Intelance is an independent UK advisory and assurance firm and an IASME Certification Body for Cyber Essentials, Cyber Essentials Plus and IASME Cyber Assurance. We work with mid-market, enterprise and regulated organisations across cyber assurance, governance, risk and technology. We are appointing professionals who already hold formal UK Cyber Security Council (UKCSC) registration in Cyber Security Governance and Risk Management at Principal or Chartered level, to join our associate panel and support the assessment and advisory of large, complex organisations. This is not permanent employment. Work is offered on a project-by-project basis according to client demand, suitability and availability. There is no guaranteed volume of work. Please note: current UKCSC registration in Cyber Security Governance and Risk Management at Principal or Chartered level is an essential requirement for this role. Applications without it will not be progressed. Tasks You may be asked to: Lead independent cyber governance and risk reviews for large, complex and regulated organisations. Assess risk appetite, risk ownership, control effectiveness and risk-treatment decisions. Review policies, risk registers, control mappings, assurance evidence and governance arrangements. Judge whether evidence supports the conclusions presented to senior leaders. Explain cyber risks and control gaps clearly to boards, executives and non-technical stakeholders. Lead interviews and workshops with CISOs, risk owners and control owners. Produce clear, defensible, client-ready governance and risk reports. Complete scheme-specific training and participate in internal quality reviews where required. Requirements You must hold: Current UK Cyber Security Council (UKCSC) professional registration in Cyber Security Governance and Risk Management at Principal or Chartered level. This is mandatory and will be verified. You should also have: Substantial senior experience in cyber governance, risk management or formal cyber assurance. Experience advising boards, executive teams or senior risk committees in large or regulated organisations. Practical knowledge of recognised frameworks such as ISO 27001, NIST CSF, Cyber Essentials or equivalent. Excellent written English and the ability to challenge weak evidence respectfully. CISM, CRISC, CISA and ISO 27001 Lead Auditor or Lead Implementer are welcome but do not replace the UKCSC registration requirement. You must be based in the UK, able to attend UK client sites when agreed, and able to contract through a limited company or another compliant arrangement. Benefits Senior cyber governance, risk and assurance assignments. Flexible associate working based on your availability. Direct access to Intelance leadership. Work with experienced governance, architecture and technical-assurance specialists. Clear scopes, templates and quality-review arrangements. Potential inclusion in Intelance proposals and associate credentials, subject to agreement. Please provide: Your CV and LinkedIn profile. Your UK Cyber Security Council registration: specialism, level (Principal or Chartered) and your registration number or public UKCSC profile link. Your location, availability and expected day rate. One example of a difficult enterprise cyber-risk decision you personally led. Details of any relevant Cyber Essentials, IASME, ISO 27001 or risk qualifications.
Aug 24, 2026
Full time
Intelance is an independent UK advisory and assurance firm and an IASME Certification Body for Cyber Essentials, Cyber Essentials Plus and IASME Cyber Assurance. We work with mid-market, enterprise and regulated organisations across cyber assurance, governance, risk and technology. We are appointing professionals who already hold formal UK Cyber Security Council (UKCSC) registration in Cyber Security Governance and Risk Management at Principal or Chartered level, to join our associate panel and support the assessment and advisory of large, complex organisations. This is not permanent employment. Work is offered on a project-by-project basis according to client demand, suitability and availability. There is no guaranteed volume of work. Please note: current UKCSC registration in Cyber Security Governance and Risk Management at Principal or Chartered level is an essential requirement for this role. Applications without it will not be progressed. Tasks You may be asked to: Lead independent cyber governance and risk reviews for large, complex and regulated organisations. Assess risk appetite, risk ownership, control effectiveness and risk-treatment decisions. Review policies, risk registers, control mappings, assurance evidence and governance arrangements. Judge whether evidence supports the conclusions presented to senior leaders. Explain cyber risks and control gaps clearly to boards, executives and non-technical stakeholders. Lead interviews and workshops with CISOs, risk owners and control owners. Produce clear, defensible, client-ready governance and risk reports. Complete scheme-specific training and participate in internal quality reviews where required. Requirements You must hold: Current UK Cyber Security Council (UKCSC) professional registration in Cyber Security Governance and Risk Management at Principal or Chartered level. This is mandatory and will be verified. You should also have: Substantial senior experience in cyber governance, risk management or formal cyber assurance. Experience advising boards, executive teams or senior risk committees in large or regulated organisations. Practical knowledge of recognised frameworks such as ISO 27001, NIST CSF, Cyber Essentials or equivalent. Excellent written English and the ability to challenge weak evidence respectfully. CISM, CRISC, CISA and ISO 27001 Lead Auditor or Lead Implementer are welcome but do not replace the UKCSC registration requirement. You must be based in the UK, able to attend UK client sites when agreed, and able to contract through a limited company or another compliant arrangement. Benefits Senior cyber governance, risk and assurance assignments. Flexible associate working based on your availability. Direct access to Intelance leadership. Work with experienced governance, architecture and technical-assurance specialists. Clear scopes, templates and quality-review arrangements. Potential inclusion in Intelance proposals and associate credentials, subject to agreement. Please provide: Your CV and LinkedIn profile. Your UK Cyber Security Council registration: specialism, level (Principal or Chartered) and your registration number or public UKCSC profile link. Your location, availability and expected day rate. One example of a difficult enterprise cyber-risk decision you personally led. Details of any relevant Cyber Essentials, IASME, ISO 27001 or risk qualifications.
Intelance is an independent UK advisory and assurance firm and an IASME Certification Body for Cyber Essentials, Cyber Essentials Plus and IASME Cyber Assurance. We work with mid-market, enterprise and regulated organisations across cyber assurance, governance, risk and technology. We are appointing professionals who already hold formal UK Cyber Security Council (UKCSC) registration in Cyber Security Governance and Risk Management at Principal or Chartered level, to join our associate panel and support the assessment and advisory of large, complex organisations. This is not permanent employment. Work is offered on a project-by-project basis according to client demand, suitability and availability. There is no guaranteed volume of work. Please note: current UKCSC registration in Cyber Security Governance and Risk Management at Principal or Chartered level is an essential requirement for this role. Applications without it will not be progressed. Tasks You may be asked to: Lead independent cyber governance and risk reviews for large, complex and regulated organisations. Assess risk appetite, risk ownership, control effectiveness and risk-treatment decisions. Review policies, risk registers, control mappings, assurance evidence and governance arrangements. Judge whether evidence supports the conclusions presented to senior leaders. Explain cyber risks and control gaps clearly to boards, executives and non-technical stakeholders. Lead interviews and workshops with CISOs, risk owners and control owners. Produce clear, defensible, client-ready governance and risk reports. Complete scheme-specific training and participate in internal quality reviews where required. Requirements You must hold: Current UK Cyber Security Council (UKCSC) professional registration in Cyber Security Governance and Risk Management at Principal or Chartered level. This is mandatory and will be verified. You should also have: Substantial senior experience in cyber governance, risk management or formal cyber assurance. Experience advising boards, executive teams or senior risk committees in large or regulated organisations. Practical knowledge of recognised frameworks such as ISO 27001, NIST CSF, Cyber Essentials or equivalent. Excellent written English and the ability to challenge weak evidence respectfully. CISM, CRISC, CISA and ISO 27001 Lead Auditor or Lead Implementer are welcome but do not replace the UKCSC registration requirement. You must be based in the UK, able to attend UK client sites when agreed, and able to contract through a limited company or another compliant arrangement. Benefits Senior cyber governance, risk and assurance assignments. Flexible associate working based on your availability. Direct access to Intelance leadership. Work with experienced governance, architecture and technical-assurance specialists. Clear scopes, templates and quality-review arrangements. Potential inclusion in Intelance proposals and associate credentials, subject to agreement.
Aug 24, 2026
Full time
Intelance is an independent UK advisory and assurance firm and an IASME Certification Body for Cyber Essentials, Cyber Essentials Plus and IASME Cyber Assurance. We work with mid-market, enterprise and regulated organisations across cyber assurance, governance, risk and technology. We are appointing professionals who already hold formal UK Cyber Security Council (UKCSC) registration in Cyber Security Governance and Risk Management at Principal or Chartered level, to join our associate panel and support the assessment and advisory of large, complex organisations. This is not permanent employment. Work is offered on a project-by-project basis according to client demand, suitability and availability. There is no guaranteed volume of work. Please note: current UKCSC registration in Cyber Security Governance and Risk Management at Principal or Chartered level is an essential requirement for this role. Applications without it will not be progressed. Tasks You may be asked to: Lead independent cyber governance and risk reviews for large, complex and regulated organisations. Assess risk appetite, risk ownership, control effectiveness and risk-treatment decisions. Review policies, risk registers, control mappings, assurance evidence and governance arrangements. Judge whether evidence supports the conclusions presented to senior leaders. Explain cyber risks and control gaps clearly to boards, executives and non-technical stakeholders. Lead interviews and workshops with CISOs, risk owners and control owners. Produce clear, defensible, client-ready governance and risk reports. Complete scheme-specific training and participate in internal quality reviews where required. Requirements You must hold: Current UK Cyber Security Council (UKCSC) professional registration in Cyber Security Governance and Risk Management at Principal or Chartered level. This is mandatory and will be verified. You should also have: Substantial senior experience in cyber governance, risk management or formal cyber assurance. Experience advising boards, executive teams or senior risk committees in large or regulated organisations. Practical knowledge of recognised frameworks such as ISO 27001, NIST CSF, Cyber Essentials or equivalent. Excellent written English and the ability to challenge weak evidence respectfully. CISM, CRISC, CISA and ISO 27001 Lead Auditor or Lead Implementer are welcome but do not replace the UKCSC registration requirement. You must be based in the UK, able to attend UK client sites when agreed, and able to contract through a limited company or another compliant arrangement. Benefits Senior cyber governance, risk and assurance assignments. Flexible associate working based on your availability. Direct access to Intelance leadership. Work with experienced governance, architecture and technical-assurance specialists. Clear scopes, templates and quality-review arrangements. Potential inclusion in Intelance proposals and associate credentials, subject to agreement.
Project Quality Assurance Engineer This role will be based at our Cyber Centre of Excellence in Maidenhead. Hybrid working is available. Candidates must be willing and able to obtain & maintain DV Security Clearance. Our Cyber business unit is at the forefront of pioneering advanced cryptographic and key management solutions, facilitating the confidential exchange of vital information for customers operating at both tactical and strategic echelons. Join our team and participate in the innovation that ensures the highest security and trust worldwide. As Project Quality Engineer, you are responsible for developing and implementing project quality plans that meet business, customer and contractual requirements. Working under the delegated authority of the Director of Security, Quality & Compliance, the role assures quality across assigned projects and supports the mandatory quality elements of the Business Management System, and helps ensure agreed quality objectives and deliverables are consistently achieved. Key Responsibilities: Develop, implement and maintain project and product quality plans to ensure customer flow-down requirements, contractual obligations and applicable quality standards are met. Define, communicate and manage project quality assurance activities through approved quality plans and effective quality controls. Plan and conduct project, product and process audits in line with applicable standards, including AS9101, to confirm compliance with customer, statutory, regulatory and business management system requirements. Carry out in-process, final and first article inspections to verify that defined processes consistently deliver products that meet specification. Manage non-conformance reporting, root cause analysis, corrective and preventive actions to support continual improvement and prevent recurrence. Work with project, production and process teams to improve operating processes, product yields and overall quality performance. Review, improve and, where appropriate, implement quality processes within Cyber to ensure products and services meet customer needs efficiently and cost-effectively. Develop and maintain strong relationships with internal and external stakeholders to support effective quality outcomes. Promote a quality-focused culture across the business. Required Skills and Qualifications: Degree-qualified, or able to demonstrate equivalent verifiable experience, ideally in a business, quality, software engineering or mechanical engineering discipline. Proven quality engineering experience within the aerospace, defence or similarly regulated sector. Qualified internal auditor with experience of AS9100; IRCA-approved Lead Auditor qualification is preferred. Experience working in a business improvement environment, with knowledge of recognised improvement frameworks. Experience in the use of root cause analysis and problem-solving methodologies. Notice: Due to the nature of the programs we deliver for our customers, candidates may need to obtain the relevant security clearance or handle export-controlled material as defined by the role's requirements. Applicants must be able to obtain and maintain the appropriate level of security clearance for the role. Due to the nature of our work, you must be a British Citizen who has been resident in the UK for the past 5 years in order to apply for SC clearance and 10 years for DV. For more information, please visit the UKSV website. Our Benefits: Every employee is critical to our success, and as such, we offer a range of flexible employee benefits, including: Participation in an Annual Bonus Scheme Private Medical Cover 25 days holiday (plus Bank Holidays) with the option to buy an extra 5 days Pension Contribution 4 x Life Assurance Cover Flexible working hours with opportunity for a 1pm finish on a Friday Flexible benefits including cycle to work scheme, will writing and more Security Clearance Allowance where relevant and subject to you holding the required security clearance Diversity, Equity & Inclusion Statement: At Ultra I&C, we are an equal opportunity employer and value diversity and inclusivity. Underpinned by our values, behaviours, and policies, we want you to feel empowered to be the best version of yourself. We also believe that people from different backgrounds and cultures will increase our diversity of thinking, ensuring we successfully deliver to our customers. We, therefore, do not discriminate based on race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We also support requests for flexible working arrangements wherever possible.
