SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Aug 22, 2026
Full time
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
SRT Marine Systems plc
Gloucester, Gloucestershire
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Aug 22, 2026
Full time
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Aug 22, 2026
Full time
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Vehicle allowance Company pension scheme. Professional membership fees paid. Funded continuing professional development. Support towards Chartered status and advanced qualifications. Role This is a rare opportunity to take ownership of Health, Safety, Quality, Environmental, Information Security and Corporate Compliance across a growing specialist contractor delivering complex projects throughout the UK. Reporting directly to the Directors, you will play a pivotal role in shaping the company's governance framework, strengthening their compliance culture and supporting the next phase of business growth across Defence, Government, Critical National Infrastructure and commercial sectors. This role offers far more than traditional Health & Safety management. It is an opportunity to influence strategic decision-making, modernise assurance processes and build an integrated compliance function that enables safe, secure and successful project delivery. Their teams work within some of the UK's most complex and security-sensitive environments, including Defence establishments, Government facilities, Critical National Infrastructure sites and operational commercial environments. Responsibilities You will act as the principal advisor to the Board on matters relating to: Health & Safety Corporate Governance Principal Contractor Compliance CDM Regulations Integrated Management Systems ISO Compliance Information Security Risk Management Environmental Performance Internal and External Auditing Accreditation and Certification Supply Chain Assurance Training and Competence You will work collaboratively with Directors, managers, employees, subcontractors and clients to ensure compliance is embedded into everyday decision-making and operational delivery. Key Responsibilities Strategic Leadership Lead and develop the company's Health, Safety, Quality, Environmental and Information Security strategy Provide expert advice and guidance to Directors and senior leadership teams. Promote a positive, proactive and accountable compliance culture. Ensure legal, contractual and regulatory obligations are effectively managed. Integrated Management Systems Own and continually improve the company's Integrated Management System. Lead compliance with ISO 9001, ISO 14001, ISO 45001 and ISO 27001. Ensure ongoing certification readiness and continual improvement. Health, Safety and CDM Compliance Act as the company's competent Health & Safety adviser. Support the business in delivering its duties as Principal Contractor. Provide leadership on CDM compliance across projects. Lead incident investigations, corrective actions and organisational learning initiatives. Governance, Assurance and Audit Develop and deliver risk-based audit programmes. Lead internal and external assurance activities. Manage certification bodies, client audits and compliance assessments. Produce meaningful compliance reporting and dashboards for senior leadership. Information Security and Corporate Compliance Support the development and maintenance of ISO 27001 certification. Strengthen information security, governance and business resilience arrangements. Support compliance with Defence, Government and client-specific requirements. Maintain effective corporate governance and risk management frameworks. People, Culture and Capability Oversee competence management and compliance training programmes. Develop leadership accountability across all levels of the business. Build employee engagement and ownership of compliance responsibilities. Foster a culture of continual improvement and operational excellence. Requirement You are an experienced Health, Safety and Compliance leader who combines technical expertise with commercial awareness and practical problem solving skills. You are comfortable operating at Board level whilst remaining engaged with operational delivery and project teams. You understand how robust governance, effective assurance and strong leadership can support business growth, protect reputation and improve client confidence. Experience within regulated industries such as construction, infrastructure, telecommunications, utilities, Defence or Critical National Infrastructure would be highly advantageous. Essential NEBOSH Diploma or equivalent Level 6 Health & Safety qualification. Chartered IOSH membership or demonstrable progression toward Chartered status. Significant senior level Health, Safety and Compliance leadership experience. Strong knowledge of CDM Regulations and Principal Contractor responsibilities. Experience managing Integrated Management Systems. Practical experience of ISO 9001, ISO 14001 and ISO 45001. Working knowledge of ISO 27001 and Information Security governance. Experience leading audit, compliance and assurance programmes. Strong stakeholder management and communication skills. Full UK Driving Licence and willingness to travel throughout the UK. Desirable Chartered IOSH status. Lead Auditor qualifications. Experience working within Defence or Government environments. Knowledge of UK Government Security requirements. Experience with Cyber Essentials Plus. Previous responsibility for corporate governance and business assurance functions. Experience within telecommunications, infrastructure, civil engineering or secure communications sectors. Security Clearance Current security clearance is not essential; however, candidates must be eligible and willing to undergo UK Government Security Vetting and satisfy the requirements for Developed Vetting where required by the role, project or client. You will work directly with company leadership, support major programmes within Defence and Critical National Infrastructure, and help create the governance framework that supports future growth.
