it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

13 jobs found

Email me jobs like this
Refine Search
Current Search
cyber security grc consultant
Cyber Security Consultant - GRC (Defence)
Cyberfort Group
Join Cyberfort - Cyber Security Consultant - GRC (MOD) Location: Hybrid / East England - 3 days on-site presence required Contract Type: Full-time / Permanent Salary: Competitive + Benefits About Cyberfort At Cyberfort, we're securing the digital future. As a leading UK provider of cybersecurity solutions, we deliver cutting-edge services in Managed Detection & Response (MDR), Penetration Testing, Security Operations, and Strategic Consulting. We're large enough to offer exciting opportunities, yet agile enough to ensure every voice is heard. At Cyberfort, you're not just joining a company, you're becoming part of a mission-driven team. Why Join Us? Purpose-Driven Work - Help protect businesses and communities from evolving cyber threats. Growth & Development - Access mentoring, apprenticeships, graduate schemes, and continuous learning platforms. Inclusive Culture - We champion diversity through our Women's Network, Neurodiversity Awareness, and Inclusion Committee. Flexible Working - Hybrid and remote options to support work-life balance. Top-Tier Benefits - Competitive salary, private healthcare, wellbeing support, generous holiday allowance, and more. About the Role: Cyber Security Consultant - GRC (MOD) As a Cyber Security Consultant, you will play a pivotal role in delivering Secure by Design risk and security assurance services within MOD and Public Sector environments. You'll collaborate with multi-disciplinary teams to define and implement security risk assessments and best practice solutions, ensuring alignment with business risk appetites and transformation goals. You'll be part of a knowledge-sharing culture, working alongside expert peers in Secure Architecture and Risk Planning. This role supports the next phase of Cyberfort's growth and contributes to our mission of enabling clients to make proportionate, risk-informed decisions. Key Responsibilities Deliver Secure by Design risk and security assurance functions within MOD/Public Sector. Lead and advise on risk management frameworks, ISMS, and Enterprise Security Risk Management. Facilitate security and risk workshops with Authority departments. Produce clear reporting on vulnerabilities, risks, controls, and treatment activities. Provide pragmatic remediation and risk management guidance. Support secure design across technology platforms including cloud infrastructures. Contribute to blogs and research within the Cyberfort community. What We're Looking For Proven experience working in Governance, Risk and Compliance within Public Sector/MOD. Strong analytical, communication, and teamwork abilities. Passion for cybersecurity and continuous learning. Security Assurance Coordinator or Delivery Team Security Lead roles MOD/GDS Secure by Design Principles JSP440, JSP604/453, JSP490 Supplier Chain Assurance Security legislation (GDPR, PCI DSS, ICO) ISO 27001, NIST CSF, CIS Controls v8 Threat modelling, kill chain, attack tree analysis Cloud security (AWS, Azure), containerisation, firewalls Secure SDLC implementation HLD/LLD reviews ITHC scoping and remediation AI security (ISO42001 desirable) Certifications: AWS/Azure Security Professional, CCSP, CISSP, CISM, CIISEC, UK Cyber Security Council registration (Chartered or Principal). Clearance: Due to the nature of the projects, you'll be working on, you must hold an active and transferable DV (Developed vetting) clearance Must be a British citizen / resident in UK Inclusive Hiring We understand that one size doesn't fit all. If you need adjustments during the recruitment process, we're here to support you. Cyberfort is proud to be a Disability Confident Employer, a CyberFirst partner, and a signatory of the Armed Forces Covenant. Ready to Apply? If you're passionate about cybersecurity and want to make a real impact, we'd love to hear from you. Learn More Cyberfort Careers Page: Working at Cyberfort: LinkedIn:
26/07/2026
Full time
Join Cyberfort - Cyber Security Consultant - GRC (MOD) Location: Hybrid / East England - 3 days on-site presence required Contract Type: Full-time / Permanent Salary: Competitive + Benefits About Cyberfort At Cyberfort, we're securing the digital future. As a leading UK provider of cybersecurity solutions, we deliver cutting-edge services in Managed Detection & Response (MDR), Penetration Testing, Security Operations, and Strategic Consulting. We're large enough to offer exciting opportunities, yet agile enough to ensure every voice is heard. At Cyberfort, you're not just joining a company, you're becoming part of a mission-driven team. Why Join Us? Purpose-Driven Work - Help protect businesses and communities from evolving cyber threats. Growth & Development - Access mentoring, apprenticeships, graduate schemes, and continuous learning platforms. Inclusive Culture - We champion diversity through our Women's Network, Neurodiversity Awareness, and Inclusion Committee. Flexible Working - Hybrid and remote options to support work-life balance. Top-Tier Benefits - Competitive salary, private healthcare, wellbeing support, generous holiday allowance, and more. About the Role: Cyber Security Consultant - GRC (MOD) As a Cyber Security Consultant, you will play a pivotal role in delivering Secure by Design risk and security assurance services within MOD and Public Sector environments. You'll collaborate with multi-disciplinary teams to define and implement security risk assessments and best practice solutions, ensuring alignment with business risk appetites and transformation goals. You'll be part of a knowledge-sharing culture, working alongside expert peers in Secure Architecture and Risk Planning. This role supports the next phase of Cyberfort's growth and contributes to our mission of enabling clients to make proportionate, risk-informed decisions. Key Responsibilities Deliver Secure by Design risk and security assurance functions within MOD/Public Sector. Lead and advise on risk management frameworks, ISMS, and Enterprise Security Risk Management. Facilitate security and risk workshops with Authority departments. Produce clear reporting on vulnerabilities, risks, controls, and treatment activities. Provide pragmatic remediation and risk management guidance. Support secure design across technology platforms including cloud infrastructures. Contribute to blogs and research within the Cyberfort community. What We're Looking For Proven experience working in Governance, Risk and Compliance within Public Sector/MOD. Strong analytical, communication, and teamwork abilities. Passion for cybersecurity and continuous learning. Security Assurance Coordinator or Delivery Team Security Lead roles MOD/GDS Secure by Design Principles JSP440, JSP604/453, JSP490 Supplier Chain Assurance Security legislation (GDPR, PCI DSS, ICO) ISO 27001, NIST CSF, CIS Controls v8 Threat modelling, kill chain, attack tree analysis Cloud security (AWS, Azure), containerisation, firewalls Secure SDLC implementation HLD/LLD reviews ITHC scoping and remediation AI security (ISO42001 desirable) Certifications: AWS/Azure Security Professional, CCSP, CISSP, CISM, CIISEC, UK Cyber Security Council registration (Chartered or Principal). Clearance: Due to the nature of the projects, you'll be working on, you must hold an active and transferable DV (Developed vetting) clearance Must be a British citizen / resident in UK Inclusive Hiring We understand that one size doesn't fit all. If you need adjustments during the recruitment process, we're here to support you. Cyberfort is proud to be a Disability Confident Employer, a CyberFirst partner, and a signatory of the Armed Forces Covenant. Ready to Apply? If you're passionate about cybersecurity and want to make a real impact, we'd love to hear from you. Learn More Cyberfort Careers Page: Working at Cyberfort: LinkedIn:
GRC Cyber Security Consultant (MOD) - DV Cleared
Cyberfort Group
Cyberfort Group is seeking a Cyber Security Consultant to deliver crucial risk and security assurance services. The role requires collaboration with teams in Public Sector environments and involves strong governance and compliance experience. The ideal candidate will have a passion for cybersecurity, relevant certifications, and the ability to lead risk management functions. The position is hybrid, requiring occasional on-site presence.
26/07/2026
Full time
Cyberfort Group is seeking a Cyber Security Consultant to deliver crucial risk and security assurance services. The role requires collaboration with teams in Public Sector environments and involves strong governance and compliance experience. The ideal candidate will have a passion for cybersecurity, relevant certifications, and the ability to lead risk management functions. The position is hybrid, requiring occasional on-site presence.
Senior Cybersecurity Consultant
Instil Software Ltd City, Belfast
The Role We are looking for a Senior Cybersecurity Consultant to join our Cyber Consultancy team in Belfast. This is a hands on consulting role focused on delivering cybersecurity and information security engagements, with a strong emphasis on ISO27001 implementations, audit readiness, and governance, risk, and compliance (GRC). You will lead client engagements end to end, from initial assessment through to implementation and audit, working closely with client stakeholders to deliver practical, measurable outcomes. What You Will Do Engagement Delivery: Lead new and existing information and cybersecurity engagements. Deliver ISO27001 implementations, from gap assessment through to certification readiness. Deliver cyber incident exercising, including tabletop scenarios and simulations. Audit & Assurance: Lead internal audits aligned to ISO27001. Support clients through external audits and certification processes. Drive remediation activities to close audit findings and strengthen control effectiveness. Risk & Compliance: Conduct risk assessments and support the development of risk treatment plans. Develop and implement policies, standards, and controls aligned to ISO27001. Support clients in embedding effective governance, risk, and compliance practices. Stakeholder Management: Work directly with client stakeholders to manage delivery, expectations, and outcomes. Communicate clearly with both technical and non technical audiences. Manage multiple engagements and priorities effectively. What You Will Bring Essential Minimum 5 years' experience in cyber or information security roles, with a focus on governance, risk, and compliance. Proven experience delivering ISO27001 implementations end to end, including audit readiness. Hands on experience leading internal audits and supporting external audits. Strong, practical knowledge of ISO27001 and ISMS implementation. ISO27001 Lead Auditor certification. Experience in consulting or project based environments, with strong stakeholder management and communication skills. Nice to Have Experience delivering cyber incident exercising. Knowledge of additional frameworks such as: CAF (Cyber Assessment Framework) NIST Cyber Security Framework ISO22301 Lead Auditor certification (Business Continuity). ISO42001 Lead Auditor certification (AI Management Systems). Experience working in regulated or public sector environments. Eligibility for, or holding, UK Security Clearance (SC). Benefits Recognition That Matters: A discretionary annual performance bonus that rewards your impact and contribution to our success. Flexibility Built In: Flexible working arrangements and summer hours, because life isn't 9 to 5, and balance matters. Financial Security: A highly competitive pension scheme with generous employer contributions, private healthcare, and life assurance for peace of mind. Health & Wellbeing: Employee Assistance Programme, mental health support, cycle to work scheme, and regular social events to keep our culture vibrant. Time to Recharge: 35 days holiday, enhanced maternity pay, and family first policies so you can focus on what matters most. Learning Never Stops: From courses to certifications, we'll invest in your development so you can keep growing and shaping what's next. Community & Culture: Opportunities to volunteer, give back, and be part of initiatives that make Instil a truly inclusive and connected workplace.
