it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

22 jobs found

Email me jobs like this
Refine Search
Current Search
analyst senior grc analyst
Deputy Programme Manager Instrumented Live Training (Area Weapon Effects Simulation) (ILT-A)
Cubic Corporation Salisbury, Wiltshire
Business Unit: Cubic Defense Company Cubic is a global organization that delivers technology solutions in transportation and defense. It provides command, control, communications, computers, cyber, intelligence, surveillance, and reconnaissance (C5ISR) solutions, as well as live, virtual, constructive, and game-based training to serve U.S. and allied forces. Summary The Deputy Programme Manager (DPM) for the ILT-A Programme supports senior programme leadership during a period of rapid growth and change. The candidate will work with programme and project managers, the Regional General Manager, and the ILT-A Programme Manager to ensure successful delivery of the existing business portfolio across Cubic UK (CDUK). The role is primarily office based with occasional field based delivery and operational oversight in the UK and overseas. Key Responsibilities Assist the Programme Manager in planning, scheduling, execution, and delivery of design and build projects. Coordinate multiple parallel projects, ensuring alignment with programme objectives, budget constraints, and timelines. Engage cross functional teams, including engineering, supply chain, procurement, and manufacturing, to develop strategies. Support stakeholder communication and engagement, providing regular updates on project progress, risks, and opportunities. Manage project resources effectively, including financial budgets and personnel allocation. Develop and track key performance indicators (KPIs) to measure project success and continuous improvement. Support the implementation, monitoring, and continuous improvement of security controls across the CDUK IT infrastructure and business systems. Manage risk registers and assist in the identification of risks, including security risks, and implement mitigation plans. Implement and enhance the security strategy, championing a culture of cyber security awareness and best practice across CDUK. Contribute to the upkeep of security certifications in alignment with frameworks such as Cyber Essentials and the Cyber Assessment Framework (CAF). Work with third party providers on security audits and reviews, and support continual improvement of cyber security policies. Maintain contemporary knowledge of current threats and cyber trends. Essential Requirements Proven experience and understanding of programme or project management within an engineering, manufacturing, or defence environment. Ability to manage multiple design and build projects simultaneously. Excellent stakeholder management skills, with experience engaging internal and external partners. Strong problem solving and risk management capabilities. Experience managing risk registers. Proficiency in project management methodologies and tools, including scheduling (e.g., Agile, PRINCE2, PMP, MS Project, P6). Understanding of cyber and information security best practice frameworks, standards, and certifications such as NIST, ISO27001, SbD, and ideally PSN, Cyber Essentials, and CAF. Experience providing security advice across a variety of projects. Strong Governance Risk and Compliance (GRC) knowledge, understanding, and skillset. Experience with budgeting, financial reporting, and resource planning. Desirable Requirements Typically 8+ years of relevant experience. Experience as an information security analyst (IT audit, governance, risk and compliance) within the public or private sector. Degree in Engineering, Project Management, or a related discipline. Experience within defence, aerospace, or highly regulated industries. Familiarity with regulatory and compliance requirements. Membership of a relevant professional body (e.g., APM, PMI, INCOSE). Background in IT (infrastructure, networks, software or cyber security). Personal Qualities Self motivated, proactive, and able to work under pressure to meet challenging deadlines with minimal supervision. Strong relationship building and influencing skills. Excellent communication skills (written and verbal), proactive and solution focused mindset. Ability to lead teams and quickly acquire new skills. Willingness to travel. Worker Type Employee You are committed to hiring and retaining a diverse workforce and are proud to be an Equal Opportunity/Affirmative Action Employer. We are committed to ensuring a workplace free of discrimination based on race, color, religion, age, disability, genetic information, sex, sexual orientation, gender identity, national origin, military or veteran status, or any other basis protected by applicable law. For more information on Equal Employment please visit:
27/07/2026
Full time
Business Unit: Cubic Defense Company Cubic is a global organization that delivers technology solutions in transportation and defense. It provides command, control, communications, computers, cyber, intelligence, surveillance, and reconnaissance (C5ISR) solutions, as well as live, virtual, constructive, and game-based training to serve U.S. and allied forces. Summary The Deputy Programme Manager (DPM) for the ILT-A Programme supports senior programme leadership during a period of rapid growth and change. The candidate will work with programme and project managers, the Regional General Manager, and the ILT-A Programme Manager to ensure successful delivery of the existing business portfolio across Cubic UK (CDUK). The role is primarily office based with occasional field based delivery and operational oversight in the UK and overseas. Key Responsibilities Assist the Programme Manager in planning, scheduling, execution, and delivery of design and build projects. Coordinate multiple parallel projects, ensuring alignment with programme objectives, budget constraints, and timelines. Engage cross functional teams, including engineering, supply chain, procurement, and manufacturing, to develop strategies. Support stakeholder communication and engagement, providing regular updates on project progress, risks, and opportunities. Manage project resources effectively, including financial budgets and personnel allocation. Develop and track key performance indicators (KPIs) to measure project success and continuous improvement. Support the implementation, monitoring, and continuous improvement of security controls across the CDUK IT infrastructure and business systems. Manage risk registers and assist in the identification of risks, including security risks, and implement mitigation plans. Implement and enhance the security strategy, championing a culture of cyber security awareness and best practice across CDUK. Contribute to the upkeep of security certifications in alignment with frameworks such as Cyber Essentials and the Cyber Assessment Framework (CAF). Work with third party providers on security audits and reviews, and support continual improvement of cyber security policies. Maintain contemporary knowledge of current threats and cyber trends. Essential Requirements Proven experience and understanding of programme or project management within an engineering, manufacturing, or defence environment. Ability to manage multiple design and build projects simultaneously. Excellent stakeholder management skills, with experience engaging internal and external partners. Strong problem solving and risk management capabilities. Experience managing risk registers. Proficiency in project management methodologies and tools, including scheduling (e.g., Agile, PRINCE2, PMP, MS Project, P6). Understanding of cyber and information security best practice frameworks, standards, and certifications such as NIST, ISO27001, SbD, and ideally PSN, Cyber Essentials, and CAF. Experience providing security advice across a variety of projects. Strong Governance Risk and Compliance (GRC) knowledge, understanding, and skillset. Experience with budgeting, financial reporting, and resource planning. Desirable Requirements Typically 8+ years of relevant experience. Experience as an information security analyst (IT audit, governance, risk and compliance) within the public or private sector. Degree in Engineering, Project Management, or a related discipline. Experience within defence, aerospace, or highly regulated industries. Familiarity with regulatory and compliance requirements. Membership of a relevant professional body (e.g., APM, PMI, INCOSE). Background in IT (infrastructure, networks, software or cyber security). Personal Qualities Self motivated, proactive, and able to work under pressure to meet challenging deadlines with minimal supervision. Strong relationship building and influencing skills. Excellent communication skills (written and verbal), proactive and solution focused mindset. Ability to lead teams and quickly acquire new skills. Willingness to travel. Worker Type Employee You are committed to hiring and retaining a diverse workforce and are proud to be an Equal Opportunity/Affirmative Action Employer. We are committed to ensuring a workplace free of discrimination based on race, color, religion, age, disability, genetic information, sex, sexual orientation, gender identity, national origin, military or veteran status, or any other basis protected by applicable law. For more information on Equal Employment please visit:
Deerfoot Recruitment Solutions Limited
Senior ServiceNow Engineer - GRC/IRM
Deerfoot Recruitment Solutions Limited City, London
Senior ServiceNow Engineer - GRC/IRM London (Hybrid - 3 days onsite per week) Banking - Up to 120,000 + Bonus + Benefits Do you want to take true technical ownership of a global GRC platform, driving IRM, BCM and TPRM capability for a major financial services organisation? If you're a Senior ServiceNow Engineer looking for your next challenge at Vice President level, this could be the role you've been waiting for. You'll join a growing ServiceNow Core team as the go-to Subject Matter Expert for the platform, shaping how risk, resilience and third-party risk are managed across the business. This is a rare opportunity to combine hands-on technical delivery with real influence over platform strategy, governance and roadmap. What you'll be doing: Acting as the SME for the ServiceNow platform, owning its development, governance and day-to-day technical delivery, with a focus on the GRC suite (IRM, BCM, TPRM) Translating business requirements into scalable ServiceNow solutions, driving automation, integration and best-practice configuration Triaging, estimating and delivering platform enhancements, upgrades and releases, while maintaining a strong Health Scan score Providing technical governance and change approval, and leading testing/preparation for platform upgrades Producing and maintaining documentation, training materials and process guides, while mentoring junior and off-shore team members Building strong relationships with stakeholders across the region and globally to share best practice and drive continuous improvement What you'll bring: 5+ years' technical experience implementing and supporting ServiceNow, with hands-on IRM module expertise essential Strong understanding of risk management, GRC and ServiceNow best practice, with sharp problem-solving and root-cause analysis skills Proven experience in a regulated environment (financial services, insurance or critical infrastructure), with the credibility to manage audit and IT security requirements Excellent communication, stakeholder management and leadership skills, with a structured, detail-focused approach Desirable: current ServiceNow certifications, familiarity with ITIL/COBIT, and exposure to DORA compliance The package: Up to 120,000 plus bonus and benefits, based in London with hybrid working (3 days in the office per week). If this sounds like the platform-defining role you've been looking for, apply now or get in touch for a confidential conversation about the opportunity. If you've held any of these roles or used these technologies/skills, this role could be a great fit: ServiceNow Engineer, ServiceNow Developer, ServiceNow Consultant, ServiceNow Technical Lead, GRC Engineer, GRC Analyst, IRM Engineer, IRM Consultant, Integrated Risk Management Engineer, Business Continuity Management (BCM) Specialist, Third-Party Risk Management (TPRM) Consultant, Risk & Compliance Technology Engineer, ServiceNow Platform Engineer, ServiceNow Administrator, ITIL, COBIT, DORA compliance. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate 1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
24/07/2026
Full time
Senior ServiceNow Engineer - GRC/IRM London (Hybrid - 3 days onsite per week) Banking - Up to 120,000 + Bonus + Benefits Do you want to take true technical ownership of a global GRC platform, driving IRM, BCM and TPRM capability for a major financial services organisation? If you're a Senior ServiceNow Engineer looking for your next challenge at Vice President level, this could be the role you've been waiting for. You'll join a growing ServiceNow Core team as the go-to Subject Matter Expert for the platform, shaping how risk, resilience and third-party risk are managed across the business. This is a rare opportunity to combine hands-on technical delivery with real influence over platform strategy, governance and roadmap. What you'll be doing: Acting as the SME for the ServiceNow platform, owning its development, governance and day-to-day technical delivery, with a focus on the GRC suite (IRM, BCM, TPRM) Translating business requirements into scalable ServiceNow solutions, driving automation, integration and best-practice configuration Triaging, estimating and delivering platform enhancements, upgrades and releases, while maintaining a strong Health Scan score Providing technical governance and change approval, and leading testing/preparation for platform upgrades Producing and maintaining documentation, training materials and process guides, while mentoring junior and off-shore team members Building strong relationships with stakeholders across the region and globally to share best practice and drive continuous improvement What you'll bring: 5+ years' technical experience implementing and supporting ServiceNow, with hands-on IRM module expertise essential Strong understanding of risk management, GRC and ServiceNow best practice, with sharp problem-solving and root-cause analysis skills Proven experience in a regulated environment (financial services, insurance or critical infrastructure), with the credibility to manage audit and IT security requirements Excellent communication, stakeholder management and leadership skills, with a structured, detail-focused approach Desirable: current ServiceNow certifications, familiarity with ITIL/COBIT, and exposure to DORA compliance The package: Up to 120,000 plus bonus and benefits, based in London with hybrid working (3 days in the office per week). If this sounds like the platform-defining role you've been looking for, apply now or get in touch for a confidential conversation about the opportunity. If you've held any of these roles or used these technologies/skills, this role could be a great fit: ServiceNow Engineer, ServiceNow Developer, ServiceNow Consultant, ServiceNow Technical Lead, GRC Engineer, GRC Analyst, IRM Engineer, IRM Consultant, Integrated Risk Management Engineer, Business Continuity Management (BCM) Specialist, Third-Party Risk Management (TPRM) Consultant, Risk & Compliance Technology Engineer, ServiceNow Platform Engineer, ServiceNow Administrator, ITIL, COBIT, DORA compliance. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate 1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
Deerfoot Recruitment Solutions Limited
Senior ServiceNow Engineer - GRC/IRM
Deerfoot Recruitment Solutions Limited City, London
Senior ServiceNow Engineer - GRC/IRM London (Hybrid - 3 days onsite per week) Banking - Up to £120,000 + Bonus + Benefits Do you want to take true technical ownership of a global GRC platform, driving IRM, BCM and TPRM capability for a major financial services organisation? If you're a Senior ServiceNow Engineer looking for your next challenge at Vice President level, this could be the role you've been waiting for. You'll join a growing ServiceNow Core team as the go-to Subject Matter Expert for the platform, shaping how risk, resilience and third-party risk are managed across the business. This is a rare opportunity to combine hands-on technical delivery with real influence over platform strategy, governance and roadmap. What you'll be doing: Acting as the SME for the ServiceNow platform, owning its development, governance and day-to-day technical delivery, with a focus on the GRC suite (IRM, BCM, TPRM) Translating business requirements into scalable ServiceNow solutions, driving automation, integration and best-practice configuration Triaging, estimating and delivering platform enhancements, upgrades and releases, while maintaining a strong Health Scan score Providing technical governance and change approval, and leading testing/preparation for platform upgrades Producing and maintaining documentation, training materials and process guides, while mentoring junior and off-shore team members Building strong relationships with stakeholders across the region and globally to share best practice and drive continuous improvement What you'll bring: 5+ years' technical experience implementing and supporting ServiceNow, with hands-on IRM module expertise essential Strong understanding of risk management, GRC and ServiceNow best practice, with sharp problem-solving and root-cause analysis skills Proven experience in a regulated environment (financial services, insurance or critical infrastructure), with the credibility to manage audit and IT security requirements Excellent communication, stakeholder management and leadership skills, with a structured, detail-focused approach Desirable: current ServiceNow certifications, familiarity with ITIL/COBIT, and exposure to DORA compliance The package: Up to £120,000 plus bonus and benefits, based in London with hybrid working (3 days in the office per week). If this sounds like the platform-defining role you've been looking for, apply now or get in touch for a confidential conversation about the opportunity. If you've held any of these roles or used these technologies/skills, this role could be a great fit: ServiceNow Engineer, ServiceNow Developer, ServiceNow Consultant, ServiceNow Technical Lead, GRC Engineer, GRC Analyst, IRM Engineer, IRM Consultant, Integrated Risk Management Engineer, Business Continuity Management (BCM) Specialist, Third-Party Risk Management (TPRM) Consultant, Risk & Compliance Technology Engineer, ServiceNow Platform Engineer, ServiceNow Administrator, ITIL, COBIT, DORA compliance. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate £1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
24/07/2026
Full time
Senior ServiceNow Engineer - GRC/IRM London (Hybrid - 3 days onsite per week) Banking - Up to £120,000 + Bonus + Benefits Do you want to take true technical ownership of a global GRC platform, driving IRM, BCM and TPRM capability for a major financial services organisation? If you're a Senior ServiceNow Engineer looking for your next challenge at Vice President level, this could be the role you've been waiting for. You'll join a growing ServiceNow Core team as the go-to Subject Matter Expert for the platform, shaping how risk, resilience and third-party risk are managed across the business. This is a rare opportunity to combine hands-on technical delivery with real influence over platform strategy, governance and roadmap. What you'll be doing: Acting as the SME for the ServiceNow platform, owning its development, governance and day-to-day technical delivery, with a focus on the GRC suite (IRM, BCM, TPRM) Translating business requirements into scalable ServiceNow solutions, driving automation, integration and best-practice configuration Triaging, estimating and delivering platform enhancements, upgrades and releases, while maintaining a strong Health Scan score Providing technical governance and change approval, and leading testing/preparation for platform upgrades Producing and maintaining documentation, training materials and process guides, while mentoring junior and off-shore team members Building strong relationships with stakeholders across the region and globally to share best practice and drive continuous improvement What you'll bring: 5+ years' technical experience implementing and supporting ServiceNow, with hands-on IRM module expertise essential Strong understanding of risk management, GRC and ServiceNow best practice, with sharp problem-solving and root-cause analysis skills Proven experience in a regulated environment (financial services, insurance or critical infrastructure), with the credibility to manage audit and IT security requirements Excellent communication, stakeholder management and leadership skills, with a structured, detail-focused approach Desirable: current ServiceNow certifications, familiarity with ITIL/COBIT, and exposure to DORA compliance The package: Up to £120,000 plus bonus and benefits, based in London with hybrid working (3 days in the office per week). If this sounds like the platform-defining role you've been looking for, apply now or get in touch for a confidential conversation about the opportunity. If you've held any of these roles or used these technologies/skills, this role could be a great fit: ServiceNow Engineer, ServiceNow Developer, ServiceNow Consultant, ServiceNow Technical Lead, GRC Engineer, GRC Analyst, IRM Engineer, IRM Consultant, Integrated Risk Management Engineer, Business Continuity Management (BCM) Specialist, Third-Party Risk Management (TPRM) Consultant, Risk & Compliance Technology Engineer, ServiceNow Platform Engineer, ServiceNow Administrator, ITIL, COBIT, DORA compliance. Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate £1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
Cybersecurity - Senior Manager
CFGI
About CFGI CFGI is a global consulting firm that helps organisations navigate complex business challenges with confidence. With a strong presence in the UK, we partner with companies across industries to deliver best-in-class advisory services in accounting, risk, cyber security, technology, and business transformation. We pride ourselves on combining technical expertise with a practical, hands on approach, helping our clients strengthen resilience, meet regulatory requirements, and stay ahead in an increasingly digital and risk driven landscape. Technical and Domain Experience Conduct cybersecurity maturity and risk assessment and for clients. Practical experience implementing security controls, in areas such as MDR, IAM, Network Security, Cloud Deployments. Advise clients on cybersecurity strategy, metrics and reporting for various levels of stakeholders, including Audit Committees and Board of Directors. Build risk management practices for clients, including policies, procedures, Risk Register, etc. Previous experience as a systems administrator, systems engineer, or security analyst. Understanding of operating system hardening principles, network design principles, and systems security. Guide clients in establishing cybersecurity policies, standards, and procedures. Manage cybersecurity training & awareness services for clients from design to implementation. Understanding of security analysis, security events, and penetration testing. Soft Skills Strong interpersonal and communication skills; experience with cross cultural communications. Calmness and clarity of thought under pressure and ability to maintain positive attitude. Agile and flexible, capable of dealing with ambiguity, and confronting challenges and opportunities with speed, endurance, and decisiveness. Confidence to manage upwards, provide forward thinking ideas and actively participate in improving CFGI's cyber offering. Technical Qualifications and Certifications Industry certifications are preferred, but not required: CISSP, CISM, etc. Technology specific qualifications in technology or security solutions. Experience Whilst we will judge the quality of candidates not their time served in the industry, a good gauge for this role would be around 5 years' experience in technology and security related fields. Your experience does not have to be purely cyber security consulting. We believe individuals with practical skillsets from in house roles, broader technology management or GRC, for example, would be well placed in our team. We know great candidates bring a mix of skills and experiences, you don't need to have done everything listed in this job description to apply.
