We are looking for an experienced GRC Manager to join a growing Information Security function within a PE-backed international organisation undergoing significant growth and transformation. Reporting directly to the Director of Information Security, you'll take ownership of Governance, Risk and Compliance activities across the business, with an immediate focus on supporting the organisation through ISO 27001 certification. This is an opportunity to have genuine ownership. We're not looking for someone who has simply contributed to GRC within a large team; we need someone who understands how to take frameworks, controls and best practice and implement them effectively within a lean, fast-moving organisation. The Role You'll take ownership across: Driving the organisation's ISO 27001 certification journey and ongoing ISMS maturity. Developing and maintaining security policies, standards and governance frameworks. Managing information security risks, risk registers, treatment plans and remediation. Coordinating audit evidence, control assessments and audit readiness. Supporting compliance with NIS2, NCSC CAF, GDPR and Cyber Essentials. Managing third-party security assessments, supplier assurance and customer security questionnaires. Producing meaningful security KPIs, KRIs and executive reporting. Working across IT, OT, Legal, Procurement, Operations and Commercial teams to drive security improvements. Supporting security awareness, business continuity and post-incident improvement activities. Continuously improving and automating GRC processes as the organisation grows. Experience The key requirement is someone who has personally helped take an organisation through ISO 27001 certification and understands what successful implementation looks like in practice. You'll ideally bring: Strong practical experience across information security Governance, Risk & Compliance. Experience developing or significantly maturing a GRC function or ISMS. End-to-end ownership of ISO 27001 controls, evidence, audits and remediation. Experience managing security risks and driving actions through to completion. Exposure to third-party/supplier assurance and customer security requirements. Knowledge of NIS2 would be particularly valuable. Excellent stakeholder management and communication skills. You'll need the confidence to challenge and influence people across the organisation, translating complex security risks into clear business language for audiences ranging from technical teams through to senior executives. We're open on industry background. More important is your ability to operate autonomously, adapt best practice to a lean environment and take genuine ownership rather than being one part of a large GRC function. Why Join? The organisation is undergoing significant growth, including acquisitions across Europe, making Information Security an important part of its wider transformation and value-creation strategy. You'll work directly with the Director of Information Security, have access to specialist external partners and wider group security expertise and can shape how GRC develops as the organisation continues to scale. There will also be occasional travel to other UK and European locations. At Gleeson Recruitment Group, we embrace inclusivity and welcome applicants of all backgrounds, experiences, and abilities. We are proud to be a disability confident employer. By applying you will be registered as a candidate with Gleeson Recruitment Limited. Our Privacy Policy is available on our website and explains how we will use your data.
Aug 26, 2026
Full time
We are looking for an experienced GRC Manager to join a growing Information Security function within a PE-backed international organisation undergoing significant growth and transformation. Reporting directly to the Director of Information Security, you'll take ownership of Governance, Risk and Compliance activities across the business, with an immediate focus on supporting the organisation through ISO 27001 certification. This is an opportunity to have genuine ownership. We're not looking for someone who has simply contributed to GRC within a large team; we need someone who understands how to take frameworks, controls and best practice and implement them effectively within a lean, fast-moving organisation. The Role You'll take ownership across: Driving the organisation's ISO 27001 certification journey and ongoing ISMS maturity. Developing and maintaining security policies, standards and governance frameworks. Managing information security risks, risk registers, treatment plans and remediation. Coordinating audit evidence, control assessments and audit readiness. Supporting compliance with NIS2, NCSC CAF, GDPR and Cyber Essentials. Managing third-party security assessments, supplier assurance and customer security questionnaires. Producing meaningful security KPIs, KRIs and executive reporting. Working across IT, OT, Legal, Procurement, Operations and Commercial teams to drive security improvements. Supporting security awareness, business continuity and post-incident improvement activities. Continuously improving and automating GRC processes as the organisation grows. Experience The key requirement is someone who has personally helped take an organisation through ISO 27001 certification and understands what successful implementation looks like in practice. You'll ideally bring: Strong practical experience across information security Governance, Risk & Compliance. Experience developing or significantly maturing a GRC function or ISMS. End-to-end ownership of ISO 27001 controls, evidence, audits and remediation. Experience managing security risks and driving actions through to completion. Exposure to third-party/supplier assurance and customer security requirements. Knowledge of NIS2 would be particularly valuable. Excellent stakeholder management and communication skills. You'll need the confidence to challenge and influence people across the organisation, translating complex security risks into clear business language for audiences ranging from technical teams through to senior executives. We're open on industry background. More important is your ability to operate autonomously, adapt best practice to a lean environment and take genuine ownership rather than being one part of a large GRC function. Why Join? The organisation is undergoing significant growth, including acquisitions across Europe, making Information Security an important part of its wider transformation and value-creation strategy. You'll work directly with the Director of Information Security, have access to specialist external partners and wider group security expertise and can shape how GRC develops as the organisation continues to scale. There will also be occasional travel to other UK and European locations. At Gleeson Recruitment Group, we embrace inclusivity and welcome applicants of all backgrounds, experiences, and abilities. We are proud to be a disability confident employer. By applying you will be registered as a candidate with Gleeson Recruitment Limited. Our Privacy Policy is available on our website and explains how we will use your data.
About the job Job summary Discover what it's like to work in a compliance role that makes an impact. Could you help us shape a stronger, fairer future? Your next career move starts here. HMRC's Fraud Investigation Service (FIS) is responsible for the department's civil and criminal investigations. Covert Operations, Digital Exploitation (CODE) sits within FIS. Working across Law Enforcement and government, CODE provides investigative tools and covert techniques to front-line investigations and works with key partners to develop and provide access to new technology and systems to enable investigators to respond to serious and complex tax evasion and crime. Working across Law Enforcement and government, CODE provides investigative tools and covert techniques to front-line investigations and works with key partners to develop and provide access to new technology and systems to enable investigators to respond to serious and complex tax evasion and crime. Job description As a Digital Portfolio Manager in the Capability Development, Infrastructure and Innovation team within CODE, you will play a crucial role in supporting His Majesty's Government in the fight against serious and organised crime. Your work will directly contribute to high-profile investigations, helping to recover and protect hundreds of millions of pounds annually through innovative technical solutions. The team manages a diverse and rapidly expanding portfolio of projects, ranging from the development of bespoke forensic tools tailored to highly specific investigative needs, to the design and implementation of scalable data visualisation platforms that enhance analytical capabilities. You will collaborate closely with law enforcement agencies, intelligence teams, and external partners to ensure that cutting-edge technology is leveraged effectively in tackling financial crime, cyber threats, and fraud. This role offers an exciting opportunity to work at the forefront of data engineering within a mission-driven environment, where your expertise will help shape the future of digital investigations and forensic analysis. Person specification The CODE Tech Portfolio Office (PO) is a critical enabler of both project delivery and business as usual across CODE's responsibilities. The Portfolio Office acts as the fulcrum between business needs, project delivery, suppliers, commercial processes, and external partners, ensuring that complex, sensitive, and high risk technology initiatives are aligned, governed, and delivered effectively. This role supports the Portfolio Lead by taking delegated responsibility for defined elements of portfolio coordination, commercial and supplier engagement, project stewardship, and stakeholder management. The post holder will operate across all CODE's environments and work closely with internal delivery teams, commercial colleagues, external suppliers, and UK and international partners. This role aligns to the Digital Portfolio Manager profession and capability framework, with a focus on supporting and enabling portfolio level outcomes more than direct project management. Key Responsibilities Portfolio Coordination and Planning Support the coordination of the CODE Tech portfolio, ensuring alignment between business requirements, delivery activity, supplier capability, and strategic outcomes. Contribute to portfolio planning, prioritisation, and analysis, supporting the development and maintenance of a coherent, deliverable pipeline of work. Provide subject matter expertise on the interaction between requirements, supplier solutions, and delivery outcomes, supporting informed decision making across the portfolio. Commercial and Supplier Engagement Undertake delegated commercial and supplier management activity, including smaller and less complex commercial engagements arising from projects and BAU activity. Work closely with CODE Commercial and Departmental Commercial teams to coordinate activity and ensure effective hand offs and shared visibility of upcoming demands. Maintain portfolio level oversight of supplier engagement where activity is constrained by classification, ensuring that requirements are articulated and translated appropriately for wider commercial use. Engage directly with suppliers and partners under the direction of the Portfolio Lead. Project and Delivery Stewardship Provide portfolio level stewardship of projects, supporting effective engagement between project managers, suppliers, and business stakeholders. Undertake delegated responsibility for regulatory engagement related to the portfolio, including coordinating inspections and associated portfolio level responses. Support problem management post implementation, acting as a subject matter expert to assist service and support functions where required. Deputise for the Portfolio Lead at selected internal and external meetings, representing HMRC interests where appropriate. Stakeholder Management and Collaboration Engage with a wide range of internal and external stakeholders, including delivery teams, business management, commercial colleagues, regulators, and UK or international. Support cross functional collaboration to ensure that portfolio activity is joined up, well understood, and effectively governed. Contribute to clear communication of portfolio priorities, risks, and constraints to stakeholders. Continuous Improvement and Portfolio Maturity Contribute to the development and maturity of the CODE Tech Portfolio Office, supporting rebalancing of workload and improved resilience. Identify opportunities to improve portfolio processes, governance, and ways of working, particularly in sensitive environments. Essential Criteria: Experience working in or supporting a portfolio, programme, or complex delivery environment, ideally from a digital or civils background, rather than single project delivery. Experience of stakeholder management across multiple functions, including delivery, commercial, and external partners. Experience of using the relationship between business requirements, supplier capability, and delivery outcomes. Experience supporting or coordinating commercial or supplier engagement within a structured governance framework Experience of working confidently with sensitive and classified information, exercising sound judgement and discretion. Strong organisational and analytical skills, with the ability to manage competing priorities. Familiarity with Government or large organisation commercial processes and working alongside commercial teams. Additional Security Information The successful candidate will be required to apply for Developed Vetting (DV) clearance level once in post but must already hold or be willing to obtain Security Check (SC) clearance level before starting the role. In addition to the standard pre-employment checks for appointment into the Civil Service, all candidates must also obtain National Security Vetting at Security Check (SC) clearance level for this vacancy. You will normally need to meet the minimum UK residency period as determined by the level of vetting being undertaken, which for SC is 5 years UK residency prior to your vetting application. Once in post you will be required to apply for Developed Vetting ( DV ) clearance which has a requirement for 10 years UK residency. If you have any questions about this residency requirement, please speak to the vacancy holder for this post. This post is open to 'UK Nationals Only' Technical skills We'll assess you against these technical skills during the selection process: Stakeholder relationship management Agile working Governance and assurance. Benefits Alongside your salary of £50,686, HM Revenue and Customs contributes £14,683 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window). HMRC operates both Flexible and Hybrid Working policies, allowing you to balance your work and personal commitments. We welcome applications from those who need to work a more flexible arrangement and will agree to requests where possible, considering our operational and customer service needs. We offer a generous leave allowance, starting at 25 days and increasing by a day for every year of qualifying service up to a maximum of 30 days. Pension - We make contributions to our colleagues' Alpha pension equal to at least 28.97% of their salary. Family friendly policies. Personal support. Coaching and development. To find out more about HMRC benefits and find out what it's really like to work for HMRC hear from our insiders or visit Thinking of joining the Civil Service Things you need to know Artificial intelligence Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use. Selection process details . click apply for full job details
Aug 26, 2026
Full time
About the job Job summary Discover what it's like to work in a compliance role that makes an impact. Could you help us shape a stronger, fairer future? Your next career move starts here. HMRC's Fraud Investigation Service (FIS) is responsible for the department's civil and criminal investigations. Covert Operations, Digital Exploitation (CODE) sits within FIS. Working across Law Enforcement and government, CODE provides investigative tools and covert techniques to front-line investigations and works with key partners to develop and provide access to new technology and systems to enable investigators to respond to serious and complex tax evasion and crime. Working across Law Enforcement and government, CODE provides investigative tools and covert techniques to front-line investigations and works with key partners to develop and provide access to new technology and systems to enable investigators to respond to serious and complex tax evasion and crime. Job description As a Digital Portfolio Manager in the Capability Development, Infrastructure and Innovation team within CODE, you will play a crucial role in supporting His Majesty's Government in the fight against serious and organised crime. Your work will directly contribute to high-profile investigations, helping to recover and protect hundreds of millions of pounds annually through innovative technical solutions. The team manages a diverse and rapidly expanding portfolio of projects, ranging from the development of bespoke forensic tools tailored to highly specific investigative needs, to the design and implementation of scalable data visualisation platforms that enhance analytical capabilities. You will collaborate closely with law enforcement agencies, intelligence teams, and external partners to ensure that cutting-edge technology is leveraged effectively in tackling financial crime, cyber threats, and fraud. This role offers an exciting opportunity to work at the forefront of data engineering within a mission-driven environment, where your expertise will help shape the future of digital investigations and forensic analysis. Person specification The CODE Tech Portfolio Office (PO) is a critical enabler of both project delivery and business as usual across CODE's responsibilities. The Portfolio Office acts as the fulcrum between business needs, project delivery, suppliers, commercial processes, and external partners, ensuring that complex, sensitive, and high risk technology initiatives are aligned, governed, and delivered effectively. This role supports the Portfolio Lead by taking delegated responsibility for defined elements of portfolio coordination, commercial and supplier engagement, project stewardship, and stakeholder management. The post holder will operate across all CODE's environments and work closely with internal delivery teams, commercial colleagues, external suppliers, and UK and international partners. This role aligns to the Digital Portfolio Manager profession and capability framework, with a focus on supporting and enabling portfolio level outcomes more than direct project management. Key Responsibilities Portfolio Coordination and Planning Support the coordination of the CODE Tech portfolio, ensuring alignment between business requirements, delivery activity, supplier capability, and strategic outcomes. Contribute to portfolio planning, prioritisation, and analysis, supporting the development and maintenance of a coherent, deliverable pipeline of work. Provide subject matter expertise on the interaction between requirements, supplier solutions, and delivery outcomes, supporting informed decision making across the portfolio. Commercial and Supplier Engagement Undertake delegated commercial and supplier management activity, including smaller and less complex commercial engagements arising from projects and BAU activity. Work closely with CODE Commercial and Departmental Commercial teams to coordinate activity and ensure effective hand offs and shared visibility of upcoming demands. Maintain portfolio level oversight of supplier engagement where activity is constrained by classification, ensuring that requirements are articulated and translated appropriately for wider commercial use. Engage directly with suppliers and partners under the direction of the Portfolio Lead. Project and Delivery Stewardship Provide portfolio level stewardship of projects, supporting effective engagement between project managers, suppliers, and business stakeholders. Undertake delegated responsibility for regulatory engagement related to the portfolio, including coordinating inspections and associated portfolio level responses. Support problem management post implementation, acting as a subject matter expert to assist service and support functions where required. Deputise for the Portfolio Lead at selected internal and external meetings, representing HMRC interests where appropriate. Stakeholder Management and Collaboration Engage with a wide range of internal and external stakeholders, including delivery teams, business management, commercial colleagues, regulators, and UK or international. Support cross functional collaboration to ensure that portfolio activity is joined up, well understood, and effectively governed. Contribute to clear communication of portfolio priorities, risks, and constraints to stakeholders. Continuous Improvement and Portfolio Maturity Contribute to the development and maturity of the CODE Tech Portfolio Office, supporting rebalancing of workload and improved resilience. Identify opportunities to improve portfolio processes, governance, and ways of working, particularly in sensitive environments. Essential Criteria: Experience working in or supporting a portfolio, programme, or complex delivery environment, ideally from a digital or civils background, rather than single project delivery. Experience of stakeholder management across multiple functions, including delivery, commercial, and external partners. Experience of using the relationship between business requirements, supplier capability, and delivery outcomes. Experience supporting or coordinating commercial or supplier engagement within a structured governance framework Experience of working confidently with sensitive and classified information, exercising sound judgement and discretion. Strong organisational and analytical skills, with the ability to manage competing priorities. Familiarity with Government or large organisation commercial processes and working alongside commercial teams. Additional Security Information The successful candidate will be required to apply for Developed Vetting (DV) clearance level once in post but must already hold or be willing to obtain Security Check (SC) clearance level before starting the role. In addition to the standard pre-employment checks for appointment into the Civil Service, all candidates must also obtain National Security Vetting at Security Check (SC) clearance level for this vacancy. You will normally need to meet the minimum UK residency period as determined by the level of vetting being undertaken, which for SC is 5 years UK residency prior to your vetting application. Once in post you will be required to apply for Developed Vetting ( DV ) clearance which has a requirement for 10 years UK residency. If you have any questions about this residency requirement, please speak to the vacancy holder for this post. This post is open to 'UK Nationals Only' Technical skills We'll assess you against these technical skills during the selection process: Stakeholder relationship management Agile working Governance and assurance. Benefits Alongside your salary of £50,686, HM Revenue and Customs contributes £14,683 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides (opens in a new window). HMRC operates both Flexible and Hybrid Working policies, allowing you to balance your work and personal commitments. We welcome applications from those who need to work a more flexible arrangement and will agree to requests where possible, considering our operational and customer service needs. We offer a generous leave allowance, starting at 25 days and increasing by a day for every year of qualifying service up to a maximum of 30 days. Pension - We make contributions to our colleagues' Alpha pension equal to at least 28.97% of their salary. Family friendly policies. Personal support. Coaching and development. To find out more about HMRC benefits and find out what it's really like to work for HMRC hear from our insiders or visit Thinking of joining the Civil Service Things you need to know Artificial intelligence Artificial intelligence can be a useful tool to support your application, however, all examples and statements provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, as your own) applications may be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance (opens in a new window) for more information on appropriate and inappropriate use. Selection process details . click apply for full job details
