IT Security Analyst Location: London - Remote with occasional travel to office Salary: £50,000 + Flexible Benefits Scheme Contract type: Permanent About the Role Morson Edge have partnered with a leading organisation to recruit a skilled IT Security Analyst to play a key role in protecting our clients digital infrastructure. You ll monitor security systems, analyse threats, and respond to incidents ensuring the confidentiality, integrity, and availability of information assets. Working closely with the IT Security Manager, you ll help strengthen defences, resolve security issues, and contribute to a proactive cyber-security culture. Key Responsibilities Monitor the organisation s networks and systems for potential security issues. Investigate and resolve cyber incidents promptly and effectively. Implement and manage security measures including firewalls, encryption, and endpoint protection. Maintain clear documentation of breaches, assessments, and remediation actions. Conduct vulnerability testing, penetration testing, and risk assessments. Collaborate with the IT Security Manager to identify and mitigate network vulnerabilities. Analyse logs from multiple sources to detect and respond to abnormal activity. Assist with internal and external security audits and compliance reviews. Evaluate and recommend improvements to enhance security posture. Support vendor security assessments and ensure third-party compliance with internal standards. Contribute to continuous improvement of the organisation s cyber-security framework and strategy. Skills and Experience Essential: Degree in Cyber Security, Computer Science, or equivalent experience. Proven experience within a SOC (Security Operations Centre) or NOC (Network Operations Centre). Strong understanding of incident response methodologies and the MITRE ATT&CK framework. Experience using SIEM, IDS/IPS, vulnerability scanners, and Azure security tools. Technical expertise in Microsoft Defender, EDR (Endpoint Detection and Response), and network architecture. Practical experience managing cyber incidents and implementing secure configurations. Excellent analytical and problem-solving skills, with clear documentation and communication abilities. Familiarity with NIST, ISO 27001, and CIS Controls frameworks. Ability to work under pressure, prioritise effectively, and maintain attention to detail. Desirable: Professional certifications such as GSEC, CISSP, OSCP, CISA, CompTIA Sec+, or equivalent. Knowledge of ITIL processes and cyber governance frameworks. Experience with scripting, automation, and digital forensics. Awareness of PCI DSS, SDLC, and network analysis principles. This is a great opportunity to join a leading organisation, this role is mostly remote with occasional travel to London, please note this role cannot offer sponsorship. Please apply to hear more!
12/11/2025
Full time
IT Security Analyst Location: London - Remote with occasional travel to office Salary: £50,000 + Flexible Benefits Scheme Contract type: Permanent About the Role Morson Edge have partnered with a leading organisation to recruit a skilled IT Security Analyst to play a key role in protecting our clients digital infrastructure. You ll monitor security systems, analyse threats, and respond to incidents ensuring the confidentiality, integrity, and availability of information assets. Working closely with the IT Security Manager, you ll help strengthen defences, resolve security issues, and contribute to a proactive cyber-security culture. Key Responsibilities Monitor the organisation s networks and systems for potential security issues. Investigate and resolve cyber incidents promptly and effectively. Implement and manage security measures including firewalls, encryption, and endpoint protection. Maintain clear documentation of breaches, assessments, and remediation actions. Conduct vulnerability testing, penetration testing, and risk assessments. Collaborate with the IT Security Manager to identify and mitigate network vulnerabilities. Analyse logs from multiple sources to detect and respond to abnormal activity. Assist with internal and external security audits and compliance reviews. Evaluate and recommend improvements to enhance security posture. Support vendor security assessments and ensure third-party compliance with internal standards. Contribute to continuous improvement of the organisation s cyber-security framework and strategy. Skills and Experience Essential: Degree in Cyber Security, Computer Science, or equivalent experience. Proven experience within a SOC (Security Operations Centre) or NOC (Network Operations Centre). Strong understanding of incident response methodologies and the MITRE ATT&CK framework. Experience using SIEM, IDS/IPS, vulnerability scanners, and Azure security tools. Technical expertise in Microsoft Defender, EDR (Endpoint Detection and Response), and network architecture. Practical experience managing cyber incidents and implementing secure configurations. Excellent analytical and problem-solving skills, with clear documentation and communication abilities. Familiarity with NIST, ISO 27001, and CIS Controls frameworks. Ability to work under pressure, prioritise effectively, and maintain attention to detail. Desirable: Professional certifications such as GSEC, CISSP, OSCP, CISA, CompTIA Sec+, or equivalent. Knowledge of ITIL processes and cyber governance frameworks. Experience with scripting, automation, and digital forensics. Awareness of PCI DSS, SDLC, and network analysis principles. This is a great opportunity to join a leading organisation, this role is mostly remote with occasional travel to London, please note this role cannot offer sponsorship. Please apply to hear more!
Work with top professionals, tackle dynamic risks, and deliver clear guidance that makes a real difference. If you're experienced in security frameworks like ISO27001 or NIST and want to shape security strategies in a fast-paced environment, we'd love to hear from you. My client is a leading Telecommunication Business, looking for a skilled Security Risk Manager to help strengthen their organisation's approach to information security, risk mitigation, and compliance. In this role, you'll work alongside talented teams, evaluating 3rd party supplier security, identifying threats, and implementing effective controls to keep data and assets protected. Your responsibilities will include: Conducting risk assessments and supplier due diligence across a range of projects. Communicating security risks clearly to business stakeholders so they can take informed action. Ensuring compliance with industry regulations and security standards (ISO27001, NIST, GDPR). Developing and maintaining policies, procedures, and audit practices that improve overall security posture. Responding proactively to emerging risks in a fast-changing landscape. If you have a solid background in Cyber Security and Risk Management, can explain technical topics in clear terms, and want to make a tangible impact, we want to hear from you ! Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates
11/11/2025
Full time
Work with top professionals, tackle dynamic risks, and deliver clear guidance that makes a real difference. If you're experienced in security frameworks like ISO27001 or NIST and want to shape security strategies in a fast-paced environment, we'd love to hear from you. My client is a leading Telecommunication Business, looking for a skilled Security Risk Manager to help strengthen their organisation's approach to information security, risk mitigation, and compliance. In this role, you'll work alongside talented teams, evaluating 3rd party supplier security, identifying threats, and implementing effective controls to keep data and assets protected. Your responsibilities will include: Conducting risk assessments and supplier due diligence across a range of projects. Communicating security risks clearly to business stakeholders so they can take informed action. Ensuring compliance with industry regulations and security standards (ISO27001, NIST, GDPR). Developing and maintaining policies, procedures, and audit practices that improve overall security posture. Responding proactively to emerging risks in a fast-changing landscape. If you have a solid background in Cyber Security and Risk Management, can explain technical topics in clear terms, and want to make a tangible impact, we want to hear from you ! Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates
Technical Architect 6 month contract Based in Reading Offering 108ph Inside IR35 Do you have experience with architecture frameworks (TOGAF, MODAF, NAF, etc.)? Do you have experience working in Agile/SAFe delivery environments? Do you want to work with an industry-leading company? If your answer to these is yes, then this could be the role for you! As the Technical Architect, you will be working alongside a market-leading Defence and Aerospace company who are constantly growing and developing. They are always looking to bring on new talents such as yourself and further develop your skills to enable you to grow within the company and industry. You will be involved in: Act as the technical authority for systems and services Define and evolve architectures that balance customer needs, architecture principles, and secure-by-design standards Contribute to divisional and line-of-business roadmaps, identifying opportunities for technology insertion and innovation Lead technical reviews, trade-off studies, and risk assessments for major design decisions Mentor and coach Technical Architects and Engineers, raising capability across the community Represent the company at senior customer forums, technical boards, and industry events Support business winning, including technical design, bids, and proposal development Your skillset may include: Extensive technical expertise with a proven track record of designing secure, integrated systems and services Proven experience in system and service architecture in a domain (infrastructure, applications, data, networking, cloud) Knowledge of architecture frameworks (e.g. TOGAF, MODAF, NAF) Advanced understanding of secure system design principles and cybersecurity standards Experience shaping architectures within Agile or SAFe delivery environments Ability to mentor, coach, and provide thought leadership within a technical community Industry certifications (e.g. TOGAF, ArchiMate) Vendor certifications (e.g. AWS, Azure, Cisco, VMware) Experience contributing to technology roadmaps and enterprise strategy Familiarity with service design, operational transformation, and digital modernisation Exposure to cloud-native, DevSecOps, and automation approaches If this all sounds like something you will be interested in then simply apply and we can discuss the opportunity further! Technical Architect 6 month contract Based in Reading Offering 108ph Inside IR35 Disclaimer: This vacancy is being advertised by either Advanced Resource Managers Limited, Advanced Resource Managers IT Limited or Advanced Resource Managers Engineering Limited ("ARM"). ARM is a specialist talent acquisition and management consultancy. We provide technical contingency recruitment and a portfolio of more complex resource solutions. Our specialist recruitment divisions cover the entire technical arena, including some of the most economically and strategically important industries in the UK and the world today. We will never send your CV without your permission. Where the role is marked as Outside IR35 in the advertisement this is subject to receipt of a final Status Determination Statement from the end Client and may be subject to change.