22/07/2026
Full time
About CFGI CFGI is a global consulting firm that helps organisations navigate complex business challenges with confidence. With a strong presence in the UK, we partner with companies across industries to deliver best-in-class advisory services in accounting, risk, cyber security, technology, and business transformation. We pride ourselves on combining technical expertise with a practical, hands on approach, helping our clients strengthen resilience, meet regulatory requirements, and stay ahead in an increasingly digital and risk driven landscape. Technical and Domain Experience Conduct cybersecurity maturity and risk assessment and for clients. Practical experience implementing security controls, in areas such as MDR, IAM, Network Security, Cloud Deployments. Advise clients on cybersecurity strategy, metrics and reporting for various levels of stakeholders, including Audit Committees and Board of Directors. Build risk management practices for clients, including policies, procedures, Risk Register, etc. Previous experience as a systems administrator, systems engineer, or security analyst. Understanding of operating system hardening principles, network design principles, and systems security. Guide clients in establishing cybersecurity policies, standards, and procedures. Manage cybersecurity training & awareness services for clients from design to implementation. Understanding of security analysis, security events, and penetration testing. Soft Skills Strong interpersonal and communication skills; experience with cross cultural communications. Calmness and clarity of thought under pressure and ability to maintain positive attitude. Agile and flexible, capable of dealing with ambiguity, and confronting challenges and opportunities with speed, endurance, and decisiveness. Confidence to manage upwards, provide forward thinking ideas and actively participate in improving CFGI's cyber offering. Technical Qualifications and Certifications Industry certifications are preferred, but not required: CISSP, CISM, etc. Technology specific qualifications in technology or security solutions. Experience Whilst we will judge the quality of candidates not their time served in the industry, a good gauge for this role would be around 5 years' experience in technology and security related fields. Your experience does not have to be purely cyber security consulting. We believe individuals with practical skillsets from in house roles, broader technology management or GRC, for example, would be well placed in our team. We know great candidates bring a mix of skills and experiences, you don't need to have done everything listed in this job description to apply.
Senior Cybersecurity & Risk Strategy Leader
CFGI
About CFGI CFGI is a global consulting firm that helps organisations navigate complex business challenges with confidence. With a strong presence in the UK, we partner with companies across industries to deliver best-in-class advisory services in accounting, risk, cyber security, technology, and business transformation. We pride ourselves on combining technical expertise with a practical, hands on approach, helping our clients strengthen resilience, meet regulatory requirements, and stay ahead in an increasingly digital and risk driven landscape. Technical and Domain Experience Conduct cybersecurity maturity and risk assessment and for clients. Practical experience implementing security controls, in areas such as MDR, IAM, Network Security, Cloud Deployments. Advise clients on cybersecurity strategy, metrics and reporting for various levels of stakeholders, including Audit Committees and Board of Directors. Build risk management practices for clients, including policies, procedures, Risk Register, etc. Previous experience as a systems administrator, systems engineer, or security analyst. Understanding of operating system hardening principles, network design principles, and systems security. Guide clients in establishing cybersecurity policies, standards, and procedures. Manage cybersecurity training & awareness services for clients from design to implementation. Understanding of security analysis, security events, and penetration testing. Soft Skills Strong interpersonal and communication skills; experience with cross cultural communications. Calmness and clarity of thought under pressure and ability to maintain positive attitude. Agile and flexible, capable of dealing with ambiguity, and confronting challenges and opportunities with speed, endurance, and decisiveness. Confidence to manage upwards, provide forward thinking ideas and actively participate in improving CFGI's cyber offering. Technical Qualifications and Certifications Industry certifications are preferred, but not required: CISSP, CISM, etc. Technology specific qualifications in technology or security solutions. Experience Whilst we will judge the quality of candidates not their time served in the industry, a good gauge for this role would be around 5 years' experience in technology and security related fields. Your experience does not have to be purely cyber security consulting. We believe individuals with practical skillsets from in house roles, broader technology management or GRC, for example, would be well placed in our team. We know great candidates bring a mix of skills and experiences, you don't need to have done everything listed in this job description to apply.
22/07/2026
Full time
About CFGI CFGI is a global consulting firm that helps organisations navigate complex business challenges with confidence. With a strong presence in the UK, we partner with companies across industries to deliver best-in-class advisory services in accounting, risk, cyber security, technology, and business transformation. We pride ourselves on combining technical expertise with a practical, hands on approach, helping our clients strengthen resilience, meet regulatory requirements, and stay ahead in an increasingly digital and risk driven landscape. Technical and Domain Experience Conduct cybersecurity maturity and risk assessment and for clients. Practical experience implementing security controls, in areas such as MDR, IAM, Network Security, Cloud Deployments. Advise clients on cybersecurity strategy, metrics and reporting for various levels of stakeholders, including Audit Committees and Board of Directors. Build risk management practices for clients, including policies, procedures, Risk Register, etc. Previous experience as a systems administrator, systems engineer, or security analyst. Understanding of operating system hardening principles, network design principles, and systems security. Guide clients in establishing cybersecurity policies, standards, and procedures. Manage cybersecurity training & awareness services for clients from design to implementation. Understanding of security analysis, security events, and penetration testing. Soft Skills Strong interpersonal and communication skills; experience with cross cultural communications. Calmness and clarity of thought under pressure and ability to maintain positive attitude. Agile and flexible, capable of dealing with ambiguity, and confronting challenges and opportunities with speed, endurance, and decisiveness. Confidence to manage upwards, provide forward thinking ideas and actively participate in improving CFGI's cyber offering. Technical Qualifications and Certifications Industry certifications are preferred, but not required: CISSP, CISM, etc. Technology specific qualifications in technology or security solutions. Experience Whilst we will judge the quality of candidates not their time served in the industry, a good gauge for this role would be around 5 years' experience in technology and security related fields. Your experience does not have to be purely cyber security consulting. We believe individuals with practical skillsets from in house roles, broader technology management or GRC, for example, would be well placed in our team. We know great candidates bring a mix of skills and experiences, you don't need to have done everything listed in this job description to apply.
Senior Technology Governance, Risk & Compliance (GRC) Specialist
Yorkshire Water Leeds, Yorkshire
Senior Technology Governance, Risk & Compliance (GRC) Specialist Hello! Thanks for stopping by. Let us tell you about all the great reasons to join us here at Yorkshire Water: We offer a competitive salary, depending on experience £51,563 - £64,474 (band 4a) Annual incentive related bonus (£1000 maximum bonus opportunity for the performance year) Attractive pension scheme (up to 12% company contribution) Development opportunities in line with the Senior Technology GRC Specialist progression plan 25 days annual leave plus bank holidays - plus 2 extra wellness days! Life assurance cover of 4 times pensionable salary A great benefits package - choose from health cash plan scheme, critical illness insurance, dental insurance, life assurance flex and partner cover. Retail savings scheme Online GP service, cycle to work scheme, gym membership discounts and many more! Location: This role will initially be based in Bradford but we're moving our office to Leeds Valley Park in September 2026, so you'll be based there in the future - Hybrid Working Work type: Permanent. 37 hours per week, Monday - Friday. We have an exciting opportunity for a Senior Technology GRC Specialist to join the Information & Cyber Security team at Yorkshire Water and be a part of helping Yorkshire Water to provide the best service to our customers. Could this be you? What we do Everyone has an idea of what a water company does. Here in Yorkshire, we make sure that over 5.4 million people living in the region and the millions of people who visit our region each year, can rely on our services, and have clean and safe drinking water on tap and that their wastewater is taken away. But for us, it's so much more than this. We look after communities, protect the environment, and plan to look after Yorkshire's water, today, tomorrow 24/7, 365 days a year. We provide essential water and wastewater services to every corner of the Yorkshire region, and play a key role in the region's health, wellbeing, and prosperity. New environmental legislation, unprecedented levels of investment and changing expectations from customers means that this is an exciting time to discover opportunities within the water industry. Information & Cyber Security team are a key part of how we plan to meet the changing expectations of customers and regulators. Where you fit in As our Senior Technology GRC Specialist you will Lead, mentor and develop Technology GRC analysts and junior team members, ensuring the team has the skills, knowledge and capabilities required to deliver effective governance, risk and compliance activities. Champion the value of governance, risk and compliance at management level, driving cultural change and embedding best-practice GRC principles across the organisation. Support the management and continual improvement of the Technology GRC and Risk Management Frameworks, ensuring alignment with regulatory requirements, industry standards and business objectives. Build and maintain effective relationships with senior leaders, business units, auditors, regulators, vendors and external agencies to support Technology governance, risk and compliance outcomes. Lead Technology compliance monitoring, controls testing and assurance activities, managing audits, findings, remediation plans, policy exemptions and ongoing compliance obligations. Conduct and facilitate Technology risk assessments, audits and reviews, maintaining risk registers, evaluating controls and providing proportionate recommendations to mitigate risk and strengthen resilience. Provide expert advice, guidance and training on Technology governance, risk and compliance matters, enabling informed decision-making and increasing organisational awareness. Develop, implement, maintain and assure Technology policies, standards and procedures, ensuring they remain effective, compliant and aligned with recognised frameworks and best practice. Support Technology incident investigations and regulatory reporting requirements, coordinating with stakeholders and data owners to ensure incidents are effectively managed and resolved in accordance with legal and company obligations. Manage Technology GRC reporting, metrics, KPIs and KRIs, while driving continuous improvement, influencing stakeholders, supporting commercial objectives and fostering strong collaboration across the organisation. What skills & qualifications you will need Certification in information technology, Computer Science, Information Systems or a related discipline, or equivalent demonstrable industry experience. Proven experience in Technology Governance, Risk and Compliance, with at least three years operating in a senior specialist or leadership role. Strong track record of partnering with senior leaders and stakeholders to provide expert advice, guidance and training on governance, risk and compliance matters. Comprehensive knowledge of recognised Technology GRC frameworks, standards and methodologies, including COBIT, ITIL, ISO 27001, NIST and GDPR. Highly developed influencing, negotiation and stakeholder management skills, with the ability to build credibility, drive engagement and inspire positive change. Excellent analytical, problem-solving and decision-making capabilities, with experience identifying, assessing and mitigating Technology risks through practical and effective controls. Strong communication, presentation, organisational and project management skills, with the ability to explain complex technical and compliance concepts to a wide range of audiences and manage competing priorities effectively. Demonstrates high levels of professionalism, integrity and discretion, alongside a proactive, innovative mindset and the ability to adapt to evolving technologies, risks and regulatory requirements. You will also benefit from having Experience operating in a strategic and/or operational leadership role within a commercial and/or highly regulated environment, with the ability to balance business objectives and regulatory obligations. Demonstrable experience in Technology and Information Security incident management and investigations, including working within established governance and reporting frameworks. Good understanding of General Data Protection Regulation (GDPR) requirements, with practical experience of working alongside legal, audit and compliance teams to ensure regulatory adherence. Proven experience conducting Technology compliance reviews and audits, alongside strong stakeholder, vendor and third-party management and negotiation skills. Although we operate 24 hours a day, 365 days a year, it's important to us that we support flexible working patterns and job share options (when we can), to help you make the best of both your work and home life. We know that juggling childcare responsibilities or getting that ideal work/life balance isn't always easy! Do we sound like your cup of tea? If you've got experience as a Senior Technology GRC Specialist and want to help us deliver great service for our customers whilst looking after the environment, then be sure to apply today to find out what a career with Yorkshire Water can offer you. If successful for the role, you will be required to undergo pre-employment checks that will include a Basic Disclosure Check, carried out through a Third-Party Company, prior to commencing employment. Depending on the role, you may also be required to go through the security vetting process for either a Counter Terrorist Check or Security Check clearance. All our roles are subject to a medical questionnaire, and further medicals when required. We are committed to removing barriers and ensuring our recruitment process is accessible to everyone. We offer a range of adjustments to make your application experience as comfortable and straightforward as possible. If you have an accessibility need, disability, or condition that requires changes to the recruitment process, please include this information in your application. We will then discuss any reasonable adjustments required. Kelda Group reserve the right to close this position before the published closing date, should the need occur. We therefore advise that you complete and submit your application as soon as possible.
20/07/2026
Full time
Senior Technology Governance, Risk & Compliance (GRC) Specialist Hello! Thanks for stopping by. Let us tell you about all the great reasons to join us here at Yorkshire Water: We offer a competitive salary, depending on experience £51,563 - £64,474 (band 4a) Annual incentive related bonus (£1000 maximum bonus opportunity for the performance year) Attractive pension scheme (up to 12% company contribution) Development opportunities in line with the Senior Technology GRC Specialist progression plan 25 days annual leave plus bank holidays - plus 2 extra wellness days! Life assurance cover of 4 times pensionable salary A great benefits package - choose from health cash plan scheme, critical illness insurance, dental insurance, life assurance flex and partner cover. Retail savings scheme Online GP service, cycle to work scheme, gym membership discounts and many more! Location: This role will initially be based in Bradford but we're moving our office to Leeds Valley Park in September 2026, so you'll be based there in the future - Hybrid Working Work type: Permanent. 37 hours per week, Monday - Friday. We have an exciting opportunity for a Senior Technology GRC Specialist to join the Information & Cyber Security team at Yorkshire Water and be a part of helping Yorkshire Water to provide the best service to our customers. Could this be you? What we do Everyone has an idea of what a water company does. Here in Yorkshire, we make sure that over 5.4 million people living in the region and the millions of people who visit our region each year, can rely on our services, and have clean and safe drinking water on tap and that their wastewater is taken away. But for us, it's so much more than this. We look after communities, protect the environment, and plan to look after Yorkshire's water, today, tomorrow 24/7, 365 days a year. We provide essential water and wastewater services to every corner of the Yorkshire region, and play a key role in the region's health, wellbeing, and prosperity. New environmental legislation, unprecedented levels of investment and changing expectations from customers means that this is an exciting time to discover opportunities within the water industry. Information & Cyber Security team are a key part of how we plan to meet the changing expectations of customers and regulators. Where you fit in As our Senior Technology GRC Specialist you will Lead, mentor and develop Technology GRC analysts and junior team members, ensuring the team has the skills, knowledge and capabilities required to deliver effective governance, risk and compliance activities. Champion the value of governance, risk and compliance at management level, driving cultural change and embedding best-practice GRC principles across the organisation. Support the management and continual improvement of the Technology GRC and Risk Management Frameworks, ensuring alignment with regulatory requirements, industry standards and business objectives. Build and maintain effective relationships with senior leaders, business units, auditors, regulators, vendors and external agencies to support Technology governance, risk and compliance outcomes. Lead Technology compliance monitoring, controls testing and assurance activities, managing audits, findings, remediation plans, policy exemptions and ongoing compliance obligations. Conduct and facilitate Technology risk assessments, audits and reviews, maintaining risk registers, evaluating controls and providing proportionate recommendations to mitigate risk and strengthen resilience. Provide expert advice, guidance and training on Technology governance, risk and compliance matters, enabling informed decision-making and increasing organisational awareness. Develop, implement, maintain and assure Technology policies, standards and procedures, ensuring they remain effective, compliant and aligned with recognised frameworks and best practice. Support Technology incident investigations and regulatory reporting requirements, coordinating with stakeholders and data owners to ensure incidents are effectively managed and resolved in accordance with legal and company obligations. Manage Technology GRC reporting, metrics, KPIs and KRIs, while driving continuous improvement, influencing stakeholders, supporting commercial objectives and fostering strong collaboration across the organisation. What skills & qualifications you will need Certification in information technology, Computer Science, Information Systems or a related discipline, or equivalent demonstrable industry experience. Proven experience in Technology Governance, Risk and Compliance, with at least three years operating in a senior specialist or leadership role. Strong track record of partnering with senior leaders and stakeholders to provide expert advice, guidance and training on governance, risk and compliance matters. Comprehensive knowledge of recognised Technology GRC frameworks, standards and methodologies, including COBIT, ITIL, ISO 27001, NIST and GDPR. Highly developed influencing, negotiation and stakeholder management skills, with the ability to build credibility, drive engagement and inspire positive change. Excellent analytical, problem-solving and decision-making capabilities, with experience identifying, assessing and mitigating Technology risks through practical and effective controls. Strong communication, presentation, organisational and project management skills, with the ability to explain complex technical and compliance concepts to a wide range of audiences and manage competing priorities effectively. Demonstrates high levels of professionalism, integrity and discretion, alongside a proactive, innovative mindset and the ability to adapt to evolving technologies, risks and regulatory requirements. You will also benefit from having Experience operating in a strategic and/or operational leadership role within a commercial and/or highly regulated environment, with the ability to balance business objectives and regulatory obligations. Demonstrable experience in Technology and Information Security incident management and investigations, including working within established governance and reporting frameworks. Good understanding of General Data Protection Regulation (GDPR) requirements, with practical experience of working alongside legal, audit and compliance teams to ensure regulatory adherence. Proven experience conducting Technology compliance reviews and audits, alongside strong stakeholder, vendor and third-party management and negotiation skills. Although we operate 24 hours a day, 365 days a year, it's important to us that we support flexible working patterns and job share options (when we can), to help you make the best of both your work and home life. We know that juggling childcare responsibilities or getting that ideal work/life balance isn't always easy! Do we sound like your cup of tea? If you've got experience as a Senior Technology GRC Specialist and want to help us deliver great service for our customers whilst looking after the environment, then be sure to apply today to find out what a career with Yorkshire Water can offer you. If successful for the role, you will be required to undergo pre-employment checks that will include a Basic Disclosure Check, carried out through a Third-Party Company, prior to commencing employment. Depending on the role, you may also be required to go through the security vetting process for either a Counter Terrorist Check or Security Check clearance. All our roles are subject to a medical questionnaire, and further medicals when required. We are committed to removing barriers and ensuring our recruitment process is accessible to everyone. We offer a range of adjustments to make your application experience as comfortable and straightforward as possible. If you have an accessibility need, disability, or condition that requires changes to the recruitment process, please include this information in your application. We will then discuss any reasonable adjustments required. Kelda Group reserve the right to close this position before the published closing date, should the need occur. We therefore advise that you complete and submit your application as soon as possible.