Trusted Connectivity for AI-Powered Dominance. Everfox delivers trusted connectivity to protect the world's most critical environments and safeguard the sensitive data powering decision advantage. Built for mission-critical operations, Everfox protects what matters most by securing how data moves, how users access it, and how threats are neutralized across every domain. We enable mission speed and secure collaboration across networks, domains, and allies, while ensuring the data powering AI and advanced analytics remains trusted and protected. We don't just defend systems; we deliver decision dominance. Our Purpose. Protect what matters most by enabling organizations to operate security in the most complex and high-risk digital environments. Our Vision. To be the most trusted authority in high-assurance cybersecurity, enabling secure collaboration across every domain. Our Belief. Security should never limit mission success - it should enable it. Our Promise. We deliver absolute confidence in environments where failure is not an option. About the role: Location: London, United Kingdom (Hybrid, 2-3 days per week) Key Responsibilities: Build proactive talent pipelines and sourcing strategies for priority and hard to fill roles, applying market intelligence and competitive insights to improve sourcing effectiveness. Manage end to end hiring-from intake, assessment, and structured interviews through offer acceptance-while coaching hiring teams on interviewing effectiveness and selection quality. Act as a trusted advisor to hiring leaders, influencing hiring decisions with candidate insights, labor market data, and workforce trends. Optimize recruiting workflows to improve recruiter, candidate, and hiring manager experience; maintain ATS data integrity and consistent process execution. Interpret workforce trends and advise leaders proactively on pipeline health, talent availability, and competitive dynamics to align recruiting with business demand. Strengthen candidate experience and partner with stakeholders to enhance employer brand positioning and engagement strategies. Align recruiting priorities to workforce demand and business objectives across London and European hiring needs, anticipating future talent requirements. Contribute to scalable recruiting operations, continuous improvement initiatives, and data driven hiring recommendations; mentor peers and support team capability growth through expertise and influence. Key Knowledge and Skills: Advanced sourcing: market mapping, talent pipelining, and competitive research; expert use of LinkedIn and sourcing tools. Assessment excellence: structured interviewing, rubric based evaluation, and coaching hiring teams to improve selection quality. Stakeholder partnership: trusted advisor to senior hiring leaders; confident influencing decisions with data and market insights. Process optimization: full cycle recruiting with workflow improvements that elevate recruiter, candidate, and hiring manager experience. Data & insights: apply recruiting analytics and labor market intelligence to recommendations; interpret workforce trends to guide leaders. Candidate & employer experience: strengthen employer brand positioning, engagement strategies, and consistent candidate communications. Business alignment: align recruiting priorities to business objectives; anticipate future needs and advise proactively. Leadership contribution: mentor others and lead initiatives through expertise and influence (without direct people management). Experience with Workday ATS preferred. Key Education Requirements: Bachelor's degree (or equivalent experience) in Human Resources, Business, or a related field. 6-10+ years of progressive, full lifecycle recruiting experience, ideally within technology, cybersecurity, defense, or regulated environments. Proficiency with ATS/CRM platforms and recruiting analytics tools; strong familiarity with UK/EU hiring practices and compliance. Relevant certifications (e.g., CIPD, AIRS, Social Talent) are beneficial. Success Indicators: Pipeline health and time to fill for priority roles meet or exceed targets; improved offer acceptance and quality of hire outcomes. Positive candidate experience and hiring manager satisfaction; strengthened employer brand engagement. Data driven, proactive workforce insights influence hiring plans and reduce talent risk across London/EU markets. A reasonable estimate of the base salary range for this role is: £69,900.00-97,700.00 GBP The actual salary offered may vary within the range based on a candidates' unique experience, locale, and business needs. In addition to base salary and either bonus or commission, Everfox offers a generous benefits package including competitive annual leave, pension match, PMI, dental, health cash plan, income protection, in a hybrid work environment. competitive annual leave pension match PMI dental health cash plan income protection Everfox is an equal employment opportunity employer and complies with all applicable federal, state, and local laws prohibiting discrimination. Everfox does not discriminate against any employee or applicant based on race, color, religion, sex, age, national origin, disability, veteran status, marital status, medical condition, or any other category protected by applicable law. If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to use or access the Company's career webpage as a result of your disability. You may request reasonable accommodations by sending an email to . Applicants must have the right to work in the location to which you have applied. Everfox delivers trusted connectivity to protect the world's most critical environments and safeguard the sensitive data powering decision advantage. Built for mission-critical operations, Everfox protects what matters most by securing how data moves, how users access it, and how threats are neutralized across every domain. We enable mission speed and secure collaboration across networks, domains, and allies, while ensuring the data powering AI and advanced analytics remains trusted and protected. We don't just defend systems; we deliver decision dominance. Our Purpose. Protect what matters most by enabling organizations to operate security in the most complex and high-risk digital environments. Our Vision. To be the most trusted authority in high-assurance cybersecurity, enabling secure collaboration across every domain. Our Belief. Security should never limit mission success - it should enable it. Our Promise. We deliver absolute confidence in environments where failure is not an option.
Aug 26, 2026
Full time
Trusted Connectivity for AI-Powered Dominance. Everfox delivers trusted connectivity to protect the world's most critical environments and safeguard the sensitive data powering decision advantage. Built for mission-critical operations, Everfox protects what matters most by securing how data moves, how users access it, and how threats are neutralized across every domain. We enable mission speed and secure collaboration across networks, domains, and allies, while ensuring the data powering AI and advanced analytics remains trusted and protected. We don't just defend systems; we deliver decision dominance. Our Purpose. Protect what matters most by enabling organizations to operate security in the most complex and high-risk digital environments. Our Vision. To be the most trusted authority in high-assurance cybersecurity, enabling secure collaboration across every domain. Our Belief. Security should never limit mission success - it should enable it. Our Promise. We deliver absolute confidence in environments where failure is not an option. About the role: Location: London, United Kingdom (Hybrid, 2-3 days per week) Key Responsibilities: Build proactive talent pipelines and sourcing strategies for priority and hard to fill roles, applying market intelligence and competitive insights to improve sourcing effectiveness. Manage end to end hiring-from intake, assessment, and structured interviews through offer acceptance-while coaching hiring teams on interviewing effectiveness and selection quality. Act as a trusted advisor to hiring leaders, influencing hiring decisions with candidate insights, labor market data, and workforce trends. Optimize recruiting workflows to improve recruiter, candidate, and hiring manager experience; maintain ATS data integrity and consistent process execution. Interpret workforce trends and advise leaders proactively on pipeline health, talent availability, and competitive dynamics to align recruiting with business demand. Strengthen candidate experience and partner with stakeholders to enhance employer brand positioning and engagement strategies. Align recruiting priorities to workforce demand and business objectives across London and European hiring needs, anticipating future talent requirements. Contribute to scalable recruiting operations, continuous improvement initiatives, and data driven hiring recommendations; mentor peers and support team capability growth through expertise and influence. Key Knowledge and Skills: Advanced sourcing: market mapping, talent pipelining, and competitive research; expert use of LinkedIn and sourcing tools. Assessment excellence: structured interviewing, rubric based evaluation, and coaching hiring teams to improve selection quality. Stakeholder partnership: trusted advisor to senior hiring leaders; confident influencing decisions with data and market insights. Process optimization: full cycle recruiting with workflow improvements that elevate recruiter, candidate, and hiring manager experience. Data & insights: apply recruiting analytics and labor market intelligence to recommendations; interpret workforce trends to guide leaders. Candidate & employer experience: strengthen employer brand positioning, engagement strategies, and consistent candidate communications. Business alignment: align recruiting priorities to business objectives; anticipate future needs and advise proactively. Leadership contribution: mentor others and lead initiatives through expertise and influence (without direct people management). Experience with Workday ATS preferred. Key Education Requirements: Bachelor's degree (or equivalent experience) in Human Resources, Business, or a related field. 6-10+ years of progressive, full lifecycle recruiting experience, ideally within technology, cybersecurity, defense, or regulated environments. Proficiency with ATS/CRM platforms and recruiting analytics tools; strong familiarity with UK/EU hiring practices and compliance. Relevant certifications (e.g., CIPD, AIRS, Social Talent) are beneficial. Success Indicators: Pipeline health and time to fill for priority roles meet or exceed targets; improved offer acceptance and quality of hire outcomes. Positive candidate experience and hiring manager satisfaction; strengthened employer brand engagement. Data driven, proactive workforce insights influence hiring plans and reduce talent risk across London/EU markets. A reasonable estimate of the base salary range for this role is: £69,900.00-97,700.00 GBP The actual salary offered may vary within the range based on a candidates' unique experience, locale, and business needs. In addition to base salary and either bonus or commission, Everfox offers a generous benefits package including competitive annual leave, pension match, PMI, dental, health cash plan, income protection, in a hybrid work environment. competitive annual leave pension match PMI dental health cash plan income protection Everfox is an equal employment opportunity employer and complies with all applicable federal, state, and local laws prohibiting discrimination. Everfox does not discriminate against any employee or applicant based on race, color, religion, sex, age, national origin, disability, veteran status, marital status, medical condition, or any other category protected by applicable law. If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to use or access the Company's career webpage as a result of your disability. You may request reasonable accommodations by sending an email to . Applicants must have the right to work in the location to which you have applied. Everfox delivers trusted connectivity to protect the world's most critical environments and safeguard the sensitive data powering decision advantage. Built for mission-critical operations, Everfox protects what matters most by securing how data moves, how users access it, and how threats are neutralized across every domain. We enable mission speed and secure collaboration across networks, domains, and allies, while ensuring the data powering AI and advanced analytics remains trusted and protected. We don't just defend systems; we deliver decision dominance. Our Purpose. Protect what matters most by enabling organizations to operate security in the most complex and high-risk digital environments. Our Vision. To be the most trusted authority in high-assurance cybersecurity, enabling secure collaboration across every domain. Our Belief. Security should never limit mission success - it should enable it. Our Promise. We deliver absolute confidence in environments where failure is not an option.
Isr Recruitment Limited
Eaglescliffe, County Durham
The Opportunity Our client is looking to appoint an experienced ICT Cyber & Information Security Manager to take responsibility for a broad range of cyber security, information security, risk and compliance activities across the organisation. This is a key role within the Information Security function, providing the opportunity to take ownership of security activities ranging from the ICT Annual Delivery Plan through to major business growth initiatives, including site transitions and acquisitions across the UK and internationally. You'll work closely with internal teams, senior stakeholders and external partners to strengthen the organisation's cyber and information security posture, manage risk and ensure compliance with relevant security standards and legislation. The successful candidate will combine strong technical security knowledge with excellent governance, risk management and stakeholder-management skills. Skills and Experience: Experience leading cyber security, information security and/or compliance activities within a medium-to-large enterprise environment. Strong experience managing an enterprise information/cyber security risk register. Strong practical knowledge of Information Security Management Systems (ISMS). Experience implementing, maintaining and continually improving an ISMS. Experience preparing for and participating in internal and external security audits. Strong knowledge of ISO 27002 and experience delivering against its requirements. Strong knowledge of Cyber Essentials / Cyber Essentials Plus. Experience working with NIST security frameworks. Knowledge of CAF / Cyber Assessment Framework and its application to organisational security. Understanding of NIS2, GDPR and the Data Protection Act. Strong understanding of cyber security risk, governance, controls and remediation. Qualifications Professional security qualifications such as the following would be highly desirable: CISSP / CISM / CISA ISO 27001/27002-related qualifications Other recognised cyber security, information assurance or risk-management certifications Role and Responsibilities: Act as a key pillar of the organisation's Information Security programme, driving and managing cyber and information security activities. Work collaboratively with internal teams and external partners to deliver security initiatives and improvements. Develop, review and rehearse incident response plans, ensuring the organisation is prepared to detect, investigate and respond effectively to cyber incidents and data breaches. Work with relevant teams to review, test and improve Business Continuity, Recovery Time Objective (RTO) and Recovery Time Strategy (RTS) arrangements. Conduct and support security risk assessments and vulnerability assessments to identify threats, vulnerabilities and areas for improvement. Develop and implement appropriate risk mitigation strategies. Manage and maintain ICT Cyber & Data Security Risk Registers, ensuring risks are appropriately assessed, owned, mitigated and reported. Review, develop, implement and maintain cyber security, information security, data protection and compliance policies. Monitor changes in the regulatory and threat landscape and assess their impact on the organisation. Ensure compliance with relevant legislation, regulations, frameworks and security standards, including GDPR, Data Protection Act, NIS2, NIST, Cyber Essentials and ISO 27002. Lead and coordinate information security metrics, reporting and management information. Support and oversee offensive security activities, vulnerability management and security testing. Maintain and continuously improve the organisation's Information Security Management System (ISMS). Lead or participate in internal and external security audits and assessments, including ISO 27002 and Cyber Essentials Plus. Provide security input into business change, technology projects, acquisitions, site transitions and other strategic initiatives. Work with stakeholders to embed security by design across ICT and wider business activities. Applications: To learn more about our established client and this newly created role working as a IT Security Manager for our client based in the Teesside / County Durham area (with excellent flexible/remote working options available); please call and speak with Edward Laing here at ISR Recruitment to learn more or please send through a copy of your latest CV and/or share your online business profile for a call back in the very strictest of confidence.
Aug 24, 2026
Full time
The Opportunity Our client is looking to appoint an experienced ICT Cyber & Information Security Manager to take responsibility for a broad range of cyber security, information security, risk and compliance activities across the organisation. This is a key role within the Information Security function, providing the opportunity to take ownership of security activities ranging from the ICT Annual Delivery Plan through to major business growth initiatives, including site transitions and acquisitions across the UK and internationally. You'll work closely with internal teams, senior stakeholders and external partners to strengthen the organisation's cyber and information security posture, manage risk and ensure compliance with relevant security standards and legislation. The successful candidate will combine strong technical security knowledge with excellent governance, risk management and stakeholder-management skills. Skills and Experience: Experience leading cyber security, information security and/or compliance activities within a medium-to-large enterprise environment. Strong experience managing an enterprise information/cyber security risk register. Strong practical knowledge of Information Security Management Systems (ISMS). Experience implementing, maintaining and continually improving an ISMS. Experience preparing for and participating in internal and external security audits. Strong knowledge of ISO 27002 and experience delivering against its requirements. Strong knowledge of Cyber Essentials / Cyber Essentials Plus. Experience working with NIST security frameworks. Knowledge of CAF / Cyber Assessment Framework and its application to organisational security. Understanding of NIS2, GDPR and the Data Protection Act. Strong understanding of cyber security risk, governance, controls and remediation. Qualifications Professional security qualifications such as the following would be highly desirable: CISSP / CISM / CISA ISO 27001/27002-related qualifications Other recognised cyber security, information assurance or risk-management certifications Role and Responsibilities: Act as a key pillar of the organisation's Information Security programme, driving and managing cyber and information security activities. Work collaboratively with internal teams and external partners to deliver security initiatives and improvements. Develop, review and rehearse incident response plans, ensuring the organisation is prepared to detect, investigate and respond effectively to cyber incidents and data breaches. Work with relevant teams to review, test and improve Business Continuity, Recovery Time Objective (RTO) and Recovery Time Strategy (RTS) arrangements. Conduct and support security risk assessments and vulnerability assessments to identify threats, vulnerabilities and areas for improvement. Develop and implement appropriate risk mitigation strategies. Manage and maintain ICT Cyber & Data Security Risk Registers, ensuring risks are appropriately assessed, owned, mitigated and reported. Review, develop, implement and maintain cyber security, information security, data protection and compliance policies. Monitor changes in the regulatory and threat landscape and assess their impact on the organisation. Ensure compliance with relevant legislation, regulations, frameworks and security standards, including GDPR, Data Protection Act, NIS2, NIST, Cyber Essentials and ISO 27002. Lead and coordinate information security metrics, reporting and management information. Support and oversee offensive security activities, vulnerability management and security testing. Maintain and continuously improve the organisation's Information Security Management System (ISMS). Lead or participate in internal and external security audits and assessments, including ISO 27002 and Cyber Essentials Plus. Provide security input into business change, technology projects, acquisitions, site transitions and other strategic initiatives. Work with stakeholders to embed security by design across ICT and wider business activities. Applications: To learn more about our established client and this newly created role working as a IT Security Manager for our client based in the Teesside / County Durham area (with excellent flexible/remote working options available); please call and speak with Edward Laing here at ISR Recruitment to learn more or please send through a copy of your latest CV and/or share your online business profile for a call back in the very strictest of confidence.