Aug 22, 2026
Full time
Project Quality Assurance Engineer This role will be based at our Cyber Centre of Excellence in Maidenhead. Hybrid working is available. Candidates must be willing and able to obtain & maintain DV Security Clearance. Our Cyber business unit is at the forefront of pioneering advanced cryptographic and key management solutions, facilitating the confidential exchange of vital information for customers operating at both tactical and strategic echelons. Join our team and participate in the innovation that ensures the highest security and trust worldwide. As Project Quality Engineer, you are responsible for developing and implementing project quality plans that meet business, customer and contractual requirements. Working under the delegated authority of the Director of Security, Quality & Compliance, the role assures quality across assigned projects and supports the mandatory quality elements of the Business Management System, and helps ensure agreed quality objectives and deliverables are consistently achieved. Key Responsibilities: Develop, implement and maintain project and product quality plans to ensure customer flow-down requirements, contractual obligations and applicable quality standards are met. Define, communicate and manage project quality assurance activities through approved quality plans and effective quality controls. Plan and conduct project, product and process audits in line with applicable standards, including AS9101, to confirm compliance with customer, statutory, regulatory and business management system requirements. Carry out in-process, final and first article inspections to verify that defined processes consistently deliver products that meet specification. Manage non-conformance reporting, root cause analysis, corrective and preventive actions to support continual improvement and prevent recurrence. Work with project, production and process teams to improve operating processes, product yields and overall quality performance. Review, improve and, where appropriate, implement quality processes within Cyber to ensure products and services meet customer needs efficiently and cost-effectively. Develop and maintain strong relationships with internal and external stakeholders to support effective quality outcomes. Promote a quality-focused culture across the business. Required Skills and Qualifications: Degree-qualified, or able to demonstrate equivalent verifiable experience, ideally in a business, quality, software engineering or mechanical engineering discipline. Proven quality engineering experience within the aerospace, defence or similarly regulated sector. Qualified internal auditor with experience of AS9100; IRCA-approved Lead Auditor qualification is preferred. Experience working in a business improvement environment, with knowledge of recognised improvement frameworks. Experience in the use of root cause analysis and problem-solving methodologies. Notice: Due to the nature of the programs we deliver for our customers, candidates may need to obtain the relevant security clearance or handle export-controlled material as defined by the role's requirements. Applicants must be able to obtain and maintain the appropriate level of security clearance for the role. Due to the nature of our work, you must be a British Citizen who has been resident in the UK for the past 5 years in order to apply for SC clearance and 10 years for DV. For more information, please visit the UKSV website. Our Benefits: Every employee is critical to our success, and as such, we offer a range of flexible employee benefits, including: Participation in an Annual Bonus Scheme Private Medical Cover 25 days holiday (plus Bank Holidays) with the option to buy an extra 5 days Pension Contribution 4 x Life Assurance Cover Flexible working hours with opportunity for a 1pm finish on a Friday Flexible benefits including cycle to work scheme, will writing and more Security Clearance Allowance where relevant and subject to you holding the required security clearance Diversity, Equity & Inclusion Statement: At Ultra I&C, we are an equal opportunity employer and value diversity and inclusivity. Underpinned by our values, behaviours, and policies, we want you to feel empowered to be the best version of yourself. We also believe that people from different backgrounds and cultures will increase our diversity of thinking, ensuring we successfully deliver to our customers. We, therefore, do not discriminate based on race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We also support requests for flexible working arrangements wherever possible.
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Aug 22, 2026
Full time
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
SRT Marine Systems plc
Gloucester, Gloucestershire
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Aug 22, 2026
Full time
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Aug 22, 2026
Full time
SRT Marine Systems plc (SRT) are a market leader in its domain of international marine surveillance technology and systems. We are respected, established and an ambitious multi-national company headquartered in the UK with a global customer base. The company has a global impact in the marine domain by leading the next generation of Maritime Domain Awareness 'MDA' technologies, products and systems that significantly enhance, security, safety and environment protection and sustainability. Our customers are worldwide and range from the largest national coast guards to individual vessel owners. SRT is an exciting company where high quality results are rewarded. We are ambitious and are constantly seeking to innovate to deliver better products and services to our customers. We strive to make SRT a rewarding and challenging place to work where talented hard-working individuals have the opportunity to make a real impact across the marine world. We are looking for a Security & Compliance Manager to own the security of how our products and systems are deployed, operated and maintained in customer environments around the world, and to lead the security assurance and certification activity that stands behind them. This is a senior, customer-facing leadership role sitting at the intersection of secure delivery, customer operations and corporate security. You as a Security & Compliance Manager will work closely with our delivery, customer-facing, network & infrastructure and corporate IT teams, and with our external security partners, to make sure the systems we deploy remain secure throughout their operational life. The role is focused on leadership, coordination and communication rather than hands-on engineering. Much of the knowledge needed already exists across the business - your job is to bring it together into a coherent programme, and to be the champion who drives it through, backed by enough technical understanding to hold detailed conversations with customers, auditors and developers. The role of Security & Compliance Manager is primarily based from our Bristol office, but you must be willing to travel to our offices in Cardiff and Bath on occasion, and from time to time to customer sites worldwide, with good flexibility for Hybrid working. Responsibilities - Security & Compliance Manager - not exhaustive: Act as the senior voice and champion for security across our delivery and customer operations, ensuring deployed systems receive the same security attention as new ones. Define the customer operating policies, principles and patterns that delivery and customer-facing teams should follow for the secure implementation and operation of SRT systems. Own the through-life security of equipment deployed in customer environments, including patching, secure configuration, and equipment lifecycle and end-of-life replacement. Lead SRT's responses to customer security requirements, assurance questionnaires and connection approvals, including for sophisticated government and defence customers. Work with internal stakeholders to ensure engineering and operational reality supports the security claims we make to customers, partners and auditors. Lead our assurance and certification activity, including Cyber Essentials Plus, ISO 27001 and other relevant standards. Bring together the security expertise that already exists across the business into one coherent, prioritised programme of improvement. Direct our external security partners as an extended resource pool for monitoring, assessments and remediation. Assign pragmatic risk levels and support sensible prioritisation of remediation alongside project delivery and other commitments. Report clearly to senior leadership on risk, progress and priorities in business terms. Requirements - Security & Compliance Manager - not exhaustive: Strong experience in security management, security assurance, compliance or a similar role, ideally where systems are delivered into and operated within customer environments. A track record of achieving and maintaining certifications such as ISO 27001 and Cyber Essentials Plus, including managing audits. Practical understanding of securing deployed infrastructure, including firewalls, patching, secure configuration and equipment lifecycle management. Experience leading customer-facing security engagements, including security questionnaires, accreditation and third-party assurance. The presence and communication skills to champion change across teams and to influence stakeholders without direct authority. The judgement to assess risk and business impact pragmatically. Experience coordinating third-party security providers such as managed SOC or security service partners. Familiarity with recognised frameworks such as ISO 27001, Cyber Essentials Plus, NIST CSF or similar. Experience in an engineering or manufacturing business delivering long-lived systems would be helpful. Experience in high-trust, regulated or mission-critical environments would be valuable. Benefits Highly Competitive Salary and benefits package 25 days annual leave rising to 28 days with service Real individual development opportunities SRT Marine Systems plc is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and welcome applications from all backgrounds.
Vehicle allowance Company pension scheme. Professional membership fees paid. Funded continuing professional development. Support towards Chartered status and advanced qualifications. Role This is a rare opportunity to take ownership of Health, Safety, Quality, Environmental, Information Security and Corporate Compliance across a growing specialist contractor delivering complex projects throughout the UK. Reporting directly to the Directors, you will play a pivotal role in shaping the company's governance framework, strengthening their compliance culture and supporting the next phase of business growth across Defence, Government, Critical National Infrastructure and commercial sectors. This role offers far more than traditional Health & Safety management. It is an opportunity to influence strategic decision-making, modernise assurance processes and build an integrated compliance function that enables safe, secure and successful project delivery. Their teams work within some of the UK's most complex and security-sensitive environments, including Defence establishments, Government facilities, Critical National Infrastructure sites and operational commercial environments. Responsibilities You will act as the principal advisor to the Board on matters relating to: Health & Safety Corporate Governance Principal Contractor Compliance CDM Regulations Integrated Management Systems ISO Compliance Information Security Risk Management Environmental Performance Internal and External Auditing Accreditation and Certification Supply Chain Assurance Training and Competence You will work collaboratively with Directors, managers, employees, subcontractors and clients to ensure compliance is embedded into everyday decision-making and operational delivery. Key Responsibilities Strategic Leadership Lead and develop the company's Health, Safety, Quality, Environmental and Information Security strategy Provide expert advice and guidance to Directors and senior leadership teams. Promote a positive, proactive and accountable compliance culture. Ensure legal, contractual and regulatory obligations are effectively managed. Integrated Management Systems Own and continually improve the company's Integrated Management System. Lead compliance with ISO 9001, ISO 14001, ISO 45001 and ISO 27001. Ensure ongoing certification readiness and continual improvement. Health, Safety and CDM Compliance Act as the company's competent Health & Safety adviser. Support the business in delivering its duties as Principal Contractor. Provide leadership on CDM compliance across projects. Lead incident investigations, corrective actions and organisational learning initiatives. Governance, Assurance and Audit Develop and deliver risk-based audit programmes. Lead internal and external assurance activities. Manage certification bodies, client audits and compliance assessments. Produce meaningful compliance reporting and dashboards for senior leadership. Information Security and Corporate Compliance Support the development and maintenance of ISO 27001 certification. Strengthen information security, governance and business resilience arrangements. Support compliance with Defence, Government and client-specific requirements. Maintain effective corporate governance and risk management frameworks. People, Culture and Capability Oversee competence management and compliance training programmes. Develop leadership accountability across all levels of the business. Build employee engagement and ownership of compliance responsibilities. Foster a culture of continual improvement and operational excellence. Requirement You are an experienced Health, Safety and Compliance leader who combines technical expertise with commercial awareness and practical problem solving skills. You are comfortable operating at Board level whilst remaining engaged with operational delivery and project teams. You understand how robust governance, effective assurance and strong leadership can support business growth, protect reputation and improve client confidence. Experience within regulated industries such as construction, infrastructure, telecommunications, utilities, Defence or Critical National Infrastructure would be highly advantageous. Essential NEBOSH Diploma or equivalent Level 6 Health & Safety qualification. Chartered IOSH membership or demonstrable progression toward Chartered status. Significant senior level Health, Safety and Compliance leadership experience. Strong knowledge of CDM Regulations and Principal Contractor responsibilities. Experience managing Integrated Management Systems. Practical experience of ISO 9001, ISO 14001 and ISO 45001. Working knowledge of ISO 27001 and Information Security governance. Experience leading audit, compliance and assurance programmes. Strong stakeholder management and communication skills. Full UK Driving Licence and willingness to travel throughout the UK. Desirable Chartered IOSH status. Lead Auditor qualifications. Experience working within Defence or Government environments. Knowledge of UK Government Security requirements. Experience with Cyber Essentials Plus. Previous responsibility for corporate governance and business assurance functions. Experience within telecommunications, infrastructure, civil engineering or secure communications sectors. Security Clearance Current security clearance is not essential; however, candidates must be eligible and willing to undergo UK Government Security Vetting and satisfy the requirements for Developed Vetting where required by the role, project or client. You will work directly with company leadership, support major programmes within Defence and Critical National Infrastructure, and help create the governance framework that supports future growth.
Aug 22, 2026
Full time
Vehicle allowance Company pension scheme. Professional membership fees paid. Funded continuing professional development. Support towards Chartered status and advanced qualifications. Role This is a rare opportunity to take ownership of Health, Safety, Quality, Environmental, Information Security and Corporate Compliance across a growing specialist contractor delivering complex projects throughout the UK. Reporting directly to the Directors, you will play a pivotal role in shaping the company's governance framework, strengthening their compliance culture and supporting the next phase of business growth across Defence, Government, Critical National Infrastructure and commercial sectors. This role offers far more than traditional Health & Safety management. It is an opportunity to influence strategic decision-making, modernise assurance processes and build an integrated compliance function that enables safe, secure and successful project delivery. Their teams work within some of the UK's most complex and security-sensitive environments, including Defence establishments, Government facilities, Critical National Infrastructure sites and operational commercial environments. Responsibilities You will act as the principal advisor to the Board on matters relating to: Health & Safety Corporate Governance Principal Contractor Compliance CDM Regulations Integrated Management Systems ISO Compliance Information Security Risk Management Environmental Performance Internal and External Auditing Accreditation and Certification Supply Chain Assurance Training and Competence You will work collaboratively with Directors, managers, employees, subcontractors and clients to ensure compliance is embedded into everyday decision-making and operational delivery. Key Responsibilities Strategic Leadership Lead and develop the company's Health, Safety, Quality, Environmental and Information Security strategy Provide expert advice and guidance to Directors and senior leadership teams. Promote a positive, proactive and accountable compliance culture. Ensure legal, contractual and regulatory obligations are effectively managed. Integrated Management Systems Own and continually improve the company's Integrated Management System. Lead compliance with ISO 9001, ISO 14001, ISO 45001 and ISO 27001. Ensure ongoing certification readiness and continual improvement. Health, Safety and CDM Compliance Act as the company's competent Health & Safety adviser. Support the business in delivering its duties as Principal Contractor. Provide leadership on CDM compliance across projects. Lead incident investigations, corrective actions and organisational learning initiatives. Governance, Assurance and Audit Develop and deliver risk-based audit programmes. Lead internal and external assurance activities. Manage certification bodies, client audits and compliance assessments. Produce meaningful compliance reporting and dashboards for senior leadership. Information Security and Corporate Compliance Support the development and maintenance of ISO 27001 certification. Strengthen information security, governance and business resilience arrangements. Support compliance with Defence, Government and client-specific requirements. Maintain effective corporate governance and risk management frameworks. People, Culture and Capability Oversee competence management and compliance training programmes. Develop leadership accountability across all levels of the business. Build employee engagement and ownership of compliance responsibilities. Foster a culture of continual improvement and operational excellence. Requirement You are an experienced Health, Safety and Compliance leader who combines technical expertise with commercial awareness and practical problem solving skills. You are comfortable operating at Board level whilst remaining engaged with operational delivery and project teams. You understand how robust governance, effective assurance and strong leadership can support business growth, protect reputation and improve client confidence. Experience within regulated industries such as construction, infrastructure, telecommunications, utilities, Defence or Critical National Infrastructure would be highly advantageous. Essential NEBOSH Diploma or equivalent Level 6 Health & Safety qualification. Chartered IOSH membership or demonstrable progression toward Chartered status. Significant senior level Health, Safety and Compliance leadership experience. Strong knowledge of CDM Regulations and Principal Contractor responsibilities. Experience managing Integrated Management Systems. Practical experience of ISO 9001, ISO 14001 and ISO 45001. Working knowledge of ISO 27001 and Information Security governance. Experience leading audit, compliance and assurance programmes. Strong stakeholder management and communication skills. Full UK Driving Licence and willingness to travel throughout the UK. Desirable Chartered IOSH status. Lead Auditor qualifications. Experience working within Defence or Government environments. Knowledge of UK Government Security requirements. Experience with Cyber Essentials Plus. Previous responsibility for corporate governance and business assurance functions. Experience within telecommunications, infrastructure, civil engineering or secure communications sectors. Security Clearance Current security clearance is not essential; however, candidates must be eligible and willing to undergo UK Government Security Vetting and satisfy the requirements for Developed Vetting where required by the role, project or client. You will work directly with company leadership, support major programmes within Defence and Critical National Infrastructure, and help create the governance framework that supports future growth.