25/07/2026
Full time
The Role We are looking for a Senior Cybersecurity Consultant to join our Cyber Consultancy team in Belfast. This is a hands on consulting role focused on delivering cybersecurity and information security engagements, with a strong emphasis on ISO27001 implementations, audit readiness, and governance, risk, and compliance (GRC). You will lead client engagements end to end, from initial assessment through to implementation and audit, working closely with client stakeholders to deliver practical, measurable outcomes. What You Will Do Engagement Delivery: Lead new and existing information and cybersecurity engagements. Deliver ISO27001 implementations, from gap assessment through to certification readiness. Deliver cyber incident exercising, including tabletop scenarios and simulations. Audit & Assurance: Lead internal audits aligned to ISO27001. Support clients through external audits and certification processes. Drive remediation activities to close audit findings and strengthen control effectiveness. Risk & Compliance: Conduct risk assessments and support the development of risk treatment plans. Develop and implement policies, standards, and controls aligned to ISO27001. Support clients in embedding effective governance, risk, and compliance practices. Stakeholder Management: Work directly with client stakeholders to manage delivery, expectations, and outcomes. Communicate clearly with both technical and non technical audiences. Manage multiple engagements and priorities effectively. What You Will Bring Essential Minimum 5 years' experience in cyber or information security roles, with a focus on governance, risk, and compliance. Proven experience delivering ISO27001 implementations end to end, including audit readiness. Hands on experience leading internal audits and supporting external audits. Strong, practical knowledge of ISO27001 and ISMS implementation. ISO27001 Lead Auditor certification. Experience in consulting or project based environments, with strong stakeholder management and communication skills. Nice to Have Experience delivering cyber incident exercising. Knowledge of additional frameworks such as: CAF (Cyber Assessment Framework) NIST Cyber Security Framework ISO22301 Lead Auditor certification (Business Continuity). ISO42001 Lead Auditor certification (AI Management Systems). Experience working in regulated or public sector environments. Eligibility for, or holding, UK Security Clearance (SC). Benefits Recognition That Matters: A discretionary annual performance bonus that rewards your impact and contribution to our success. Flexibility Built In: Flexible working arrangements and summer hours, because life isn't 9 to 5, and balance matters. Financial Security: A highly competitive pension scheme with generous employer contributions, private healthcare, and life assurance for peace of mind. Health & Wellbeing: Employee Assistance Programme, mental health support, cycle to work scheme, and regular social events to keep our culture vibrant. Time to Recharge: 35 days holiday, enhanced maternity pay, and family first policies so you can focus on what matters most. Learning Never Stops: From courses to certifications, we'll invest in your development so you can keep growing and shaping what's next. Community & Culture: Opportunities to volunteer, give back, and be part of initiatives that make Instil a truly inclusive and connected workplace.
Lead Cyber Security Consultant
Actica Consulting Limited Guildford, Surrey
Lead Cyber Security Consultant Department: Consultancy Employment Type: Full Time Location: United Kingdom / Remote Description As a Lead Cyber Security Consultant at Actica Consulting, you will have the opportunity to lead multiple, small Actica teams in their support to a wide range of high-profile UK public sector and defence organisations. Your help enables our customers to protect their ICT investments, and in doing so you will play a key role in nationally critical projects which make a real difference to people's everyday lives. You will be joining an established business practice with multiple in-flight projects and a continued demand for our services. This role will be responsible for the outputs of several small Actica teams, engaging senior customer stakeholders, supporting Actica personnel in the execution of their roles, supporting the mentoring and development of staff as well as growing the business through engaging with our established customer base and seeking new opportunities. Projects require the skills and experience to: Provide advice and guidance on Information Assurance topics Develop IA strategies, policies, guidance and awareness Plan and manage the delivery of a security work programme Define security requirements Design and implement security architectures Oversee the secure development and accreditation of information systems. Our position as both client-side advisor and at times working with industry delivery teams means that your role will involve significant stakeholder engagement, dealing directly with the client, including in resolving day day issues involved in assignment delivery and developing follow on opportunities, so excellent interpersonal and influencing skills are essential. Locations: London, Guildford, Bristol, M4 corridor Roles and Responsibilities Leading one or more Actica teams, you will undertake a number of varying consultancy assignments. Due to the potential variety in assignments your responsibilities will range from developing security architectures, to providing guidance on GRC activities. Other responsibilities will include: Providing security expertise for major system procurements and Agile programmes to ensure secure delivery; Identifying, analysing and evaluating information risks across a range of programmes, projects and systems; Explaining to risk owners the causes, likelihood and potential business impacts of information risks; Identifying and presenting options for treating or transferring information risks; Authoring and/or supporting the development of security assurance documentation; Developing or reviewing new security architectures; Scoping security testing activities, and explaining the results and required remediation. As part of the management team for the security practice your responsibilities will also include: Managing the delivery of security services by Actica teams across several live projects; Working with our client side customers to manage contract delivery; Working with our industry side customers to develop compelling, winning proposals and ultimately deliver projects into UK Defence or Public Sector; Coach, mentor and help develop junior Actica staff. Skills, Knowledge and Expertise The following attributes and areas of experience will make you particularly suited to this role with Actica: Experience of complex ICT systems security in a technical delivery or consulting capacity in the UK Defence sector or Public Sector; The ability to present and justify conclusions to project teams and business stakeholders; Proven abilities in delivering to client expectations and requirements; and Strong verbal and written communications skills. Knowledge of the following is highly desirable for the role: Structured security frameworks, such as HMG SPF and ISO27001; Security, technical and enterprise architecture methods such as TOGAF and SABSA; Technical risk assessments; Software development methods and techniques e.g. Agile methods such as SCRUM; Enterprise security packages, security enforcing software and devices, such as identity management and federation, cryptography, public key infrastructure, firewalls, SIEM, vulnerability scanning, etc. Additional Requirements: Must be eligible and willing to obtain UK Government Security Clearance. Key Attributes for Success: Ability to engage effectively with stakeholders, including resolving issues and identifying new opportunities. Strong interpersonal and influencing skills. Adaptability to a fast paced, ever changing environment. Working Arrangements: Hybrid working model, with an office base in Guildford, Surrey and access to our other offices in London, Swindon and Cheltenham. Typical working week might involve 2-3 days working at clients' premises or other locations and the remainder at home or at one of our offices. Some projects may require up to 5 days per week on site with colleagues. The practicalities of some project work means that individuals may need to stay away from home during the working week. Team based project environment with opportunities to participate in internal initiatives. Career Development You will have the opportunity to further your career in consulting, specialising in the application of information assurance and cyber security expertise to a wide range of business problems. We provide substantial training leading to nationally recognised certifications, such as chartered or principal status with the UK Cyber Security Council, or certifications such as CompTIA, NIST, PCiIAA, CISMP, CISSP, CREST, ISO27001 Lead Implementer/Auditor, SABSA, and TOGAF. A Mentor will be on hand to provide support and guidance throughout your journey with Actica. You will also work with a Performance and Development Manager, often outside of your project line of control, who will conduct regular reviews based on project feedback to set career objectives and identify training courses which are both relevant to your current project work, and aligned with your planned career progression. Our Commitment to Diversity Actica aims to nurture a diverse workforce through inclusive working practices, promoting equality in our recruitment activities, and by employing candidates on the basis of merit. Discrimination against individuals on the grounds of protected characteristics is not permitted and we take steps to ensure that our staff are made aware of their legal responsibilities when making hiring decisions. We offer a competitive suite of benefits
24/07/2026
Full time
Lead Cyber Security Consultant Department: Consultancy Employment Type: Full Time Location: United Kingdom / Remote Description As a Lead Cyber Security Consultant at Actica Consulting, you will have the opportunity to lead multiple, small Actica teams in their support to a wide range of high-profile UK public sector and defence organisations. Your help enables our customers to protect their ICT investments, and in doing so you will play a key role in nationally critical projects which make a real difference to people's everyday lives. You will be joining an established business practice with multiple in-flight projects and a continued demand for our services. This role will be responsible for the outputs of several small Actica teams, engaging senior customer stakeholders, supporting Actica personnel in the execution of their roles, supporting the mentoring and development of staff as well as growing the business through engaging with our established customer base and seeking new opportunities. Projects require the skills and experience to: Provide advice and guidance on Information Assurance topics Develop IA strategies, policies, guidance and awareness Plan and manage the delivery of a security work programme Define security requirements Design and implement security architectures Oversee the secure development and accreditation of information systems. Our position as both client-side advisor and at times working with industry delivery teams means that your role will involve significant stakeholder engagement, dealing directly with the client, including in resolving day day issues involved in assignment delivery and developing follow on opportunities, so excellent interpersonal and influencing skills are essential. Locations: London, Guildford, Bristol, M4 corridor Roles and Responsibilities Leading one or more Actica teams, you will undertake a number of varying consultancy assignments. Due to the potential variety in assignments your responsibilities will range from developing security architectures, to providing guidance on GRC activities. Other responsibilities will include: Providing security expertise for major system procurements and Agile programmes to ensure secure delivery; Identifying, analysing and evaluating information risks across a range of programmes, projects and systems; Explaining to risk owners the causes, likelihood and potential business impacts of information risks; Identifying and presenting options for treating or transferring information risks; Authoring and/or supporting the development of security assurance documentation; Developing or reviewing new security architectures; Scoping security testing activities, and explaining the results and required remediation. As part of the management team for the security practice your responsibilities will also include: Managing the delivery of security services by Actica teams across several live projects; Working with our client side customers to manage contract delivery; Working with our industry side customers to develop compelling, winning proposals and ultimately deliver projects into UK Defence or Public Sector; Coach, mentor and help develop junior Actica staff. Skills, Knowledge and Expertise The following attributes and areas of experience will make you particularly suited to this role with Actica: Experience of complex ICT systems security in a technical delivery or consulting capacity in the UK Defence sector or Public Sector; The ability to present and justify conclusions to project teams and business stakeholders; Proven abilities in delivering to client expectations and requirements; and Strong verbal and written communications skills. Knowledge of the following is highly desirable for the role: Structured security frameworks, such as HMG SPF and ISO27001; Security, technical and enterprise architecture methods such as TOGAF and SABSA; Technical risk assessments; Software development methods and techniques e.g. Agile methods such as SCRUM; Enterprise security packages, security enforcing software and devices, such as identity management and federation, cryptography, public key infrastructure, firewalls, SIEM, vulnerability scanning, etc. Additional Requirements: Must be eligible and willing to obtain UK Government Security Clearance. Key Attributes for Success: Ability to engage effectively with stakeholders, including resolving issues and identifying new opportunities. Strong interpersonal and influencing skills. Adaptability to a fast paced, ever changing environment. Working Arrangements: Hybrid working model, with an office base in Guildford, Surrey and access to our other offices in London, Swindon and Cheltenham. Typical working week might involve 2-3 days working at clients' premises or other locations and the remainder at home or at one of our offices. Some projects may require up to 5 days per week on site with colleagues. The practicalities of some project work means that individuals may need to stay away from home during the working week. Team based project environment with opportunities to participate in internal initiatives. Career Development You will have the opportunity to further your career in consulting, specialising in the application of information assurance and cyber security expertise to a wide range of business problems. We provide substantial training leading to nationally recognised certifications, such as chartered or principal status with the UK Cyber Security Council, or certifications such as CompTIA, NIST, PCiIAA, CISMP, CISSP, CREST, ISO27001 Lead Implementer/Auditor, SABSA, and TOGAF. A Mentor will be on hand to provide support and guidance throughout your journey with Actica. You will also work with a Performance and Development Manager, often outside of your project line of control, who will conduct regular reviews based on project feedback to set career objectives and identify training courses which are both relevant to your current project work, and aligned with your planned career progression. Our Commitment to Diversity Actica aims to nurture a diverse workforce through inclusive working practices, promoting equality in our recruitment activities, and by employing candidates on the basis of merit. Discrimination against individuals on the grounds of protected characteristics is not permitted and we take steps to ensure that our staff are made aware of their legal responsibilities when making hiring decisions. We offer a competitive suite of benefits