11/11/2025
Contractor
Technical Architect 6 month contract Based in Reading Offering 108ph Inside IR35 Do you have experience with architecture frameworks (TOGAF, MODAF, NAF, etc.)? Do you have experience working in Agile/SAFe delivery environments? Do you want to work with an industry-leading company? If your answer to these is yes, then this could be the role for you! As the Technical Architect, you will be working alongside a market-leading Defence and Aerospace company who are constantly growing and developing. They are always looking to bring on new talents such as yourself and further develop your skills to enable you to grow within the company and industry. You will be involved in: Act as the technical authority for systems and services Define and evolve architectures that balance customer needs, architecture principles, and secure-by-design standards Contribute to divisional and line-of-business roadmaps, identifying opportunities for technology insertion and innovation Lead technical reviews, trade-off studies, and risk assessments for major design decisions Mentor and coach Technical Architects and Engineers, raising capability across the community Represent the company at senior customer forums, technical boards, and industry events Support business winning, including technical design, bids, and proposal development Your skillset may include: Extensive technical expertise with a proven track record of designing secure, integrated systems and services Proven experience in system and service architecture in a domain (infrastructure, applications, data, networking, cloud) Knowledge of architecture frameworks (e.g. TOGAF, MODAF, NAF) Advanced understanding of secure system design principles and cybersecurity standards Experience shaping architectures within Agile or SAFe delivery environments Ability to mentor, coach, and provide thought leadership within a technical community Industry certifications (e.g. TOGAF, ArchiMate) Vendor certifications (e.g. AWS, Azure, Cisco, VMware) Experience contributing to technology roadmaps and enterprise strategy Familiarity with service design, operational transformation, and digital modernisation Exposure to cloud-native, DevSecOps, and automation approaches If this all sounds like something you will be interested in then simply apply and we can discuss the opportunity further! Technical Architect 6 month contract Based in Reading Offering 108ph Inside IR35 Disclaimer: This vacancy is being advertised by either Advanced Resource Managers Limited, Advanced Resource Managers IT Limited or Advanced Resource Managers Engineering Limited ("ARM"). ARM is a specialist talent acquisition and management consultancy. We provide technical contingency recruitment and a portfolio of more complex resource solutions. Our specialist recruitment divisions cover the entire technical arena, including some of the most economically and strategically important industries in the UK and the world today. We will never send your CV without your permission. Where the role is marked as Outside IR35 in the advertisement this is subject to receipt of a final Status Determination Statement from the end Client and may be subject to change.
Jonathan Lee Recruitment Ltd
Caldecote, Warwickshire
Technical Project Manager Are you ready to take your career to the next level with a role that combines innovation, leadership, and technical excellence? This is your chance to become a pivotal part of a growing organisation that is shaping the future of autonomous off-highway technologies. As a Technical Project Manager, you'll be at the forefront of delivering cutting-edge engineering projects, ensuring quality, cost, and time objectives are met while working on projects that make a real impact. What You Will Do as Technical Project Manager; Drive the delivery of engineering projects, focusing on embedded software and hardware integration, ensuring quality, cost, and time objectives are achieved Accurately forecast project resources, budgets, and timelines, collaborating with technical leads to allocate engineering resources effectively Prepare and maintain Work Breakdown Structures for engineering activities, ensuring seamless project execution Provide governance updates to the Programme Manager, covering budgets, timing, risks, issues, opportunities, and lessons learned Monitor and report on defect resolution and quality standards across the software team, ensuring continuous improvement Support operational assembly and testing activities for production vehicles, ensuring smooth integration of new technologies What You Will Bring as Technical Project Manager; A relevant engineering degree or equivalent with proven technical industry knowledge Proven experience in managing technical software projects, particularly in real-time and embedded systems Strong knowledge of Agile project management methods, including Kanban and Scrum Demonstrable expertise in autonomous driving technology and software development The ability to achieve SC clearance and a continuous improvement mindset As a Technical Project Manager you'll play a key role in establishing this company as the partner of choice for innovative autonomous off-highway technologies. The company is focused on delivering excellence and developing software systems that meet international safety standards and cyber-security requirements. Your contributions will directly support their mission to create advanced solutions for the global market. Location: This role is based at the company's UK headquarters in Warwickshire Interested? If you're ready to lead exciting projects and make a tangible impact in a dynamic industry, apply now to become Technical Project Manager and take the next step in your career! Your CV will be forwarded to Jonathan Lee Recruitment, a leading engineering and manufacturing recruitment consultancy established in 1978. The services advertised by Jonathan Lee Recruitment are those of an Employment Agency. In order for your CV to be processed effectively, please ensure your name, email address, phone number and location (post code OR town OR county, as a minimum) are included.
11/11/2025
Full time
Technical Project Manager Are you ready to take your career to the next level with a role that combines innovation, leadership, and technical excellence? This is your chance to become a pivotal part of a growing organisation that is shaping the future of autonomous off-highway technologies. As a Technical Project Manager, you'll be at the forefront of delivering cutting-edge engineering projects, ensuring quality, cost, and time objectives are met while working on projects that make a real impact. What You Will Do as Technical Project Manager; Drive the delivery of engineering projects, focusing on embedded software and hardware integration, ensuring quality, cost, and time objectives are achieved Accurately forecast project resources, budgets, and timelines, collaborating with technical leads to allocate engineering resources effectively Prepare and maintain Work Breakdown Structures for engineering activities, ensuring seamless project execution Provide governance updates to the Programme Manager, covering budgets, timing, risks, issues, opportunities, and lessons learned Monitor and report on defect resolution and quality standards across the software team, ensuring continuous improvement Support operational assembly and testing activities for production vehicles, ensuring smooth integration of new technologies What You Will Bring as Technical Project Manager; A relevant engineering degree or equivalent with proven technical industry knowledge Proven experience in managing technical software projects, particularly in real-time and embedded systems Strong knowledge of Agile project management methods, including Kanban and Scrum Demonstrable expertise in autonomous driving technology and software development The ability to achieve SC clearance and a continuous improvement mindset As a Technical Project Manager you'll play a key role in establishing this company as the partner of choice for innovative autonomous off-highway technologies. The company is focused on delivering excellence and developing software systems that meet international safety standards and cyber-security requirements. Your contributions will directly support their mission to create advanced solutions for the global market. Location: This role is based at the company's UK headquarters in Warwickshire Interested? If you're ready to lead exciting projects and make a tangible impact in a dynamic industry, apply now to become Technical Project Manager and take the next step in your career! Your CV will be forwarded to Jonathan Lee Recruitment, a leading engineering and manufacturing recruitment consultancy established in 1978. The services advertised by Jonathan Lee Recruitment are those of an Employment Agency. In order for your CV to be processed effectively, please ensure your name, email address, phone number and location (post code OR town OR county, as a minimum) are included.
Information Security Manager Location: Oxfordshire Salary: £48,000 - £52,000 Contract: Permanent, Full-Time Hybrid Working: 50/50 split Team size: 1 direct report (Junior InfoSec Analyst) Ready to lead the charge in safeguarding cutting-edge science? Join my client , a world-renowned research organisation, as their Information Security Manager . This is your chance to make a real impact, protecting vital data and systems while enabling groundbreaking environmental research. Why this role matters Cybersecurity isn't just about defence - it's about empowering innovation. In this hands-on leadership role, you'll shape the security strategy, mentor a talented team, and embed a culture of security across the organisation. Reporting to the Head of IT, you'll combine strategic vision with technical expertise to keep my client resilient and future-ready. What you'll do Lead my client's Information Security programme with creativity and cost-effectiveness Manage a small, dedicated team and oversee budgets Develop and maintain security policies, standards, and procedures Drive risk assessments, incident response, and internal reporting Champion security awareness through training for all staff Recommend and implement cutting-edge security technologies Communicate security goals clearly across diverse teams What we're looking for Proven experience in Information Security Management or similar Professional qualification (CISSP, CISM) or relevant degree Strong knowledge of frameworks: Cyber Essentials, GDPR, ISO27001, NIST Technical expertise in Cloud, Data Analytics, Security Technologies Experience managing security within business and tech-led projects Excellent communication skills - able to make complex concepts simple A strategic thinker who sees security as a business enabler Why join my client? You'll work alongside scientists and technologists tackling global environmental challenges. My client values excellence, integrity, and teamwork , and is committed to helping you grow professionally while making a difference.
11/11/2025
Full time
Information Security Manager Location: Oxfordshire Salary: £48,000 - £52,000 Contract: Permanent, Full-Time Hybrid Working: 50/50 split Team size: 1 direct report (Junior InfoSec Analyst) Ready to lead the charge in safeguarding cutting-edge science? Join my client , a world-renowned research organisation, as their Information Security Manager . This is your chance to make a real impact, protecting vital data and systems while enabling groundbreaking environmental research. Why this role matters Cybersecurity isn't just about defence - it's about empowering innovation. In this hands-on leadership role, you'll shape the security strategy, mentor a talented team, and embed a culture of security across the organisation. Reporting to the Head of IT, you'll combine strategic vision with technical expertise to keep my client resilient and future-ready. What you'll do Lead my client's Information Security programme with creativity and cost-effectiveness Manage a small, dedicated team and oversee budgets Develop and maintain security policies, standards, and procedures Drive risk assessments, incident response, and internal reporting Champion security awareness through training for all staff Recommend and implement cutting-edge security technologies Communicate security goals clearly across diverse teams What we're looking for Proven experience in Information Security Management or similar Professional qualification (CISSP, CISM) or relevant degree Strong knowledge of frameworks: Cyber Essentials, GDPR, ISO27001, NIST Technical expertise in Cloud, Data Analytics, Security Technologies Experience managing security within business and tech-led projects Excellent communication skills - able to make complex concepts simple A strategic thinker who sees security as a business enabler Why join my client? You'll work alongside scientists and technologists tackling global environmental challenges. My client values excellence, integrity, and teamwork , and is committed to helping you grow professionally while making a difference.