Aug 22, 2026
Full time
Vehicle allowance Company pension scheme. Professional membership fees paid. Funded continuing professional development. Support towards Chartered status and advanced qualifications. Role This is a rare opportunity to take ownership of Health, Safety, Quality, Environmental, Information Security and Corporate Compliance across a growing specialist contractor delivering complex projects throughout the UK. Reporting directly to the Directors, you will play a pivotal role in shaping the company's governance framework, strengthening their compliance culture and supporting the next phase of business growth across Defence, Government, Critical National Infrastructure and commercial sectors. This role offers far more than traditional Health & Safety management. It is an opportunity to influence strategic decision-making, modernise assurance processes and build an integrated compliance function that enables safe, secure and successful project delivery. Their teams work within some of the UK's most complex and security-sensitive environments, including Defence establishments, Government facilities, Critical National Infrastructure sites and operational commercial environments. Responsibilities You will act as the principal advisor to the Board on matters relating to: Health & Safety Corporate Governance Principal Contractor Compliance CDM Regulations Integrated Management Systems ISO Compliance Information Security Risk Management Environmental Performance Internal and External Auditing Accreditation and Certification Supply Chain Assurance Training and Competence You will work collaboratively with Directors, managers, employees, subcontractors and clients to ensure compliance is embedded into everyday decision-making and operational delivery. Key Responsibilities Strategic Leadership Lead and develop the company's Health, Safety, Quality, Environmental and Information Security strategy Provide expert advice and guidance to Directors and senior leadership teams. Promote a positive, proactive and accountable compliance culture. Ensure legal, contractual and regulatory obligations are effectively managed. Integrated Management Systems Own and continually improve the company's Integrated Management System. Lead compliance with ISO 9001, ISO 14001, ISO 45001 and ISO 27001. Ensure ongoing certification readiness and continual improvement. Health, Safety and CDM Compliance Act as the company's competent Health & Safety adviser. Support the business in delivering its duties as Principal Contractor. Provide leadership on CDM compliance across projects. Lead incident investigations, corrective actions and organisational learning initiatives. Governance, Assurance and Audit Develop and deliver risk-based audit programmes. Lead internal and external assurance activities. Manage certification bodies, client audits and compliance assessments. Produce meaningful compliance reporting and dashboards for senior leadership. Information Security and Corporate Compliance Support the development and maintenance of ISO 27001 certification. Strengthen information security, governance and business resilience arrangements. Support compliance with Defence, Government and client-specific requirements. Maintain effective corporate governance and risk management frameworks. People, Culture and Capability Oversee competence management and compliance training programmes. Develop leadership accountability across all levels of the business. Build employee engagement and ownership of compliance responsibilities. Foster a culture of continual improvement and operational excellence. Requirement You are an experienced Health, Safety and Compliance leader who combines technical expertise with commercial awareness and practical problem solving skills. You are comfortable operating at Board level whilst remaining engaged with operational delivery and project teams. You understand how robust governance, effective assurance and strong leadership can support business growth, protect reputation and improve client confidence. Experience within regulated industries such as construction, infrastructure, telecommunications, utilities, Defence or Critical National Infrastructure would be highly advantageous. Essential NEBOSH Diploma or equivalent Level 6 Health & Safety qualification. Chartered IOSH membership or demonstrable progression toward Chartered status. Significant senior level Health, Safety and Compliance leadership experience. Strong knowledge of CDM Regulations and Principal Contractor responsibilities. Experience managing Integrated Management Systems. Practical experience of ISO 9001, ISO 14001 and ISO 45001. Working knowledge of ISO 27001 and Information Security governance. Experience leading audit, compliance and assurance programmes. Strong stakeholder management and communication skills. Full UK Driving Licence and willingness to travel throughout the UK. Desirable Chartered IOSH status. Lead Auditor qualifications. Experience working within Defence or Government environments. Knowledge of UK Government Security requirements. Experience with Cyber Essentials Plus. Previous responsibility for corporate governance and business assurance functions. Experience within telecommunications, infrastructure, civil engineering or secure communications sectors. Security Clearance Current security clearance is not essential; however, candidates must be eligible and willing to undergo UK Government Security Vetting and satisfy the requirements for Developed Vetting where required by the role, project or client. You will work directly with company leadership, support major programmes within Defence and Critical National Infrastructure, and help create the governance framework that supports future growth.
Information Security & Assurance Officer Salary: up to 50,000 + 15% Project Uplift + Company Car/Car Allowance Location: Suffolk (onsite) REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities. You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders. This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments and support internal and external audits Manage supplier and third-party security assurance activities Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring Work closely with SOC and security service providers to support incident management and response activities Produce security reports, dashboards and assurance documentation for senior stakeholders Deliver security awareness initiatives across the organisation Support continuous improvement of security controls, processes and governance frameworks About You We're interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier or third-party security assessments Security incident management and response processes Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms Building strong relationships with stakeholders at all levels Desirable Experience Cyber Essentials or Cyber Essentials Plus NIST Cyber Security Framework Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent What's on Offer? 15% project uplift paid monthly Company car or car allowance Annual bonus Private medical insurance Life assurance Enhanced pension contributions 25 days annual leave plus bank holidays Additional holiday purchase scheme Professional memberships paid Ongoing training and development opportunities This is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.
Aug 21, 2026
Full time
Information Security & Assurance Officer Salary: up to 50,000 + 15% Project Uplift + Company Car/Car Allowance Location: Suffolk (onsite) REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities. You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders. This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments and support internal and external audits Manage supplier and third-party security assurance activities Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring Work closely with SOC and security service providers to support incident management and response activities Produce security reports, dashboards and assurance documentation for senior stakeholders Deliver security awareness initiatives across the organisation Support continuous improvement of security controls, processes and governance frameworks About You We're interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier or third-party security assessments Security incident management and response processes Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms Building strong relationships with stakeholders at all levels Desirable Experience Cyber Essentials or Cyber Essentials Plus NIST Cyber Security Framework Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent What's on Offer? 15% project uplift paid monthly Company car or car allowance Annual bonus Private medical insurance Life assurance Enhanced pension contributions 25 days annual leave plus bank holidays Additional holiday purchase scheme Professional memberships paid Ongoing training and development opportunities This is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.