Hays Specialist Recruitment Limited
Cyber Essentials Plus Consultant
Hays Specialist Recruitment Limited
A major organisation operating within a complex, business-critical environment is seeking an experienced Cyber Essentials Plus Consultant to lead a significant remediation and certification programme. Following a recent review of the organisation's Cyber Essentials Plus readiness, a number of gaps have been identified that must be addressed before certification can be successfully achieved. The successful contractor will take ownership of the programme, driving remediation activity across technology teams and lead the organisation through to successful certification. This is a delivery-focused role requiring an individual who understands the Cyber Essentials and Cyber Essentials Plus process from end to end and can move beyond advisory recommendations to deliver tangible improvements. The Role: You will be responsible for assessing the current position, identifying gaps against Cyber Essentials Plus requirements and leading the remediation activity required to achieve certification. Working closely with technical and operational stakeholders, you will help improve security controls, challenge existing approaches and ensure regulatory and security requirements are embedded across the organisation. Key responsibilities will include: Leading Cyber Essentials Plus readiness and remediation activities Taking ownership of the certification programme from planning through to assessment Conducting gap analysis against Cyber Essentials Plus requirements Developing and driving remediation plans across infrastructure, endpoint and operational teams Reviewing security controls, policies and technical configurations Advising on security frameworks, standards and best practice Managing stakeholders across technology, security and operational functions Tracking risks, dependencies and programme progress through to completion What We're Looking For Proven experience delivering Cyber Essentials or Cyber Essentials Plus certification programmes Strong understanding of Cyber Essentials Plus requirements and assessment methodology Experience leading remediation initiatives and addressing audit or certification findings Good understanding of wider security frameworks and controls Technically minded with the ability to engage effectively with infrastructure, network, cloud and endpoint teams Strong stakeholder management and communication skills Comfortable operating in environments where security maturity is still developing Contract Details Outside IR35 Initial 6-month contract £350 - £450 per day Hybrid working North West England One-stage interview process Immediate start available This role will suit a Cyber Security Consultant, Cyber Essentials Consultant, Information Security Consultant or GRC professional who enjoys hands-on delivery and can drive change within a complex operational environment.If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
21/07/2026
Contractor
A major organisation operating within a complex, business-critical environment is seeking an experienced Cyber Essentials Plus Consultant to lead a significant remediation and certification programme. Following a recent review of the organisation's Cyber Essentials Plus readiness, a number of gaps have been identified that must be addressed before certification can be successfully achieved. The successful contractor will take ownership of the programme, driving remediation activity across technology teams and lead the organisation through to successful certification. This is a delivery-focused role requiring an individual who understands the Cyber Essentials and Cyber Essentials Plus process from end to end and can move beyond advisory recommendations to deliver tangible improvements. The Role: You will be responsible for assessing the current position, identifying gaps against Cyber Essentials Plus requirements and leading the remediation activity required to achieve certification. Working closely with technical and operational stakeholders, you will help improve security controls, challenge existing approaches and ensure regulatory and security requirements are embedded across the organisation. Key responsibilities will include: Leading Cyber Essentials Plus readiness and remediation activities Taking ownership of the certification programme from planning through to assessment Conducting gap analysis against Cyber Essentials Plus requirements Developing and driving remediation plans across infrastructure, endpoint and operational teams Reviewing security controls, policies and technical configurations Advising on security frameworks, standards and best practice Managing stakeholders across technology, security and operational functions Tracking risks, dependencies and programme progress through to completion What We're Looking For Proven experience delivering Cyber Essentials or Cyber Essentials Plus certification programmes Strong understanding of Cyber Essentials Plus requirements and assessment methodology Experience leading remediation initiatives and addressing audit or certification findings Good understanding of wider security frameworks and controls Technically minded with the ability to engage effectively with infrastructure, network, cloud and endpoint teams Strong stakeholder management and communication skills Comfortable operating in environments where security maturity is still developing Contract Details Outside IR35 Initial 6-month contract £350 - £450 per day Hybrid working North West England One-stage interview process Immediate start available This role will suit a Cyber Security Consultant, Cyber Essentials Consultant, Information Security Consultant or GRC professional who enjoys hands-on delivery and can drive change within a complex operational environment.If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
Lynx Recruitment Ltd
Business Development Manager
Lynx Recruitment Ltd St. Albans, Hertfordshire
Business Development Manager - Cyber Security St Albans (Hybrid Working) £40,000 - £50,000 Basic + Uncapped Commission Full Time Permanent Ready to Build Your Career in Cyber Security Sales? This isn't a role where you'll inherit a portfolio of existing accounts and simply manage relationships. This is an opportunity for ambitious sales professionals who enjoy creating opportunities, winning new business and building long-term client relationships within one of the UK's fastest-growing technology sectors. If you're motivated by prospecting, opening new doors and being rewarded for your success, we'd love to hear from you. The Role We're looking for two New Business Development Managers to join a growing cyber security consultancy. You'll be responsible for identifying and winning new customers, developing your own sales pipeline and becoming a trusted advisor to organisations looking to strengthen their cyber security posture. With the support of experienced technical consultants, marketing and leading cyber security vendors, you'll have everything you need to succeed-except a list of existing accounts. This is a genuine new business sales role . What You'll Be Selling You'll represent a portfolio of industry-leading cyber security solutions including: Managed Security Services Microsoft Security Solutions Vulnerability Management CrowdStrike Qualys AppCheck Email Security Penetration Testing Security Assessments Governance, Risk & Compliance (GRC) Cyber Security Advisory Services Typical deal values range from £20,000 to £750,000+ , with many customers choosing long-term managed service agreements. Key Responsibilities Generate and qualify new business opportunities. Build relationships with CIOs, CISOs, IT Directors and senior decision-makers. Conduct discovery meetings to understand customer challenges. Develop tailored commercial proposals alongside technical specialists. Negotiate and close new business opportunities. Build and manage a healthy sales pipeline. Become a trusted advisor within your customer base. About You We're looking for driven, commercially minded sales professionals who enjoy winning new business and building relationships. Ideally you'll have: At least 2 years' experience in B2B technology sales. A genuine passion for new business development. Experience selling Cyber Security, Cloud, SaaS, IT Services or Managed Services (desirable but not essential). Excellent communication, negotiation and presentation skills. Strong commercial awareness. A resilient, proactive and self-motivated approach. A genuine hunter mentality with a desire to exceed targets. You'll Enjoy This Role If You Love winning new business. Thrive on prospecting and opening new doors. Enjoy building relationships from scratch. Want autonomy and ownership. Are ambitious and motivated by uncapped earnings. Want to build a long-term career within cyber security sales. What's On Offer? Competitive basic salary of £40,000-£50,000 + Uncapped commission with excellent earning potential. Hybrid working. Defined sales territory. Technical pre-sales support. Marketing support to help generate opportunities. Access to market-leading cyber security vendors. Genuine career progression within a growing business. Supportive, collaborative and ambitious team culture. Apply Today If you're an ambitious sales professional looking to develop your career within the rapidly growing cyber security market, we'd love to hear from you. This is your opportunity to join a business where success is recognised, hard work is rewarded and your career progression is in your hands.
20/07/2026
Full time
Business Development Manager - Cyber Security St Albans (Hybrid Working) £40,000 - £50,000 Basic + Uncapped Commission Full Time Permanent Ready to Build Your Career in Cyber Security Sales? This isn't a role where you'll inherit a portfolio of existing accounts and simply manage relationships. This is an opportunity for ambitious sales professionals who enjoy creating opportunities, winning new business and building long-term client relationships within one of the UK's fastest-growing technology sectors. If you're motivated by prospecting, opening new doors and being rewarded for your success, we'd love to hear from you. The Role We're looking for two New Business Development Managers to join a growing cyber security consultancy. You'll be responsible for identifying and winning new customers, developing your own sales pipeline and becoming a trusted advisor to organisations looking to strengthen their cyber security posture. With the support of experienced technical consultants, marketing and leading cyber security vendors, you'll have everything you need to succeed-except a list of existing accounts. This is a genuine new business sales role . What You'll Be Selling You'll represent a portfolio of industry-leading cyber security solutions including: Managed Security Services Microsoft Security Solutions Vulnerability Management CrowdStrike Qualys AppCheck Email Security Penetration Testing Security Assessments Governance, Risk & Compliance (GRC) Cyber Security Advisory Services Typical deal values range from £20,000 to £750,000+ , with many customers choosing long-term managed service agreements. Key Responsibilities Generate and qualify new business opportunities. Build relationships with CIOs, CISOs, IT Directors and senior decision-makers. Conduct discovery meetings to understand customer challenges. Develop tailored commercial proposals alongside technical specialists. Negotiate and close new business opportunities. Build and manage a healthy sales pipeline. Become a trusted advisor within your customer base. About You We're looking for driven, commercially minded sales professionals who enjoy winning new business and building relationships. Ideally you'll have: At least 2 years' experience in B2B technology sales. A genuine passion for new business development. Experience selling Cyber Security, Cloud, SaaS, IT Services or Managed Services (desirable but not essential). Excellent communication, negotiation and presentation skills. Strong commercial awareness. A resilient, proactive and self-motivated approach. A genuine hunter mentality with a desire to exceed targets. You'll Enjoy This Role If You Love winning new business. Thrive on prospecting and opening new doors. Enjoy building relationships from scratch. Want autonomy and ownership. Are ambitious and motivated by uncapped earnings. Want to build a long-term career within cyber security sales. What's On Offer? Competitive basic salary of £40,000-£50,000 + Uncapped commission with excellent earning potential. Hybrid working. Defined sales territory. Technical pre-sales support. Marketing support to help generate opportunities. Access to market-leading cyber security vendors. Genuine career progression within a growing business. Supportive, collaborative and ambitious team culture. Apply Today If you're an ambitious sales professional looking to develop your career within the rapidly growing cyber security market, we'd love to hear from you. This is your opportunity to join a business where success is recognised, hard work is rewarded and your career progression is in your hands.