Senior Risk Management Analyst
Cubic Corporation Salfords, Surrey
Business Unit:Cubic Transportation SystemsCompany Details:When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people's lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation. Led by our talented teams around the world, Cubic is committed to solving global issues through innovation and service to our customers and partners.We have a top-tier portfolio of businesses, including Cubic Transportation Systems (CTS) and Cubic Defense (CD). Explore more on Details:Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly. A significant feature is providing Fare and Payment card services to government and municipal customers across the globe.Job Summary:As Member of the Cubic information security team, you will provide security compliance support for production transaction processing environments. Evaluate posture of security controls and operating environment to ensure compliance with organization security policies and controls. Plans and prepares the scope of IT compliance evaluation programs across the organization and isolates potential risks or liabilities and develops mitigation plans. Partners with external auditors to coordinate and facilitate PCI-DSS, ISO 27001, etc. compliance/audit efforts. This position typically works under limited supervision and direction. Candidates for this position will regularly exercise discretionary and substantial decision-making authority.RESPONSIBILITIESEssential Job Duties and ResponsibilitiesPerform as the recognized Subject Matter Expert on Security Risk Assessment methodology, policy, strategy and processes.Facilitate all security audit operations, including scheduling, vendor coordination, program, and stakeholder coordination.Responsible for coordination with the Internal/External Auditors and Information Technology teams to successfully complete periodic audits. Works independently to schedule and conduct control walk through meetings and address follow up procedures to ensure all stakeholders understand duties and responsibilitiesLead the design and control reviews and assessments to support continuous compliance with security policies and standardsManage security review processes for all solutions to ensure they their design and implementation meets compliance requirements - including PCI-DSS, ISO 27001, SOC 1 & SOC 2 and other regional requirements Document and actively communicate any areas where the solutions and processes are not fully compliant.Identify and report significant information security risks associated with applications, development, networking, data centers, Cloud and physical IT infrastructure, vendors and other third parties.Identify stakeholders in remediation of compliance gaps and actively escalate issues to them in a constructive manner that helps them understand the actions required. Work to gain acceptance of responsibility and track progress towards remediation. Actively manage escalation as needed if solutions are not resolved in a timely manner.Work with system operators and security subject matter experts to communicate system compliance gaps and develop acceptable remediation plans.Capture compliance gaps and remediation plans in the OneTrust GRC system. Plans, reviews, and performs (as needed) controls monitoring around complex customer facing systems using the One Trust.Liaisengage with Cubic customers and Security Teams to build positive relationships and outcomesSupports efforts to educate Security Management and Security Team Members in compliant IT processes and controls. Prepare and maintain process and control documentationAid in the development of solutions to problems identified during audits and translates these solutions into practical recommendations. Partner with Operations and Engineering Teams to ensure timely and acceptable remediation of issues.Follow up on recommendations and appraises corrective actions taken to improve deficient conditions. To the greatest extent possible, ensure all Corporate Standards, SDLC, Change Management, and risk governance protocols are followed.Review vendor contracts and SOC reports to evaluate the impact on the company's controls. Coordinates with third party vendors where appropriate.General Duties and Responsibilities:Reliably demonstrate accountability for work assignments and proactive communications about issues and status. A strong history of proactively identifying effective solutions for challenges.Able to reliably demonstrate ethical behavior and accurate communications even when complex factors are involved.Able to operate in a professional manner, even in tense or continuous with Cubic's Quality Management SystemComply with Cubic's quality, health, safety, and security policies.Support the company's strategic objectives and collaborate across with Cubic Human Resources ProceduresSKILLS/EXPERIENCE/KNOWLEDGEEssential:Strong written and oral communication skills in English, with capability to use Microsoft Office solutions. Ability to effectively and openly collaborate with team members clients, IT management, staff, and business units in a cross functional and matrixed IT organizationComfortable working with staff at all levels and in other geographical locations within the organizationFamiliarity with PCI DSS 4, ISO , and or SOC I/II requirements and audits.Expert level experience collaborating with stakeholders and solution providers in a cross functional and matrixed IT organization. Able to adapt style efforts to persuade in delivering messages that relate to the wider business. Is frequently called on to advise others on complex matters and may be accountable through team for delivery of business targets.Exhibits advanced wide- ranging experience, using in- depth professional knowledge, acumen, concepts and company objectives to develop, resolve complex models and procedures. Provides solutions to issues in creative and effective ways. Understands the interrelationships of different disciplines. Directs the application of existing principles and guides development of new policies and ideas.Understands and works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors. Determines methods and procedures on new assignments. Exercises judgment in selecting methods, evaluating, adapting complex techniques and evaluation criteria for obtaining results.Desirable:Deep understanding of security risks and threats as they relate to the company's operating environments.QUALIFICATIONSEssential:Experience in services or IT systems in a mission critical setting.University degree in Computer Science, Engineering, or other technical fields, or Business Administration with relevant IT work experience.Experience working in IT security and/or Payment Card processing systems. Strong understanding of technical concepts, as well as demonstrated ability to understand complex internally developed systems.The candidate must reside within commuting distance from CTS offices in, and be able to periodically travel within the region.DesirableRelevant security or IT compliance certification in one or more areas, such as CISA, CRISC, CCSK, CCISSP, GIAC, PCI-ISA/QSA or equivalent.Knowledge of or willingness to learn information security best practices as it pertains to Open Payments, Mobility as a Service, data classifications, Microsoft Azure, AWS (or similar) cloud security and infrastructure, Web infrastructure security (Applications and APIs), Network security tools (IDS/IPS, firewalls, etc.), Encryption technology and implementation, Database security, Operating system security and hardening, vulnerability assessment tools and writing risk mitigation plans according to the assessment, and SIEM and FIM solutions.Worker Type:EmployeeWe are committed to creating an inclusive workplace and welcome applications from people of all backgrounds. We do not discriminate based on any protected characteristic under applicable law.
20/07/2026
Full time
Business Unit:Cubic Transportation SystemsCompany Details:When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people's lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation. Led by our talented teams around the world, Cubic is committed to solving global issues through innovation and service to our customers and partners.We have a top-tier portfolio of businesses, including Cubic Transportation Systems (CTS) and Cubic Defense (CD). Explore more on Details:Cubic Transportation Systems (CTS) is a global leader in intelligent transportation solutions, specializing in technologies that make public transit more efficient, accessible, and user-friendly. A significant feature is providing Fare and Payment card services to government and municipal customers across the globe.Job Summary:As Member of the Cubic information security team, you will provide security compliance support for production transaction processing environments. Evaluate posture of security controls and operating environment to ensure compliance with organization security policies and controls. Plans and prepares the scope of IT compliance evaluation programs across the organization and isolates potential risks or liabilities and develops mitigation plans. Partners with external auditors to coordinate and facilitate PCI-DSS, ISO 27001, etc. compliance/audit efforts. This position typically works under limited supervision and direction. Candidates for this position will regularly exercise discretionary and substantial decision-making authority.RESPONSIBILITIESEssential Job Duties and ResponsibilitiesPerform as the recognized Subject Matter Expert on Security Risk Assessment methodology, policy, strategy and processes.Facilitate all security audit operations, including scheduling, vendor coordination, program, and stakeholder coordination.Responsible for coordination with the Internal/External Auditors and Information Technology teams to successfully complete periodic audits. Works independently to schedule and conduct control walk through meetings and address follow up procedures to ensure all stakeholders understand duties and responsibilitiesLead the design and control reviews and assessments to support continuous compliance with security policies and standardsManage security review processes for all solutions to ensure they their design and implementation meets compliance requirements - including PCI-DSS, ISO 27001, SOC 1 & SOC 2 and other regional requirements Document and actively communicate any areas where the solutions and processes are not fully compliant.Identify and report significant information security risks associated with applications, development, networking, data centers, Cloud and physical IT infrastructure, vendors and other third parties.Identify stakeholders in remediation of compliance gaps and actively escalate issues to them in a constructive manner that helps them understand the actions required. Work to gain acceptance of responsibility and track progress towards remediation. Actively manage escalation as needed if solutions are not resolved in a timely manner.Work with system operators and security subject matter experts to communicate system compliance gaps and develop acceptable remediation plans.Capture compliance gaps and remediation plans in the OneTrust GRC system. Plans, reviews, and performs (as needed) controls monitoring around complex customer facing systems using the One Trust.Liaisengage with Cubic customers and Security Teams to build positive relationships and outcomesSupports efforts to educate Security Management and Security Team Members in compliant IT processes and controls. Prepare and maintain process and control documentationAid in the development of solutions to problems identified during audits and translates these solutions into practical recommendations. Partner with Operations and Engineering Teams to ensure timely and acceptable remediation of issues.Follow up on recommendations and appraises corrective actions taken to improve deficient conditions. To the greatest extent possible, ensure all Corporate Standards, SDLC, Change Management, and risk governance protocols are followed.Review vendor contracts and SOC reports to evaluate the impact on the company's controls. Coordinates with third party vendors where appropriate.General Duties and Responsibilities:Reliably demonstrate accountability for work assignments and proactive communications about issues and status. A strong history of proactively identifying effective solutions for challenges.Able to reliably demonstrate ethical behavior and accurate communications even when complex factors are involved.Able to operate in a professional manner, even in tense or continuous with Cubic's Quality Management SystemComply with Cubic's quality, health, safety, and security policies.Support the company's strategic objectives and collaborate across with Cubic Human Resources ProceduresSKILLS/EXPERIENCE/KNOWLEDGEEssential:Strong written and oral communication skills in English, with capability to use Microsoft Office solutions. Ability to effectively and openly collaborate with team members clients, IT management, staff, and business units in a cross functional and matrixed IT organizationComfortable working with staff at all levels and in other geographical locations within the organizationFamiliarity with PCI DSS 4, ISO , and or SOC I/II requirements and audits.Expert level experience collaborating with stakeholders and solution providers in a cross functional and matrixed IT organization. Able to adapt style efforts to persuade in delivering messages that relate to the wider business. Is frequently called on to advise others on complex matters and may be accountable through team for delivery of business targets.Exhibits advanced wide- ranging experience, using in- depth professional knowledge, acumen, concepts and company objectives to develop, resolve complex models and procedures. Provides solutions to issues in creative and effective ways. Understands the interrelationships of different disciplines. Directs the application of existing principles and guides development of new policies and ideas.Understands and works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors. Determines methods and procedures on new assignments. Exercises judgment in selecting methods, evaluating, adapting complex techniques and evaluation criteria for obtaining results.Desirable:Deep understanding of security risks and threats as they relate to the company's operating environments.QUALIFICATIONSEssential:Experience in services or IT systems in a mission critical setting.University degree in Computer Science, Engineering, or other technical fields, or Business Administration with relevant IT work experience.Experience working in IT security and/or Payment Card processing systems. Strong understanding of technical concepts, as well as demonstrated ability to understand complex internally developed systems.The candidate must reside within commuting distance from CTS offices in, and be able to periodically travel within the region.DesirableRelevant security or IT compliance certification in one or more areas, such as CISA, CRISC, CCSK, CCISSP, GIAC, PCI-ISA/QSA or equivalent.Knowledge of or willingness to learn information security best practices as it pertains to Open Payments, Mobility as a Service, data classifications, Microsoft Azure, AWS (or similar) cloud security and infrastructure, Web infrastructure security (Applications and APIs), Network security tools (IDS/IPS, firewalls, etc.), Encryption technology and implementation, Database security, Operating system security and hardening, vulnerability assessment tools and writing risk mitigation plans according to the assessment, and SIEM and FIM solutions.Worker Type:EmployeeWe are committed to creating an inclusive workplace and welcome applications from people of all backgrounds. We do not discriminate based on any protected characteristic under applicable law.
Senior Technology Governance, Risk & Compliance (GRC) Specialist
Yorkshire Water Bradford, Yorkshire
Senior Technology Governance, Risk & Compliance (GRC) Specialist Hello! Thanks for stopping by. Let us tell you about all the great reasons to join us here at Yorkshire Water: We offer a competitive salary, depending on experience £51,563 - £64,474 (band 4a) Annual incentive related bonus (£1000 maximum bonus opportunity for the performance year) Attractive pension scheme (up to 12% company contribution) Development opportunities in line with the Senior Technology GRC Specialist progression plan 25 days annual leave plus bank holidays - plus 2 extra wellness days! Life assurance cover of 4 times pensionable salary A great benefits package - choose from health cash plan scheme, critical illness insurance, dental insurance, life assurance flex and partner cover. Retail savings scheme Online GP service, cycle to work scheme, gym membership discounts and many more! Location: This role will initially be based in Bradford but we're moving our office to Leeds Valley Park in September 2026, so you'll be based there in the future - Hybrid Working Work type: Permanent. 37 hours per week, Monday - Friday. We have an exciting opportunity for a Senior Technology GRC Specialist to join the Information & Cyber Security team at Yorkshire Water and be a part of helping Yorkshire Water to provide the best service to our customers. Could this be you? What we do Everyone has an idea of what a water company does. Here in Yorkshire, we make sure that over 5.4 million people living in the region and the millions of people who visit our region each year, can rely on our services, and have clean and safe drinking water on tap and that their wastewater is taken away. But for us, it's so much more than this. We look after communities, protect the environment, and plan to look after Yorkshire's water, today, tomorrow 24/7, 365 days a year. We provide essential water and wastewater services to every corner of the Yorkshire region, and play a key role in the region's health, wellbeing, and prosperity. New environmental legislation, unprecedented levels of investment and changing expectations from customers means that this is an exciting time to discover opportunities within the water industry. Information & Cyber Security team are a key part of how we plan to meet the changing expectations of customers and regulators. Where you fit in As our Senior Technology GRC Specialist you will Lead, mentor and develop Technology GRC analysts and junior team members, ensuring the team has the skills, knowledge and capabilities required to deliver effective governance, risk and compliance activities. Champion the value of governance, risk and compliance at management level, driving cultural change and embedding best-practice GRC principles across the organisation. Support the management and continual improvement of the Technology GRC and Risk Management Frameworks, ensuring alignment with regulatory requirements, industry standards and business objectives. Build and maintain effective relationships with senior leaders, business units, auditors, regulators, vendors and external agencies to support Technology governance, risk and compliance outcomes. Lead Technology compliance monitoring, controls testing and assurance activities, managing audits, findings, remediation plans, policy exemptions and ongoing compliance obligations. Conduct and facilitate Technology risk assessments, audits and reviews, maintaining risk registers, evaluating controls and providing proportionate recommendations to mitigate risk and strengthen resilience. Provide expert advice, guidance and training on Technology governance, risk and compliance matters, enabling informed decision-making and increasing organisational awareness. Develop, implement, maintain and assure Technology policies, standards and procedures, ensuring they remain effective, compliant and aligned with recognised frameworks and best practice. Support Technology incident investigations and regulatory reporting requirements, coordinating with stakeholders and data owners to ensure incidents are effectively managed and resolved in accordance with legal and company obligations. Manage Technology GRC reporting, metrics, KPIs and KRIs, while driving continuous improvement, influencing stakeholders, supporting commercial objectives and fostering strong collaboration across the organisation. What skills & qualifications you will need Certification in information technology, Computer Science, Information Systems or a related discipline, or equivalent demonstrable industry experience. Proven experience in Technology Governance, Risk and Compliance, with at least three years operating in a senior specialist or leadership role. Strong track record of partnering with senior leaders and stakeholders to provide expert advice, guidance and training on governance, risk and compliance matters. Comprehensive knowledge of recognised Technology GRC frameworks, standards and methodologies, including COBIT, ITIL, ISO 27001, NIST and GDPR. Highly developed influencing, negotiation and stakeholder management skills, with the ability to build credibility, drive engagement and inspire positive change. Excellent analytical, problem-solving and decision-making capabilities, with experience identifying, assessing and mitigating Technology risks through practical and effective controls. Strong communication, presentation, organisational and project management skills, with the ability to explain complex technical and compliance concepts to a wide range of audiences and manage competing priorities effectively. Demonstrates high levels of professionalism, integrity and discretion, alongside a proactive, innovative mindset and the ability to adapt to evolving technologies, risks and regulatory requirements. You will also benefit from having Experience operating in a strategic and/or operational leadership role within a commercial and/or highly regulated environment, with the ability to balance business objectives and regulatory obligations. Demonstrable experience in Technology and Information Security incident management and investigations, including working within established governance and reporting frameworks. Good understanding of General Data Protection Regulation (GDPR) requirements, with practical experience of working alongside legal, audit and compliance teams to ensure regulatory adherence. Proven experience conducting Technology compliance reviews and audits, alongside strong stakeholder, vendor and third-party management and negotiation skills. Although we operate 24 hours a day, 365 days a year, it's important to us that we support flexible working patterns and job share options (when we can), to help you make the best of both your work and home life. We know that juggling childcare responsibilities or getting that ideal work/life balance isn't always easy! Do we sound like your cup of tea? If you've got experience as a Senior Technology GRC Specialist and want to help us deliver great service for our customers whilst looking after the environment, then be sure to apply today to find out what a career with Yorkshire Water can offer you. If successful for the role, you will be required to undergo pre-employment checks that will include a Basic Disclosure Check, carried out through a Third-Party Company, prior to commencing employment. Depending on the role, you may also be required to go through the security vetting process for either a Counter Terrorist Check or Security Check clearance. All our roles are subject to a medical questionnaire, and further medicals when required. We are committed to removing barriers and ensuring our recruitment process is accessible to everyone. We offer a range of adjustments to make your application experience as comfortable and straightforward as possible. If you have an accessibility need, disability, or condition that requires changes to the recruitment process, please include this information in your application. We will then discuss any reasonable adjustments required. Kelda Group reserve the right to close this position before the published closing date, should the need occur. We therefore advise that you complete and submit your application as soon as possible.