Citizens Advice Stevenage is an ambitious and innovative member of the Citizens Advice network. We have expanded our services and offering to meet the increased demand in the area, doubling in size over the last few years. As a positive subsequence, we are looking for a Head of Finance & Business Support, who will become a core member of the Senior Leadership Team, responsible for overseeing the financial stewardship of Citizens Advice Stevenage. To lead on financial governance, business support operations, and compliance, ensuring the organization operates sustainably and meets all legal and regulatory obligations. The role is pivotal in safeguarding the charity's financial integrity, supporting strategic decision-making, and enabling effective service delivery. Financial Leadership Prepare, review, and present draft and final budgets for approval by the board, ensuring timely submission of financial information to the CEO and Trustee Board. Oversee financial reporting processes, ensuring accuracy, transparency, and compliance with regulatory standards, including variance analysis and annual balance sheets, ensuring timely submission of financial information to the CEO and Trustee Board. Manage the reserves policy, ensuring regular review and alignment with operational needs and financial risks. Identify and manage financial risks, ensuring integration into the organization's risk register and adherence to appropriate mitigations. Ensure that the day-to-day finance and back-office function is high performing and compliant, safeguarding effective and efficient financial management processes. To co-ordinate the proactive and timely dissemination of high-quality financial information to services, the CEO, and Board such as annual budgets, monthly management accounts, cash flow analysis, financial forecasting and monthly business performance figures. To ensure that the organisation has in place, robust and compliant financial systems and procedures; and that these are complied with by all budget holders, ensuring that any oversights are fully investigated and reported upwards as necessary. To lead on the preparation of statutory accounts, provide year end accounts, provide appropriate support and assistance to the organisation's auditors and delivery of recommendations arising from the Audit process. To ensure that all statutory returns are complete in a timely and effective manner, including those in relation to VAT, PAYE, NIC and SSP, and that appropriate compliance dates are met for the Charities Commission and Companies House. Oversee the transactions, activities and processes of the external payroll provider. To monitor and advise on current and future tax legislation, with a view to optimisation. To support service managers in the preparation of bids and contract negotiations and provide financial activity analysis and reports in line with specific project reporting requirements. To monitor, report and make recommendations regarding the Investment and Reserves Policy to the Board. To oversee the payroll function to ensure employees are paid in an accurate and timely manner. To monitor and control creditors and debtors, ensuring invoices are paid on time and the risk of bad debts is minimised. Compliance and Risk Management Ensure compliance with all applicable regulatory frameworks, including the Charity Commission, Companies House, FCA, ICO, and other relevant bodies. Maintain and regularly review financial systems, controls, and policies, ensuring they are effectively implemented and aligned with legal requirements. Conduct due diligence for pension, redundancy, and other liabilities, ensuring plans are in place for management and mitigation. Support the trustee board in understanding risks related to projects and contracts, providing assurance of compliance with funders' requirements. To lead on the Risk Management process, advising the CEO and managers on risk matters, and reviewing the risk register on a regular basis, reporting to the Board of Trustees. To check, amend and monitor the Financial Procedures Manual; reporting material breaches to the CEO and Board of Trustees, as required/in-line with governance. Working with the senior leadership team monitoring and updating Insurance matters as required, reporting to the CEO and Board of Trustees. Business Support Operations Lead on organisational business continuity planning, ensuring resilience during crises and alignment with the charity's objectives. Oversee the development, implementation, and review of key policies, ensuring they reflect legal obligations and organisational values. Manage IT systems and cybersecurity measures to protect organisational data and operations, ensuring compliance with standards such as Cyber Essentials. Strategic Contribution Provides proactive strategic financial advice and guidance to the Trustees and wider leadership team, monitoring and reporting on the financial performance against agreed targets, identified risks and key performance indicators. Provide financial and operational insights to inform strategic decision-making and long-term planning. Foster a culture of continuous improvement and financial accountability across the organisation. Funding strategy: Support the CEO and board to regularly review the sustainability of its income sources and their impact on achieving charitable purposes in the short, medium and longer term. Work with the CEO and Head of Impact and Development to prepare the funding strategy that should go beyond immediate budgetary considerations and look at the wider funding landscape. The organisation needs to understand potential emerging opportunities and the organisation's readiness to pursue them. Team and Stakeholder Engagement Build and maintain effective relationships with trustees, funders, regulators, and key stakeholders, to ensure that Citizens Advice Stevenage meets its financial, regulatory and legal obligations. Provide leadership and support to finance and business support teams, ensuring professional development and effective performance management. People management and development Develop and implement a culture of continuous learning that will equip and develop people to deliver outstanding delivery. Responsibility for the training and development plan for the Finance and Business Support ensuring it is in effective operation including maintaining records of training needs identified and training attended. Working with the rest of the leadership team ensure the organisation delivers a fair, inclusive, equitable and transparent employee and volunteer experience, taking account of our EDI aims and in line with employment law and the Equality Act 2010. Ensure Open and timely communication that provides information about the organisation and context for decisions that are made, helps to build trust and confidence and earn legitimacy. Ensure the effective performance management and development of staff through regular supervision sessions, appraisals and learning and development. Person Specification ACA/ACCA/CIMA Qualified, CPE up to date. Strong financial management experience at a similar level within the charity/not for profit sector A proven track record of leading, developing and inspiring small teams Experience of strategic business & financial planning, forecasting and budget management. Sound experience of producing month-end management accounts and audited year-end financial accounts Experience of managing and using financial systems A working knowledge of relevant legislation (regulatory, legal and financial) in the context of a charitable organisation Experience of managing change and change programmes A track record of initiating, leading and managing associated risks Strong influencing, negotiating and collaborative working skills, with the ability to present complex financial information clearly and concisely in writing or verbally Confident IT skills; confident using Microsoft Office applications, especially Excel Experience designing and introducing new financial processes, procedures and reports Working knowledge of QuickBooks software advantageous Experience working with a Board of Trustees advantageous Understanding of Charity Commission and Companies House reporting requirements Project and/or professional services experience Understanding of Charity Law Experience of working in the not-for-profit sector Understanding and experience using the Charity Governance Code Experience in working with Charity SORP . click apply for full job details
Aug 22, 2026
Full time
Citizens Advice Stevenage is an ambitious and innovative member of the Citizens Advice network. We have expanded our services and offering to meet the increased demand in the area, doubling in size over the last few years. As a positive subsequence, we are looking for a Head of Finance & Business Support, who will become a core member of the Senior Leadership Team, responsible for overseeing the financial stewardship of Citizens Advice Stevenage. To lead on financial governance, business support operations, and compliance, ensuring the organization operates sustainably and meets all legal and regulatory obligations. The role is pivotal in safeguarding the charity's financial integrity, supporting strategic decision-making, and enabling effective service delivery. Financial Leadership Prepare, review, and present draft and final budgets for approval by the board, ensuring timely submission of financial information to the CEO and Trustee Board. Oversee financial reporting processes, ensuring accuracy, transparency, and compliance with regulatory standards, including variance analysis and annual balance sheets, ensuring timely submission of financial information to the CEO and Trustee Board. Manage the reserves policy, ensuring regular review and alignment with operational needs and financial risks. Identify and manage financial risks, ensuring integration into the organization's risk register and adherence to appropriate mitigations. Ensure that the day-to-day finance and back-office function is high performing and compliant, safeguarding effective and efficient financial management processes. To co-ordinate the proactive and timely dissemination of high-quality financial information to services, the CEO, and Board such as annual budgets, monthly management accounts, cash flow analysis, financial forecasting and monthly business performance figures. To ensure that the organisation has in place, robust and compliant financial systems and procedures; and that these are complied with by all budget holders, ensuring that any oversights are fully investigated and reported upwards as necessary. To lead on the preparation of statutory accounts, provide year end accounts, provide appropriate support and assistance to the organisation's auditors and delivery of recommendations arising from the Audit process. To ensure that all statutory returns are complete in a timely and effective manner, including those in relation to VAT, PAYE, NIC and SSP, and that appropriate compliance dates are met for the Charities Commission and Companies House. Oversee the transactions, activities and processes of the external payroll provider. To monitor and advise on current and future tax legislation, with a view to optimisation. To support service managers in the preparation of bids and contract negotiations and provide financial activity analysis and reports in line with specific project reporting requirements. To monitor, report and make recommendations regarding the Investment and Reserves Policy to the Board. To oversee the payroll function to ensure employees are paid in an accurate and timely manner. To monitor and control creditors and debtors, ensuring invoices are paid on time and the risk of bad debts is minimised. Compliance and Risk Management Ensure compliance with all applicable regulatory frameworks, including the Charity Commission, Companies House, FCA, ICO, and other relevant bodies. Maintain and regularly review financial systems, controls, and policies, ensuring they are effectively implemented and aligned with legal requirements. Conduct due diligence for pension, redundancy, and other liabilities, ensuring plans are in place for management and mitigation. Support the trustee board in understanding risks related to projects and contracts, providing assurance of compliance with funders' requirements. To lead on the Risk Management process, advising the CEO and managers on risk matters, and reviewing the risk register on a regular basis, reporting to the Board of Trustees. To check, amend and monitor the Financial Procedures Manual; reporting material breaches to the CEO and Board of Trustees, as required/in-line with governance. Working with the senior leadership team monitoring and updating Insurance matters as required, reporting to the CEO and Board of Trustees. Business Support Operations Lead on organisational business continuity planning, ensuring resilience during crises and alignment with the charity's objectives. Oversee the development, implementation, and review of key policies, ensuring they reflect legal obligations and organisational values. Manage IT systems and cybersecurity measures to protect organisational data and operations, ensuring compliance with standards such as Cyber Essentials. Strategic Contribution Provides proactive strategic financial advice and guidance to the Trustees and wider leadership team, monitoring and reporting on the financial performance against agreed targets, identified risks and key performance indicators. Provide financial and operational insights to inform strategic decision-making and long-term planning. Foster a culture of continuous improvement and financial accountability across the organisation. Funding strategy: Support the CEO and board to regularly review the sustainability of its income sources and their impact on achieving charitable purposes in the short, medium and longer term. Work with the CEO and Head of Impact and Development to prepare the funding strategy that should go beyond immediate budgetary considerations and look at the wider funding landscape. The organisation needs to understand potential emerging opportunities and the organisation's readiness to pursue them. Team and Stakeholder Engagement Build and maintain effective relationships with trustees, funders, regulators, and key stakeholders, to ensure that Citizens Advice Stevenage meets its financial, regulatory and legal obligations. Provide leadership and support to finance and business support teams, ensuring professional development and effective performance management. People management and development Develop and implement a culture of continuous learning that will equip and develop people to deliver outstanding delivery. Responsibility for the training and development plan for the Finance and Business Support ensuring it is in effective operation including maintaining records of training needs identified and training attended. Working with the rest of the leadership team ensure the organisation delivers a fair, inclusive, equitable and transparent employee and volunteer experience, taking account of our EDI aims and in line with employment law and the Equality Act 2010. Ensure Open and timely communication that provides information about the organisation and context for decisions that are made, helps to build trust and confidence and earn legitimacy. Ensure the effective performance management and development of staff through regular supervision sessions, appraisals and learning and development. Person Specification ACA/ACCA/CIMA Qualified, CPE up to date. Strong financial management experience at a similar level within the charity/not for profit sector A proven track record of leading, developing and inspiring small teams Experience of strategic business & financial planning, forecasting and budget management. Sound experience of producing month-end management accounts and audited year-end financial accounts Experience of managing and using financial systems A working knowledge of relevant legislation (regulatory, legal and financial) in the context of a charitable organisation Experience of managing change and change programmes A track record of initiating, leading and managing associated risks Strong influencing, negotiating and collaborative working skills, with the ability to present complex financial information clearly and concisely in writing or verbally Confident IT skills; confident using Microsoft Office applications, especially Excel Experience designing and introducing new financial processes, procedures and reports Working knowledge of QuickBooks software advantageous Experience working with a Board of Trustees advantageous Understanding of Charity Commission and Companies House reporting requirements Project and/or professional services experience Understanding of Charity Law Experience of working in the not-for-profit sector Understanding and experience using the Charity Governance Code Experience in working with Charity SORP . click apply for full job details
Information Security & Assurance Officer Salary: up to 50,000 + 15% Project Uplift + Company Car/Car Allowance Location: Suffolk (onsite) REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities. You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders. This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments and support internal and external audits Manage supplier and third-party security assurance activities Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring Work closely with SOC and security service providers to support incident management and response activities Produce security reports, dashboards and assurance documentation for senior stakeholders Deliver security awareness initiatives across the organisation Support continuous improvement of security controls, processes and governance frameworks About You We're interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier or third-party security assessments Security incident management and response processes Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms Building strong relationships with stakeholders at all levels Desirable Experience Cyber Essentials or Cyber Essentials Plus NIST Cyber Security Framework Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent What's on Offer? 15% project uplift paid monthly Company car or car allowance Annual bonus Private medical insurance Life assurance Enhanced pension contributions 25 days annual leave plus bank holidays Additional holiday purchase scheme Professional memberships paid Ongoing training and development opportunities This is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.