Blackstone is the world's largest alternative asset manager. We seek to create positive economic impact and long-term value for our investors, the companies we invest in, and the communities in which we work. We do this by using extraordinary people and flexible capital to help companies solve problems. Our $1.1 trillion in assets under management include investment vehicles focused on private equity, real estate, public debt and equity, infrastructure, life sciences, growth equity, opportunistic, non-investment grade credit, real assets and secondary funds, all on a global basis. Further information is available at . on and .Blackstone Internal Audit provides independent assurance to executive management and the Blackstone Audit Committee regarding the effectiveness of the Firm's governance, risk management, and internal control processes. We are seeking a highly motivated AVP to join our Technology Audit team to lead and execute risk-based audits, and serve as a key point of contact for regional technology stakeholders and audit colleagues. The role offers broad exposure across the Blackstone technology platform and exposure to key areas, including investment and asset management, risk management, operations, finance, and compliance. Key Responsibilities The BXIA AVP will drive key activities undertaken by the Technology Audit team. Responsibilities include, but are not limited to: Audit Planning & Execution: Lead risk assessment and planning processes; contribute to the design and execution of technology audit work programs; and perform risk-based audits of systems, applications, infrastructure (including cloud), and IT processes across Blackstone's global businesses. Controls Testing & Documentation: Identify and evaluate key controls, test design and operating effectiveness, document results, identify findings, and develop corrective actions that mitigate risk, drive efficiency, and add value. Integrated Audits: Partner with and guide business auditors on integrated audits - mapping IT systems and data flows to business processes, identifying technology risks and control gaps, and translating technical findings into clear business impact. Stakeholder Engagement: Build relationships with technology and business stakeholders; understand their operating and risk environments and serve as a trusted point of contact for regional technology risk matters. Innovation & Industry Awareness: Identify opportunities to drive audit efficiency through automation, AI, and data analytics; stay current with evolving technology trends, regulatory and industry developments. Departmental Initiatives: Lead and participate in department-wide strategic initiatives and special projects. Qualifications Blackstone seeks to hire individuals who are highly motivated, intelligently curious, and have demonstrated excellence in their prior endeavors. The ideal candidate will bring a genuine passion for technology, a self-starter mentality, and the drive to independently research and solve complex problems. Strong communication, project management, and attention to detail are equally as important as technical expertise. Successful candidates will demonstrate: Experienced: 7+ years in IT Audit, or technology risk, ideally within financial services or a Big Four firm. Technically Proficient: Familiarity with key technology domains (e.g., infrastructure, cybersecurity, cloud, AI) and control frameworks (e.g., NIST, ITIL, COBIT), with exposure to EMEA and/or APAC regulatory environments a plus. Curious & Self-Directed: Genuine passion for technology and a self-starter mentality; independently researches emerging trends, takes initiative, and operates with a high degree of autonomy and sound judgment. Integrity-Driven: Committed to the highest personal and professional standards. Analytically Sound: Strong problem-solving and critical thinking skills; data analytics experience a plus. Interpersonally Skilled: Exceptional communication skills, with the ability to present complex technical topics clearly and influence and engage senior stakeholders across global teams. Educated: Bachelor's or Master's degree in Computer Science, Information Systems, Finance, or a related field. CISA preferred; cloud or security certifications (e.g., CISM, CISSP, AWS, Azure) a plus.The duties and responsibilities described here are not exhaustive and additional assignments, duties, or responsibilities may be required of this position. Assignments, duties, and responsibilities may be changed at any time, with or without notice, by Blackstone in its sole discretion.Blackstone is committed to providing equal employment opportunities to all employees and applicants for employment without regard to race, color, creed, religion, sex, pregnancy, national origin, ancestry, citizenship status, age, marital or partnership status, sexual orientation, gender identity or expression, disability, genetic predisposition, veteran or military status, status as a victim of domestic violence, a sex offense or stalking, or any other class or status in accordance with applicable federal, state and local laws. This policy applies to all terms and conditions of employment, including but not limited to hiring, placement, promotion, termination, transfer, leave of absence, compensation, and training. All Blackstone employees, including but not limited to recruiting personnel and hiring managers, are required to abide by this policy.If you need a reasonable accommodation to complete your application, please contact Human Resources at (US), (0) (EMEA) or (APAC).Depending on the position, you may be required to obtain certain securities licenses if you are in a client facing role and/or if you are engaged in the following: Attending client meetings where you are discussing Blackstone products and/or and client questions; Marketing Blackstone funds to new or existing clients; Supervising or training securities licensed employees; Structuring or creating Blackstone funds/products; and Advising on marketing plans prepared by a sales team or developing and/or contributing information for marketing materials. Note: The above list is not the exhaustive list of activities requiring securities licenses and there may be roles that require review on a case-by-case basis. Please speak with your Blackstone Recruiting contact with any questions. To submit your application please complete the form below. Fields marked with a red asterisk must be completed to be considered for employment (although some can be answered "prefer not to say"). Failure to provide this information may compromise the follow-up of your application. When you have finished click Submit at the bottom of this form.