Capability Lead - Cyber Security
Story Terrace Inc. Corsham, Wiltshire
Capability Lead - Cyber Security Location: Hybrid opportunities available with offices in Corsham & Warrington. Occasional travel to client sites, industry events and company locations. A Forward-looking Engineering Company Ebeni is involved in projects and programmes in the Defence, Aerospace, Aviation, Nuclear, Rail and Automotive markets. Ebeni is a people-centric company, respecting individual aspirations as well as promoting benefit to all: customers, employees and society. Our people, their skills, knowledge and experience, are our most valuable asset. We take pride in our reputation and recognise it is built on the commitment and dedication of our people. Our core values, Excellence, Benefit, Integrity, are reflected in our name and underpin both how we do business and how we approach our work. In short, you can rely on Ebeni to deliver innovative solutions that assure the safety and security of existing and emerging technologies. Our Team As part of Ebeni's Cyber team, you will play a key role in shaping the future of our cyber security capability. Working closely with technical and business leaders, you will provide strategic and technical leadership across service development, delivery quality, team capability and business growth. This is an exciting opportunity to influence the direction of a growing cyber consultancy, whilst continuing to deliver high-value consultancy services to clients across a range of sectors. The Role As Capability Lead - Cyber Security, you will be responsible for developing, maintaining and growing Ebeni's cyber capability, ensuring the organisation delivers high-quality, technically credible services aligned with customer needs and market opportunities. Key responsibilities include: Developing and executing the strategy for Ebeni's cyber capability in collaboration with Business Unit Leads. Providing technical leadership and oversight across cyber security service offerings, methodologies and delivery standards. Ensuring the quality, consistency and technical excellence of cyber security project delivery. Supporting and mentoring cyber consultants, helping to develop professional standards, capability and career progression. Leading and contributing to complex cyber security consultancy engagements, acting as a trusted technical authority. Supporting business development activities through bid support, proposal development, customer engagement and opportunity shaping. Representing Ebeni at client meetings, industry events and professional forums. Driving growth across cyber security services and supporting expansion into new markets and sectors. Providing technical leadership for accredited cyber security services and governance activities, including leading Ebeni's journey to achieve and maintain Accredited Cyber Security Consultancy (ACSC) status, ensuring alignment with all relevant industry frameworks, standards and professional requirements. Supporting continuous improvement of cyber security service offerings, assurance approaches and technical governance processes. Please note that all applicants must be able to obtain and/or maintain a valid UK security clearance. Skills & Experience We are looking for an experienced cyber security professional with a strong consultancy background and a passion for developing people, services and capability. Candidates should demonstrate experience in some or all of the following areas: Cyber Security, Governance, Risk and Compliance (GRC), Information Assurance and Risk Management. Delivering complex cyber security consultancy engagements and technical assurance activities. Developing and improving cyber security services, methodologies and technical standards. Technical leadership of cyber security teams and multidisciplinary delivery environments. Supporting business development through bids, proposals, customer engagement and solution development. Security governance and assurance activities aligned to recognised industry frameworks and standards. Stakeholder management and engagement across technical, operational and executive audiences. Coaching, mentoring and developing cyber security professionals. Experience in one or more of the following would be advantageous: NCSC guidance, UK Cyber Security Council frameworks and CIISec professional standards. Defence, Government, Critical National Infrastructure or other highly regulated sectors. Security governance, risk and compliance services. Cyber security assurance, audit, architecture or accreditation activities. Building and scaling cyber security capabilities within a consultancy environment. Relevant cyber security qualifications, professional memberships or chartered status (e.g. CIISec, CISSP, CISM or UK Cyber Security Council Chartered status) are desirable; equivalent experience and demonstrable expertise will be considered. Personal Development Ebeni put people first, and wellbeing is at the forefront of what we do. We provide opportunities for our people to develop and aim to provide a rewarding work-life balance. Our success depends on motivated, committed and trusted employees who feel they play a part in helping the business grow. All our consultants are assigned an experienced career development coach to support their professional growth and progression. Join Us All applications will receive consideration for employment without regard to race, ethnicity, religion, gender, gender identity or expression, sexual orientation, nationality, disability, age, faith or social background. We actively encourage applications from underrepresented and minority groups and operate an inclusive recruitment process, providing reasonable adjustments wherever needed.
19/07/2026
Full time
Capability Lead - Cyber Security Location: Hybrid opportunities available with offices in Corsham & Warrington. Occasional travel to client sites, industry events and company locations. A Forward-looking Engineering Company Ebeni is involved in projects and programmes in the Defence, Aerospace, Aviation, Nuclear, Rail and Automotive markets. Ebeni is a people-centric company, respecting individual aspirations as well as promoting benefit to all: customers, employees and society. Our people, their skills, knowledge and experience, are our most valuable asset. We take pride in our reputation and recognise it is built on the commitment and dedication of our people. Our core values, Excellence, Benefit, Integrity, are reflected in our name and underpin both how we do business and how we approach our work. In short, you can rely on Ebeni to deliver innovative solutions that assure the safety and security of existing and emerging technologies. Our Team As part of Ebeni's Cyber team, you will play a key role in shaping the future of our cyber security capability. Working closely with technical and business leaders, you will provide strategic and technical leadership across service development, delivery quality, team capability and business growth. This is an exciting opportunity to influence the direction of a growing cyber consultancy, whilst continuing to deliver high-value consultancy services to clients across a range of sectors. The Role As Capability Lead - Cyber Security, you will be responsible for developing, maintaining and growing Ebeni's cyber capability, ensuring the organisation delivers high-quality, technically credible services aligned with customer needs and market opportunities. Key responsibilities include: Developing and executing the strategy for Ebeni's cyber capability in collaboration with Business Unit Leads. Providing technical leadership and oversight across cyber security service offerings, methodologies and delivery standards. Ensuring the quality, consistency and technical excellence of cyber security project delivery. Supporting and mentoring cyber consultants, helping to develop professional standards, capability and career progression. Leading and contributing to complex cyber security consultancy engagements, acting as a trusted technical authority. Supporting business development activities through bid support, proposal development, customer engagement and opportunity shaping. Representing Ebeni at client meetings, industry events and professional forums. Driving growth across cyber security services and supporting expansion into new markets and sectors. Providing technical leadership for accredited cyber security services and governance activities, including leading Ebeni's journey to achieve and maintain Accredited Cyber Security Consultancy (ACSC) status, ensuring alignment with all relevant industry frameworks, standards and professional requirements. Supporting continuous improvement of cyber security service offerings, assurance approaches and technical governance processes. Please note that all applicants must be able to obtain and/or maintain a valid UK security clearance. Skills & Experience We are looking for an experienced cyber security professional with a strong consultancy background and a passion for developing people, services and capability. Candidates should demonstrate experience in some or all of the following areas: Cyber Security, Governance, Risk and Compliance (GRC), Information Assurance and Risk Management. Delivering complex cyber security consultancy engagements and technical assurance activities. Developing and improving cyber security services, methodologies and technical standards. Technical leadership of cyber security teams and multidisciplinary delivery environments. Supporting business development through bids, proposals, customer engagement and solution development. Security governance and assurance activities aligned to recognised industry frameworks and standards. Stakeholder management and engagement across technical, operational and executive audiences. Coaching, mentoring and developing cyber security professionals. Experience in one or more of the following would be advantageous: NCSC guidance, UK Cyber Security Council frameworks and CIISec professional standards. Defence, Government, Critical National Infrastructure or other highly regulated sectors. Security governance, risk and compliance services. Cyber security assurance, audit, architecture or accreditation activities. Building and scaling cyber security capabilities within a consultancy environment. Relevant cyber security qualifications, professional memberships or chartered status (e.g. CIISec, CISSP, CISM or UK Cyber Security Council Chartered status) are desirable; equivalent experience and demonstrable expertise will be considered. Personal Development Ebeni put people first, and wellbeing is at the forefront of what we do. We provide opportunities for our people to develop and aim to provide a rewarding work-life balance. Our success depends on motivated, committed and trusted employees who feel they play a part in helping the business grow. All our consultants are assigned an experienced career development coach to support their professional growth and progression. Join Us All applications will receive consideration for employment without regard to race, ethnicity, religion, gender, gender identity or expression, sexual orientation, nationality, disability, age, faith or social background. We actively encourage applications from underrepresented and minority groups and operate an inclusive recruitment process, providing reasonable adjustments wherever needed.
Cyber Security Consultant / Security Architect
Make UK Corsham, Wiltshire
Cyber Security Consultant / Security Architect Salary: Up to £90,000 This is a client-facing role supporting MOD and public sector environments across secure design, cyber assurance, risk management and technical security architecture. We need someone who can review technical designs, understand security risk, advise on controls, support Secure by Design activity and produce clear assurance documentation. Strong fit for someone with experience across MOD, defence, government, public sector, CNI or highly regulated environments. Relevant backgrounds could include Security Architect, Cyber Security Consultant, Security Assurance Consultant, Secure by Design Consultant or Technical Security Consultant. Role Summary We are looking for a Cyber Security Consultant with a strong Security Architecture background to support secure design, cyber assurance and risk management across MOD and public sector environments. This role would suit someone who has worked across security architecture, secure system design, technical assurance and cyber risk, and who is comfortable operating in a highly regulated defence environment. This is not a purely documentation-led GRC role. We need someone who can understand technical systems, assess security risk, challenge architecture decisions, shape secure designs and produce clear assurance outputs for senior technical and non-technical stakeholders. The role is based 5 days per week on site at MOD Corsham. Requirements Support secure system design and cyber assurance activity across MOD and public sector programmes. Review technical architectures and advise on security risks, controls and design improvements. Produce and maintain security architecture documentation, risk assessments, assurance plans and security management artefacts. Support Secure by Design activity across complex systems and programmes. Assess security controls across cloud, infrastructure, networks, identity, applications and data. Translate technical security risks into clear, practical advice for programme teams and senior stakeholders. Support the development of security cases, risk treatment plans and accreditation-style documentation. Work with technical teams, delivery teams, suppliers and customer stakeholders to ensure security requirements are properly understood and implemented. Review outputs from vulnerability assessments, penetration tests and supplier assurance activity, then advise on remediation and risk acceptance. Help clients align with relevant frameworks and standards, including ISO 27001, NIST, CAF, GovAssure, Secure by Design and HMG / MOD assurance expectations. Strong background in Security Architecture, Cyber Security Consultancy, Security Assurance or Secure Design. Experience working in defence, MOD, public sector, government, CNI or another highly regulated environment. Good understanding of secure architecture principles across infrastructure, cloud, networks, identity, applications and data. Experience producing security documentation for complex technical environments. Ability to review technical designs and explain cyber risk clearly. Strong stakeholder management skills, including the ability to advise technical teams and brief non-technical decision makers. Knowledge of security frameworks such as ISO 27001, NIST, CAF, Secure by Design, GovAssure or HMG / MOD security standards. Comfortable working 5 days per week on site at MOD Corsham. Current SC clearance, or DV Useful Certifications CISSP CISM CISA CCP TOGAF ISO 27001 Lead Implementer or Lead Auditor CCSP AWS Security Benefits Annual salary reviews and a discretionary Company consultant bonus scheme Company pension scheme Private healthcare (including dental and optical) for you and your family Flexible and remote working options 25 days of holiday per year, increasing with service Life assurance and income protection Employee Assistance Programme/ Wellbeing Support Time off for Armed Forces Reservists Recognition for long service Recruitment Bounty referral scheme Social events to build team camaraderie.
