer needs, product policy, make team buy (MTB) strategy & applicable legislation, standards & regulations. Review technical security risks and opportunities and related mitigation plans throughout the bid or project. Ensure best trade off between customer requirements & product policy consistent with schedule, costs, MTB strategy & risks/ opportunities. Check the production and the maintenance/service aspects of the solution with the Production Process/Technology Manager (PPTM) and the Service Engineering Manager. Approve the technical specification and source selection of subsystems/products to be outsourced, by taking into account MTB policy, export restrictions and offset requirements. Check that the engineering environment for the solution is consistent with country/company instruction, and overall solution cost, technical risks & schedule. Ensure, with the support of engineering SMEs & safety stakeholders that solution design takes into account contract requirements and applicable security legislation, standards & regulations, and that related certification activities are performed correctly. Review and approve the completion of security specific integration, verification, validation and qualification results. Lead bid/project security engineering reviews and approve the security deliverables at each project decision milestone. Organise appropriate technical meetings and peer reviews together with the Engineering Delivery Manager and other technical stakeholders and experts, in order to perform the solution technical assessment and validation. Contribute to business strategy and product development as required. Interface with the client to define the solution. Keep abreast of technical, legislative and industry specific standards developments in security both within and outside of the company. Technical Skills and Experience Strong technical writing skills and excellent interpersonal communication skills. Expertise in cyber and information security solutions relevant to the company, e.g. urban signalling, mainline signalling, communication systems, integrated control systems, etc. Excellent understanding of risk assessment frameworks and compliance methodologies. Strong knowledge of business case development, resource planning, and effective budget management. Extensive experience across systems engineering lifecycle disciplines with a focus on security, including secure by design principles, requirements capture, modelling, analysis, system design, and independent verification and validation (IV&V). In depth knowledge and experience of full systems engineering lifecycles for large, complex systems. Expertise in industry specific security standards and legislation. Well proven technical/project experience in the development and application of security solutions to critical OT or IT control systems and/or safety critical systems. Additional Qualifications Mandatory: Qualified to Degree level (preferably Masters) in a relevant field, e.g. cyber security, networks, computer science, etc. Desirable: Certified or working towards a senior level security accreditation, such as CISSP, CISM, etc. Human Skills Proven track record of building and maintaining cross functional relationships to deliver outcomes that benefit both the immediate team and the wider business. Excellent presentation skills. Effective personal organisation and an ability to remain composed and focused under pressure. Demonstrated ability to lead, manage, mentor and coach a diverse team. Excellent problem solving ability, trade off skills and attention to detail. What to Expect We aim to complete a two stage interview process. The interviews will focus on technical and behavioural competencies. Reasonable adjustments are available with prior notice so please let the Talent Acquisition (TA) partner know if this would be necessary. To find out what reasonable adjustments are, and what might be available, your TA partner will be happy to discuss this with you. What We Can Offer We're committed to giving you opportunities to be your best. We believe in embracing the passion and potential of our people, and to achieve this we offer market leading training, development and experiences, along with the opportunity to be mentored and coached by some of the smartest minds in the industry. We hire from within as our first priority, so you'll have a myriad of opportunities within our diverse, global organisation. Flexibility Your health and well being matters to us and that's why we offer you the flexibility to do what's important to you; whether that's part time hours, job sharing, home working, or the ability to flex your start and finish times. Where possible, we support a working pattern that suits your lifestyle and helps you reach your ambitions. Equal Opportunity Statement At Hitachi Rail, there is a place for everyone. We welcome and value differences in background, age, gender, sexuality, family status, disability, race, nationality, ethnicity, religion, and world view. It is our commitment to create an inclusive environment - we are proud to be an equal opportunity employer. Security Clearance Some vacancies may require full Security Clearance which can require further evidence to be provided. For further details of the evidence required to apply for Baseline and Security Clearance please refer to the UK Government website.
To view a previously saved application, please login to your candidatehomepage. Set up a job alert to receive updates on the latest Aston Martin Lagondajob opportunities. Apply now Job no: 512121 Work type: Full Time - Permanent Location: Gaydon, Warwickshire Categories: Information Technology If you're someone who understands the real commercial and operational impact of software, beyond just licences and tooling, this is a role where you can genuinely shape how an organisation controls, optimises and invests in its technology estate. Within our IT function, we partner closely with the wider business to deliver secure, stable and progressive technology solutions that support transformation and drive growth. This role sits right at the centre of that, giving you ownership of how software is governed, understood and used across the organisation. As our Software Asset Manager, you'll take accountability for building and evolving our enterprise-wide SAM capability. This isn't just about maintaining compliance, it's about setting the strategy, defining the standards, and creating a sustainable operating model that gives the business confidence in its technology decisions. You'll be the go-to authority on licence position, audit readiness and optimisation insight, helping senior stakeholders make informed decisions around renewals, vendor negotiations and future investments. Day to day, you'll lead the governance framework for SAM, setting clear policies and controls across the full lifecycle, from acquisition through to retirement. You'll work closely with Architecture, Procurement, Finance, Legal and Security to ensure all software decisions are aligned, compliant and commercially sound. You'll also own our approach to audits, managing publisher engagement and leading responses in a controlled, evidence-based way that protects the organisation from unnecessary risk or cost. A key part of the role is maintaining a trusted, accurate view of our software estate. You'll oversee the end-to-end SAM lifecycle, discovery, reconciliation, optimisation and renewal readiness, ensuring data quality is high and outputs are genuinely useful. From that, you'll translate insight into real actions, whether that's re-harvesting licences, right-sizing subscriptions or supporting complex commercial negotiations with data-led recommendations. You'll also take ownership of our SAM tooling capability, including ServiceNow SAM Pro, ensuring it's configured, integrated and governed in a way that produces decision-grade reporting. Alongside this, you'll define and deliver a clear KPI framework that gives visibility of compliance posture, audit readiness and cost optimisation opportunities to senior stakeholders. We're looking for someone who has operated at enterprise scale and can demonstrate experience building or leading a SAM function across hybrid environments. You'll be comfortable owning licence positions and audit defence, with a strong understanding of complex vendor licensing models, particularly across major publishers like Microsoft, Oracle, Adobe or IBM. Just as importantly, you'll be confident influencing across a matrix organisation, bringing stakeholders with you and driving adoption of standards and controls. Strong commercial awareness is key here. You'll know how to turn data into meaningful insight, and insight into tangible outcomes, whether that's cost savings, risk reduction or improved decision-making. Demonstrable experience with SAM tooling (ServiceNow SAM Pro) is essential. Experience with data governance and integration into wider ITSM or CMDB environments is also important. This role would suit someone who enjoys ownership, thrives on bringing structure and clarity to complex environments, and is motivated by making a real impact at an organisational level. Alongside the core role, you'll occasionally provide cover for finance-related SAM activities during periods of absence, ensuring continuity across critical compliance and optimisation work within agreed governance. We offer a hybrid working model, with an expectation of two days per week on site in Gaydon, alongside occasional travel to other locations as needed. If you're ready to take ownership of a capability that directly influences risk, cost and strategic decision-making, this is a great opportunity to do just that. Apply now to be part of shaping how we manage and maximise our software investment. Belong at Aston Martin At Aston Martin, we believe that the stunning beauty, craftsmanship, and artistry that define our brand come from the diverse voices and talents of our extraordinary team. We are committed to fostering a culture where everyone feels valued, respected, and empowered to thrive. Your unique perspectives, shaped by your education, culture, ethnicity, race, gender identity, sexual orientation, age, religion, abilities, and more, are what make us stronger and more innovative. We celebrate the richness of diversity and actively seek individuals who bring something new to the table. If you require any accommodations or support during the application process, please don't hesitate to reach out. We're here to ensure that you can bring your best, in every way. Let's build something remarkable together. The post holder will be required to comply with all policies and procedures issued by and on behalf of Aston Martin Lagonda Ltd Advertised: 26 May 2026 GMT Daylight Time Applications close: 09 Jun 2026 GMT Daylight Time
30/05/2026
Full time