Aug 21, 2026
Full time
Information Security & Assurance Officer Salary: up to 50,000 + 15% Project Uplift + Company Car/Car Allowance Location: Suffolk (onsite) REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities. You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders. This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments and support internal and external audits Manage supplier and third-party security assurance activities Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring Work closely with SOC and security service providers to support incident management and response activities Produce security reports, dashboards and assurance documentation for senior stakeholders Deliver security awareness initiatives across the organisation Support continuous improvement of security controls, processes and governance frameworks About You We're interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier or third-party security assessments Security incident management and response processes Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms Building strong relationships with stakeholders at all levels Desirable Experience Cyber Essentials or Cyber Essentials Plus NIST Cyber Security Framework Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent What's on Offer? 15% project uplift paid monthly Company car or car allowance Annual bonus Private medical insurance Life assurance Enhanced pension contributions 25 days annual leave plus bank holidays Additional holiday purchase scheme Professional memberships paid Ongoing training and development opportunities This is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.
About OLIX AI is growing faster than any technology in history and the explosion in demand has created a massive infrastructure gap; we can no longer build chips or power stations fast enough to keep up. The industry is still leaning on a ten-year-old hardware blueprint that has reached its limit. A new paradigm that is faster and more efficient will be the biggest economic opportunity of the next century and create the most important company of the next decade. The OLIX Decode Accelerator 1 (DX-1) is the first accelerator architected specifically for decode. Rack-scale co-design of logic, data movement, packaging, optics and interconnect enables a step change in system level performance. The Role Quality at OLIX is not a support function, it is a strategic pillar. As we drive toward tape-out and the transition from development to production, we need a Director of Quality who will build the quality infrastructure that OLIX's technology deserves: rigorous enough to satisfy world-class customers and partners, and lean enough to move at the pace our mission demands. This is a founding quality leadership role. OLIX is a fabless company: we build our products through a global network of best-in-class manufacturing and supply-chain partners, which means quality at OLIX is won or lost in the supply chain. You will define what quality means for novel optical computing technology, build our Quality Management System from a blank page, own supplier and partner quality across our manufacturing ecosystem, and be the quality voice at every critical decision point from tape-out readiness through to deployment. OLIX systems are designed for deployment at datacentre scale, so quality does not end at shipment. You will own reliability from component qualification through to fleet performance in the field, and you will scale the quality organisation as OLIX grows from first product launch into high-volume manufacturing. Key Responsibilities Quality Management System Design, implement, and own OLIX's Quality Management System from the ground up, targeting ISO 9001 certification and laying the foundation for more advanced standards as the business scales Define quality policies, procedures, metrics, document control, and CAPA processes that are fit for a fast-moving fabless company: rigorous without being bureaucratic Establish quality gates and review processes across the full product lifecycle, from design sign-off through tape-out, manufacturing, test, and deployment Build a quality culture at OLIX, partnering with engineering and operations teams to embed quality thinking early Supplier & Partner Quality Own the supplier quality programme across OLIX's foundry, OSAT, contract manufacturer, and component ecosystem, spanning silicon, advanced packaging, optical components, and compound semiconductor supply Lead supplier qualification, audits, corrective action programmes, and ongoing performance management through structured KPIs and scorecards Define and manage incoming inspection and acceptance criteria for wafers, substrates, optical components, and materials arriving from the supply chain Build OLIX's approved supplier list and qualification documentation to the standard required by tier-1 customers and strategic partners Product Qualification & Reliability Own the product qualification strategy for OLIX's silicon, optical components, modules, and systems: reliability test plans, qualification flows, and acceptance criteria informed by JEDEC and Telcordia GR-468 or equivalent standards Lead Design for Reliability reviews alongside engineering and manufacturing teams, ensuring quality implications are factored into design decisions before commitments are made Stand up failure analysis capability and FRACAS processes to close the loop on development, manufacturing, and field quality issues Drive yield, defect, and reliability improvement programmes across manufacturing partners using structured methodologies including SPC, FMEA, 8D, and DOE Manufacturing & Fleet Quality Establish manufacturing quality systems with OSAT and contract manufacturing partners: process capability, control plans, PFMEA, escape prevention, and data-driven continuous improvement Define quality and compliance requirements for OLIX's internal cleanroom and pilot manufacturing capability, including equipment safety and conformity Own field quality for deployed systems: fleet reliability metrics, field failure analysis, and corrective action loops that feed back into design and manufacturing Regulatory Compliance & Certification Ensure OLIX products meet applicable regulatory and certification requirements for datacentre deployment, including CE and UKCA marking, product safety (IEC 62368-1), laser safety (IEC 60825), EMC and EMI, RoHS, REACH, conflict minerals, and cybersecurity requirements under the Cyber Resilience Act Define and manage compliance validation activities with test houses, notified bodies, and certification partners across target markets Skills & Experience 12+ years in Quality Engineering or Quality Management within the semiconductor, photonics, electronics, or advanced manufacturing industries, including at least five years leading teams Demonstrated experience building a Quality Management System from the ground up in a fabless or early-stage environment, then scaling it through NPI into volume production Deep supplier quality expertise managing foundries, OSATs, and contract manufacturers in an outsourced manufacturing model Strong grounding in semiconductor and optoelectronic qualification and reliability: JEDEC, Telcordia GR-468, or equivalent standards Hands-on proficiency with quality tools and methodologies: SPC, FMEA and PFMEA, control plans, 8D, DOE, and CAPA Experience leading product compliance and certification for electronic hardware, including CE or UKCA, safety, and EMC Comfortable operating hands-on in a fast-moving, pre-scale environment: able to define standards without over-engineering them, and to build the team as the company grows Willingness to travel regularly to manufacturing partners across Taiwan, Japan, the US, and Europe Bachelor's degree in Engineering, Physics, Materials Science, or a related technical discipline Nice to Have Experience with optical or photonic component reliability, including laser-based components Datacentre or hyperscaler hardware quality experience, including fleet reliability and RAS ISO 9001 Lead Auditor certification, ASQ CQE or CMQ/OE, or Six Sigma Black Belt Master's degree in Engineering, Quality, Manufacturing, or Business Administration Compensation & Equity Competitive Salary: Commensurate with your experience, skills, and location Equity & Ownership: Meaningful stock options. You're not just joining the mission; you're owning a piece of it Proximity Bonus: We value your time. To minimise your commute and maximise your life, we offer an annual Living-Local Bonus if your residence is within 20 minutes of the office Retirement Benefits:Employer-contributed retirement plans to help you build long-term financial security Due to U.S. export control regulations, candidates' eligibility to work at OLIX depends on their most recent citizenship or permanent residency status. We are generally unable to consider applicants whose most recent citizenship or permanent residence is in certain restricted countries (currently including Iran, North Korea, Syria, Cuba, Russia, Belarus, China, Hong Kong, Macau, and Venezuela). Applicants who have subsequently obtained citizenship or permanent residency in another country not subject to these restrictions may still be eligible.
Aug 21, 2026
Full time
About OLIX AI is growing faster than any technology in history and the explosion in demand has created a massive infrastructure gap; we can no longer build chips or power stations fast enough to keep up. The industry is still leaning on a ten-year-old hardware blueprint that has reached its limit. A new paradigm that is faster and more efficient will be the biggest economic opportunity of the next century and create the most important company of the next decade. The OLIX Decode Accelerator 1 (DX-1) is the first accelerator architected specifically for decode. Rack-scale co-design of logic, data movement, packaging, optics and interconnect enables a step change in system level performance. The Role Quality at OLIX is not a support function, it is a strategic pillar. As we drive toward tape-out and the transition from development to production, we need a Director of Quality who will build the quality infrastructure that OLIX's technology deserves: rigorous enough to satisfy world-class customers and partners, and lean enough to move at the pace our mission demands. This is a founding quality leadership role. OLIX is a fabless company: we build our products through a global network of best-in-class manufacturing and supply-chain partners, which means quality at OLIX is won or lost in the supply chain. You will define what quality means for novel optical computing technology, build our Quality Management System from a blank page, own supplier and partner quality across our manufacturing ecosystem, and be the quality voice at every critical decision point from tape-out readiness through to deployment. OLIX systems are designed for deployment at datacentre scale, so quality does not end at shipment. You will own reliability from component qualification through to fleet performance in the field, and you will scale the quality organisation as OLIX grows from first product launch into high-volume manufacturing. Key Responsibilities Quality Management System Design, implement, and own OLIX's Quality Management System from the ground up, targeting ISO 9001 certification and laying the foundation for more advanced standards as the business scales Define quality policies, procedures, metrics, document control, and CAPA processes that are fit for a fast-moving fabless company: rigorous without being bureaucratic Establish quality gates and review processes across the full product lifecycle, from design sign-off through tape-out, manufacturing, test, and deployment Build a quality culture at OLIX, partnering with engineering and operations teams to embed quality thinking early Supplier & Partner Quality Own the supplier quality programme across OLIX's foundry, OSAT, contract manufacturer, and component ecosystem, spanning silicon, advanced packaging, optical components, and compound semiconductor supply Lead supplier qualification, audits, corrective action programmes, and ongoing performance management through structured KPIs and scorecards Define and manage incoming inspection and acceptance criteria for wafers, substrates, optical components, and materials arriving from the supply chain Build OLIX's approved supplier list and qualification documentation to the standard required by tier-1 customers and strategic partners Product Qualification & Reliability Own the product qualification strategy for OLIX's silicon, optical components, modules, and systems: reliability test plans, qualification flows, and acceptance criteria informed by JEDEC and Telcordia GR-468 or equivalent standards Lead Design for Reliability reviews alongside engineering and manufacturing teams, ensuring quality implications are factored into design decisions before commitments are made Stand up failure analysis capability and FRACAS processes to close the loop on development, manufacturing, and field quality issues Drive yield, defect, and reliability improvement programmes across manufacturing partners using structured methodologies including SPC, FMEA, 8D, and DOE Manufacturing & Fleet Quality Establish manufacturing quality systems with OSAT and contract manufacturing partners: process capability, control plans, PFMEA, escape prevention, and data-driven continuous improvement Define quality and compliance requirements for OLIX's internal cleanroom and pilot manufacturing capability, including equipment safety and conformity Own field quality for deployed systems: fleet reliability metrics, field failure analysis, and corrective action loops that feed back into design and manufacturing Regulatory Compliance & Certification Ensure OLIX products meet applicable regulatory and certification requirements for datacentre deployment, including CE and UKCA marking, product safety (IEC 62368-1), laser safety (IEC 60825), EMC and EMI, RoHS, REACH, conflict minerals, and cybersecurity requirements under the Cyber Resilience Act Define and manage compliance validation activities with test houses, notified bodies, and certification partners across target markets Skills & Experience 12+ years in Quality Engineering or Quality Management within the semiconductor, photonics, electronics, or advanced manufacturing industries, including at least five years leading teams Demonstrated experience building a Quality Management System from the ground up in a fabless or early-stage environment, then scaling it through NPI into volume production Deep supplier quality expertise managing foundries, OSATs, and contract manufacturers in an outsourced manufacturing model Strong grounding in semiconductor and optoelectronic qualification and reliability: JEDEC, Telcordia GR-468, or equivalent standards Hands-on proficiency with quality tools and methodologies: SPC, FMEA and PFMEA, control plans, 8D, DOE, and CAPA Experience leading product compliance and certification for electronic hardware, including CE or UKCA, safety, and EMC Comfortable operating hands-on in a fast-moving, pre-scale environment: able to define standards without over-engineering them, and to build the team as the company grows Willingness to travel regularly to manufacturing partners across Taiwan, Japan, the US, and Europe Bachelor's degree in Engineering, Physics, Materials Science, or a related technical discipline Nice to Have Experience with optical or photonic component reliability, including laser-based components Datacentre or hyperscaler hardware quality experience, including fleet reliability and RAS ISO 9001 Lead Auditor certification, ASQ CQE or CMQ/OE, or Six Sigma Black Belt Master's degree in Engineering, Quality, Manufacturing, or Business Administration Compensation & Equity Competitive Salary: Commensurate with your experience, skills, and location Equity & Ownership: Meaningful stock options. You're not just joining the mission; you're owning a piece of it Proximity Bonus: We value your time. To minimise your commute and maximise your life, we offer an annual Living-Local Bonus if your residence is within 20 minutes of the office Retirement Benefits:Employer-contributed retirement plans to help you build long-term financial security Due to U.S. export control regulations, candidates' eligibility to work at OLIX depends on their most recent citizenship or permanent residency status. We are generally unable to consider applicants whose most recent citizenship or permanent residence is in certain restricted countries (currently including Iran, North Korea, Syria, Cuba, Russia, Belarus, China, Hong Kong, Macau, and Venezuela). Applicants who have subsequently obtained citizenship or permanent residency in another country not subject to these restrictions may still be eligible.