18/07/2026
Full time
Cyber Security Consultant / Security Architect Salary: Up to £90,000 This is a client-facing role supporting MOD and public sector environments across secure design, cyber assurance, risk management and technical security architecture. We need someone who can review technical designs, understand security risk, advise on controls, support Secure by Design activity and produce clear assurance documentation. Strong fit for someone with experience across MOD, defence, government, public sector, CNI or highly regulated environments. Relevant backgrounds could include Security Architect, Cyber Security Consultant, Security Assurance Consultant, Secure by Design Consultant or Technical Security Consultant. Role Summary We are looking for a Cyber Security Consultant with a strong Security Architecture background to support secure design, cyber assurance and risk management across MOD and public sector environments. This role would suit someone who has worked across security architecture, secure system design, technical assurance and cyber risk, and who is comfortable operating in a highly regulated defence environment. This is not a purely documentation-led GRC role. We need someone who can understand technical systems, assess security risk, challenge architecture decisions, shape secure designs and produce clear assurance outputs for senior technical and non-technical stakeholders. The role is based 5 days per week on site at MOD Corsham. Requirements Support secure system design and cyber assurance activity across MOD and public sector programmes. Review technical architectures and advise on security risks, controls and design improvements. Produce and maintain security architecture documentation, risk assessments, assurance plans and security management artefacts. Support Secure by Design activity across complex systems and programmes. Assess security controls across cloud, infrastructure, networks, identity, applications and data. Translate technical security risks into clear, practical advice for programme teams and senior stakeholders. Support the development of security cases, risk treatment plans and accreditation-style documentation. Work with technical teams, delivery teams, suppliers and customer stakeholders to ensure security requirements are properly understood and implemented. Review outputs from vulnerability assessments, penetration tests and supplier assurance activity, then advise on remediation and risk acceptance. Help clients align with relevant frameworks and standards, including ISO 27001, NIST, CAF, GovAssure, Secure by Design and HMG / MOD assurance expectations. Strong background in Security Architecture, Cyber Security Consultancy, Security Assurance or Secure Design. Experience working in defence, MOD, public sector, government, CNI or another highly regulated environment. Good understanding of secure architecture principles across infrastructure, cloud, networks, identity, applications and data. Experience producing security documentation for complex technical environments. Ability to review technical designs and explain cyber risk clearly. Strong stakeholder management skills, including the ability to advise technical teams and brief non-technical decision makers. Knowledge of security frameworks such as ISO 27001, NIST, CAF, Secure by Design, GovAssure or HMG / MOD security standards. Comfortable working 5 days per week on site at MOD Corsham. Current SC clearance, or DV Useful Certifications CISSP CISM CISA CCP TOGAF ISO 27001 Lead Implementer or Lead Auditor CCSP AWS Security Benefits Annual salary reviews and a discretionary Company consultant bonus scheme Company pension scheme Private healthcare (including dental and optical) for you and your family Flexible and remote working options 25 days of holiday per year, increasing with service Life assurance and income protection Employee Assistance Programme/ Wellbeing Support Time off for Armed Forces Reservists Recognition for long service Recruitment Bounty referral scheme Social events to build team camaraderie.
Adecco
Cyber Security GRC Consultant
Adecco Salisbury, Wiltshire
Cyber Security GRC Consultant (DV Clearance required) Salisbury (Onsite, 5 days/week) Competitive Salary + Benefits We are looking for an experienced DV Cleared Cyber Security GRC Consultant to support a major security and compliance programme within a highly secure environment. This is a key role focused on ensuring security controls, governance frameworks, and compliance obligations are effectively aligned with recognised industry standards and contractual requirements. You'll work closely with technical and business stakeholders to identify risks, assess existing controls, and drive security improvements across complex programmes. You will be responsible for the assessment, governance, assurance, and continuous improvement of security controls, helping organisations maintain robust cyber security practices while meeting regulatory and business requirements. Key Responsibilities: Translate contractual and regulatory security requirements into practical security controls aligned with recognised frameworks. Conduct security risk assessments, control reviews, and gap analysis activities. Identify security weaknesses and recommend appropriate mitigation strategies. Deliver security assurance activities including evidence reviews, compliance validation, and control testing. Support the development and enhancement of security policies, standards, and governance processes. Collaborate with stakeholders, suppliers, and project teams to ensure security requirements are understood and met. Assist with audits, compliance activities, and reporting to technical and non-technical audiences. We're Looking For: Proven experience within Cyber Security Governance, Risk & Compliance (GRC) environments. Strong knowledge of NIST CSF, NIST 800-53, ISO 27001, and NCSC CAF . Experience conducting risk assessments and security control reviews. Ability to interpret regulatory or contractual requirements and translate them into actionable security controls. Excellent stakeholder management and communication skills. Ability to work independently and manage multiple priorities in a fast-paced environment. Desirable: CISSP, CISA, CRISC, ISO 27001 certifications, alongside exposure to frameworks such as ISO 22301, ISO 31000, GDPR, PCI-DSS, OWASP, and other security assurance standards. Security Clearance: Candidates should hold current DV Clearance . If you're passionate about cyber security governance, risk management, and helping organisations strengthen their security posture, we'd love to hear from you.
17/07/2026
Full time
Cyber Security GRC Consultant (DV Clearance required) Salisbury (Onsite, 5 days/week) Competitive Salary + Benefits We are looking for an experienced DV Cleared Cyber Security GRC Consultant to support a major security and compliance programme within a highly secure environment. This is a key role focused on ensuring security controls, governance frameworks, and compliance obligations are effectively aligned with recognised industry standards and contractual requirements. You'll work closely with technical and business stakeholders to identify risks, assess existing controls, and drive security improvements across complex programmes. You will be responsible for the assessment, governance, assurance, and continuous improvement of security controls, helping organisations maintain robust cyber security practices while meeting regulatory and business requirements. Key Responsibilities: Translate contractual and regulatory security requirements into practical security controls aligned with recognised frameworks. Conduct security risk assessments, control reviews, and gap analysis activities. Identify security weaknesses and recommend appropriate mitigation strategies. Deliver security assurance activities including evidence reviews, compliance validation, and control testing. Support the development and enhancement of security policies, standards, and governance processes. Collaborate with stakeholders, suppliers, and project teams to ensure security requirements are understood and met. Assist with audits, compliance activities, and reporting to technical and non-technical audiences. We're Looking For: Proven experience within Cyber Security Governance, Risk & Compliance (GRC) environments. Strong knowledge of NIST CSF, NIST 800-53, ISO 27001, and NCSC CAF . Experience conducting risk assessments and security control reviews. Ability to interpret regulatory or contractual requirements and translate them into actionable security controls. Excellent stakeholder management and communication skills. Ability to work independently and manage multiple priorities in a fast-paced environment. Desirable: CISSP, CISA, CRISC, ISO 27001 certifications, alongside exposure to frameworks such as ISO 22301, ISO 31000, GDPR, PCI-DSS, OWASP, and other security assurance standards. Security Clearance: Candidates should hold current DV Clearance . If you're passionate about cyber security governance, risk management, and helping organisations strengthen their security posture, we'd love to hear from you.
Senior Information Governance Security Consultant
Civica UK Ltd
Description We're Civica and we make software that helps deliver critical services for citizens all around the world. From local to state government, to education, to health and care, over 5,000 public bodies across the globe use our software to help provide critical services to over 100 million citizens. Our aspiration is to be a GovTech champion everywhere we work around the globe, supporting the needs of citizens and those that serve them every day. Building on 21 years of continuous growth and success, we're at a pivotal point on our journey to realise that aspiration. Why you'll love this role of Senior Information Governance Security Consultant This is a high-impact, client-facing role where you will help organisations strengthen their information governance and cyber security posture. You'll work across a variety of public and private sector clients, delivering consultancy that directly improves resilience, compliance, and risk management. You'll have the opportunity to lead meaningful security engagements, from gap analysis and risk assessments to certification support and security improvement programmes. This role offers a strong mix of autonomy, variety, and influence-ideal for someone who enjoys solving complex security challenges and driving best practice. If you are passionate about governance, risk, and compliance, and enjoy working closely with clients to deliver real-world impact, this role gives you the platform to do exactly that. This role can be performed predominantly from home, with occasional travel to offices. Responsibilities Deliver Information Governance (IG) and Information Security (IS) consultancy services to clients Conduct gap analysis, risk assessments, and risk treatment planning Assess organisations against standards such as Cyber Essentials, Cyber Essentials Plus, and ISO 27001 Support clients through certification processes and security improvement programmes Perform audits to ensure effectiveness of security controls Produce high-quality security reports and present findings to stakeholders Provide continuous assessment of client security practices and recommend improvements Contribute to the development and enhancement of IG and cyber security service offerings Deliver consultancy across recognised frameworks such as the NCSC Cyber Assessment Framework (CAF) Develop and review security policies, procedures, and controls Deliver security awareness training, workshops, and exercises Collaborate with internal teams and support pre/post sales activities Mentor colleagues and contribute to team knowledge sharing Maintain strong client relationships and stakeholder communication Experience & Skills Strong experience in IT Governance, Risk & Compliance (GRC) across cloud and on-premise environments Knowledge of security and data protection frameworks including ISO 27001, Cyber Essentials Plus, and GDPR Experience applying risk management principles and methodologies In-depth understanding of Cyber Essentials and NCSC CAF Ability to advise on security strategy and risk mitigation Strong knowledge of information security principles and technical controls Proven experience in client-facing roles Excellent communication skills, with the ability to engage stakeholders at all levels Strong organisational skills with attention to detail Ability to work independently with minimal supervision Nice to have: Experience implementing and auditing ISMS aligned to ISO 27001 Relevant certifications such as CISSP, CISM, CISA, or CEH Experience working with frameworks such as DTAC, DSPT, CAF, or PSN Experience delivering security awareness programmes Experience in third-party assurance activities Ability to communicate complex security risks to both technical and non-technical audiences, including C-level stakeholders Strong presentation and reporting skills Experience working with Local Government We Want You to Bring Your Whole Self to Work There is no such thing as the perfect candidate, so if you think you have what it takes but don't necessarily meet every single point on the list above, please still get in touch. We'd love to have a chat and see if you could be a great fit. Why You'll Love Working with Us As a company, we're passionate about what we do and the citizens we serve. If you, too, want to champion the use of technology in public services to improve outcomes for citizens and public sector organizations, then Civica is the right place for you. We will help you unlock the best version of yourself, achieve career growth, and make a real difference to people and communities. Time Off & Work-Life Balance 25 Days Annual Leave + bank holidays - plus the option to buy up to 10 extra days! Days of Difference - Up to 3 extra days off for volunteering. Financial Well-being & Security Pension Contribution - 5% employer match to support your future. Income Protection - Up to 75% salary cover for long-term illness. Life Assurance - 4x salary tax-free lump sum. Critical Illness Cover - £25,000 lump sum (extendable to dependents). Health & Perks Private Medical Insurance - Fast access to private healthcare. Health Cash Plan - Claim back physio, therapies & more. Dental Insurance - Cover for routine & emergency care. Electric Vehicle (EV) Scheme - A wide range of electric & hybrid vehicles. Affinity Groups - Join employee-led communities. Bounty Bonus - Refer a friend & get rewarded. At Civica, we are committed to building an inclusive and diverse workplace where everyone feels valued and supported. We believe that a variety of perspectives drives innovation and excellence, and we welcome applicants from all backgrounds, cultures, and experiences. We are an equal opportunity employer. We do not discriminate based on race, ethnicity, religion, gender, sexual orientation, disability, age, or any other legally protected characteristic. Our recruitment process is designed to ensure fairness and transparency, so every candidate has an equal chance to contribute to our mission. If you need any adjustments or accommodations to participate in our recruitment process, please let us know. We are here to support you.
