Business Development Manager - Cyber Security St Albans (Hybrid Working) £40,000 - £50,000 Basic + Uncapped Commission Full Time Permanent Ready to Build Your Career in Cyber Security Sales? This isn't a role where you'll inherit a portfolio of existing accounts and simply manage relationships. This is an opportunity for ambitious sales professionals who enjoy creating opportunities, winning new business and building long-term client relationships within one of the UK's fastest-growing technology sectors. If you're motivated by prospecting, opening new doors and being rewarded for your success, we'd love to hear from you. The Role We're looking for two New Business Development Managers to join a growing cyber security consultancy. You'll be responsible for identifying and winning new customers, developing your own sales pipeline and becoming a trusted advisor to organisations looking to strengthen their cyber security posture. With the support of experienced technical consultants, marketing and leading cyber security vendors, you'll have everything you need to succeed-except a list of existing accounts. This is a genuine new business sales role . What You'll Be Selling You'll represent a portfolio of industry-leading cyber security solutions including: Managed Security Services Microsoft Security Solutions Vulnerability Management CrowdStrike Qualys AppCheck Email Security Penetration Testing Security Assessments Governance, Risk & Compliance (GRC) Cyber Security Advisory Services Typical deal values range from £20,000 to £750,000+ , with many customers choosing long-term managed service agreements. Key Responsibilities Generate and qualify new business opportunities. Build relationships with CIOs, CISOs, IT Directors and senior decision-makers. Conduct discovery meetings to understand customer challenges. Develop tailored commercial proposals alongside technical specialists. Negotiate and close new business opportunities. Build and manage a healthy sales pipeline. Become a trusted advisor within your customer base. About You We're looking for driven, commercially minded sales professionals who enjoy winning new business and building relationships. Ideally you'll have: At least 2 years' experience in B2B technology sales. A genuine passion for new business development. Experience selling Cyber Security, Cloud, SaaS, IT Services or Managed Services (desirable but not essential). Excellent communication, negotiation and presentation skills. Strong commercial awareness. A resilient, proactive and self-motivated approach. A genuine hunter mentality with a desire to exceed targets. You'll Enjoy This Role If You Love winning new business. Thrive on prospecting and opening new doors. Enjoy building relationships from scratch. Want autonomy and ownership. Are ambitious and motivated by uncapped earnings. Want to build a long-term career within cyber security sales. What's On Offer? Competitive basic salary of £40,000-£50,000 + Uncapped commission with excellent earning potential. Hybrid working. Defined sales territory. Technical pre-sales support. Marketing support to help generate opportunities. Access to market-leading cyber security vendors. Genuine career progression within a growing business. Supportive, collaborative and ambitious team culture. Apply Today If you're an ambitious sales professional looking to develop your career within the rapidly growing cyber security market, we'd love to hear from you. This is your opportunity to join a business where success is recognised, hard work is rewarded and your career progression is in your hands.
Jul 20, 2026
Full time
Business Development Manager - Cyber Security St Albans (Hybrid Working) £40,000 - £50,000 Basic + Uncapped Commission Full Time Permanent Ready to Build Your Career in Cyber Security Sales? This isn't a role where you'll inherit a portfolio of existing accounts and simply manage relationships. This is an opportunity for ambitious sales professionals who enjoy creating opportunities, winning new business and building long-term client relationships within one of the UK's fastest-growing technology sectors. If you're motivated by prospecting, opening new doors and being rewarded for your success, we'd love to hear from you. The Role We're looking for two New Business Development Managers to join a growing cyber security consultancy. You'll be responsible for identifying and winning new customers, developing your own sales pipeline and becoming a trusted advisor to organisations looking to strengthen their cyber security posture. With the support of experienced technical consultants, marketing and leading cyber security vendors, you'll have everything you need to succeed-except a list of existing accounts. This is a genuine new business sales role . What You'll Be Selling You'll represent a portfolio of industry-leading cyber security solutions including: Managed Security Services Microsoft Security Solutions Vulnerability Management CrowdStrike Qualys AppCheck Email Security Penetration Testing Security Assessments Governance, Risk & Compliance (GRC) Cyber Security Advisory Services Typical deal values range from £20,000 to £750,000+ , with many customers choosing long-term managed service agreements. Key Responsibilities Generate and qualify new business opportunities. Build relationships with CIOs, CISOs, IT Directors and senior decision-makers. Conduct discovery meetings to understand customer challenges. Develop tailored commercial proposals alongside technical specialists. Negotiate and close new business opportunities. Build and manage a healthy sales pipeline. Become a trusted advisor within your customer base. About You We're looking for driven, commercially minded sales professionals who enjoy winning new business and building relationships. Ideally you'll have: At least 2 years' experience in B2B technology sales. A genuine passion for new business development. Experience selling Cyber Security, Cloud, SaaS, IT Services or Managed Services (desirable but not essential). Excellent communication, negotiation and presentation skills. Strong commercial awareness. A resilient, proactive and self-motivated approach. A genuine hunter mentality with a desire to exceed targets. You'll Enjoy This Role If You Love winning new business. Thrive on prospecting and opening new doors. Enjoy building relationships from scratch. Want autonomy and ownership. Are ambitious and motivated by uncapped earnings. Want to build a long-term career within cyber security sales. What's On Offer? Competitive basic salary of £40,000-£50,000 + Uncapped commission with excellent earning potential. Hybrid working. Defined sales territory. Technical pre-sales support. Marketing support to help generate opportunities. Access to market-leading cyber security vendors. Genuine career progression within a growing business. Supportive, collaborative and ambitious team culture. Apply Today If you're an ambitious sales professional looking to develop your career within the rapidly growing cyber security market, we'd love to hear from you. This is your opportunity to join a business where success is recognised, hard work is rewarded and your career progression is in your hands.
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As Vanta's EMEA Customer Success Manager for the Strategic Segment, you will be responsible for a portfolio of Vanta's largest and most complex customers, organizations with 10,000+ employees operating in highly regulated, global environments. This is a senior, high-impact role focused on driving executive alignment, long-term value realization, and measurable business outcomes across complex stakeholder groups. You will serve as a strategic advisor to CISOs, CIOs, Heads of GRC, and executive sponsors, ensuring Vanta is embedded as a critical component of their security and compliance strategy. You will combine deep GRC domain expertise, executive presence, and sophisticated account leadership to drive retention, expansion, and long-term partnership. What you'll do as a Customer Success Manager, Strategic at Vanta: Own post-sales success for a portfolio of Strategic accounts (10,000+ employees), managing complex, global customer environments. Lead executive-level engagement, including C-suite alignment, executive business reviews, and multi-year roadmap planning. Develop and execute comprehensive account success plans tied to measurable business outcomes and customer security objectives. Drive large-scale onboarding and enterprise-wide adoption across multiple business units and geographies. Partner closely with Account Executives to identify and drive expansion opportunities across compliance frameworks, Trust Reports, Risk Management, and additional Vanta solutions. Serve as a trusted GRC advisor, guiding customers through complex regulatory environments such as SOC 2, ISO 27001, ISO 42001, GDPR, HIPAA, and custom frameworks. Provide strategic guidance on scaling security programs, operationalizing continuous compliance, and maturing risk management processes. Navigate and influence complex stakeholder ecosystems including security, IT, legal, procurement, and executive leadership. Act as the voice of the customer, influencing product strategy and cross-functional priorities to improve enterprise readiness and customer outcomes. Proactively manage risk across accounts, including renewal forecasting, stakeholder changes, organisational shifts, and evolving compliance landscapes. Lead cross-functional initiatives with Product, Engineering, Support, and Sales to resolve sophisticated customer challenges. How to be successful in this role: 8+ years of Customer Success experience in a SaaS environment, with at least 3+ years managing large enterprise or strategic accounts. Strong GRC domain expertise, with hands on experience in security compliance frameworks such as SOC 2, ISO 27001, HIPAA, GDPR, ISO 42001, or similar. Proven experience engaging and influencing C-level executives in complex, global organisations. Demonstrated success driving retention and expansion within large, multi-threaded accounts. Experience leading executive business reviews, building multi-year strategic plans, and delivering measurable business outcomes. Ability to manage ambiguity and operate effectively in highly matrixed customer organisations. Strong commercial acumen with experience partnering on large renewals and expansion motions. Exceptional communication skills, with the ability to translate technical security concepts into executive-level business value. Strong analytical and problem-solving skills, with the ability to identify risk and drive proactive account strategies. High level of ownership, accountability, and ability to influence without authority. Open to using AI to amplify their skills and strengthen their work-demonstrating curiosity, a willingness to learn, and sound judgment in applying AI responsibly to improve efficiency and impact. What you can expect as a Vanta'n: Industry-competitive salary and equity 100% covered medical, dental, and vision benefits with dependents coverage 16 weeks paid Parental Leave for all new parents Health & wellness stipend Remote workspace, internet, and mobile phone stipend Commuter benefits for team members who attend the office Pension matching 25 days of Annual Leave per year and unlimited sick time 8 company-paid holidays Virtual team building activities, lunch and learns, and other company-wide events! Offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply. About Vanta We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. Now more than ever, making security continuous-not just a point-in-time check- is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust- all in a way that's real-time and transparent.