Are you a governance leader who thrives at the intersection of information security, compliance, and organisational resilience? We're looking for an experienced Senior Security Governance Manager to drive our Information Governance, Cyber Security, and Quality frameworks to new heights. This is a high-impact role where you'll shape the strategic direction of security governance across the business, ensuring compliance with UK, NHS, and international regulations - while empowering teams to work securely and confidently in a complex digital environment. What You'll Be Responsible For Information Governance Develop and execute the organisation's Information Governance (IG) strategy in line with UK, NHS, and international data protection frameworks. Maintain governance policies and key artefacts such as DPIAs, Data Processing Agreements (DPAs), and Data Sharing Agreements (DSAs). Coordinate completion of the Data Security Protection Toolkit and support independent audit processes. Monitor compliance across business units and lead corrective actions where required. Cyber Security Lead the implementation and maintenance of Cyber Security policies, ensuring robust governance across all business areas. Manage the ISO 27001 certification lifecycle - including audits, remediation, and recertification. Collaborate with technical and product teams to embed security standards and oversee incident response procedures. Drive measurable improvements in risk reduction and compliance maturity through strong audit oversight and playbook management. Digital & Clinical Safety Partner with IT, Clinical, Legal, and Executive teams to align on digital safety practices. Maintain and review Digital Clinical Safety Policies, ensuring compliance with DCB0129/0160 and the Medical Device Directive. Oversee training compliance for clinical and digital safety roles, ensuring safety case documentation remains current. Quality Management Lead the Quality Management System (QMS) aligned to ISO 9001, maintaining full documentation and audit readiness. Manage the ISO 9001 audit programme and guide remediation efforts. Support executive decision-making by maintaining clear visibility of organisational compliance. Cross-Domain Governance Administer governance committee operations, risk registers, and action logs across IG and Cyber domains. Maintain accurate and auditable records of training, compliance, and risk activities to support evidence-based reporting. Who You Are A trusted leader who sees the bigger picture and delivers with consistency. Excellent at bringing people together - building relationships across technical, clinical, and corporate teams. Someone who challenges the status quo, drives improvement, and leads change with clarity and empathy. A confident communicator who can translate complex governance data into clear, actionable insights. You Will Provide strategic direction and clear communication across teams and senior stakeholders. Use influence and negotiation to secure alignment on best practices and risk management priorities. Produce concise, impactful reports and presentations that inform key business decisions. Maintain accuracy and attention to detail in all compliance and reporting activities. Essential Experience Experience in leading Security Governance Transformation Programmes within the healthcare sector Experience in preparation for CAS Audits Proven experience in governance, risk, or compliance within a regulated or healthcare environment. Strong understanding of IG legislation, ISO Standards, Cyber frameworks, and NHS digital safety protocols. Demonstrated leadership and strategy execution within a governance or security function Strong coordination skills across technical and clinical disciplines. Experience working with SIROs, Caldicott Guardians, DPOs, and certification bodies. Knowledge of international regulatory frameworks and multi-site operations. Experience with DCB0129/0160 standards, incident management, and external inspections. Rates depend on experience and client requirements
11/11/2025
Contractor
Are you a governance leader who thrives at the intersection of information security, compliance, and organisational resilience? We're looking for an experienced Senior Security Governance Manager to drive our Information Governance, Cyber Security, and Quality frameworks to new heights. This is a high-impact role where you'll shape the strategic direction of security governance across the business, ensuring compliance with UK, NHS, and international regulations - while empowering teams to work securely and confidently in a complex digital environment. What You'll Be Responsible For Information Governance Develop and execute the organisation's Information Governance (IG) strategy in line with UK, NHS, and international data protection frameworks. Maintain governance policies and key artefacts such as DPIAs, Data Processing Agreements (DPAs), and Data Sharing Agreements (DSAs). Coordinate completion of the Data Security Protection Toolkit and support independent audit processes. Monitor compliance across business units and lead corrective actions where required. Cyber Security Lead the implementation and maintenance of Cyber Security policies, ensuring robust governance across all business areas. Manage the ISO 27001 certification lifecycle - including audits, remediation, and recertification. Collaborate with technical and product teams to embed security standards and oversee incident response procedures. Drive measurable improvements in risk reduction and compliance maturity through strong audit oversight and playbook management. Digital & Clinical Safety Partner with IT, Clinical, Legal, and Executive teams to align on digital safety practices. Maintain and review Digital Clinical Safety Policies, ensuring compliance with DCB0129/0160 and the Medical Device Directive. Oversee training compliance for clinical and digital safety roles, ensuring safety case documentation remains current. Quality Management Lead the Quality Management System (QMS) aligned to ISO 9001, maintaining full documentation and audit readiness. Manage the ISO 9001 audit programme and guide remediation efforts. Support executive decision-making by maintaining clear visibility of organisational compliance. Cross-Domain Governance Administer governance committee operations, risk registers, and action logs across IG and Cyber domains. Maintain accurate and auditable records of training, compliance, and risk activities to support evidence-based reporting. Who You Are A trusted leader who sees the bigger picture and delivers with consistency. Excellent at bringing people together - building relationships across technical, clinical, and corporate teams. Someone who challenges the status quo, drives improvement, and leads change with clarity and empathy. A confident communicator who can translate complex governance data into clear, actionable insights. You Will Provide strategic direction and clear communication across teams and senior stakeholders. Use influence and negotiation to secure alignment on best practices and risk management priorities. Produce concise, impactful reports and presentations that inform key business decisions. Maintain accuracy and attention to detail in all compliance and reporting activities. Essential Experience Experience in leading Security Governance Transformation Programmes within the healthcare sector Experience in preparation for CAS Audits Proven experience in governance, risk, or compliance within a regulated or healthcare environment. Strong understanding of IG legislation, ISO Standards, Cyber frameworks, and NHS digital safety protocols. Demonstrated leadership and strategy execution within a governance or security function Strong coordination skills across technical and clinical disciplines. Experience working with SIROs, Caldicott Guardians, DPOs, and certification bodies. Knowledge of international regulatory frameworks and multi-site operations. Experience with DCB0129/0160 standards, incident management, and external inspections. Rates depend on experience and client requirements
JOB DETAILS - 350- 400 PER DAY - INSIDE IR35 - 50/50 HYBRID ROLE BASED IN OXFORD/READING OFFICE - 3-MONTH CONTRACT SKILLS - Strong experience with cyber frameworks, e.g. Cyber Essentials, GDPR, ISO27001 and NIST. - Knowledge of enterprise security design alongside MS Security stack, AWS, MS Azure, MS Linux and ERP Solutions. - Technical understanding of Cloud, Data Analytics, Security Technologies and Application Security. RESPONSIBILITIES - Lead the Information Security programme and manage Information Security team. - Develop and maintain security policies, standards, procedures and guidance. - Provide strategic threat management, including risk assessments, incident management and internal reporting. What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now. If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
11/11/2025
Contractor
JOB DETAILS - 350- 400 PER DAY - INSIDE IR35 - 50/50 HYBRID ROLE BASED IN OXFORD/READING OFFICE - 3-MONTH CONTRACT SKILLS - Strong experience with cyber frameworks, e.g. Cyber Essentials, GDPR, ISO27001 and NIST. - Knowledge of enterprise security design alongside MS Security stack, AWS, MS Azure, MS Linux and ERP Solutions. - Technical understanding of Cloud, Data Analytics, Security Technologies and Application Security. RESPONSIBILITIES - Lead the Information Security programme and manage Information Security team. - Develop and maintain security policies, standards, procedures and guidance. - Provide strategic threat management, including risk assessments, incident management and internal reporting. What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now. If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
JOB DETAILS - £350-£400 PER DAY- INSIDE IR35- 50/50 HYBRID ROLE BASED IN OXFORD/READING OFFICE- 3-MONTH CONTRACT SKILLS - Strong experience with cyber frameworks, e.g. Cyber Essentials, GDPR, ISO27001 and NIST.- Knowledge of enterprise security design alongside MS Security stack, AWS, MS Azure, MS Linux and ERP Solutions.- Technical understanding of Cloud, Data Analytics, Security Technologies and Application Security. RESPONSIBILITIES - Lead the Information Security programme and manage Information Security team.- Develop and maintain security policies, standards, procedures and guidance.- Provide strategic threat management, including risk assessments, incident management and internal reporting. What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
11/11/2025
Contractor
JOB DETAILS - £350-£400 PER DAY- INSIDE IR35- 50/50 HYBRID ROLE BASED IN OXFORD/READING OFFICE- 3-MONTH CONTRACT SKILLS - Strong experience with cyber frameworks, e.g. Cyber Essentials, GDPR, ISO27001 and NIST.- Knowledge of enterprise security design alongside MS Security stack, AWS, MS Azure, MS Linux and ERP Solutions.- Technical understanding of Cloud, Data Analytics, Security Technologies and Application Security. RESPONSIBILITIES - Lead the Information Security programme and manage Information Security team.- Develop and maintain security policies, standards, procedures and guidance.- Provide strategic threat management, including risk assessments, incident management and internal reporting. What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
As a Control Testing Lead, you will play a key role within the Information Security team, supporting the Control Test and Assurance Manager in the delivery of a robust and forward-looking Cybersecurity Control Testing & Assurance Programme. This role requires strong cybersecurity expertise combined with hands-on experience in control testing, particularly in evaluating the effectiveness of security controls and ensuring alignment with internal policies, standards, and industry frameworks. This role will report directly to the Control Testing & Assurance Manager, with whom you will work to deliver the goals of the company to have a stable and fit-for-purpose control testing environment that supports the organisation's security and compliance objectives. What you'll be doing as a Control Testing Lead - Cyber Security Support the implementation and continuous improvement of the Cybersecurity Control Testing Framework. Execute control testing in line with defined procedures, templates, and standards. Assist in the development and localisation of standard test scripts, ensuring they are tailored to specific control environments and aligned with the organisation's Enterprise Risk Management Framework. Conduct control testing activities to evaluate the design and operational effectiveness of cybersecurity controls, documenting results clearly and raising issues where appropriate. Ensure timely delivery of assigned control assessments in accordance with the agreed testing schedule and escalation protocols. Maintain accurate and consistent documentation for each control assessment, including test plans, test results, and final reports. Escalate issues, delays, or risks to the Control Testing & Assurance Manager, contributing to the resolution of challenges and continuous improvement of the testing process. Collaborate with control owners and stakeholders to gather evidence, clarify control objectives, and support the smooth execution of testing activities. Stay informed on relevant cybersecurity frameworks (e.g., NIST CSF, CIS Controls) and industry best practices to support the evolution of the control testing programme. To thrive in this role, the essential criteria you'll need are Proven experience in performing cybersecurity control assessments, including evaluating design and operational effectiveness. Strong understanding of information security principles, cyber risk management, and control frameworks. Experience in IT, OT and Cloud environments, with a focus on cybersecurity controls. Clear and professional verbal and written communication, including the ability to explain cybersecurity issues to non-technical audiences. Ability to work independently with minimal supervision, taking ownership of assigned tasks and driving them to completion while maintaining high standards of quality and accuracy. Strong understanding of Cybersecurity Domains, including Threat Intelligence, Vulnerability Management, Security Testing, Security Architecture, Infrastructure Protection, Application Security, Identity and Access Management, Incident Investigation & Response and Cryptography. Additional skills and experiences would be great to have/bring: Experience working in a regulated environment. Experience within the water utility industry or large, complex critical national infrastructure. Experience in internal audit, external audit, or assurance functions related to IT or cybersecurity. Professional certifications such as CISA, CISSP, CRISC, or ISO 27001 Lead Auditor are advantageous. GCS is acting as an Employment Agency in relation to this vacancy.