# Workday Project ManagerBirmingham, Glasgow, London, Manchester, WorthingApply for this job Permanent Experienced Professionals SaaS Solutions ID 507603-en\_GB About the job you're considering We are looking for an experienced Workday Engagement Manager to join our growing Workday Practice and lead the successful delivery of Workday engagements for our clients. This is a client-facing delivery leadership role for someone who combines strong project and programme management capability with commercial awareness, stakeholder leadership and a practical understanding of Workday delivery. You will take accountability for the delivery of Workday engagements, working with client sponsors, delivery leaders, functional and technical teams, commercial stakeholders, and account teams to deliver high-quality outcomes. You will also contribute to the continued growth of our Workday capability by supporting pre-sales activity, strengthening delivery governance, developing reusable delivery assets, and sharing knowledge across the practice. Your Role As a Workday Engagement Manager, you will act as the primary delivery lead for Workday implementation, enhancement and optimisation engagements. You will manage the end-to-end delivery lifecycle, create the conditions for effective project execution, and ensure that scope, timeline, budget, quality, risk, commercial performance and client satisfaction are actively managed throughout the engagement. You will be expected to bring a modern consulting mindset: outcome-focused, commercially aware, structured in delivery, confident with senior stakeholders and comfortable helping clients adopt Workday capabilities, data-led decision-making, automation and emerging AI-enabled functionality responsibly and effectively. Engagement delivery and governance Lead the end-to-end delivery of Workday implementation, enhancement and optimisation projects, ensuring engagements are delivered to agreed scope, quality, timeline and budget expectations. Own and maintain robust project governance, including plans, RAID management, status reporting, decision tracking, change control, dependency management and delivery assurance inputs. Client leadership and stakeholder management Act as a trusted delivery partner and primary point of contact for client stakeholders throughout the engagement lifecycle. Build and maintain strong relationships with client sponsors, programme leaders, HR, Finance, IT and operational stakeholders. Commercial, risk and quality management Manage engagement commercials, including forecast, budget, profitability, resource demand, scope control and change management within agreed governance. Ensure delivery quality through effective governance, review points, risk management, assurance activity and adherence to Workday and Capgemini delivery methods. Team leadership and practice contribution Lead, motivate and coordinate diverse delivery teams across onshore, nearshore and offshore locations. Create clarity for teams by setting expectations, managing workload, removing blockers and promoting collaborative ways of working. Your skills and experience Proven experience leading technology or Workday implementation engagements in a consultancy or professional services environment. Current Workday Services Partner certification as an Engagement Manager/Project Manager Strong understanding of Workday delivery lifecycles, deployment methodologies and the practical realities of delivering HCM, Finance, Payroll, Recruiting or broader Workday programmes. Demonstrable experience managing scope, plans, resources, budgets, risks, issues, dependencies, quality standards and profitability targets. Ability to lead diverse project teams and coordinate activity across functional, technical, data, testing, change and deployment workstreams. Strong client-facing skills, with the confidence to engage senior stakeholders, manage expectations and translate delivery complexity into clear business language. Commercial awareness and experience supporting statements of work, change control, delivery estimates, governance reporting and project financial management. Excellent communication, facilitation, problem-solving and organisational skills, with a structured and proactive approach to delivery leadership. Experience working across onshore, nearshore and offshore delivery models with multi-disciplinary and geographically distributed teams. A practical, inclusive and outcome-focused leadership style, with a willingness to coach others and contribute to the wider practice. Desirable experience Experience managing complex or multi-workstream Workday programmes, including senior stakeholder governance and delivery recovery activity. Experience supporting pre-sales, bid responses, solution proposals, mobilisation planning, commercial shaping or client demonstrations. Awareness of Workday HCM, Finance, Payroll, Recruiting, Talent, Absence, Time Tracking, Integrations, Security, Reporting, Extend or broader enterprise architecture considerations. Understanding of responsible AI adoption in HR and Finance transformation, including data readiness, governance, explainability, adoption and change considerations. Professional project or programme management qualification such as PRINCE2, PMP, MSP, Agile or equivalent practical delivery experience. We are a Disability Confident Employer Capgemini is proud to be a Disability Confident Employer (Level 2) under the UK Government's Disability Confident scheme.As part of our commitment to inclusive recruitment, we will offer an interview to all candidates who:Declare they have a disability, and Meet the minimum essential criteria for the role.Please opt in during the application process. Your security clearance and pre-employment checks If you are successfully offered this position, you will go through a series of pre-employment checks, including: identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service) To be successfully appointed to this role, it is a requirement to obtain Security Check (SC) clearance. To obtain SC clearance, the successful applicant must have resided continuously within the United Kingdom for the last 5 years, along with other criteria and requirements. Throughout the recruitment process, you will be asked questions about your security clearance eligibility such as, but not limited to, country of residence and nationality. Some posts are restricted to sole UK Nationals for security reasons; therefore, you may be asked about your citizenship in the application process. Make it real - what does it mean for you? Shape Your Path You will be empowered to explore, innovate, and progress. You will benefit from Capgemini's 'learning for life' mindset, meaning you will have countless training and development opportunities from thinktanks to hackathons, and access to 250,000 courses with numerous external certifications from AWS, Microsoft, Harvard ManageMentor, Cybersecurity qualifications and much more.Flexibility to work your way You will be encouraged to have a positive work-life balance. Our hybrid-first way of working means we embed hybrid working in all that we do and make flexible working arrangements the day-to-day reality for our people. All UK employees are eligible to request flexible working arrangements. Why you should consider Capgemini Growing clients' businesses while building a more sustainable, more inclusive future is a tough ask. When you join Capgemini, you'll join a thriving company and become part of a collective of free-thinkers, entrepreneurs and industry experts. We find new ways technology can help us reimagine what's possible. It's why, together, we seek out opportunities that will transform the world's leading businesses, and it's how you'll gain the experiences and connections you need to shape your future. By learning from each other every day, sharing knowledge, and always pushing yourself to do better, you'll build the skills you want. You'll use your skills to help our clients leverage technology to innovate and grow their business. So, it might not always be easy, but making the world a better place rarely is. About Capgemini Capgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organisations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420,000 team members in more than 50 countries. We deliver end-to-end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2025 global revenues of €22.5 billion.
Aug 24, 2026
Full time
# Workday Project ManagerBirmingham, Glasgow, London, Manchester, WorthingApply for this job Permanent Experienced Professionals SaaS Solutions ID 507603-en\_GB About the job you're considering We are looking for an experienced Workday Engagement Manager to join our growing Workday Practice and lead the successful delivery of Workday engagements for our clients. This is a client-facing delivery leadership role for someone who combines strong project and programme management capability with commercial awareness, stakeholder leadership and a practical understanding of Workday delivery. You will take accountability for the delivery of Workday engagements, working with client sponsors, delivery leaders, functional and technical teams, commercial stakeholders, and account teams to deliver high-quality outcomes. You will also contribute to the continued growth of our Workday capability by supporting pre-sales activity, strengthening delivery governance, developing reusable delivery assets, and sharing knowledge across the practice. Your Role As a Workday Engagement Manager, you will act as the primary delivery lead for Workday implementation, enhancement and optimisation engagements. You will manage the end-to-end delivery lifecycle, create the conditions for effective project execution, and ensure that scope, timeline, budget, quality, risk, commercial performance and client satisfaction are actively managed throughout the engagement. You will be expected to bring a modern consulting mindset: outcome-focused, commercially aware, structured in delivery, confident with senior stakeholders and comfortable helping clients adopt Workday capabilities, data-led decision-making, automation and emerging AI-enabled functionality responsibly and effectively. Engagement delivery and governance Lead the end-to-end delivery of Workday implementation, enhancement and optimisation projects, ensuring engagements are delivered to agreed scope, quality, timeline and budget expectations. Own and maintain robust project governance, including plans, RAID management, status reporting, decision tracking, change control, dependency management and delivery assurance inputs. Client leadership and stakeholder management Act as a trusted delivery partner and primary point of contact for client stakeholders throughout the engagement lifecycle. Build and maintain strong relationships with client sponsors, programme leaders, HR, Finance, IT and operational stakeholders. Commercial, risk and quality management Manage engagement commercials, including forecast, budget, profitability, resource demand, scope control and change management within agreed governance. Ensure delivery quality through effective governance, review points, risk management, assurance activity and adherence to Workday and Capgemini delivery methods. Team leadership and practice contribution Lead, motivate and coordinate diverse delivery teams across onshore, nearshore and offshore locations. Create clarity for teams by setting expectations, managing workload, removing blockers and promoting collaborative ways of working. Your skills and experience Proven experience leading technology or Workday implementation engagements in a consultancy or professional services environment. Current Workday Services Partner certification as an Engagement Manager/Project Manager Strong understanding of Workday delivery lifecycles, deployment methodologies and the practical realities of delivering HCM, Finance, Payroll, Recruiting or broader Workday programmes. Demonstrable experience managing scope, plans, resources, budgets, risks, issues, dependencies, quality standards and profitability targets. Ability to lead diverse project teams and coordinate activity across functional, technical, data, testing, change and deployment workstreams. Strong client-facing skills, with the confidence to engage senior stakeholders, manage expectations and translate delivery complexity into clear business language. Commercial awareness and experience supporting statements of work, change control, delivery estimates, governance reporting and project financial management. Excellent communication, facilitation, problem-solving and organisational skills, with a structured and proactive approach to delivery leadership. Experience working across onshore, nearshore and offshore delivery models with multi-disciplinary and geographically distributed teams. A practical, inclusive and outcome-focused leadership style, with a willingness to coach others and contribute to the wider practice. Desirable experience Experience managing complex or multi-workstream Workday programmes, including senior stakeholder governance and delivery recovery activity. Experience supporting pre-sales, bid responses, solution proposals, mobilisation planning, commercial shaping or client demonstrations. Awareness of Workday HCM, Finance, Payroll, Recruiting, Talent, Absence, Time Tracking, Integrations, Security, Reporting, Extend or broader enterprise architecture considerations. Understanding of responsible AI adoption in HR and Finance transformation, including data readiness, governance, explainability, adoption and change considerations. Professional project or programme management qualification such as PRINCE2, PMP, MSP, Agile or equivalent practical delivery experience. We are a Disability Confident Employer Capgemini is proud to be a Disability Confident Employer (Level 2) under the UK Government's Disability Confident scheme.As part of our commitment to inclusive recruitment, we will offer an interview to all candidates who:Declare they have a disability, and Meet the minimum essential criteria for the role.Please opt in during the application process. Your security clearance and pre-employment checks If you are successfully offered this position, you will go through a series of pre-employment checks, including: identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service) To be successfully appointed to this role, it is a requirement to obtain Security Check (SC) clearance. To obtain SC clearance, the successful applicant must have resided continuously within the United Kingdom for the last 5 years, along with other criteria and requirements. Throughout the recruitment process, you will be asked questions about your security clearance eligibility such as, but not limited to, country of residence and nationality. Some posts are restricted to sole UK Nationals for security reasons; therefore, you may be asked about your citizenship in the application process. Make it real - what does it mean for you? Shape Your Path You will be empowered to explore, innovate, and progress. You will benefit from Capgemini's 'learning for life' mindset, meaning you will have countless training and development opportunities from thinktanks to hackathons, and access to 250,000 courses with numerous external certifications from AWS, Microsoft, Harvard ManageMentor, Cybersecurity qualifications and much more.Flexibility to work your way You will be encouraged to have a positive work-life balance. Our hybrid-first way of working means we embed hybrid working in all that we do and make flexible working arrangements the day-to-day reality for our people. All UK employees are eligible to request flexible working arrangements. Why you should consider Capgemini Growing clients' businesses while building a more sustainable, more inclusive future is a tough ask. When you join Capgemini, you'll join a thriving company and become part of a collective of free-thinkers, entrepreneurs and industry experts. We find new ways technology can help us reimagine what's possible. It's why, together, we seek out opportunities that will transform the world's leading businesses, and it's how you'll gain the experiences and connections you need to shape your future. By learning from each other every day, sharing knowledge, and always pushing yourself to do better, you'll build the skills you want. You'll use your skills to help our clients leverage technology to innovate and grow their business. So, it might not always be easy, but making the world a better place rarely is. About Capgemini Capgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organisations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420,000 team members in more than 50 countries. We deliver end-to-end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2025 global revenues of €22.5 billion.
Trusted Connectivity for AI-Powered Dominance. Everfox delivers trusted connectivity to protect the world's most critical environments and safeguard the sensitive data powering decision advantage. Built for mission-critical operations, Everfox protects what matters most by securing how data moves, how users access it, and how threats are neutralized across every domain. We enable mission speed and secure collaboration across networks, domains, and allies, while ensuring the data powering AI and advanced analytics remains trusted and protected. We don't just defend systems; we deliver decision dominance. Our Purpose. Protect what matters most by enabling organizations to operate security in the most complex and high-risk digital environments. Our Vision. To be the most trusted authority in high-assurance cybersecurity, enabling secure collaboration across every domain. Our Belief. Security should never limit mission success - it should enable it. Our Promise. We deliver absolute confidence in environments where failure is not an option. About the role: Location: London, United Kingdom (Hybrid, 2-3 days per week) Key Responsibilities: Build proactive talent pipelines and sourcing strategies for priority and hard to fill roles, applying market intelligence and competitive insights to improve sourcing effectiveness. Manage end to end hiring-from intake, assessment, and structured interviews through offer acceptance-while coaching hiring teams on interviewing effectiveness and selection quality. Act as a trusted advisor to hiring leaders, influencing hiring decisions with candidate insights, labor market data, and workforce trends. Optimize recruiting workflows to improve recruiter, candidate, and hiring manager experience; maintain ATS data integrity and consistent process execution. Interpret workforce trends and advise leaders proactively on pipeline health, talent availability, and competitive dynamics to align recruiting with business demand. Strengthen candidate experience and partner with stakeholders to enhance employer brand positioning and engagement strategies. Align recruiting priorities to workforce demand and business objectives across London and European hiring needs, anticipating future talent requirements. Contribute to scalable recruiting operations, continuous improvement initiatives, and data driven hiring recommendations; mentor peers and support team capability growth through expertise and influence. Key Knowledge and Skills: Advanced sourcing: market mapping, talent pipelining, and competitive research; expert use of LinkedIn and sourcing tools. Assessment excellence: structured interviewing, rubric based evaluation, and coaching hiring teams to improve selection quality. Stakeholder partnership: trusted advisor to senior hiring leaders; confident influencing decisions with data and market insights. Process optimization: full cycle recruiting with workflow improvements that elevate recruiter, candidate, and hiring manager experience. Data & insights: apply recruiting analytics and labor market intelligence to recommendations; interpret workforce trends to guide leaders. Candidate & employer experience: strengthen employer brand positioning, engagement strategies, and consistent candidate communications. Business alignment: align recruiting priorities to business objectives; anticipate future needs and advise proactively. Leadership contribution: mentor others and lead initiatives through expertise and influence (without direct people management). Experience with Workday ATS preferred. Key Education Requirements: Bachelor's degree (or equivalent experience) in Human Resources, Business, or a related field. 6-10+ years of progressive, full lifecycle recruiting experience, ideally within technology, cybersecurity, defense, or regulated environments. Proficiency with ATS/CRM platforms and recruiting analytics tools; strong familiarity with UK/EU hiring practices and compliance. Relevant certifications (e.g., CIPD, AIRS, Social Talent) are beneficial. Success Indicators: Pipeline health and time to fill for priority roles meet or exceed targets; improved offer acceptance and quality of hire outcomes. Positive candidate experience and hiring manager satisfaction; strengthened employer brand engagement. Data driven, proactive workforce insights influence hiring plans and reduce talent risk across London/EU markets. A reasonable estimate of the base salary range for this role is: £69,900.00-97,700.00 GBP The actual salary offered may vary within the range based on a candidates' unique experience, locale, and business needs. In addition to base salary and either bonus or commission, Everfox offers a generous benefits package including competitive annual leave, pension match, PMI, dental, health cash plan, income protection, in a hybrid work environment. competitive annual leave pension match PMI dental health cash plan income protection Everfox is an equal employment opportunity employer and complies with all applicable federal, state, and local laws prohibiting discrimination. Everfox does not discriminate against any employee or applicant based on race, color, religion, sex, age, national origin, disability, veteran status, marital status, medical condition, or any other category protected by applicable law. If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to use or access the Company's career webpage as a result of your disability. You may request reasonable accommodations by sending an email to . Applicants must have the right to work in the location to which you have applied. Everfox delivers trusted connectivity to protect the world's most critical environments and safeguard the sensitive data powering decision advantage. Built for mission-critical operations, Everfox protects what matters most by securing how data moves, how users access it, and how threats are neutralized across every domain. We enable mission speed and secure collaboration across networks, domains, and allies, while ensuring the data powering AI and advanced analytics remains trusted and protected. We don't just defend systems; we deliver decision dominance. Our Purpose. Protect what matters most by enabling organizations to operate security in the most complex and high-risk digital environments. Our Vision. To be the most trusted authority in high-assurance cybersecurity, enabling secure collaboration across every domain. Our Belief. Security should never limit mission success - it should enable it. Our Promise. We deliver absolute confidence in environments where failure is not an option.