Third Party Cyber Risk LeadApplylocations: UK - London ( St Botolph )time type: Full timeposted on: Posted Todayjob requisition id: 2026-628 Job Title: Third Party Cyber Risk Lead Reporting to: Cyber Governance Manager Direct Reports: None Position Type: Permanent Why Tokio Marine HCC? Standing still is not an option in the current world of Insurance. TMHCC is one of the world's leading Specialty Insurers. With deep expertise in our chosen lines of business, our unparalleled track record and a solid balance sheet, TMHCC evaluates and manages risk like no one else in the industry. Looking beyond profit, empowering our people and delivering on our commitments are at the core of our customer values, along with a desire to grow and provide creative and innovative solutions to our clients. About Operations Operations sits at the heart of TMHCC, we ensure the smooth running of all business processes - from policy administration and claims handling to data, technology, and delivery. We focus on driving efficiency which enables our teams across the business to deliver exceptional results every day. Our value statement: Ops makes it happen. Operations is made up of 7 functions, this role sits within: IT We are the foundation for TMHCC's success - enabling the business to grow, compete, and innovate through technology, security, and solution design. From shaping strategy to delivering resilient operations, we ensure every capability is aligned to business value. Our inclusive and collaborative culture empowers everyone to explore ideas, solve meaningful challenges, and build fulfilling careers that make a real impact. Job Purpose: Reporting to the Cyber Governance Manager in the Business Information Security Office you will own and mature TMHCC International's third-party cyber risk management processes, streamlining processes as the vendor landscape grows. You will partner with internal teams such as Procurement and Legal to prioritise risk, remediate issues and deliver clear management information on cyber risk across the third-party portfolio. Key Responsibilities: Own, manage, and evolve the third-party security due diligence process for TMHCC International vendors, including onboarding and continuous monitoring. Establish and maintain a vendor criticality assessment process; Ensure the appropriate vendor due diligence and monitoring activities take place in accordance with vendor criticality. Own and maintain ongoing due diligence requirements for critical and high-risk suppliers in line with regulatory expectations, including DORA, NIS2, PRA and FCA requirements etc. Build MI and dashboards to showcase security due diligence and third-party risk management efforts for senior IT stakeholders and executives. Collaborate with IT, Procurement, and Legal teams to embed third party security risk management controls into the overall vendor risk management process. Ensure compliance with relevant industry regulations and standards (e.g., DORA, NIS2, CIS Controls, NIST, GDPR). Provide security guidance on third party due diligence, contract reviews, and other ad-hoc vendor security risk management queries. Create and maintain vendor security risk management documentation (including process documentation) and training materials. Stay current on emerging vendor security trends, tools, and technologies. Support the Cyber Governance Manager by providing metrics to the Divisional IT Risk Reporting and Dashboards. Escalate significant cyber risks and issues as they emerge to the Cyber Governance Manager and BISO for action or information. Performance Objectives: Develop a strong understanding on TMHCC's third party landscape and current organisational controls used within the vendor risk management process and take on responsibility for cyber third-party risk management. Identify gaps and improvement areas within the cyber third-party risk processes, develop plans to further mature cyber security controls within this area, and own the implementation of these plans going forward. Skills and Experience Specification: Essential: Experience in cyber/information security risk roles with a focus on third-party/vendor risk management. Bachelor's degree in information security, Technology Risk Management or a related field. Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor. Experience in regulated industries, implementing relevant regulations and expectations for third-party security risk management. Proven experience designing, running, and improving vendor security due diligence processes. Strong knowledge of security assurance certifications and assessments maintained by vendors (e.g., ISO 27001, SOC 2, CSA STAR/CAIQ, vendor security questionnaires) Deep understanding of and ability to articulate the risk associated with vendor risk posture to both technical and non-technical stakeholders. Ability to coordinate and chair regular meetings and workshops with multiple stakeholders to provide guidance, collaboration and oversight of third-party security risk management initiatives. Confidence in presenting information and acting as a source of SME knowledge and guidance. Analytical, conceptual thinking, planning and execution skills. Ability to drive improvements and take charge of initiatives, backed with excellent coordination strength as well as assertiveness. Results-orientated and able to manage to measurable targets and desired outcomes. A passion to champion a cyber security culture and continuous learning of latest cyber threat trends. Strong communication skills with the ability to explain complex security issues to non-technical stakeholders. Desirable: Experience with third party risk management platforms or GRC tooling. Capability and experience in building actionable MI and dashboards (e.g. using Power BI) and turning data into clear decisions and narratives. Experience of the Specialty and Lloyd's/Companies market insurance industry. What We Offer The Tokio Marine HCC Group of Companies offers a competitive salary and employee benefit package. We are a successful, dynamic organization experiencing rapid growth and are seeking energetic and confident individuals to join our team of professionals.The Tokio Marine HCC Group of companies is an equal opportunity employer. Please visit for more information about our companies. success is our priority. In a world that is rapidly changing, TMHCC enables you to take on opportunities with confidence. At Tokio Marine HCC, we pride ourselves on hiring the smartest, most conscientious people, who want to make a difference no matter their background. And then we give them the support and trust they need. We're always looking for curious, creative transformative thinkers who want to change the status quo and have a passion for doing the right thing. If this is you, then we want you on our team.
Aug 21, 2026
Full time
Third Party Cyber Risk LeadApplylocations: UK - London ( St Botolph )time type: Full timeposted on: Posted Todayjob requisition id: 2026-628 Job Title: Third Party Cyber Risk Lead Reporting to: Cyber Governance Manager Direct Reports: None Position Type: Permanent Why Tokio Marine HCC? Standing still is not an option in the current world of Insurance. TMHCC is one of the world's leading Specialty Insurers. With deep expertise in our chosen lines of business, our unparalleled track record and a solid balance sheet, TMHCC evaluates and manages risk like no one else in the industry. Looking beyond profit, empowering our people and delivering on our commitments are at the core of our customer values, along with a desire to grow and provide creative and innovative solutions to our clients. About Operations Operations sits at the heart of TMHCC, we ensure the smooth running of all business processes - from policy administration and claims handling to data, technology, and delivery. We focus on driving efficiency which enables our teams across the business to deliver exceptional results every day. Our value statement: Ops makes it happen. Operations is made up of 7 functions, this role sits within: IT We are the foundation for TMHCC's success - enabling the business to grow, compete, and innovate through technology, security, and solution design. From shaping strategy to delivering resilient operations, we ensure every capability is aligned to business value. Our inclusive and collaborative culture empowers everyone to explore ideas, solve meaningful challenges, and build fulfilling careers that make a real impact. Job Purpose: Reporting to the Cyber Governance Manager in the Business Information Security Office you will own and mature TMHCC International's third-party cyber risk management processes, streamlining processes as the vendor landscape grows. You will partner with internal teams such as Procurement and Legal to prioritise risk, remediate issues and deliver clear management information on cyber risk across the third-party portfolio. Key Responsibilities: Own, manage, and evolve the third-party security due diligence process for TMHCC International vendors, including onboarding and continuous monitoring. Establish and maintain a vendor criticality assessment process; Ensure the appropriate vendor due diligence and monitoring activities take place in accordance with vendor criticality. Own and maintain ongoing due diligence requirements for critical and high-risk suppliers in line with regulatory expectations, including DORA, NIS2, PRA and FCA requirements etc. Build MI and dashboards to showcase security due diligence and third-party risk management efforts for senior IT stakeholders and executives. Collaborate with IT, Procurement, and Legal teams to embed third party security risk management controls into the overall vendor risk management process. Ensure compliance with relevant industry regulations and standards (e.g., DORA, NIS2, CIS Controls, NIST, GDPR). Provide security guidance on third party due diligence, contract reviews, and other ad-hoc vendor security risk management queries. Create and maintain vendor security risk management documentation (including process documentation) and training materials. Stay current on emerging vendor security trends, tools, and technologies. Support the Cyber Governance Manager by providing metrics to the Divisional IT Risk Reporting and Dashboards. Escalate significant cyber risks and issues as they emerge to the Cyber Governance Manager and BISO for action or information. Performance Objectives: Develop a strong understanding on TMHCC's third party landscape and current organisational controls used within the vendor risk management process and take on responsibility for cyber third-party risk management. Identify gaps and improvement areas within the cyber third-party risk processes, develop plans to further mature cyber security controls within this area, and own the implementation of these plans going forward. Skills and Experience Specification: Essential: Experience in cyber/information security risk roles with a focus on third-party/vendor risk management. Bachelor's degree in information security, Technology Risk Management or a related field. Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor. Experience in regulated industries, implementing relevant regulations and expectations for third-party security risk management. Proven experience designing, running, and improving vendor security due diligence processes. Strong knowledge of security assurance certifications and assessments maintained by vendors (e.g., ISO 27001, SOC 2, CSA STAR/CAIQ, vendor security questionnaires) Deep understanding of and ability to articulate the risk associated with vendor risk posture to both technical and non-technical stakeholders. Ability to coordinate and chair regular meetings and workshops with multiple stakeholders to provide guidance, collaboration and oversight of third-party security risk management initiatives. Confidence in presenting information and acting as a source of SME knowledge and guidance. Analytical, conceptual thinking, planning and execution skills. Ability to drive improvements and take charge of initiatives, backed with excellent coordination strength as well as assertiveness. Results-orientated and able to manage to measurable targets and desired outcomes. A passion to champion a cyber security culture and continuous learning of latest cyber threat trends. Strong communication skills with the ability to explain complex security issues to non-technical stakeholders. Desirable: Experience with third party risk management platforms or GRC tooling. Capability and experience in building actionable MI and dashboards (e.g. using Power BI) and turning data into clear decisions and narratives. Experience of the Specialty and Lloyd's/Companies market insurance industry. What We Offer The Tokio Marine HCC Group of Companies offers a competitive salary and employee benefit package. We are a successful, dynamic organization experiencing rapid growth and are seeking energetic and confident individuals to join our team of professionals.The Tokio Marine HCC Group of companies is an equal opportunity employer. Please visit for more information about our companies. success is our priority. In a world that is rapidly changing, TMHCC enables you to take on opportunities with confidence. At Tokio Marine HCC, we pride ourselves on hiring the smartest, most conscientious people, who want to make a difference no matter their background. And then we give them the support and trust they need. We're always looking for curious, creative transformative thinkers who want to change the status quo and have a passion for doing the right thing. If this is you, then we want you on our team.
Head of Security (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Head of Security (CISO) to lead and evolve our group-wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Qualifications Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Benefits Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
Aug 14, 2026
Full time
Head of Security (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Head of Security (CISO) to lead and evolve our group-wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Qualifications Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Benefits Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
Chief Information Security Officer (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Chief Information Security Officer (CISO) to lead and evolve our group wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI-DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI-DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI-DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
Aug 07, 2026
Full time
Chief Information Security Officer (CISO) Location: Hybrid Permanent ClearCourse is seeking an experienced Chief Information Security Officer (CISO) to lead and evolve our group wide security strategy across a diverse portfolio of 40+ software and payments businesses. Reporting to the Chief Technology & Transformation Officer, with a dotted line to the Board and Audit Committee, this is a pivotal executive leadership role responsible for security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI-DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding security across the organisation. What you'll do Define and lead the Group's security strategy, policies, and governance framework Provide Board-level reporting on security posture, risks, and compliance activities Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI-DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials, PCI-DSS, and data protection obligations Manage relationships with auditors, regulators, cyber insurers, and certification bodies Lead security assessments and integration activities for acquisitions, driving alignment to Group standards Partner with Platform Engineering teams to embed security practices into development lifecycles without impacting delivery velocity Lead and develop the GRC function to support a proactive and risk aware security culture Previous experience operating at CISO level within a multi-product or multi-entity organisation Hands on experience leading PCI DSS compliance programmes and QSA assessments Proven expertise building and managing enterprise wide GRC frameworks and risk registers Experience assessing and integrating security functions following M&A activity Strong understanding of DevSecOps principles and embedding security into engineering practices Experience leading major security incidents, including external communications and stakeholder management Ability to influence at Board and executive leadership level Strong leadership skills with experience building and developing high performing security teams Competitive salary + benefits 25 days holiday + your birthday off Private medical insurance (Bupa) & health cash plan Life assurance & income protection Enhanced parental leave & family wellbeing support Perkbox discounts & perks Generous pension contributions Hybrid working model This is a rare opportunity to shape and lead the security strategy of a fast growing international software and payments group. You'll work at executive level, influence critical business decisions, and play a key role in safeguarding the future growth of the organisation. If you're passionate about security leadership and thrive in complex, evolving environments, we'd love to hear from you.
Colt Technology Services Group Ltd. seeks a Technology Lead Internal Auditor to lead technology and security audits across Colt locations, guiding planning, execution, reporting and follow-up. You will assess control design and operation, and communicate findings clearly to senior stakeholders. The role requires deep audit experience in technology/cyber security, strong analytical and people skills, and readiness to coach junior staff while upholding Colt's audit methodology.
Jul 31, 2026
Full time
Colt Technology Services Group Ltd. seeks a Technology Lead Internal Auditor to lead technology and security audits across Colt locations, guiding planning, execution, reporting and follow-up. You will assess control design and operation, and communicate findings clearly to senior stakeholders. The role requires deep audit experience in technology/cyber security, strong analytical and people skills, and readiness to coach junior staff while upholding Colt's audit methodology.