18/07/2026
Full time
Senior Technology Governance, Risk & Compliance (GRC) Specialist Hello! Thanks for stopping by. Let us tell you about all the great reasons to join us here at Yorkshire Water: We offer a competitive salary, depending on experience £51,563 - £64,474 (band 4a) Annual incentive related bonus (£1000 maximum bonus opportunity for the performance year) Attractive pension scheme (up to 12% company contribution) Development opportunities in line with the Senior Technology GRC Specialist progression plan 25 days annual leave plus bank holidays - plus 2 extra wellness days! Life assurance cover of 4 times pensionable salary A great benefits package - choose from health cash plan scheme, critical illness insurance, dental insurance, life assurance flex and partner cover. Retail savings scheme Online GP service, cycle to work scheme, gym membership discounts and many more! Location: This role will initially be based in Bradford but we're moving our office to Leeds Valley Park in September 2026, so you'll be based there in the future - Hybrid Working Work type: Permanent. 37 hours per week, Monday - Friday. We have an exciting opportunity for a Senior Technology GRC Specialist to join the Information & Cyber Security team at Yorkshire Water and be a part of helping Yorkshire Water to provide the best service to our customers. Could this be you? What we do Everyone has an idea of what a water company does. Here in Yorkshire, we make sure that over 5.4 million people living in the region and the millions of people who visit our region each year, can rely on our services, and have clean and safe drinking water on tap and that their wastewater is taken away. But for us, it's so much more than this. We look after communities, protect the environment, and plan to look after Yorkshire's water, today, tomorrow 24/7, 365 days a year. We provide essential water and wastewater services to every corner of the Yorkshire region, and play a key role in the region's health, wellbeing, and prosperity. New environmental legislation, unprecedented levels of investment and changing expectations from customers means that this is an exciting time to discover opportunities within the water industry. Information & Cyber Security team are a key part of how we plan to meet the changing expectations of customers and regulators. Where you fit in As our Senior Technology GRC Specialist you will Lead, mentor and develop Technology GRC analysts and junior team members, ensuring the team has the skills, knowledge and capabilities required to deliver effective governance, risk and compliance activities. Champion the value of governance, risk and compliance at management level, driving cultural change and embedding best-practice GRC principles across the organisation. Support the management and continual improvement of the Technology GRC and Risk Management Frameworks, ensuring alignment with regulatory requirements, industry standards and business objectives. Build and maintain effective relationships with senior leaders, business units, auditors, regulators, vendors and external agencies to support Technology governance, risk and compliance outcomes. Lead Technology compliance monitoring, controls testing and assurance activities, managing audits, findings, remediation plans, policy exemptions and ongoing compliance obligations. Conduct and facilitate Technology risk assessments, audits and reviews, maintaining risk registers, evaluating controls and providing proportionate recommendations to mitigate risk and strengthen resilience. Provide expert advice, guidance and training on Technology governance, risk and compliance matters, enabling informed decision-making and increasing organisational awareness. Develop, implement, maintain and assure Technology policies, standards and procedures, ensuring they remain effective, compliant and aligned with recognised frameworks and best practice. Support Technology incident investigations and regulatory reporting requirements, coordinating with stakeholders and data owners to ensure incidents are effectively managed and resolved in accordance with legal and company obligations. Manage Technology GRC reporting, metrics, KPIs and KRIs, while driving continuous improvement, influencing stakeholders, supporting commercial objectives and fostering strong collaboration across the organisation. What skills & qualifications you will need Certification in information technology, Computer Science, Information Systems or a related discipline, or equivalent demonstrable industry experience. Proven experience in Technology Governance, Risk and Compliance, with at least three years operating in a senior specialist or leadership role. Strong track record of partnering with senior leaders and stakeholders to provide expert advice, guidance and training on governance, risk and compliance matters. Comprehensive knowledge of recognised Technology GRC frameworks, standards and methodologies, including COBIT, ITIL, ISO 27001, NIST and GDPR. Highly developed influencing, negotiation and stakeholder management skills, with the ability to build credibility, drive engagement and inspire positive change. Excellent analytical, problem-solving and decision-making capabilities, with experience identifying, assessing and mitigating Technology risks through practical and effective controls. Strong communication, presentation, organisational and project management skills, with the ability to explain complex technical and compliance concepts to a wide range of audiences and manage competing priorities effectively. Demonstrates high levels of professionalism, integrity and discretion, alongside a proactive, innovative mindset and the ability to adapt to evolving technologies, risks and regulatory requirements. You will also benefit from having Experience operating in a strategic and/or operational leadership role within a commercial and/or highly regulated environment, with the ability to balance business objectives and regulatory obligations. Demonstrable experience in Technology and Information Security incident management and investigations, including working within established governance and reporting frameworks. Good understanding of General Data Protection Regulation (GDPR) requirements, with practical experience of working alongside legal, audit and compliance teams to ensure regulatory adherence. Proven experience conducting Technology compliance reviews and audits, alongside strong stakeholder, vendor and third-party management and negotiation skills. Although we operate 24 hours a day, 365 days a year, it's important to us that we support flexible working patterns and job share options (when we can), to help you make the best of both your work and home life. We know that juggling childcare responsibilities or getting that ideal work/life balance isn't always easy! Do we sound like your cup of tea? If you've got experience as a Senior Technology GRC Specialist and want to help us deliver great service for our customers whilst looking after the environment, then be sure to apply today to find out what a career with Yorkshire Water can offer you. If successful for the role, you will be required to undergo pre-employment checks that will include a Basic Disclosure Check, carried out through a Third-Party Company, prior to commencing employment. Depending on the role, you may also be required to go through the security vetting process for either a Counter Terrorist Check or Security Check clearance. All our roles are subject to a medical questionnaire, and further medicals when required. We are committed to removing barriers and ensuring our recruitment process is accessible to everyone. We offer a range of adjustments to make your application experience as comfortable and straightforward as possible. If you have an accessibility need, disability, or condition that requires changes to the recruitment process, please include this information in your application. We will then discuss any reasonable adjustments required. Kelda Group reserve the right to close this position before the published closing date, should the need occur. We therefore advise that you complete and submit your application as soon as possible.
Lead Analyst - Data Products & Integrity, Compliance Data Enablement
7360-Janssen-Cilag Limited Legal Entity High Wycombe, Buckinghamshire
Company Overview At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at Job Summary Legal & Compliance / Health Care Compliance. Lead Analyst - Data Products & Integrity, Compliance Data Enablement, located in New Brunswick, NJ or other J&J location in the Americas, EMEA or ASPAC. Reporting to the Senior Manager, Compliance Data Enablement. Responsibilities Design, build, and maintain curated, reusable datasets and data products for the global HCC data ecosystem, including transparency reporting. Design and implement data quality controls within data products to improve completeness, accuracy, consistency, and timeliness. Proactively identify root causes of data quality issues and partner with process and system owners to prevent recurring defects. Contribute to the data product lifecycle, including intake, design, delivery, maintenance, issue management, and continuous improvement. Structure data for analytics, audit, compliance monitoring, reporting, and business consumption. Support ad hoc data requests, rapid insights, PoCs, and pilots by providing fit for purpose data assets and practical guidance. Participate in a Data Concierge model to triage incoming data requests, provide rapid insights, or route needs into structured data product development. Partner with analytics, strategic enablement, technology, regional HCC, and reporting teams to co develop data products and respond to changing business, compliance, and regulatory needs. Enable business users through structured, reusable data assets, clear documentation, and practical guidance on appropriate data use. Support data catalogue development and data discoverability by maintaining metadata, definitions, lineage, and usage documentation. Ensure data products align with data governance standards, privacy expectations, access controls, and approved ways of working. Identify data process gaps, risks, and improvement opportunities across the HCC data ecosystem. Qualifications & Requirements Minimum 6 years of professional experience, preferably in pharmaceutical, medical device, health care, compliance, data, or analytics environments. Experience with transaction systems, data products, analytics datasets, external reporting, or compliance monitoring, with a focus on accuracy, usability, and compliance with local and global standards. High integrity, ethical judgement, Credo-based decision making. Strong attention to detail, problem solving, analytical thinking. Stakeholder partnership, cross functional teaming, user focused enablement. Results driven, adaptable, and committed to continuous improvement and learning. Tools and Analytics SQL, Python, Alteryx, data profiling, modern analytics/reporting tools such as Power BI, Tableau, Qlik Sense, AWS, MS Fabric, Databricks, or similar platforms. Data Products and Modelling Ability to design reusable data products, structure data for analytics, reporting, and compliance use cases, and manage ownership, purpose, quality expectations, and lifecycle. Data Governance and Quality Knowledge of data ownership, stewardship, metadata, catalogues, access controls, documentation, validation, anomaly detection, and quality metrics. Root Cause and Improvement Ability to investigate data issues, identify causes, and implement sustainable controls with process and system owners. Business Translation and Communication Ability to translate business, compliance, reporting, and analytics needs into practical data solutions and explain data concepts clearly to global stakeholders. Location and Travel New Brunswick, NJ, or another J&J location in the Americas, EMEA or ASPAC. Up to 5% domestic and/or international travel may be required. Required Skills Communication Complaints Investigation Compliance Management Corporate Governance Critical Thinking Data Reporting Detail Oriented Governance Risk and Compliance (GRC) Platforms Healthcare Industry Health Care Regulation Internal Auditing Legal Services Medical Compliance Organizing Problem Solving Process Improvements Preferred Skills Communication Complaints Investigation Compliance Management Corporate Governance Critical Thinking Data Reporting Detail Oriented Governance Risk and Compliance (GRC) Platforms Healthcare Industry Health Care Regulation Internal Auditing Legal Services Medical Compliance Organizing Problem Solving Process Improvements
17/07/2026
Full time
Company Overview At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at Job Summary Legal & Compliance / Health Care Compliance. Lead Analyst - Data Products & Integrity, Compliance Data Enablement, located in New Brunswick, NJ or other J&J location in the Americas, EMEA or ASPAC. Reporting to the Senior Manager, Compliance Data Enablement. Responsibilities Design, build, and maintain curated, reusable datasets and data products for the global HCC data ecosystem, including transparency reporting. Design and implement data quality controls within data products to improve completeness, accuracy, consistency, and timeliness. Proactively identify root causes of data quality issues and partner with process and system owners to prevent recurring defects. Contribute to the data product lifecycle, including intake, design, delivery, maintenance, issue management, and continuous improvement. Structure data for analytics, audit, compliance monitoring, reporting, and business consumption. Support ad hoc data requests, rapid insights, PoCs, and pilots by providing fit for purpose data assets and practical guidance. Participate in a Data Concierge model to triage incoming data requests, provide rapid insights, or route needs into structured data product development. Partner with analytics, strategic enablement, technology, regional HCC, and reporting teams to co develop data products and respond to changing business, compliance, and regulatory needs. Enable business users through structured, reusable data assets, clear documentation, and practical guidance on appropriate data use. Support data catalogue development and data discoverability by maintaining metadata, definitions, lineage, and usage documentation. Ensure data products align with data governance standards, privacy expectations, access controls, and approved ways of working. Identify data process gaps, risks, and improvement opportunities across the HCC data ecosystem. Qualifications & Requirements Minimum 6 years of professional experience, preferably in pharmaceutical, medical device, health care, compliance, data, or analytics environments. Experience with transaction systems, data products, analytics datasets, external reporting, or compliance monitoring, with a focus on accuracy, usability, and compliance with local and global standards. High integrity, ethical judgement, Credo-based decision making. Strong attention to detail, problem solving, analytical thinking. Stakeholder partnership, cross functional teaming, user focused enablement. Results driven, adaptable, and committed to continuous improvement and learning. Tools and Analytics SQL, Python, Alteryx, data profiling, modern analytics/reporting tools such as Power BI, Tableau, Qlik Sense, AWS, MS Fabric, Databricks, or similar platforms. Data Products and Modelling Ability to design reusable data products, structure data for analytics, reporting, and compliance use cases, and manage ownership, purpose, quality expectations, and lifecycle. Data Governance and Quality Knowledge of data ownership, stewardship, metadata, catalogues, access controls, documentation, validation, anomaly detection, and quality metrics. Root Cause and Improvement Ability to investigate data issues, identify causes, and implement sustainable controls with process and system owners. Business Translation and Communication Ability to translate business, compliance, reporting, and analytics needs into practical data solutions and explain data concepts clearly to global stakeholders. Location and Travel New Brunswick, NJ, or another J&J location in the Americas, EMEA or ASPAC. Up to 5% domestic and/or international travel may be required. Required Skills Communication Complaints Investigation Compliance Management Corporate Governance Critical Thinking Data Reporting Detail Oriented Governance Risk and Compliance (GRC) Platforms Healthcare Industry Health Care Regulation Internal Auditing Legal Services Medical Compliance Organizing Problem Solving Process Improvements Preferred Skills Communication Complaints Investigation Compliance Management Corporate Governance Critical Thinking Data Reporting Detail Oriented Governance Risk and Compliance (GRC) Platforms Healthcare Industry Health Care Regulation Internal Auditing Legal Services Medical Compliance Organizing Problem Solving Process Improvements
Governance, Risk & Compliance (GRC) Analyst
Quilter plc Southampton, Hampshire
About the Business Quilter plc is a leading wealth management business, overseeing £141.2billion in customer investments. It offers financial advice, investment platforms, multi asset solutions and discretionary fund management through its Affluent and High Net Worth segments. Position Details Level: 3 Department: COO - Business Risk Location: Southampton, United Kingdom (Hybrid: 2-3 days per week in office) Contract: Permanent Regulated: Non Regulated Role Overview We are looking for a Governance, Risk & Compliance (GRC) Analyst to support the COO Business Risk and Governance team. The role embeds our enterprise and operational risk management frameworks, supports informed decision making and promotes a positive risk culture aligned to the Group COO's SMCR responsibilities. Key Responsibilities Support COO first line of defence colleagues with GRC activity, queries and regulatory requests. Implement, embed and improve Quilter's risk management frameworks. Provide analysis, insight, briefings, reports and presentations for decision making. Track industry, regulatory and internal methodology changes; educate colleagues on key requirements. Identify opportunities to improve processes, increase efficiency, add value and enhance client outcomes. Support change activity in line with risk and governance frameworks. Build effective working relationships across business areas, central functions, 2nd line Risk, Internal Audit and external partners. Support related framework activity, including Supplier Due Diligence, Consumer Duty, Operational Resilience, Business Developed Applications and SMCR. Contribute to quarterly RCSA activity, audit activity, Group Policy Attestation processes and oversight of risk management activity. Provide assurance through testing, reviewing controls and preparing clear reports with recommendations. Produce accurate and insightful reporting for management and governance forums; support GRC metrics, data and reporting. Co ordinate governance processes and committee support (agendas, meeting materials, actions and records). Maintain accurate governance records for ExCo, Board and other senior forums. Support Corporate Governance requirements and delivery of Board and Committee papers. About You Highly motivated, adaptable and able to work autonomously under tight deadlines. Delivery focused with strong planning, analytical and communication skills. Experience in financial services, preferably within Affluent or high net worth segments. Knowledge of risk management practices and relevant regulatory bodies such as CASS, COBS, SMCR. Proficiency with Microsoft Word, Excel and the ability to use data and metrics to drive action. Credibility, professionalism, strong personal integrity and ability to influence across all levels. Consumer Duty While not a direct customer facing role, the duties performed support overall positive outcomes for our customers by enabling leaders to balance risk and reward and ensure regulatory compliance. This contributes to improved services, customer centric outcomes and overall satisfaction. Benefits Holiday: 182 hours (26 days) Quilter Incentive Scheme - all employees eligible for incentive participation. Non contributory company pension scheme, boostable via personal contributions. Private Medical Insurance - single cover standard with optional extension. Life Assurance - 4 salary. Income Protection - 75% of salary, payable after 26 weeks of absence. Healthcare Cash Plan - Jersey employees only. Flexible benefits available for UK employees via salary deduction. Inclusion & Diversity We value diversity and promote inclusivity in all aspects of our culture. We provide equal opportunities for all applicants and celebrate unique contributions. We are committed to treating all job applicants fairly and with respect, welcoming a wide range of backgrounds, identities and abilities. Reasonable adjustments are available upon request to ensure accessibility throughout the recruitment process.