Aug 22, 2026
Full time
Trusted Connectivity for AI-Powered Dominance. Everfox delivers trusted connectivity to protect the world's most critical environments and safeguard the sensitive data powering decision advantage. Built for mission-critical operations, Everfox protects what matters most by securing how data moves, how users access it, and how threats are neutralized across every domain. We enable mission speed and secure collaboration across networks, domains, and allies, while ensuring the data powering AI and advanced analytics remains trusted and protected. We don't just defend systems; we deliver decision dominance. Our Purpose. Protect what matters most by enabling organizations to operate security in the most complex and high-risk digital environments. Our Vision. To be the most trusted authority in high-assurance cybersecurity, enabling secure collaboration across every domain. Our Belief. Security should never limit mission success - it should enable it. Our Promise. We deliver absolute confidence in environments where failure is not an option. About the role: Location: London, United Kingdom (Hybrid, 2-3 days per week) Key Responsibilities: Build proactive talent pipelines and sourcing strategies for priority and hard to fill roles, applying market intelligence and competitive insights to improve sourcing effectiveness. Manage end to end hiring-from intake, assessment, and structured interviews through offer acceptance-while coaching hiring teams on interviewing effectiveness and selection quality. Act as a trusted advisor to hiring leaders, influencing hiring decisions with candidate insights, labor market data, and workforce trends. Optimize recruiting workflows to improve recruiter, candidate, and hiring manager experience; maintain ATS data integrity and consistent process execution. Interpret workforce trends and advise leaders proactively on pipeline health, talent availability, and competitive dynamics to align recruiting with business demand. Strengthen candidate experience and partner with stakeholders to enhance employer brand positioning and engagement strategies. Align recruiting priorities to workforce demand and business objectives across London and European hiring needs, anticipating future talent requirements. Contribute to scalable recruiting operations, continuous improvement initiatives, and data driven hiring recommendations; mentor peers and support team capability growth through expertise and influence. Key Knowledge and Skills: Advanced sourcing: market mapping, talent pipelining, and competitive research; expert use of LinkedIn and sourcing tools. Assessment excellence: structured interviewing, rubric based evaluation, and coaching hiring teams to improve selection quality. Stakeholder partnership: trusted advisor to senior hiring leaders; confident influencing decisions with data and market insights. Process optimization: full cycle recruiting with workflow improvements that elevate recruiter, candidate, and hiring manager experience. Data & insights: apply recruiting analytics and labor market intelligence to recommendations; interpret workforce trends to guide leaders. Candidate & employer experience: strengthen employer brand positioning, engagement strategies, and consistent candidate communications. Business alignment: align recruiting priorities to business objectives; anticipate future needs and advise proactively. Leadership contribution: mentor others and lead initiatives through expertise and influence (without direct people management). Experience with Workday ATS preferred. Key Education Requirements: Bachelor's degree (or equivalent experience) in Human Resources, Business, or a related field. 6-10+ years of progressive, full lifecycle recruiting experience, ideally within technology, cybersecurity, defense, or regulated environments. Proficiency with ATS/CRM platforms and recruiting analytics tools; strong familiarity with UK/EU hiring practices and compliance. Relevant certifications (e.g., CIPD, AIRS, Social Talent) are beneficial. Success Indicators: Pipeline health and time to fill for priority roles meet or exceed targets; improved offer acceptance and quality of hire outcomes. Positive candidate experience and hiring manager satisfaction; strengthened employer brand engagement. Data driven, proactive workforce insights influence hiring plans and reduce talent risk across London/EU markets. A reasonable estimate of the base salary range for this role is: £69,900.00-97,700.00 GBP The actual salary offered may vary within the range based on a candidates' unique experience, locale, and business needs. In addition to base salary and either bonus or commission, Everfox offers a generous benefits package including competitive annual leave, pension match, PMI, dental, health cash plan, income protection, in a hybrid work environment. competitive annual leave pension match PMI dental health cash plan income protection Everfox is an equal employment opportunity employer and complies with all applicable federal, state, and local laws prohibiting discrimination. Everfox does not discriminate against any employee or applicant based on race, color, religion, sex, age, national origin, disability, veteran status, marital status, medical condition, or any other category protected by applicable law. If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to use or access the Company's career webpage as a result of your disability. You may request reasonable accommodations by sending an email to . Applicants must have the right to work in the location to which you have applied. Everfox delivers trusted connectivity to protect the world's most critical environments and safeguard the sensitive data powering decision advantage. Built for mission-critical operations, Everfox protects what matters most by securing how data moves, how users access it, and how threats are neutralized across every domain. We enable mission speed and secure collaboration across networks, domains, and allies, while ensuring the data powering AI and advanced analytics remains trusted and protected. We don't just defend systems; we deliver decision dominance. Our Purpose. Protect what matters most by enabling organizations to operate security in the most complex and high-risk digital environments. Our Vision. To be the most trusted authority in high-assurance cybersecurity, enabling secure collaboration across every domain. Our Belief. Security should never limit mission success - it should enable it. Our Promise. We deliver absolute confidence in environments where failure is not an option.
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Aug 22, 2026
Full time
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
SRT Marine Systems plc
Gloucester, Gloucestershire
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Aug 22, 2026
Full time
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Aug 22, 2026
Full time
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Senior IT Operations Manager Deep Sea Electronics is a global leader in the design and manufacture of generator controllers, automatic transfer switch controllers, battery chargers, and vehicle and off-highway control systems. With over 200 employees across four continents, we supply our products to customers in more than 150 countries, both directly from our UK head office and through a well-established international distributor network. This is a hands-on senior leadership role responsible for shaping and delivering the organisation's IT strategy, while maintaining overall accountability for the day-to-day management and operational performance of the IT function. The role holder will assume end-to-end responsibility for the company's IT function, providing strategic and operational leadership across all technology services, infrastructure, networks, systems, applications, cybersecurity, and end-user support. They will ensure that technology capabilities are secure, resilient, scalable, and aligned with the organisation's business objectives. The successful candidate will lead both the IT team, establish and embed robust IT governance and change management processes, and take ownership of the organisation's cybersecurity programme, including leading the journey towards ISO 27001 accreditation. They will be accountable for service delivery, infrastructure performance, information security, technology risk management, and the development and execution of the long-term IT roadmap. Operating within a manufacturing environment, the role requires close collaboration with the organisation's parent company to ensure effective alignment, integration, and standardisation of IT services and strategic initiatives where appropriate. As a key member of the leadership team, the postholder will act as a trusted advisor and stakeholder to directors and senior business leaders, translating business requirements into technology solutions and ensuring IT investments deliver measurable business value. The Senior IT Operations Manager is a senior operational leadership position requiring an individual who can successfully balance strategic thinking with hands-on technical oversight. The right candidate will be equally comfortable resolving complex infrastructure challenges, leading and developing technical teams, and presenting technology strategy, risks, and opportunities to senior leadership. The Senior IT Operations Manager will be responsible for: IT Leadership and Direction Define and deliver the IT strategy aligned with overall business objectives and group direction across all technology services Act as the senior IT advisor to the leadership team, contributing to business planning and decision-making Develop a scalable and secure IT architecture to support future growth and international operations Drive continuous improvement across the organisation IT Infrastructure & Operations Responsible for the day-to-day performance, availability, and reliability of all IT infrastructure including networks, servers, end-user computing, cloud, VoIP, and connectivity services Ensure IT support services are delivered to agreed SLAs across all sites Oversee system maintenance, patching, upgrades, and capacity planning Supporting a complex engineering environment Own disaster recovery and business continuity planning, documentation, and regular testing Parent Company Integration & Change Management Act as the primary senior business stakeholder for IT integration and alignment activities with our parent company. Taking part in international IT team meetings and activities Design, implement, and embed a structured IT change management process from the ground up, ensuring it is adopted and followed consistently across the business Align the change management framework with parent company requirements where applicable, whilst protecting local operational continuity Cyber Security & ISO 27001 Lead the organisation's ISO 27001 accreditation programme from scoping through to certification Maintain and improve the day-to-day cyber security posture of the business Ensure alignment with international and parent company cybersecurity standards. Ensure disaster recovery, data protection, and business continuity plans are fit for purpose and regularly tested Manage compliance with relevant legal and regulatory requirements relating to IT systems and data Team Leadership & Development Lead, manage, and develop the IT team covering both support and network/infrastructure functions Set clear objectives, performance standards, and personal development plans for all team members Support the development of apprentices and longer-serving employees, building capability and reducing key-person dependency. Foster a proactive, service-oriented culture within the IT function Budget & Vendor Management Own and manage the IT budget, ensuring accurate forecasting and cost control Manage supplier and third-party relationships, holding vendors accountable for service quality and value Oversee procurement of IT systems, hardware, software, and services Why you should be our new Senior IT Operations Manager: 25 days holiday + Bank Holidays Company-wide performance-based annual bonus scheme Bupa Healthcare package + Life Assurance Enhanced Maternity/Paternity pay 5% Pension contributions Flexible holiday scheme
Aug 22, 2026
Full time
Senior IT Operations Manager Deep Sea Electronics is a global leader in the design and manufacture of generator controllers, automatic transfer switch controllers, battery chargers, and vehicle and off-highway control systems. With over 200 employees across four continents, we supply our products to customers in more than 150 countries, both directly from our UK head office and through a well-established international distributor network. This is a hands-on senior leadership role responsible for shaping and delivering the organisation's IT strategy, while maintaining overall accountability for the day-to-day management and operational performance of the IT function. The role holder will assume end-to-end responsibility for the company's IT function, providing strategic and operational leadership across all technology services, infrastructure, networks, systems, applications, cybersecurity, and end-user support. They will ensure that technology capabilities are secure, resilient, scalable, and aligned with the organisation's business objectives. The successful candidate will lead both the IT team, establish and embed robust IT governance and change management processes, and take ownership of the organisation's cybersecurity programme, including leading the journey towards ISO 27001 accreditation. They will be accountable for service delivery, infrastructure performance, information security, technology risk management, and the development and execution of the long-term IT roadmap. Operating within a manufacturing environment, the role requires close collaboration with the organisation's parent company to ensure effective alignment, integration, and standardisation of IT services and strategic initiatives where appropriate. As a key member of the leadership team, the postholder will act as a trusted advisor and stakeholder to directors and senior business leaders, translating business requirements into technology solutions and ensuring IT investments deliver measurable business value. The Senior IT Operations Manager is a senior operational leadership position requiring an individual who can successfully balance strategic thinking with hands-on technical oversight. The right candidate will be equally comfortable resolving complex infrastructure challenges, leading and developing technical teams, and presenting technology strategy, risks, and opportunities to senior leadership. The Senior IT Operations Manager will be responsible for: IT Leadership and Direction Define and deliver the IT strategy aligned with overall business objectives and group direction across all technology services Act as the senior IT advisor to the leadership team, contributing to business planning and decision-making Develop a scalable and secure IT architecture to support future growth and international operations Drive continuous improvement across the organisation IT Infrastructure & Operations Responsible for the day-to-day performance, availability, and reliability of all IT infrastructure including networks, servers, end-user computing, cloud, VoIP, and connectivity services Ensure IT support services are delivered to agreed SLAs across all sites Oversee system maintenance, patching, upgrades, and capacity planning Supporting a complex engineering environment Own disaster recovery and business continuity planning, documentation, and regular testing Parent Company Integration & Change Management Act as the primary senior business stakeholder for IT integration and alignment activities with our parent company. Taking part in international IT team meetings and activities Design, implement, and embed a structured IT change management process from the ground up, ensuring it is adopted and followed consistently across the business Align the change management framework with parent company requirements where applicable, whilst protecting local operational continuity Cyber Security & ISO 27001 Lead the organisation's ISO 27001 accreditation programme from scoping through to certification Maintain and improve the day-to-day cyber security posture of the business Ensure alignment with international and parent company cybersecurity standards. Ensure disaster recovery, data protection, and business continuity plans are fit for purpose and regularly tested Manage compliance with relevant legal and regulatory requirements relating to IT systems and data Team Leadership & Development Lead, manage, and develop the IT team covering both support and network/infrastructure functions Set clear objectives, performance standards, and personal development plans for all team members Support the development of apprentices and longer-serving employees, building capability and reducing key-person dependency. Foster a proactive, service-oriented culture within the IT function Budget & Vendor Management Own and manage the IT budget, ensuring accurate forecasting and cost control Manage supplier and third-party relationships, holding vendors accountable for service quality and value Oversee procurement of IT systems, hardware, software, and services Why you should be our new Senior IT Operations Manager: 25 days holiday + Bank Holidays Company-wide performance-based annual bonus scheme Bupa Healthcare package + Life Assurance Enhanced Maternity/Paternity pay 5% Pension contributions Flexible holiday scheme
Ganymede Solutions
Middleton St. George, County Durham
Cyber Security Contractor Rate: £500.00 - £550.00p/d (Outside IR35) North Yorkshire Are you an experienced Cyber Security professional with a background in Defence or regulated industrial environments, looking for a hands-on contract where you can lead the security workstream on a genuinely high-profile project? Do you enjoy working across the full lifecycle, from threat modelling and risk assessment through to customer-facing assurance documentation? My client is an established manufacturer of precision technology, delivering solutions used across a range of regulated sectors including defence, energy, and industrial environments. They've built a strong reputation for reliability and operational integrity, with products used in demanding and safety-critical settings. Lead Cyber Security Delivery on a Live MOD Project This is a hands-on contract covering the full cyber-security workstream for a specialist monitoring and alarm system, delivered in line with the MOD Secure by Design (SbD) approach. You'll be joining at the software delivery stage, with the architectural design already complete, and will take ownership of security from requirements through to implementation, test and handover. You'll be working closely with a small, focused project team, including a Project Manager and Lead Engineer, reporting into the Embedded Software Engineering Manager. Your responsibilities: Your day-to-day work will involve identifying vulnerabilities and developing the project's risk assessment, threat model and security architecture, ensuring security risks are proportionately treated and clearly evidenced. You'll be advising engineering teams on security controls across IT, OT and industrial control-system environments, reviewing system architecture, network design, access management and logging arrangements. You'll also produce a significant volume of customer-facing documentation, including security requirements, risk assessments, design documentation and assurance material, and will support engagement with MOD stakeholders and assurance functions throughout the project. What We're Looking For To be successful in this role, you'll need proven experience delivering cyber security and assurance work within MOD, Defence, government or other regulated industrial environments, along with practical experience applying MOD Secure by Design principles. You should be confident carrying out cyber risk assessment, threat modelling and security requirements engineering, with a solid understanding of OT/ICS security (PLC, HMI, SCADA) and how it interacts with safety and availability. Strong documentation and stakeholder-management skills are essential, along with the ability to work autonomously and explain security requirements pragmatically to non-specialists. You'll need to be eligible to work on UK Defence projects and hold the required security clearance (SC). Why Apply? This is a genuine opportunity to lead cyber security delivery on a fascinating, high-integrity Defence project, for a well-established business with a strong reputation in precision sensing technology. You'll be working in a fully office-based, close-knit team environment, with real ownership over the project's security workstream from this stage through to handover. Ganymede is committed to creating a diverse workforce and is an equal opportunities employer. We welcome applications from all suitably qualified persons regardless of age, disability, gender, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, and sexual orientation
Aug 22, 2026
Contractor
Cyber Security Contractor Rate: £500.00 - £550.00p/d (Outside IR35) North Yorkshire Are you an experienced Cyber Security professional with a background in Defence or regulated industrial environments, looking for a hands-on contract where you can lead the security workstream on a genuinely high-profile project? Do you enjoy working across the full lifecycle, from threat modelling and risk assessment through to customer-facing assurance documentation? My client is an established manufacturer of precision technology, delivering solutions used across a range of regulated sectors including defence, energy, and industrial environments. They've built a strong reputation for reliability and operational integrity, with products used in demanding and safety-critical settings. Lead Cyber Security Delivery on a Live MOD Project This is a hands-on contract covering the full cyber-security workstream for a specialist monitoring and alarm system, delivered in line with the MOD Secure by Design (SbD) approach. You'll be joining at the software delivery stage, with the architectural design already complete, and will take ownership of security from requirements through to implementation, test and handover. You'll be working closely with a small, focused project team, including a Project Manager and Lead Engineer, reporting into the Embedded Software Engineering Manager. Your responsibilities: Your day-to-day work will involve identifying vulnerabilities and developing the project's risk assessment, threat model and security architecture, ensuring security risks are proportionately treated and clearly evidenced. You'll be advising engineering teams on security controls across IT, OT and industrial control-system environments, reviewing system architecture, network design, access management and logging arrangements. You'll also produce a significant volume of customer-facing documentation, including security requirements, risk assessments, design documentation and assurance material, and will support engagement with MOD stakeholders and assurance functions throughout the project. What We're Looking For To be successful in this role, you'll need proven experience delivering cyber security and assurance work within MOD, Defence, government or other regulated industrial environments, along with practical experience applying MOD Secure by Design principles. You should be confident carrying out cyber risk assessment, threat modelling and security requirements engineering, with a solid understanding of OT/ICS security (PLC, HMI, SCADA) and how it interacts with safety and availability. Strong documentation and stakeholder-management skills are essential, along with the ability to work autonomously and explain security requirements pragmatically to non-specialists. You'll need to be eligible to work on UK Defence projects and hold the required security clearance (SC). Why Apply? This is a genuine opportunity to lead cyber security delivery on a fascinating, high-integrity Defence project, for a well-established business with a strong reputation in precision sensing technology. You'll be working in a fully office-based, close-knit team environment, with real ownership over the project's security workstream from this stage through to handover. Ganymede is committed to creating a diverse workforce and is an equal opportunities employer. We welcome applications from all suitably qualified persons regardless of age, disability, gender, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, and sexual orientation
Vehicle allowance Company pension scheme. Professional membership fees paid. Funded continuing professional development. Support towards Chartered status and advanced qualifications. Role This is a rare opportunity to take ownership of Health, Safety, Quality, Environmental, Information Security and Corporate Compliance across a growing specialist contractor delivering complex projects throughout the UK. Reporting directly to the Directors, you will play a pivotal role in shaping the company's governance framework, strengthening their compliance culture and supporting the next phase of business growth across Defence, Government, Critical National Infrastructure and commercial sectors. This role offers far more than traditional Health & Safety management. It is an opportunity to influence strategic decision-making, modernise assurance processes and build an integrated compliance function that enables safe, secure and successful project delivery. Their teams work within some of the UK's most complex and security-sensitive environments, including Defence establishments, Government facilities, Critical National Infrastructure sites and operational commercial environments. Responsibilities You will act as the principal advisor to the Board on matters relating to: Health & Safety Corporate Governance Principal Contractor Compliance CDM Regulations Integrated Management Systems ISO Compliance Information Security Risk Management Environmental Performance Internal and External Auditing Accreditation and Certification Supply Chain Assurance Training and Competence You will work collaboratively with Directors, managers, employees, subcontractors and clients to ensure compliance is embedded into everyday decision-making and operational delivery. Key Responsibilities Strategic Leadership Lead and develop the company's Health, Safety, Quality, Environmental and Information Security strategy Provide expert advice and guidance to Directors and senior leadership teams. Promote a positive, proactive and accountable compliance culture. Ensure legal, contractual and regulatory obligations are effectively managed. Integrated Management Systems Own and continually improve the company's Integrated Management System. Lead compliance with ISO 9001, ISO 14001, ISO 45001 and ISO 27001. Ensure ongoing certification readiness and continual improvement. Health, Safety and CDM Compliance Act as the company's competent Health & Safety adviser. Support the business in delivering its duties as Principal Contractor. Provide leadership on CDM compliance across projects. Lead incident investigations, corrective actions and organisational learning initiatives. Governance, Assurance and Audit Develop and deliver risk-based audit programmes. Lead internal and external assurance activities. Manage certification bodies, client audits and compliance assessments. Produce meaningful compliance reporting and dashboards for senior leadership. Information Security and Corporate Compliance Support the development and maintenance of ISO 27001 certification. Strengthen information security, governance and business resilience arrangements. Support compliance with Defence, Government and client-specific requirements. Maintain effective corporate governance and risk management frameworks. People, Culture and Capability Oversee competence management and compliance training programmes. Develop leadership accountability across all levels of the business. Build employee engagement and ownership of compliance responsibilities. Foster a culture of continual improvement and operational excellence. Requirement You are an experienced Health, Safety and Compliance leader who combines technical expertise with commercial awareness and practical problem solving skills. You are comfortable operating at Board level whilst remaining engaged with operational delivery and project teams. You understand how robust governance, effective assurance and strong leadership can support business growth, protect reputation and improve client confidence. Experience within regulated industries such as construction, infrastructure, telecommunications, utilities, Defence or Critical National Infrastructure would be highly advantageous. Essential NEBOSH Diploma or equivalent Level 6 Health & Safety qualification. Chartered IOSH membership or demonstrable progression toward Chartered status. Significant senior level Health, Safety and Compliance leadership experience. Strong knowledge of CDM Regulations and Principal Contractor responsibilities. Experience managing Integrated Management Systems. Practical experience of ISO 9001, ISO 14001 and ISO 45001. Working knowledge of ISO 27001 and Information Security governance. Experience leading audit, compliance and assurance programmes. Strong stakeholder management and communication skills. Full UK Driving Licence and willingness to travel throughout the UK. Desirable Chartered IOSH status. Lead Auditor qualifications. Experience working within Defence or Government environments. Knowledge of UK Government Security requirements. Experience with Cyber Essentials Plus. Previous responsibility for corporate governance and business assurance functions. Experience within telecommunications, infrastructure, civil engineering or secure communications sectors. Security Clearance Current security clearance is not essential; however, candidates must be eligible and willing to undergo UK Government Security Vetting and satisfy the requirements for Developed Vetting where required by the role, project or client. You will work directly with company leadership, support major programmes within Defence and Critical National Infrastructure, and help create the governance framework that supports future growth.