12/07/2026
Full time
Description We're Civica and we make software that helps deliver critical services for citizens all around the world. From local to state government, to education, to health and care, over 5,000 public bodies across the globe use our software to help provide critical services to over 100 million citizens. Our aspiration is to be a GovTech champion everywhere we work around the globe, supporting the needs of citizens and those that serve them every day. Building on 21 years of continuous growth and success, we're at a pivotal point on our journey to realise that aspiration. Why you'll love this role of Senior Information Governance Security Consultant This is a high-impact, client-facing role where you will help organisations strengthen their information governance and cyber security posture. You'll work across a variety of public and private sector clients, delivering consultancy that directly improves resilience, compliance, and risk management. You'll have the opportunity to lead meaningful security engagements, from gap analysis and risk assessments to certification support and security improvement programmes. This role offers a strong mix of autonomy, variety, and influence-ideal for someone who enjoys solving complex security challenges and driving best practice. If you are passionate about governance, risk, and compliance, and enjoy working closely with clients to deliver real-world impact, this role gives you the platform to do exactly that. This role can be performed predominantly from home, with occasional travel to offices. Responsibilities Deliver Information Governance (IG) and Information Security (IS) consultancy services to clients Conduct gap analysis, risk assessments, and risk treatment planning Assess organisations against standards such as Cyber Essentials, Cyber Essentials Plus, and ISO 27001 Support clients through certification processes and security improvement programmes Perform audits to ensure effectiveness of security controls Produce high-quality security reports and present findings to stakeholders Provide continuous assessment of client security practices and recommend improvements Contribute to the development and enhancement of IG and cyber security service offerings Deliver consultancy across recognised frameworks such as the NCSC Cyber Assessment Framework (CAF) Develop and review security policies, procedures, and controls Deliver security awareness training, workshops, and exercises Collaborate with internal teams and support pre/post sales activities Mentor colleagues and contribute to team knowledge sharing Maintain strong client relationships and stakeholder communication Experience & Skills Strong experience in IT Governance, Risk & Compliance (GRC) across cloud and on-premise environments Knowledge of security and data protection frameworks including ISO 27001, Cyber Essentials Plus, and GDPR Experience applying risk management principles and methodologies In-depth understanding of Cyber Essentials and NCSC CAF Ability to advise on security strategy and risk mitigation Strong knowledge of information security principles and technical controls Proven experience in client-facing roles Excellent communication skills, with the ability to engage stakeholders at all levels Strong organisational skills with attention to detail Ability to work independently with minimal supervision Nice to have: Experience implementing and auditing ISMS aligned to ISO 27001 Relevant certifications such as CISSP, CISM, CISA, or CEH Experience working with frameworks such as DTAC, DSPT, CAF, or PSN Experience delivering security awareness programmes Experience in third-party assurance activities Ability to communicate complex security risks to both technical and non-technical audiences, including C-level stakeholders Strong presentation and reporting skills Experience working with Local Government We Want You to Bring Your Whole Self to Work There is no such thing as the perfect candidate, so if you think you have what it takes but don't necessarily meet every single point on the list above, please still get in touch. We'd love to have a chat and see if you could be a great fit. Why You'll Love Working with Us As a company, we're passionate about what we do and the citizens we serve. If you, too, want to champion the use of technology in public services to improve outcomes for citizens and public sector organizations, then Civica is the right place for you. We will help you unlock the best version of yourself, achieve career growth, and make a real difference to people and communities. Time Off & Work-Life Balance 25 Days Annual Leave + bank holidays - plus the option to buy up to 10 extra days! Days of Difference - Up to 3 extra days off for volunteering. Financial Well-being & Security Pension Contribution - 5% employer match to support your future. Income Protection - Up to 75% salary cover for long-term illness. Life Assurance - 4x salary tax-free lump sum. Critical Illness Cover - £25,000 lump sum (extendable to dependents). Health & Perks Private Medical Insurance - Fast access to private healthcare. Health Cash Plan - Claim back physio, therapies & more. Dental Insurance - Cover for routine & emergency care. Electric Vehicle (EV) Scheme - A wide range of electric & hybrid vehicles. Affinity Groups - Join employee-led communities. Bounty Bonus - Refer a friend & get rewarded. At Civica, we are committed to building an inclusive and diverse workplace where everyone feels valued and supported. We believe that a variety of perspectives drives innovation and excellence, and we welcome applicants from all backgrounds, cultures, and experiences. We are an equal opportunity employer. We do not discriminate based on race, ethnicity, religion, gender, sexual orientation, disability, age, or any other legally protected characteristic. Our recruitment process is designed to ensure fairness and transparency, so every candidate has an equal chance to contribute to our mission. If you need any adjustments or accommodations to participate in our recruitment process, please let us know. We are here to support you.
Forward Deployed Engineer
HelmGuard Technologies, Inc.
About HelmGuard We're building agent-native risk infrastructure: risk management and trust building, delivered by AI agents, for a world increasingly run by them. As more decisions and transactions run through agents, the volume of risk to manage and trust to establish is growing very fast. Today both functions are fragmented, split across internal teams, point products, and outside consultants, and rebuilt from scratch whenever someone needs an answer. HelmGuard brings them onto one platform and runs them continuously: our agents sit on top of proprietary data and reassess as conditions change, rather than at fixed checkpoints. So our customers spend their time deciding and acting on what matters, not assembling the evidence to get there. Hundreds of billions of dollars are spent across risk management and trust building annually. These funds are going to be reallocated to agent-native solutions in the next five years, and we will capture that spend. We've grown to seven-figure revenue within months of product launch, on the back of multi-year contracts with leading enterprises in financial services, regulated technology, and healthcare. Our founders come from Palantir and academic institutions: Oxford, Stanford, and ETH. We're backed by leading UK and US institutional investors and exceptions angels from Meta, Isomorphic Labs, Palantir, SpaceXAI, and more. We're hiring across founding-team roles for people who want outsize impact, the influence over direction and culture that comes only from joining this early, and pre-Series A equity upside. Your Impact In this role, you'll be the critical node for our platform's adoption. Once a customer signs, it's on you to make them successful. You'll expand the relationship, and turn each account into a reference customer that defines how we sell to everyone who comes after. The customers you make successful in year one become the basis of everything we build in year three. The Role As a Forward Deployed Engineer (FDE), you own our enterprise accounts end-to-end and get your hands dirty with related development. You're the first person our customers call and their trusted counterpart. You sit across the table from CSOs, VPs of Risk, heads of compliance, and you turn their messiest workflows into something that runs on our platform. Our platform is user-friendly, but we find great value in staying close to customers and understanding their needs. Expect roughly one to two customer meetings per week per account, plus the async work around it, driving adoption, configuring the platform, chasing requirements, helping decide what features to implement and implementing them, keeping things moving. You'll own a dozen plus accounts at any given time. This is the closest thing we have to a founding-team role outside the founders. You'll be partnering directly with our CTO to help shape what the company becomes. What You Will Do Own strategic accounts: adoption, expansion, renewal, the whole thing Run weekly working sessions with senior stakeholders; drive the agenda, close the loop Configure the platform to fit each customer's reality Manage the async cadence: emails, follow-ups, status updates, internal escalations Translate customer needs into prioritized product feedback that actually changes the roadmap Hold your own in procurement, security review, and contract conversations Ship code with Claude Code. When a customer needs a UI fix, a small feature, or a bug squashed, you do it. You don't need to be an engineer today, but you need to want to ship by month three. We'll teach you. You Probably Have 2-5 years of experience doing something hard and impressive Real commercial instinct: you've sold, negotiated, or owned customer outcomes in a way you can point to Comfort being the single point of accountability when something is on fire Bonus Solutions architect, deployment strategist, customer engineer, or similar background at a technical enterprise company Experience at a Series A/B enterprise startup (GRC, cyber or legal tech in particular) Background in risk, compliance, or financial services Experience in software development Culture and Values We value a diversity of perspectives and experiences. We also hold a small set of core beliefs that reflect how we operate, and share them transparently with candidates so the fit is clear from the outset. Put Customers First. Our customers buy outcomes from us, not features. We judge every decision by whether it delivers on that promise. Take Ownership. Founding-stage means problems don't come pre-scoped. You see something that needs doing, scope it, ship it, own the outcome. We expect this from everyone, and provide you the backing to execute on it. Work Hard, With Gratitude. This is the most consequential window for building enterprise software in a generation. We work hard because the opportunity is rare, and we do it with gratitude for the moment, for the people we get to build it with, and for the customers willing to bet on us this early. Say the Silly Thing. The best ideas usually start out sounding half-baked, so we'd rather you say the silly thing than sit on it. We want you opinionated and willing to argue, and just as willing to change your mind when someone makes a better case. Disagreement here is a contribution, not a risk. Working at HelmGuard Location. King's Cross, London (Gridiron building). We're built around in-person collaboration and expect most days to be in-office, with flexibility for the days that need it. Compensation. Top decile for the London market, with meaningful EMI-eligible options. Perks. Daily team lunch and specialty coffee, a roof terrace overlooking King's Cross, on-site showers for those who enjoy active commuting, and serious per-engineer AI tooling and API budgets. Tech Stack. TypeScript, Node.js, React, Tailwind, OpenAPI, Express, Azure (Container Apps, Service Bus, Front Door, Entra ID), Postgres, Terraform, GitHub Actions, Docker. Anthropic-first AI with in-house evals and scaffolding. Claude Code throughout.