Jul 20, 2026
Full time
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As Vanta's EMEA Customer Success Manager for the Strategic Segment, you will be responsible for a portfolio of Vanta's largest and most complex customers, organizations with 10,000+ employees operating in highly regulated, global environments. This is a senior, high-impact role focused on driving executive alignment, long-term value realization, and measurable business outcomes across complex stakeholder groups. You will serve as a strategic advisor to CISOs, CIOs, Heads of GRC, and executive sponsors, ensuring Vanta is embedded as a critical component of their security and compliance strategy. You will combine deep GRC domain expertise, executive presence, and sophisticated account leadership to drive retention, expansion, and long-term partnership. What you'll do as a Customer Success Manager, Strategic at Vanta: Own post-sales success for a portfolio of Strategic accounts (10,000+ employees), managing complex, global customer environments. Lead executive-level engagement, including C-suite alignment, executive business reviews, and multi-year roadmap planning. Develop and execute comprehensive account success plans tied to measurable business outcomes and customer security objectives. Drive large-scale onboarding and enterprise-wide adoption across multiple business units and geographies. Partner closely with Account Executives to identify and drive expansion opportunities across compliance frameworks, Trust Reports, Risk Management, and additional Vanta solutions. Serve as a trusted GRC advisor, guiding customers through complex regulatory environments such as SOC 2, ISO 27001, ISO 42001, GDPR, HIPAA, and custom frameworks. Provide strategic guidance on scaling security programs, operationalizing continuous compliance, and maturing risk management processes. Navigate and influence complex stakeholder ecosystems including security, IT, legal, procurement, and executive leadership. Act as the voice of the customer, influencing product strategy and cross-functional priorities to improve enterprise readiness and customer outcomes. Proactively manage risk across accounts, including renewal forecasting, stakeholder changes, organisational shifts, and evolving compliance landscapes. Lead cross-functional initiatives with Product, Engineering, Support, and Sales to resolve sophisticated customer challenges. How to be successful in this role: 8+ years of Customer Success experience in a SaaS environment, with at least 3+ years managing large enterprise or strategic accounts. Strong GRC domain expertise, with hands on experience in security compliance frameworks such as SOC 2, ISO 27001, HIPAA, GDPR, ISO 42001, or similar. Proven experience engaging and influencing C-level executives in complex, global organisations. Demonstrated success driving retention and expansion within large, multi-threaded accounts. Experience leading executive business reviews, building multi-year strategic plans, and delivering measurable business outcomes. Ability to manage ambiguity and operate effectively in highly matrixed customer organisations. Strong commercial acumen with experience partnering on large renewals and expansion motions. Exceptional communication skills, with the ability to translate technical security concepts into executive-level business value. Strong analytical and problem-solving skills, with the ability to identify risk and drive proactive account strategies. High level of ownership, accountability, and ability to influence without authority. Open to using AI to amplify their skills and strengthen their work-demonstrating curiosity, a willingness to learn, and sound judgment in applying AI responsibly to improve efficiency and impact. What you can expect as a Vanta'n: Industry-competitive salary and equity 100% covered medical, dental, and vision benefits with dependents coverage 16 weeks paid Parental Leave for all new parents Health & wellness stipend Remote workspace, internet, and mobile phone stipend Commuter benefits for team members who attend the office Pension matching 25 days of Annual Leave per year and unlimited sick time 8 company-paid holidays Virtual team building activities, lunch and learns, and other company-wide events! Offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply. About Vanta We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. Now more than ever, making security continuous-not just a point-in-time check- is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust- all in a way that's real-time and transparent.
Role Overview We have an exciting opportunity for a Senior Security Consultant to join our growing Governance, Risk and Assurance (GRA) team. Within this role, you will utilise your GRAC and cybersecurity expertise to advise clients on information security, lead technical consulting engagements and support in the delivery of complex security programmes. Responsibilities Lead cyber governance, risk and compliance engagements, applying strong knowledge of cyber threats, risks, controls and mitigations to deliver effective security outcomes. Engage with clients to understand their threat landscape and business context, conducting risk and compliance assessments against recognised frameworks (e.g. ISO 27001, NIST, SOC 2). Design, review and advise on the implementation and adoption of information security policies, standards, procedures and frameworks. Lead cyber and third party risk assessments, evaluate supplier security posture, and provide risk based recommendations for supplier selection and oversight. Identify control gaps, document findings, and track remediation activities to support assurance and audit outcomes. Produce clear, concise risk and compliance reports for executive and C suite stakeholders, including prioritised mitigation strategies and improvement roadmaps. Contribute to thought leadership and continuous improvement by staying current with industry developments and sharing knowledge across the cyber security community. Demonstrate strong communication, stakeholder management and mentoring skills, upholding the highest standards of integrity and professionalism. About you You have extensive experience of designing, leading and delivering cyber governance, risk and assurance outcomes, with a proven track record of successfully leading GRC and security assurance initiatives. You possess strong knowledge of recognised cyber security frameworks and standards, including ISO/IEC 27001, NIS Directives, NIST, and UK Government Functional Standards, with demonstrable experience aligning security controls to MOD requirements such as DEFSTAN 05-138, JSP 440, JSP 604 and Defence Cyber Resilience policies. You are experienced in applying UK Government security and assurance frameworks, including GovAssure, the Cyber Assessment Framework (CAF), Defence Cyber Certification (DCC) and Government Standard (GovS) 007. You are a confident stakeholder manager, able to clearly articulate cyber risk and the value of security investment to senior leaders, while mentoring and guiding teams to deliver high quality outcomes. You hold relevant academic or professional qualifications, such as an MSc in cyber security or related specialism, Cyber Essentials Assessor, Cyber Assurance Assessor, CISM, CISSP, PCIRM or ISO/IEC 27001 Lead Implementer or Lead Auditor certification. You hold, or are actively working towards, Principal or Chartered Cyber Security Professional (ChCSP) status. You are eligible to work in the UK and able to obtain and maintain UK security clearance. You will have the flexibility to work from home, FSP office locations or at times visit client sites. What we look for in our people Strong alignment with FSP values and ethos. Commitment to teamwork, quality and mutual success. Proactivity with an ability to operate with pace and energy. Strong communication and interpersonal skills. Excellent planning and organisational skills. Dedication to excellence and quality. Equal and Fair Opportunity FSP is an equal opportunity employer and welcomes applications from all suitably qualified candidates. We assess applicants based on their skills, experience, and potential, without regard to age, disability, sexual orientation, gender identity, family or parental status, race, colour, nationality, ethnic or national origin, religion or belief, or any other protected characteristic. Please note that visa sponsorship is available for some roles, subject to eligibility and business requirements. We are committed to providing a fair and inclusive recruitment process. If you require any reasonable adjustments to participate fully in an interview or meeting (whether virtual or in person), please let us know.