16/07/2026
Full time
About the Business Quilter plc is a leading wealth management business, overseeing £141.2billion in customer investments. It offers financial advice, investment platforms, multi asset solutions and discretionary fund management through its Affluent and High Net Worth segments. Position Details Level: 3 Department: COO - Business Risk Location: Southampton, United Kingdom (Hybrid: 2-3 days per week in office) Contract: Permanent Regulated: Non Regulated Role Overview We are looking for a Governance, Risk & Compliance (GRC) Analyst to support the COO Business Risk and Governance team. The role embeds our enterprise and operational risk management frameworks, supports informed decision making and promotes a positive risk culture aligned to the Group COO's SMCR responsibilities. Key Responsibilities Support COO first line of defence colleagues with GRC activity, queries and regulatory requests. Implement, embed and improve Quilter's risk management frameworks. Provide analysis, insight, briefings, reports and presentations for decision making. Track industry, regulatory and internal methodology changes; educate colleagues on key requirements. Identify opportunities to improve processes, increase efficiency, add value and enhance client outcomes. Support change activity in line with risk and governance frameworks. Build effective working relationships across business areas, central functions, 2nd line Risk, Internal Audit and external partners. Support related framework activity, including Supplier Due Diligence, Consumer Duty, Operational Resilience, Business Developed Applications and SMCR. Contribute to quarterly RCSA activity, audit activity, Group Policy Attestation processes and oversight of risk management activity. Provide assurance through testing, reviewing controls and preparing clear reports with recommendations. Produce accurate and insightful reporting for management and governance forums; support GRC metrics, data and reporting. Co ordinate governance processes and committee support (agendas, meeting materials, actions and records). Maintain accurate governance records for ExCo, Board and other senior forums. Support Corporate Governance requirements and delivery of Board and Committee papers. About You Highly motivated, adaptable and able to work autonomously under tight deadlines. Delivery focused with strong planning, analytical and communication skills. Experience in financial services, preferably within Affluent or high net worth segments. Knowledge of risk management practices and relevant regulatory bodies such as CASS, COBS, SMCR. Proficiency with Microsoft Word, Excel and the ability to use data and metrics to drive action. Credibility, professionalism, strong personal integrity and ability to influence across all levels. Consumer Duty While not a direct customer facing role, the duties performed support overall positive outcomes for our customers by enabling leaders to balance risk and reward and ensure regulatory compliance. This contributes to improved services, customer centric outcomes and overall satisfaction. Benefits Holiday: 182 hours (26 days) Quilter Incentive Scheme - all employees eligible for incentive participation. Non contributory company pension scheme, boostable via personal contributions. Private Medical Insurance - single cover standard with optional extension. Life Assurance - 4 salary. Income Protection - 75% of salary, payable after 26 weeks of absence. Healthcare Cash Plan - Jersey employees only. Flexible benefits available for UK employees via salary deduction. Inclusion & Diversity We value diversity and promote inclusivity in all aspects of our culture. We provide equal opportunities for all applicants and celebrate unique contributions. We are committed to treating all job applicants fairly and with respect, welcoming a wide range of backgrounds, identities and abilities. Reasonable adjustments are available upon request to ensure accessibility throughout the recruitment process.
Hays Senior Finance
Interim Regulatory Analyst / GRC Consultant
Hays Senior Finance
Your New Company Join a large, complex organisation operating within a highly regulated environment, where compliance, governance and regulatory adherence are critical to business success. You'll be working alongside senior stakeholders, technology teams, security professionals and programme leaders to help interpret evolving regulatory requirements and support informed business decision-making. Your New Role As a Regulatory Analyst / GRC Consultant, you will act as a trusted advisor on regulatory and governance matters, providing expert guidance on how regulatory frameworks impact business operations, technology initiatives and strategic decisions. This is a consultative role focused on interpretation and advice rather than hands-on delivery, requiring someone who can analyse complex regulations and translate them into clear business implications and recommendations. Key responsibilities will include: Analysing regulatory frameworks including TSA, ISO 27001, SOX and related governance requirements. Providing strategic advice on regulatory and compliance impacts across projects and programmes. Acting as a regulatory subject matter expert during stakeholder meetings and discussions. Supporting responses to regulatory enquiries and customer compliance queries. Interpreting regulatory requirements and translating them into practical business recommendations. Identifying gaps between current practices and regulatory expectations. Advising senior stakeholders on compliance risks, obligations and best practice. Supporting a fast-paced environment where regulatory priorities can change quickly. What You'll Need to Succeed To be successful in this role, you will have: Strong experience within Regulatory Compliance, Governance, Risk & Compliance (GRC), Controls or Advisory environments. Proven experience interpreting complex regulatory or control frameworks and advising stakeholders accordingly. Knowledge of TSA (Telecoms Security Act) is highly desirable. Experience working with frameworks such as ISO 27001, SOX, NIST or similar governance and compliance standards. Excellent analytical and impact assessment skills. The ability to translate technical or regulatory requirements into clear business outcomes. Strong stakeholder management and communication skills. A consultative mindset with the confidence to challenge, advise and influence. Previous consultancy or advisory experience would be advantageous. What You'll Get in Return Competitive day rate of 590. Hybrid working model with approximately two days on-site per week. Opportunity to work within a complex regulatory environment on high-profile compliance initiatives. Exposure to senior stakeholders and strategic decision-making. A collaborative and fast-moving environment where your expertise will add real value What You Need to Do Now If you're an experienced Regulatory Analyst, GRC Consultant or Governance professional looking for your next contract opportunity, apply now or contact us for a confidential discussion. Please note that occasional travel to either Reading or Paddington may be required at short notice, and flexibility around on-site working is essential. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
15/07/2026
Seasonal
Your New Company Join a large, complex organisation operating within a highly regulated environment, where compliance, governance and regulatory adherence are critical to business success. You'll be working alongside senior stakeholders, technology teams, security professionals and programme leaders to help interpret evolving regulatory requirements and support informed business decision-making. Your New Role As a Regulatory Analyst / GRC Consultant, you will act as a trusted advisor on regulatory and governance matters, providing expert guidance on how regulatory frameworks impact business operations, technology initiatives and strategic decisions. This is a consultative role focused on interpretation and advice rather than hands-on delivery, requiring someone who can analyse complex regulations and translate them into clear business implications and recommendations. Key responsibilities will include: Analysing regulatory frameworks including TSA, ISO 27001, SOX and related governance requirements. Providing strategic advice on regulatory and compliance impacts across projects and programmes. Acting as a regulatory subject matter expert during stakeholder meetings and discussions. Supporting responses to regulatory enquiries and customer compliance queries. Interpreting regulatory requirements and translating them into practical business recommendations. Identifying gaps between current practices and regulatory expectations. Advising senior stakeholders on compliance risks, obligations and best practice. Supporting a fast-paced environment where regulatory priorities can change quickly. What You'll Need to Succeed To be successful in this role, you will have: Strong experience within Regulatory Compliance, Governance, Risk & Compliance (GRC), Controls or Advisory environments. Proven experience interpreting complex regulatory or control frameworks and advising stakeholders accordingly. Knowledge of TSA (Telecoms Security Act) is highly desirable. Experience working with frameworks such as ISO 27001, SOX, NIST or similar governance and compliance standards. Excellent analytical and impact assessment skills. The ability to translate technical or regulatory requirements into clear business outcomes. Strong stakeholder management and communication skills. A consultative mindset with the confidence to challenge, advise and influence. Previous consultancy or advisory experience would be advantageous. What You'll Get in Return Competitive day rate of 590. Hybrid working model with approximately two days on-site per week. Opportunity to work within a complex regulatory environment on high-profile compliance initiatives. Exposure to senior stakeholders and strategic decision-making. A collaborative and fast-moving environment where your expertise will add real value What You Need to Do Now If you're an experienced Regulatory Analyst, GRC Consultant or Governance professional looking for your next contract opportunity, apply now or contact us for a confidential discussion. Please note that occasional travel to either Reading or Paddington may be required at short notice, and flexibility around on-site working is essential. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Information Security GRC Analyst
GEDU CAREERS
Working Pattern: Full-Time - 40 hrs Per Week Salary Range: £40,000 to £42,500 Our Vision: Changing lives through education. We're looking for an Information Security GRC professional to join our team! If you have experience in risk, compliance, and frameworks like ISO 27001 or NIST, this is a great opportunity to make an impact across GBS and the GEDU Group. Please note, we are unable to offer sponsorship for this position. What the role involves: Perform risk assessments in line with security best practice and GBS/GEDU information security policies and procedures. Support the Information Security Manager in maintaining the corporate IS risk register and compiling monthly reporting to Senior Management via monthly and ad-hoc dashboards and summaries . Support the Information Security Manager to implement ISO 27001 framework for GBS and GEDU Group. Work with stakeholders to identify corrective action plans and reduce risks to acceptable levels. Continually improve the information security risk assessment process and documentation. Carry out third-party risk assessments for GBS and GEDU group. Produce, update and review all information security policies, and provide appropriate training where needed. Maintain and ensure compliance with all external regulatory requirements. Track and report on external and internal information security audit findings to ensure successful closure and completion. Maintain and assist in the regular update and provision of security awareness training to all levels of staff. Assist in efforts to plan and track progress toward security certifications (e.g., Cyber Essentials Plus) Assist with technical analysis and investigations by working collaboratively with technical analysts and the Information Security Manager QUALIFICATIONS: Bachelor's degree in information technology, Computer Science, or a related field. ESSENTIAL SKILLS and EXPERIENCE: Proven experience in implementing ISO 27001 compliance and Business Continuity/ITDR is mandatory. Experience in working with Governance Risk Compliance (GRC) and GRC reporting More than 5 years of experience in Information Security, Risk and IT Experience in performing impact, likelihood and risk analyses / assessments. Ability to 'translate' technical security issues into business risk. DESIRABLE SKILLS and EXPERIENCE: Knowledge of cyber audit and frameworks desirable Ability to form complex communications/messages/policies in a simple, clear and concise manner to various stakeholders and interested parties Analytical mindset and creative problem-solving links What we offer: Time off that fits your lifestyle - 33 days annual leave (including bank holidays), 1-day extra leave per year of service (up to 5 days) and Buy/Sell additional holidays (up to 5 days) Opportunities for growth - tuition reimbursement for career development courses, wide variety of training courses Pension Scheme and Flexible Benefits (via salary sacrifice) - Cycle to Work, Workplace Nursery, Tech, Health, Dental and Life Assurance schemes, Women's Health scheme (via Hertlity), and much more Discounts, Perks and Employee Assistance: discounts platform, Employee Assistance Programme (EAP), discounted gym membership, eyecare vouchers and much more Reward for your impact - annual salary increase reviews, annual discretionary bonus, £500 award, employee referral scheme GBS is committed to equality, diversity and inclusion and providing a workplace free from discrimination or harassment. We welcome applications from all backgrounds and communities. We take our core values seriously and work hard to create an environment where everyone feels welcomed. About Us GEDU Global Education is a dynamic and innovative group of education providers. Across our institutions, programmes are designed to have a direct impact on the lives of our students, apprentices and trainees; to equip them with the skills, knowledge and experience necessary for success in their chosen field. Job Info Job Identification 25761 Posting Date 05/19/2026, 09:09 AM Apply Before 06/14/2026, 11:00 PM Degree Level Bachelor's Degree Job Schedule Full time Locations 891 Greenford Road London, Greater London, UB6 0HE, GB Organization Global Banking School Ltd, Global Banking School Ltd, GEDU
14/07/2026
Full time
Working Pattern: Full-Time - 40 hrs Per Week Salary Range: £40,000 to £42,500 Our Vision: Changing lives through education. We're looking for an Information Security GRC professional to join our team! If you have experience in risk, compliance, and frameworks like ISO 27001 or NIST, this is a great opportunity to make an impact across GBS and the GEDU Group. Please note, we are unable to offer sponsorship for this position. What the role involves: Perform risk assessments in line with security best practice and GBS/GEDU information security policies and procedures. Support the Information Security Manager in maintaining the corporate IS risk register and compiling monthly reporting to Senior Management via monthly and ad-hoc dashboards and summaries . Support the Information Security Manager to implement ISO 27001 framework for GBS and GEDU Group. Work with stakeholders to identify corrective action plans and reduce risks to acceptable levels. Continually improve the information security risk assessment process and documentation. Carry out third-party risk assessments for GBS and GEDU group. Produce, update and review all information security policies, and provide appropriate training where needed. Maintain and ensure compliance with all external regulatory requirements. Track and report on external and internal information security audit findings to ensure successful closure and completion. Maintain and assist in the regular update and provision of security awareness training to all levels of staff. Assist in efforts to plan and track progress toward security certifications (e.g., Cyber Essentials Plus) Assist with technical analysis and investigations by working collaboratively with technical analysts and the Information Security Manager QUALIFICATIONS: Bachelor's degree in information technology, Computer Science, or a related field. ESSENTIAL SKILLS and EXPERIENCE: Proven experience in implementing ISO 27001 compliance and Business Continuity/ITDR is mandatory. Experience in working with Governance Risk Compliance (GRC) and GRC reporting More than 5 years of experience in Information Security, Risk and IT Experience in performing impact, likelihood and risk analyses / assessments. Ability to 'translate' technical security issues into business risk. DESIRABLE SKILLS and EXPERIENCE: Knowledge of cyber audit and frameworks desirable Ability to form complex communications/messages/policies in a simple, clear and concise manner to various stakeholders and interested parties Analytical mindset and creative problem-solving links What we offer: Time off that fits your lifestyle - 33 days annual leave (including bank holidays), 1-day extra leave per year of service (up to 5 days) and Buy/Sell additional holidays (up to 5 days) Opportunities for growth - tuition reimbursement for career development courses, wide variety of training courses Pension Scheme and Flexible Benefits (via salary sacrifice) - Cycle to Work, Workplace Nursery, Tech, Health, Dental and Life Assurance schemes, Women's Health scheme (via Hertlity), and much more Discounts, Perks and Employee Assistance: discounts platform, Employee Assistance Programme (EAP), discounted gym membership, eyecare vouchers and much more Reward for your impact - annual salary increase reviews, annual discretionary bonus, £500 award, employee referral scheme GBS is committed to equality, diversity and inclusion and providing a workplace free from discrimination or harassment. We welcome applications from all backgrounds and communities. We take our core values seriously and work hard to create an environment where everyone feels welcomed. About Us GEDU Global Education is a dynamic and innovative group of education providers. Across our institutions, programmes are designed to have a direct impact on the lives of our students, apprentices and trainees; to equip them with the skills, knowledge and experience necessary for success in their chosen field. Job Info Job Identification 25761 Posting Date 05/19/2026, 09:09 AM Apply Before 06/14/2026, 11:00 PM Degree Level Bachelor's Degree Job Schedule Full time Locations 891 Greenford Road London, Greater London, UB6 0HE, GB Organization Global Banking School Ltd, Global Banking School Ltd, GEDU
Information Security Analyst Information security London
Checkout Ltd
Company Description We're You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we're behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there's a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you've come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we're shaping the future of fintech - and we're just getting started. The Role As an Information Security Analyst at you will work across the full breadth of the information security function, spanning Governance, Risk and Compliance (GRC), AI Governance, Application Security (AppSec), Technology Risk, and Data Governance. This is a role for someone who has built a solid foundation in information security and is ready to move from guided execution to genuine ownership of tasks and smaller workstreams. Security at Checkout operates at scale and at pace. We are a global payments business, regulated across multiple jurisdictions, building infrastructure that processes billions of transactions. Our security function needs analysts who understand how different domains fit together, communicate clearly with technical and non-technical colleagues, and take accountability for the quality of their work. At L2 you will implement security controls, respond to security incidents, identify risks, and support compliance activities across multiple domains. You work independently for extended periods and are developing the cross-domain knowledge and stakeholder skills that will prepare you for programme ownership at L3 and beyond. How You'll Make Impact Governance, Risk and Compliance Support workstreams within Checkout's GRC programme, including ISO 27001, SOC 2, PCI DSS, and applicable regulatory obligations across our global licensed entities. Assist with control evidence collection activities, coordinating with internal teams to gather accurate and timely evidence in support of audit readiness. Maintain GRC documentation including policies, standards, procedures, and control matrices under the guidance of senior colleagues. Support monitoring of the risk register, tracking remediation activity against agreed timelines and escalating where commitments are at risk. Assist in conducting third party risk assessments, evaluating supplier security controls in line with Checkout's TPRM framework. Develop working knowledge of regulatory obligations across Checkout's operating markets, including FCA/PRA requirements, payment scheme rules, and DORA. AI Governance Support the operationalisation of Checkout's AI governance framework, aligned to ISO 42001, the EU AI Act, and NIST AI RMF. Assist in conducting AI risk assessments for internal AI and ML systems and third party AI tools, under the guidance of more senior analysts. Help maintain an inventory of AI use cases and associated risk classifications, working with product and engineering teams as directed. Develop awareness of the evolving regulatory landscape for AI in financial services and contribute to policy and control documentation. Contribute to the development and communication of responsible AI usage guidance for staff, helping teams across the business understand acceptable use boundaries, data handling expectations, and the risks associated with AI tools in a regulated environment. Application Security Contribute to Checkout's application security programme, including support for secure code review processes, SDLC integration, and developer security guidance. Support threat modelling activities for new and existing products, identifying security requirements under the guidance of senior colleagues. Assist in managing vulnerability findings from penetration tests, bug bounty programmes, and automated tooling, tracking remediation and validating fixes. Apply knowledge of the OWASP Top 10 and secure development frameworks to practical security reviews and guidance activities. Technology Risk Support technology risk assessments across infrastructure, cloud environments, and third party systems, contributing to outputs with actionable treatment recommendations. Assist with control assurance activities including vulnerability scanning coordination, access control assessments, and firewall and configuration reviews. Develop an understanding of Checkout's technology risk landscape, identifying emerging threats and contributing inputs to the risk register. Support DORA related ICT risk management activities under the direction of senior analysts. Data Governance Support Checkout's data governance programme, including data classification activities, data flow mapping, and enforcement of data handling standards. Assist with data loss prevention (DLP) controls and tooling, contributing to activities that ensure sensitive data is protected throughout its lifecycle. Help maintain records of processing activities (RoPA) and support data protection impact assessments (DPIAs) for new systems. Develop working knowledge of GDPR, UK GDPR, and applicable regional data protection requirements as they affect Checkout's operations. Cross domain Collaboration Work with Engineering, Product, Legal, Procurement, Finance, and Compliance teams to support the embedding of security requirements into processes, systems, and projects. Respond to security due diligence requests from merchants, partners, and regulators with accuracy and within agreed SLAs, escalating complex queries appropriately. Communicate clearly with internal stakeholders on security requirements, keeping teams updated on changes and project progress. Contribute to security awareness initiatives, promoting a security conscious culture across Checkout. What We're Looking for Experience 1 to 2 years of experience in information security, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Working knowledge of at least one of the following domains: GRC, AppSec, technology risk, or data governance. Practical familiarity with at least one compliance framework: PCI DSS, ISO 27001, SOC 2, NIST CSF, or equivalent. Some exposure to external audits, risk assessments, or security assurance activities. Ability to manage tasks independently and deliver on commitments reliably. Skills and Approach Clear written and verbal communication. You can translate security concepts for technical and non technical audiences. Detail oriented and methodical. You approach your work carefully and follow through consistently. Curious and proactive. You ask questions, flag issues early, and look for root causes rather than surface fixes. Collaborative and adaptable. You work effectively across teams and adjust your approach as priorities shift. Receptive to feedback and committed to developing your information security skills across multiple domains. Preferred Pursuing or holding a relevant certification: CompTIA Security+, CISA (in progress), ISO 27001 Foundation, or equivalent. Familiarity with cloud environments (AWS, Azure, GCP) from a security or compliance perspective. Exposure to security or GRC tooling such as Wiz, Qualys, Microsoft Sentinel, ServiceNow GRC, or similar. Awareness of AI governance frameworks or the OWASP LLM Top 10. Some scripting or automation experience (Python, etc.) is a plus.