To view a previously saved application, please login to your candidatehomepage. Set up a job alert to receive updates on the latest Aston Martin Lagondajob opportunities. Apply now Job no: 512121 Work type: Full Time - Permanent Location: Gaydon, Warwickshire Categories: Information Technology If you're someone who understands the real commercial and operational impact of software, beyond just licences and tooling, this is a role where you can genuinely shape how an organisation controls, optimises and invests in its technology estate. Within our IT function, we partner closely with the wider business to deliver secure, stable and progressive technology solutions that support transformation and drive growth. This role sits right at the centre of that, giving you ownership of how software is governed, understood and used across the organisation. As our Software Asset Manager, you'll take accountability for building and evolving our enterprise-wide SAM capability. This isn't just about maintaining compliance, it's about setting the strategy, defining the standards, and creating a sustainable operating model that gives the business confidence in its technology decisions. You'll be the go-to authority on licence position, audit readiness and optimisation insight, helping senior stakeholders make informed decisions around renewals, vendor negotiations and future investments. Day to day, you'll lead the governance framework for SAM, setting clear policies and controls across the full lifecycle, from acquisition through to retirement. You'll work closely with Architecture, Procurement, Finance, Legal and Security to ensure all software decisions are aligned, compliant and commercially sound. You'll also own our approach to audits, managing publisher engagement and leading responses in a controlled, evidence-based way that protects the organisation from unnecessary risk or cost. A key part of the role is maintaining a trusted, accurate view of our software estate. You'll oversee the end-to-end SAM lifecycle, discovery, reconciliation, optimisation and renewal readiness, ensuring data quality is high and outputs are genuinely useful. From that, you'll translate insight into real actions, whether that's re-harvesting licences, right-sizing subscriptions or supporting complex commercial negotiations with data-led recommendations. You'll also take ownership of our SAM tooling capability, including ServiceNow SAM Pro, ensuring it's configured, integrated and governed in a way that produces decision-grade reporting. Alongside this, you'll define and deliver a clear KPI framework that gives visibility of compliance posture, audit readiness and cost optimisation opportunities to senior stakeholders. We're looking for someone who has operated at enterprise scale and can demonstrate experience building or leading a SAM function across hybrid environments. You'll be comfortable owning licence positions and audit defence, with a strong understanding of complex vendor licensing models, particularly across major publishers like Microsoft, Oracle, Adobe or IBM. Just as importantly, you'll be confident influencing across a matrix organisation, bringing stakeholders with you and driving adoption of standards and controls. Strong commercial awareness is key here. You'll know how to turn data into meaningful insight, and insight into tangible outcomes, whether that's cost savings, risk reduction or improved decision-making. Demonstrable experience with SAM tooling (ServiceNow SAM Pro) is essential. Experience with data governance and integration into wider ITSM or CMDB environments is also important. This role would suit someone who enjoys ownership, thrives on bringing structure and clarity to complex environments, and is motivated by making a real impact at an organisational level. Alongside the core role, you'll occasionally provide cover for finance-related SAM activities during periods of absence, ensuring continuity across critical compliance and optimisation work within agreed governance. We offer a hybrid working model, with an expectation of two days per week on site in Gaydon, alongside occasional travel to other locations as needed. If you're ready to take ownership of a capability that directly influences risk, cost and strategic decision-making, this is a great opportunity to do just that. Apply now to be part of shaping how we manage and maximise our software investment. Belong at Aston Martin At Aston Martin, we believe that the stunning beauty, craftsmanship, and artistry that define our brand come from the diverse voices and talents of our extraordinary team. We are committed to fostering a culture where everyone feels valued, respected, and empowered to thrive. Your unique perspectives, shaped by your education, culture, ethnicity, race, gender identity, sexual orientation, age, religion, abilities, and more, are what make us stronger and more innovative. We celebrate the richness of diversity and actively seek individuals who bring something new to the table. If you require any accommodations or support during the application process, please don't hesitate to reach out. We're here to ensure that you can bring your best, in every way. Let's build something remarkable together. The post holder will be required to comply with all policies and procedures issued by and on behalf of Aston Martin Lagonda Ltd Advertised: 26 May 2026 GMT Daylight Time Applications close: 09 Jun 2026 GMT Daylight Time
GCS Recruitment is seeking a Cyber Security Project Manager Contractor to oversee security workstreams for M&A integration for a London-based gaming studio. This senior role involves managing cross-functional teams and ensuring compliance throughout the transition process. Key responsibilities include leading cyber security workstreams, creating project plans, addressing security risks, and implementing updated security controls. Candidates should have 5-10 years of relevant experience, particularly in M&A and stakeholder management.
30/05/2026
Full time
GCS Recruitment is seeking a Cyber Security Project Manager Contractor to oversee security workstreams for M&A integration for a London-based gaming studio. This senior role involves managing cross-functional teams and ensuring compliance throughout the transition process. Key responsibilities include leading cyber security workstreams, creating project plans, addressing security risks, and implementing updated security controls. Candidates should have 5-10 years of relevant experience, particularly in M&A and stakeholder management.
Job Description Purpose of the role To design, develop and improve software, utilising various engineering methodologies, that provides business, platform, and technology capabilities for our customers and colleagues. Accountabilities Development and delivery of high-quality software solutions by using industry aligned programming languages, frameworks, and tools. Ensuring that code is scalable, maintainable, and optimized for performance. Cross functional collaboration with product managers, designers, and other engineers to define software requirements, devise solution strategies, and ensure seamless integration and alignment with business objectives. Collaboration with peers, participation in code reviews, and promotion of a culture of code quality and knowledge sharing. Staying informed of industry technology trends and innovations and actively contributing to the organisation's technology communities to foster a culture of technical excellence and growth. Adherence to secure coding practices to mitigate vulnerabilities, protect sensitive data, and ensure secure software solutions. Implementation of effective unit testing practices to ensure proper code design, readability, and reliability. Assistant Vice President Expectations To advise and influence decision making, contribute to policy development and take responsibility for operational effectiveness. Collaborate closely with other functions/business divisions. Lead a team performing complex tasks, using well developed professional knowledge and skills to deliver on work that impacts the whole business function. Set objectives and coach employees in pursuit of those objectives, appraisal of performance relative to objectives and determination of reward outcomes. For People Leaders: demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: Listen and be authentic Energise and inspire Align across the enterprise Develop others For an individual contributor: lead collaborative assignments and guide team members through structured assignments, identify the need for inclusion of other areas of specialization to complete assignments. Identify new directions for assignments and/or projects, including cross functional methodologies or practices to meet required outcomes. Consult on complex issues, providing advice to People Leaders to support the resolution of escalated issues, identify ways to mitigate risk and develop new policies/procedures in support of the control and governance agenda. Take ownership for managing risk and strengthening controls in relation to the work performed. Engage in complex analysis of data from multiple sources, internal and external, to solve problems creatively and effectively. Communicating complex information and influencing or convincing stakeholders to achieve outcomes. Requirements To be successful in this role you should have: Experience with Permissions and Profiles using policy as code to define a set of permission roles, and other security model paradigms such as ReBAC, ABAC, and RBAC. Experience with Java, BDD testing concepts and Public Cloud (AWS). Understanding of authorisation and authentication technologies such as Policy as Code, IAM. Experience with Ping solutions (PingGateway, PingAM, PingIDM, PingDS). Some other highly desirable skills include: Willingness to constructively disrupt and challenge the norm. Relationship building skills, patience and resilience to change current thinking and working practices. Ability to translate technical concepts and solutions to both non technical and technical teams without losing the detail. Location This role will be based out of our Glasgow or Knutsford office.
30/05/2026
Full time
Job Description Purpose of the role To design, develop and improve software, utilising various engineering methodologies, that provides business, platform, and technology capabilities for our customers and colleagues. Accountabilities Development and delivery of high-quality software solutions by using industry aligned programming languages, frameworks, and tools. Ensuring that code is scalable, maintainable, and optimized for performance. Cross functional collaboration with product managers, designers, and other engineers to define software requirements, devise solution strategies, and ensure seamless integration and alignment with business objectives. Collaboration with peers, participation in code reviews, and promotion of a culture of code quality and knowledge sharing. Staying informed of industry technology trends and innovations and actively contributing to the organisation's technology communities to foster a culture of technical excellence and growth. Adherence to secure coding practices to mitigate vulnerabilities, protect sensitive data, and ensure secure software solutions. Implementation of effective unit testing practices to ensure proper code design, readability, and reliability. Assistant Vice President Expectations To advise and influence decision making, contribute to policy development and take responsibility for operational effectiveness. Collaborate closely with other functions/business divisions. Lead a team performing complex tasks, using well developed professional knowledge and skills to deliver on work that impacts the whole business function. Set objectives and coach employees in pursuit of those objectives, appraisal of performance relative to objectives and determination of reward outcomes. For People Leaders: demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: Listen and be authentic Energise and inspire Align across the enterprise Develop others For an individual contributor: lead collaborative assignments and guide team members through structured assignments, identify the need for inclusion of other areas of specialization to complete assignments. Identify new directions for assignments and/or projects, including cross functional methodologies or practices to meet required outcomes. Consult on complex issues, providing advice to People Leaders to support the resolution of escalated issues, identify ways to mitigate risk and develop new policies/procedures in support of the control and governance agenda. Take ownership for managing risk and strengthening controls in relation to the work performed. Engage in complex analysis of data from multiple sources, internal and external, to solve problems creatively and effectively. Communicating complex information and influencing or convincing stakeholders to achieve outcomes. Requirements To be successful in this role you should have: Experience with Permissions and Profiles using policy as code to define a set of permission roles, and other security model paradigms such as ReBAC, ABAC, and RBAC. Experience with Java, BDD testing concepts and Public Cloud (AWS). Understanding of authorisation and authentication technologies such as Policy as Code, IAM. Experience with Ping solutions (PingGateway, PingAM, PingIDM, PingDS). Some other highly desirable skills include: Willingness to constructively disrupt and challenge the norm. Relationship building skills, patience and resilience to change current thinking and working practices. Ability to translate technical concepts and solutions to both non technical and technical teams without losing the detail. Location This role will be based out of our Glasgow or Knutsford office.