Jul 06, 2026
Full time
Role Overview We have an exciting opportunity for a Senior Security Consultant to join our growing Governance, Risk and Assurance (GRA) team. Within this role, you will utilise your GRAC and cybersecurity expertise to advise clients on information security, lead technical consulting engagements and support in the delivery of complex security programmes. Responsibilities Lead cyber governance, risk and compliance engagements, applying strong knowledge of cyber threats, risks, controls and mitigations to deliver effective security outcomes. Engage with clients to understand their threat landscape and business context, conducting risk and compliance assessments against recognised frameworks (e.g. ISO 27001, NIST, SOC 2). Design, review and advise on the implementation and adoption of information security policies, standards, procedures and frameworks. Lead cyber and third party risk assessments, evaluate supplier security posture, and provide risk based recommendations for supplier selection and oversight. Identify control gaps, document findings, and track remediation activities to support assurance and audit outcomes. Produce clear, concise risk and compliance reports for executive and C suite stakeholders, including prioritised mitigation strategies and improvement roadmaps. Contribute to thought leadership and continuous improvement by staying current with industry developments and sharing knowledge across the cyber security community. Demonstrate strong communication, stakeholder management and mentoring skills, upholding the highest standards of integrity and professionalism. About you You have extensive experience of designing, leading and delivering cyber governance, risk and assurance outcomes, with a proven track record of successfully leading GRC and security assurance initiatives. You possess strong knowledge of recognised cyber security frameworks and standards, including ISO/IEC 27001, NIS Directives, NIST, and UK Government Functional Standards, with demonstrable experience aligning security controls to MOD requirements such as DEFSTAN 05-138, JSP 440, JSP 604 and Defence Cyber Resilience policies. You are experienced in applying UK Government security and assurance frameworks, including GovAssure, the Cyber Assessment Framework (CAF), Defence Cyber Certification (DCC) and Government Standard (GovS) 007. You are a confident stakeholder manager, able to clearly articulate cyber risk and the value of security investment to senior leaders, while mentoring and guiding teams to deliver high quality outcomes. You hold relevant academic or professional qualifications, such as an MSc in cyber security or related specialism, Cyber Essentials Assessor, Cyber Assurance Assessor, CISM, CISSP, PCIRM or ISO/IEC 27001 Lead Implementer or Lead Auditor certification. You hold, or are actively working towards, Principal or Chartered Cyber Security Professional (ChCSP) status. You are eligible to work in the UK and able to obtain and maintain UK security clearance. You will have the flexibility to work from home, FSP office locations or at times visit client sites. What we look for in our people Strong alignment with FSP values and ethos. Commitment to teamwork, quality and mutual success. Proactivity with an ability to operate with pace and energy. Strong communication and interpersonal skills. Excellent planning and organisational skills. Dedication to excellence and quality. Equal and Fair Opportunity FSP is an equal opportunity employer and welcomes applications from all suitably qualified candidates. We assess applicants based on their skills, experience, and potential, without regard to age, disability, sexual orientation, gender identity, family or parental status, race, colour, nationality, ethnic or national origin, religion or belief, or any other protected characteristic. Please note that visa sponsorship is available for some roles, subject to eligibility and business requirements. We are committed to providing a fair and inclusive recruitment process. If you require any reasonable adjustments to participate fully in an interview or meeting (whether virtual or in person), please let us know.
Role Overview We have an exciting opportunity for a Senior Security Consultant to join our growing Governance, Risk and Assurance (GRA) team. Within this role, you will utilise your GRAC and cybersecurity expertise to advise clients on information security, lead technical consulting engagements and support in the delivery of complex security programmes. Responsibilities Lead cyber governance, risk and compliance engagements, applying strong knowledge of cyber threats, risks, controls and mitigations to deliver effective security outcomes. Engage with clients to understand their threat landscape and business context, conducting risk and compliance assessments against recognised frameworks (e.g. ISO 27001, NIST, SOC 2). Design, review and advise on the implementation and adoption of information security policies, standards, procedures and frameworks. Lead cyber and third party risk assessments, evaluate supplier security posture, and provide risk based recommendations for supplier selection and oversight. Identify control gaps, document findings, and track remediation activities to support assurance and audit outcomes. Produce clear, concise risk and compliance reports for executive and C suite stakeholders, including prioritised mitigation strategies and improvement roadmaps. Contribute to thought leadership and continuous improvement by staying current with industry developments and sharing knowledge across the cyber security community. Demonstrate strong communication, stakeholder management and mentoring skills, upholding the highest standards of integrity and professionalism. About you You have extensive experience of designing, leading and delivering cyber governance, risk and assurance outcomes, with a proven track record of successfully leading GRC and security assurance initiatives. You possess strong knowledge of recognised cyber security frameworks and standards, including ISO/IEC 27001, NIS Directives, NIST, and UK Government Functional Standards, with demonstrable experience aligning security controls to MOD requirements such as DEFSTAN 05-138, JSP 440, JSP 604 and Defence Cyber Resilience policies. You are experienced in applying UK Government security and assurance frameworks, including GovAssure, the Cyber Assessment Framework (CAF), Defence Cyber Certification (DCC) and Government Standard (GovS) 007. You are a confident stakeholder manager, able to clearly articulate cyber risk and the value of security investment to senior leaders, while mentoring and guiding teams to deliver high quality outcomes. You hold relevant academic or professional qualifications, such as an MSc in cyber security or related specialism, Cyber Essentials Assessor, Cyber Assurance Assessor, CISM, CISSP, PCIRM or ISO/IEC 27001 Lead Implementer or Lead Auditor certification. You hold, or are actively working towards, Principal or Chartered Cyber Security Professional (ChCSP) status. You are eligible to work in the UK and able to obtain and maintain UK security clearance. You will have the flexibility to work from home, FSP office locations or at times visit client sites. What we look for in our people Strong alignment with FSP values and ethos. Commitment to teamwork, quality and mutual success. Proactivity with an ability to operate with pace and energy. Strong communication and interpersonal skills. Excellent planning and organisational skills. Dedication to excellence and quality. Equal and Fair Opportunity FSP is an equal opportunity employer and welcomes applications from all suitably qualified candidates. We assess applicants based on their skills, experience, and potential, without regard to age, disability, sexual orientation, gender identity, family or parental status, race, colour, nationality, ethnic or national origin, religion or belief, or any other protected characteristic. Please note that visa sponsorship is available for some roles, subject to eligibility and business requirements. We are committed to providing a fair and inclusive recruitment process. If you require any reasonable adjustments to participate fully in an interview or meeting (whether virtual or in person), please let us know.