May 30, 2026
Full time
Blackstone is the world's largest alternative asset manager. We seek to create positive economic impact and long-term value for our investors, the companies we invest in, and the communities in which we work. We do this by using extraordinary people and flexible capital to help companies solve problems. Our $1.1 trillion in assets under management include investment vehicles focused on private equity, real estate, public debt and equity, infrastructure, life sciences, growth equity, opportunistic, non-investment grade credit, real assets and secondary funds, all on a global basis. Further information is available at . on and .Blackstone Internal Audit provides independent assurance to executive management and the Blackstone Audit Committee regarding the effectiveness of the Firm's governance, risk management, and internal control processes. We are seeking a highly motivated AVP to join our Technology Audit team to lead and execute risk-based audits, and serve as a key point of contact for regional technology stakeholders and audit colleagues. The role offers broad exposure across the Blackstone technology platform and exposure to key areas, including investment and asset management, risk management, operations, finance, and compliance. Key Responsibilities The BXIA AVP will drive key activities undertaken by the Technology Audit team. Responsibilities include, but are not limited to: Audit Planning & Execution: Lead risk assessment and planning processes; contribute to the design and execution of technology audit work programs; and perform risk-based audits of systems, applications, infrastructure (including cloud), and IT processes across Blackstone's global businesses. Controls Testing & Documentation: Identify and evaluate key controls, test design and operating effectiveness, document results, identify findings, and develop corrective actions that mitigate risk, drive efficiency, and add value. Integrated Audits: Partner with and guide business auditors on integrated audits - mapping IT systems and data flows to business processes, identifying technology risks and control gaps, and translating technical findings into clear business impact. Stakeholder Engagement: Build relationships with technology and business stakeholders; understand their operating and risk environments and serve as a trusted point of contact for regional technology risk matters. Innovation & Industry Awareness: Identify opportunities to drive audit efficiency through automation, AI, and data analytics; stay current with evolving technology trends, regulatory and industry developments. Departmental Initiatives: Lead and participate in department-wide strategic initiatives and special projects. Qualifications Blackstone seeks to hire individuals who are highly motivated, intelligently curious, and have demonstrated excellence in their prior endeavors. The ideal candidate will bring a genuine passion for technology, a self-starter mentality, and the drive to independently research and solve complex problems. Strong communication, project management, and attention to detail are equally as important as technical expertise. Successful candidates will demonstrate: Experienced: 7+ years in IT Audit, or technology risk, ideally within financial services or a Big Four firm. Technically Proficient: Familiarity with key technology domains (e.g., infrastructure, cybersecurity, cloud, AI) and control frameworks (e.g., NIST, ITIL, COBIT), with exposure to EMEA and/or APAC regulatory environments a plus. Curious & Self-Directed: Genuine passion for technology and a self-starter mentality; independently researches emerging trends, takes initiative, and operates with a high degree of autonomy and sound judgment. Integrity-Driven: Committed to the highest personal and professional standards. Analytically Sound: Strong problem-solving and critical thinking skills; data analytics experience a plus. Interpersonally Skilled: Exceptional communication skills, with the ability to present complex technical topics clearly and influence and engage senior stakeholders across global teams. Educated: Bachelor's or Master's degree in Computer Science, Information Systems, Finance, or a related field. CISA preferred; cloud or security certifications (e.g., CISM, CISSP, AWS, Azure) a plus.The duties and responsibilities described here are not exhaustive and additional assignments, duties, or responsibilities may be required of this position. Assignments, duties, and responsibilities may be changed at any time, with or without notice, by Blackstone in its sole discretion.Blackstone is committed to providing equal employment opportunities to all employees and applicants for employment without regard to race, color, creed, religion, sex, pregnancy, national origin, ancestry, citizenship status, age, marital or partnership status, sexual orientation, gender identity or expression, disability, genetic predisposition, veteran or military status, status as a victim of domestic violence, a sex offense or stalking, or any other class or status in accordance with applicable federal, state and local laws. This policy applies to all terms and conditions of employment, including but not limited to hiring, placement, promotion, termination, transfer, leave of absence, compensation, and training. All Blackstone employees, including but not limited to recruiting personnel and hiring managers, are required to abide by this policy.If you need a reasonable accommodation to complete your application, please contact Human Resources at (US), (0) (EMEA) or (APAC).Depending on the position, you may be required to obtain certain securities licenses if you are in a client facing role and/or if you are engaged in the following: Attending client meetings where you are discussing Blackstone products and/or and client questions; Marketing Blackstone funds to new or existing clients; Supervising or training securities licensed employees; Structuring or creating Blackstone funds/products; and Advising on marketing plans prepared by a sales team or developing and/or contributing information for marketing materials. Note: The above list is not the exhaustive list of activities requiring securities licenses and there may be roles that require review on a case-by-case basis. Please speak with your Blackstone Recruiting contact with any questions. To submit your application please complete the form below. Fields marked with a red asterisk must be completed to be considered for employment (although some can be answered "prefer not to say"). Failure to provide this information may compromise the follow-up of your application. When you have finished click Submit at the bottom of this form.
Technology Governance Lead (Risk, Compliance & Security) London Hybrid Up to £80,000 plus excellent bens We are looking for a Technology Governance Lead to drive a proactive, secure-by-default, and compliant-by-design culture across our technology organisation. Reporting to the Head of IT Transformation, this role will take ownership of technology risk, cyber governance, security oversight, and compliance assurance across platforms, delivery teams, and third-party services. This is a strategic and hands-on leadership role focused on improving governance maturity, strengthening resilience, enhancing audit outcomes, and ensuring technology risks are clearly understood, managed, and communicated across the business. The successful candidate will work closely with Engineering, Infrastructure, Product, Data, Security, and senior stakeholders to embed pragmatic governance practices that support delivery while maintaining strong control. Role & Responsibilities Technology Risk & Security Oversight Own and manage the organisation's technology risk landscape across applications, infrastructure, data, and third parties Maintain visibility of cyber risks, vulnerabilities, remediation activity, and emerging threats Ensure risks are identified, assessed, mitigated, and reported consistently Provide regular risk and governance reporting to senior leadership and governance forums Governance & Compliance Embed security, risk, and compliance controls into technology delivery processes Define and maintain governance standards, policies, and control frameworks Ensure technology changes align with internal policies and regulatory expectations Drive consistent governance practices across all technology teams Cyber Security & Resilience Oversee cyber security remediation activities and control improvements Ensure effective monitoring, incident management, and response processes are in place Support disaster recovery, resilience, and business continuity readiness Track and drive resolution of security vulnerabilities and audit findings Audit & Assurance Lead technology assurance activities including audits, internal reviews, and control testing Improve audit readiness through strong evidence management and documentation Act as the primary point of contact for technology risk, compliance, and audit matters Translate technical risks into clear business-level communication for senior stakeholders Continuous Improvement & Culture Promote a proactive risk and security culture across the organisation Embed accountability for governance, risk, and compliance across delivery teams Continuously improve governance processes to reduce friction while maintaining strong control Support awareness and education around technology risk and security best practice Skills & Experience Essential Skills Strong experience in technology governance, risk management, cyber security, or IT compliance Proven ability to implement and operate governance frameworks and control environments Experience managing technology risk across infrastructure, applications, cloud services, and third parties Strong understanding of cyber security principles, vulnerability management, and operational resilience Experience leading audits, assurance activities, and remediation programmes Ability to communicate complex technical risks clearly to senior business stakeholders Strong stakeholder management and influencing skills across technical and non-technical teams Good understanding of security and governance frameworks such as ISO 27001, NIST, COBIT, or similar Desirable Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or similar Experience supporting cloud governance and modern technology environments Exposure to enterprise transformation or technology change programmes