10/07/2026
Full time
Company Description We're You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we're behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there's a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you've come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we're shaping the future of fintech - and we're just getting started. The Role As an Information Security Analyst at you will work across the full breadth of the information security function, spanning Governance, Risk and Compliance (GRC), AI Governance, Application Security (AppSec), Technology Risk, and Data Governance. This is a role for someone who has built a solid foundation in information security and is ready to move from guided execution to genuine ownership of tasks and smaller workstreams. Security at Checkout operates at scale and at pace. We are a global payments business, regulated across multiple jurisdictions, building infrastructure that processes billions of transactions. Our security function needs analysts who understand how different domains fit together, communicate clearly with technical and non-technical colleagues, and take accountability for the quality of their work. At L2 you will implement security controls, respond to security incidents, identify risks, and support compliance activities across multiple domains. You work independently for extended periods and are developing the cross-domain knowledge and stakeholder skills that will prepare you for programme ownership at L3 and beyond. How You'll Make Impact Governance, Risk and Compliance Support workstreams within Checkout's GRC programme, including ISO 27001, SOC 2, PCI DSS, and applicable regulatory obligations across our global licensed entities. Assist with control evidence collection activities, coordinating with internal teams to gather accurate and timely evidence in support of audit readiness. Maintain GRC documentation including policies, standards, procedures, and control matrices under the guidance of senior colleagues. Support monitoring of the risk register, tracking remediation activity against agreed timelines and escalating where commitments are at risk. Assist in conducting third party risk assessments, evaluating supplier security controls in line with Checkout's TPRM framework. Develop working knowledge of regulatory obligations across Checkout's operating markets, including FCA/PRA requirements, payment scheme rules, and DORA. AI Governance Support the operationalisation of Checkout's AI governance framework, aligned to ISO 42001, the EU AI Act, and NIST AI RMF. Assist in conducting AI risk assessments for internal AI and ML systems and third party AI tools, under the guidance of more senior analysts. Help maintain an inventory of AI use cases and associated risk classifications, working with product and engineering teams as directed. Develop awareness of the evolving regulatory landscape for AI in financial services and contribute to policy and control documentation. Contribute to the development and communication of responsible AI usage guidance for staff, helping teams across the business understand acceptable use boundaries, data handling expectations, and the risks associated with AI tools in a regulated environment. Application Security Contribute to Checkout's application security programme, including support for secure code review processes, SDLC integration, and developer security guidance. Support threat modelling activities for new and existing products, identifying security requirements under the guidance of senior colleagues. Assist in managing vulnerability findings from penetration tests, bug bounty programmes, and automated tooling, tracking remediation and validating fixes. Apply knowledge of the OWASP Top 10 and secure development frameworks to practical security reviews and guidance activities. Technology Risk Support technology risk assessments across infrastructure, cloud environments, and third party systems, contributing to outputs with actionable treatment recommendations. Assist with control assurance activities including vulnerability scanning coordination, access control assessments, and firewall and configuration reviews. Develop an understanding of Checkout's technology risk landscape, identifying emerging threats and contributing inputs to the risk register. Support DORA related ICT risk management activities under the direction of senior analysts. Data Governance Support Checkout's data governance programme, including data classification activities, data flow mapping, and enforcement of data handling standards. Assist with data loss prevention (DLP) controls and tooling, contributing to activities that ensure sensitive data is protected throughout its lifecycle. Help maintain records of processing activities (RoPA) and support data protection impact assessments (DPIAs) for new systems. Develop working knowledge of GDPR, UK GDPR, and applicable regional data protection requirements as they affect Checkout's operations. Cross domain Collaboration Work with Engineering, Product, Legal, Procurement, Finance, and Compliance teams to support the embedding of security requirements into processes, systems, and projects. Respond to security due diligence requests from merchants, partners, and regulators with accuracy and within agreed SLAs, escalating complex queries appropriately. Communicate clearly with internal stakeholders on security requirements, keeping teams updated on changes and project progress. Contribute to security awareness initiatives, promoting a security conscious culture across Checkout. What We're Looking for Experience 1 to 2 years of experience in information security, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Working knowledge of at least one of the following domains: GRC, AppSec, technology risk, or data governance. Practical familiarity with at least one compliance framework: PCI DSS, ISO 27001, SOC 2, NIST CSF, or equivalent. Some exposure to external audits, risk assessments, or security assurance activities. Ability to manage tasks independently and deliver on commitments reliably. Skills and Approach Clear written and verbal communication. You can translate security concepts for technical and non technical audiences. Detail oriented and methodical. You approach your work carefully and follow through consistently. Curious and proactive. You ask questions, flag issues early, and look for root causes rather than surface fixes. Collaborative and adaptable. You work effectively across teams and adjust your approach as priorities shift. Receptive to feedback and committed to developing your information security skills across multiple domains. Preferred Pursuing or holding a relevant certification: CompTIA Security+, CISA (in progress), ISO 27001 Foundation, or equivalent. Familiarity with cloud environments (AWS, Azure, GCP) from a security or compliance perspective. Exposure to security or GRC tooling such as Wiz, Qualys, Microsoft Sentinel, ServiceNow GRC, or similar. Awareness of AI governance frameworks or the OWASP LLM Top 10. Some scripting or automation experience (Python, etc.) is a plus.
Senior Information Security Analyst Information security London
Checkout Ltd
Company Description We're You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we're behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there's a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you've come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we're shaping the future of fintech - and we're just getting started. The Role As a Senior Information Security Analyst within the GRC team, you will lead the strategic and technical execution of Checkout's governance, risk and compliance programme. This is a role for a seasoned GRC professional who brings deep expertise across regulatory compliance, enterprise risk management, and security governance - and who can operate with full autonomy while shaping how the function evolves. You will take ownership of Checkout's most complex and high stakes compliance programmes - PCI DSS v4.0.1, ISO 27001, SOC 2, DORA, and emerging obligations across our global licensed entities - while providing expert guidance to engineering, product, legal, and compliance teams on the security requirements that underpin our ability to operate and grow in regulated markets worldwide. At L4, you are a trusted advisor. You do not just manage compliance - you set the direction for it. You define how risk is identified, assessed, and treated. You advise on product and infrastructure decisions from a risk perspective. You mentor and develop junior and mid level analysts. And you work closely with security leadership to ensure the GRC programme is aligned to the business's strategic objectives and risk appetite. Your influence extends well beyond the GRC team. You help shape the security culture at Checkout, driving a risk aware mindset across the business through clear communication, pragmatic guidance, and expert leadership. How You'll Make An Impact GRC Programme Leadership Lead defined sub areas of Checkout's GRC programme end to end, including PCI DSS v4.0.1, ISO 27001, SOC 2, and regulatory obligations across Europe, MENA, APAC, and the Americas. Define how control evidence is collected and maintained, moving the function toward continuous audit readiness and away from point in time preparation. Own and drive improvements to GRC documentation including policies, standards, procedures, and control matrices - ensuring they reflect Checkout's evolving risk profile and regulatory obligations. Lead gap analyses against new and evolving requirements, including DORA ICT risk obligations and the EU AI Act, producing prioritised remediation roadmaps with clear business impact framing. Own the risk register for your sub area, managing risk treatment through to closure and escalating to leadership where risk appetite may be exceeded. Define and refine Checkout's third party risk management approach for high risk and critical vendors, setting assessment standards and overseeing their consistent application. Drive continual improvement of the GRC programme itself - regularly assessing programme maturity, identifying process inefficiencies, and implementing improvements to how risk is identified, assessed, treated, and reported across the business. Audit and Assessment Leadership Serve as the primary point of contact for external auditors, QSAs, and regulatory assessors across PCI DSS, ISO 27001, SOC 2, and ITGC audit cycles. Demonstrated experience implementing ISO management system standards end to end, covering initial scoping and gap assessment through control design, policy development, internal audit programme, and certification - ideally across more than one standard. Lead end to end audit delivery - scoping, evidence preparation, walkthrough facilitation, finding management, and formal closure. Own the end to end response process for complex merchant assurance and regulatory due diligence requests, ensuring Checkout's compliance posture is presented accurately and persuasively. Lead quarterly and annual compliance activities including vulnerability scanning coordination, penetration testing programmes, access reviews, and firewall configuration assurance. Policy, Controls and Regulatory Strategy Apply expert knowledge of PCI DSS v4.0.1, ISO 27001/27002, SOC 2, DORA, NIST CSF, and related frameworks to drive control design, policy development, and compliance strategy. Advise product and engineering teams on compliance requirements at the point of design, embedding regulatory obligations into architecture decisions and development workflows. Lead Checkout's regulatory change management activities - monitoring the evolving landscape across financial services, data protection, and AI regulation, assessing business impact, and driving remediation programmes. Identify and drive systemic improvements to GRC processes, including automation opportunities that improve programme efficiency and evidence quality. Contribute to the design and development of GRC tooling, dashboards, and risk reporting to improve leadership visibility of Checkout's compliance and risk posture. Stakeholder Influence and Team Development Act as a senior trusted advisor to Engineering, Product, Legal, Finance, Procurement, and Compliance on all GRC matters, communicating risk in business terms that drive informed decisions. Represent the GRC function in cross functional forums, governance committees, and regulatory discussions, influencing decisions that affect Checkout's risk posture. Mentor and develop junior and mid level GRC analysts (L1-L3), raising the capability of the team through structured knowledge sharing, review, and coaching. Promote a security first culture across Checkout through proactive engagement, executive level reporting, and accessible guidance that empowers non security teams to make good risk decisions. What We're Looking For Experience 5 or more years of experience in GRC, information security compliance, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Deep working knowledge of PCI DSS (v4.0.1 required), ISO 27001, and SOC 2. Practical experience with DORA, NIST CSF, the EU AI Act, or FCA/PRA obligations is strongly preferred. Demonstrated track record of leading external audits and regulatory assessments end to end, including managing assessor relationships and driving findings to closure. Proven ability to own and deliver complex GRC programme workstreams independently, including gap analyses, risk treatment programmes, and regulatory change initiatives. Experience advising engineering and product teams on compliance requirements, with the ability to translate regulatory obligations into practical, proportionate controls. Track record of developing and mentoring less experienced colleagues. Skills and Approach Expert written and verbal communication. You can frame complex regulatory and risk issues for a technical audience, a business stakeholder, and executive leadership - and adapt your style to drive the right outcome in each context. Strategic and analytical thinker. You see beyond individual findings and controls to understand systemic risk patterns, root causes, and the broader implications for the business. Decisive under ambiguity. You can set direction and make sound judgement calls on prioritisation and risk treatment without waiting for perfect information. Highly collaborative and influential. You understand that compliance must be embedded across the business, and you build the relationships and credibility needed to make that happen. Pragmatic and outcome focused. You design controls and processes that are proportionate to risk and workable in practice, not just theoretically sound. Preferred CISA, CISM, CISSP, PCIP, ISO 27001 Lead Implementer or Lead Auditor, or equivalent advanced certification. Familiarity with cloud environments (AWS, Azure, GCP) at an architecture or control level. Experience with AI governance frameworks such as ISO 42001, the EU AI Act, or NIST AI RMF. Experience designing or implementing GRC tooling, risk platforms, or compliance automation solutions. Background in a Big Four advisory, payments scheme, or regulatory environment is advantageous. Additional Information Bring all of you to work. We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one. Here, you'll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It's a place where ambition gets met with opportunity, and where your growth is in your hands. We work as one team, and we back each other to succeed. So whatever your background or identity, if you're ready to grow and make a difference, you'll be right at home here. It's important we set you up for success and make our process as accessible as possible. So let us know in your application . click apply for full job details
10/07/2026
Full time
Company Description We're You might not know our name, but companies like eBay, Spotify, Klarna, Uber, and Sony do, because we're behind many of the digital experiences you use every day. We are where the world checks out, enabling over 10 billion transactions yearly for more than one billion global shoppers. Whether you want to book a holiday, order food, renew a subscription, or check out online, there's a good chance our tech powers the payments behind the scenes. Our platform helps the most ambitious businesses deliver effortless digital experiences, at scale. If you want to do career-defining work, you've come to the right place. We move fast, think globally, and believe great teams are built by hiring exceptional people with conviction, curiosity, and the desire to make an impact. With 20 offices across six continents and London as our HQ, we're shaping the future of fintech - and we're just getting started. The Role As a Senior Information Security Analyst within the GRC team, you will lead the strategic and technical execution of Checkout's governance, risk and compliance programme. This is a role for a seasoned GRC professional who brings deep expertise across regulatory compliance, enterprise risk management, and security governance - and who can operate with full autonomy while shaping how the function evolves. You will take ownership of Checkout's most complex and high stakes compliance programmes - PCI DSS v4.0.1, ISO 27001, SOC 2, DORA, and emerging obligations across our global licensed entities - while providing expert guidance to engineering, product, legal, and compliance teams on the security requirements that underpin our ability to operate and grow in regulated markets worldwide. At L4, you are a trusted advisor. You do not just manage compliance - you set the direction for it. You define how risk is identified, assessed, and treated. You advise on product and infrastructure decisions from a risk perspective. You mentor and develop junior and mid level analysts. And you work closely with security leadership to ensure the GRC programme is aligned to the business's strategic objectives and risk appetite. Your influence extends well beyond the GRC team. You help shape the security culture at Checkout, driving a risk aware mindset across the business through clear communication, pragmatic guidance, and expert leadership. How You'll Make An Impact GRC Programme Leadership Lead defined sub areas of Checkout's GRC programme end to end, including PCI DSS v4.0.1, ISO 27001, SOC 2, and regulatory obligations across Europe, MENA, APAC, and the Americas. Define how control evidence is collected and maintained, moving the function toward continuous audit readiness and away from point in time preparation. Own and drive improvements to GRC documentation including policies, standards, procedures, and control matrices - ensuring they reflect Checkout's evolving risk profile and regulatory obligations. Lead gap analyses against new and evolving requirements, including DORA ICT risk obligations and the EU AI Act, producing prioritised remediation roadmaps with clear business impact framing. Own the risk register for your sub area, managing risk treatment through to closure and escalating to leadership where risk appetite may be exceeded. Define and refine Checkout's third party risk management approach for high risk and critical vendors, setting assessment standards and overseeing their consistent application. Drive continual improvement of the GRC programme itself - regularly assessing programme maturity, identifying process inefficiencies, and implementing improvements to how risk is identified, assessed, treated, and reported across the business. Audit and Assessment Leadership Serve as the primary point of contact for external auditors, QSAs, and regulatory assessors across PCI DSS, ISO 27001, SOC 2, and ITGC audit cycles. Demonstrated experience implementing ISO management system standards end to end, covering initial scoping and gap assessment through control design, policy development, internal audit programme, and certification - ideally across more than one standard. Lead end to end audit delivery - scoping, evidence preparation, walkthrough facilitation, finding management, and formal closure. Own the end to end response process for complex merchant assurance and regulatory due diligence requests, ensuring Checkout's compliance posture is presented accurately and persuasively. Lead quarterly and annual compliance activities including vulnerability scanning coordination, penetration testing programmes, access reviews, and firewall configuration assurance. Policy, Controls and Regulatory Strategy Apply expert knowledge of PCI DSS v4.0.1, ISO 27001/27002, SOC 2, DORA, NIST CSF, and related frameworks to drive control design, policy development, and compliance strategy. Advise product and engineering teams on compliance requirements at the