Jul 06, 2026
Full time
Role Overview We have an exciting opportunity for a Senior Security Consultant to join our growing Governance, Risk and Assurance (GRA) team. Within this role, you will utilise your GRAC and cybersecurity expertise to advise clients on information security, lead technical consulting engagements and support in the delivery of complex security programmes. Responsibilities Lead cyber governance, risk and compliance engagements, applying strong knowledge of cyber threats, risks, controls and mitigations to deliver effective security outcomes. Engage with clients to understand their threat landscape and business context, conducting risk and compliance assessments against recognised frameworks (e.g. ISO 27001, NIST, SOC 2). Design, review and advise on the implementation and adoption of information security policies, standards, procedures and frameworks. Lead cyber and third party risk assessments, evaluate supplier security posture, and provide risk based recommendations for supplier selection and oversight. Identify control gaps, document findings, and track remediation activities to support assurance and audit outcomes. Produce clear, concise risk and compliance reports for executive and C suite stakeholders, including prioritised mitigation strategies and improvement roadmaps. Contribute to thought leadership and continuous improvement by staying current with industry developments and sharing knowledge across the cyber security community. Demonstrate strong communication, stakeholder management and mentoring skills, upholding the highest standards of integrity and professionalism. About you You have extensive experience of designing, leading and delivering cyber governance, risk and assurance outcomes, with a proven track record of successfully leading GRC and security assurance initiatives. You possess strong knowledge of recognised cyber security frameworks and standards, including ISO/IEC 27001, NIS Directives, NIST, and UK Government Functional Standards, with demonstrable experience aligning security controls to MOD requirements such as DEFSTAN 05-138, JSP 440, JSP 604 and Defence Cyber Resilience policies. You are experienced in applying UK Government security and assurance frameworks, including GovAssure, the Cyber Assessment Framework (CAF), Defence Cyber Certification (DCC) and Government Standard (GovS) 007. You are a confident stakeholder manager, able to clearly articulate cyber risk and the value of security investment to senior leaders, while mentoring and guiding teams to deliver high quality outcomes. You hold relevant academic or professional qualifications, such as an MSc in cyber security or related specialism, Cyber Essentials Assessor, Cyber Assurance Assessor, CISM, CISSP, PCIRM or ISO/IEC 27001 Lead Implementer or Lead Auditor certification. You hold, or are actively working towards, Principal or Chartered Cyber Security Professional (ChCSP) status. You are eligible to work in the UK and able to obtain and maintain UK security clearance. You will have the flexibility to work from home, FSP office locations or at times visit client sites. What we look for in our people Strong alignment with FSP values and ethos. Commitment to teamwork, quality and mutual success. Proactivity with an ability to operate with pace and energy. Strong communication and interpersonal skills. Excellent planning and organisational skills. Dedication to excellence and quality. Equal and Fair Opportunity FSP is an equal opportunity employer and welcomes applications from all suitably qualified candidates. We assess applicants based on their skills, experience, and potential, without regard to age, disability, sexual orientation, gender identity, family or parental status, race, colour, nationality, ethnic or national origin, religion or belief, or any other protected characteristic. Please note that visa sponsorship is available for some roles, subject to eligibility and business requirements. We are committed to providing a fair and inclusive recruitment process. If you require any reasonable adjustments to participate fully in an interview or meeting (whether virtual or in person), please let us know.
Cyber Security Delivery Manager £80-90k Portsmouth (Hybrid) SC Clearance Eligibility essential Are you a senior cyber security professional who can lead from the front - advising at board level one day and getting hands-on with a security architecture review the next? We're recruiting on behalf of a well-regarded cyber security consultancy based in Hampshire. They work with a range of clients on complex, meaningful security challenges - and they're looking for an experienced Cyber Manager to join the senior team. This isn't a purely strategic role. You'll lead engagements, grow client relationships, and help shape the direction of the business - but you'll also roll your sleeves up when the work demands it. Salary: £ Package: Gym, private medical insurance, company pension, work from home flex Working Structure: Hybrid remote in Portsmouth (2 days onsite) Security Clearance: Active or Eligible for SC clearance. The Role: As Cyber Security Delivery Manager, you'll take ownership of client engagements from start to finish, covering risk assessments, security architecture reviews, policy development, incident response planning, and governance work. You'll be the senior point of contact on engagements, ensuring quality and consistency across everything that goes out the door. What You'll Be Doing: Leading end-to-end cyber security engagements across advisory and hands-on delivery Managing multiple projects simultaneously, ensuring delivery quality and client satisfaction Building and maintaining strong relationships with clients, including at CISO and board level Leading proposals and bids, contributing to go-to-market strategy and service development Supporting and developing junior and mid-level consultants through active mentoring Putting sensible operational processes in place and keeping day-to-day delivery on track Contributing to hiring decisions as the team grows What You'll Need: Significant experience delivering cyber security projects in a consultancy or professional services environment Strong technical knowledge across core cyber domains - risk management, security architecture, governance, assurance, or incident response CISSP, CISM, or equivalent professional certification A proven track record of leading teams and managing senior client relationships The ability to communicate complex security topics clearly to both technical and non-technical stakeholders Eligibility to obtain or active SC (Security Clearance) Self-motivated, decisive, and comfortable operating with a high degree of autonomy Desired but not essential: Experience across multiple disciplines such as GRC, penetration testing, SOC, cloud security, or OT security Familiarity with frameworks including NIST, ISO 27001, CAF, or Cyber Essentials Experience working with government, defence, or critical national infrastructure clients Additional certifications such as CREST, OSCP, or NCSC Certified Professional If this sounds like the right next step, apply now or get in touch for a confidential conversation. Candidates must be eligible to work in the UK and able to obtain Security Clearance. Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy. To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.
May 23, 2026
Full time
Cyber Security Delivery Manager £80-90k Portsmouth (Hybrid) SC Clearance Eligibility essential Are you a senior cyber security professional who can lead from the front - advising at board level one day and getting hands-on with a security architecture review the next? We're recruiting on behalf of a well-regarded cyber security consultancy based in Hampshire. They work with a range of clients on complex, meaningful security challenges - and they're looking for an experienced Cyber Manager to join the senior team. This isn't a purely strategic role. You'll lead engagements, grow client relationships, and help shape the direction of the business - but you'll also roll your sleeves up when the work demands it. Salary: £ Package: Gym, private medical insurance, company pension, work from home flex Working Structure: Hybrid remote in Portsmouth (2 days onsite) Security Clearance: Active or Eligible for SC clearance. The Role: As Cyber Security Delivery Manager, you'll take ownership of client engagements from start to finish, covering risk assessments, security architecture reviews, policy development, incident response planning, and governance work. You'll be the senior point of contact on engagements, ensuring quality and consistency across everything that goes out the door. What You'll Be Doing: Leading end-to-end cyber security engagements across advisory and hands-on delivery Managing multiple projects simultaneously, ensuring delivery quality and client satisfaction Building and maintaining strong relationships with clients, including at CISO and board level Leading proposals and bids, contributing to go-to-market strategy and service development Supporting and developing junior and mid-level consultants through active mentoring Putting sensible operational processes in place and keeping day-to-day delivery on track Contributing to hiring decisions as the team grows What You'll Need: Significant experience delivering cyber security projects in a consultancy or professional services environment Strong technical knowledge across core cyber domains - risk management, security architecture, governance, assurance, or incident response CISSP, CISM, or equivalent professional certification A proven track record of leading teams and managing senior client relationships The ability to communicate complex security topics clearly to both technical and non-technical stakeholders Eligibility to obtain or active SC (Security Clearance) Self-motivated, decisive, and comfortable operating with a high degree of autonomy Desired but not essential: Experience across multiple disciplines such as GRC, penetration testing, SOC, cloud security, or OT security Familiarity with frameworks including NIST, ISO 27001, CAF, or Cyber Essentials Experience working with government, defence, or critical national infrastructure clients Additional certifications such as CREST, OSCP, or NCSC Certified Professional If this sounds like the right next step, apply now or get in touch for a confidential conversation. Candidates must be eligible to work in the UK and able to obtain Security Clearance. Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy. To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.