11/11/2025
Full time
As a Control Testing Lead, you will play a key role within the Information Security team, supporting the Control Test and Assurance Manager in the delivery of a robust and forward-looking Cybersecurity Control Testing & Assurance Programme. This role requires strong cybersecurity expertise combined with hands-on experience in control testing, particularly in evaluating the effectiveness of security controls and ensuring alignment with internal policies, standards, and industry frameworks. This role will report directly to the Control Testing & Assurance Manager, with whom you will work to deliver the goals of the company to have a stable and fit-for-purpose control testing environment that supports the organisation's security and compliance objectives. What you'll be doing as a Control Testing Lead - Cyber Security Support the implementation and continuous improvement of the Cybersecurity Control Testing Framework. Execute control testing in line with defined procedures, templates, and standards. Assist in the development and localisation of standard test scripts, ensuring they are tailored to specific control environments and aligned with the organisation's Enterprise Risk Management Framework. Conduct control testing activities to evaluate the design and operational effectiveness of cybersecurity controls, documenting results clearly and raising issues where appropriate. Ensure timely delivery of assigned control assessments in accordance with the agreed testing schedule and escalation protocols. Maintain accurate and consistent documentation for each control assessment, including test plans, test results, and final reports. Escalate issues, delays, or risks to the Control Testing & Assurance Manager, contributing to the resolution of challenges and continuous improvement of the testing process. Collaborate with control owners and stakeholders to gather evidence, clarify control objectives, and support the smooth execution of testing activities. Stay informed on relevant cybersecurity frameworks (e.g., NIST CSF, CIS Controls) and industry best practices to support the evolution of the control testing programme. To thrive in this role, the essential criteria you'll need are Proven experience in performing cybersecurity control assessments, including evaluating design and operational effectiveness. Strong understanding of information security principles, cyber risk management, and control frameworks. Experience in IT, OT and Cloud environments, with a focus on cybersecurity controls. Clear and professional verbal and written communication, including the ability to explain cybersecurity issues to non-technical audiences. Ability to work independently with minimal supervision, taking ownership of assigned tasks and driving them to completion while maintaining high standards of quality and accuracy. Strong understanding of Cybersecurity Domains, including Threat Intelligence, Vulnerability Management, Security Testing, Security Architecture, Infrastructure Protection, Application Security, Identity and Access Management, Incident Investigation & Response and Cryptography. Additional skills and experiences would be great to have/bring: Experience working in a regulated environment. Experience within the water utility industry or large, complex critical national infrastructure. Experience in internal audit, external audit, or assurance functions related to IT or cybersecurity. Professional certifications such as CISA, CISSP, CRISC, or ISO 27001 Lead Auditor are advantageous. GCS is acting as an Employment Agency in relation to this vacancy.
To see more Chinese jobs please follow us on WeChat: teamchinapf AND pfteamchina Ref: 22973 The Skills You'll Need: Fluent in Mandarin, IT Infrastructure, System Administration working experience. Your New Salary: Depending on experience Office based Start: ASAP Working hours : 35 hours Mandarin Speaking IT Infrastructure Manager - What You'll be Doing: Responsible for the daily operation and maintenance of IT rooms, SAN storage, tape backup, AS400 systems, x86 platform systems, database, anti-virus systems with all supporting facilities and application systems within the department that includes but not limited to daily system monitoring and maintenance, system change management, system capacity management, data management, IT service management, incident and failure management, and emergency management Lead IT projects that includes project budgeting and planning, carrying out business requests analysis and control, proposing and reviewing technical solutions, supervising implementation process, and examining project delivery Responsible for the establishment and renewal of IT specifications related to AS400 systems, x86 platform systems, database, SAN, tape backup, anti-virus systems, IT rooms with all supporting facilities and online devices Propose implementation procedures to Management according to Head Office's policies and IT Centre's requirements Assess systems, IT rooms and IT devices security risk, proposing security risk control solutions and being responsible for execution. Responsible for the design and maintenance of contingency plans of the above systems, carrying out annual disaster recovery testing and contingency plans testing Carry out research on new technologies and products, carrying out technical solution design for the continuing development of IT Centre Mandarin Speaking IT Infrastructure Manager - The Skills You'll Need to Succeed: Degree educated in Information Technology, Computer Science, Software Engineering or other equivalent Certificate in SSCP, MCSA, RHCE, CCNP is preferred Experience in system administration (e.g. Windows Server, Linux) Experience in virtual technology products (e.g. VMware, Hyper-V) Experience in IT room and device administration Experience in project management Knowledge of principles of Information Technology Knowledge of database operations and management Knowledge of Information Security, Cyber Security and GDPR Good problem solving skills Team player Excellent English and Mandarin communication skills Please view all our Team China jobs at people-first-recruitment Please follow us on Linkedin: people-first-team-china We would be grateful if you could send your CV as a Word document. If your application is successful, you will be contacted within 7 days. We regret that due to the high volume of applications we receive we cannot provide feedback on individual CVs. Please note that we can only consider candidates who are eligible to work in the UK and are able to provide relevant supporting documentation. People First is committed to increasing diversity, and maintaining an inclusive workplace culture. We welcome applications from all qualified candidates regardless of their ethnicity, race, gender, religious beliefs, sexual orientation, age, marital status or whether or not they have a disability. People First (Recruitment) Limited acts as an employment agency for permanent and fixed term contract recruitment and as an employment business for the supply of temporary workers. Please note that by applying for this job you accept our Terms of Use and Privacy Policy which can be found on our website.
10/11/2025
Full time
To see more Chinese jobs please follow us on WeChat: teamchinapf AND pfteamchina Ref: 22973 The Skills You'll Need: Fluent in Mandarin, IT Infrastructure, System Administration working experience. Your New Salary: Depending on experience Office based Start: ASAP Working hours : 35 hours Mandarin Speaking IT Infrastructure Manager - What You'll be Doing: Responsible for the daily operation and maintenance of IT rooms, SAN storage, tape backup, AS400 systems, x86 platform systems, database, anti-virus systems with all supporting facilities and application systems within the department that includes but not limited to daily system monitoring and maintenance, system change management, system capacity management, data management, IT service management, incident and failure management, and emergency management Lead IT projects that includes project budgeting and planning, carrying out business requests analysis and control, proposing and reviewing technical solutions, supervising implementation process, and examining project delivery Responsible for the establishment and renewal of IT specifications related to AS400 systems, x86 platform systems, database, SAN, tape backup, anti-virus systems, IT rooms with all supporting facilities and online devices Propose implementation procedures to Management according to Head Office's policies and IT Centre's requirements Assess systems, IT rooms and IT devices security risk, proposing security risk control solutions and being responsible for execution. Responsible for the design and maintenance of contingency plans of the above systems, carrying out annual disaster recovery testing and contingency plans testing Carry out research on new technologies and products, carrying out technical solution design for the continuing development of IT Centre Mandarin Speaking IT Infrastructure Manager - The Skills You'll Need to Succeed: Degree educated in Information Technology, Computer Science, Software Engineering or other equivalent Certificate in SSCP, MCSA, RHCE, CCNP is preferred Experience in system administration (e.g. Windows Server, Linux) Experience in virtual technology products (e.g. VMware, Hyper-V) Experience in IT room and device administration Experience in project management Knowledge of principles of Information Technology Knowledge of database operations and management Knowledge of Information Security, Cyber Security and GDPR Good problem solving skills Team player Excellent English and Mandarin communication skills Please view all our Team China jobs at people-first-recruitment Please follow us on Linkedin: people-first-team-china We would be grateful if you could send your CV as a Word document. If your application is successful, you will be contacted within 7 days. We regret that due to the high volume of applications we receive we cannot provide feedback on individual CVs. Please note that we can only consider candidates who are eligible to work in the UK and are able to provide relevant supporting documentation. People First is committed to increasing diversity, and maintaining an inclusive workplace culture. We welcome applications from all qualified candidates regardless of their ethnicity, race, gender, religious beliefs, sexual orientation, age, marital status or whether or not they have a disability. People First (Recruitment) Limited acts as an employment agency for permanent and fixed term contract recruitment and as an employment business for the supply of temporary workers. Please note that by applying for this job you accept our Terms of Use and Privacy Policy which can be found on our website.
We are seeking an experienced IT Operations Manager to oversee the day-to-day management of our clients IT infrastructure to ensure the reliability, efficiency, and security of all systems, networks, and services. The ideal candidate will lead a team of IT professionals, manage system performance, and drive continuous improvement in IT operations aligned with business objectives. Your day to day duties as the IT Operations Manager will include, but not be limited to: Supporting the IT Director with the implementation of the firms IT and AI & Innovation Strategies Collaborate with the Innovation Manager and the Digital Adoption Team members to support innovation projects. Participate in internal and external audits, including ISO27001 and ISO22301. Manage the Cyber Essential Plus accreditation renewals. Develop and document processes and procedures, providing to ensure they are fully implemented within the team. Identify and manage operational risks Technical competencies must include: Microsoft 365 Platform, including Exchange, SharePoint, OneDrive and Office Strong technical knowledge of network and server operating system Experience with support of Windows Operating Systems, SQL Server and Active Directory, including PowerShell scripting Proven experience in server virtualisation and Cloud-based Infrastructure Enterprise Backup, Replication and Business Continuity and Disaster recover mitigation and response To find out more or have a confidential chat, please do get in touch.