This role is working on a hybrid basis, 3 days per week from any of our offices located in the UK (Staines-upon-Thames, Cheadle, Bristol, Peterborough) and 2 days per week from home Job Summary The ESI Business Security Office is a function of ADP's Global Security Organization (GSO). It enables the ADP Employer Services International (ESI) organization to effectively manage security within the business. BSO associates work closely with Business Units to ensure clients and associates are aligned with current security practices and policies. Each Business Unit has a Business Security Analyst (BSA) assigned, who works closely with (Senior) Management on all GSO-related topics. Scope of Responsibilities Business Resilience: support the business being resilient, with Business continuity planning and exercising, managing incidents and crisis. Risk Management: identify, document and monitor BU risks and controls within the global security taxonomy, provide risk reporting, advise on risk mitigation and remediation within the framework of GSO Operational Risk Management. Incident Management: provide governance over and support with established Business Incident and Technology Incident processes. Product Security: be a partner in ensuring product security by providing insight through reporting, conversations with product management and GSO subject matter experts. Relationship Management: use tools and bring value to our relationship with BU's at any level of the organization. Security Culture: provide associates with training, security engagement opportunities and other awareness communications. Support adoption of Security transformation programs. Business Value: position security as a market differentiator for Clients, Sales and support business growth. Use metrics and analysis to anticipate business needs. Technology Transformation: be an active partner and adviser to support ADP's technology and cybersecurity transformation. Deliver dedicated security services for the ESI UK, Ireland, Sweden and Netherlands Business Units. Act as a Security Consultant to the BU Senior Leaders, management and associates, to support them with security programs and resources. Help mitigate risk, protect privacy, and meet unexpected security challenges, anticipate emerging threats. Represent GSO's converged security organization covering a wide range of disciplines including Cyber, Incident Management, (Third Party) Risk Management, Business Continuity and Physical Security. Be a trusted advisor to the respective Business Units, effectively manage security risks and foster a transparent, cutting edge security culture. Provide consultation on prospect and client inquiries, audit requests and the review of security terms in contracts by engaging directly with client service, sales, and legal teams. Occasional travel to ADP, Vendor or Client sites may be required. Reporting Lines The Business Security Analyst reports into the EMEA Senior Director Business Security Office whose scope and team cover the Netherlands, Germany, Poland, France, Switzerland, Italy, Spain, Romania, Tunisia, UK, Ireland and Sweden. The Business Security Analyst identifies their own tasks within their area of responsibility and reports progress and deliverables within the respective Business Units and direct reporting lines, without others providing operational task management. Knowledge and Skill Requirements Bachelor's or Master's degree preferred. English language fluency required. Information Security related certifications and security product certifications are desirable. Security and/or risk management experience in a large and complex business environment. Experience in business process improvement or project management. Knowledge of security methodologies, policies, (industry)standards, certifications and best practices. Knowledge of information systems, infrastructure, operations and software development. Proficiency with MS Office 365 applications. Basic knowledge of HR or payroll processes is a plus. Soft Skills Results oriented self-starter who likes to work independently in a multicultural environment. Client-focused and business-oriented individual who understands the impact of security changes on clients and business. Visible relationship builder who can convince and lead others without managerial responsibility. Impactful communication skills on all operational and leadership levels. Ability to recognize and deal appropriately with sensitive and confidential information. Detail oriented and able to meet inflexible deadlines. Ability to quickly learn new procedures, skills, and techniques. Potential to demonstrate and grow into executive presence and influential leadership. Diversity, Equity, Inclusion & Equal Employment Opportunity at ADP ADP is committed to an inclusive, diverse and equitable workplace, and is further committed to providing equal employment opportunities regardless of any protected characteristic including: race, color, genetic information, creed, national origin, religion, sex, affectionate or sexual orientation, gender identity or expression, lawful alien status, ancestry, age, marital status, protected veteran status or disability. Hiring decisions are based upon ADP's operating needs, and applicant merit including, but not limited to, qualifications, experience, availability, cooperation, and job performance. Ethics at ADP ADP has a long, proud history of conducting business with the highest ethical standards and full compliance with all applicable laws. We also expect our people to uphold our values with the highest level of integrity and behave in a manner that fosters an honest and respectful workplace. Click to learn more about ADP's culture and our full set of values.
30/05/2026
Full time
This role is working on a hybrid basis, 3 days per week from any of our offices located in the UK (Staines-upon-Thames, Cheadle, Bristol, Peterborough) and 2 days per week from home Job Summary The ESI Business Security Office is a function of ADP's Global Security Organization (GSO). It enables the ADP Employer Services International (ESI) organization to effectively manage security within the business. BSO associates work closely with Business Units to ensure clients and associates are aligned with current security practices and policies. Each Business Unit has a Business Security Analyst (BSA) assigned, who works closely with (Senior) Management on all GSO-related topics. Scope of Responsibilities Business Resilience: support the business being resilient, with Business continuity planning and exercising, managing incidents and crisis. Risk Management: identify, document and monitor BU risks and controls within the global security taxonomy, provide risk reporting, advise on risk mitigation and remediation within the framework of GSO Operational Risk Management. Incident Management: provide governance over and support with established Business Incident and Technology Incident processes. Product Security: be a partner in ensuring product security by providing insight through reporting, conversations with product management and GSO subject matter experts. Relationship Management: use tools and bring value to our relationship with BU's at any level of the organization. Security Culture: provide associates with training, security engagement opportunities and other awareness communications. Support adoption of Security transformation programs. Business Value: position security as a market differentiator for Clients, Sales and support business growth. Use metrics and analysis to anticipate business needs. Technology Transformation: be an active partner and adviser to support ADP's technology and cybersecurity transformation. Deliver dedicated security services for the ESI UK, Ireland, Sweden and Netherlands Business Units. Act as a Security Consultant to the BU Senior Leaders, management and associates, to support them with security programs and resources. Help mitigate risk, protect privacy, and meet unexpected security challenges, anticipate emerging threats. Represent GSO's converged security organization covering a wide range of disciplines including Cyber, Incident Management, (Third Party) Risk Management, Business Continuity and Physical Security. Be a trusted advisor to the respective Business Units, effectively manage security risks and foster a transparent, cutting edge security culture. Provide consultation on prospect and client inquiries, audit requests and the review of security terms in contracts by engaging directly with client service, sales, and legal teams. Occasional travel to ADP, Vendor or Client sites may be required. Reporting Lines The Business Security Analyst reports into the EMEA Senior Director Business Security Office whose scope and team cover the Netherlands, Germany, Poland, France, Switzerland, Italy, Spain, Romania, Tunisia, UK, Ireland and Sweden. The Business Security Analyst identifies their own tasks within their area of responsibility and reports progress and deliverables within the respective Business Units and direct reporting lines, without others providing operational task management. Knowledge and Skill Requirements Bachelor's or Master's degree preferred. English language fluency required. Information Security related certifications and security product certifications are desirable. Security and/or risk management experience in a large and complex business environment. Experience in business process improvement or project management. Knowledge of security methodologies, policies, (industry)standards, certifications and best practices. Knowledge of information systems, infrastructure, operations and software development. Proficiency with MS Office 365 applications. Basic knowledge of HR or payroll processes is a plus. Soft Skills Results oriented self-starter who likes to work independently in a multicultural environment. Client-focused and business-oriented individual who understands the impact of security changes on clients and business. Visible relationship builder who can convince and lead others without managerial responsibility. Impactful communication skills on all operational and leadership levels. Ability to recognize and deal appropriately with sensitive and confidential information. Detail oriented and able to meet inflexible deadlines. Ability to quickly learn new procedures, skills, and techniques. Potential to demonstrate and grow into executive presence and influential leadership. Diversity, Equity, Inclusion & Equal Employment Opportunity at ADP ADP is committed to an inclusive, diverse and equitable workplace, and is further committed to providing equal employment opportunities regardless of any protected characteristic including: race, color, genetic information, creed, national origin, religion, sex, affectionate or sexual orientation, gender identity or expression, lawful alien status, ancestry, age, marital status, protected veteran status or disability. Hiring decisions are based upon ADP's operating needs, and applicant merit including, but not limited to, qualifications, experience, availability, cooperation, and job performance. Ethics at ADP ADP has a long, proud history of conducting business with the highest ethical standards and full compliance with all applicable laws. We also expect our people to uphold our values with the highest level of integrity and behave in a manner that fosters an honest and respectful workplace. Click to learn more about ADP's culture and our full set of values.
As a Product Associate in the Salesforce team at JP Morgan Personal Investing, you contribute to the team by leveraging your expertise in product development and optimization to make a significant impact, supported by user research and internal stakeholder feedback to fuel the creation of innovative products and continuously improve existing offerings for our internal customers. Collaborate closely with cross functional teams and play a crucial role in shaping the future of our platform and ongoing success. Job responsibilities Partners with the Product Manager to identify new product opportunities that reflect the needs of our stakeholders through ongoing discovery Supports the collection of user research and business processes mapping to inform the strategic product roadmap and provide insight on potential product features that provide value to stakeholders Owns end to end delivery of entire features and contributes to key initiatives Considers and plans for upstream and downstream implications of new product features on the overall platform experience Writes the requirements, epics, and user stories to support product development Acts as a scrum master to coordinate sprint activities for the delivery team Coordinates and participate in peer and business testing to ensure new solutions meet the requirements and are ready for production rollout Supports and trains end-users to drive adoption and maximize the platform's capabilities Partners with cross functional teams to assist with broader Salesforce initiatives and improvements Participates in release and change management activities, compliance with the firm's risk, controls, and regulatory standards Analyzes, tracks, and evaluates product metrics across the product development life cycle Configures complex reports and dashboards to enhance service operations Required qualifications, capabilities, and skills Experience or equivalent expertise in product management or a relevant domain area Proficient knowledge of the product development life cycle Experience in product life cycle activities including discovery and requirements definition Exposure to operational management and change readiness work streams Developing knowledge of data analytics and data literacy Previous experience with the Salesforce platform, ideally as an Administrator or Consultant including but not limited to reporting & dashboards, standard data model and object relationships, security model, sales & service cloud capabilities Preferred qualifications, capabilities, and skills Salesforce Administrator certification Excellent understanding of standard Salesforce object relationships, particularly unique ones such as Person Accounts, Activities, Opportunities etc. Excellent understanding of the standard Salesforce sharing model including role hierarchy, sharing rules, permission sets etc. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success. The Digital team is dedicated to creating innovative, industry leading products and experiences that help customers access, share and control their financial data so they can make smart decisions with their money.