11/07/2026
Full time
About HelmGuard We're building agent-native risk infrastructure: risk management and trust building, delivered by AI agents, for a world increasingly run by them. As more decisions and transactions run through agents, the volume of risk to manage and trust to establish is growing very fast. Today both functions are fragmented, split across internal teams, point products, and outside consultants, and rebuilt from scratch whenever someone needs an answer. HelmGuard brings them onto one platform and runs them continuously: our agents sit on top of proprietary data and reassess as conditions change, rather than at fixed checkpoints. So our customers spend their time deciding and acting on what matters, not assembling the evidence to get there. Hundreds of billions of dollars are spent across risk management and trust building annually. These funds are going to be reallocated to agent-native solutions in the next five years, and we will capture that spend. We've grown to seven-figure revenue within months of product launch, on the back of multi-year contracts with leading enterprises in financial services, regulated technology, and healthcare. Our founders come from Palantir and academic institutions: Oxford, Stanford, and ETH. We're backed by leading UK and US institutional investors and exceptions angels from Meta, Isomorphic Labs, Palantir, SpaceXAI, and more. We're hiring across founding-team roles for people who want outsize impact, the influence over direction and culture that comes only from joining this early, and pre-Series A equity upside. Your Impact In this role, you'll be the critical node for our platform's adoption. Once a customer signs, it's on you to make them successful. You'll expand the relationship, and turn each account into a reference customer that defines how we sell to everyone who comes after. The customers you make successful in year one become the basis of everything we build in year three. The Role As a Forward Deployed Engineer (FDE), you own our enterprise accounts end-to-end and get your hands dirty with related development. You're the first person our customers call and their trusted counterpart. You sit across the table from CSOs, VPs of Risk, heads of compliance, and you turn their messiest workflows into something that runs on our platform. Our platform is user-friendly, but we find great value in staying close to customers and understanding their needs. Expect roughly one to two customer meetings per week per account, plus the async work around it, driving adoption, configuring the platform, chasing requirements, helping decide what features to implement and implementing them, keeping things moving. You'll own a dozen plus accounts at any given time. This is the closest thing we have to a founding-team role outside the founders. You'll be partnering directly with our CTO to help shape what the company becomes. What You Will Do Own strategic accounts: adoption, expansion, renewal, the whole thing Run weekly working sessions with senior stakeholders; drive the agenda, close the loop Configure the platform to fit each customer's reality Manage the async cadence: emails, follow-ups, status updates, internal escalations Translate customer needs into prioritized product feedback that actually changes the roadmap Hold your own in procurement, security review, and contract conversations Ship code with Claude Code. When a customer needs a UI fix, a small feature, or a bug squashed, you do it. You don't need to be an engineer today, but you need to want to ship by month three. We'll teach you. You Probably Have 2-5 years of experience doing something hard and impressive Real commercial instinct: you've sold, negotiated, or owned customer outcomes in a way you can point to Comfort being the single point of accountability when something is on fire Bonus Solutions architect, deployment strategist, customer engineer, or similar background at a technical enterprise company Experience at a Series A/B enterprise startup (GRC, cyber or legal tech in particular) Background in risk, compliance, or financial services Experience in software development Culture and Values We value a diversity of perspectives and experiences. We also hold a small set of core beliefs that reflect how we operate, and share them transparently with candidates so the fit is clear from the outset. Put Customers First. Our customers buy outcomes from us, not features. We judge every decision by whether it delivers on that promise. Take Ownership. Founding-stage means problems don't come pre-scoped. You see something that needs doing, scope it, ship it, own the outcome. We expect this from everyone, and provide you the backing to execute on it. Work Hard, With Gratitude. This is the most consequential window for building enterprise software in a generation. We work hard because the opportunity is rare, and we do it with gratitude for the moment, for the people we get to build it with, and for the customers willing to bet on us this early. Say the Silly Thing. The best ideas usually start out sounding half-baked, so we'd rather you say the silly thing than sit on it. We want you opinionated and willing to argue, and just as willing to change your mind when someone makes a better case. Disagreement here is a contribution, not a risk. Working at HelmGuard Location. King's Cross, London (Gridiron building). We're built around in-person collaboration and expect most days to be in-office, with flexibility for the days that need it. Compensation. Top decile for the London market, with meaningful EMI-eligible options. Perks. Daily team lunch and specialty coffee, a roof terrace overlooking King's Cross, on-site showers for those who enjoy active commuting, and serious per-engineer AI tooling and API budgets. Tech Stack. TypeScript, Node.js, React, Tailwind, OpenAPI, Express, Azure (Container Apps, Service Bus, Front Door, Entra ID), Postgres, Terraform, GitHub Actions, Docker. Anthropic-first AI with in-house evals and scaffolding. Claude Code throughout.
Information Security GRC Engineering Consultant
PowerToFly
About Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid. At Visa, you'll have the opportunity to create impact at scale - tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world. Join Visa and do work that matters - to you, to your community, and to the world. Progress starts with you. Job Description In your role as Information Security GRC Engineering Consultant - Featurespace, you will help us achieve our goals and deliver success on behalf of our customers by: Building systems and frameworks, in line with industry standards, Visa Key Controls and customer expectations, that make compliance continuous, measurable, and low friction, moving Featurespace away from point in time, audit driven assurance toward scalable, repeatable control based implementation. Acting as a hands on, solutions driven GRC engineering consultant, translating regulatory and control requirements (PCI DSS, SOC 2, Visa KCX) into practical, implementable controls within our products, teams and cloud environments. Designing and implementing automation where it adds genuine value, including control validation, evidence collection, workflow orchestration, and compliance telemetry. Leading compliance outcomes through expertise and influence (not direct line management), working cross functionally with the product, engineering and platform teams in Featurespace, and the central Visa Cyber, Risk and Legal teams. Helping Featurespace integrate effectively into Visa's security and compliance ecosystem, ensuring centrally provided capabilities (policies, third party risk, training, tooling) are correctly applied to Featurespace products, services, and delivery models. Providing assurance to our customers by providing appropriate responses to customer RFP questions and customer audits on topics such as cybersecurity, technology operations, and compliance with standards (e.g., PCI DSS, SOC 2). Responsibilities As a company we hire people with a willingness to adapt to a variable role, so along with the key responsibilities below, we ask for ownership of any other duties as required. 1. Control Framework Ownership & Assurance Lead the implementation and ongoing operation of Featurespace's security controls framework, ensuring alignment with Visa Key Controls, PCI DSS, SOC 2, and other applicable regulatory or customer requirements, and ensuring controls are implemented in a manner appropriate to Featurespace products, services, and delivery models. Coordinate and lead Featurespace's annual certification and assurance activities (e.g. PCI DSS, SOC 2), acting as the primary point of integration between Featurespace internal teams, external auditors, and Visa central control functions, and ensuring audit activities are delivered efficiently, accurately, and on time. Ensure all processes are operating effectively and are correctly evidenced, including the maintenance of appropriate documentation, dependency mapping, and traceability to responsible teams and subject matter experts. 2. GRC Engineering, Integration & Automation Translate regulatory, compliance, and control requirements into practical, product aware implementations, working directly with engineering and platform teams to embed controls into architectures, CI/CD pipelines, cloud environments, and operating processes. Design, build, and maintain automation to support compliance activities where it adds demonstrable value, including: control validation and continuous assurance evidence collection, normalisation, and retention workflow orchestration and exception handling metrics, reporting, and compliance visibility Apply engineering judgement to determine what should be automated in the short term, what requires process or architectural maturity or redesign to be effective, and what is not suitable for automation. Ensure Featurespace teams are effectively integrated with Visa's centrally provided security and compliance capabilities, identifying when changes in Featurespace products, architectures, suppliers, customer requirements, or operating models introduce new or materially changed obligations, and ensuring the appropriate Visa processes and assessments are engaged, including: policy and standards frameworks third party risk management processes security architecture assessments security awareness and training programmes legal and commercial contracting risk management and governance tooling 3. Advisory, Enablement & Secure by Design Act as a trusted advisor and subject matter expert to Featurespace engineering, product, commercial, and leadership teams, helping stakeholders understand information security and compliance expectations and how to meet them pragmatically. Drive a secure by design and shift left mindset, ensuring compliance and assurance considerations are addressed early in delivery rather than deferred to audit windows, and facilitating the timely closure of gaps and findings identified through Visa vulnerability management and secure assessment processes. Develop and maintain repeatable patterns, reference implementations, standards, procedures, and guidance that reduce friction for delivery teams while maintaining strong assurance, consulting with and coordinating input from subject matter experts as required. 4. Risk Management, Audit & External Engagement Conduct security risk assessments and business impact analyses, and recommend appropriate control improvements to address identified risks or weaknesses. Provide oversight and assurance of corrective, preventative, or remediation activities, utilising Visa risk management tooling, working with identified application and service owners, and escalating issues at risk of missing deadlines in a timely and effective manner. Represent Information Security with customers, auditors, and internal stakeholders, particularly during assurance windows and customer security engagements. Coordinate and lead responses to customer RFP questions and security audits, ensuring responses are timely, accurate, repeatable, re usable, traceable to responsible SMEs, and supported by appropriate evidence. Support incident response and recovery activities where compliance or control effectiveness is impacted, ensuring appropriate remediation actions are taken and evidenced. Travel periodically as required for customer, company, or relevant events. This is a hybrid position. Expectation of days in office will be confirmed by your hiring manager.