10/11/2025
Full time
We are seeking an experienced IT Operations Manager to oversee the day-to-day management of our clients IT infrastructure to ensure the reliability, efficiency, and security of all systems, networks, and services. The ideal candidate will lead a team of IT professionals, manage system performance, and drive continuous improvement in IT operations aligned with business objectives. Your day to day duties as the IT Operations Manager will include, but not be limited to: Supporting the IT Director with the implementation of the firms IT and AI & Innovation Strategies Collaborate with the Innovation Manager and the Digital Adoption Team members to support innovation projects. Participate in internal and external audits, including ISO27001 and ISO22301. Manage the Cyber Essential Plus accreditation renewals. Develop and document processes and procedures, providing to ensure they are fully implemented within the team. Identify and manage operational risks Technical competencies must include: Microsoft 365 Platform, including Exchange, SharePoint, OneDrive and Office Strong technical knowledge of network and server operating system Experience with support of Windows Operating Systems, SQL Server and Active Directory, including PowerShell scripting Proven experience in server virtualisation and Cloud-based Infrastructure Enterprise Backup, Replication and Business Continuity and Disaster recover mitigation and response To find out more or have a confidential chat, please do get in touch.
Clear IT Recruitment Limited
Loughborough, Leicestershire
My client, a local government body, is seeking a Head of ICT & Data Security to join their team in Loughborough. About the Role We're looking for an experienced IT Security and Governance Manager to lead the our client's information security, cyber resilience, and ICT governance work. In this role, you'll make sure our systems, data, and networks stay secure, reliable, and compliant. You'll manage cyber and data protection risks, oversee our technical infrastructure, and ensure we meet key security standards such as ISO 27001, Cyber Essentials, PSN, and PCI-DSS. You'll also manage our client's corporate insurance function, helping ensure our policies and coverage are robust and compliant. What You'll Do • Lead the development and implementation of IT and information security policies and controls. • Oversee the cyber security posture, risk management, and incident response. • Manage compliance for Data Protection, Freedom of Information (FOI), and Subject Access Requests (SARs). • Monitor and improve the network and server infrastructure (on-premise and cloud). • Promote cyber awareness and best practice across the organisation. • Ensure successful completion of security audits and certifications (ISO 27001, Cyber Essentials, PSN, PCI-DSS). • Manage the corporate insurance service, working with governance officers and external partners. • Build strong working relationships with internal teams, senior managers, and external regulators such as the ICO. Essential skills and experience: • Experience managing a multi-disciplinary technical or IT security team. • In-depth understanding of information security, data protection, and compliance. • Strong technical knowledge of networks, infrastructure, and cloud environments. • Experience managing risk assessments, incident response, and security operations. • Excellent problem-solving, communication, and leadership skills. Desirable qualifications and experience: • CISM, CISSP, ISO 27001 Lead Implementer/Auditor, or ITIL certification. • Experience with frameworks such as PSN, PCI-DSS, NHS DSP Toolkit, or CAF. • Understanding of insurance laws and governance Should you have any questions or wish to apply please do not hesitate to contact Clear IT Recruitment Limited. Please Note: Due to the number of applications we receive we may be unable to respond to every application directly. If you have not heard from us within 3 working days please assume your application has been unsuccessful.
10/11/2025
Full time
My client, a local government body, is seeking a Head of ICT & Data Security to join their team in Loughborough. About the Role We're looking for an experienced IT Security and Governance Manager to lead the our client's information security, cyber resilience, and ICT governance work. In this role, you'll make sure our systems, data, and networks stay secure, reliable, and compliant. You'll manage cyber and data protection risks, oversee our technical infrastructure, and ensure we meet key security standards such as ISO 27001, Cyber Essentials, PSN, and PCI-DSS. You'll also manage our client's corporate insurance function, helping ensure our policies and coverage are robust and compliant. What You'll Do • Lead the development and implementation of IT and information security policies and controls. • Oversee the cyber security posture, risk management, and incident response. • Manage compliance for Data Protection, Freedom of Information (FOI), and Subject Access Requests (SARs). • Monitor and improve the network and server infrastructure (on-premise and cloud). • Promote cyber awareness and best practice across the organisation. • Ensure successful completion of security audits and certifications (ISO 27001, Cyber Essentials, PSN, PCI-DSS). • Manage the corporate insurance service, working with governance officers and external partners. • Build strong working relationships with internal teams, senior managers, and external regulators such as the ICO. Essential skills and experience: • Experience managing a multi-disciplinary technical or IT security team. • In-depth understanding of information security, data protection, and compliance. • Strong technical knowledge of networks, infrastructure, and cloud environments. • Experience managing risk assessments, incident response, and security operations. • Excellent problem-solving, communication, and leadership skills. Desirable qualifications and experience: • CISM, CISSP, ISO 27001 Lead Implementer/Auditor, or ITIL certification. • Experience with frameworks such as PSN, PCI-DSS, NHS DSP Toolkit, or CAF. • Understanding of insurance laws and governance Should you have any questions or wish to apply please do not hesitate to contact Clear IT Recruitment Limited. Please Note: Due to the number of applications we receive we may be unable to respond to every application directly. If you have not heard from us within 3 working days please assume your application has been unsuccessful.
Your New Opportunity: A leading independent research organisation is seeking an Information Security Manager to join its cross-functional IT team. This is a unique chance to shape the security landscape of an organisation whose work supports scientific discovery and environmental insight across the UK and beyond. Your Role: In this hands-on leadership position, you'll report to the Head of IT and take ownership of both strategic governance and technical delivery. You'll lead a small, dedicated team, including mentoring an Information Security Analyst currently undertaking day-release studies. Your ability to coach, guide, and inspire will be key to embedding a culture of security across the organisation.You'll collaborate with scientists, technologists, and operational teams to ensure security is not just a technical requirement, but a shared responsibility. Your structured approach to incident response and clear communication will strengthen resilience and build trust across departments. Key Responsibilities: Lead the organisation's Information Security programme, ensuring it is responsive, innovative, and cost-effective Manage a small team and oversee the security budget Develop and maintain security policies, standards, and procedures Conduct risk assessments, manage incidents, and report findings Promote security awareness across technical and non-technical teams Recommend and implement technological improvements Communicate security goals and initiatives effectively across the organisation What You'll Bring: Proven experience in a senior security, governance, or assurance role A professional qualification (e.g., CISSP, CISM) or relevant degree Strong knowledge of frameworks such as Cyber Essentials, GDPR, ISO27001, and NIST Technical expertise in Cloud, Data Analytics, Microsoft/AWS/Azure environments Experience managing change projects and influencing cross-functional teams Excellent communication and stakeholder engagement skills Why This Role: This is an ideal opportunity for someone who sees information security as a business enabler - someone who can influence behaviour, manage resistance, and advocate for controls that align with operational needs, especially in complex environments like research and academia.You'll be joining an organisation that values excellence, integrity, and collaboration, and whose work makes a real-world impact on people and the planet. What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
10/11/2025
Full time
Your New Opportunity: A leading independent research organisation is seeking an Information Security Manager to join its cross-functional IT team. This is a unique chance to shape the security landscape of an organisation whose work supports scientific discovery and environmental insight across the UK and beyond. Your Role: In this hands-on leadership position, you'll report to the Head of IT and take ownership of both strategic governance and technical delivery. You'll lead a small, dedicated team, including mentoring an Information Security Analyst currently undertaking day-release studies. Your ability to coach, guide, and inspire will be key to embedding a culture of security across the organisation.You'll collaborate with scientists, technologists, and operational teams to ensure security is not just a technical requirement, but a shared responsibility. Your structured approach to incident response and clear communication will strengthen resilience and build trust across departments. Key Responsibilities: Lead the organisation's Information Security programme, ensuring it is responsive, innovative, and cost-effective Manage a small team and oversee the security budget Develop and maintain security policies, standards, and procedures Conduct risk assessments, manage incidents, and report findings Promote security awareness across technical and non-technical teams Recommend and implement technological improvements Communicate security goals and initiatives effectively across the organisation What You'll Bring: Proven experience in a senior security, governance, or assurance role A professional qualification (e.g., CISSP, CISM) or relevant degree Strong knowledge of frameworks such as Cyber Essentials, GDPR, ISO27001, and NIST Technical expertise in Cloud, Data Analytics, Microsoft/AWS/Azure environments Experience managing change projects and influencing cross-functional teams Excellent communication and stakeholder engagement skills Why This Role: This is an ideal opportunity for someone who sees information security as a business enabler - someone who can influence behaviour, manage resistance, and advocate for controls that align with operational needs, especially in complex environments like research and academia.You'll be joining an organisation that values excellence, integrity, and collaboration, and whose work makes a real-world impact on people and the planet. What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
My client is seeking a Head of ICT & Data Security to join their team based in Loughborough, Leicestershire. About the Role My client is seeking an experienced IT Security and Governance Manager to lead the client's information security, cyber resilience, and ICT governance work. In this role, you ll make sure the systems, data, and networks stay secure, reliable, and compliant. You ll manage cyber and data protection risks, oversee our technical infrastructure, and ensure our client meets key security standards such as ISO 27001, Cyber Essentials, PSN, and PCI-DSS. You ll also manage the client's corporate insurance function, helping ensure the policies and coverage are robust and compliant. What You ll Do • Lead the development and implementation of IT and information security policies and controls. • Oversee the cyber security posture, risk management, and incident response. • Manage compliance for Data Protection, Freedom of Information (FOI), and Subject Access Requests (SARs). • Monitor and improve the network and server infrastructure (on-premise and cloud). • Promote cyber awareness and best practice across the organisation. • Ensure successful completion of security audits and certifications (ISO 27001, Cyber Essentials, PSN, PCI-DSS). • Manage the corporate insurance service, working with governance officers and external partners. • Build strong working relationships with internal teams, senior managers, and external regulators such as the ICO. Essential skills and experience: • Experience managing a multi-disciplinary technical or IT security team. • In-depth understanding of information security, data protection, and compliance. • Strong technical knowledge of networks, infrastructure, and cloud environments. • Experience managing risk assessments, incident response, and security operations. • Excellent problem-solving, communication, and leadership skills. Desirable qualifications and experience: • CISM, CISSP, ISO 27001 Lead Implementer/Auditor, or ITIL certification. • Experience with frameworks such as PSN, PCI-DSS, NHS DSP Toolkit, or CAF. • Understanding of insurance laws and governance. Should you have any questions or wish to apply please do not hesitate to contact Clear IT Recruitment Limited. Please Note: Due to the number of applications we receive we may be unable to respond to every application directly. If you have not heard from us within 3 working days please assume your application has been unsuccessful.