Aug 22, 2026
Full time
Vehicle allowance Company pension scheme. Professional membership fees paid. Funded continuing professional development. Support towards Chartered status and advanced qualifications. Role This is a rare opportunity to take ownership of Health, Safety, Quality, Environmental, Information Security and Corporate Compliance across a growing specialist contractor delivering complex projects throughout the UK. Reporting directly to the Directors, you will play a pivotal role in shaping the company's governance framework, strengthening their compliance culture and supporting the next phase of business growth across Defence, Government, Critical National Infrastructure and commercial sectors. This role offers far more than traditional Health & Safety management. It is an opportunity to influence strategic decision-making, modernise assurance processes and build an integrated compliance function that enables safe, secure and successful project delivery. Their teams work within some of the UK's most complex and security-sensitive environments, including Defence establishments, Government facilities, Critical National Infrastructure sites and operational commercial environments. Responsibilities You will act as the principal advisor to the Board on matters relating to: Health & Safety Corporate Governance Principal Contractor Compliance CDM Regulations Integrated Management Systems ISO Compliance Information Security Risk Management Environmental Performance Internal and External Auditing Accreditation and Certification Supply Chain Assurance Training and Competence You will work collaboratively with Directors, managers, employees, subcontractors and clients to ensure compliance is embedded into everyday decision-making and operational delivery. Key Responsibilities Strategic Leadership Lead and develop the company's Health, Safety, Quality, Environmental and Information Security strategy Provide expert advice and guidance to Directors and senior leadership teams. Promote a positive, proactive and accountable compliance culture. Ensure legal, contractual and regulatory obligations are effectively managed. Integrated Management Systems Own and continually improve the company's Integrated Management System. Lead compliance with ISO 9001, ISO 14001, ISO 45001 and ISO 27001. Ensure ongoing certification readiness and continual improvement. Health, Safety and CDM Compliance Act as the company's competent Health & Safety adviser. Support the business in delivering its duties as Principal Contractor. Provide leadership on CDM compliance across projects. Lead incident investigations, corrective actions and organisational learning initiatives. Governance, Assurance and Audit Develop and deliver risk-based audit programmes. Lead internal and external assurance activities. Manage certification bodies, client audits and compliance assessments. Produce meaningful compliance reporting and dashboards for senior leadership. Information Security and Corporate Compliance Support the development and maintenance of ISO 27001 certification. Strengthen information security, governance and business resilience arrangements. Support compliance with Defence, Government and client-specific requirements. Maintain effective corporate governance and risk management frameworks. People, Culture and Capability Oversee competence management and compliance training programmes. Develop leadership accountability across all levels of the business. Build employee engagement and ownership of compliance responsibilities. Foster a culture of continual improvement and operational excellence. Requirement You are an experienced Health, Safety and Compliance leader who combines technical expertise with commercial awareness and practical problem solving skills. You are comfortable operating at Board level whilst remaining engaged with operational delivery and project teams. You understand how robust governance, effective assurance and strong leadership can support business growth, protect reputation and improve client confidence. Experience within regulated industries such as construction, infrastructure, telecommunications, utilities, Defence or Critical National Infrastructure would be highly advantageous. Essential NEBOSH Diploma or equivalent Level 6 Health & Safety qualification. Chartered IOSH membership or demonstrable progression toward Chartered status. Significant senior level Health, Safety and Compliance leadership experience. Strong knowledge of CDM Regulations and Principal Contractor responsibilities. Experience managing Integrated Management Systems. Practical experience of ISO 9001, ISO 14001 and ISO 45001. Working knowledge of ISO 27001 and Information Security governance. Experience leading audit, compliance and assurance programmes. Strong stakeholder management and communication skills. Full UK Driving Licence and willingness to travel throughout the UK. Desirable Chartered IOSH status. Lead Auditor qualifications. Experience working within Defence or Government environments. Knowledge of UK Government Security requirements. Experience with Cyber Essentials Plus. Previous responsibility for corporate governance and business assurance functions. Experience within telecommunications, infrastructure, civil engineering or secure communications sectors. Security Clearance Current security clearance is not essential; however, candidates must be eligible and willing to undergo UK Government Security Vetting and satisfy the requirements for Developed Vetting where required by the role, project or client. You will work directly with company leadership, support major programmes within Defence and Critical National Infrastructure, and help create the governance framework that supports future growth.
Citizens Advice Stevenage is an ambitious and innovative member of the Citizens Advice network. We have expanded our services and offering to meet the increased demand in the area, doubling in size over the last few years. As a positive subsequence, we are looking for a Head of Finance & Business Support, who will become a core member of the Senior Leadership Team, responsible for overseeing the financial stewardship of Citizens Advice Stevenage. To lead on financial governance, business support operations, and compliance, ensuring the organization operates sustainably and meets all legal and regulatory obligations. The role is pivotal in safeguarding the charity's financial integrity, supporting strategic decision-making, and enabling effective service delivery. Financial Leadership Prepare, review, and present draft and final budgets for approval by the board, ensuring timely submission of financial information to the CEO and Trustee Board. Oversee financial reporting processes, ensuring accuracy, transparency, and compliance with regulatory standards, including variance analysis and annual balance sheets, ensuring timely submission of financial information to the CEO and Trustee Board. Manage the reserves policy, ensuring regular review and alignment with operational needs and financial risks. Identify and manage financial risks, ensuring integration into the organization's risk register and adherence to appropriate mitigations. Ensure that the day-to-day finance and back-office function is high performing and compliant, safeguarding effective and efficient financial management processes. To co-ordinate the proactive and timely dissemination of high-quality financial information to services, the CEO, and Board such as annual budgets, monthly management accounts, cash flow analysis, financial forecasting and monthly business performance figures. To ensure that the organisation has in place, robust and compliant financial systems and procedures; and that these are complied with by all budget holders, ensuring that any oversights are fully investigated and reported upwards as necessary. To lead on the preparation of statutory accounts, provide year end accounts, provide appropriate support and assistance to the organisation's auditors and delivery of recommendations arising from the Audit process. To ensure that all statutory returns are complete in a timely and effective manner, including those in relation to VAT, PAYE, NIC and SSP, and that appropriate compliance dates are met for the Charities Commission and Companies House. Oversee the transactions, activities and processes of the external payroll provider. To monitor and advise on current and future tax legislation, with a view to optimisation. To support service managers in the preparation of bids and contract negotiations and provide financial activity analysis and reports in line with specific project reporting requirements. To monitor, report and make recommendations regarding the Investment and Reserves Policy to the Board. To oversee the payroll function to ensure employees are paid in an accurate and timely manner. To monitor and control creditors and debtors, ensuring invoices are paid on time and the risk of bad debts is minimised. Compliance and Risk Management Ensure compliance with all applicable regulatory frameworks, including the Charity Commission, Companies House, FCA, ICO, and other relevant bodies. Maintain and regularly review financial systems, controls, and policies, ensuring they are effectively implemented and aligned with legal requirements. Conduct due diligence for pension, redundancy, and other liabilities, ensuring plans are in place for management and mitigation. Support the trustee board in understanding risks related to projects and contracts, providing assurance of compliance with funders' requirements. To lead on the Risk Management process, advising the CEO and managers on risk matters, and reviewing the risk register on a regular basis, reporting to the Board of Trustees. To check, amend and monitor the Financial Procedures Manual; reporting material breaches to the CEO and Board of Trustees, as required/in-line with governance. Working with the senior leadership team monitoring and updating Insurance matters as required, reporting to the CEO and Board of Trustees. Business Support Operations Lead on organisational business continuity planning, ensuring resilience during crises and alignment with the charity's objectives. Oversee the development, implementation, and review of key policies, ensuring they reflect legal obligations and organisational values. Manage IT systems and cybersecurity measures to protect organisational data and operations, ensuring compliance with standards such as Cyber Essentials. Strategic Contribution Provides proactive strategic financial advice and guidance to the Trustees and wider leadership team, monitoring and reporting on the financial performance against agreed targets, identified risks and key performance indicators. Provide financial and operational insights to inform strategic decision-making and long-term planning. Foster a culture of continuous improvement and financial accountability across the organisation. Funding strategy: Support the CEO and board to regularly review the sustainability of its income sources and their impact on achieving charitable purposes in the short, medium and longer term. Work with the CEO and Head of Impact and Development to prepare the funding strategy that should go beyond immediate budgetary considerations and look at the wider funding landscape. The organisation needs to understand potential emerging opportunities and the organisation's readiness to pursue them. Team and Stakeholder Engagement Build and maintain effective relationships with trustees, funders, regulators, and key stakeholders, to ensure that Citizens Advice Stevenage meets its financial, regulatory and legal obligations. Provide leadership and support to finance and business support teams, ensuring professional development and effective performance management. People management and development Develop and implement a culture of continuous learning that will equip and develop people to deliver outstanding delivery. Responsibility for the training and development plan for the Finance and Business Support ensuring it is in effective operation including maintaining records of training needs identified and training attended. Working with the rest of the leadership team ensure the organisation delivers a fair, inclusive, equitable and transparent employee and volunteer experience, taking account of our EDI aims and in line with employment law and the Equality Act 2010. Ensure Open and timely communication that provides information about the organisation and context for decisions that are made, helps to build trust and confidence and earn legitimacy. Ensure the effective performance management and development of staff through regular supervision sessions, appraisals and learning and development. Person Specification ACA/ACCA/CIMA Qualified, CPE up to date. Strong financial management experience at a similar level within the charity/not for profit sector A proven track record of leading, developing and inspiring small teams Experience of strategic business & financial planning, forecasting and budget management. Sound experience of producing month-end management accounts and audited year-end financial accounts Experience of managing and using financial systems A working knowledge of relevant legislation (regulatory, legal and financial) in the context of a charitable organisation Experience of managing change and change programmes A track record of initiating, leading and managing associated risks Strong influencing, negotiating and collaborative working skills, with the ability to present complex financial information clearly and concisely in writing or verbally Confident IT skills; confident using Microsoft Office applications, especially Excel Experience designing and introducing new financial processes, procedures and reports Working knowledge of QuickBooks software advantageous Experience working with a Board of Trustees advantageous Understanding of Charity Commission and Companies House reporting requirements Project and/or professional services experience Understanding of Charity Law Experience of working in the not-for-profit sector Understanding and experience using the Charity Governance Code Experience in working with Charity SORP . click apply for full job details
Aug 22, 2026
Full time
Citizens Advice Stevenage is an ambitious and innovative member of the Citizens Advice network. We have expanded our services and offering to meet the increased demand in the area, doubling in size over the last few years. As a positive subsequence, we are looking for a Head of Finance & Business Support, who will become a core member of the Senior Leadership Team, responsible for overseeing the financial stewardship of Citizens Advice Stevenage. To lead on financial governance, business support operations, and compliance, ensuring the organization operates sustainably and meets all legal and regulatory obligations. The role is pivotal in safeguarding the charity's financial integrity, supporting strategic decision-making, and enabling effective service delivery. Financial Leadership Prepare, review, and present draft and final budgets for approval by the board, ensuring timely submission of financial information to the CEO and Trustee Board. Oversee financial reporting processes, ensuring accuracy, transparency, and compliance with regulatory standards, including variance analysis and annual balance sheets, ensuring timely submission of financial information to the CEO and Trustee Board. Manage the reserves policy, ensuring regular review and alignment with operational needs and financial risks. Identify and manage financial risks, ensuring integration into the organization's risk register and adherence to appropriate mitigations. Ensure that the day-to-day finance and back-office function is high performing and compliant, safeguarding effective and efficient financial management processes. To co-ordinate the proactive and timely dissemination of high-quality financial information to services, the CEO, and Board such as annual budgets, monthly management accounts, cash flow analysis, financial forecasting and monthly business performance figures. To ensure that the organisation has in place, robust and compliant financial systems and procedures; and that these are complied with by all budget holders, ensuring that any oversights are fully investigated and reported upwards as necessary. To lead on the preparation of statutory accounts, provide year end accounts, provide appropriate support and assistance to the organisation's auditors and delivery of recommendations arising from the Audit process. To ensure that all statutory returns are complete in a timely and effective manner, including those in relation to VAT, PAYE, NIC and SSP, and that appropriate compliance dates are met for the Charities Commission and Companies House. Oversee the transactions, activities and processes of the external payroll provider. To monitor and advise on current and future tax legislation, with a view to optimisation. To support service managers in the preparation of bids and contract negotiations and provide financial activity analysis and reports in line with specific project reporting requirements. To monitor, report and make recommendations regarding the Investment and Reserves Policy to the Board. To oversee the payroll function to ensure employees are paid in an accurate and timely manner. To monitor and control creditors and debtors, ensuring invoices are paid on time and the risk of bad debts is minimised. Compliance and Risk Management Ensure compliance with all applicable regulatory frameworks, including the Charity Commission, Companies House, FCA, ICO, and other relevant bodies. Maintain and regularly review financial systems, controls, and policies, ensuring they are effectively implemented and aligned with legal requirements. Conduct due diligence for pension, redundancy, and other liabilities, ensuring plans are in place for management and mitigation. Support the trustee board in understanding risks related to projects and contracts, providing assurance of compliance with funders' requirements. To lead on the Risk Management process, advising the CEO and managers on risk matters, and reviewing the risk register on a regular basis, reporting to the Board of Trustees. To check, amend and monitor the Financial Procedures Manual; reporting material breaches to the CEO and Board of Trustees, as required/in-line with governance. Working with the senior leadership team monitoring and updating Insurance matters as required, reporting to the CEO and Board of Trustees. Business Support Operations Lead on organisational business continuity planning, ensuring resilience during crises and alignment with the charity's objectives. Oversee the development, implementation, and review of key policies, ensuring they reflect legal obligations and organisational values. Manage IT systems and cybersecurity measures to protect organisational data and operations, ensuring compliance with standards such as Cyber Essentials. Strategic Contribution Provides proactive strategic financial advice and guidance to the Trustees and wider leadership team, monitoring and reporting on the financial performance against agreed targets, identified risks and key performance indicators. Provide financial and operational insights to inform strategic decision-making and long-term planning. Foster a culture of continuous improvement and financial accountability across the organisation. Funding strategy: Support the CEO and board to regularly review the sustainability of its income sources and their impact on achieving charitable purposes in the short, medium and longer term. Work with the CEO and Head of Impact and Development to prepare the funding strategy that should go beyond immediate budgetary considerations and look at the wider funding landscape. The organisation needs to understand potential emerging opportunities and the organisation's readiness to pursue them. Team and Stakeholder Engagement Build and maintain effective relationships with trustees, funders, regulators, and key stakeholders, to ensure that Citizens Advice Stevenage meets its financial, regulatory and legal obligations. Provide leadership and support to finance and business support teams, ensuring professional development and effective performance management. People management and development Develop and implement a culture of continuous learning that will equip and develop people to deliver outstanding delivery. Responsibility for the training and development plan for the Finance and Business Support ensuring it is in effective operation including maintaining records of training needs identified and training attended. Working with the rest of the leadership team ensure the organisation delivers a fair, inclusive, equitable and transparent employee and volunteer experience, taking account of our EDI aims and in line with employment law and the Equality Act 2010. Ensure Open and timely communication that provides information about the organisation and context for decisions that are made, helps to build trust and confidence and earn legitimacy. Ensure the effective performance management and development of staff through regular supervision sessions, appraisals and learning and development. Person Specification ACA/ACCA/CIMA Qualified, CPE up to date. Strong financial management experience at a similar level within the charity/not for profit sector A proven track record of leading, developing and inspiring small teams Experience of strategic business & financial planning, forecasting and budget management. Sound experience of producing month-end management accounts and audited year-end financial accounts Experience of managing and using financial systems A working knowledge of relevant legislation (regulatory, legal and financial) in the context of a charitable organisation Experience of managing change and change programmes A track record of initiating, leading and managing associated risks Strong influencing, negotiating and collaborative working skills, with the ability to present complex financial information clearly and concisely in writing or verbally Confident IT skills; confident using Microsoft Office applications, especially Excel Experience designing and introducing new financial processes, procedures and reports Working knowledge of QuickBooks software advantageous Experience working with a Board of Trustees advantageous Understanding of Charity Commission and Companies House reporting requirements Project and/or professional services experience Understanding of Charity Law Experience of working in the not-for-profit sector Understanding and experience using the Charity Governance Code Experience in working with Charity SORP . click apply for full job details