May 20, 2026
Full time
Technology Governance Lead (Risk, Compliance & Security) London Hybrid Up to £80,000 plus excellent bens We are looking for a Technology Governance Lead to drive a proactive, secure-by-default, and compliant-by-design culture across our technology organisation. Reporting to the Head of IT Transformation, this role will take ownership of technology risk, cyber governance, security oversight, and compliance assurance across platforms, delivery teams, and third-party services. This is a strategic and hands-on leadership role focused on improving governance maturity, strengthening resilience, enhancing audit outcomes, and ensuring technology risks are clearly understood, managed, and communicated across the business. The successful candidate will work closely with Engineering, Infrastructure, Product, Data, Security, and senior stakeholders to embed pragmatic governance practices that support delivery while maintaining strong control. Role & Responsibilities Technology Risk & Security Oversight Own and manage the organisation's technology risk landscape across applications, infrastructure, data, and third parties Maintain visibility of cyber risks, vulnerabilities, remediation activity, and emerging threats Ensure risks are identified, assessed, mitigated, and reported consistently Provide regular risk and governance reporting to senior leadership and governance forums Governance & Compliance Embed security, risk, and compliance controls into technology delivery processes Define and maintain governance standards, policies, and control frameworks Ensure technology changes align with internal policies and regulatory expectations Drive consistent governance practices across all technology teams Cyber Security & Resilience Oversee cyber security remediation activities and control improvements Ensure effective monitoring, incident management, and response processes are in place Support disaster recovery, resilience, and business continuity readiness Track and drive resolution of security vulnerabilities and audit findings Audit & Assurance Lead technology assurance activities including audits, internal reviews, and control testing Improve audit readiness through strong evidence management and documentation Act as the primary point of contact for technology risk, compliance, and audit matters Translate technical risks into clear business-level communication for senior stakeholders Continuous Improvement & Culture Promote a proactive risk and security culture across the organisation Embed accountability for governance, risk, and compliance across delivery teams Continuously improve governance processes to reduce friction while maintaining strong control Support awareness and education around technology risk and security best practice Skills & Experience Essential Skills Strong experience in technology governance, risk management, cyber security, or IT compliance Proven ability to implement and operate governance frameworks and control environments Experience managing technology risk across infrastructure, applications, cloud services, and third parties Strong understanding of cyber security principles, vulnerability management, and operational resilience Experience leading audits, assurance activities, and remediation programmes Ability to communicate complex technical risks clearly to senior business stakeholders Strong stakeholder management and influencing skills across technical and non-technical teams Good understanding of security and governance frameworks such as ISO 27001, NIST, COBIT, or similar Desirable Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or similar Experience supporting cloud governance and modern technology environments Exposure to enterprise transformation or technology change programmes
IT Auditor Location: London / Hybrid Contract: 6 months Day rate: From £550 per day (DOE) via Umbrella Company Diversity & Inclusion Commitment Our commitment is to provide equal opportunities regardless of gender, age, ethnicity, disability, sexual orientation, religion, or belief. We actively engage with employers to develop programmes and pathways that embrace diverse talent and promote inclusive employment worldwide through partnerships and other initiatives. We recognise and celebrate the value of difference and believe it makes us faster, smarter, and more innovative. Company Overview Our client is one of the largest financial institutions headquartered in Japan, with an established presence across both consumer and corporate banking globally. Through its subsidiaries and affiliates, the organisation provides a broad range of financial services, including commercial banking, leasing, securities, credit cards, consumer finance, and related services. Opportunity Overview Our client is seeking an IT Auditor to join their Internal Audit function on an initial 6-month contract . The role operates Monday to Friday during standard office hours, with occasional out-of-hours work in line with business requirements. The position follows a hybrid working model , with 2-3 days per week in the London office and the remaining time working remotely. Role Summary This role supports the delivery of independent assurance over the IT control environment across EMEA business entities. The IT Auditor will undertake and manage audits across a range of IT infrastructure and applications , support audit teams in delivering detailed testing, and contribute to audit opinions provided to EMEA Regional Management and the Group Audit Committee in Tokyo . Position Description Internal Audit provides independent opinions on the effectiveness of changes and controls implemented across the EMEA region. This role is responsible for providing insight and assurance over key controls , and therefore requires the expertise to offer advisory and consultancy input where appropriate during audit engagements. Key Responsibilities Prepare audit planning materials to ensure internal controls addressing key risks are appropriately tested, providing reasonable assurance to the Board, Group Management, Entity Management, and regulators that an effective control environment exists. Deliver control assurance activities, including testing and documentation, and at times take a lead role in managing defined areas of audit coverage . Direct testing efforts towards key risk areas, agreeing scope and focus with the Audit Partner, and share specialist knowledge with other audit team members. Prepare draft Audit Findings for review by Audit Department Management, ensuring findings are factually accurate and clearly articulated. Clearly communicate audit issues and recommendations to Audit Management and business stakeholders, including senior management, demonstrating resilience and confidence in challenging discussions. Prepare final internal audit reports , clearly highlighting areas of positive assurance as well as opportunities for improvement within the control environment. Conduct follow-up reviews and validate management actions to ensure closure of High and Moderate priority audit findings , providing guidance and support where required. The IT Auditor may also support the Audit Partner in maintaining relationships with senior management (Director, Executive Director, and Managing Director level) within assigned areas, developing insight into business activities and advising on key areas of risk. Essential Requirements Professional Experience: Experience in internal audit with a focus on IT audits within financial services or a regulated environment. Technical Knowledge: Strong understanding of IT governance frameworks (e.g. COBIT), cybersecurity principles, IT General Controls, and regulatory requirements such as DORA or GDPR . Risk & Control Expertise: Ability to assess technology risks across infrastructure, applications, and third-party services, and design effective audit procedures. Analytical Skills: Strong capability in evaluating complex technical environments, identifying control gaps, and using data analytics to support audit testing. Communication Skills: Excellent written and verbal communication skills, with the ability to explain technical issues to both technical and non-technical stakeholders. Leadership & Team Management: Proven experience leading IT audit engagements, mentoring team members, and managing competing priorities. Stakeholder Management: Ability to engage effectively with senior IT and business leaders, influence decision-making, and maintain strong professional relationships. Resilience & Professionalism: Confident handling challenge and presenting issues clearly to senior stakeholders. Additional Information Candidates must evidence the above requirements in their CV to be considered. If you do not hear from us within 48 hours , unfortunately your application has not been successful on this occasion. We may, however, retain your details for future suitable opportunities. We use generative AI tools to support our candidate screening process. This helps ensure a fair, consistent, and efficient experience for all applicants. All final hiring decisions are made by our recruitment and hiring teams following careful review.