10/11/2025
Full time
My client is seeking a Head of ICT & Data Security to join their team based in Loughborough, Leicestershire. About the Role My client is seeking an experienced IT Security and Governance Manager to lead the client's information security, cyber resilience, and ICT governance work. In this role, you ll make sure the systems, data, and networks stay secure, reliable, and compliant. You ll manage cyber and data protection risks, oversee our technical infrastructure, and ensure our client meets key security standards such as ISO 27001, Cyber Essentials, PSN, and PCI-DSS. You ll also manage the client's corporate insurance function, helping ensure the policies and coverage are robust and compliant. What You ll Do • Lead the development and implementation of IT and information security policies and controls. • Oversee the cyber security posture, risk management, and incident response. • Manage compliance for Data Protection, Freedom of Information (FOI), and Subject Access Requests (SARs). • Monitor and improve the network and server infrastructure (on-premise and cloud). • Promote cyber awareness and best practice across the organisation. • Ensure successful completion of security audits and certifications (ISO 27001, Cyber Essentials, PSN, PCI-DSS). • Manage the corporate insurance service, working with governance officers and external partners. • Build strong working relationships with internal teams, senior managers, and external regulators such as the ICO. Essential skills and experience: • Experience managing a multi-disciplinary technical or IT security team. • In-depth understanding of information security, data protection, and compliance. • Strong technical knowledge of networks, infrastructure, and cloud environments. • Experience managing risk assessments, incident response, and security operations. • Excellent problem-solving, communication, and leadership skills. Desirable qualifications and experience: • CISM, CISSP, ISO 27001 Lead Implementer/Auditor, or ITIL certification. • Experience with frameworks such as PSN, PCI-DSS, NHS DSP Toolkit, or CAF. • Understanding of insurance laws and governance. Should you have any questions or wish to apply please do not hesitate to contact Clear IT Recruitment Limited. Please Note: Due to the number of applications we receive we may be unable to respond to every application directly. If you have not heard from us within 3 working days please assume your application has been unsuccessful.
Role: IT SecOps Engineer Contract Type: Permanent Location: Banbury / Hybrid working, 3 days in office. This role can be based out of any office on the Chiltern network Salary: Up to 58,000 per annum Closing Date: Monday 24th November 2025 There is an expectations to travel to different Chiltern sites outside of your base location to support wider colleagues and attend meetings. Job Purpose The IT Security Operations Engineer is responsible for protecting the digital services that support a safe and reliable journey for our passengers and a secure working environment for our staff. This is a hands-on role focused on strengthening our security posture through technical expertise and cross-departmental collaboration. You will report into the IT Information Security Manager with expected collaboration with the wider IT Team management, representing Digital, Data and Technology (DDaT). Key purposes of this role include: Safeguarding Operations: Actively manage and enhance our security platforms (primarily SIEM, XDR and IDAM polices) to detect, prevent, and respond to cyber threats across our IT and operational networks. Implementing and reviewing Security Controls: Serve as the subject matter expert for implementing technical security controls on applications, networks, and infrastructure to mitigate risk. Fostering Collaboration: Work closely with a wide range of internal teams, from IT colleagues to Train Engineers, to ensure security best practices are understood and integrated into their processes and systems. Key Accountabilities Threat and Vulnerability Management Develop incidence response and security measures for protection. Complete risk and exploitability assessments against vulnerabilities and live threats. Serve as a subject matter expert in vulnerability management for incident response and risk assessments. Oversee patching compliance and report/escalate vulnerabilities for remediation. Security tooling and Process Improvement Manage the deployment of new security tools, ensuring existing tools are maintained and tuned. Identify gaps, implement enhancements, and drive automation for continuous improvement. Integrate tools with SIEM, CMDB, and ticketing systems to streamline workflows. Create and update troubleshooting guides and knowledge base articles to support the wider team. Compliance and Governance Ensure practices meet known frameworks and standards including (but not restricted to): Cyber Essentials Plus, Cyber Assessment Framework, ISO 27001, and CIS. Support and participate in internal and external security audits, providing technical assurance and evidence to ensure our systems adhere to required standards. Collaboration and Mentorship Represent the function in cross-functional forums, steering committees, and stakeholder engagements. Provide mentorship to the DDaT team members, promoting a culture of continuous improvement. Person Specification Essential A background in IT infrastructure, cloud services, and cyber security. Proven continuous development in both technical and soft domains. Proficiency with security tools and technologies such as SIEM, DLP, network protection, threat detection, and endpoint protection. An understanding of network infrastructure such as VPNs, firewalls, switches, routers, LANs, Intrusion Detection, and vulnerability scanning. Understanding of IT and cyber security frameworks, standards, and regulations (examples: ISO27001, NIS2, GDPR, and CAF). Understanding of the Cyber Kill Chain and MITRE ATT&CK frameworks. Ability to collaborate effectively with various internal and external stakeholders. Relevant certifications such as Microsoft Security Operations Analyst (SC-200) or Azure Security Engineer (AZ-500), or the ability to demonstrate equivalent knowledge. Desirable Familiarity with the Microsoft security suite: Defender, InTune, Purview, EntraID, and Azure. Further certifications such as CISSP, CISM, or CRISC are advantageous Familiarity with PCI-DSS standards. Experience influencing cyber security investments and initiatives by providing expert advice to stakeholders and management. Educated to degree level or equivalent.
10/11/2025
Full time
Role: IT SecOps Engineer Contract Type: Permanent Location: Banbury / Hybrid working, 3 days in office. This role can be based out of any office on the Chiltern network Salary: Up to 58,000 per annum Closing Date: Monday 24th November 2025 There is an expectations to travel to different Chiltern sites outside of your base location to support wider colleagues and attend meetings. Job Purpose The IT Security Operations Engineer is responsible for protecting the digital services that support a safe and reliable journey for our passengers and a secure working environment for our staff. This is a hands-on role focused on strengthening our security posture through technical expertise and cross-departmental collaboration. You will report into the IT Information Security Manager with expected collaboration with the wider IT Team management, representing Digital, Data and Technology (DDaT). Key purposes of this role include: Safeguarding Operations: Actively manage and enhance our security platforms (primarily SIEM, XDR and IDAM polices) to detect, prevent, and respond to cyber threats across our IT and operational networks. Implementing and reviewing Security Controls: Serve as the subject matter expert for implementing technical security controls on applications, networks, and infrastructure to mitigate risk. Fostering Collaboration: Work closely with a wide range of internal teams, from IT colleagues to Train Engineers, to ensure security best practices are understood and integrated into their processes and systems. Key Accountabilities Threat and Vulnerability Management Develop incidence response and security measures for protection. Complete risk and exploitability assessments against vulnerabilities and live threats. Serve as a subject matter expert in vulnerability management for incident response and risk assessments. Oversee patching compliance and report/escalate vulnerabilities for remediation. Security tooling and Process Improvement Manage the deployment of new security tools, ensuring existing tools are maintained and tuned. Identify gaps, implement enhancements, and drive automation for continuous improvement. Integrate tools with SIEM, CMDB, and ticketing systems to streamline workflows. Create and update troubleshooting guides and knowledge base articles to support the wider team. Compliance and Governance Ensure practices meet known frameworks and standards including (but not restricted to): Cyber Essentials Plus, Cyber Assessment Framework, ISO 27001, and CIS. Support and participate in internal and external security audits, providing technical assurance and evidence to ensure our systems adhere to required standards. Collaboration and Mentorship Represent the function in cross-functional forums, steering committees, and stakeholder engagements. Provide mentorship to the DDaT team members, promoting a culture of continuous improvement. Person Specification Essential A background in IT infrastructure, cloud services, and cyber security. Proven continuous development in both technical and soft domains. Proficiency with security tools and technologies such as SIEM, DLP, network protection, threat detection, and endpoint protection. An understanding of network infrastructure such as VPNs, firewalls, switches, routers, LANs, Intrusion Detection, and vulnerability scanning. Understanding of IT and cyber security frameworks, standards, and regulations (examples: ISO27001, NIS2, GDPR, and CAF). Understanding of the Cyber Kill Chain and MITRE ATT&CK frameworks. Ability to collaborate effectively with various internal and external stakeholders. Relevant certifications such as Microsoft Security Operations Analyst (SC-200) or Azure Security Engineer (AZ-500), or the ability to demonstrate equivalent knowledge. Desirable Familiarity with the Microsoft security suite: Defender, InTune, Purview, EntraID, and Azure. Further certifications such as CISSP, CISM, or CRISC are advantageous Familiarity with PCI-DSS standards. Experience influencing cyber security investments and initiatives by providing expert advice to stakeholders and management. Educated to degree level or equivalent.