point of design, embedding regulatory obligations into architecture decisions and development workflows. Lead Checkout's regulatory change management activities - monitoring the evolving landscape across financial services, data protection, and AI regulation, assessing business impact, and driving remediation programmes. Identify and drive systemic improvements to GRC processes, including automation opportunities that improve programme efficiency and evidence quality. Contribute to the design and development of GRC tooling, dashboards, and risk reporting to improve leadership visibility of Checkout's compliance and risk posture. Stakeholder Influence and Team Development Act as a senior trusted advisor to Engineering, Product, Legal, Finance, Procurement, and Compliance on all GRC matters, communicating risk in business terms that drive informed decisions. Represent the GRC function in cross functional forums, governance committees, and regulatory discussions, influencing decisions that affect Checkout's risk posture. Mentor and develop junior and mid level GRC analysts (L1-L3), raising the capability of the team through structured knowledge sharing, review, and coaching. Promote a security first culture across Checkout through proactive engagement, executive level reporting, and accessible guidance that empowers non security teams to make good risk decisions. What We're Looking For Experience 5 or more years of experience in GRC, information security compliance, IT audit, or a closely related function, ideally within payments, financial services, or fintech. Deep working knowledge of PCI DSS (v4.0.1 required), ISO 27001, and SOC 2. Practical experience with DORA, NIST CSF, the EU AI Act, or FCA/PRA obligations is strongly preferred. Demonstrated track record of leading external audits and regulatory assessments end to end, including managing assessor relationships and driving findings to closure. Proven ability to own and deliver complex GRC programme workstreams independently, including gap analyses, risk treatment programmes, and regulatory change initiatives. Experience advising engineering and product teams on compliance requirements, with the ability to translate regulatory obligations into practical, proportionate controls. Track record of developing and mentoring less experienced colleagues. Skills and Approach Expert written and verbal communication. You can frame complex regulatory and risk issues for a technical audience, a business stakeholder, and executive leadership - and adapt your style to drive the right outcome in each context. Strategic and analytical thinker. You see beyond individual findings and controls to understand systemic risk patterns, root causes, and the broader implications for the business. Decisive under ambiguity. You can set direction and make sound judgement calls on prioritisation and risk treatment without waiting for perfect information. Highly collaborative and influential. You understand that compliance must be embedded across the business, and you build the relationships and credibility needed to make that happen. Pragmatic and outcome focused. You design controls and processes that are proportionate to risk and workable in practice, not just theoretically sound. Preferred CISA, CISM, CISSP, PCIP, ISO 27001 Lead Implementer or Lead Auditor, or equivalent advanced certification. Familiarity with cloud environments (AWS, Azure, GCP) at an architecture or control level. Experience with AI governance frameworks such as ISO 42001, the EU AI Act, or NIST AI RMF. Experience designing or implementing GRC tooling, risk platforms, or compliance automation solutions. Background in a Big Four advisory, payments scheme, or regulatory environment is advantageous. Additional Information Bring all of you to work. We create the conditions for high performers to thrive, through real ownership, fewer blockers, and work that makes a difference from day one. Here, you'll move fast, take on meaningful challenges, and be recognized for the impact you deliver. It's a place where ambition gets met with opportunity, and where your growth is in your hands. We work as one team, and we back each other to succeed. So whatever your background or identity, if you're ready to grow and make a difference, you'll be right at home here. It's important we set you up for success and make our process as accessible as possible. So let us know in your application . click apply for full job details
Governance Risk and Compliance (GRC) Analyst
Assured Data Protection Inc. Leeds, Yorkshire
Governance Risk and Compliance (GRC) Analyst Leeds, West Yorkshire, United Kingdom - Full Time Location : Hybrid - Remote / Leeds UK Position Title : Governance, Risk and Compliance (GRC) Analyst Job Type : Full-Time Assured Data Protection is a global leader in data backup and disaster recovery managed services, specialising in safeguarding against data loss and downtime in the event of a disaster, cyber, or ransomware attack. Our fully managed services include immutable backup, disaster recovery, and cyber resiliency to protect data on-premises and in the cloud, with 24/7/365 expert support. We offer a flexible, consumption-based model to grow with your business, making data protection cost-effective and scalable. Our purpose built software provides industry leading monitoring and reporting capabilities to provide actionable insights into your data protection strategy. Our global datacentres ensure data sovereignty, meeting your organisation's compliance requirements. A dedicated team is always available to recover your data and minimise disruption in the event of a disaster. As the Governance, Risk and Compliance Analyst, you will work under the direction of the Global Head of Compliance to ensure international compliance needs are met. The GRC analyst is a key member of the Governance, Risk and Compliance team, responsible for supporting the development, implementation and maintenance of the company's GRC framework. The role involves a blend of operational and analytical tasks, working closely with various departments to ensure adherence to internal policies and external regulations. The role is critical for developing, implementing and maintaining the business' GRC Framework, contributing to a culture of compliance, integrity and ethical conduct. Key Responsibilities: Governance Assist in maintaining our Information Security Management System (ISMS), Quality Management System (QMS) and SOC2 in our Compliance monitoring tooling. Support with policy development and creation. Compliance & Regulatory Adherence Complete customer, partner and vendor due diligence activities. Assist with internal and external audits. Identify and remedy gaps in policy and process to support compliance needs. Assist in the development of Compliance training programs to support a culture of compliance within the organisation. Risk Management Assist with our Risk Management process which includes maintenance of our Risk Register. Ensure identified risks are documented and logged on our InfoSec Risk Register. Key Experience and Qualifications: Preferred Qualifications Industry recognised certifications such as CRISC, ISO 27001 Lead Implementer would be highly beneficial. Experience Prior work experience or equivalent in the Technology sector. Prior work experience in international compliance frameworks and standards; such as UK & EU GDPR, HIPAA, PCI-DSS, NIST, SOC2, ISO 27001, ISO 9001. Project Management experience. Prior experience with compliance tooling. Experience working with Information Security and Legal Teams. Skills & Competencies Understanding of core Risk Management principles. Ability to embrace flexibility and adapt seamlessly to change. Ability to use initiative to solve complex problems. Ability to communicate with stakeholders at every seniority level of the business. What We Offer: Hybrid working options for flexibility Regular team building and off site company events. A dynamic, inclusive, and collaborative work environment At Assured Data Protection we value diversity and inclusivity. We offer perks such as flex holidays and flexible working practices to allow our employees to show up as their whole selves. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know. You must have the legal right to work in the UK at the time of application, as we are unable to offer visa sponsorship for this role.
09/07/2026
Full time
Governance Risk and Compliance (GRC) Analyst Leeds, West Yorkshire, United Kingdom - Full Time Location : Hybrid - Remote / Leeds UK Position Title : Governance, Risk and Compliance (GRC) Analyst Job Type : Full-Time Assured Data Protection is a global leader in data backup and disaster recovery managed services, specialising in safeguarding against data loss and downtime in the event of a disaster, cyber, or ransomware attack. Our fully managed services include immutable backup, disaster recovery, and cyber resiliency to protect data on-premises and in the cloud, with 24/7/365 expert support. We offer a flexible, consumption-based model to grow with your business, making data protection cost-effective and scalable. Our purpose built software provides industry leading monitoring and reporting capabilities to provide actionable insights into your data protection strategy. Our global datacentres ensure data sovereignty, meeting your organisation's compliance requirements. A dedicated team is always available to recover your data and minimise disruption in the event of a disaster. As the Governance, Risk and Compliance Analyst, you will work under the direction of the Global Head of Compliance to ensure international compliance needs are met. The GRC analyst is a key member of the Governance, Risk and Compliance team, responsible for supporting the development, implementation and maintenance of the company's GRC framework. The role involves a blend of operational and analytical tasks, working closely with various departments to ensure adherence to internal policies and external regulations. The role is critical for developing, implementing and maintaining the business' GRC Framework, contributing to a culture of compliance, integrity and ethical conduct. Key Responsibilities: Governance Assist in maintaining our Information Security Management System (ISMS), Quality Management System (QMS) and SOC2 in our Compliance monitoring tooling. Support with policy development and creation. Compliance & Regulatory Adherence Complete customer, partner and vendor due diligence activities. Assist with internal and external audits. Identify and remedy gaps in policy and process to support compliance needs. Assist in the development of Compliance training programs to support a culture of compliance within the organisation. Risk Management Assist with our Risk Management process which includes maintenance of our Risk Register. Ensure identified risks are documented and logged on our InfoSec Risk Register. Key Experience and Qualifications: Preferred Qualifications Industry recognised certifications such as CRISC, ISO 27001 Lead Implementer would be highly beneficial. Experience Prior work experience or equivalent in the Technology sector. Prior work experience in international compliance frameworks and standards; such as UK & EU GDPR, HIPAA, PCI-DSS, NIST, SOC2, ISO 27001, ISO 9001. Project Management experience. Prior experience with compliance tooling. Experience working with Information Security and Legal Teams. Skills & Competencies Understanding of core Risk Management principles. Ability to embrace flexibility and adapt seamlessly to change. Ability to use initiative to solve complex problems. Ability to communicate with stakeholders at every seniority level of the business. What We Offer: Hybrid working options for flexibility Regular team building and off site company events. A dynamic, inclusive, and collaborative work environment At Assured Data Protection we value diversity and inclusivity. We offer perks such as flex holidays and flexible working practices to allow our employees to show up as their whole selves. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you have a disability or special need that requires accommodation, please do not hesitate to let us know. You must have the legal right to work in the UK at the time of application, as we are unable to offer visa sponsorship for this role.
Zachary Daniels Recruitment
Senior GRC Cyber Security Analyst
Zachary Daniels Recruitment
Senior GRC Cyber Security Analyst London (Hybrid, 3 days in office) 70,000- 85,000 + Benefits A growing international organisation is looking to strengthen its cyber security capability with the appointment of a Senior Cyber Security Analyst (Governance, Risk & Compliance). This is a fantastic opportunity to join a developing security function where you'll play a key role in governance, risk management, regulatory compliance and information security assurance across the business. The Opportunity Working closely with the Director of Information Security, you'll help drive security governance, maintain compliance frameworks and provide clear security risk insight to stakeholders across the organisation. This is a varied role offering exposure to security strategy, audits, supplier assurance and executive reporting within a complex technology environment. Key Responsibilities Governance & Compliance Maintain Information Security policies, standards and procedures Support compliance with ISO 27001, GDPR, NIS2 and related frameworks Coordinate audit evidence and compliance activities Maintain governance documentation and control frameworks Risk Management Maintain the Information Security Risk Register Facilitate risk assessments with business stakeholders Track remediation plans and improvement actions Produce meaningful security reporting and dashboards Third Party Assurance Conduct supplier security assessments Manage customer security questionnaires Support third-party due diligence activities Reporting & Security Awareness Produce KPI and KRI reporting Support executive and board reporting Coordinate security awareness initiatives Contribute to Business Continuity and Disaster Recovery activities About You You'll have previous experience within a Cyber Security Governance, Risk & Compliance function together with knowledge of: ISO 27001 GDPR NIS2 Risk Management Security Policies & Standards Audit & Compliance Supplier Assurance Microsoft 365 Relevant cyber security certifications would be advantageous but are not essential. Package 70,000- 85,000 DOE Hybrid Working 3 days in the London Office Opportunity to shape and mature cyber governance Exposure to enterprise security programmes Excellent long-term career progression Apply today with your most up-to-date CV! BH36687
07/07/2026
Full time
Senior GRC Cyber Security Analyst London (Hybrid, 3 days in office) 70,000- 85,000 + Benefits A growing international organisation is looking to strengthen its cyber security capability with the appointment of a Senior Cyber Security Analyst (Governance, Risk & Compliance). This is a fantastic opportunity to join a developing security function where you'll play a key role in governance, risk management, regulatory compliance and information security assurance across the business. The Opportunity Working closely with the Director of Information Security, you'll help drive security governance, maintain compliance frameworks and provide clear security risk insight to stakeholders across the organisation. This is a varied role offering exposure to security strategy, audits, supplier assurance and executive reporting within a complex technology environment. Key Responsibilities Governance & Compliance Maintain Information Security policies, standards and procedures Support compliance with ISO 27001, GDPR, NIS2 and related frameworks Coordinate audit evidence and compliance activities Maintain governance documentation and control frameworks Risk Management Maintain the Information Security Risk Register Facilitate risk assessments with business stakeholders Track remediation plans and improvement actions Produce meaningful security reporting and dashboards Third Party Assurance Conduct supplier security assessments Manage customer security questionnaires Support third-party due diligence activities Reporting & Security Awareness Produce KPI and KRI reporting Support executive and board reporting Coordinate security awareness initiatives Contribute to Business Continuity and Disaster Recovery activities About You You'll have previous experience within a Cyber Security Governance, Risk & Compliance function together with knowledge of: ISO 27001 GDPR NIS2 Risk Management Security Policies & Standards Audit & Compliance Supplier Assurance Microsoft 365 Relevant cyber security certifications would be advantageous but are not essential. Package 70,000- 85,000 DOE Hybrid Working 3 days in the London Office Opportunity to shape and mature cyber governance Exposure to enterprise security programmes Excellent long-term career progression Apply today with your most up-to-date CV! BH36687
Cybersecurity Analyst
Academy Education Network Ltd Manchester, Lancashire
Overview Cybersecurity Analysts protect organisations from cyber threats. Depending on the speciality, roles may involve monitoring live security events in a Security Operations Centre (SOC), researching threat intelligence, conducting penetration tests to uncover vulnerabilities, or managing Governance, Risk & Compliance (GRC) workstreams. All work aligns with recognised frameworks such as NIST CSF, ISO 27001, and CIS Controls. Responsibilities Monitor security events and respond to active threats in real time. Run vulnerability assessments, penetration tests, and incident response exercises. Specialise in SOC analysis, threat intelligence, penetration testing, GRC, or cloud security. Work for banks, telcos, defence contractors, government agencies, NHS and FTSE 100 corporates. Career Progression Typical career stages for a Cybersecurity Analyst: Years 0-2: SOC Analyst (Tier 1) - monitor events and respond to common incidents; progression via CompTIA Security+ and SANS GCIH or CEH. Years 2-5: Cybersecurity Analyst / Penetration Tester - specialise in penetration testing (CREST CRT, OSCP), threat intelligence or GRC (ISO 27001 Lead Auditor). Years 5-8: Senior Analyst / Security Engineer - lead complex incident response, run major risk assessments, or design enterprise security architecture; often required to hold CISSP. Years 8+: Lead / Head of Security / CISO - strategic leadership of an organisation's security function; requires technical depth and business/board level communication. Qualifications & Skills Required technical knowledge and professional traits include: Calm decision making under incident pressure. Clear written reporting for non technical executives. Ethical decision making and professional integrity. Continuous learning across rapidly evolving threats. Methodical, evidence based investigation. Teamwork across IT, business and law enforcement. Relevant certifications such as CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP, ISO 27001 Lead Auditor. Typical Salary Ranges (UK) Junior SOC analysts at major banks and managed service providers start at £35,000-£45,000. Penetration testers and threat intelligence analysts at top consultancies earn £45,000-£65,000 within 3 years. Senior engineers and CISO track leaders in FTSE 100 companies can reach £100,000+. Education and Entry Routes Common pathways include: MSc Cybersecurity - 1 year postgraduate specialist degree (many are NCSC certified). Cybersecurity Apprenticeship - 2-4 years, fully employer funded (Levels 4 & 6). CompTIA Security+ plus a Tier 1 SOC role - common entry for career changers. University undergraduate degree in Cybersecurity or Computer Science - 3 years; with student loans and progression into junior roles. FAQ - Becoming a Cybersecurity Analyst in the UK How long does it take to become a cyber analyst? Typically straight after a 3 year undergraduate degree, or via CompTIA Security+ and a Tier 1 SOC role. Do I need a cybersecurity degree to work in the UK? Not strictly, but a specialist degree and relevant certifications are the most reliable route. Is the role on the Skilled Worker visa shortage list? No; however, salaries often meet the threshold and most private sector employers sponsor international analysts. What's the difference between a SOC analyst and a penetration tester? SOC analysts monitor events; penetration testers actively find vulnerabilities. Which UK certifications matter most? CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP. Can I move into cybersecurity from another career? Yes - career changers can transition via Security+ and a Tier 1 SOC role within 6-12 months.