Cyber Governance Risk and Compliance Manager Contract Duration: Until 13 November 2027 Location: Hybrid (2 days onsite - office based in London or Sheffield) Job Type: Contract We are seeking an experienced Cyber Governance Risk and Compliance (GRC) Manager to join our team. This role involves driving risk assurance, compliance oversight, and certification delivery across a complex, multi-entity environment. The successful candidate will be a hands-on GRC Manager who can operate with autonomy, bring structure to ambiguity, and engage effectively across business and technology stakeholders. Day-to-day of the role : Subsidiary Risk Assurance & Governance : Conduct risk assessments, develop risk heat maps, and produce executive-level summaries. ISO 27001 & Cyber Essentials Delivery : Oversee readiness assessments, provide governance oversight, and validate compliance with standards. Reporting & Stakeholder Engagement : Deliver regular reports, manage stakeholder engagement, and maintain centralised dashboards. Strategic Roadmapping : Develop a 3-year cyber compliance roadmap, detailing priorities, timelines, and resource requirements. Compliance & Advisory : Provide ongoing support for compliance, interpret regulatory requirements, and ensure alignment with industry standards. Incident Leadership & Management : Lead the coordination of high-severity cyber incidents, ensuring effective communication and structured execution. Required Skills & Qualifications: Core Experience : Proven experience in Cyber Incident Response or Major Incident Management, preferably in a SOC or Security Operations environment. Stakeholder & Leadership Skills : Excellent communication skills, ability to influence and negotiate under pressure, and experience with senior stakeholders. Operational Capability : Experience managing incident bridges/war rooms and strong decision-making skills in high-pressure situations. Technical Understanding (Desirable) : Knowledge of cyber security concepts, Endpoint Detection & Response, SIEM platforms, and ServiceNow. To apply for the Cyber Governance Risk and Compliance Manager position, please submit your CV and a member of the Reed Professional Services Talent Team will be in touch
May 19, 2026
Seasonal
Cyber Governance Risk and Compliance Manager Contract Duration: Until 13 November 2027 Location: Hybrid (2 days onsite - office based in London or Sheffield) Job Type: Contract We are seeking an experienced Cyber Governance Risk and Compliance (GRC) Manager to join our team. This role involves driving risk assurance, compliance oversight, and certification delivery across a complex, multi-entity environment. The successful candidate will be a hands-on GRC Manager who can operate with autonomy, bring structure to ambiguity, and engage effectively across business and technology stakeholders. Day-to-day of the role : Subsidiary Risk Assurance & Governance : Conduct risk assessments, develop risk heat maps, and produce executive-level summaries. ISO 27001 & Cyber Essentials Delivery : Oversee readiness assessments, provide governance oversight, and validate compliance with standards. Reporting & Stakeholder Engagement : Deliver regular reports, manage stakeholder engagement, and maintain centralised dashboards. Strategic Roadmapping : Develop a 3-year cyber compliance roadmap, detailing priorities, timelines, and resource requirements. Compliance & Advisory : Provide ongoing support for compliance, interpret regulatory requirements, and ensure alignment with industry standards. Incident Leadership & Management : Lead the coordination of high-severity cyber incidents, ensuring effective communication and structured execution. Required Skills & Qualifications: Core Experience : Proven experience in Cyber Incident Response or Major Incident Management, preferably in a SOC or Security Operations environment. Stakeholder & Leadership Skills : Excellent communication skills, ability to influence and negotiate under pressure, and experience with senior stakeholders. Operational Capability : Experience managing incident bridges/war rooms and strong decision-making skills in high-pressure situations. Technical Understanding (Desirable) : Knowledge of cyber security concepts, Endpoint Detection & Response, SIEM platforms, and ServiceNow. To apply for the Cyber Governance Risk and Compliance Manager position, please submit your CV and a member of the Reed Professional Services Talent Team will be in touch
Cyber Governance Risk and Compliance Manager Contract Duration: Until 13 November 2027 Location: Hybrid (2 days onsite - office based in London or Sheffield) Job Type: Contract We are seeking an experienced Cyber Governance Risk and Compliance (GRC) Manager to join our team. This role involves driving risk assurance, compliance oversight, and certification delivery across a complex, multi-entity environment. The successful candidate will be a hands-on GRC Manager who can operate with autonomy, bring structure to ambiguity, and engage effectively across business and technology stakeholders. Day-to-day of the role : Subsidiary Risk Assurance & Governance : Conduct risk assessments, develop risk heat maps, and produce executive-level summaries. ISO 27001 & Cyber Essentials Delivery : Oversee readiness assessments, provide governance oversight, and validate compliance with standards. Reporting & Stakeholder Engagement : Deliver regular reports, manage stakeholder engagement, and maintain centralised dashboards. Strategic Roadmapping : Develop a 3-year cyber compliance roadmap, detailing priorities, timelines, and resource requirements. Compliance & Advisory : Provide ongoing support for compliance, interpret regulatory requirements, and ensure alignment with industry standards. Incident Leadership & Management : Lead the coordination of high-severity cyber incidents, ensuring effective communication and structured execution. Required Skills & Qualifications: Core Experience : Proven experience in Cyber Incident Response or Major Incident Management, preferably in a SOC or Security Operations environment. Stakeholder & Leadership Skills : Excellent communication skills, ability to influence and negotiate under pressure, and experience with senior stakeholders. Operational Capability : Experience managing incident bridges/war rooms and strong decision-making skills in high-pressure situations. Technical Understanding (Desirable) : Knowledge of cyber security concepts, Endpoint Detection & Response, SIEM platforms, and ServiceNow. To apply for the Cyber Governance Risk and Compliance Manager position, please submit your CV and a member of the Reed Professional Services Talent Team will be in touch
May 19, 2026
Seasonal
Cyber Governance Risk and Compliance Manager Contract Duration: Until 13 November 2027 Location: Hybrid (2 days onsite - office based in London or Sheffield) Job Type: Contract We are seeking an experienced Cyber Governance Risk and Compliance (GRC) Manager to join our team. This role involves driving risk assurance, compliance oversight, and certification delivery across a complex, multi-entity environment. The successful candidate will be a hands-on GRC Manager who can operate with autonomy, bring structure to ambiguity, and engage effectively across business and technology stakeholders. Day-to-day of the role : Subsidiary Risk Assurance & Governance : Conduct risk assessments, develop risk heat maps, and produce executive-level summaries. ISO 27001 & Cyber Essentials Delivery : Oversee readiness assessments, provide governance oversight, and validate compliance with standards. Reporting & Stakeholder Engagement : Deliver regular reports, manage stakeholder engagement, and maintain centralised dashboards. Strategic Roadmapping : Develop a 3-year cyber compliance roadmap, detailing priorities, timelines, and resource requirements. Compliance & Advisory : Provide ongoing support for compliance, interpret regulatory requirements, and ensure alignment with industry standards. Incident Leadership & Management : Lead the coordination of high-severity cyber incidents, ensuring effective communication and structured execution. Required Skills & Qualifications: Core Experience : Proven experience in Cyber Incident Response or Major Incident Management, preferably in a SOC or Security Operations environment. Stakeholder & Leadership Skills : Excellent communication skills, ability to influence and negotiate under pressure, and experience with senior stakeholders. Operational Capability : Experience managing incident bridges/war rooms and strong decision-making skills in high-pressure situations. Technical Understanding (Desirable) : Knowledge of cyber security concepts, Endpoint Detection & Response, SIEM platforms, and ServiceNow. To apply for the Cyber Governance Risk and Compliance Manager position, please submit your CV and a member of the Reed Professional Services Talent Team will be in touch
Cyber Security Governance, Risk and Compliance Manager - Lincolnshire based (hybrid) - Full time permanent role with a large business - Salary circa £60k plus bonus, great pension and more! We're partnering with a well-established, values-driven organisation looking to appoint a Cyber GRC Manager to strengthen governance, risk, and compliance across their technology and cyber landscape. This is a key role where you'll help shape and embed best-practice frameworks, ensuring the business remains secure, compliant, and resilient in an evolving threat environment. The Role You'll take ownership of cyber governance and risk management, working closely with senior stakeholders to identify, assess, and mitigate risk while ensuring alignment with regulatory requirements and industry standards. Key Responsibilities Leading cyber risk management activities, including maintaining risk registers Supporting governance frameworks, policies, and controls Delivering risk-based audits across IT and cyber environments Collaborating with internal teams and external partners Providing clear reporting and insight to senior stakeholders About You Experience within cyber GRC, IT audit, or risk management Strong understanding of frameworks such as ISO 27001, NIST, or similar Confident communicator, able to translate technical risks into business impact Proactive and detail-oriented, with a collaborative approach
May 08, 2026
Full time
Cyber Security Governance, Risk and Compliance Manager - Lincolnshire based (hybrid) - Full time permanent role with a large business - Salary circa £60k plus bonus, great pension and more! We're partnering with a well-established, values-driven organisation looking to appoint a Cyber GRC Manager to strengthen governance, risk, and compliance across their technology and cyber landscape. This is a key role where you'll help shape and embed best-practice frameworks, ensuring the business remains secure, compliant, and resilient in an evolving threat environment. The Role You'll take ownership of cyber governance and risk management, working closely with senior stakeholders to identify, assess, and mitigate risk while ensuring alignment with regulatory requirements and industry standards. Key Responsibilities Leading cyber risk management activities, including maintaining risk registers Supporting governance frameworks, policies, and controls Delivering risk-based audits across IT and cyber environments Collaborating with internal teams and external partners Providing clear reporting and insight to senior stakeholders About You Experience within cyber GRC, IT audit, or risk management Strong understanding of frameworks such as ISO 27001, NIST, or similar Confident communicator, able to translate technical risks into business impact Proactive and detail-oriented, with a collaborative approach