07/07/2026
Full time
About Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid. At Visa, you'll have the opportunity to create impact at scale - tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world. Join Visa and do work that matters - to you, to your community, and to the world. Progress starts with you. Job Description In your role as Information Security GRC Engineering Consultant - Featurespace, you will help us achieve our goals and deliver success on behalf of our customers by: Building systems and frameworks, in line with industry standards, Visa Key Controls and customer expectations, that make compliance continuous, measurable, and low friction, moving Featurespace away from point in time, audit driven assurance toward scalable, repeatable control based implementation. Acting as a hands on, solutions driven GRC engineering consultant, translating regulatory and control requirements (PCI DSS, SOC 2, Visa KCX) into practical, implementable controls within our products, teams and cloud environments. Designing and implementing automation where it adds genuine value, including control validation, evidence collection, workflow orchestration, and compliance telemetry. Leading compliance outcomes through expertise and influence (not direct line management), working cross functionally with the product, engineering and platform teams in Featurespace, and the central Visa Cyber, Risk and Legal teams. Helping Featurespace integrate effectively into Visa's security and compliance ecosystem, ensuring centrally provided capabilities (policies, third party risk, training, tooling) are correctly applied to Featurespace products, services, and delivery models. Providing assurance to our customers by providing appropriate responses to customer RFP questions and customer audits on topics such as cybersecurity, technology operations, and compliance with standards (e.g., PCI DSS, SOC 2). Responsibilities As a company we hire people with a willingness to adapt to a variable role, so along with the key responsibilities below, we ask for ownership of any other duties as required. 1. Control Framework Ownership & Assurance Lead the implementation and ongoing operation of Featurespace's security controls framework, ensuring alignment with Visa Key Controls, PCI DSS, SOC 2, and other applicable regulatory or customer requirements, and ensuring controls are implemented in a manner appropriate to Featurespace products, services, and delivery models. Coordinate and lead Featurespace's annual certification and assurance activities (e.g. PCI DSS, SOC 2), acting as the primary point of integration between Featurespace internal teams, external auditors, and Visa central control functions, and ensuring audit activities are delivered efficiently, accurately, and on time. Ensure all processes are operating effectively and are correctly evidenced, including the maintenance of appropriate documentation, dependency mapping, and traceability to responsible teams and subject matter experts. 2. GRC Engineering, Integration & Automation Translate regulatory, compliance, and control requirements into practical, product aware implementations, working directly with engineering and platform teams to embed controls into architectures, CI/CD pipelines, cloud environments, and operating processes. Design, build, and maintain automation to support compliance activities where it adds demonstrable value, including: control validation and continuous assurance evidence collection, normalisation, and retention workflow orchestration and exception handling metrics, reporting, and compliance visibility Apply engineering judgement to determine what should be automated in the short term, what requires process or architectural maturity or redesign to be effective, and what is not suitable for automation. Ensure Featurespace teams are effectively integrated with Visa's centrally provided security and compliance capabilities, identifying when changes in Featurespace products, architectures, suppliers, customer requirements, or operating models introduce new or materially changed obligations, and ensuring the appropriate Visa processes and assessments are engaged, including: policy and standards frameworks third party risk management processes security architecture assessments security awareness and training programmes legal and commercial contracting risk management and governance tooling 3. Advisory, Enablement & Secure by Design Act as a trusted advisor and subject matter expert to Featurespace engineering, product, commercial, and leadership teams, helping stakeholders understand information security and compliance expectations and how to meet them pragmatically. Drive a secure by design and shift left mindset, ensuring compliance and assurance considerations are addressed early in delivery rather than deferred to audit windows, and facilitating the timely closure of gaps and findings identified through Visa vulnerability management and secure assessment processes. Develop and maintain repeatable patterns, reference implementations, standards, procedures, and guidance that reduce friction for delivery teams while maintaining strong assurance, consulting with and coordinating input from subject matter experts as required. 4. Risk Management, Audit & External Engagement Conduct security risk assessments and business impact analyses, and recommend appropriate control improvements to address identified risks or weaknesses. Provide oversight and assurance of corrective, preventative, or remediation activities, utilising Visa risk management tooling, working with identified application and service owners, and escalating issues at risk of missing deadlines in a timely and effective manner. Represent Information Security with customers, auditors, and internal stakeholders, particularly during assurance windows and customer security engagements. Coordinate and lead responses to customer RFP questions and security audits, ensuring responses are timely, accurate, repeatable, re usable, traceable to responsible SMEs, and supported by appropriate evidence. Support incident response and recovery activities where compliance or control effectiveness is impacted, ensuring appropriate remediation actions are taken and evidenced. Travel periodically as required for customer, company, or relevant events. This is a hybrid position. Expectation of days in office will be confirmed by your hiring manager.
Deerfoot Recruitment Solutions Limited
Senior VP - IT Infrastructure Risk and Control
Deerfoot Recruitment Solutions Limited City, London
VP Risk & Control, Technology Central London International Bank c. 120k base + bonus + good package Hybrid (3 days a week on-site) close to Moorgate tube As a long-established partner and recipient of a supplier award for our delivery into this international banking group, Deerfoot is assisting with a Senior VP Level opportunity where you can shape risk, governance and control across a major technology function. This is a unique role for a high-calibre practitioner who can bridge the gap between deep technical infrastructure environments and executive board reporting, with a clear trajectory to Director level within 12 to 24 months. This role requires a 50/50 balance between strategic evolution and hands-on execution. Acting as a trusted partner and a robust governance function, you will ensure technical risks are accurately identified and remediated while translating complex data into decision-ready insights for executive leadership. What you'll be doing Driving 50/50 strategy and delivery , working line-by-line with infrastructure Product Owners to challenge, identify, and mitigate risks while building practical end-of-life roadmaps. Governing the Digital Engineering Risk & Control framework , ensuring alignment with wider Technology risk appetite, operational resilience, BCP, and EMEA strategies. Producing high-quality board packs and executive summaries , translating detailed technical risks into concise, high-level reporting for MD-level leadership and risk committees. Partnering with Product, Platform, Cyber Security, IT Risk and Internal Audit teams to assess risks arising from new product implementations and change activities. Managing audits, assurance activity, loss events and control checks across the infrastructure estate, ensuring product teams are held to account. Operating initially as a senior individual contributor with the mandate, capability, and vision to introduce line management and scale the team as the function matures. What you'll need Substantial experience managing risk within IT infrastructure environments (covering the infrastructure stack, networks, and storage) within financial services or a similarly large, regulated estate. The technical credibility and confidence to challenge , ensuring you understand the environment well enough to robustly challenge technical teams and product owners. Exceptional stakeholder management skills , with the ability to navigate smoothly between technical floor-level details and executive-level presentations. Hands-on experience with delivery and execution in a lean team environment; this is a role for a doer who can drive solutions, not a purely advisory consultant. Familiarity with technology risk frameworks, controls, and compliance requirements relevant to a major banking infrastructure environment. Strong line management capability , with the desire to take on people management responsibilities as the team expands. Qualifications Desirable: CRISC, CISA, CISM, ITIL, or equivalent practical experience demonstrating a transition from a technical infrastructure background into risk and control. Why this role stands out This is a pivotal role with massive internal visibility, offering a direct path to a Director position within 12 to 24 months as the department continues its upward growth trajectory. If you are a senior risk professional who misses being close to the detail and wants the autonomy to evolve a function from the ground up, this role offers the perfect balance of strategic influence and tangible delivery. Candidates who have held the following roles may be interested in this vacancy: VP Technology Risk & Control, Technology Risk Director, VP IT Infrastructure Risk, Head of Technology Risk & Control, VP Technology Governance, Risk & Compliance (GRC), Head of IT Infrastructure Governance, Director of IT Infrastructure Risk & Governance, Associate Director - Technology Risk & Control, Head of Technology Controls & Assurance, Senior Technology Risk Manager, Senior IT Risk & Governance Lead, Director - Technology Risk Management, IT Risk Manager Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate 1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.
01/07/2026
Full time
VP Risk & Control, Technology Central London International Bank c. 120k base + bonus + good package Hybrid (3 days a week on-site) close to Moorgate tube As a long-established partner and recipient of a supplier award for our delivery into this international banking group, Deerfoot is assisting with a Senior VP Level opportunity where you can shape risk, governance and control across a major technology function. This is a unique role for a high-calibre practitioner who can bridge the gap between deep technical infrastructure environments and executive board reporting, with a clear trajectory to Director level within 12 to 24 months. This role requires a 50/50 balance between strategic evolution and hands-on execution. Acting as a trusted partner and a robust governance function, you will ensure technical risks are accurately identified and remediated while translating complex data into decision-ready insights for executive leadership. What you'll be doing Driving 50/50 strategy and delivery , working line-by-line with infrastructure Product Owners to challenge, identify, and mitigate risks while building practical end-of-life roadmaps. Governing the Digital Engineering Risk & Control framework , ensuring alignment with wider Technology risk appetite, operational resilience, BCP, and EMEA strategies. Producing high-quality board packs and executive summaries , translating detailed technical risks into concise, high-level reporting for MD-level leadership and risk committees. Partnering with Product, Platform, Cyber Security, IT Risk and Internal Audit teams to assess risks arising from new product implementations and change activities. Managing audits, assurance activity, loss events and control checks across the infrastructure estate, ensuring product teams are held to account. Operating initially as a senior individual contributor with the mandate, capability, and vision to introduce line management and scale the team as the function matures. What you'll need Substantial experience managing risk within IT infrastructure environments (covering the infrastructure stack, networks, and storage) within financial services or a similarly large, regulated estate. The technical credibility and confidence to challenge , ensuring you understand the environment well enough to robustly challenge technical teams and product owners. Exceptional stakeholder management skills , with the ability to navigate smoothly between technical floor-level details and executive-level presentations. Hands-on experience with delivery and execution in a lean team environment; this is a role for a doer who can drive solutions, not a purely advisory consultant. Familiarity with technology risk frameworks, controls, and compliance requirements relevant to a major banking infrastructure environment. Strong line management capability , with the desire to take on people management responsibilities as the team expands. Qualifications Desirable: CRISC, CISA, CISM, ITIL, or equivalent practical experience demonstrating a transition from a technical infrastructure background into risk and control. Why this role stands out This is a pivotal role with massive internal visibility, offering a direct path to a Director position within 12 to 24 months as the department continues its upward growth trajectory. If you are a senior risk professional who misses being close to the detail and wants the autonomy to evolve a function from the ground up, this role offers the perfect balance of strategic influence and tangible delivery. Candidates who have held the following roles may be interested in this vacancy: VP Technology Risk & Control, Technology Risk Director, VP IT Infrastructure Risk, Head of Technology Risk & Control, VP Technology Governance, Risk & Compliance (GRC), Head of IT Infrastructure Governance, Director of IT Infrastructure Risk & Governance, Associate Director - Technology Risk & Control, Head of Technology Controls & Assurance, Senior Technology Risk Manager, Senior IT Risk & Governance Lead, Director - Technology Risk Management, IT Risk Manager Deerfoot Recruitment Solutions Ltd is a leading independent tech recruitment consultancy in the UK. For every CV sent to clients, we donate 1 to The Born Free Foundation. We are a Climate Action Workforce in partnership with Ecologi. If this role isn't right for you, explore our referral reward program with payouts at interview and placement milestones. Visit our website for details. Deerfoot Recruitment Solutions Ltd is acting as an Employment Agency in relation to this vacancy.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board