May 18, 2026
Contractor
IT Auditor Location: London / Hybrid Contract: 6 months Day rate: From £550 per day (DOE) via Umbrella Company Diversity & Inclusion Commitment Our commitment is to provide equal opportunities regardless of gender, age, ethnicity, disability, sexual orientation, religion, or belief. We actively engage with employers to develop programmes and pathways that embrace diverse talent and promote inclusive employment worldwide through partnerships and other initiatives. We recognise and celebrate the value of difference and believe it makes us faster, smarter, and more innovative. Company Overview Our client is one of the largest financial institutions headquartered in Japan, with an established presence across both consumer and corporate banking globally. Through its subsidiaries and affiliates, the organisation provides a broad range of financial services, including commercial banking, leasing, securities, credit cards, consumer finance, and related services. Opportunity Overview Our client is seeking an IT Auditor to join their Internal Audit function on an initial 6-month contract . The role operates Monday to Friday during standard office hours, with occasional out-of-hours work in line with business requirements. The position follows a hybrid working model , with 2-3 days per week in the London office and the remaining time working remotely. Role Summary This role supports the delivery of independent assurance over the IT control environment across EMEA business entities. The IT Auditor will undertake and manage audits across a range of IT infrastructure and applications , support audit teams in delivering detailed testing, and contribute to audit opinions provided to EMEA Regional Management and the Group Audit Committee in Tokyo . Position Description Internal Audit provides independent opinions on the effectiveness of changes and controls implemented across the EMEA region. This role is responsible for providing insight and assurance over key controls , and therefore requires the expertise to offer advisory and consultancy input where appropriate during audit engagements. Key Responsibilities Prepare audit planning materials to ensure internal controls addressing key risks are appropriately tested, providing reasonable assurance to the Board, Group Management, Entity Management, and regulators that an effective control environment exists. Deliver control assurance activities, including testing and documentation, and at times take a lead role in managing defined areas of audit coverage . Direct testing efforts towards key risk areas, agreeing scope and focus with the Audit Partner, and share specialist knowledge with other audit team members. Prepare draft Audit Findings for review by Audit Department Management, ensuring findings are factually accurate and clearly articulated. Clearly communicate audit issues and recommendations to Audit Management and business stakeholders, including senior management, demonstrating resilience and confidence in challenging discussions. Prepare final internal audit reports , clearly highlighting areas of positive assurance as well as opportunities for improvement within the control environment. Conduct follow-up reviews and validate management actions to ensure closure of High and Moderate priority audit findings , providing guidance and support where required. The IT Auditor may also support the Audit Partner in maintaining relationships with senior management (Director, Executive Director, and Managing Director level) within assigned areas, developing insight into business activities and advising on key areas of risk. Essential Requirements Professional Experience: Experience in internal audit with a focus on IT audits within financial services or a regulated environment. Technical Knowledge: Strong understanding of IT governance frameworks (e.g. COBIT), cybersecurity principles, IT General Controls, and regulatory requirements such as DORA or GDPR . Risk & Control Expertise: Ability to assess technology risks across infrastructure, applications, and third-party services, and design effective audit procedures. Analytical Skills: Strong capability in evaluating complex technical environments, identifying control gaps, and using data analytics to support audit testing. Communication Skills: Excellent written and verbal communication skills, with the ability to explain technical issues to both technical and non-technical stakeholders. Leadership & Team Management: Proven experience leading IT audit engagements, mentoring team members, and managing competing priorities. Stakeholder Management: Ability to engage effectively with senior IT and business leaders, influence decision-making, and maintain strong professional relationships. Resilience & Professionalism: Confident handling challenge and presenting issues clearly to senior stakeholders. Additional Information Candidates must evidence the above requirements in their CV to be considered. If you do not hear from us within 48 hours , unfortunately your application has not been successful on this occasion. We may, however, retain your details for future suitable opportunities. We use generative AI tools to support our candidate screening process. This helps ensure a fair, consistent, and efficient experience for all applicants. All final hiring decisions are made by our recruitment and hiring teams following careful review.