30/05/2026
Full time
As a Product Associate in the Salesforce team at JP Morgan Personal Investing, you contribute to the team by leveraging your expertise in product development and optimization to make a significant impact, supported by user research and internal stakeholder feedback to fuel the creation of innovative products and continuously improve existing offerings for our internal customers. Collaborate closely with cross functional teams and play a crucial role in shaping the future of our platform and ongoing success. Job responsibilities Partners with the Product Manager to identify new product opportunities that reflect the needs of our stakeholders through ongoing discovery Supports the collection of user research and business processes mapping to inform the strategic product roadmap and provide insight on potential product features that provide value to stakeholders Owns end to end delivery of entire features and contributes to key initiatives Considers and plans for upstream and downstream implications of new product features on the overall platform experience Writes the requirements, epics, and user stories to support product development Acts as a scrum master to coordinate sprint activities for the delivery team Coordinates and participate in peer and business testing to ensure new solutions meet the requirements and are ready for production rollout Supports and trains end-users to drive adoption and maximize the platform's capabilities Partners with cross functional teams to assist with broader Salesforce initiatives and improvements Participates in release and change management activities, compliance with the firm's risk, controls, and regulatory standards Analyzes, tracks, and evaluates product metrics across the product development life cycle Configures complex reports and dashboards to enhance service operations Required qualifications, capabilities, and skills Experience or equivalent expertise in product management or a relevant domain area Proficient knowledge of the product development life cycle Experience in product life cycle activities including discovery and requirements definition Exposure to operational management and change readiness work streams Developing knowledge of data analytics and data literacy Previous experience with the Salesforce platform, ideally as an Administrator or Consultant including but not limited to reporting & dashboards, standard data model and object relationships, security model, sales & service cloud capabilities Preferred qualifications, capabilities, and skills Salesforce Administrator certification Excellent understanding of standard Salesforce object relationships, particularly unique ones such as Person Accounts, Activities, Opportunities etc. Excellent understanding of the standard Salesforce sharing model including role hierarchy, sharing rules, permission sets etc. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success. The Digital team is dedicated to creating innovative, industry leading products and experiences that help customers access, share and control their financial data so they can make smart decisions with their money.
Overview As part of the EMEA Technology (TEC) function, the Risk & Control pillar partners with the business to ensure technology risks are identified, managed and reported effectively, and that controls are designed and operating to protect our clients, services and data. Main Purpose of the Role Lead the end-to-end validation of audit and self identified issue closures across EMEA TEC. The role ensures that remediation is complete, effective and sustainable, and that closure evidence meets Internal Audit (IA), 2LOD and regulatory standards. The post holder will operate as the independent quality gate for issue closure, providing challenge, coaching and independent review of action plans, artefacts and control performance. The role requires active ongoing engagement with engineering teams and internal audit teams through the issue lifecycle to ensure work is on track, meeting expectations and positioned to successfully mitigate risk. Key Responsibilities Own the independent validation process for technology audit and risk issues, confirming remediation is complete, risks are mitigated and residual risk is acceptable. Define and maintain issue validation standards, templates and evidence checklists aligned to IA methodology, 2LOD requirements and relevant regulations (e.g., DORA, SOX). Perform detailed evidence reviews (design and operating effectiveness) including sampling, re performance and walkthroughs; document outcomes in clear working papers. Partner with control owners to agree closure criteria up front; provide challenge to action plans to ensure root causes are addressed and controls are embedded sustainably. Track remediation progress on key issues and identify risks to effective closure. Support and QA transparent closure packs for IA review. Support regulatory interactions and external audits by providing high quality validation artefacts and concise status reporting. Champion a strong risk & control culture across TEC; coach product and engineering teams on effective remediation and durable control design. Work Experience (Essential) Risk Management / Internal Audit / External Audit within a highly regulated international organisation; Technology Risk Management, Cyber Security, SOX and other regulations. Preferred: Banking / Finance experience highly preferred. Skills and Experience Deep understanding of IT general controls and application controls, and familiarity with frameworks such as COBIT, NIST, CRI and ISO 27001. Demonstrable experience in 1LOD technology risk & controls, Internal Audit, or 2LOD oversight within financial services. Hands on experience within Internal and/or External Audit would be highly beneficial. Strong knowledge of regulatory requirements relevant to technology (e.g., DORA, SOX 404, EBA/ECB ICT expectations) and audit standards. Hands on experience validating remediation and control effectiveness, including sampling methods, evidence sufficiency and documentation standards. Excellent communication and influencing skills with the confidence to challenge senior stakeholders constructively. Superior written skills with the ability to craft concise closure rationales and audit ready documentation. Personal Requirements Self motivated, organised and delivery focused; able to manage multiple high severity issues to tight deadlines. Analytical and objective with meticulous attention to detail; applies sound judgement under pressure. Data literate, curious and comfortable learning new tools and technologies for evidence gathering and analysis. Collaborative and inclusive; builds strong partnerships with technology, risk and audit teams. Strategic thinker who can distil complex technical topics for non technical audiences. We are open to considering flexible working requests in line with organisational requirements. EEO Statement MUFG is committed to embracing diversity and building an inclusive culture where all employees are valued, respected and their opinions count. We support the principles of equality, diversity and inclusion in recruitment and employment, and oppose all forms of discrimination on the grounds of age, sex, gender, sexual orientation, disability, pregnancy and maternity, race, gender reassignment, religion or belief and marriage or civil partnership. We make our recruitment decisions in a non discriminatory manner in accordance with our commitment to identifying the right skills for the right role and our obligations under the law. At MUFG, our colleagues are our greatest assets. Our Culture Principles provide a roadmap for how each of our colleagues must think and act to become more client obsessed, inclusive and innovative. They reflect who we are, who we want to be and what we expect from one another. We are excited to see you take the next step in exploring a career with us and encourage you to spend more time reviewing them!
30/05/2026
Full time
Overview As part of the EMEA Technology (TEC) function, the Risk & Control pillar partners with the business to ensure technology risks are identified, managed and reported effectively, and that controls are designed and operating to protect our clients, services and data. Main Purpose of the Role Lead the end-to-end validation of audit and self identified issue closures across EMEA TEC. The role ensures that remediation is complete, effective and sustainable, and that closure evidence meets Internal Audit (IA), 2LOD and regulatory standards. The post holder will operate as the independent quality gate for issue closure, providing challenge, coaching and independent review of action plans, artefacts and control performance. The role requires active ongoing engagement with engineering teams and internal audit teams through the issue lifecycle to ensure work is on track, meeting expectations and positioned to successfully mitigate risk. Key Responsibilities Own the independent validation process for technology audit and risk issues, confirming remediation is complete, risks are mitigated and residual risk is acceptable. Define and maintain issue validation standards, templates and evidence checklists aligned to IA methodology, 2LOD requirements and relevant regulations (e.g., DORA, SOX). Perform detailed evidence reviews (design and operating effectiveness) including sampling, re performance and walkthroughs; document outcomes in clear working papers. Partner with control owners to agree closure criteria up front; provide challenge to action plans to ensure root causes are addressed and controls are embedded sustainably. Track remediation progress on key issues and identify risks to effective closure. Support and QA transparent closure packs for IA review. Support regulatory interactions and external audits by providing high quality validation artefacts and concise status reporting. Champion a strong risk & control culture across TEC; coach product and engineering teams on effective remediation and durable control design. Work Experience (Essential) Risk Management / Internal Audit / External Audit within a highly regulated international organisation; Technology Risk Management, Cyber Security, SOX and other regulations. Preferred: Banking / Finance experience highly preferred. Skills and Experience Deep understanding of IT general controls and application controls, and familiarity with frameworks such as COBIT, NIST, CRI and ISO 27001. Demonstrable experience in 1LOD technology risk & controls, Internal Audit, or 2LOD oversight within financial services. Hands on experience within Internal and/or External Audit would be highly beneficial. Strong knowledge of regulatory requirements relevant to technology (e.g., DORA, SOX 404, EBA/ECB ICT expectations) and audit standards. Hands on experience validating remediation and control effectiveness, including sampling methods, evidence sufficiency and documentation standards. Excellent communication and influencing skills with the confidence to challenge senior stakeholders constructively. Superior written skills with the ability to craft concise closure rationales and audit ready documentation. Personal Requirements Self motivated, organised and delivery focused; able to manage multiple high severity issues to tight deadlines. Analytical and objective with meticulous attention to detail; applies sound judgement under pressure. Data literate, curious and comfortable learning new tools and technologies for evidence gathering and analysis. Collaborative and inclusive; builds strong partnerships with technology, risk and audit teams. Strategic thinker who can distil complex technical topics for non technical audiences. We are open to considering flexible working requests in line with organisational requirements. EEO Statement MUFG is committed to embracing diversity and building an inclusive culture where all employees are valued, respected and their opinions count. We support the principles of equality, diversity and inclusion in recruitment and employment, and oppose all forms of discrimination on the grounds of age, sex, gender, sexual orientation, disability, pregnancy and maternity, race, gender reassignment, religion or belief and marriage or civil partnership. We make our recruitment decisions in a non discriminatory manner in accordance with our commitment to identifying the right skills for the right role and our obligations under the law. At MUFG, our colleagues are our greatest assets. Our Culture Principles provide a roadmap for how each of our colleagues must think and act to become more client obsessed, inclusive and innovative. They reflect who we are, who we want to be and what we expect from one another. We are excited to see you take the next step in exploring a career with us and encourage you to spend more time reviewing them!