Job Description Overview Become a vital member of our Complex Projects, Delivery Partner team, proudly taking on some of the world's most exciting and prestigious projects. Join us, and you'll be part of our genuinely collaborative environment, where everyone is supported to make the most of their talents. It's about recognising everyone's contributions equally while delivering excellence together. When you join our practice team, you'll share our vision to be the industry's foremost capability in Estimating & Cost Advisory and always doing what's right. Enjoy a diverse and exciting workload surrounded by talented colleagues ready to lend a hand. You'll support multi-disciplinary and specialist project teams on high-profile schemes across a range of sectors, delivering high impact estimating services to a range of key clients. Plus, you'll have the opportunity to grow your career and develop our internal capabilities. We are looking to hire a Cost Assurance Consultant - Cost Verification and Assurance to support our growing business. In Complex Projects we work across three major markets: Infrastructure (Water, Defence, Aviation, etc.). Transport (Rail, Highways, Local Authorities, etc.). Energy (Nuclear, Renewable Energy, Power, etc.). Your role Provide cost verification, audit and assurance activities, including forensic reviews across large-scale complex infrastructure projects. Support and deliver evaluation of cost data and structures, assessing them against contractual/commercial principles. Analyse supplier cost data to identify patterns, themes, trends and risks. Provide detailed cost verification, payroll audits and wider data sampling for targeted audit activities. Assess and appraise cost capture and commercial management processes. Identify supplier commercial process improvement opportunities for improved commercial governance and cost control. Interpret and advise on contract documentation, particularly under NEC4 contracts. Engage with client teams, contractors and other project stakeholders to complete cost verification/substantiation together with obtaining key documentation and data. Deliver high-quality assurance reports and present those findings to senior stakeholders. Support the presentation of outputs and recommendations to clients and their wider supply chain. Support the integration of innovative digital tools for data analysis and reporting. About you Demonstratable experience of delivering cost and commercial assurance/audit activities. Competent in the interpretation of a wide range of contracts, with experience in the application of the principles of a schedule of cost components. Experienced and comfortable analysing large data sets as well as experience of different costing systems. The ability to interrogate and assess data sets and produce outputs that can be used in the decision-making process. Bachelor's degree in an Estimating, Quantity Surveying, Engineering, Construction sectors or Equivalent Work Experience. Chartership with or demonstrably working towards RICS, ICE, AACE, ACostE or similar. Good working knowledge of NEC3/4 suit of contracts across all option types. Ability to work autonomously in a fast-paced environment, working through challenges as they develop during the delivery stage. Strong report writing and presentation skills. Excellent communication skills both verbal and written. Experience of working within a client organisation, either directly or through a colocation/secondment arrangement. Rewards & benefits Explore the rewards and benefits that help you thrive - at every stage of your life and your career. Enjoy competitive salaries, employee rewards and a brilliant range of benefits you can tailor to suit your own health, wellbeing, financial and lifestyle choices. Make the most of a myriad of opportunities for training and professional development to grow your skills and expertise. And combine our hybrid working culture and flexible holiday allowances to balance a great job and fulfilling personal life. Be rewarded. About AtkinsRéalis We're AtkinsRéalis, a world-class engineering services and nuclear organization. We connect people, data and technology to transform the world's infrastructure and energy systems. Together, with our industry partners and clients, and our global team of consultants, designers, engineers and project managers, we can change the world. We're committed to leading our clients across our various end markets to engineer a better future for our planet and its people. Additional information Security Clearance This role may require security clearance and offers of employment will be dependent on obtaining the relevant level of clearance. If this is necessary, it will be discussed with you at interview. The vetting process is delivered by United Kingdom Security Vetting (UKSV) and may require candidates to provide proof of residency in the UK of 5 years or longer. We are committed to creating a culture where everyone feels that they belong - a place where we can all be ourselves, thrive and develop to be the best we can be. So, we offer a range of family friendly, inclusive employment policies, flexible working arrangements and employee resource groups to support all employees. As an Equal Opportunities Employer, we value applications from all backgrounds, cultures and ability. As a Disability Confident Leader, we are committed to offering an interview to all applicants who have a disability and meet the essential criteria. Worker Type Employee Job Type Regular At AtkinsRéalis At AtkinsRéalis, we seek to hire individuals with diverse characteristics, backgrounds and perspectives. We strongly believe that world-class talent makes no distinctions based on gender, ethnic or national origin, sexual identity and orientation, age, religion or disability, but enriches itself through these differences. Created by the integration of long-standing organizations dating back to 1911, AtkinsRéalis is a world-class engineering services and nuclear company dedicated to engineering a better future for our planet and its people. We create sustainable solutions that connect people, data and technology to transform the world's infrastructure and energy systems. We deploy global capabilities locally to our clients and deliver unique end-to-end services across the whole life cycle of an asset including consulting, advisory & environmental services, intelligent networks & cybersecurity, design & engineering, procurement, project & construction management, operations & maintenance, decommissioning and capital. The breadth and depth of our capabilities are delivered to clients in strategic sectors such as Engineering Services, Nuclear and Capital. News and information are available at Atkinsrealis or follow us on LinkedIn.
Aug 21, 2026
Full time
Job Description Overview Become a vital member of our Complex Projects, Delivery Partner team, proudly taking on some of the world's most exciting and prestigious projects. Join us, and you'll be part of our genuinely collaborative environment, where everyone is supported to make the most of their talents. It's about recognising everyone's contributions equally while delivering excellence together. When you join our practice team, you'll share our vision to be the industry's foremost capability in Estimating & Cost Advisory and always doing what's right. Enjoy a diverse and exciting workload surrounded by talented colleagues ready to lend a hand. You'll support multi-disciplinary and specialist project teams on high-profile schemes across a range of sectors, delivering high impact estimating services to a range of key clients. Plus, you'll have the opportunity to grow your career and develop our internal capabilities. We are looking to hire a Cost Assurance Consultant - Cost Verification and Assurance to support our growing business. In Complex Projects we work across three major markets: Infrastructure (Water, Defence, Aviation, etc.). Transport (Rail, Highways, Local Authorities, etc.). Energy (Nuclear, Renewable Energy, Power, etc.). Your role Provide cost verification, audit and assurance activities, including forensic reviews across large-scale complex infrastructure projects. Support and deliver evaluation of cost data and structures, assessing them against contractual/commercial principles. Analyse supplier cost data to identify patterns, themes, trends and risks. Provide detailed cost verification, payroll audits and wider data sampling for targeted audit activities. Assess and appraise cost capture and commercial management processes. Identify supplier commercial process improvement opportunities for improved commercial governance and cost control. Interpret and advise on contract documentation, particularly under NEC4 contracts. Engage with client teams, contractors and other project stakeholders to complete cost verification/substantiation together with obtaining key documentation and data. Deliver high-quality assurance reports and present those findings to senior stakeholders. Support the presentation of outputs and recommendations to clients and their wider supply chain. Support the integration of innovative digital tools for data analysis and reporting. About you Demonstratable experience of delivering cost and commercial assurance/audit activities. Competent in the interpretation of a wide range of contracts, with experience in the application of the principles of a schedule of cost components. Experienced and comfortable analysing large data sets as well as experience of different costing systems. The ability to interrogate and assess data sets and produce outputs that can be used in the decision-making process. Bachelor's degree in an Estimating, Quantity Surveying, Engineering, Construction sectors or Equivalent Work Experience. Chartership with or demonstrably working towards RICS, ICE, AACE, ACostE or similar. Good working knowledge of NEC3/4 suit of contracts across all option types. Ability to work autonomously in a fast-paced environment, working through challenges as they develop during the delivery stage. Strong report writing and presentation skills. Excellent communication skills both verbal and written. Experience of working within a client organisation, either directly or through a colocation/secondment arrangement. Rewards & benefits Explore the rewards and benefits that help you thrive - at every stage of your life and your career. Enjoy competitive salaries, employee rewards and a brilliant range of benefits you can tailor to suit your own health, wellbeing, financial and lifestyle choices. Make the most of a myriad of opportunities for training and professional development to grow your skills and expertise. And combine our hybrid working culture and flexible holiday allowances to balance a great job and fulfilling personal life. Be rewarded. About AtkinsRéalis We're AtkinsRéalis, a world-class engineering services and nuclear organization. We connect people, data and technology to transform the world's infrastructure and energy systems. Together, with our industry partners and clients, and our global team of consultants, designers, engineers and project managers, we can change the world. We're committed to leading our clients across our various end markets to engineer a better future for our planet and its people. Additional information Security Clearance This role may require security clearance and offers of employment will be dependent on obtaining the relevant level of clearance. If this is necessary, it will be discussed with you at interview. The vetting process is delivered by United Kingdom Security Vetting (UKSV) and may require candidates to provide proof of residency in the UK of 5 years or longer. We are committed to creating a culture where everyone feels that they belong - a place where we can all be ourselves, thrive and develop to be the best we can be. So, we offer a range of family friendly, inclusive employment policies, flexible working arrangements and employee resource groups to support all employees. As an Equal Opportunities Employer, we value applications from all backgrounds, cultures and ability. As a Disability Confident Leader, we are committed to offering an interview to all applicants who have a disability and meet the essential criteria. Worker Type Employee Job Type Regular At AtkinsRéalis At AtkinsRéalis, we seek to hire individuals with diverse characteristics, backgrounds and perspectives. We strongly believe that world-class talent makes no distinctions based on gender, ethnic or national origin, sexual identity and orientation, age, religion or disability, but enriches itself through these differences. Created by the integration of long-standing organizations dating back to 1911, AtkinsRéalis is a world-class engineering services and nuclear company dedicated to engineering a better future for our planet and its people. We create sustainable solutions that connect people, data and technology to transform the world's infrastructure and energy systems. We deploy global capabilities locally to our clients and deliver unique end-to-end services across the whole life cycle of an asset including consulting, advisory & environmental services, intelligent networks & cybersecurity, design & engineering, procurement, project & construction management, operations & maintenance, decommissioning and capital. The breadth and depth of our capabilities are delivered to clients in strategic sectors such as Engineering Services, Nuclear and Capital. News and information are available at Atkinsrealis or follow us on LinkedIn.
Third Party Cyber Risk LeadApplylocations: UK - London ( St Botolph )time type: Full timeposted on: Posted Todayjob requisition id: 2026-628 Job Title: Third Party Cyber Risk Lead Reporting to: Cyber Governance Manager Direct Reports: None Position Type: Permanent Why Tokio Marine HCC? Standing still is not an option in the current world of Insurance. TMHCC is one of the world's leading Specialty Insurers. With deep expertise in our chosen lines of business, our unparalleled track record and a solid balance sheet, TMHCC evaluates and manages risk like no one else in the industry. Looking beyond profit, empowering our people and delivering on our commitments are at the core of our customer values, along with a desire to grow and provide creative and innovative solutions to our clients. About Operations Operations sits at the heart of TMHCC, we ensure the smooth running of all business processes - from policy administration and claims handling to data, technology, and delivery. We focus on driving efficiency which enables our teams across the business to deliver exceptional results every day. Our value statement: Ops makes it happen. Operations is made up of 7 functions, this role sits within: IT We are the foundation for TMHCC's success - enabling the business to grow, compete, and innovate through technology, security, and solution design. From shaping strategy to delivering resilient operations, we ensure every capability is aligned to business value. Our inclusive and collaborative culture empowers everyone to explore ideas, solve meaningful challenges, and build fulfilling careers that make a real impact. Job Purpose: Reporting to the Cyber Governance Manager in the Business Information Security Office you will own and mature TMHCC International's third-party cyber risk management processes, streamlining processes as the vendor landscape grows. You will partner with internal teams such as Procurement and Legal to prioritise risk, remediate issues and deliver clear management information on cyber risk across the third-party portfolio. Key Responsibilities: Own, manage, and evolve the third-party security due diligence process for TMHCC International vendors, including onboarding and continuous monitoring. Establish and maintain a vendor criticality assessment process; Ensure the appropriate vendor due diligence and monitoring activities take place in accordance with vendor criticality. Own and maintain ongoing due diligence requirements for critical and high-risk suppliers in line with regulatory expectations, including DORA, NIS2, PRA and FCA requirements etc. Build MI and dashboards to showcase security due diligence and third-party risk management efforts for senior IT stakeholders and executives. Collaborate with IT, Procurement, and Legal teams to embed third party security risk management controls into the overall vendor risk management process. Ensure compliance with relevant industry regulations and standards (e.g., DORA, NIS2, CIS Controls, NIST, GDPR). Provide security guidance on third party due diligence, contract reviews, and other ad-hoc vendor security risk management queries. Create and maintain vendor security risk management documentation (including process documentation) and training materials. Stay current on emerging vendor security trends, tools, and technologies. Support the Cyber Governance Manager by providing metrics to the Divisional IT Risk Reporting and Dashboards. Escalate significant cyber risks and issues as they emerge to the Cyber Governance Manager and BISO for action or information. Performance Objectives: Develop a strong understanding on TMHCC's third party landscape and current organisational controls used within the vendor risk management process and take on responsibility for cyber third-party risk management. Identify gaps and improvement areas within the cyber third-party risk processes, develop plans to further mature cyber security controls within this area, and own the implementation of these plans going forward. Skills and Experience Specification: Essential: Experience in cyber/information security risk roles with a focus on third-party/vendor risk management. Bachelor's degree in information security, Technology Risk Management or a related field. Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor. Experience in regulated industries, implementing relevant regulations and expectations for third-party security risk management. Proven experience designing, running, and improving vendor security due diligence processes. Strong knowledge of security assurance certifications and assessments maintained by vendors (e.g., ISO 27001, SOC 2, CSA STAR/CAIQ, vendor security questionnaires) Deep understanding of and ability to articulate the risk associated with vendor risk posture to both technical and non-technical stakeholders. Ability to coordinate and chair regular meetings and workshops with multiple stakeholders to provide guidance, collaboration and oversight of third-party security risk management initiatives. Confidence in presenting information and acting as a source of SME knowledge and guidance. Analytical, conceptual thinking, planning and execution skills. Ability to drive improvements and take charge of initiatives, backed with excellent coordination strength as well as assertiveness. Results-orientated and able to manage to measurable targets and desired outcomes. A passion to champion a cyber security culture and continuous learning of latest cyber threat trends. Strong communication skills with the ability to explain complex security issues to non-technical stakeholders. Desirable: Experience with third party risk management platforms or GRC tooling. Capability and experience in building actionable MI and dashboards (e.g. using Power BI) and turning data into clear decisions and narratives. Experience of the Specialty and Lloyd's/Companies market insurance industry. What We Offer The Tokio Marine HCC Group of Companies offers a competitive salary and employee benefit package. We are a successful, dynamic organization experiencing rapid growth and are seeking energetic and confident individuals to join our team of professionals.The Tokio Marine HCC Group of companies is an equal opportunity employer. Please visit for more information about our companies. success is our priority. In a world that is rapidly changing, TMHCC enables you to take on opportunities with confidence. At Tokio Marine HCC, we pride ourselves on hiring the smartest, most conscientious people, who want to make a difference no matter their background. And then we give them the support and trust they need. We're always looking for curious, creative transformative thinkers who want to change the status quo and have a passion for doing the right thing. If this is you, then we want you on our team.