Purpose of Position As Information Security Risk Manager (f/m/d) you will own and drive Awin's global Information Security Risk Management capability end-to-end, ensuring the business not only understands its risks but takes measurable action to reduce them. You will be accountable for embedding a strong culture of risk ownership across the organisation, proactively identifying gaps, and driving remediation through to completion. This role requires structured risk identification, assessment, and reporting whilst acting as a advisor to senior leadership and the board. It ensures that risk appetite is clearly defined, actively used in decision-making, and consistently monitored. Your location: Ideally in Berlin, Munich, Madrid, Warsaw, London, Milan, Ia?i, Stockholm, or Paris (or in Germany, Spain, Poland, UK, Italy, Romania, Sweden, or France) Key Tasks Lead enterprise-wide risk identification and assessment across strategic initiatives, technology, and third parties. Ensure risks are prioritised and clearly articulated in business terms (financial, regulatory, reputational) to enable effective decision-making. Drive risk remediation to closure, holding risk owners accountable for delivery and escalating where progress stalls. Ensure risk management is embedded in cross-functional initiatives and considered as part of key business decisions. Own and maintain the Information Security Risk Register, ensuring it reflects true risk exposure, progress, and outcomes, not just status updates. Facilitate risk reviews that are focused on decisions, accountability, and measurable progress. Define, embed, and maintain the organisation's risk appetite, ensuring it is actively used in both business and technology decision-making. Establish and track KPIs that measure real improvements in risk posture, not just activity. Provide clear, opinionated, and actionable risk insights to senior management and the board. Act as the bridge between technical and business teams, ensuring risks are clearly understood and acted upon. Confidently challenge and influence stakeholders to ensure risks are neither understated nor inappropriately accepted. Own and continuously improve Awin's global information security risk management framework, aligned to ISO 27001 and regulatory requirements. Monitor control effectiveness, proactively identify weaknesses, and drive improvements. Embed risk management into business processes so that risks are considered early and proactively, rather than retrospectively. As the most senior member of the team, mentor and develop GRC team members, building capability in risk management and assurance. Lead horizon scanning across emerging threats, regulatory changes, and industry developments, translating these into practical risk implications and actions for the business. Skills & Expertise Proven track record of owning and delivering risk management initiatives end-to-end Experience driving risk remediation across teams without direct authority Strong experience presenting and defending risk positions to senior leadership and boards Hands-on experience within an ISO 27001-certified ISMS environment Strong knowledge of frameworks such as ISO 27001 Experience designing, implementing, or improving control frameworks Experience with GRC platforms (e.g. Hyperproof) Confident communicator (with very good English skills) - able to build relationships and challenge/influence senior stakeholders Our Offer Flexi-Week and Work-Life Balance : We prioritise your mental health and well-being, offering you a flexible four-day Flexi-Week at full pay and with no reduction to your annual holiday allowance. We also offer a variety of different paid special leaves as well as volunteer days. Remote Working Allowance: You will receive a monthly allowance to cover part of your running costs. In addition, we will support you in setting up your remote workspace appropriately. Pension: Awin offers access to an additional pension insurance to all employees in Germany. Flexi-Office: We offer an international culture and flexibility through our Flexi-Office and hybrid/remote work possibilities to work across Awin regions Development : We've built our extensive training suite Awin Academy to cover a wide range of skills that nurture you professionally and personally, with trainings conveniently packaged together to support your overall development. Appreciation : Thank and reward colleagues by sending them a voucher through our peer-to-peer program Established in 2000, Awin is proud of our dynamic, social and inclusive culture. Like all businesses, we've had to adapt and nurture our culture in a virtual environment. Our virtual hub brings our colleagues from across the globe together for various social activities. Diversity & Inclusion are paramount to us, and we proudly pursue and hire diverse team members. We champion uniqueness and authenticity; this is who we are at our core. Our network of affiliate partnerships are diverse and transparent, as are the employees powering our vision to build the world's leading open partner ecosystem. We welcome all backgrounds, identities, and experiences. If you need support at any point in the application or interview process, please let us know. Awin is part of the Axel Springer group.Learn more at , and explore the Axel Springer Essentials here: Apply now to begin the next stage of your career at a progressive company that supports both your professional and personal development.
May 08, 2026
Full time
Purpose of Position As Information Security Risk Manager (f/m/d) you will own and drive Awin's global Information Security Risk Management capability end-to-end, ensuring the business not only understands its risks but takes measurable action to reduce them. You will be accountable for embedding a strong culture of risk ownership across the organisation, proactively identifying gaps, and driving remediation through to completion. This role requires structured risk identification, assessment, and reporting whilst acting as a advisor to senior leadership and the board. It ensures that risk appetite is clearly defined, actively used in decision-making, and consistently monitored. Your location: Ideally in Berlin, Munich, Madrid, Warsaw, London, Milan, Ia?i, Stockholm, or Paris (or in Germany, Spain, Poland, UK, Italy, Romania, Sweden, or France) Key Tasks Lead enterprise-wide risk identification and assessment across strategic initiatives, technology, and third parties. Ensure risks are prioritised and clearly articulated in business terms (financial, regulatory, reputational) to enable effective decision-making. Drive risk remediation to closure, holding risk owners accountable for delivery and escalating where progress stalls. Ensure risk management is embedded in cross-functional initiatives and considered as part of key business decisions. Own and maintain the Information Security Risk Register, ensuring it reflects true risk exposure, progress, and outcomes, not just status updates. Facilitate risk reviews that are focused on decisions, accountability, and measurable progress. Define, embed, and maintain the organisation's risk appetite, ensuring it is actively used in both business and technology decision-making. Establish and track KPIs that measure real improvements in risk posture, not just activity. Provide clear, opinionated, and actionable risk insights to senior management and the board. Act as the bridge between technical and business teams, ensuring risks are clearly understood and acted upon. Confidently challenge and influence stakeholders to ensure risks are neither understated nor inappropriately accepted. Own and continuously improve Awin's global information security risk management framework, aligned to ISO 27001 and regulatory requirements. Monitor control effectiveness, proactively identify weaknesses, and drive improvements. Embed risk management into business processes so that risks are considered early and proactively, rather than retrospectively. As the most senior member of the team, mentor and develop GRC team members, building capability in risk management and assurance. Lead horizon scanning across emerging threats, regulatory changes, and industry developments, translating these into practical risk implications and actions for the business. Skills & Expertise Proven track record of owning and delivering risk management initiatives end-to-end Experience driving risk remediation across teams without direct authority Strong experience presenting and defending risk positions to senior leadership and boards Hands-on experience within an ISO 27001-certified ISMS environment Strong knowledge of frameworks such as ISO 27001 Experience designing, implementing, or improving control frameworks Experience with GRC platforms (e.g. Hyperproof) Confident communicator (with very good English skills) - able to build relationships and challenge/influence senior stakeholders Our Offer Flexi-Week and Work-Life Balance : We prioritise your mental health and well-being, offering you a flexible four-day Flexi-Week at full pay and with no reduction to your annual holiday allowance. We also offer a variety of different paid special leaves as well as volunteer days. Remote Working Allowance: You will receive a monthly allowance to cover part of your running costs. In addition, we will support you in setting up your remote workspace appropriately. Pension: Awin offers access to an additional pension insurance to all employees in Germany. Flexi-Office: We offer an international culture and flexibility through our Flexi-Office and hybrid/remote work possibilities to work across Awin regions Development : We've built our extensive training suite Awin Academy to cover a wide range of skills that nurture you professionally and personally, with trainings conveniently packaged together to support your overall development. Appreciation : Thank and reward colleagues by sending them a voucher through our peer-to-peer program Established in 2000, Awin is proud of our dynamic, social and inclusive culture. Like all businesses, we've had to adapt and nurture our culture in a virtual environment. Our virtual hub brings our colleagues from across the globe together for various social activities. Diversity & Inclusion are paramount to us, and we proudly pursue and hire diverse team members. We champion uniqueness and authenticity; this is who we are at our core. Our network of affiliate partnerships are diverse and transparent, as are the employees powering our vision to build the world's leading open partner ecosystem. We welcome all backgrounds, identities, and experiences. If you need support at any point in the application or interview process, please let us know. Awin is part of the Axel Springer group.Learn more at , and explore the Axel Springer Essentials here: Apply now to begin the next stage of your career at a progressive company that supports both your professional and personal development.