Select how often (in days) to receive an alert: The Technology Lead Internal Auditor is primarily responsible for leading and/or participating in technology and security focused audits with support over technology control elements of financial and operational audit assignments. They will be responsible for evaluating the adequacy of Colt's (Colt Core and DCS) overall control environment in both design and application, highlighting inefficiencies in processes and supporting the business in building a sustainable control environment. The Technology Lead Internal Auditor will also be responsible for assisting on ad-hoc special projects and completing audit projects in any of Colt's locations. This role is a great opportunity to add value and develop expertise across technology, security, and transformation processes across multiple business units. What you will do Deliver and/or lead technology and security audit assignments across Colt locations in a timely and efficient manner, participating in all stages of the audit from planning, execution, reporting and follow-up Fully understand and communicate the impact of audit findings (including root causes and risks) to relevant key stakeholders. As technology and security can be complex, being able to communicate complex technical issues and ideas in simple terms is highly valued. Make value add recommendations to the business to improve controls, processes and overall governance Engage with stakeholders to obtain a comprehensive understanding of the business under review and the implications for audit Build trust and credibility with technology stakeholders throughout the audit process Maintain audit documentation in accordance with Colt audit methodology Provide coaching to junior staff members (e.g. graduates/apprentices) on audit methodology and practices, where applicable What we're looking for Experienced technology auditor (e.g. CISA, CISSP, ISO or CIMA qualification preferred but not essential) Some experience in using or planning data analytic based audits. Ability to analyse data and identify trends, think critically and solve problems using a high degree of intellectual curiosity and good judgement Over 3 years' experience working in a technology and/or cyber security audit related role either as an internal auditor or in related auditing/assurance fields Good experience of controls on risk and assurance assignments, including greenfield audits Strong knowledge of audit techniques for technology and security (business and operational control and risk management, a bonus). Ability to operate in a flat organisational structure with direct exposure to senior management andExecutives Strong communication skills, proactiveness, and competence to influence outcomes Work effectively with team members and the wider businessto build partnerships. Job Segment: Internal Audit, Cyber Security, Risk Management, Audit, Finance, Security
Jul 31, 2026
Full time
Select how often (in days) to receive an alert: The Technology Lead Internal Auditor is primarily responsible for leading and/or participating in technology and security focused audits with support over technology control elements of financial and operational audit assignments. They will be responsible for evaluating the adequacy of Colt's (Colt Core and DCS) overall control environment in both design and application, highlighting inefficiencies in processes and supporting the business in building a sustainable control environment. The Technology Lead Internal Auditor will also be responsible for assisting on ad-hoc special projects and completing audit projects in any of Colt's locations. This role is a great opportunity to add value and develop expertise across technology, security, and transformation processes across multiple business units. What you will do Deliver and/or lead technology and security audit assignments across Colt locations in a timely and efficient manner, participating in all stages of the audit from planning, execution, reporting and follow-up Fully understand and communicate the impact of audit findings (including root causes and risks) to relevant key stakeholders. As technology and security can be complex, being able to communicate complex technical issues and ideas in simple terms is highly valued. Make value add recommendations to the business to improve controls, processes and overall governance Engage with stakeholders to obtain a comprehensive understanding of the business under review and the implications for audit Build trust and credibility with technology stakeholders throughout the audit process Maintain audit documentation in accordance with Colt audit methodology Provide coaching to junior staff members (e.g. graduates/apprentices) on audit methodology and practices, where applicable What we're looking for Experienced technology auditor (e.g. CISA, CISSP, ISO or CIMA qualification preferred but not essential) Some experience in using or planning data analytic based audits. Ability to analyse data and identify trends, think critically and solve problems using a high degree of intellectual curiosity and good judgement Over 3 years' experience working in a technology and/or cyber security audit related role either as an internal auditor or in related auditing/assurance fields Good experience of controls on risk and assurance assignments, including greenfield audits Strong knowledge of audit techniques for technology and security (business and operational control and risk management, a bonus). Ability to operate in a flat organisational structure with direct exposure to senior management andExecutives Strong communication skills, proactiveness, and competence to influence outcomes Work effectively with team members and the wider businessto build partnerships. Job Segment: Internal Audit, Cyber Security, Risk Management, Audit, Finance, Security
Location: Hybrid with travel to Corsham and other South Military sites. Security Clearance: SC Conventus is recruiting a Junior Cyber Audit Consultant to join a Defence focused Cyber Assurance team, playing a supporting role to senior consultants delivering audits across customer processes and systems. This is a great opportunity to build a career in Defence Cyber Audit, with a genuine pathway to progress into a fully fledged Cyber Audit Consultant role. You will be playing a supporting role to the main consultants delivering Cyber Risk Profile (CRP) audit work, with development into a fully fledged Cyber Audit Consultant role over time. Responsibilities: Plan and conduct audits of customer processes and systems to ensure compliance with regulatory requirements such as the NCSC Cyber Assessment Framework (CAF) and GovAssure. Support and, over time, help lead audit activity, ensuring findings are properly documented and reported. Communicate audit findings and recommendations, working collaboratively with management to help develop and implement effective corrective actions. Maintain accurate and current records of audit activities, including audit reports and documentation of corrective actions taken. Stay current with regulatory requirements and industry best practice relating to auditing, compliance and risk management. Contribute to cyber report writing and the production of Cyber Risk Profiles (CRP) Skills/Experience: Experience of ISO 27001, the NCSC Cyber Assessment Framework (CAF), DCC and Cyber Risk Profile (CRP) work. Experience of cyber report writing. Relevant ISO certification (for example ISO 27001 Lead Auditor or equivalent) is desirable. Experience in auditing, compliance or risk management, ideally gained in the Public Sector, particularly Defence. Understanding of NCSC CAF v3.2/v4.0. Some MoD experience is desirable but not essential. Strong analytical and problem solving skills. Excellent communication and interpersonal skills. Ability to work independently and as part of a team. Permanent role with a genuine career path into a Cyber Audit Consultant position. Structured support, mentoring and development within a specialist Defence focused team. Exposure to nationally significant Defence cyber assurance work. Due to the nature of the work, applicants must hold or be eligible to hold UK Security clearance to SC level. Please familiarise yourself with the security vetting process before applying.
Jul 31, 2026
Full time
Location: Hybrid with travel to Corsham and other South Military sites. Security Clearance: SC Conventus is recruiting a Junior Cyber Audit Consultant to join a Defence focused Cyber Assurance team, playing a supporting role to senior consultants delivering audits across customer processes and systems. This is a great opportunity to build a career in Defence Cyber Audit, with a genuine pathway to progress into a fully fledged Cyber Audit Consultant role. You will be playing a supporting role to the main consultants delivering Cyber Risk Profile (CRP) audit work, with development into a fully fledged Cyber Audit Consultant role over time. Responsibilities: Plan and conduct audits of customer processes and systems to ensure compliance with regulatory requirements such as the NCSC Cyber Assessment Framework (CAF) and GovAssure. Support and, over time, help lead audit activity, ensuring findings are properly documented and reported. Communicate audit findings and recommendations, working collaboratively with management to help develop and implement effective corrective actions. Maintain accurate and current records of audit activities, including audit reports and documentation of corrective actions taken. Stay current with regulatory requirements and industry best practice relating to auditing, compliance and risk management. Contribute to cyber report writing and the production of Cyber Risk Profiles (CRP) Skills/Experience: Experience of ISO 27001, the NCSC Cyber Assessment Framework (CAF), DCC and Cyber Risk Profile (CRP) work. Experience of cyber report writing. Relevant ISO certification (for example ISO 27001 Lead Auditor or equivalent) is desirable. Experience in auditing, compliance or risk management, ideally gained in the Public Sector, particularly Defence. Understanding of NCSC CAF v3.2/v4.0. Some MoD experience is desirable but not essential. Strong analytical and problem solving skills. Excellent communication and interpersonal skills. Ability to work independently and as part of a team. Permanent role with a genuine career path into a Cyber Audit Consultant position. Structured support, mentoring and development within a specialist Defence focused team. Exposure to nationally significant Defence cyber assurance work. Due to the nature of the work, applicants must hold or be eligible to hold UK Security clearance to SC level. Please familiarise yourself with the security vetting process before applying.
Goldman Sachs Group, Inc.
Birmingham, Staffordshire
Internal Audit, Asset & Wealth Management Technology Audit, Vice President, Birmingham Birmingham, West Midlands, England, United Kingdom Job Description In Internal Audit, we ensure that Goldman Sachs maintains effective controls by assessing the reliability of financial reports, monitoring the firm's compliance with laws and regulations, and advising management on developing smart control solutions. Our group has unique insight on the financial industry and its products and operations. We're looking for detail oriented team players who have an interest in financial markets and want to gain insight into the firm's operations and control processes. What We Do As the third line of defense, Internal Audit's mission is to independently assess the firm's internal control structure, including the firm's governance processes and controls, risk management and capital and anti financial crime frameworks, raise awareness of control risk, and monitor the implementation of management's control measures. In doing so, internal Audit: Communicates and reports on the effectiveness of the firm's governance, risk management and controls that mitigate current and evolving risk Raises awareness of control risk Assesses the firm's control culture and conduct risks Monitors management's implementation of control measures Goldman Sachs Internal Audit comprises individuals from diverse backgrounds including chartered accountants, developers, risk management professionals, cybersecurity professionals, and data scientists. We are organized into global teams comprising business and technology auditors to cover all of the firm's businesses and functions, including global banking & markets, asset & wealth management, risk management, finance, cyber security and technology risk, and engineering. Who We Look For Goldman Sachs internal auditors demonstrate strong risk and control mindsets, possess analytical skills, exercise professional skepticism and are able to challenge and discuss effectively with management on risks and control measures. We look for individuals who enjoy learning about audit, businesses and functions, have innovative and creative mindsets to adopt analytical techniques to enhance audit processes, build relationships, and are able to evolve and thrive in a fast paced global environment. Asset & Wealth Management covers the firm's Wealth Management, Public and Private Asset Management businesses. As a Technology Auditor, you will be involved in providing assurance on the integrity and quality of data used for the purposes of portfolio construction and management, deal workflows, investment research flows, reporting for internal and regulatory purposes, application stability, system operations along with other general technology controls. As part of the third line of defense, you will be involved in independently assessing the firm's overall control environment, and communicating the results to the firm's local and global management on the effectiveness of the firm's controls that mitigate current and emerging risks, and monitoring the management's implementation of control measures. In doing so, you are supporting the provision of independent, objective and timely assurance around the firm's internal control structure, and supporting the Audit Committee, the Board of Directors and Risk Committee in fulfilling their oversight responsibilities. For each assigned review you will report to an experienced project manager. You will be expected to: Assist/lead the risk assessment, scoping and planning of reviews. Assist/lead the execution of the reviews. Specifically focusing on the following: Analyze the design of controls around the underlying system architecture in the context of information technology controls and its impact on the business. Analyze the business and technology processes to evaluate the design and effectiveness of the relevant technology controls by designing and executing tests to validate identified system control features, which may require data analysis, code inspection and re performance of system processes. Document the results of the test steps executed within the Internal Audit workflow application as per the departmental guidelines. Assist in/lead the vetting of audit observations. Assist in/lead the tracking, monitoring and recording of remediation of risks identified in reviews. Qualifications BE/B Tech/MCA/MBA/MS in Information Systems or equivalent University degree in technology Minimum 8 years of experience in technology audit focusing on Financial Services Technology audit. Technology audit skills including an understanding of: System architecture, with high level understanding of databases, operating systems and messaging Prior experience of testing automated IT application controls System Development / Programming Languages System Architecture (Distributed/Messaging, Cloud, emerging technologies) Operating Systems and databases Data analysis skills (SQL, ACL, or similar tools) Application security principles System development lifecycle (SDLC) Management, monitoring and operations of technology (backups, change management, system monitoring, incident/problem management) Business continuity planning and disaster recovery design and implementation Security within the software development lifecycle Ability to review code (object oriented programming languages) Experience in managing audit engagements or technology projects Relevant Certification or industry accreditation (CISA, CISSP, etc.) Ability to work effectively across a large global audit team, understanding the team's role in the overall strategy of the firm Strong written and verbal communication skills a must; strong interpersonal skills essential. Requirement for frequent interaction with technology management Must be able to multitask while managing both timelines and workload Experience with AI, Data Analytics tools and techniques Audit experience in Cloud and other emerging technologies About Goldman Sachs At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We're committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veterans status, disability, or any other characteristic protected by applicable law. Job Info Job Identification 164888 Job Category Vice President Posting Date 03/09/2026, 05:25 PM Locations Birmingham, West Midlands, England, United Kingdom
Jul 31, 2026
Full time