Opportunity for a talented Information Security Manager / IT Manager - in a brand new role within a highly successful business to work full-time, on a 12 month fixed term contract Monday - Friday, 9am-5:30pm. Main Duties will include: Responsible for developing the data strategy alongside senior management. Responsible for imbedding data strategy and leading the implementation project. Responsible for meeting the business needs and implementation needs following agreed standards, identifying opportunities for organic growth and mutual value during engagement delivery. Responsible for maintaining consistent standards and alignment to ISO27001 (Information Security) and ISO42001 (AI) Responsible for documented framework to ensure policies align with data protection, security, and confidentiality requirements. Responsible for standardising processes, tools and documentation for all data re4lated deliverable. Responsible for Incident Management. Responsible for Business Continuity. Responsible for Monthly Management Reporting. Responsible person as the point of contact between the Commercial Business Unit in understanding the threats and opportunities within Information Security. Attending and partaking in the quarterly Risk Register meeting Responsible for daily IT operations whilst providing support for data products, platforms and projects. Lead Internal Projects - Cyber, IT, AI, IT Change Management. Lead with external auditors and regulatory bodies to uphold ISO certification standards where necessary Responsible for managing supplier relationships. Managing junior team members. Qualification, Skills and Experience required: BSc Computer Science or equivalent Information Technology Infrastructure Library or equivalent 3-5 years in IT Management Proven experience in IT infrastructures (Active Directory, Microsoft Exchange), cloud services (AWS, Azure), network security, and cybersecurity frameworks. Strong organisational skills and attention to detail Proven ability to handle confidential and sensitive information Advanced MS Office knowledge Proven problem Solving and decision-making abilities Behaviours encouraged: Professionalism & Ethics: Maintaining integrity, honesty, and taking responsibility for mistakes. Reliability & Punctuality: Being dependable, consistent in performance, and respecting time. Collaboration & Teamwork: Working well with others and offering support. Effective Communication: Being a good listener, sharing information clearly, and providing constructive feedback. Positive Attitude: Remaining professional and optimistic, even under pressure. Adaptability: Showing flexibility and willingness to learn new tasks. Respect & Courtesy: Treating colleagues, managers, and clients with respect, regardless of differing opinions. Fixed Term: 12 months
May 15, 2026
Full time
Opportunity for a talented Information Security Manager / IT Manager - in a brand new role within a highly successful business to work full-time, on a 12 month fixed term contract Monday - Friday, 9am-5:30pm. Main Duties will include: Responsible for developing the data strategy alongside senior management. Responsible for imbedding data strategy and leading the implementation project. Responsible for meeting the business needs and implementation needs following agreed standards, identifying opportunities for organic growth and mutual value during engagement delivery. Responsible for maintaining consistent standards and alignment to ISO27001 (Information Security) and ISO42001 (AI) Responsible for documented framework to ensure policies align with data protection, security, and confidentiality requirements. Responsible for standardising processes, tools and documentation for all data re4lated deliverable. Responsible for Incident Management. Responsible for Business Continuity. Responsible for Monthly Management Reporting. Responsible person as the point of contact between the Commercial Business Unit in understanding the threats and opportunities within Information Security. Attending and partaking in the quarterly Risk Register meeting Responsible for daily IT operations whilst providing support for data products, platforms and projects. Lead Internal Projects - Cyber, IT, AI, IT Change Management. Lead with external auditors and regulatory bodies to uphold ISO certification standards where necessary Responsible for managing supplier relationships. Managing junior team members. Qualification, Skills and Experience required: BSc Computer Science or equivalent Information Technology Infrastructure Library or equivalent 3-5 years in IT Management Proven experience in IT infrastructures (Active Directory, Microsoft Exchange), cloud services (AWS, Azure), network security, and cybersecurity frameworks. Strong organisational skills and attention to detail Proven ability to handle confidential and sensitive information Advanced MS Office knowledge Proven problem Solving and decision-making abilities Behaviours encouraged: Professionalism & Ethics: Maintaining integrity, honesty, and taking responsibility for mistakes. Reliability & Punctuality: Being dependable, consistent in performance, and respecting time. Collaboration & Teamwork: Working well with others and offering support. Effective Communication: Being a good listener, sharing information clearly, and providing constructive feedback. Positive Attitude: Remaining professional and optimistic, even under pressure. Adaptability: Showing flexibility and willingness to learn new tasks. Respect & Courtesy: Treating colleagues, managers, and clients with respect, regardless of differing opinions. Fixed Term: 12 months
Who we are GlobalData is a specialist information services business helping clients decode the future, make better decisions and reach more customers. Through our data, expert analysis and innovative solutions, we provide intelligence across the world s largest industries to companies, governments and industry professionals. Formed in 2016 through the combination of multiple specialist firms, we are now a fully integrated global platform with 3,500+ colleagues across 20+ industries, supporting over 5,000 customers worldwide. Why join GlobalData? We are at a pivotal stage of growth, supported by recent investment and ambitious plans. It s a fast-paced, entrepreneurial environment where collaboration drives success, and where curious, ambitious individuals can make a real impact as we work towards becoming the world s most trusted source of strategic industry intelligence. The role As Information Security Manager, you will lead the strategy and delivery of initiatives that strengthen GlobalData s cybersecurity posture across global operations. You ll ensure our people, systems and infrastructure remain secure, resilient and able to support continued growth. Reporting to the Chief Information Security Officer, you will lead a team of security professionals, drive key security programmes, and work closely with stakeholders across technology and business teams to improve cyber governance, data security and operational resilience. This role requires strong expertise in information security, AI and data governance, alongside experience in vendor management and third-party risk. What you ll be doing Lead and deliver the information security strategy aligned to business goals Develop and maintain security frameworks, policies and standards Oversee risk management, threat assessment and vulnerability programmes Ensure compliance