07/07/2026
Full time
Overview Cybersecurity Analysts protect organisations from cyber threats. Depending on the speciality, roles may involve monitoring live security events in a Security Operations Centre (SOC), researching threat intelligence, conducting penetration tests to uncover vulnerabilities, or managing Governance, Risk & Compliance (GRC) workstreams. All work aligns with recognised frameworks such as NIST CSF, ISO 27001, and CIS Controls. Responsibilities Monitor security events and respond to active threats in real time. Run vulnerability assessments, penetration tests, and incident response exercises. Specialise in SOC analysis, threat intelligence, penetration testing, GRC, or cloud security. Work for banks, telcos, defence contractors, government agencies, NHS and FTSE 100 corporates. Career Progression Typical career stages for a Cybersecurity Analyst: Years 0-2: SOC Analyst (Tier 1) - monitor events and respond to common incidents; progression via CompTIA Security+ and SANS GCIH or CEH. Years 2-5: Cybersecurity Analyst / Penetration Tester - specialise in penetration testing (CREST CRT, OSCP), threat intelligence or GRC (ISO 27001 Lead Auditor). Years 5-8: Senior Analyst / Security Engineer - lead complex incident response, run major risk assessments, or design enterprise security architecture; often required to hold CISSP. Years 8+: Lead / Head of Security / CISO - strategic leadership of an organisation's security function; requires technical depth and business/board level communication. Qualifications & Skills Required technical knowledge and professional traits include: Calm decision making under incident pressure. Clear written reporting for non technical executives. Ethical decision making and professional integrity. Continuous learning across rapidly evolving threats. Methodical, evidence based investigation. Teamwork across IT, business and law enforcement. Relevant certifications such as CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP, ISO 27001 Lead Auditor. Typical Salary Ranges (UK) Junior SOC analysts at major banks and managed service providers start at £35,000-£45,000. Penetration testers and threat intelligence analysts at top consultancies earn £45,000-£65,000 within 3 years. Senior engineers and CISO track leaders in FTSE 100 companies can reach £100,000+. Education and Entry Routes Common pathways include: MSc Cybersecurity - 1 year postgraduate specialist degree (many are NCSC certified). Cybersecurity Apprenticeship - 2-4 years, fully employer funded (Levels 4 & 6). CompTIA Security+ plus a Tier 1 SOC role - common entry for career changers. University undergraduate degree in Cybersecurity or Computer Science - 3 years; with student loans and progression into junior roles. FAQ - Becoming a Cybersecurity Analyst in the UK How long does it take to become a cyber analyst? Typically straight after a 3 year undergraduate degree, or via CompTIA Security+ and a Tier 1 SOC role. Do I need a cybersecurity degree to work in the UK? Not strictly, but a specialist degree and relevant certifications are the most reliable route. Is the role on the Skilled Worker visa shortage list? No; however, salaries often meet the threshold and most private sector employers sponsor international analysts. What's the difference between a SOC analyst and a penetration tester? SOC analysts monitor events; penetration testers actively find vulnerabilities. Which UK certifications matter most? CompTIA Security+, CEH, SANS GCIH, OSCP/CREST CRT, CISM/CISSP. Can I move into cybersecurity from another career? Yes - career changers can transition via Security+ and a Tier 1 SOC role within 6-12 months.
Application Security Assessment Specialist - Banking
Salt Digital Recruitment
Security Risk Assessment Specialist - Freelance Contractor - BrusselsRate: Flexible; Duration: 1 year; Hybrid: 8 days onsite per month in Brussels office, remainder remote. Division: CISO - IT Risk. About the role We are looking for an experienced and dynamic Senior Security Analyst to join our IT Risk Transformation team. In this role, you will contribute to the design and enhancement of our application security risk assessment process and perform security risk assessments across a wide range of applications. You will work closely with cross functional teams from across the organization and will be exposed to a diversified set of topics, business and technologies. Responsibilities Contribute to the design of an application security risk assessment framework. Design the approach for executing application security assessments. Participate in building the data model supporting the above activities. Create standard reporting templates. Organise documentation and track activity. Execute security assessments. Analyse the business context, technical architecture and supporting components of applications using sources such as CMDB, network topology, documentation and workshops. Identify relevant threats, risk scenarios and appropriate security controls based on the application's specific environment. Detect security gaps, articulate clear and actionable findings, and provide practical recommendations. Produce detailed reports outlining risks, observations and recommended security measures. Collaborate with internal stakeholders including IT, architects, project managers, business owners and risk teams to validate findings and support remediation plans. Experience 5-10 years of proven experience conducting security risk assessments. Hands on experience contributing to the design of security processes, frameworks or security solutions. Solid understanding of cybersecurity frameworks (ISO27001, CIS, NIST, DORA) and threat/risk frameworks (MITRE, EBIOS). Good knowledge of financial IT security regulatory requirements (DORA, ESMA, etc.). Practical understanding of how information security controls must be implemented. Experience in defining or applying security requirements on Microsoft Azure, IBM Mainframe or Microsoft Windows platforms is a plus. Fluency in English and prior experience in the financial sector. Knowledge of financial markets, FMIs and CSD operations is advantageous. Experience with tools such as ServiceNow, Excel and basic security testing platforms. Experience with ServiceNow GRC is advantageous. Certifications such as CISSP, CSSLP, CCSP, CISM, CISMP, GCIH, CEH are advantageous. Skills Strong communication and coordination skills, engaging effectively with stakeholders across diverse teams. Proactive, self motivated and comfortable in a dynamic, continuously evolving environment. Strong analytical capabilities and creative problem solving skills. Structured, synthetic, delivering clear, concise and relevant responses. Calm, organized, efficient under pressure, maintaining clarity even in uncertain situations. Collaborative mindset, working effectively with executives, business leaders and technical teams. Autonomous and well organized, with strong prioritisation and time management ability.
07/07/2026
Full time
Security Risk Assessment Specialist - Freelance Contractor - BrusselsRate: Flexible; Duration: 1 year; Hybrid: 8 days onsite per month in Brussels office, remainder remote. Division: CISO - IT Risk. About the role We are looking for an experienced and dynamic Senior Security Analyst to join our IT Risk Transformation team. In this role, you will contribute to the design and enhancement of our application security risk assessment process and perform security risk assessments across a wide range of applications. You will work closely with cross functional teams from across the organization and will be exposed to a diversified set of topics, business and technologies. Responsibilities Contribute to the design of an application security risk assessment framework. Design the approach for executing application security assessments. Participate in building the data model supporting the above activities. Create standard reporting templates. Organise documentation and track activity. Execute security assessments. Analyse the business context, technical architecture and supporting components of applications using sources such as CMDB, network topology, documentation and workshops. Identify relevant threats, risk scenarios and appropriate security controls based on the application's specific environment. Detect security gaps, articulate clear and actionable findings, and provide practical recommendations. Produce detailed reports outlining risks, observations and recommended security measures. Collaborate with internal stakeholders including IT, architects, project managers, business owners and risk teams to validate findings and support remediation plans. Experience 5-10 years of proven experience conducting security risk assessments. Hands on experience contributing to the design of security processes, frameworks or security solutions. Solid understanding of cybersecurity frameworks (ISO27001, CIS, NIST, DORA) and threat/risk frameworks (MITRE, EBIOS). Good knowledge of financial IT security regulatory requirements (DORA, ESMA, etc.). Practical understanding of how information security controls must be implemented. Experience in defining or applying security requirements on Microsoft Azure, IBM Mainframe or Microsoft Windows platforms is a plus. Fluency in English and prior experience in the financial sector. Knowledge of financial markets, FMIs and CSD operations is advantageous. Experience with tools such as ServiceNow, Excel and basic security testing platforms. Experience with ServiceNow GRC is advantageous. Certifications such as CISSP, CSSLP, CCSP, CISM, CISMP, GCIH, CEH are advantageous. Skills Strong communication and coordination skills, engaging effectively with stakeholders across diverse teams. Proactive, self motivated and comfortable in a dynamic, continuously evolving environment. Strong analytical capabilities and creative problem solving skills. Structured, synthetic, delivering clear, concise and relevant responses. Calm, organized, efficient under pressure, maintaining clarity even in uncertain situations. Collaborative mindset, working effectively with executives, business leaders and technical teams. Autonomous and well organized, with strong prioritisation and time management ability.
Senior Security Risk & GRC Analyst
Limelight Health
Limelight Health is seeking an experienced GRC Analyst to enhance governance, risk, and compliance functions. You will lead security assessments, support compliance activities, and provide strategic risk guidance within a hybrid working environment that requires occasional travel to our Winchester or London office. The ideal candidate possesses strong cyber security understanding, analytical skills, and a relevant degree. The role also necessitates UK Security Clearance, reflecting our commitment to national security.
05/07/2026
Full time
Limelight Health is seeking an experienced GRC Analyst to enhance governance, risk, and compliance functions. You will lead security assessments, support compliance activities, and provide strategic risk guidance within a hybrid working environment that requires occasional travel to our Winchester or London office. The ideal candidate possesses strong cyber security understanding, analytical skills, and a relevant degree. The role also necessitates UK Security Clearance, reflecting our commitment to national security.
Cybersecurity Trust & Assurance Analyst
Redis Enterprise
We're Redis. We built the product that runs the fast apps our world runs on. (If you checked the weather, used your credit card, or looked at your flight status online today, you're welcome.) At Redis, you'll work with the fastest, simplest technology in the business-whether you're building it, telling its story, or selling it to our 10,000+ worldwide customers. We're creating a faster world with simpler experiences. You in? Why would you love this job? Join a team that's focused on building a stronger, smarter control environment. We're looking for someone with technical acumen and experience in GRC to help identify control gaps, assess risk, strengthen controls, and influence positive change across the organization. If you're a strategic thinker, a collaborative partner, and passionate about helping teams navigate risk while enabling innovation, this could be the role for you! What you'll do: Customer Trust and Assurance Develop and implement strategies to enhance customer trust by ensuring the highest data protection and privacy standards. Communicate the organization's commitment to cybersecurity and data protection to customers, providing transparency around security practices and measures. Collaborate with customer-facing teams to address customer concerns related to cybersecurity and data protection, ensuring prompt and effective resolution. Monitor and respond to customer feedback regarding cybersecurity, using insights to drive improvements in security practices and customer communication. Conduct comprehensive risk assessments of third party vendors and service providers to identify potential security risks. Controls Assurance and Compliance Design, implement, and maintain robust cyber controls framework to ensure compliance with industry standards, regulatory requirements, and internal policies. Regularly review and test the effectiveness of controls to ensure they are operating as intended. Build on an existing continuous controls monitoring program to provide real time visibility into the effectiveness of cyber controls. Utilize automated tools and AI technologies to continuously monitor and assess the performance of security controls, promptly identifying and addressing any deficiencies. Stakeholder Communication and Reporting Collaborate with teams across the organization to identify security and privacy risk mitigation needs. Partner with Legal, IT, and Engineering teams to implement technical controls. Provide regular updates and reports to senior management, the board of directors, and other key stakeholders on the status of cyber risks, control effectiveness, and incident response activities. Communicate complex technical information in a clear and concise manner to non technical audiences. What will you need to have? 2-4 years of dedicated experience in cyber risk management, control assurance, and other governance related domains. Relevant certifications such as CISSP, CISM, CRISC, or similar are not required, but nice to have. Strong understanding of regulatory requirements and industry standards (e.g., NIST, ISO 27001, PCI, GDPR). Fluent in both engineering and governance, with the ability to translate risk and control requirements into practical, scalable technical solutions. Excellent leadership and communication skills, and comfortable communicating in high risk situations. Prior experience working in high tech companies, specifically in cloud native environments is preferable. As a global company, we value a culture of curiosity, diversity of thought, and innovation from our employees, customers, and partners. Redis is committed to a diverse and inclusive work environment where all employees' differences are celebrated and supported, and everyone feels safe to bring their authentic selves to work. Redis is dedicated to equal employment opportunities regardless of race, color, ancestry, religion, sex, national orientation, sexual orientation, age, marital status, disability, gender identity, gender expression, Veteran status, or any other classification protected by federal, state, or local law. We strive to create a workplace where every voice is heard, and every idea is respected. Redis is committed to working with and providing access and reasonable accommodation to applicants with mental and/or physical disabilities. If you think you may require accommodations for any part of the recruitment process, please send a request to . All requests for accommodations are treated discreetly and confidentially, as practical and permitted by law. Any offer of employment at Redis is contingent upon the successful completion of a background check, consistent with applicable laws. Redis reserves the right to retain data longer than stated in the privacy policy in order to evaluate candidates.
04/07/2026
Full time
We're Redis. We built the product that runs the fast apps our world runs on. (If you checked the weather, used your credit card, or looked at your flight status online today, you're welcome.) At Redis, you'll work with the fastest, simplest technology in the business-whether you're building it, telling its story, or selling it to our 10,000+ worldwide customers. We're creating a faster world with simpler experiences. You in? Why would you love this job? Join a team that's focused on building a stronger, smarter control environment. We're looking for someone with technical acumen and experience in GRC to help identify control gaps, assess risk, strengthen controls, and influence positive change across the organization. If you're a strategic thinker, a collaborative partner, and passionate about helping teams navigate risk while enabling innovation, this could be the role for you! What you'll do: Customer Trust and Assurance Develop and implement strategies to enhance customer trust by ensuring the highest data protection and privacy standards. Communicate the organization's commitment to cybersecurity and data protection to customers, providing transparency around security practices and measures. Collaborate with customer-facing teams to address customer concerns related to cybersecurity and data protection, ensuring prompt and effective resolution. Monitor and respond to customer feedback regarding cybersecurity, using insights to drive improvements in security practices and customer communication. Conduct comprehensive risk assessments of third party vendors and service providers to identify potential security risks. Controls Assurance and Compliance Design, implement, and maintain robust cyber controls framework to ensure compliance with industry standards, regulatory requirements, and internal policies. Regularly review and test the effectiveness of controls to ensure they are operating as intended. Build on an existing continuous controls monitoring program to provide real time visibility into the effectiveness of cyber controls. Utilize automated tools and AI technologies to continuously monitor and assess the performance of security controls, promptly identifying and addressing any deficiencies. Stakeholder Communication and Reporting Collaborate with teams across the organization to identify security and privacy risk mitigation needs. Partner with Legal, IT, and Engineering teams to implement technical controls. Provide regular updates and reports to senior management, the board of directors, and other key stakeholders on the status of cyber risks, control effectiveness, and incident response activities. Communicate complex technical information in a clear and concise manner to non technical audiences. What will you need to have? 2-4 years of dedicated experience in cyber risk management, control assurance, and other governance related domains. Relevant certifications such as CISSP, CISM, CRISC, or similar are not required, but nice to have. Strong understanding of regulatory requirements and industry standards (e.g., NIST, ISO 27001, PCI, GDPR). Fluent in both engineering and governance, with the ability to translate risk and control requirements into practical, scalable technical solutions. Excellent leadership and communication skills, and comfortable communicating in high risk situations. Prior experience working in high tech companies, specifically in cloud native environments is preferable. As a global company, we value a culture of curiosity, diversity of thought, and innovation from our employees, customers, and partners. Redis is committed to a diverse and inclusive work environment where all employees' differences are celebrated and supported, and everyone feels safe to bring their authentic selves to work. Redis is dedicated to equal employment opportunities regardless of race, color, ancestry, religion, sex, national orientation, sexual orientation, age, marital status, disability, gender identity, gender expression, Veteran status, or any other classification protected by federal, state, or local law. We strive to create a workplace where every voice is heard, and every idea is respected. Redis is committed to working with and providing access and reasonable accommodation to applicants with mental and/or physical disabilities. If you think you may require accommodations for any part of the recruitment process, please send a request to . All requests for accommodations are treated discreetly and confidentially, as practical and permitted by law. Any offer of employment at Redis is contingent upon the successful completion of a background check, consistent with applicable laws. Redis reserves the right to retain data longer than stated in the privacy policy in order to evaluate candidates.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board