Internal Audit, Asset & Wealth Management Technology Audit, Vice President, Birmingham Birmingham, West Midlands, England, United Kingdom Job Description In Internal Audit, we ensure that Goldman Sachs maintains effective controls by assessing the reliability of financial reports, monitoring the firm's compliance with laws and regulations, and advising management on developing smart control solutions. Our group has unique insight on the financial industry and its products and operations. We're looking for detail oriented team players who have an interest in financial markets and want to gain insight into the firm's operations and control processes. What We Do As the third line of defense, Internal Audit's mission is to independently assess the firm's internal control structure, including the firm's governance processes and controls, risk management and capital and anti financial crime frameworks, raise awareness of control risk, and monitor the implementation of management's control measures. In doing so, internal Audit: Communicates and reports on the effectiveness of the firm's governance, risk management and controls that mitigate current and evolving risk Raises awareness of control risk Assesses the firm's control culture and conduct risks Monitors management's implementation of control measures Goldman Sachs Internal Audit comprises individuals from diverse backgrounds including chartered accountants, developers, risk management professionals, cybersecurity professionals, and data scientists. We are organized into global teams comprising business and technology auditors to cover all of the firm's businesses and functions, including global banking & markets, asset & wealth management, risk management, finance, cyber security and technology risk, and engineering. Who We Look For Goldman Sachs internal auditors demonstrate strong risk and control mindsets, possess analytical skills, exercise professional skepticism and are able to challenge and discuss effectively with management on risks and control measures. We look for individuals who enjoy learning about audit, businesses and functions, have innovative and creative mindsets to adopt analytical techniques to enhance audit processes, build relationships, and are able to evolve and thrive in a fast paced global environment. Asset & Wealth Management covers the firm's Wealth Management, Public and Private Asset Management businesses. As a Technology Auditor, you will be involved in providing assurance on the integrity and quality of data used for the purposes of portfolio construction and management, deal workflows, investment research flows, reporting for internal and regulatory purposes, application stability, system operations along with other general technology controls. As part of the third line of defense, you will be involved in independently assessing the firm's overall control environment, and communicating the results to the firm's local and global management on the effectiveness of the firm's controls that mitigate current and emerging risks, and monitoring the management's implementation of control measures. In doing so, you are supporting the provision of independent, objective and timely assurance around the firm's internal control structure, and supporting the Audit Committee, the Board of Directors and Risk Committee in fulfilling their oversight responsibilities. For each assigned review you will report to an experienced project manager. You will be expected to: Assist/lead the risk assessment, scoping and planning of reviews. Assist/lead the execution of the reviews. Specifically focusing on the following: Analyze the design of controls around the underlying system architecture in the context of information technology controls and its impact on the business. Analyze the business and technology processes to evaluate the design and effectiveness of the relevant technology controls by designing and executing tests to validate identified system control features, which may require data analysis, code inspection and re performance of system processes. Document the results of the test steps executed within the Internal Audit workflow application as per the departmental guidelines. Assist in/lead the vetting of audit observations. Assist in/lead the tracking, monitoring and recording of remediation of risks identified in reviews. Qualifications BE/B Tech/MCA/MBA/MS in Information Systems or equivalent University degree in technology Minimum 8 years of experience in technology audit focusing on Financial Services Technology audit. Technology audit skills including an understanding of: System architecture, with high level understanding of databases, operating systems and messaging Prior experience of testing automated IT application controls System Development / Programming Languages System Architecture (Distributed/Messaging, Cloud, emerging technologies) Operating Systems and databases Data analysis skills (SQL, ACL, or similar tools) Application security principles System development lifecycle (SDLC) Management, monitoring and operations of technology (backups, change management, system monitoring, incident/problem management) Business continuity planning and disaster recovery design and implementation Security within the software development lifecycle Ability to review code (object oriented programming languages) Experience in managing audit engagements or technology projects Relevant Certification or industry accreditation (CISA, CISSP, etc.) Ability to work effectively across a large global audit team, understanding the team's role in the overall strategy of the firm Strong written and verbal communication skills a must; strong interpersonal skills essential. Requirement for frequent interaction with technology management Must be able to multitask while managing both timelines and workload Experience with AI, Data Analytics tools and techniques Audit experience in Cloud and other emerging technologies About Goldman Sachs At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We're committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veterans status, disability, or any other characteristic protected by applicable law. Job Info Job Identification 164888 Job Category Vice President Posting Date 03/09/2026, 05:25 PM Locations Birmingham, West Midlands, England, United Kingdom
LocationSunderland, United Kingdom# Customer Success Manager at OneClickComplyLocationSunderland, United KingdomSalary£32500 - £60000 /yearJob TypeFull-timeDate PostedApril 30th, 2026Apply NowOneClickComply is changing how businesses think about cybersecurity compliance. We've built a platform that automates the hard parts - technical control implementation, policy generation, continuous monitoring, and real-time audit evidence - so that achieving certifications like ISO 27001, SOC 2, Cyber Essentials, and CIS v8 takes weeks instead of months. We work with a growing network of audit and enablement partners and serve clients across every industry who need to prove they take security seriously.We're a small, fast-moving team where your ideas don't get lost in layers of hierarchy. If you've ever been frustrated by how unnecessarily painful compliance can be, you'll understand exactly why we exist. The Opportunity This role puts you right at the heart of the client experience. You'll own the post-sale relationship across every channel - live chat, phone, video calls, and email - making sure every customer gets real, measurable value from our platform and feels genuinely supported from their very first onboarding call through to renewal and beyond.You'll be the person our clients turn to when they need help navigating the platform, understanding where they are on their compliance journey, or figuring out what comes next. When they need deeper technical guidance, you'll bring in our Security Compliance Specialists. When they're ready for penetration testing or a formal audit, you'll make the introductions to the right enablement partners. You're the thread that ties the whole experience together.This isn't a passive support role. You'll have genuine influence over how we onboard, engage, and grow our client base - and over the direction of the customer success function as we scale. There's also a real financial incentive to grow accounts: with a base salary of £32,500 plus uncapped commission on upsells, your OTE will be in the region of £60,000. What You'll Be Doing Owning the client relationship across every touchpoint. You'll manage a portfolio of B2B accounts, providing responsive, high-quality support via live chat, telephone, email, and scheduled video calls. You'll be the consistent, trusted point of contact that clients know they can rely on - whether it's a quick question on chat or a detailed walkthrough over the phone. Running onboarding that sets clients up for success . You'll lead onboarding calls and implementation sessions for every new client, walking them through platform configuration, control setup, dashboards, and integrations. You'll build and refine onboarding playbooks so that every client's first experience is smooth, structured, and confidence-building. Working hand in hand with our Security Compliance Specialists . You'll be the first point of contact for clients, triaging their needs and bringing in our Compliance Advisory team when deeper technical or framework-specific expertise is required. You'll stay close to those conversations so you always understand where each client is on their journey and can follow up effectively. Connecting clients with the right enablement partners . When clients are ready for penetration testing, vulnerability assessments, formal audits, or other specialist services, you'll make warm introductions to our network of trusted enablement partners - including penetration testers, auditors, and certification bodies. You'll coordinate scheduling, manage expectations on both sides, and make sure the handoff is seamless. Delivering webinars and group enablement . You'll plan and host regular webinars covering platform features, compliance best practices, framework updates, and tips for getting the most from OneClickComply. These sessions will help scale your impact beyond one-to-one interactions and position us as a trusted voice in the compliance space. Conducting regular check-ins and business reviews . You'll run quarterly business reviews with key accounts, track adoption metrics and health scores, and make sure every client has a clear path to their compliance goals. You'll stay ahead of churn risk by spotting disengagement early and acting on it. Driving upsell and expansion revenue . You'll identify opportunities to expand accounts - whether that's additional frameworks, more seats, or premium services - and you'll be rewarded for it. Commission on successful upsells forms a meaningful part of your compensation, so the better your clients do, the better you do. Being the voice of the customer internally . You'll work closely with product, engineering, and sales to relay what clients are asking for, where they're getting stuck, and what would make the biggest difference to their experience. Your insights will directly shape the roadmap. Writing support articles and client-facing content . You'll build out our knowledge base by writing clear, practical support articles, how-to guides, and FAQs that help clients self-serve and get to value faster. You'll also produce walkthrough videos, best-practice materials, and webinar follow-up content - reducing inbound support volume and giving every client the resources to succeed on their own terms. What We're Looking For You'll have at least 2 years of experience in a customer success, account management, or client-facing role within a B2B SaaS environment. This is a firm requirement - we need someone who already understands the rhythms of SaaS onboarding, adoption, renewal cycles, and the metrics that matter.You're confident and personable on the phone and on camera. You're the kind of person who can jump from a live chat conversation to an onboarding call to a webinar and bring the same energy and clarity to each. You build relationships quickly and earn trust by being organised, proactive, and genuinely helpful.You're a strong writer. Whether it's a support article, a follow-up email, or a webinar script, you can take something complex and make it clear and practical without dumbing it down.You're comfortable having strategic conversations with senior stakeholders and equally happy rolling up your sleeves for a hands-on platform walkthrough with an end user. You've got a track record of identifying and closing upsell or expansion opportunities, and you're motivated by a compensation model that rewards you for growing accounts.Experience in cybersecurity, compliance, GRC, or RegTech is a strong plus but not essential - if you're a quick learner with a genuine curiosity about the space, we'll get you up to speed. Familiarity with frameworks like ISO 27001, SOC 2, or Cyber Essentials is a bonus.You'll thrive here if you're naturally data-minded, comfortable using CRM and CS tools to manage your book of business, and energised by the challenge of building processes in a company that's still defining them. Compensation £32,500 base salary plus uncapped commission on upsell and expansion revenue, with on-target earnings (OTE) in the region of £60,000. Your earning potential grows as your accounts grow. Why Join Us You'll be joining at a stage where you can genuinely shape how customer success works at OneClickComply. Your understanding of what clients need won't just improve retention - it will directly influence how the product evolves. There's no red tape, no death by committee. Just a team that cares about making compliance less painful for everyone. The Benefits We've put together a benefits package that we think goes well beyond what you'd expect from a company our size. Your health and wellbeing come first. You and your family get 24/7 access to GP appointments and prescriptions, unlimited telephone, face-to-face, and video counselling, virtual physiotherapy, and unlimited eye testing. You'll also have access to virtual gym classes and discounted
Jul 30, 2026
Full time
LocationSunderland, United Kingdom# Customer Success Manager at OneClickComplyLocationSunderland, United KingdomSalary£32500 - £60000 /yearJob TypeFull-timeDate PostedApril 30th, 2026Apply NowOneClickComply is changing how businesses think about cybersecurity compliance. We've built a platform that automates the hard parts - technical control implementation, policy generation, continuous monitoring, and real-time audit evidence - so that achieving certifications like ISO 27001, SOC 2, Cyber Essentials, and CIS v8 takes weeks instead of months. We work with a growing network of audit and enablement partners and serve clients across every industry who need to prove they take security seriously.We're a small, fast-moving team where your ideas don't get lost in layers of hierarchy. If you've ever been frustrated by how unnecessarily painful compliance can be, you'll understand exactly why we exist. The Opportunity This role puts you right at the heart of the client experience. You'll own the post-sale relationship across every channel - live chat, phone, video calls, and email - making sure every customer gets real, measurable value from our platform and feels genuinely supported from their very first onboarding call through to renewal and beyond.You'll be the person our clients turn to when they need help navigating the platform, understanding where they are on their compliance journey, or figuring out what comes next. When they need deeper technical guidance, you'll bring in our Security Compliance Specialists. When they're ready for penetration testing or a formal audit, you'll make the introductions to the right enablement partners. You're the thread that ties the whole experience together.This isn't a passive support role. You'll have genuine influence over how we onboard, engage, and grow our client base - and over the direction of the customer success function as we scale. There's also a real financial incentive to grow accounts: with a base salary of £32,500 plus uncapped commission on upsells, your OTE will be in the region of £60,000. What You'll Be Doing Owning the client relationship across every touchpoint. You'll manage a portfolio of B2B accounts, providing responsive, high-quality support via live chat, telephone, email, and scheduled video calls. You'll be the consistent, trusted point of contact that clients know they can rely on - whether it's a quick question on chat or a detailed walkthrough over the phone. Running onboarding that sets clients up for success . You'll lead onboarding calls and implementation sessions for every new client, walking them through platform configuration, control setup, dashboards, and integrations. You'll build and refine onboarding playbooks so that every client's first experience is smooth, structured, and confidence-building. Working hand in hand with our Security Compliance Specialists . You'll be the first point of contact for clients, triaging their needs and bringing in our Compliance Advisory team when deeper technical or framework-specific expertise is required. You'll stay close to those conversations so you always understand where each client is on their journey and can follow up effectively. Connecting clients with the right enablement partners . When clients are ready for penetration testing, vulnerability assessments, formal audits, or other specialist services, you'll make warm introductions to our network of trusted enablement partners - including penetration testers, auditors, and certification bodies. You'll coordinate scheduling, manage expectations on both sides, and make sure the handoff is seamless. Delivering webinars and group enablement . You'll plan and host regular webinars covering platform features, compliance best practices, framework updates, and tips for getting the most from OneClickComply. These sessions will help scale your impact beyond one-to-one interactions and position us as a trusted voice in the compliance space. Conducting regular check-ins and business reviews . You'll run quarterly business reviews with key accounts, track adoption metrics and health scores, and make sure every client has a clear path to their compliance goals. You'll stay ahead of churn risk by spotting disengagement early and acting on it. Driving upsell and expansion revenue . You'll identify opportunities to expand accounts - whether that's additional frameworks, more seats, or premium services - and you'll be rewarded for it. Commission on successful upsells forms a meaningful part of your compensation, so the better your clients do, the better you do. Being the voice of the customer internally . You'll work closely with product, engineering, and sales to relay what clients are asking for, where they're getting stuck, and what would make the biggest difference to their experience. Your insights will directly shape the roadmap. Writing support articles and client-facing content . You'll build out our knowledge base by writing clear, practical support articles, how-to guides, and FAQs that help clients self-serve and get to value faster. You'll also produce walkthrough videos, best-practice materials, and webinar follow-up content - reducing inbound support volume and giving every client the resources to succeed on their own terms. What We're Looking For You'll have at least 2 years of experience in a customer success, account management, or client-facing role within a B2B SaaS environment. This is a firm requirement - we need someone who already understands the rhythms of SaaS onboarding, adoption, renewal cycles, and the metrics that matter.You're confident and personable on the phone and on camera. You're the kind of person who can jump from a live chat conversation to an onboarding call to a webinar and bring the same energy and clarity to each. You build relationships quickly and earn trust by being organised, proactive, and genuinely helpful.You're a strong writer. Whether it's a support article, a follow-up email, or a webinar script, you can take something complex and make it clear and practical without dumbing it down.You're comfortable having strategic conversations with senior stakeholders and equally happy rolling up your sleeves for a hands-on platform walkthrough with an end user. You've got a track record of identifying and closing upsell or expansion opportunities, and you're motivated by a compensation model that rewards you for growing accounts.Experience in cybersecurity, compliance, GRC, or RegTech is a strong plus but not essential - if you're a quick learner with a genuine curiosity about the space, we'll get you up to speed. Familiarity with frameworks like ISO 27001, SOC 2, or Cyber Essentials is a bonus.You'll thrive here if you're naturally data-minded, comfortable using CRM and CS tools to manage your book of business, and energised by the challenge of building processes in a company that's still defining them. Compensation £32,500 base salary plus uncapped commission on upsell and expansion revenue, with on-target earnings (OTE) in the region of £60,000. Your earning potential grows as your accounts grow. Why Join Us You'll be joining at a stage where you can genuinely shape how customer success works at OneClickComply. Your understanding of what clients need won't just improve retention - it will directly influence how the product evolves. There's no red tape, no death by committee. Just a team that cares about making compliance less painful for everyone. The Benefits We've put together a benefits package that we think goes well beyond what you'd expect from a company our size. Your health and wellbeing come first. You and your family get 24/7 access to GP appointments and prescriptions, unlimited telephone, face-to-face, and video counselling, virtual physiotherapy, and unlimited eye testing. You'll also have access to virtual gym classes and discounted