Aug 21, 2026
Full time
Third Party Cyber Risk LeadApplylocations: UK - London ( St Botolph )time type: Full timeposted on: Posted Todayjob requisition id: 2026-628 Job Title: Third Party Cyber Risk Lead Reporting to: Cyber Governance Manager Direct Reports: None Position Type: Permanent Why Tokio Marine HCC? Standing still is not an option in the current world of Insurance. TMHCC is one of the world's leading Specialty Insurers. With deep expertise in our chosen lines of business, our unparalleled track record and a solid balance sheet, TMHCC evaluates and manages risk like no one else in the industry. Looking beyond profit, empowering our people and delivering on our commitments are at the core of our customer values, along with a desire to grow and provide creative and innovative solutions to our clients. About Operations Operations sits at the heart of TMHCC, we ensure the smooth running of all business processes - from policy administration and claims handling to data, technology, and delivery. We focus on driving efficiency which enables our teams across the business to deliver exceptional results every day. Our value statement: Ops makes it happen. Operations is made up of 7 functions, this role sits within: IT We are the foundation for TMHCC's success - enabling the business to grow, compete, and innovate through technology, security, and solution design. From shaping strategy to delivering resilient operations, we ensure every capability is aligned to business value. Our inclusive and collaborative culture empowers everyone to explore ideas, solve meaningful challenges, and build fulfilling careers that make a real impact. Job Purpose: Reporting to the Cyber Governance Manager in the Business Information Security Office you will own and mature TMHCC International's third-party cyber risk management processes, streamlining processes as the vendor landscape grows. You will partner with internal teams such as Procurement and Legal to prioritise risk, remediate issues and deliver clear management information on cyber risk across the third-party portfolio. Key Responsibilities: Own, manage, and evolve the third-party security due diligence process for TMHCC International vendors, including onboarding and continuous monitoring. Establish and maintain a vendor criticality assessment process; Ensure the appropriate vendor due diligence and monitoring activities take place in accordance with vendor criticality. Own and maintain ongoing due diligence requirements for critical and high-risk suppliers in line with regulatory expectations, including DORA, NIS2, PRA and FCA requirements etc. Build MI and dashboards to showcase security due diligence and third-party risk management efforts for senior IT stakeholders and executives. Collaborate with IT, Procurement, and Legal teams to embed third party security risk management controls into the overall vendor risk management process. Ensure compliance with relevant industry regulations and standards (e.g., DORA, NIS2, CIS Controls, NIST, GDPR). Provide security guidance on third party due diligence, contract reviews, and other ad-hoc vendor security risk management queries. Create and maintain vendor security risk management documentation (including process documentation) and training materials. Stay current on emerging vendor security trends, tools, and technologies. Support the Cyber Governance Manager by providing metrics to the Divisional IT Risk Reporting and Dashboards. Escalate significant cyber risks and issues as they emerge to the Cyber Governance Manager and BISO for action or information. Performance Objectives: Develop a strong understanding on TMHCC's third party landscape and current organisational controls used within the vendor risk management process and take on responsibility for cyber third-party risk management. Identify gaps and improvement areas within the cyber third-party risk processes, develop plans to further mature cyber security controls within this area, and own the implementation of these plans going forward. Skills and Experience Specification: Essential: Experience in cyber/information security risk roles with a focus on third-party/vendor risk management. Bachelor's degree in information security, Technology Risk Management or a related field. Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor. Experience in regulated industries, implementing relevant regulations and expectations for third-party security risk management. Proven experience designing, running, and improving vendor security due diligence processes. Strong knowledge of security assurance certifications and assessments maintained by vendors (e.g., ISO 27001, SOC 2, CSA STAR/CAIQ, vendor security questionnaires) Deep understanding of and ability to articulate the risk associated with vendor risk posture to both technical and non-technical stakeholders. Ability to coordinate and chair regular meetings and workshops with multiple stakeholders to provide guidance, collaboration and oversight of third-party security risk management initiatives. Confidence in presenting information and acting as a source of SME knowledge and guidance. Analytical, conceptual thinking, planning and execution skills. Ability to drive improvements and take charge of initiatives, backed with excellent coordination strength as well as assertiveness. Results-orientated and able to manage to measurable targets and desired outcomes. A passion to champion a cyber security culture and continuous learning of latest cyber threat trends. Strong communication skills with the ability to explain complex security issues to non-technical stakeholders. Desirable: Experience with third party risk management platforms or GRC tooling. Capability and experience in building actionable MI and dashboards (e.g. using Power BI) and turning data into clear decisions and narratives. Experience of the Specialty and Lloyd's/Companies market insurance industry. What We Offer The Tokio Marine HCC Group of Companies offers a competitive salary and employee benefit package. We are a successful, dynamic organization experiencing rapid growth and are seeking energetic and confident individuals to join our team of professionals.The Tokio Marine HCC Group of companies is an equal opportunity employer. Please visit for more information about our companies. success is our priority. In a world that is rapidly changing, TMHCC enables you to take on opportunities with confidence. At Tokio Marine HCC, we pride ourselves on hiring the smartest, most conscientious people, who want to make a difference no matter their background. And then we give them the support and trust they need. We're always looking for curious, creative transformative thinkers who want to change the status quo and have a passion for doing the right thing. If this is you, then we want you on our team.
National Gas Transmission Plc
Warwick, Warwickshire
Select how often (in days) to receive an alert: At National Gas, the work we do matters. As Britain's national gas network, we help keep the lights on, businesses running, and homes warm by maintaining the critical infrastructure that transports gas across Great Britain. While providing the energy security Britain relies on today, we're also helping transform the network for a clean energy future. Join us and help secure Britain's energy. About the role We're looking for an experienced Threat Intelligence & Hunting Manager to lead our intelligence fusion capability, helping National Gas anticipate, assess and respond to emerging physical, geopolitical and cyber threats. This role combines strategic intelligence leadership with proactive threat hunting to strengthen the resilience and security of critical national infrastructure. As the UK's energy landscape evolves, so do the threats facing critical national infrastructure. This role is pivotal in ensuring National Gas can identify, understand and mitigate risks before they impact our operations, people or strategic objectives. You'll lead a team responsible for producing intelligence-driven insights, managing key government and industry partnerships, and driving advanced threat hunting activities across our IT, Cloud and OT environments. Your expertise will directly influence security strategy, executive decision-making and organisational resilience. What you'll be doing Lead and develop the Threat Intelligence team, ensuring effective use of the intelligence cycle to identify and assess emerging threats. Build and maintain National Gas' common intelligence picture, delivering actionable intelligence products and executive briefings. Define and manage priority intelligence requirements, collection plans and warning indicators. Lead intelligence-led threat hunting activities to proactively identify sophisticated threats across enterprise environments. Establish and maintain relationships with key industry, government and security partners. Develop strategic threat assessments, horizon-scanning products and all-source intelligence reports to support business decision-making. Collaborate with security teams to enhance detection, monitoring and prevention capabilities across cloud, on-premise and operational technology environments. What you'll bring Significant experience in threat intelligence, intelligence analysis and intelligence operations within cyber security, defence, government or critical infrastructure environments. Strong understanding of geopolitical, physical and cyber threat landscapes and their impact on business operations. Leadership experience within cyber security operations, threat intelligence, threat hunting or incident response functions. Deep knowledge of intelligence collection, analysis methodologies and production of strategic, operational and tactical intelligence assessments. Strong technical understanding of Microsoft security technologies and security operations environments. Experience designing and leading proactive threat hunting programmes. Excellent communication skills with the ability to influence senior leaders and translate complex intelligence into clear business insights. Experience working with Operational Technology (OT) and Industrial Control System (ICS) security. Undergraduate degree or Master's qualification in Intelligence, Security Studies, Cyber Security or related discipline. SANS FOR578 (GCTI), FOR589 or equivalent threat intelligence/hunting qualifications. Experience working with government agencies and intelligence-sharing communities. Recognised leadership or management qualification. What we offer Market-leading double-match pension (up to 12% company contribution) Annual performance bonus up to 15% Access to the Tusker salary sacrifice car scheme 10x salary life assurance and income protection Flexible benefits including healthcare, dental, and technology options Family-friendly policies, wellbeing support, and professional development opportunities More information Security clearance This role is subject to National Security Vetting (NSV). Candidates must be eligible to obtain and maintain Security Clearance (SC) throughout their employment. For further information, visit (UK Security Vetting: Clearance Levels). Inclusive recruitment We're building a workforce that reflects the communities we serve, championing diversity, and creating an inclusive workplace where everyone is valued for their unique contribution. We support reasonable adjustments throughout the recruitment process and beyond. National Gas is a Disability Confident employer and signatory of the Armed Forces Covenant.
Aug 18, 2026
Full time
Select how often (in days) to receive an alert: At National Gas, the work we do matters. As Britain's national gas network, we help keep the lights on, businesses running, and homes warm by maintaining the critical infrastructure that transports gas across Great Britain. While providing the energy security Britain relies on today, we're also helping transform the network for a clean energy future. Join us and help secure Britain's energy. About the role We're looking for an experienced Threat Intelligence & Hunting Manager to lead our intelligence fusion capability, helping National Gas anticipate, assess and respond to emerging physical, geopolitical and cyber threats. This role combines strategic intelligence leadership with proactive threat hunting to strengthen the resilience and security of critical national infrastructure. As the UK's energy landscape evolves, so do the threats facing critical national infrastructure. This role is pivotal in ensuring National Gas can identify, understand and mitigate risks before they impact our operations, people or strategic objectives. You'll lead a team responsible for producing intelligence-driven insights, managing key government and industry partnerships, and driving advanced threat hunting activities across our IT, Cloud and OT environments. Your expertise will directly influence security strategy, executive decision-making and organisational resilience. What you'll be doing Lead and develop the Threat Intelligence team, ensuring effective use of the intelligence cycle to identify and assess emerging threats. Build and maintain National Gas' common intelligence picture, delivering actionable intelligence products and executive briefings. Define and manage priority intelligence requirements, collection plans and warning indicators. Lead intelligence-led threat hunting activities to proactively identify sophisticated threats across enterprise environments. Establish and maintain relationships with key industry, government and security partners. Develop strategic threat assessments, horizon-scanning products and all-source intelligence reports to support business decision-making. Collaborate with security teams to enhance detection, monitoring and prevention capabilities across cloud, on-premise and operational technology environments. What you'll bring Significant experience in threat intelligence, intelligence analysis and intelligence operations within cyber security, defence, government or critical infrastructure environments. Strong understanding of geopolitical, physical and cyber threat landscapes and their impact on business operations. Leadership experience within cyber security operations, threat intelligence, threat hunting or incident response functions. Deep knowledge of intelligence collection, analysis methodologies and production of strategic, operational and tactical intelligence assessments. Strong technical understanding of Microsoft security technologies and security operations environments. Experience designing and leading proactive threat hunting programmes. Excellent communication skills with the ability to influence senior leaders and translate complex intelligence into clear business insights. Experience working with Operational Technology (OT) and Industrial Control System (ICS) security. Undergraduate degree or Master's qualification in Intelligence, Security Studies, Cyber Security or related discipline. SANS FOR578 (GCTI), FOR589 or equivalent threat intelligence/hunting qualifications. Experience working with government agencies and intelligence-sharing communities. Recognised leadership or management qualification. What we offer Market-leading double-match pension (up to 12% company contribution) Annual performance bonus up to 15% Access to the Tusker salary sacrifice car scheme 10x salary life assurance and income protection Flexible benefits including healthcare, dental, and technology options Family-friendly policies, wellbeing support, and professional development opportunities More information Security clearance This role is subject to National Security Vetting (NSV). Candidates must be eligible to obtain and maintain Security Clearance (SC) throughout their employment. For further information, visit (UK Security Vetting: Clearance Levels). Inclusive recruitment We're building a workforce that reflects the communities we serve, championing diversity, and creating an inclusive workplace where everyone is valued for their unique contribution. We support reasonable adjustments throughout the recruitment process and beyond. National Gas is a Disability Confident employer and signatory of the Armed Forces Covenant.
Cambridge University Press & Assessment
Cambridge, Cambridgeshire
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role. We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working. This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment. Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement. Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure. Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery. Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported. Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST. Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders. Support incident preparedness, including investigations and exercises that test our ability to respond effectively. Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation. This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition. About You We are looking for someone with extensive knowledge of 5+ year experience in security testing and assurance and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks and (e.g. ISO 27001, NIST) and risk management practices. You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing. You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management. You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously. If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria: Development and maintained a supply chain risk register within a similar sized organisation Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure Experience of reporting risks to senior leadership For a detailed job description, please refer to the link at the bottom of the advert on our careers site. We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition. Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for. Rewards and benefits We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including: 28 days annual leave plus bank holidays Private medical and Permanent Health Insurance Discretionary annual bonus Group personal pension scheme Life assurance up to 4 x annual salary Green travel schemes Ready to pursue your potential? Apply now. We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2 nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after. The application and interview process consists of: 3 role related questions with brief answers A 15-minute screening call with the Hiring Manager. First stage virtual interview via MS Teams. Final stage interview: in-person at our offices in Cambridge. If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs. Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry. We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter. Why join us Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe - for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration. Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background. We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
Aug 18, 2026
Full time
Join our organisation as a Security Assurance Lead. Utilise your expertise and drive to safeguard operations in this impactful role. We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the University of Cambridge. About the role As Security Assurance Lead, you will play a key role in protecting Cambridge University Press & Assessment's information assets and strengthening our security posture. You will lead assurance activity across security testing, risk management, governance and compliance, working closely with technology, security and business teams to identify risks, improve controls and support secure ways of working. This is a varied and influential role where you will help us understand and reduce our exposure to cyber threats, shape practical security guidance, and ensure assurance activities are embedded across our technology environment. Lead security assurance activity across areas such as attack surface management, vulnerability management, penetration testing and security posture improvement. Work with technology and security teams to identify, assess and remediate vulnerabilities across systems, applications, cloud services and infrastructure. Develop and maintain security policies, standards and guidance that support effective assurance testing and secure delivery. Support risk assessments, supplier security reviews and risk register management, ensuring risks are clearly understood, tracked and reported. Contribute to security governance, compliance activities and external assessments, including alignment with frameworks such as ISO 27001 and NIST. Use threat intelligence, testing outcomes and assurance data to help shape priorities, improve resilience and inform senior stakeholders. Support incident preparedness, including investigations and exercises that test our ability to respond effectively. Help shape our security strategy, monitor emerging threats and intelligence, identifying opportunities to strengthen our approach through security automation. This position has been classified as a hybrid role, requiring the selected candidate to typically spend 40-60% of their time collaborating and connecting face-to-face at their dedicated location. Aside from our hybrid principles, other flexible working requests will be considered from the first day of employment, including other work arrangements should you require adjustments due to a disability or long-term health condition. About You We are looking for someone with extensive knowledge of 5+ year experience in security testing and assurance and a strong understanding of information security principles, emerging threats, best practices, compliance frameworks and (e.g. ISO 27001, NIST) and risk management practices. You should hold a degree in Computer Science or equivalent experience, with relevant professional qualifications including CISSP and accredited security testing. You should have proven experience in developing and managing security risks and mitigations within medium to large organisations with strong experience in stakeholder management. You should have excellent communication and presentation skills, with the ability to influence at all levels of the organisation, analytical skills to measure the effectiveness of vulnerability management plans, and be very self-motivated, proactive, and able to manage multiple projects simultaneously. If you meet the above minimum requirements, we encourage you to apply. Your application will be even stronger if you can also demonstrate the following desirable criteria: Development and maintained a supply chain risk register within a similar sized organisation Have hands on experience of the use of various AI applications and tooling, including, for example, Microsoft CoPilot, Claude etc Have experience using and deploying Pen Testing and Vulnerability Management Tools such as Tenable within complex infrastructure Experience of reporting risks to senior leadership For a detailed job description, please refer to the link at the bottom of the advert on our careers site. We are a Disability Confident (DC) employer that is committed to equality and inclusion ensuring our recruitment process is accessible to all. The DC scheme's Offer of an Interview commitment applies to applicants who opt in, and disclose a disability or a long-term health condition, and best meet the minimum criteria for the role. In instances where interviewing all qualifying candidates is not practicable, we prioritise those who best meet the minimum criteria, as we would for applicants who do not have a disability or long-term health condition. Cambridge University Press & Assessment is an approved UK employer for the sponsorship of eligible roles and applicants under the Skilled Worker visa route. Please refer to the gov.uk website for guidance to understand your own eligibility based on the role you are applying for. Rewards and benefits We will support you to be at your best in work and to live well outside of it. In addition to competitive salaries, we offer a world-class, flexible rewards package , featuring family-friendly and planet-friendly benefits including: 28 days annual leave plus bank holidays Private medical and Permanent Health Insurance Discretionary annual bonus Group personal pension scheme Life assurance up to 4 x annual salary Green travel schemes Ready to pursue your potential? Apply now. We aim to support candidates by making our interview process clear and transparent. The closing date for all applications will be 2 nd September. We will review applications on an ongoing basis, and shortlisted candidates can expect interviews to take place shortly after. The application and interview process consists of: 3 role related questions with brief answers A 15-minute screening call with the Hiring Manager. First stage virtual interview via MS Teams. Final stage interview: in-person at our offices in Cambridge. If you require any reasonable adjustments during the recruitment process due to a disability or a long-term health condition, there will be an opportunity for you to inform us via the online application form. We will do our best to accommodate your needs. Please note that successful applicants will be subject to satisfactory background checks including DBS due to working in a regulated industry. We are committed to an equitable recruitment process. As such, applications must be submitted via our official online application procedure. Please refrain from sending your CV directly to our recruiters. If you experience technical difficulties or require additional support with submitting your online application, contact the Recruiter. Why join us Joining us is your opportunity to pursue potential. You will belong to a collaborative team that is exploring new and better ways to serve students, teachers and researchers across the globe - for the benefit of individuals, society and the world. Sharing our mission will inspire your own growth, development and progress, in an environment which embraces difference, change and aspiration. Cambridge University Press & Assessment is committed to being a place where anyone can enjoy a successful career, where it is safe to speak up, and where we learn continuously to improve together. We welcome applications from all candidates, regardless of demographic characteristics (age, disability, educational attainment, ethnicity, gender, marital status, neurodiversity, religion, sex, gender identity and sexual identity), cultural, or social class/background. We believe better outcomes come through diversity of thought, background and approach. We welcome applications from people from all backgrounds and communities, actively seeking to employ people from a wide range of different communities.