Vice President, Business Information Security OfficerApplylocations: Londontime type: Full timeposted on: Posted Todayjob requisition id: -WD Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.Corporate Technology is accountable for the operation, development and support of all applications across all areas of the business. Corporate Technology ensures IT strategy, architecture and solutions are aligned to business requirements. The BISO role is part of the IT Security team. IT Security are collectively responsible for the following areas: Cyber Support and Engineering, Security Operations Centre covering pen tests, red and blue teams, Cyber and Risk Change portfolio, Threat Intelligence and Vulnerability Management for the Group and Identity and Access Management. NUMBER OF DIRECT REPORTS 2 MAIN PURPOSE OF THE ROLE Responsible for providing strategic information security leadership and oversight across all business units in the region. This role bridges global security strategy and regional business execution, ensuring that security, risk, and compliance objectives are effectively implemented, measured, and governed.The position partners closely with regional executives, technology leadership, and global security functions to embed a culture of security, drive control adoption, and maintain regulatory confidence.This role will work alongside the EMEA regional CISO on supporting the strategy, initiatives and roadmap for information security in MUFG EMEA. Working with key stakeholders internally to help embed security into the culture, whilst embedding technical controls into the mission critical business systems:Risk Advisory & Control Adoption Serve as the trusted advisor to business and technology units on security risks and control implementation. Support adoption of global security controls and standards within regional operations. Provide security input on new business initiatives, digital transformation, and third-party relationships.2. Security Training & Awareness Develop, tailor, and oversee delivery of security awareness programs by business line. Drive execution of phishing simulations and targeted learning interventions. Measure awareness effectiveness and report to management.3. Security Champion Network Establish and maintain a regional security champion community within business and operations teams. Promote local ownership of security best practices and risk reduction initiatives. Provide ongoing engagement, training, and recognition programs for champions.4. Security Strategy, Planning & Reporting Translate global and regional security objectives into actionable EMEA programs. Develop strategic plans, key risk metrics (KRIs/KPIs), and executive dashboards. Contribute to quarterly and annual reporting cycles for CISO and business leadership.5. Finance, Budgeting & Resourcing Support regional security budgeting, forecasting, and resource allocation. Track spend against plan and provide variance analysis. Assist in developing business cases for new initiatives or investments.6. Security Program Governance Oversee the implementation and governance of global security programs in EMEA. Ensure adherence to enterprise security policies and frameworks. Coordinate across multiple stakeholders to maintain governance and accountability.7. Risk, Compliance & Audit Coordination Act as the single point of contact for IT Security related audits and compliance engagements. Manage audit readiness, evidence coordination, and remediation tracking. Maintain strong relationships with internal audit, compliance, and regulatory teams.8. Reporting & Global/Regional Coordination Coordinate EMEA security reporting and represent the region in global BISO forums. Ensure consistency of risk posture and alignment with global metrics and governance. Provide regional input into global policy updates and program design. KEY RESPONSIBILITIES Communication & Training Manage the Cyber & Risk training program. Ensuring Cyber integration with the business and technology. Communicating Risk & Cyber information across Bank EMEA and Securities. Be an escalation point for concerns about IT Security. Be a positive collaborator. People Management Ensure that the function is appropriately organised and adequately resourced by staff with appropriate skillsets to achieve its strategic objectives. Lead, direct and manage staff within the function to ensure that they: + Understand the responsibilities applicable to their roles + Comply with the firm's policies and procedures + Conduct themselves in a manner commensurate with the firm's values Actively manage performance, develop talent, identify key positions and persons and create sustainable success plans. Oversee appropriate training is in place to fulfil current and future skill requirements. Culture and Leadership Actively lead the integration of Bank and Securities technology functions. Promote the MUFG values-led culture which is inclusive and diverse. Promote a dynamic, delivery driven culture that works alongside business units to provide responsive resolutions and value driven solutions. Collective leadership by example on staff cyber education and awareness to embed a proactive cyber culture. Find ways to strengthen working relationships with stakeholders, including business teams. Lead by example in building relationships across the bank, establishing a stronger peer network and helping to strengthen collaboration. Build strong relationships with internal and external stakeholders to understand industry best practice, influence change and promote technical credibility. WORK EXPERIENCE Experienced in information security, technology risk, or related disciplines within financial services sector. Experienced in IT security and control policy with specific experience of FFEIC, SOX, COBIT, NIST, CRI Profile and ISO standards. Conversant in the security & risk trends across banking and other industries. Experienced with the Defence in Depth approach Strong track record of managing teams and building effective partnerships with peers. Strong experience in delivering training Professional information security certifications (i.e. CISSP, CISM, CRISC or similar experience). Cloud Security experience and a good understanding of privacy legislation (Data Protection Act 2018 / GDPR). SKILLS AND EXPERIENCE Functional / Technical Competencies: Strong strategic and analytical thinking. Excellent communication and stakeholder management. Proven ability to balance technical, business, and regulatory priorities. Collaborative, pragmatic, and outcomes-driven leadership style. A deep understanding of IT and Cyber Security: + Defence in Depth model. + Network defence, IDS and DMZ + Network protocols and firewall standards + Detective monitoring - SIEM + Vulnerability Management + Access and Privileged Access Management Experienced in writing and maintaining IT documents, such as standards and procedures. Demonstrates an understanding of strategic business and IT issues impacting the financial services market. Strong understanding of risk and its application across technology and the business. Good understanding of project lifecycles. Education / Qualifications: Degree educated and / or equivalent experience. PERSONAL REQUIREMENTS Excellent Leadership skills Excellent communication skills Ability to manage constructive conflict effectively Strong facilitation skills Ability to build strong and lasting relationships across the bank Results driven, with a strong sense of accountability, focused on business outcomes A proactive, motivated approach. The ability to operate with urgency and prioritise work accordingly Strong decision-making skills, the ability to demonstrate sound judgement A structured and logical approach to work Strong problem-solving skills A creative and innovative approach to work Excellent interpersonal skills Excellent attention to detail and accuracy Strong numerical skills A confident approach, with the ability to provide clear direction to your team Excellent managerial/leadership experience The ability to articulate and implement the vision/strategy for the planning departmentWe are open to considering flexible working requests in line with organisational requirements.
30/05/2026
Full time
Vice President, Business Information Security OfficerApplylocations: Londontime type: Full timeposted on: Posted Todayjob requisition id: -WD Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.Corporate Technology is accountable for the operation, development and support of all applications across all areas of the business. Corporate Technology ensures IT strategy, architecture and solutions are aligned to business requirements. The BISO role is part of the IT Security team. IT Security are collectively responsible for the following areas: Cyber Support and Engineering, Security Operations Centre covering pen tests, red and blue teams, Cyber and Risk Change portfolio, Threat Intelligence and Vulnerability Management for the Group and Identity and Access Management. NUMBER OF DIRECT REPORTS 2 MAIN PURPOSE OF THE ROLE Responsible for providing strategic information security leadership and oversight across all business units in the region. This role bridges global security strategy and regional business execution, ensuring that security, risk, and compliance objectives are effectively implemented, measured, and governed.The position partners closely with regional executives, technology leadership, and global security functions to embed a culture of security, drive control adoption, and maintain regulatory confidence.This role will work alongside the EMEA regional CISO on supporting the strategy, initiatives and roadmap for information security in MUFG EMEA. Working with key stakeholders internally to help embed security into the culture, whilst embedding technical controls into the mission critical business systems:Risk Advisory & Control Adoption Serve as the trusted advisor to business and technology units on security risks and control implementation. Support adoption of global security controls and standards within regional operations. Provide security input on new business initiatives, digital transformation, and third-party relationships.2. Security Training & Awareness Develop, tailor, and oversee delivery of security awareness programs by business line. Drive execution of phishing simulations and targeted learning interventions. Measure awareness effectiveness and report to management.3. Security Champion Network Establish and maintain a regional security champion community within business and operations teams. Promote local ownership of security best practices and risk reduction initiatives. Provide ongoing engagement, training, and recognition programs for champions.4. Security Strategy, Planning & Reporting Translate global and regional security objectives into actionable EMEA programs. Develop strategic plans, key risk metrics (KRIs/KPIs), and executive dashboards. Contribute to quarterly and annual reporting cycles for CISO and business leadership.5. Finance, Budgeting & Resourcing Support regional security budgeting, forecasting, and resource allocation. Track spend against plan and provide variance analysis. Assist in developing business cases for new initiatives or investments.6. Security Program Governance Oversee the implementation and governance of global security programs in EMEA. Ensure adherence to enterprise security policies and frameworks. Coordinate across multiple stakeholders to maintain governance and accountability.7. Risk, Compliance & Audit Coordination Act as the single point of contact for IT Security related audits and compliance engagements. Manage audit readiness, evidence coordination, and remediation tracking. Maintain strong relationships with internal audit, compliance, and regulatory teams.8. Reporting & Global/Regional Coordination Coordinate EMEA security reporting and represent the region in global BISO forums. Ensure consistency of risk posture and alignment with global metrics and governance. Provide regional input into global policy updates and program design. KEY RESPONSIBILITIES Communication & Training Manage the Cyber & Risk training program. Ensuring Cyber integration with the business and technology. Communicating Risk & Cyber information across Bank EMEA and Securities. Be an escalation point for concerns about IT Security. Be a positive collaborator. People Management Ensure that the function is appropriately organised and adequately resourced by staff with appropriate skillsets to achieve its strategic objectives. Lead, direct and manage staff within the function to ensure that they: + Understand the responsibilities applicable to their roles + Comply with the firm's policies and procedures + Conduct themselves in a manner commensurate with the firm's values