with ISO 27001, ISO 42001, GDPR and other relevant frameworks Manage security operations including incident response, monitoring and investigations Partner with IT, engineering, legal and business teams to embed security best practice Lead internal/external audits, assessments and remediation plans Manage third-party and vendor security risk programmes Build, mentor and lead a high-performing security team Provide executive reporting on security risks, metrics and improvement plans Monitor emerging threats, technologies and regulations What we re looking for 8+ years experience in senior cybersecurity or information security roles Leadership experience within a complex, multinational business Experience managing global teams across multiple regions Strong knowledge of ISO 27001, NIST, CIS Controls or similar frameworks Proven experience in security operations, risk management and compliance Experience handling security incidents and crisis management Strong commercial awareness and budget management experience Excellent communication and stakeholder management skills, including senior leadership exposure Strong understanding of IT infrastructure, cloud technologies and enterprise systems Experience managing third-party vendors and technology partners Preferred Certifications CISM or similar ISO 27001 Lead Implementer / Lead Auditor ISO 42001 (desirable) Technical Skills Security architecture and cloud security (AWS) SIEM, EDR and SOC tools ISO 27001 / ISO 42001 implementation Vulnerability management and penetration testing oversight Data protection, encryption and privacy controls Third-party risk management tools and processes Leadership & Competencies Inspiring leader who develops teams and delegates effectively Strategic thinker with strong decision-making skills Able to influence senior stakeholders and collaborate cross-functionally Hands-on and comfortable operating at all levels Calm under pressure with strong prioritisation skills Able to translate technical risk into clear business impact Highly organised with strong attention to detail In addition to a rewarding career, we support our GlobalData colleagues with a range of benefits across health, finances, fitness, travel, tech and more. To find out more about the roles and benefits on offer in your region, visit (url removed) GlobalData believes strongly in the value of diversity and creating supportive, inclusive environments where our colleagues can succeed. As such, we are proud to be an Equal Opportunity Employer. GlobalData is determined to ensure that no applicant or employee receives less favourable treatment on the grounds of gender, age, disability, religion, belief, sexual orientation, marital status, race, or is disadvantaged by conditions or requirements which cannot be shown to be justifiable.
Apr 30, 2026
Full time
Who we are GlobalData is a specialist information services business helping clients decode the future, make better decisions and reach more customers. Through our data, expert analysis and innovative solutions, we provide intelligence across the world s largest industries to companies, governments and industry professionals. Formed in 2016 through the combination of multiple specialist firms, we are now a fully integrated global platform with 3,500+ colleagues across 20+ industries, supporting over 5,000 customers worldwide. Why join GlobalData? We are at a pivotal stage of growth, supported by recent investment and ambitious plans. It s a fast-paced, entrepreneurial environment where collaboration drives success, and where curious, ambitious individuals can make a real impact as we work towards becoming the world s most trusted source of strategic industry intelligence. The role As Information Security Manager, you will lead the strategy and delivery of initiatives that strengthen GlobalData s cybersecurity posture across global operations. You ll ensure our people, systems and infrastructure remain secure, resilient and able to support continued growth. Reporting to the Chief Information Security Officer, you will lead a team of security professionals, drive key security programmes, and work closely with stakeholders across technology and business teams to improve cyber governance, data security and operational resilience. This role requires strong expertise in information security, AI and data governance, alongside experience in vendor management and third-party risk. What you ll be doing Lead and deliver the information security strategy aligned to business goals Develop and maintain security frameworks, policies and standards Oversee risk management, threat assessment and vulnerability programmes Ensure compliance with ISO 27001, ISO 42001, GDPR and other relevant frameworks Manage security operations including incident response, monitoring and investigations Partner with IT, engineering, legal and business teams to embed security best practice Lead internal/external audits, assessments and remediation plans Manage third-party and vendor security risk programmes Build, mentor and lead a high-performing security team Provide executive reporting on security risks, metrics and improvement plans Monitor emerging threats, technologies and regulations What we re looking for 8+ years experience in senior cybersecurity or information security roles Leadership experience within a complex, multinational business Experience managing global teams across multiple regions Strong knowledge of ISO 27001, NIST, CIS Controls or similar frameworks Proven experience in security operations, risk management and compliance Experience handling security incidents and crisis management Strong commercial awareness and budget management experience Excellent communication and stakeholder management skills, including senior leadership exposure Strong understanding of IT infrastructure, cloud technologies and enterprise systems Experience managing third-party vendors and technology partners Preferred Certifications CISM or similar ISO 27001 Lead Implementer / Lead Auditor ISO 42001 (desirable) Technical Skills Security architecture and cloud security (AWS) SIEM, EDR and SOC tools ISO 27001 / ISO 42001 implementation Vulnerability management and penetration testing oversight Data protection, encryption and privacy controls Third-party risk management tools and processes Leadership & Competencies Inspiring leader who develops teams and delegates effectively Strategic thinker with strong decision-making skills Able to influence senior stakeholders and collaborate cross-functionally Hands-on and comfortable operating at all levels Calm under pressure with strong prioritisation skills Able to translate technical risk into clear business impact Highly organised with strong attention to detail In addition to a rewarding career, we support our GlobalData colleagues with a range of benefits across health, finances, fitness, travel, tech and more. To find out more about the roles and benefits on offer in your region, visit (url removed) GlobalData believes strongly in the value of diversity and creating supportive, inclusive environments where our colleagues can succeed. As such, we are proud to be an Equal Opportunity Employer. GlobalData is determined to ensure that no applicant or employee receives less favourable treatment on the grounds of gender, age, disability, religion, belief, sexual orientation, marital status, race, or is disadvantaged by conditions or requirements which cannot be shown to be justifiable.