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Aug 11, 2026
Full time
Introduction Saab UK is part of Scandinavia's largest defence company, bringing together the best of Swedish and British innovation. Saab offers world-leading solutions and services in defence, aviation, space, and civil security to keep people and society safe. Our UK presence has been growing at pace, meaning we can offer a wide range of opportunities for personal fulfilment and career growth. We currently employ over 600 people across eight sites in the UK, and our specialisations include software engineering, underwater robotics, radars, AI, and armed forces training. The Role: This role will be part of our UK Security Team reporting into the Head of Security at Saab UK. The role can be based either in Fareham, Farnborough or Heywood House, however it will require occasional travel oversees and travel to other Saab UK offices. Working collaboratively with the security team and IT, the role will develop and lead the Saab UK Cyber Security Strategy. As part of the Saab UK Cyber defence cell the role will be responsible for threat intelligence identification. Working closely with Security and IT develop resilience in the Saab UK Supply chain and provide the necessary GRC expertise to guide the organisation through compliancy leading on the Cyber security aspects of DefStan 05-138. This role is pivotal in safeguarding against advanced persistent threats, maintaining compliance with defence regulations, and supporting secure operations across all projects. Key Responsibilities: Develop, implement, and oversee cyber security policies aligned with defence and wider government standards. Act as the Saab UK representative on the Global Cyber Council. Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process. Manage incident response and coordinate with other company parties. Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST. Responsible for the completion of Cyber Security aspects within Supplier Assurance and selection. Maintain cyber threat awareness on a company global scale and bespoke to the organisation. Oversee security within network architecture, encryption protocols, and identity/access management for restricted environments. Direct cyber security audits and penetration testing across defence platforms and supply chains. Provide cyber security training and awareness programs tailored to defence staff and contractors. Collaborate with engineering, IT, and programme teams embedding security into defence projects (DevSecOps). Qualifications and Skills: Required: Extensive experience in cyber security management within defence, aerospace, or government environments. Strong knowledge of classified information handling and secure communication protocols. Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems. Proven track record of leading incident response in high-security environments. Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR). Excellent leadership, stakeholder management, and ability to operate under pressure. Degree in Cyber Security, Computer Science, or related field. Degree or equivalent defence/security qualifications preferred. Security clearance (SC or DV) required or eligibility to obtain. Desirable: Professional certifications: CISSP, CISM, CISA, CEH, or equivalent Experience with secure cloud environments (Azure Government, AWS GovCloud) Knowledge of cyber warfare tactics and countermeasures Experience liaising with national security agencies or defence contractors As a National Security Vetting clearance is required for this role, applicants will be required to hold National Security Vetting clearance to SC level or have the ability to gain it. By submitting an application to Saab UK you consent to undertaking workforce screening activities that may include but are not limited to: Baseline Personnel Security checks, National Security Vetting, reference checks, verification of working rights and in all circumstances preferred candidates will be placed through a security interview.
Goldman Sachs Group, Inc.
Birmingham, Staffordshire
Internal Audit, Asset & Wealth Management Technology Audit, Vice President, Birmingham Birmingham, West Midlands, England, United Kingdom Job Description In Internal Audit, we ensure that Goldman Sachs maintains effective controls by assessing the reliability of financial reports, monitoring the firm's compliance with laws and regulations, and advising management on developing smart control solutions. Our group has unique insight on the financial industry and its products and operations. We're looking for detail oriented team players who have an interest in financial markets and want to gain insight into the firm's operations and control processes. What We Do As the third line of defense, Internal Audit's mission is to independently assess the firm's internal control structure, including the firm's governance processes and controls, risk management and capital and anti financial crime frameworks, raise awareness of control risk, and monitor the implementation of management's control measures. In doing so, internal Audit: Communicates and reports on the effectiveness of the firm's governance, risk management and controls that mitigate current and evolving risk Raises awareness of control risk Assesses the firm's control culture and conduct risks Monitors management's implementation of control measures Goldman Sachs Internal Audit comprises individuals from diverse backgrounds including chartered accountants, developers, risk management professionals, cybersecurity professionals, and data scientists. We are organized into global teams comprising business and technology auditors to cover all of the firm's businesses and functions, including global banking & markets, asset & wealth management, risk management, finance, cyber security and technology risk, and engineering. Who We Look For Goldman Sachs internal auditors demonstrate strong risk and control mindsets, possess analytical skills, exercise professional skepticism and are able to challenge and discuss effectively with management on risks and control measures. We look for individuals who enjoy learning about audit, businesses and functions, have innovative and creative mindsets to adopt analytical techniques to enhance audit processes, build relationships, and are able to evolve and thrive in a fast paced global environment. Asset & Wealth Management covers the firm's Wealth Management, Public and Private Asset Management businesses. As a Technology Auditor, you will be involved in providing assurance on the integrity and quality of data used for the purposes of portfolio construction and management, deal workflows, investment research flows, reporting for internal and regulatory purposes, application stability, system operations along with other general technology controls. As part of the third line of defense, you will be involved in independently assessing the firm's overall control environment, and communicating the results to the firm's local and global management on the effectiveness of the firm's controls that mitigate current and emerging risks, and monitoring the management's implementation of control measures. In doing so, you are supporting the provision of independent, objective and timely assurance around the firm's internal control structure, and supporting the Audit Committee, the Board of Directors and Risk Committee in fulfilling their oversight responsibilities. For each assigned review you will report to an experienced project manager. You will be expected to: Assist/lead the risk assessment, scoping and planning of reviews. Assist/lead the execution of the reviews. Specifically focusing on the following: Analyze the design of controls around the underlying system architecture in the context of information technology controls and its impact on the business. Analyze the business and technology processes to evaluate the design and effectiveness of the relevant technology controls by designing and executing tests to validate identified system control features, which may require data analysis, code inspection and re performance of system processes. Document the results of the test steps executed within the Internal Audit workflow application as per the departmental guidelines. Assist in/lead the vetting of audit observations. Assist in/lead the tracking, monitoring and recording of remediation of risks identified in reviews. Qualifications BE/B Tech/MCA/MBA/MS in Information Systems or equivalent University degree in technology Minimum 8 years of experience in technology audit focusing on Financial Services Technology audit. Technology audit skills including an understanding of: System architecture, with high level understanding of databases, operating systems and messaging Prior experience of testing automated IT application controls System Development / Programming Languages System Architecture (Distributed/Messaging, Cloud, emerging technologies) Operating Systems and databases Data analysis skills (SQL, ACL, or similar tools) Application security principles System development lifecycle (SDLC) Management, monitoring and operations of technology (backups, change management, system monitoring, incident/problem management) Business continuity planning and disaster recovery design and implementation Security within the software development lifecycle Ability to review code (object oriented programming languages) Experience in managing audit engagements or technology projects Relevant Certification or industry accreditation (CISA, CISSP, etc.) Ability to work effectively across a large global audit team, understanding the team's role in the overall strategy of the firm Strong written and verbal communication skills a must; strong interpersonal skills essential. Requirement for frequent interaction with technology management Must be able to multitask while managing both timelines and workload Experience with AI, Data Analytics tools and techniques Audit experience in Cloud and other emerging technologies About Goldman Sachs At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We're committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veterans status, disability, or any other characteristic protected by applicable law. Job Info Job Identification 164888 Job Category Vice President Posting Date 03/09/2026, 05:25 PM Locations Birmingham, West Midlands, England, United Kingdom
Jul 31, 2026
Full time
Internal Audit, Asset & Wealth Management Technology Audit, Vice President, Birmingham Birmingham, West Midlands, England, United Kingdom Job Description In Internal Audit, we ensure that Goldman Sachs maintains effective controls by assessing the reliability of financial reports, monitoring the firm's compliance with laws and regulations, and advising management on developing smart control solutions. Our group has unique insight on the financial industry and its products and operations. We're looking for detail oriented team players who have an interest in financial markets and want to gain insight into the firm's operations and control processes. What We Do As the third line of defense, Internal Audit's mission is to independently assess the firm's internal control structure, including the firm's governance processes and controls, risk management and capital and anti financial crime frameworks, raise awareness of control risk, and monitor the implementation of management's control measures. In doing so, internal Audit: Communicates and reports on the effectiveness of the firm's governance, risk management and controls that mitigate current and evolving risk Raises awareness of control risk Assesses the firm's control culture and conduct risks Monitors management's implementation of control measures Goldman Sachs Internal Audit comprises individuals from diverse backgrounds including chartered accountants, developers, risk management professionals, cybersecurity professionals, and data scientists. We are organized into global teams comprising business and technology auditors to cover all of the firm's businesses and functions, including global banking & markets, asset & wealth management, risk management, finance, cyber security and technology risk, and engineering. Who We Look For Goldman Sachs internal auditors demonstrate strong risk and control mindsets, possess analytical skills, exercise professional skepticism and are able to challenge and discuss effectively with management on risks and control measures. We look for individuals who enjoy learning about audit, businesses and functions, have innovative and creative mindsets to adopt analytical techniques to enhance audit processes, build relationships, and are able to evolve and thrive in a fast paced global environment. Asset & Wealth Management covers the firm's Wealth Management, Public and Private Asset Management businesses. As a Technology Auditor, you will be involved in providing assurance on the integrity and quality of data used for the purposes of portfolio construction and management, deal workflows, investment research flows, reporting for internal and regulatory purposes, application stability, system operations along with other general technology controls. As part of the third line of defense, you will be involved in independently assessing the firm's overall control environment, and communicating the results to the firm's local and global management on the effectiveness of the firm's controls that mitigate current and emerging risks, and monitoring the management's implementation of control measures. In doing so, you are supporting the provision of independent, objective and timely assurance around the firm's internal control structure, and supporting the Audit Committee, the Board of Directors and Risk Committee in fulfilling their oversight responsibilities. For each assigned review you will report to an experienced project manager. You will be expected to: Assist/lead the risk assessment, scoping and planning of reviews. Assist/lead the execution of the reviews. Specifically focusing on the following: Analyze the design of controls around the underlying system architecture in the context of information technology controls and its impact on the business. Analyze the business and technology processes to evaluate the design and effectiveness of the relevant technology controls by designing and executing tests to validate identified system control features, which may require data analysis, code inspection and re performance of system processes. Document the results of the test steps executed within the Internal Audit workflow application as per the departmental guidelines. Assist in/lead the vetting of audit observations. Assist in/lead the tracking, monitoring and recording of remediation of risks identified in reviews. Qualifications BE/B Tech/MCA/MBA/MS in Information Systems or equivalent University degree in technology Minimum 8 years of experience in technology audit focusing on Financial Services Technology audit. Technology audit skills including an understanding of: System architecture, with high level understanding of databases, operating systems and messaging Prior experience of testing automated IT application controls System Development / Programming Languages System Architecture (Distributed/Messaging, Cloud, emerging technologies) Operating Systems and databases Data analysis skills (SQL, ACL, or similar tools) Application security principles System development lifecycle (SDLC) Management, monitoring and operations of technology (backups, change management, system monitoring, incident/problem management) Business continuity planning and disaster recovery design and implementation Security within the software development lifecycle Ability to review code (object oriented programming languages) Experience in managing audit engagements or technology projects Relevant Certification or industry accreditation (CISA, CISSP, etc.) Ability to work effectively across a large global audit team, understanding the team's role in the overall strategy of the firm Strong written and verbal communication skills a must; strong interpersonal skills essential. Requirement for frequent interaction with technology management Must be able to multitask while managing both timelines and workload Experience with AI, Data Analytics tools and techniques Audit experience in Cloud and other emerging technologies About Goldman Sachs At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We're committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veterans status, disability, or any other characteristic protected by applicable law. Job Info Job Identification 164888 Job Category Vice President Posting Date 03/09/2026, 05:25 PM Locations Birmingham, West Midlands, England, United Kingdom
Cyber Security Manager / InfoSec Manager Location Bedord / Hybrid 1-2 days a Week in the office Salary > 75k We're looking for an experienced Information Security Manager (Network / Infrastucture) with a strong technical background in network security, infrastructure security and cyber security. This role would suit someone who has progressed from a technical infrastructure or security engineering position into Information Security, Governance, Risk & Compliance (GRC) or Security Assurance. Working closely with Infrastructure, IT Operations and Engineering teams, you'll help ensure security is embedded across networks, servers, cloud environments and business systems. You'll provide technical guidance on security architecture, vulnerability management, secure configuration, patching, identity and access management, firewalls, endpoint security and infrastructure hardening, while also leading information security governance, risk management and compliance activities. You'll play a key role in maintaining and improving the Information Security Management System (ISMS), supporting ISO 27001 certification, managing security audits, supplier assurance, security incidents and business continuity planning. You'll also work with technical teams to assess vulnerabilities, review penetration testing results, oversee remediation activities and ensure security controls are implemented effectively across on-premise and cloud infrastructure. To be successful, you'll have previous experience in Network Security, Infrastructure Security, Cyber Security Engineering, Systems Engineering or Infrastructure Engineering before moving into an Information Security or Cyber Security Management role. You'll have a strong understanding of firewalls, switches, routing, Windows Server, Active Directory, Microsoft 365, Azure, endpoint security, vulnerability management, security monitoring, networking principles and infrastructure hardening, alongside experience with ISO 27001, Cyber Essentials, Governance, Risk & Compliance (GRC), security audits and information security frameworks. Key skills: Information Security Manager, Cyber Security Manager, Network Security, Infrastructure Security, Security Engineering, Infrastructure Engineering, Cyber Security, ISO 27001, ISMS, Azure Security, Microsoft 365 Security, Active Directory, Firewalls, Network Infrastructure, Vulnerability Management, Patch Management, Endpoint Security, Security Operations, Governance, Risk & Compliance, GRC, Security Assurance, Security Audits, Business Continuity, Disaster Recovery, Incident Response, Cyber Essentials.
Jul 30, 2026
Full time
Cyber Security Manager / InfoSec Manager Location Bedord / Hybrid 1-2 days a Week in the office Salary > 75k We're looking for an experienced Information Security Manager (Network / Infrastucture) with a strong technical background in network security, infrastructure security and cyber security. This role would suit someone who has progressed from a technical infrastructure or security engineering position into Information Security, Governance, Risk & Compliance (GRC) or Security Assurance. Working closely with Infrastructure, IT Operations and Engineering teams, you'll help ensure security is embedded across networks, servers, cloud environments and business systems. You'll provide technical guidance on security architecture, vulnerability management, secure configuration, patching, identity and access management, firewalls, endpoint security and infrastructure hardening, while also leading information security governance, risk management and compliance activities. You'll play a key role in maintaining and improving the Information Security Management System (ISMS), supporting ISO 27001 certification, managing security audits, supplier assurance, security incidents and business continuity planning. You'll also work with technical teams to assess vulnerabilities, review penetration testing results, oversee remediation activities and ensure security controls are implemented effectively across on-premise and cloud infrastructure. To be successful, you'll have previous experience in Network Security, Infrastructure Security, Cyber Security Engineering, Systems Engineering or Infrastructure Engineering before moving into an Information Security or Cyber Security Management role. You'll have a strong understanding of firewalls, switches, routing, Windows Server, Active Directory, Microsoft 365, Azure, endpoint security, vulnerability management, security monitoring, networking principles and infrastructure hardening, alongside experience with ISO 27001, Cyber Essentials, Governance, Risk & Compliance (GRC), security audits and information security frameworks. Key skills: Information Security Manager, Cyber Security Manager, Network Security, Infrastructure Security, Security Engineering, Infrastructure Engineering, Cyber Security, ISO 27001, ISMS, Azure Security, Microsoft 365 Security, Active Directory, Firewalls, Network Infrastructure, Vulnerability Management, Patch Management, Endpoint Security, Security Operations, Governance, Risk & Compliance, GRC, Security Assurance, Security Audits, Business Continuity, Disaster Recovery, Incident Response, Cyber Essentials.