Actively manage performance, develop talent, identify key positions and persons and create sustainable success plans. Oversee appropriate training is in place to fulfil current and future skill requirements. Culture and Leadership Actively lead the integration of Bank and Securities technology functions. Promote the MUFG values-led culture which is inclusive and diverse. Promote a dynamic, delivery driven culture that works alongside business units to provide responsive resolutions and value driven solutions. Collective leadership by example on staff cyber education and awareness to embed a proactive cyber culture. Find ways to strengthen working relationships with stakeholders, including business teams. Lead by example in building relationships across the bank, establishing a stronger peer network and helping to strengthen collaboration. Build strong relationships with internal and external stakeholders to understand industry best practice, influence change and promote technical credibility. WORK EXPERIENCE Experienced in information security, technology risk, or related disciplines within financial services sector. Experienced in IT security and control policy with specific experience of FFEIC, SOX, COBIT, NIST, CRI Profile and ISO standards. Conversant in the security & risk trends across banking and other industries. Experienced with the Defence in Depth approach Strong track record of managing teams and building effective partnerships with peers. Strong experience in delivering training Professional information security certifications (i.e. CISSP, CISM, CRISC or similar experience). Cloud Security experience and a good understanding of privacy legislation (Data Protection Act 2018 / GDPR). SKILLS AND EXPERIENCE Functional / Technical Competencies: Strong strategic and analytical thinking. Excellent communication and stakeholder management. Proven ability to balance technical, business, and regulatory priorities. Collaborative, pragmatic, and outcomes-driven leadership style. A deep understanding of IT and Cyber Security: + Defence in Depth model. + Network defence, IDS and DMZ + Network protocols and firewall standards + Detective monitoring - SIEM + Vulnerability Management + Access and Privileged Access Management Experienced in writing and maintaining IT documents, such as standards and procedures. Demonstrates an understanding of strategic business and IT issues impacting the financial services market. Strong understanding of risk and its application across technology and the business. Good understanding of project lifecycles. Education / Qualifications: Degree educated and / or equivalent experience. PERSONAL REQUIREMENTS Excellent Leadership skills Excellent communication skills Ability to manage constructive conflict effectively Strong facilitation skills Ability to build strong and lasting relationships across the bank Results driven, with a strong sense of accountability, focused on business outcomes A proactive, motivated approach. The ability to operate with urgency and prioritise work accordingly Strong decision-making skills, the ability to demonstrate sound judgement A structured and logical approach to work Strong problem-solving skills A creative and innovative approach to work Excellent interpersonal skills Excellent attention to detail and accuracy Strong numerical skills A confident approach, with the ability to provide clear direction to your team Excellent managerial/leadership experience The ability to articulate and implement the vision/strategy for the planning departmentWe are open to considering flexible working requests in line with organisational requirements.
Cyber Security Analyst - Governance, Risk and Culture (GRC) London, United Kingdom; Remote, United Kingdom Baringa is a global consulting firm that partners with leaders to drive change and create value. With deep industry expertise, and enabled by advanced technology, the firm helps clients to deliver with greater confidence and certainty. With over 2,000 people across the UK, Europe, North America, Asia and Australia, the firm combines global insight with local understanding. The firm works across energy and resources, financial services, government and public sector, consumer products and retail, pharmaceuticals and life sciences, manufacturing, and technology, media and telecoms, with capabilities spanning strategy, transformation and operational excellence - all powered by advanced technology, data, AI and digital innovation. Clients value Baringa's collaborative approach and the way its teams integrate seamlessly - all working with a shared understanding of what matters most. The firm is known for its kind, curious experts who listen closely and care deeply about client success as they help clients transform energy markets, modernise financial platforms, expand telecoms and digital networks through advanced data analytics, enable digital services in government, and unlock growth in consumer sectors. Certified as a Great Place to Work around the world, Baringa has been recognised by the Financial Times in 22 categories of its UK Leading Management Consultants rankings, and by Forbes for four consecutive years as one of the World's Best Management Consulting Firms. Cyber Security Analyst - Governance, Risk and Culture (GRC) Baringa's TeCy Group (Technology & Cyber) is a global function supporting the firm as it enters new markets. We're on a mission to develop great technology products and deliver great services. We've installed a new operating system for ourselves and rebooted what was a corporate IT department to an in-house technology company - transforming the way we work and opening the way to serve Baringa's clients directly. We're working on sustainability, committed to Net Zero in our supply-chain and services. We're keeping our firm safe: protecting our data and our reputation. We are embarking upon and will be the driving force behind a new 3-Year digital strategy for the firm. Yes, we've got a big job in the Baringa Technology & Cyber group. So much to build on, so much to progress. So much to deliver. So much to play for! Do you know what though? We're going to do it. All of it and more. We have the support to drive change. We have a diverse group of 90 amazing technology & cyber professionals. We have the belief. We are going to do great things. Come and join us. Overview We are currently looking for a Cyber Security Analyst to join our Governance, Risk and Culture (GRC) capability within the wider Cyber Security Team, where you will play a key role in strengthening the firm's security posture, ensuring compliance, and embedding a cyber-conscious culture across the organisation. The role contributes to the delivery of governance, risk management and assurance activities, including supplier due diligence, audit responses, and the development and maintenance of security policies, standards and controls. You will be a key member of a growing team in a dynamic, consulting-led environment, working closely with technical, IT and business stakeholders to identify and manage cyber risks and align security strategy with business priorities. Baringa will support your development across GRC domains, offering exposure to evolving regulatory requirements, cloud technologies and emerging areas such as AI, with a wide range of opportunities to shape our approach and make a meaningful impact. What will you be doing? Develop a complete understanding of Baringa's technology and information systems. Lead in the response to RFPs/audits, including supplier security due diligence and third-party audit and assurance activities. Identify and communicate current and emerging security threats and cyber risks. Support a program of awareness-raising and training to deliver compliance and to foster a cyber conscious culture across the company. Assist with the definition, implementation and maintenance of corporate security policies, standards and procedures. Provide 'hands on' assistance, particularly in technical control implementation and incident response. Coordinating the needs of in-house IT experts and remote employees, vendors and contractors. Work as part of a team to communicate ideas, suggestions and solutions that achieve the firm's long-term objectives, especially the GRC Strategy. Align organisational security strategy and infrastructure with overall business and information technology strategy. Manage company compliance with information security, policies, standards, contractual obligations and guidance through business managers and champions providing advice, support and guidance on risk based good practice. Lead on and produce technical security MI in support of governance and vulnerability management engagements. Support client engagement leads on client queries and requests - during the business development process and during ongoing client engagement - regarding Baringa's information technology security policies and processes. What are we looking for? We recruit individuals at all levels based on merit. Some of the key sills we are looking for: Experience in full-time operational Cyber Security GRC, or Cyber Security role. Experience of compliance requirements for cloud technologies stacks such as Microsoft and AWS . Experience utilising emerging technologies, such as AI, to design and implement security solutions, monitoring and improving those solutions while working with a Cyber Security team. Thorough understanding of relevant industry security standards and protocols including ISO27001, National Institute of Standards and Technology (NIST), NSCS CAF, SOC, NIS 2 Directive and NCSC Cloud Security Principles. Background of consulting and engineering the design and development of security best practices, implementation of security measures, policies and processes to meet business goals, customer needs and regulatory requirements. Ability to use logic and reasoning to identify the strengths and weaknesses of IT systems, while seeking out vulnerabilities in IT infrastructures. Assist in risk assessment procedures, policy formation, role-based authorisation methodologies, authentication technologies and security attack pathologies. Growth mentality with excellent problem-solving skills, willing to assist in all areas of Cyber and to learn new technologies & processes. A self-motivated individual with a "can do" attitude, who can work on their own initiative as well as part of a team. An excellent communicator who can help develop good Cyber practices with an ability to interact with all levels within the company. Strong leadership, stakeholder management, and project/team-building skills, including the ability to lead teams and drive initiatives in multiple departments. What a career at Baringa will give you Putting People First. Baringa is a People First company and wellbeing is at the forefront of our culture. We recognise the importance of work-life balance and flexible working and provide our staff amazing benefits. Some of these benefits include: Generous Annual Leave Policy: We recognise everyone needs a well-deserved break. We provide our employees with 5 weeks of annual leave, fully available at the start of each year. In addition to this, we have introduced our 5-Year Recharge benefit which allows all employees an additional 2 weeks of paid leave after 5 years continuous service. Flexible Working: We know that the 'ideal' work-life balance will vary from person to person and change at different stages of our working lives. To accommodate this, we have implemented a hybrid working policy and introduced more flexibility around taking unpaid leave. Corporate Responsibility Days: Our world is important to us, so all our employees get 3 every year to help social and environmental causes and increase our impact on the communities that mean the most to us. Wellbeing Fund: We want to encourage all employees to take charge and prioritise their own wellbeing. We've introduced our annual People Fund to support this by offering every individual a fund to support and manage their wellbeing through an activity of their choice. Profit Share Scheme: All employees participate in the Baringa Group Profit Share Scheme so everyone has a stake in the company's success. Diversity and Inclusion We are proud to be an Equal Opportunity Employer. We believe that creating an environment where everyone feels a sense of belonging is central to our culture and that diversity is paramount to driving creativity, innovation, and value for our clients and for our people. You can be a part of our 'Great Place to Work' - with our commitment to women and well-being in the workplace for all. Click here to see some of our recent awards and how we've achieved this. Using business as a force for good. We maintain high standards of environmental performance and transparency, which can be seen through our commitment to Net Zero with our SBTI-verified Scope 1, 2 and 3 emissions reduction targets and our support of the Better Business Act . click apply for full job details