Join our team at the Guardian and be a part of a diverse and inclusive global organisation that delivers fearless, investigative journalism, and holds power to account. Our team of award-winning journalists, cutting-edge commercial professionals, and industry-leading digital experts are committed to making a difference and represent a wide range of backgrounds and perspectives. We offer a challenging and exciting environment for career development, with a focus on training, growth and fostering an inclusive culture. We are now looking for an Information Security GRC Risk Manager to join the Group Technology & Data team. You'll support the Information Security (InfoSec) GRC Lead to deliver effective risk management, ensuring risks are consistently identified, assessed and managed and that appropriate governance, including policies and standards, supports effective risk mitigation across the organisation. You'll act as a key driver between InfoSec and the wider business, providing oversight and challenge to ensure risks are appropriately managed. About the role: Own and operate the Information Security risk management framework, ensuring alignment with enterprise risk management (ERM) practices Identify and manage emerging risks, including those associated with AI/ML systems (e.g. bias, privacy, security, and model integrity) Own and deliver risk reporting to senior stakeholders and governance forums, providing clear visibility of risk exposure and remediation progress Lead responses to information security risk queries, assessments, and assurance activities Deliver targeted risk training and awareness to embed a strong risk management culture Own and maintain the Information Security policy framework, ensuring policies and standards remain current, aligned to risk appetite, and meet regulatory requirements Highlight systemic issues, control weaknesses, and emerging threats, driving visibility and action at leadership level Benchmark practices against industry standards and evolving regulatory expectations, ensuring continuous improvement About you: Strong interpersonal skills with the ability to influence, challenge, and engage senior stakeholders, translating technical risk into clear business impact Strong experience in identifying, assessing, and managing information security risks, with the ability to apply structured risk methodologies and align to business risk appetite Highly disciplined and methodical approach to risk analysis, with the ability to break down complex issues and provide clear, actionable insights Experience producing clear, concise risk reporting, including KPIs/KRIs, and presenting insights to leadership Strong organisational skills with the ability to manage multiple priorities, maintain momentum on risk treatment, and ensure follow-through Awareness of emerging technology risks, including AI/ML-related risks, and the ability to incorporate these into risk assessments Working knowledge of industry frameworks and standards (e.g. ISO 27005, ISO 42001, NIST CSF 2.0, NIST 800-53) and relevant regulations (e.g. GDPR, EU AI Principles) Solid understanding of security controls and experience supporting or performing control assessments and testing, with the ability to identify gaps and track remediation Experience with GRC tools (e.g. Diligent One GRC etc.) and risk tracking systems We actively encourage applications from groups traditionally underrepresented in the UK media We operate in a hybrid environment working 3 days a week from our offices in Kings Cross and 2 days a week remotely. We value and respect all differences (seen and unseen) in all people. We aspire to have inclusive working experiences and an environment that reflects the audience we serve, where our people have equal access to career development opportunities, their voices are heard and can contribute to our future. We actively encourage applications from people of all backgrounds. Many of our staff work flexibly and we will consider all requests for flexible working arrangements. How to apply To apply, please upload your latest CV and a cover letter which outlines why you'd love to take on this role, and why you're a great match for what we're looking for. We appreciate the time taken to prepare each application we receive. We do not use AI-assisted technology to review applications; every application is reviewed by a member of our recruitment team. The closing date for applications is Monday 11th May 2026. All roles at the Guardian are open for everybody to apply. It is important to us that you feel supported and comfortable throughout your recruitment process, in order to perform your best. Please let us know if there are any changes we could make to help your application, this includes providing documents in accessible formats or personalising the process to better support your needs. Please contact Anna Vipers on to discuss further so we can work with you to support you through your application. Benefits at the Guardian You'll have 30 days of annual leave per year (plus bank holidays) with the option to purchase an additional 5 days. Our pension scheme is generous; if you contribute 5% then we will contribute 8-12% (depending on your age). We believe in giving back, which is why employees are given 2 volunteering days annually and the option of payroll giving. Season ticket loans are also available. You are entitled to private healthcare, life cover, income protection, and eye tests. You can also opt in to dental insurance. We have enhanced maternity, paternity, adoption and shared parental leave policies in place. We also support our employees by offering an IVF, menopause, baby loss, and trans equality policy. Culture and wellbeing We want everyone to feel like they belong at the Guardian and we champion diversity of thought. Our various employee forums provide a platform to use their voice to foster an inclusive workplace. We became the first major media organisation to achieve B Corp status. We offer tools to help you prioritise your wellbeing including access to our employee benefits platform which provides tailored support for health and wellbeing. In addition, we also offer free yoga and pilates classes. These run alongside our corporate gym membership and cycle to work scheme. Our canteen has views overlooking the Regents Canal and caters for breakfast, lunch and dinner. Learning and development We encourage personal and professional growth. Employees have access to a broad range of tools and solutions, and we are happy to support the pursuit of professional qualifications through vocational courses and apprenticeships.