The organisation is a leading Managed Service Provider (MSP), recognised among Europe's top providers for its comprehensive IT services, global client support, and high industry accreditations. It specialises in IT infrastructure, cybersecurity, support, and consultancy, delivering enterprise-level solutions to mid-market and growing businesses. Due to continued growth and development, the company is seeking a Junior Account Manager to join its expanding team. Reporting to the Accounts Director, this individual will work alongside a team of experienced Account Managers, serving as the voice of the client within the organisation. The role involves championing client needs, cultivating strong relationships, and positioning the company as a trusted, long-term advisor in achieving client business goals. Key Responsibilities Technical Consultation: Understand client requirements and recommend tailored solutions with support from the pre-sales team. Client Advocacy: Act as the primary advocate for client needs within the organisation, ensuring these are prioritised effectively. Revenue and Contract Management: Drive contract renewals, identify growth opportunities, and safeguard recurring revenue through strategic account management. Service Improvement: Facilitate feedback between clients and internal teams, contributing to process improvements that enhance service delivery. Product and Service Updates: Communicate new product and service offerings to clients, providing relevant recommendations to support retention and growth. Marketing and Communication: Collaborate with the Marketing team on client communications and campaigns, such as newsletters and business updates. Business Development: Identify new business opportunities and consult with prospective clients to explore potential collaborations. Procurement Support: Work with the Procurement team to issue accurate sales orders, contracts, and proposals, and to manage invoice queries. Compliance Support: Guide clients through compliance processes such as cybersecurity accreditation and risk management documentation. Regulatory Assistance: Support GDPR compliance through contract and documentation updates. Key Objectives and Success Criteria Client Satisfaction and Retention: Maintain a client satisfaction rating of 90% or higher through proactive engagement and issue resolution. Support an annual contract renewal rate of 95%. Revenue Growth: Identify and close cross-sell opportunities, achieving a 10% annual revenue growth target. Operational Excellence: Ensure all client accounts have updated and actionable account plans. Collaborate internally to improve process efficiency and client experience. Maintain current and actionable risk registers for all clients. Technical Knowledge and Implementation: Recommend relevant technology solutions leading to at least five successful client upgrades or enhancements annually. Ensure 100% compliance with client expectations during onboarding and transitions. Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates
10/11/2025
Full time
The organisation is a leading Managed Service Provider (MSP), recognised among Europe's top providers for its comprehensive IT services, global client support, and high industry accreditations. It specialises in IT infrastructure, cybersecurity, support, and consultancy, delivering enterprise-level solutions to mid-market and growing businesses. Due to continued growth and development, the company is seeking a Junior Account Manager to join its expanding team. Reporting to the Accounts Director, this individual will work alongside a team of experienced Account Managers, serving as the voice of the client within the organisation. The role involves championing client needs, cultivating strong relationships, and positioning the company as a trusted, long-term advisor in achieving client business goals. Key Responsibilities Technical Consultation: Understand client requirements and recommend tailored solutions with support from the pre-sales team. Client Advocacy: Act as the primary advocate for client needs within the organisation, ensuring these are prioritised effectively. Revenue and Contract Management: Drive contract renewals, identify growth opportunities, and safeguard recurring revenue through strategic account management. Service Improvement: Facilitate feedback between clients and internal teams, contributing to process improvements that enhance service delivery. Product and Service Updates: Communicate new product and service offerings to clients, providing relevant recommendations to support retention and growth. Marketing and Communication: Collaborate with the Marketing team on client communications and campaigns, such as newsletters and business updates. Business Development: Identify new business opportunities and consult with prospective clients to explore potential collaborations. Procurement Support: Work with the Procurement team to issue accurate sales orders, contracts, and proposals, and to manage invoice queries. Compliance Support: Guide clients through compliance processes such as cybersecurity accreditation and risk management documentation. Regulatory Assistance: Support GDPR compliance through contract and documentation updates. Key Objectives and Success Criteria Client Satisfaction and Retention: Maintain a client satisfaction rating of 90% or higher through proactive engagement and issue resolution. Support an annual contract renewal rate of 95%. Revenue Growth: Identify and close cross-sell opportunities, achieving a 10% annual revenue growth target. Operational Excellence: Ensure all client accounts have updated and actionable account plans. Collaborate internally to improve process efficiency and client experience. Maintain current and actionable risk registers for all clients. Technical Knowledge and Implementation: Recommend relevant technology solutions leading to at least five successful client upgrades or enhancements annually. Ensure 100% compliance with client expectations during onboarding and transitions. Robert Walters Operations Limited is an employment business and employment agency and welcomes applications from all candidates
This position sits within a well-established Security Risk & Governance team, responsible for managing the organisation's information security compliance framework. The role focuses on maintaining and improving external certifications, supporting audits, and driving awareness across the business. Reporting to the Head of GRC. It's a hybrid role requiring working in Manchester office for 3 days weekly Client Details The employer is a leading technology and telecoms service provider. They are committed to delivering innovative solutions while maintaining high-security standards to support their operations. The company offers a broad portfolio of services including network, cloud, voice, and security solutions. Description Maintain and enhance compliance with multiple security standards (e.g. ISO27001, PCI, Cyber Essentials). Manage the organisation's Information Security Management System (ISMS). Lead responses to customer security questionnaires and support proposal/audit requests. Deliver internal security awareness and training programmes. Analyse emerging compliance requirements and advise on alignment strategies. Support resilience planning and external audit coordination. Contribute to NIST maturity assessments and regulatory readiness. Profile Proven experience in security compliance and stakeholder management. Strong knowledge of ISO27001, PCI DSS, and other relevant standards. Holds certifications such as ISO27001 LA/LI, PCI Implementer, and CISA Additional qualifications like CISSP, CISM, CRISC, or ISO22301 are desirable. Background in telecoms or regulated sectors is advantageous. Comfortable working across multiple projects and adapting to evolving business needs. Job Offer Discretionary bonus Private Medical Insurance Max. 6% pension contributed from employer 25 days AL plus birthday leave Hybrid working - 3 days in Manchester office
08/11/2025
Full time
This position sits within a well-established Security Risk & Governance team, responsible for managing the organisation's information security compliance framework. The role focuses on maintaining and improving external certifications, supporting audits, and driving awareness across the business. Reporting to the Head of GRC. It's a hybrid role requiring working in Manchester office for 3 days weekly Client Details The employer is a leading technology and telecoms service provider. They are committed to delivering innovative solutions while maintaining high-security standards to support their operations. The company offers a broad portfolio of services including network, cloud, voice, and security solutions. Description Maintain and enhance compliance with multiple security standards (e.g. ISO27001, PCI, Cyber Essentials). Manage the organisation's Information Security Management System (ISMS). Lead responses to customer security questionnaires and support proposal/audit requests. Deliver internal security awareness and training programmes. Analyse emerging compliance requirements and advise on alignment strategies. Support resilience planning and external audit coordination. Contribute to NIST maturity assessments and regulatory readiness. Profile Proven experience in security compliance and stakeholder management. Strong knowledge of ISO27001, PCI DSS, and other relevant standards. Holds certifications such as ISO27001 LA/LI, PCI Implementer, and CISA Additional qualifications like CISSP, CISM, CRISC, or ISO22301 are desirable. Background in telecoms or regulated sectors is advantageous. Comfortable working across multiple projects and adapting to evolving business needs. Job Offer Discretionary bonus Private Medical Insurance Max. 6% pension contributed from employer 25 days AL plus birthday leave Hybrid working - 3 days in Manchester office
This position sits within a well-established Security Risk & Governance team, responsible for managing the organisation's information security compliance framework. The role focuses on maintaining and improving external certifications, supporting audits, and driving awareness across the business. Reporting to the Head of GRC. It's a hybrid role requiring working in Manchester office for 3 days weekly Client Details The employer is a leading technology and telecoms service provider. They are committed to delivering innovative solutions while maintaining high-security standards to support their operations. The company offers a broad portfolio of services including network, cloud, voice, and security solutions. Description Maintain and enhance compliance with multiple security standards (e.g. ISO27001, PCI, Cyber Essentials). Manage the organisation's Information Security Management System (ISMS). Lead responses to customer security questionnaires and support proposal/audit requests. Deliver internal security awareness and training programmes. Analyse emerging compliance requirements and advise on alignment strategies. Support resilience planning and external audit coordination. Contribute to NIST maturity assessments and regulatory readiness. Profile Proven experience in security compliance and stakeholder management. Strong knowledge of ISO27001, PCI DSS, and other relevant standards. Holds certifications such as ISO27001 LA/LI, PCI Implementer, and CISA Additional qualifications like CISSP, CISM, CRISC, or ISO22301 are desirable. Background in telecoms or regulated sectors is advantageous. Comfortable working across multiple projects and adapting to evolving business needs. Job Offer Discretionary bonus Private Medical Insurance Max. 6% pension contributed from employer 25 days AL plus birthday leave Hybrid working - 3 days in Manchester office
07/11/2025
Full time
This position sits within a well-established Security Risk & Governance team, responsible for managing the organisation's information security compliance framework. The role focuses on maintaining and improving external certifications, supporting audits, and driving awareness across the business. Reporting to the Head of GRC. It's a hybrid role requiring working in Manchester office for 3 days weekly Client Details The employer is a leading technology and telecoms service provider. They are committed to delivering innovative solutions while maintaining high-security standards to support their operations. The company offers a broad portfolio of services including network, cloud, voice, and security solutions. Description Maintain and enhance compliance with multiple security standards (e.g. ISO27001, PCI, Cyber Essentials). Manage the organisation's Information Security Management System (ISMS). Lead responses to customer security questionnaires and support proposal/audit requests. Deliver internal security awareness and training programmes. Analyse emerging compliance requirements and advise on alignment strategies. Support resilience planning and external audit coordination. Contribute to NIST maturity assessments and regulatory readiness. Profile Proven experience in security compliance and stakeholder management. Strong knowledge of ISO27001, PCI DSS, and other relevant standards. Holds certifications such as ISO27001 LA/LI, PCI Implementer, and CISA Additional qualifications like CISSP, CISM, CRISC, or ISO22301 are desirable. Background in telecoms or regulated sectors is advantageous. Comfortable working across multiple projects and adapting to evolving business needs. Job Offer Discretionary bonus Private Medical Insurance Max. 6% pension contributed from employer 25 days AL plus birthday leave Hybrid working - 3 days in Manchester office
Business Development Manager Up to £45K + Commission 6 month FTC Fully remote - UK based We're working with a rapidly scaling cybersecurity and AI governance consultancy that helps organisations build trust, security, and resilience across their digital operations. Their specialist services span AI Governance as a Service (AIGaaS) , Virtual Data Protection Officer (vDPO) support, ISO/TISAX compliance , and digital resilience strategy . To support their next phase of growth, they're seeking a commercially driven Business Development professional to accelerate expansion across the SME and mid-market space . The Role This is a fast-paced, hands-on position where you'll own the entire sales cycle - from prospecting and qualifying to closing new business. Working closely with the Founder, Director of Marketing, and senior consultants, you'll play a pivotal role in shaping go-to-market strategy and driving revenue growth. Key Responsibilities: Identify and develop new client opportunities within target sectors (SMEs, mid-market, and select public sector organisations). Lead proactive outreach through LinkedIn, email campaigns, events, and referrals to generate high-quality conversations. Manage and update prospect and pipeline data to ensure accurate forecasting and visibility. Convert inbound and referral leads into signed revenue. Collaborate with leadership to refine propositions, messaging, and commercial offers. Provide market insights and competitive intelligence to inform strategy. About You Proven experience in business development or consultative sales , ideally within cybersecurity, compliance, or professional services . Strong relationship builder, comfortable engaging senior decision-makers. Highly self-motivated with a proactive, start-up mindset. Excellent communication, negotiation, and commercial acumen. Organised approach to pipeline management and CRM usage. Familiarity with AI governance, GDPR/data protection, and cyber risk frameworks . Understanding of ISO/TISAX/ISO 27001 or other compliance standards desirable.