30/05/2026
Full time
Cyber Security Analyst - Governance, Risk and Culture (GRC) London, United Kingdom; Remote, United Kingdom Baringa is a global consulting firm that partners with leaders to drive change and create value. With deep industry expertise, and enabled by advanced technology, the firm helps clients to deliver with greater confidence and certainty. With over 2,000 people across the UK, Europe, North America, Asia and Australia, the firm combines global insight with local understanding. The firm works across energy and resources, financial services, government and public sector, consumer products and retail, pharmaceuticals and life sciences, manufacturing, and technology, media and telecoms, with capabilities spanning strategy, transformation and operational excellence - all powered by advanced technology, data, AI and digital innovation. Clients value Baringa's collaborative approach and the way its teams integrate seamlessly - all working with a shared understanding of what matters most. The firm is known for its kind, curious experts who listen closely and care deeply about client success as they help clients transform energy markets, modernise financial platforms, expand telecoms and digital networks through advanced data analytics, enable digital services in government, and unlock growth in consumer sectors. Certified as a Great Place to Work around the world, Baringa has been recognised by the Financial Times in 22 categories of its UK Leading Management Consultants rankings, and by Forbes for four consecutive years as one of the World's Best Management Consulting Firms. Cyber Security Analyst - Governance, Risk and Culture (GRC) Baringa's TeCy Group (Technology & Cyber) is a global function supporting the firm as it enters new markets. We're on a mission to develop great technology products and deliver great services. We've installed a new operating system for ourselves and rebooted what was a corporate IT department to an in-house technology company - transforming the way we work and opening the way to serve Baringa's clients directly. We're working on sustainability, committed to Net Zero in our supply-chain and services. We're keeping our firm safe: protecting our data and our reputation. We are embarking upon and will be the driving force behind a new 3-Year digital strategy for the firm. Yes, we've got a big job in the Baringa Technology & Cyber group. So much to build on, so much to progress. So much to deliver. So much to play for! Do you know what though? We're going to do it. All of it and more. We have the support to drive change. We have a diverse group of 90 amazing technology & cyber professionals. We have the belief. We are going to do great things. Come and join us. Overview We are currently looking for a Cyber Security Analyst to join our Governance, Risk and Culture (GRC) capability within the wider Cyber Security Team, where you will play a key role in strengthening the firm's security posture, ensuring compliance, and embedding a cyber-conscious culture across the organisation. The role contributes to the delivery of governance, risk management and assurance activities, including supplier due diligence, audit responses, and the development and maintenance of security policies, standards and controls. You will be a key member of a growing team in a dynamic, consulting-led environment, working closely with technical, IT and business stakeholders to identify and manage cyber risks and align security strategy with business priorities. Baringa will support your development across GRC domains, offering exposure to evolving regulatory requirements, cloud technologies and emerging areas such as AI, with a wide range of opportunities to shape our approach and make a meaningful impact. What will you be doing? Develop a complete understanding of Baringa's technology and information systems. Lead in the response to RFPs/audits, including supplier security due diligence and third-party audit and assurance activities. Identify and communicate current and emerging security threats and cyber risks. Support a program of awareness-raising and training to deliver compliance and to foster a cyber conscious culture across the company. Assist with the definition, implementation and maintenance of corporate security policies, standards and procedures. Provide 'hands on' assistance, particularly in technical control implementation and incident response. Coordinating the needs of in-house IT experts and remote employees, vendors and contractors. Work as part of a team to communicate ideas, suggestions and solutions that achieve the firm's long-term objectives, especially the GRC Strategy. Align organisational security strategy and infrastructure with overall business and information technology strategy. Manage company compliance with information security, policies, standards, contractual obligations and guidance through business managers and champions providing advice, support and guidance on risk based good practice. Lead on and produce technical security MI in support of governance and vulnerability management engagements. Support client engagement leads on client queries and requests - during the business development process and during ongoing client engagement - regarding Baringa's information technology security policies and processes. What are we looking for? We recruit individuals at all levels based on merit. Some of the key sills we are looking for: Experience in full-time operational Cyber Security GRC, or Cyber Security role. Experience of compliance requirements for cloud technologies stacks such as Microsoft and AWS . Experience utilising emerging technologies, such as AI, to design and implement security solutions, monitoring and improving those solutions while working with a Cyber Security team. Thorough understanding of relevant industry security standards and protocols including ISO27001, National Institute of Standards and Technology (NIST), NSCS CAF, SOC, NIS 2 Directive and NCSC Cloud Security Principles. Background of consulting and engineering the design and development of security best practices, implementation of security measures, policies and processes to meet business goals, customer needs and regulatory requirements. Ability to use logic and reasoning to identify the strengths and weaknesses of IT systems, while seeking out vulnerabilities in IT infrastructures. Assist in risk assessment procedures, policy formation, role-based authorisation methodologies, authentication technologies and security attack pathologies. Growth mentality with excellent problem-solving skills, willing to assist in all areas of Cyber and to learn new technologies & processes. A self-motivated individual with a "can do" attitude, who can work on their own initiative as well as part of a team. An excellent communicator who can help develop good Cyber practices with an ability to interact with all levels within the company. Strong leadership, stakeholder management, and project/team-building skills, including the ability to lead teams and drive initiatives in multiple departments. What a career at Baringa will give you Putting People First. Baringa is a People First company and wellbeing is at the forefront of our culture. We recognise the importance of work-life balance and flexible working and provide our staff amazing benefits. Some of these benefits include: Generous Annual Leave Policy: We recognise everyone needs a well-deserved break. We provide our employees with 5 weeks of annual leave, fully available at the start of each year. In addition to this, we have introduced our 5-Year Recharge benefit which allows all employees an additional 2 weeks of paid leave after 5 years continuous service. Flexible Working: We know that the 'ideal' work-life balance will vary from person to person and change at different stages of our working lives. To accommodate this, we have implemented a hybrid working policy and introduced more flexibility around taking unpaid leave. Corporate Responsibility Days: Our world is important to us, so all our employees get 3 every year to help social and environmental causes and increase our impact on the communities that mean the most to us. Wellbeing Fund: We want to encourage all employees to take charge and prioritise their own wellbeing. We've introduced our annual People Fund to support this by offering every individual a fund to support and manage their wellbeing through an activity of their choice. Profit Share Scheme: All employees participate in the Baringa Group Profit Share Scheme so everyone has a stake in the company's success. Diversity and Inclusion We are proud to be an Equal Opportunity Employer. We believe that creating an environment where everyone feels a sense of belonging is central to our culture and that diversity is paramount to driving creativity, innovation, and value for our clients and for our people. You can be a part of our 'Great Place to Work' - with our commitment to women and well-being in the workplace for all. Click here to see some of our recent awards and how we've achieved this. Using business as a force for good. We maintain high standards of environmental performance and transparency, which can be seen through our commitment to Net Zero with our SBTI-verified Scope 1, 2 and 3 emissions reduction targets and our support of the Better Business Act . click apply for full job details
At WHSmith our people are at the heart of everything we do. They are the ones that go the extra mile for our customers. The ones that enable our growth. The Cyber Security Manager is responsible for developing, implementing, and maintaining WHSmith's cybersecurity strategy to protect systems, networks, and data from cyber threats. This role ensures compliance with security standards, leads incident response efforts, and manages security technologies and teams. What you will be doing: Develop and implement the organization's cybersecurity strategy and roadmap. Establish and enforce security policies, standards, and procedures. Ensure compliance with relevant regulations (e.g., GDPR, ISO 27001, NIST). Conduct regular risk assessments and vulnerability management. Oversee security monitoring, threat detection, and incident response. Lead investigations into security breaches and implement corrective actions. Ensure proper configuration and management of security tools (SIEM, firewalls, EDR, IDS/IPS). Oversee security monitoring, threat detection, and incident response Lead investigations into security breaches and implement corrective actions Ensure proper configuration and management of security tools Identify, assess, and mitigate cybersecurity risks Conduct internal and external security audits Work with stakeholders to ensure compliance with legal and regulatory requirements Maintain documentation and reporting for audits and risk management Lead, mentor, and develop the cybersecurity team Manage third-party vendors and security service providers Promote a culture of security awareness across the organization Develop and deliver cybersecurity awareness programs Conduct phishing simulations and training exercises Ensure employees follow best security practices What we are looking for: Experience in cybersecurity or information security roles Strong leadership and decision making abilities Excellent communication and stakeholder management Analytical mindset with problem solving skills Ability to work under pressure during security incidents Familiarity with frameworks like ISO 27001, NIST, CIS Controls Understanding of vulnerability management and penetration testing How we reward our teams: Hybrid Working Model from home and in the office 4pm Friday Finish Flexible Working 25 Days holiday, plus your Birthday off, plus Bank Holidays with an opportunity to buy extra days holiday Family Friendly Leave Company Pension scheme Sharesave Scheme Annual Bonus based on company and personal performance Competitive Salary and Car Allowance Private Medical Staff Discount Card for stores and online Cycle to Work Scheme At WHSmith, we're all about creating an inclusive and welcoming workplace where everyone can be themselves and do their best. No matter your background, age, disability, gender, gender expression, gender identity, race or ethnicity, marital status, religion, sex, sexual orientation or anything else that makes you, you-you're welcome here. We're also open to flexible working where possible, so if that's something you need, let's chat. And if you need any adjustments during the selection process, just let our Talent Acquisition team know we're happy to help!