May 02, 2026
Full time
Join our team at the Guardian and be a part of a diverse and inclusive global organisation that delivers fearless, investigative journalism, and holds power to account. Our team of award-winning journalists, cutting-edge commercial professionals, and industry-leading digital experts are committed to making a difference and represent a wide range of backgrounds and perspectives. We offer a challenging and exciting environment for career development, with a focus on training, growth and fostering an inclusive culture. We are now looking for an Information Security GRC Risk Manager to join the Group Technology & Data team. You'll support the Information Security (InfoSec) GRC Lead to deliver effective risk management, ensuring risks are consistently identified, assessed and managed and that appropriate governance, including policies and standards, supports effective risk mitigation across the organisation. You'll act as a key driver between InfoSec and the wider business, providing oversight and challenge to ensure risks are appropriately managed. About the role: Own and operate the Information Security risk management framework, ensuring alignment with enterprise risk management (ERM) practices Identify and manage emerging risks, including those associated with AI/ML systems (e.g. bias, privacy, security, and model integrity) Own and deliver risk reporting to senior stakeholders and governance forums, providing clear visibility of risk exposure and remediation progress Lead responses to information security risk queries, assessments, and assurance activities Deliver targeted risk training and awareness to embed a strong risk management culture Own and maintain the Information Security policy framework, ensuring policies and standards remain current, aligned to risk appetite, and meet regulatory requirements Highlight systemic issues, control weaknesses, and emerging threats, driving visibility and action at leadership level Benchmark practices against industry standards and evolving regulatory expectations, ensuring continuous improvement About you: Strong interpersonal skills with the ability to influence, challenge, and engage senior stakeholders, translating technical risk into clear business impact Strong experience in identifying, assessing, and managing information security risks, with the ability to apply structured risk methodologies and align to business risk appetite Highly disciplined and methodical approach to risk analysis, with the ability to break down complex issues and provide clear, actionable insights Experience producing clear, concise risk reporting, including KPIs/KRIs, and presenting insights to leadership Strong organisational skills with the ability to manage multiple priorities, maintain momentum on risk treatment, and ensure follow-through Awareness of emerging technology risks, including AI/ML-related risks, and the ability to incorporate these into risk assessments Working knowledge of industry frameworks and standards (e.g. ISO 27005, ISO 42001, NIST CSF 2.0, NIST 800-53) and relevant regulations (e.g. GDPR, EU AI Principles) Solid understanding of security controls and experience supporting or performing control assessments and testing, with the ability to identify gaps and track remediation Experience with GRC tools (e.g. Diligent One GRC etc.) and risk tracking systems We actively encourage applications from groups traditionally underrepresented in the UK media We operate in a hybrid environment working 3 days a week from our offices in Kings Cross and 2 days a week remotely. We value and respect all differences (seen and unseen) in all people. We aspire to have inclusive working experiences and an environment that reflects the audience we serve, where our people have equal access to career development opportunities, their voices are heard and can contribute to our future. We actively encourage applications from people of all backgrounds. Many of our staff work flexibly and we will consider all requests for flexible working arrangements. How to apply To apply, please upload your latest CV and a cover letter which outlines why you'd love to take on this role, and why you're a great match for what we're looking for. We appreciate the time taken to prepare each application we receive. We do not use AI-assisted technology to review applications; every application is reviewed by a member of our recruitment team. The closing date for applications is Monday 11th May 2026. All roles at the Guardian are open for everybody to apply. It is important to us that you feel supported and comfortable throughout your recruitment process, in order to perform your best. Please let us know if there are any changes we could make to help your application, this includes providing documents in accessible formats or personalising the process to better support your needs. Please contact Anna Vipers on to discuss further so we can work with you to support you through your application. Benefits at the Guardian You'll have 30 days of annual leave per year (plus bank holidays) with the option to purchase an additional 5 days. Our pension scheme is generous; if you contribute 5% then we will contribute 8-12% (depending on your age). We believe in giving back, which is why employees are given 2 volunteering days annually and the option of payroll giving. Season ticket loans are also available. You are entitled to private healthcare, life cover, income protection, and eye tests. You can also opt in to dental insurance. We have enhanced maternity, paternity, adoption and shared parental leave policies in place. We also support our employees by offering an IVF, menopause, baby loss, and trans equality policy. Culture and wellbeing We want everyone to feel like they belong at the Guardian and we champion diversity of thought. Our various employee forums provide a platform to use their voice to foster an inclusive workplace. We became the first major media organisation to achieve B Corp status. We offer tools to help you prioritise your wellbeing including access to our employee benefits platform which provides tailored support for health and wellbeing. In addition, we also offer free yoga and pilates classes. These run alongside our corporate gym membership and cycle to work scheme. Our canteen has views overlooking the Regents Canal and caters for breakfast, lunch and dinner. Learning and development We encourage personal and professional growth. Employees have access to a broad range of tools and solutions, and we are happy to support the pursuit of professional qualifications through vocational courses and apprenticeships.
Lead Cyber Security Solution Architect - Banking - London - Up to 120,000 Basic Salary + Hybrid Working Overview We are seeking an experienced Lead Cyber Security Solution Architect to lead a team of Governance, Risk, and Control (GRC) specialists. This team is responsible for conducting Secure-by-Design assessments on technology projects, ensuring compliance with IT security policies and requirements. Role and Responsibilities Lead and manage the Secure-by-Design team across multiple business entities. Oversee security reviews for technology projects prior to implementation. Define KPIs for the team and monitor performance. Engage with business and technology stakeholders to assess technical and non-technical controls. Review reports and validate evidence of control effectiveness. Develop and implement testing strategies for IT security controls. Identify and document risks, gaps, findings, and recommend actions. Ensure timely completion of security assessments and manage team workload effectively. Essential Skills & Experience Proven ability to manage complex tasks with broad scope and ambiguity. Strong background in cybersecurity assurance, policies, and standards. Expertise across IT security domains: Governance, IAM, Risk Management, Security Testing, Incident Management, Vulnerability Management. Experience in senior stakeholder engagement and management reporting. Ability to coach and mentor team members. Deep understanding of IT security frameworks (SOX, FFIEC, ISO27001, NIST, PCI-DSS, Cloud Security Alliance). Strong managerial and leadership skills. Hands-on experience as an IT auditor, security auditor, or GRC analyst. Excellent planning, prioritization, and documentation skills. Broad technical knowledge of IT systems (OS, databases, firewalls, SIEM, DLP). Cloud Platforms: AWS and Azure. AI Knowledge: Understanding of AI principles and security implications. Solutions / Technical Network Architecture: Ability to design secure technical solutions and network architectures. Controls Experience: Strong background in implementing and assessing security controls. Splunk Knowledge: Familiarity with SIEM tools and log analysis. CyberArk: Experience with privileged access management solutions. Package Salary: Up to 120,000 Up to 20% Bonus Hybrid, with travel to London Career Development Opportunities Benefits: Pension scheme, professional training, paid holiday Lead Cyber Security Solution Architect - Banking - London - Up to 120,000 Basic Salary + Hybrid Working
Jan 21, 2026
Full time
Lead Cyber Security Solution Architect - Banking - London - Up to 120,000 Basic Salary + Hybrid Working Overview We are seeking an experienced Lead Cyber Security Solution Architect to lead a team of Governance, Risk, and Control (GRC) specialists. This team is responsible for conducting Secure-by-Design assessments on technology projects, ensuring compliance with IT security policies and requirements. Role and Responsibilities Lead and manage the Secure-by-Design team across multiple business entities. Oversee security reviews for technology projects prior to implementation. Define KPIs for the team and monitor performance. Engage with business and technology stakeholders to assess technical and non-technical controls. Review reports and validate evidence of control effectiveness. Develop and implement testing strategies for IT security controls. Identify and document risks, gaps, findings, and recommend actions. Ensure timely completion of security assessments and manage team workload effectively. Essential Skills & Experience Proven ability to manage complex tasks with broad scope and ambiguity. Strong background in cybersecurity assurance, policies, and standards. Expertise across IT security domains: Governance, IAM, Risk Management, Security Testing, Incident Management, Vulnerability Management. Experience in senior stakeholder engagement and management reporting. Ability to coach and mentor team members. Deep understanding of IT security frameworks (SOX, FFIEC, ISO27001, NIST, PCI-DSS, Cloud Security Alliance). Strong managerial and leadership skills. Hands-on experience as an IT auditor, security auditor, or GRC analyst. Excellent planning, prioritization, and documentation skills. Broad technical knowledge of IT systems (OS, databases, firewalls, SIEM, DLP). Cloud Platforms: AWS and Azure. AI Knowledge: Understanding of AI principles and security implications. Solutions / Technical Network Architecture: Ability to design secure technical solutions and network architectures. Controls Experience: Strong background in implementing and assessing security controls. Splunk Knowledge: Familiarity with SIEM tools and log analysis. CyberArk: Experience with privileged access management solutions. Package Salary: Up to 120,000 Up to 20% Bonus Hybrid, with travel to London Career Development Opportunities Benefits: Pension scheme, professional training, paid holiday Lead Cyber Security Solution Architect - Banking - London - Up to 120,000 Basic Salary + Hybrid Working