07/11/2025
Full time
Business Development Manager Up to £45K + Commission 6 month FTC Fully remote - UK based We're working with a rapidly scaling cybersecurity and AI governance consultancy that helps organisations build trust, security, and resilience across their digital operations. Their specialist services span AI Governance as a Service (AIGaaS) , Virtual Data Protection Officer (vDPO) support, ISO/TISAX compliance , and digital resilience strategy . To support their next phase of growth, they're seeking a commercially driven Business Development professional to accelerate expansion across the SME and mid-market space . The Role This is a fast-paced, hands-on position where you'll own the entire sales cycle - from prospecting and qualifying to closing new business. Working closely with the Founder, Director of Marketing, and senior consultants, you'll play a pivotal role in shaping go-to-market strategy and driving revenue growth. Key Responsibilities: Identify and develop new client opportunities within target sectors (SMEs, mid-market, and select public sector organisations). Lead proactive outreach through LinkedIn, email campaigns, events, and referrals to generate high-quality conversations. Manage and update prospect and pipeline data to ensure accurate forecasting and visibility. Convert inbound and referral leads into signed revenue. Collaborate with leadership to refine propositions, messaging, and commercial offers. Provide market insights and competitive intelligence to inform strategy. About You Proven experience in business development or consultative sales , ideally within cybersecurity, compliance, or professional services . Strong relationship builder, comfortable engaging senior decision-makers. Highly self-motivated with a proactive, start-up mindset. Excellent communication, negotiation, and commercial acumen. Organised approach to pipeline management and CRM usage. Familiarity with AI governance, GDPR/data protection, and cyber risk frameworks . Understanding of ISO/TISAX/ISO 27001 or other compliance standards desirable.
Lead Cyber Security Risk Consultant - PCI-DSS - Manchester We're seeking a strong Lead Cyber Security Risk Consultant with excellent cyber security, GRC & PCI-DSS payments experience to join our client's growing Cyber Security team. They need somebody who has excellent knowledge in PCI-DSS, ideally the subject matter expert, along with good governance, risk and compliance experience You'll have a small team of GRC Specialists to do the transactional work, so we're looking for someone who is confident and can provide the PCI-DSS expertise that is needed. Experience Required: At least 5 years in a Cyber security & GRC role, at Senior, lead or manager level. Be a PCI-DSS expert around payments ISO 27001and GDPR Knowledge of Risk Management, including risk identification, assessment, and mitigation techniques Good experience around Audits and compliance Any penetration testing experience would be a bonus You'll work closely with both internal and external stakeholders across Legal, Risk & Audit, Procurement, and IT to embed strong governance and maintain alignment with leading standards such as ISO 27001, NIST CSF, and GDPR. The position combines both strategic oversight and hands-on delivery, providing clear visibility of risks and driving measurable improvements in security maturity. This role is majority onsite in Central Manchester, but there is flex on start and finish times. They have just opened their brand-new UK based headquarters in Manchester, so it is a great time to join a global company that is going from strength to strength. Responsibilities Cyber Governance & Frameworks within a PCI-DSS environment Develop, maintain, and evolve the cyber governance and compliance framework. Define and manage information and cyber security policies, standards, and procedures. Ensure alignment with ISO 27001, NIST CSF, GDPR, and other relevant regulations. Partner with internal teams to integrate governance and compliance into daily operations. Support policy reviews, updates, and communication across business units. Risk Management & Assurance Support risk identification, assessment, and treatment processes. Maintain risk registers and monitor remediation of control gaps and audit findings. Conduct risk assessments, control testing, and compliance reviews to ensure effectiveness. Prepare and deliver reports, dashboards, and metrics for management and board-level reviews. Collaborate with technical teams to address findings and continuously improve the security posture. Compliance & Third-Party Assurance Manage compliance with key UK and international standards (e.g., GDPR, NIS Regulations, DPA 2018). Coordinate internal and external audits, certifications, and customer assurance activities. Manage other GRC specialists on projects and coordinate activities. Evaluate security risks of third-party vendors, ensuring alignment with internal security requirements. Maintain documentation, evidence, and metrics to support ongoing audit readiness. Incident Response & Awareness Support the development, testing, and refinement of incident response plans. Assist with investigation and reporting of security incidents. Promote and support information security awareness and training initiatives across the organisation. Our client is looking to pay a starting salary of £70 - 85k DOE. If you're passionate about cyber governance, risk, and compliance and want to make a real impact in a collaborative and forward-thinking environment, we'd love to hear from you. Press 'Apply Now', or send your CV directly to matthew com Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter and LinkedIn - Circle Recruitment.
07/11/2025
Full time
Lead Cyber Security Risk Consultant - PCI-DSS - Manchester We're seeking a strong Lead Cyber Security Risk Consultant with excellent cyber security, GRC & PCI-DSS payments experience to join our client's growing Cyber Security team. They need somebody who has excellent knowledge in PCI-DSS, ideally the subject matter expert, along with good governance, risk and compliance experience You'll have a small team of GRC Specialists to do the transactional work, so we're looking for someone who is confident and can provide the PCI-DSS expertise that is needed. Experience Required: At least 5 years in a Cyber security & GRC role, at Senior, lead or manager level. Be a PCI-DSS expert around payments ISO 27001and GDPR Knowledge of Risk Management, including risk identification, assessment, and mitigation techniques Good experience around Audits and compliance Any penetration testing experience would be a bonus You'll work closely with both internal and external stakeholders across Legal, Risk & Audit, Procurement, and IT to embed strong governance and maintain alignment with leading standards such as ISO 27001, NIST CSF, and GDPR. The position combines both strategic oversight and hands-on delivery, providing clear visibility of risks and driving measurable improvements in security maturity. This role is majority onsite in Central Manchester, but there is flex on start and finish times. They have just opened their brand-new UK based headquarters in Manchester, so it is a great time to join a global company that is going from strength to strength. Responsibilities Cyber Governance & Frameworks within a PCI-DSS environment Develop, maintain, and evolve the cyber governance and compliance framework. Define and manage information and cyber security policies, standards, and procedures. Ensure alignment with ISO 27001, NIST CSF, GDPR, and other relevant regulations. Partner with internal teams to integrate governance and compliance into daily operations. Support policy reviews, updates, and communication across business units. Risk Management & Assurance Support risk identification, assessment, and treatment processes. Maintain risk registers and monitor remediation of control gaps and audit findings. Conduct risk assessments, control testing, and compliance reviews to ensure effectiveness. Prepare and deliver reports, dashboards, and metrics for management and board-level reviews. Collaborate with technical teams to address findings and continuously improve the security posture. Compliance & Third-Party Assurance Manage compliance with key UK and international standards (e.g., GDPR, NIS Regulations, DPA 2018). Coordinate internal and external audits, certifications, and customer assurance activities. Manage other GRC specialists on projects and coordinate activities. Evaluate security risks of third-party vendors, ensuring alignment with internal security requirements. Maintain documentation, evidence, and metrics to support ongoing audit readiness. Incident Response & Awareness Support the development, testing, and refinement of incident response plans. Assist with investigation and reporting of security incidents. Promote and support information security awareness and training initiatives across the organisation. Our client is looking to pay a starting salary of £70 - 85k DOE. If you're passionate about cyber governance, risk, and compliance and want to make a real impact in a collaborative and forward-thinking environment, we'd love to hear from you. Press 'Apply Now', or send your CV directly to matthew com Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter and LinkedIn - Circle Recruitment.
Jobs - Frequently Asked Questions
Use the location filter to find IT jobs in cities like London, Manchester, Birmingham, and across the UK.
Entry-level roles include IT support technician, junior developer, QA tester, and helpdesk analyst.
New jobs are posted daily. Set up alerts to be notified as soon as new roles match your preferences.
Key skills include problem-solving, coding, cloud computing, networking, and familiarity with tools like AWS or SQL.
Yes, many employers offer training or junior roles. Focus on building a strong CV with relevant coursework or personal projects.