30/05/2026
Full time
At WHSmith our people are at the heart of everything we do. They are the ones that go the extra mile for our customers. The ones that enable our growth. The Cyber Security Manager is responsible for developing, implementing, and maintaining WHSmith's cybersecurity strategy to protect systems, networks, and data from cyber threats. This role ensures compliance with security standards, leads incident response efforts, and manages security technologies and teams. What you will be doing: Develop and implement the organization's cybersecurity strategy and roadmap. Establish and enforce security policies, standards, and procedures. Ensure compliance with relevant regulations (e.g., GDPR, ISO 27001, NIST). Conduct regular risk assessments and vulnerability management. Oversee security monitoring, threat detection, and incident response. Lead investigations into security breaches and implement corrective actions. Ensure proper configuration and management of security tools (SIEM, firewalls, EDR, IDS/IPS). Oversee security monitoring, threat detection, and incident response Lead investigations into security breaches and implement corrective actions Ensure proper configuration and management of security tools Identify, assess, and mitigate cybersecurity risks Conduct internal and external security audits Work with stakeholders to ensure compliance with legal and regulatory requirements Maintain documentation and reporting for audits and risk management Lead, mentor, and develop the cybersecurity team Manage third-party vendors and security service providers Promote a culture of security awareness across the organization Develop and deliver cybersecurity awareness programs Conduct phishing simulations and training exercises Ensure employees follow best security practices What we are looking for: Experience in cybersecurity or information security roles Strong leadership and decision making abilities Excellent communication and stakeholder management Analytical mindset with problem solving skills Ability to work under pressure during security incidents Familiarity with frameworks like ISO 27001, NIST, CIS Controls Understanding of vulnerability management and penetration testing How we reward our teams: Hybrid Working Model from home and in the office 4pm Friday Finish Flexible Working 25 Days holiday, plus your Birthday off, plus Bank Holidays with an opportunity to buy extra days holiday Family Friendly Leave Company Pension scheme Sharesave Scheme Annual Bonus based on company and personal performance Competitive Salary and Car Allowance Private Medical Staff Discount Card for stores and online Cycle to Work Scheme At WHSmith, we're all about creating an inclusive and welcoming workplace where everyone can be themselves and do their best. No matter your background, age, disability, gender, gender expression, gender identity, race or ethnicity, marital status, religion, sex, sexual orientation or anything else that makes you, you-you're welcome here. We're also open to flexible working where possible, so if that's something you need, let's chat. And if you need any adjustments during the selection process, just let our Talent Acquisition team know we're happy to help!
JOB DESCRIPTION Out of the successful launch of Chase in 2021, we're a new team, with a new mission. We're creating products that solve real world problems and put customers at the center - all in an environment that nurtures skills and helps you realize your potential. Our team is key to our success. We're people-first. We value collaboration, curiosity and commitment. Technologies we use: Java, Kotlin, Kubernetes, Apache Kafka, GCP, BigQuery, Spark, VertexAI, ModelArmor, DeepEval, Google ADK. Job responsibilities Set the vision and multi-year strategy for the Data & AI Platform that powers Chase's next-generation digital experiences, translating enterprise priorities into an executable roadmap and measurable outcomes. Lead and scale a multi-discipline organization spanning data platform engineering and AI/MLOps, establishing clear ownership, org structure, operating rhythms, and standards for delivery. Own the platform's end-to-end data foundation - ingestion, transformation, orchestration, metadata/catalog, quality, and governed data products built for reliability, scalability, and self-service adoption. Serve as the executive steward for compliant use of customer data, ensuring privacy, access controls, lineage, retention, and auditability are embedded by design and aligned to firm risk and regulatory expectations. Define and deliver platform enablement for LLM-powered applications, including reference architectures, developer tooling, model onboarding and deployment patterns, evaluation and testing, observability, and cost/latency guardrails. Establish engineering excellence and operational maturity through SLOs, resiliency practices, incident management, release governance, capacity planning, and continuous improvement across the platform. Drive a product-oriented platform model by partnering with product, security, legal, risk, architecture, and engineering leaders to prioritize the highest-leverage capabilities and accelerate adoption across teams. Enable data-driven product development at scale through trusted analytics pipelines, standardized telemetry, experimentation support, and consistent metrics to inform decisions and improve customer outcomes. Attract, develop, and retain top talent by building leadership depth, setting high standards, coaching managers and senior engineers, and fostering a culture of ownership, inclusion, and accountability. Required qualifications, capabilities and skills Being a problem solver: you can independently analyse a problem and come up with options on how to solve it. Flexibility regarding tools and languages: for example you have to be open to debug a permission issue one day in a python service and dig into some Java/Kotlin out-of-memory issue the other day (of course we take into account your expertise and you will have team members to help you out!). Knowledge of data structures. Experience with either Kubernetes or Docker. Experience with cloud technologies (AWS/Azure/GCP) and distributed systems, web technologies and event-driven architectures. Experience in leading people. Preferred qualifications, capabilities and skills Experience with message brokers (Kafka, RabbitMQ, Pulsar etc.). Experience with Kafka Connect. Preferably experience in setting up data platforms, setting standards - not just pipelines. Preferably experience in a distributed data processing environment/framework (e.g. Spark or Flink). Familiarity with advanced AI/ML concepts and protocols, such as Retrieval-Augmented Generation (RAG), agentic system architectures, and Model Context Protocol (MCP). Experience with MLOps tools and platforms (e.g., MLflow, Amazon SageMaker, Google VertexAI, Databricks, BentoML, KServe, Kubeflow). Experience with deploying to a GenAI platform a production system: Google VertexAI, OpenAI, AWS Bedrock, LangChain, etc. Equal Opportunity Employment We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants and employees religious practices and beliefs, as well as mental health or physical disability needs.
30/05/2026
Full time
JOB DESCRIPTION Out of the successful launch of Chase in 2021, we're a new team, with a new mission. We're creating products that solve real world problems and put customers at the center - all in an environment that nurtures skills and helps you realize your potential. Our team is key to our success. We're people-first. We value collaboration, curiosity and commitment. Technologies we use: Java, Kotlin, Kubernetes, Apache Kafka, GCP, BigQuery, Spark, VertexAI, ModelArmor, DeepEval, Google ADK. Job responsibilities Set the vision and multi-year strategy for the Data & AI Platform that powers Chase's next-generation digital experiences, translating enterprise priorities into an executable roadmap and measurable outcomes. Lead and scale a multi-discipline organization spanning data platform engineering and AI/MLOps, establishing clear ownership, org structure, operating rhythms, and standards for delivery. Own the platform's end-to-end data foundation - ingestion, transformation, orchestration, metadata/catalog, quality, and governed data products built for reliability, scalability, and self-service adoption. Serve as the executive steward for compliant use of customer data, ensuring privacy, access controls, lineage, retention, and auditability are embedded by design and aligned to firm risk and regulatory expectations. Define and deliver platform enablement for LLM-powered applications, including reference architectures, developer tooling, model onboarding and deployment patterns, evaluation and testing, observability, and cost/latency guardrails. Establish engineering excellence and operational maturity through SLOs, resiliency practices, incident management, release governance, capacity planning, and continuous improvement across the platform. Drive a product-oriented platform model by partnering with product, security, legal, risk, architecture, and engineering leaders to prioritize the highest-leverage capabilities and accelerate adoption across teams. Enable data-driven product development at scale through trusted analytics pipelines, standardized telemetry, experimentation support, and consistent metrics to inform decisions and improve customer outcomes. Attract, develop, and retain top talent by building leadership depth, setting high standards, coaching managers and senior engineers, and fostering a culture of ownership, inclusion, and accountability. Required qualifications, capabilities and skills Being a problem solver: you can independently analyse a problem and come up with options on how to solve it. Flexibility regarding tools and languages: for example you have to be open to debug a permission issue one day in a python service and dig into some Java/Kotlin out-of-memory issue the other day (of course we take into account your expertise and you will have team members to help you out!). Knowledge of data structures. Experience with either Kubernetes or Docker. Experience with cloud technologies (AWS/Azure/GCP) and distributed systems, web technologies and event-driven architectures. Experience in leading people. Preferred qualifications, capabilities and skills Experience with message brokers (Kafka, RabbitMQ, Pulsar etc.). Experience with Kafka Connect. Preferably experience in setting up data platforms, setting standards - not just pipelines. Preferably experience in a distributed data processing environment/framework (e.g. Spark or Flink). Familiarity with advanced AI/ML concepts and protocols, such as Retrieval-Augmented Generation (RAG), agentic system architectures, and Model Context Protocol (MCP). Experience with MLOps tools and platforms (e.g., MLflow, Amazon SageMaker, Google VertexAI, Databricks, BentoML, KServe, Kubeflow). Experience with deploying to a GenAI platform a production system: Google VertexAI, OpenAI, AWS Bedrock, LangChain, etc. Equal Opportunity Employment We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants and employees religious practices and beliefs, as well as mental health or physical disability needs.