Director, Compliance Audit - iLottery & InteractiveSkip to main content# Careers at AristocratDirector, Compliance Audit - iLottery & Interactive page is loaded Director, Compliance Audit - iLottery & InteractiveApplyremote type: Hybridlocations: London, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: RJoin Aristocrat's ambitious team as the Director, Compliance Audit - iLottery & Interactive! This role is an outstanding opportunity to lead and coordinate our compliance audit program across our global iLottery portfolio and broader interactive business. You will collaborate with diverse teams to maintain audit readiness, regulatory adherence, and robust control frameworks, making a significant impact in a highly regulated environment. This position offers the chance to work with groundbreaking technologies and methodologies, ensuring world-class audit processes and controls. What You'll Do Lead the global compliance audit strategy for the iLottery business, covering platforms, operations, customer implementations, and supporting services. Develop and complete a risk-based audit plan addressing regulatory, operational, security, technology, and service delivery controls. Coordinate and lead all aspects of external audits and certifications supporting lottery customers, including but not limited to SOC 1, SOC 2, ISO 27001, WLA-SCS, PCI-DSS, and jurisdiction-specific requirements. Maintain audit readiness throughout all iLottery regions by conducting proactive control evaluations, identifying gaps, monitoring remediation progress, and ongoing oversight. Partner with customer-facing teams to support regulatory reviews, customer audits, RFP/RFQ responses, and compliance due diligence activities. Promote uniformity and harmonisation of audit procedures and control frameworks across several jurisdictions and operational models. Serve as a subject matter expert on global iLottery regulatory requirements and industry compliance standards. Track new regulatory requirements and industry developments, making sure audit frameworks adapt in advance to meet shifting obligations. Partner with Compliance, Legal, Cybersecurity, Privacy, and Risk teams to assess regulatory exposure and strengthen mitigation strategies. Evaluate the efficiency of controls supporting responsible gaming, information security, data protection, financial reporting, vendor management, and operational resilience. Serve as the primary audit liaison for customers, regulators, certification bodies, and external auditors. Provide regular reporting and strategic recommendations to senior leadership regarding audit outcomes, compliance posture, risk exposure, and remediation progress. What We're Looking For 10+ years of progressive experience in audit, compliance, risk management, or governance roles within highly regulated industries. Significant experience supporting iLottery, gaming, financial services, technology, or digital platform environments. Demonstrated success in managing intricate audit programmes spanning various jurisdictions and regulatory frameworks. Experience managing external audits, certifications, and regulatory examinations. Demonstrated success working with executive leadership and customer collaborators. Strong understanding of audit methodologies, internal controls, risk management, and governance frameworks. Experience with recognized industry benchmarks and certifications such as SOC 1, SOC 2, ISO 27001, PCI-DSS, WLA-SCS, NIST, COBIT, or comparable frameworks. Strong analytical, problem-solving, and decision-making capabilities. Excellent communication, presentation, and collaborator management skills. Ability to balance regulatory obligations with operational and business objectives. Professional certifications like CIA, CISA, CRISC, CISSP, CGEIT, or their equivalents. Company Summary Aristocrat Interactive Aristocrat Interactive is Aristocrat Leisure Limited's (ASX:ALL) regulated online Real Money Gaming (RMG) business and was formed in 2024 when the Anaxi and NeoGames businesses (Anaxi, NeoGames, Aspire Global, BtoBet, and Pariplay) came together. The business is an industry leader in content and technology solutions for online RMG, with a full-service offering that includes content, proprietary technology platforms and a range of value added services across iLottery, iGaming and Online Sports Betting (OSB). About Aristocrat Aristocrat Leisure Limited (ASX: ALL) is a leading gaming content creation company powered by technology to deliver industry-leading casino games together with mobile games and online real money games, collectively entertaining millions of players worldwide, every day. Headquartered in Sydney, Australia, Aristocrat has three operating business units, spanning regulated land-based gaming (Aristocrat Gaming), social casino (Product Madness) and regulated online real money (Aristocrat Interactive). Our team of over 8,500 people across the globe are united by our company mission to bring joy to life through the power of play . Our Values All about the Player Talent Unleashed Collective Brilliance Good Business Good Citizen Travel Expectations None Additional Information This role is subject to mandatory background screening and regulatory approvals. As part of your employment with Aristocrat, you may be required to complete a criminal background check, submit fingerprints, and obtain licenses or registrations with applicable gaming regulatory authorities.Aristocrat operates in a highly regulated environment and holds licenses in over 340 gaming jurisdictions worldwide. To meet our global compliance obligations, you will be required to provide the disclosure of relevant personal and background information to government agencies, sovereign nations/tribal regulators, and other applicable gaming regulatory bodies. This is a condition of Aristocrat's gaming licenses. The specific information required may vary depending on the jurisdiction and project assignment. At this time, we are unable to sponsor work visas for this position. Candidates must be authorized to work in the job posting location for this position on a full-time basis without the need for current or future visa sponsorship. About AristocratAristocrat Leisure Limited (Aristocrat) is a global entertainment and content creation company powered by technology to deliver world-leading casino and mobile games. Listed on the Australian Securities Exchange (ASX), Aristocrat (ASX code: ALL) is headquartered in Sydney, Australia, with over 7300 employees working in more than 20 locations across the globe. Aristocrat offers a diverse range of products and services including electronic gaming machines, casino management systems, mobile games and online real money games, including iLottery.Aristocrat has seven corporate functions and three reporting segments that span regulated land-based gaming (Aristocrat Gaming), social casino (Product Madness) and regulated online real money gaming (Aristocrat Interactive). Our game and product portfolios collectively entertain millions of players worldwide every day.Across our global enterprise, Aristocrat aims to create long-term sustainable value for all stakeholders by upholding our core values and producing the world's best gaming content. Our people-first mindset prioritises the safety and wellbeing of our people. We have ambitions to be an industry leader in responsible gameplay and we invest in employees' development and offer career pathways, so they have what they need to do their best work at Aristocrat.Our values of Talent Unleashed, All About the Player, Collective Brilliance and Good Business, Good Citizen guide and inspire us every day. We are excited about the future of Aristocrat and united by our mission and we invite everyone to join us as we bring joy to life through the power of play ! Employment Equality StatementAristocrat Leisure Limited or its affiliates worldwide provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to any protected characteristic, such as race, color, sex, religion, national origin, physical or mental disability, genetic characteristic, pregnancy, breastfeeding or related medical condition, sexual orientation, gender identity, gender expression, ancestry, citizenship, age, marital, military and veteran status, or any other characteristic prohibited by local, state/provincial or federal law.If you need assistance or accommodation applying for a position, please reach out to .
Jul 30, 2026
Full time
Director, Compliance Audit - iLottery & InteractiveSkip to main content# Careers at AristocratDirector, Compliance Audit - iLottery & Interactive page is loaded Director, Compliance Audit - iLottery & InteractiveApplyremote type: Hybridlocations: London, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: RJoin Aristocrat's ambitious team as the Director, Compliance Audit - iLottery & Interactive! This role is an outstanding opportunity to lead and coordinate our compliance audit program across our global iLottery portfolio and broader interactive business. You will collaborate with diverse teams to maintain audit readiness, regulatory adherence, and robust control frameworks, making a significant impact in a highly regulated environment. This position offers the chance to work with groundbreaking technologies and methodologies, ensuring world-class audit processes and controls. What You'll Do Lead the global compliance audit strategy for the iLottery business, covering platforms, operations, customer implementations, and supporting services. Develop and complete a risk-based audit plan addressing regulatory, operational, security, technology, and service delivery controls. Coordinate and lead all aspects of external audits and certifications supporting lottery customers, including but not limited to SOC 1, SOC 2, ISO 27001, WLA-SCS, PCI-DSS, and jurisdiction-specific requirements. Maintain audit readiness throughout all iLottery regions by conducting proactive control evaluations, identifying gaps, monitoring remediation progress, and ongoing oversight. Partner with customer-facing teams to support regulatory reviews, customer audits, RFP/RFQ responses, and compliance due diligence activities. Promote uniformity and harmonisation of audit procedures and control frameworks across several jurisdictions and operational models. Serve as a subject matter expert on global iLottery regulatory requirements and industry compliance standards. Track new regulatory requirements and industry developments, making sure audit frameworks adapt in advance to meet shifting obligations. Partner with Compliance, Legal, Cybersecurity, Privacy, and Risk teams to assess regulatory exposure and strengthen mitigation strategies. Evaluate the efficiency of controls supporting responsible gaming, information security, data protection, financial reporting, vendor management, and operational resilience. Serve as the primary audit liaison for customers, regulators, certification bodies, and external auditors. Provide regular reporting and strategic recommendations to senior leadership regarding audit outcomes, compliance posture, risk exposure, and remediation progress. What We're Looking For 10+ years of progressive experience in audit, compliance, risk management, or governance roles within highly regulated industries. Significant experience supporting iLottery, gaming, financial services, technology, or digital platform environments. Demonstrated success in managing intricate audit programmes spanning various jurisdictions and regulatory frameworks. Experience managing external audits, certifications, and regulatory examinations. Demonstrated success working with executive leadership and customer collaborators. Strong understanding of audit methodologies, internal controls, risk management, and governance frameworks. Experience with recognized industry benchmarks and certifications such as SOC 1, SOC 2, ISO 27001, PCI-DSS, WLA-SCS, NIST, COBIT, or comparable frameworks. Strong analytical, problem-solving, and decision-making capabilities. Excellent communication, presentation, and collaborator management skills. Ability to balance regulatory obligations with operational and business objectives. Professional certifications like CIA, CISA, CRISC, CISSP, CGEIT, or their equivalents. Company Summary Aristocrat Interactive Aristocrat Interactive is Aristocrat Leisure Limited's (ASX:ALL) regulated online Real Money Gaming (RMG) business and was formed in 2024 when the Anaxi and NeoGames businesses (Anaxi, NeoGames, Aspire Global, BtoBet, and Pariplay) came together. The business is an industry leader in content and technology solutions for online RMG, with a full-service offering that includes content, proprietary technology platforms and a range of value added services across iLottery, iGaming and Online Sports Betting (OSB). About Aristocrat Aristocrat Leisure Limited (ASX: ALL) is a leading gaming content creation company powered by technology to deliver industry-leading casino games together with mobile games and online real money games, collectively entertaining millions of players worldwide, every day. Headquartered in Sydney, Australia, Aristocrat has three operating business units, spanning regulated land-based gaming (Aristocrat Gaming), social casino (Product Madness) and regulated online real money (Aristocrat Interactive). Our team of over 8,500 people across the globe are united by our company mission to bring joy to life through the power of play . Our Values All about the Player Talent Unleashed Collective Brilliance Good Business Good Citizen Travel Expectations None Additional Information This role is subject to mandatory background screening and regulatory approvals. As part of your employment with Aristocrat, you may be required to complete a criminal background check, submit fingerprints, and obtain licenses or registrations with applicable gaming regulatory authorities.Aristocrat operates in a highly regulated environment and holds licenses in over 340 gaming jurisdictions worldwide. To meet our global compliance obligations, you will be required to provide the disclosure of relevant personal and background information to government agencies, sovereign nations/tribal regulators, and other applicable gaming regulatory bodies. This is a condition of Aristocrat's gaming licenses. The specific information required may vary depending on the jurisdiction and project assignment. At this time, we are unable to sponsor work visas for this position. Candidates must be authorized to work in the job posting location for this position on a full-time basis without the need for current or future visa sponsorship. About AristocratAristocrat Leisure Limited (Aristocrat) is a global entertainment and content creation company powered by technology to deliver world-leading casino and mobile games. Listed on the Australian Securities Exchange (ASX), Aristocrat (ASX code: ALL) is headquartered in Sydney, Australia, with over 7300 employees working in more than 20 locations across the globe. Aristocrat offers a diverse range of products and services including electronic gaming machines, casino management systems, mobile games and online real money games, including iLottery.Aristocrat has seven corporate functions and three reporting segments that span regulated land-based gaming (Aristocrat Gaming), social casino (Product Madness) and regulated online real money gaming (Aristocrat Interactive). Our game and product portfolios collectively entertain millions of players worldwide every day.Across our global enterprise, Aristocrat aims to create long-term sustainable value for all stakeholders by upholding our core values and producing the world's best gaming content. Our people-first mindset prioritises the safety and wellbeing of our people. We have ambitions to be an industry leader in responsible gameplay and we invest in employees' development and offer career pathways, so they have what they need to do their best work at Aristocrat.Our values of Talent Unleashed, All About the Player, Collective Brilliance and Good Business, Good Citizen guide and inspire us every day. We are excited about the future of Aristocrat and united by our mission and we invite everyone to join us as we bring joy to life through the power of play ! Employment Equality StatementAristocrat Leisure Limited or its affiliates worldwide provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to any protected characteristic, such as race, color, sex, religion, national origin, physical or mental disability, genetic characteristic, pregnancy, breastfeeding or related medical condition, sexual orientation, gender identity, gender expression, ancestry, citizenship, age, marital, military and veteran status, or any other characteristic prohibited by local, state/provincial or federal law.If you need assistance or accommodation applying for a position, please reach out to .
Ultra Electronics Group
Cheltenham, Gloucestershire
The Head of Supplier Performance page is loaded The Head of Supplier Performancelocations: Cheltenham, Gloucestershire, England, UKtime type: Full timeposted on: Posted Todayjob requisition id: REQ-11435# We are Ultra Precision Control Systems Ultra PCS is a leading developer of mission and safety critical equipment in the defence and aerospace industry. Our team of experts are at the heart of our success, which is why we are dedicated to fostering a safe working environment and a positive culture where every staff member feels valued and respected.We solve our customers' problems, providing engineering solutions to safety and mission critical challenges in the air and on the ground. Our solutions can be found in the latest military aircraft and vehicles, in civil aircraft, and in unmanned vehicles.We help to ensure our customers get to where they need to be safely, achieve their objectives and keep on going back.# Flexible Working Wherever possible, we will consider a variety of working options to suit your lifestyle, whether that be hybrid home/office working, flexible working and part or full time employment. It's the 'innovating' and 'empowering' values that we ASPIRE to be. We welcome the challenge to work in new ways and have trust in you when getting the job done because we recognise, our business is our people.# Job DescriptionUltra Precision Control Systems (PCS) are looking for a Head of Supplier Performance to join the team, reporting into the Supply Chain Director. The Head of Supplier Performance is responsible for defining and executing the global supplier performance and development strategy to achieve a Zero Defects culture across the supply base. This includes governance of quality, delivery, cost, cybersecurity, environmental compliance, and regulatory adherence (AS9100, EASA/CAA Part 145, Part 21J, 21G, ISO 27001, ISO 14001, Cyber Essentials Plus, CAAC). The role ensures deployment of Zero Defects tools including APQP, PPAP, PFMEA, Control Plans, SPC, and structured problem-solving. Key Responsibilities: Establish and govern the Supplier Zero Defects Strategy, embedding Zero Defects tools into supplier performance management. Lead the deployment of APQP, PPAP, DFMEA, PFMEA, Control Plans, SPC, problem-solving across suppliers. Develop Product Control Plans and supplier KPI frameworks aligned with Zero Defects expectations. Ensure supplier compliance with AS9100, AS9145, Part 145, Part 21J/G, CAAC, ISO 27001, ISO 14001. Achieve and sustain >98% On-Time Delivery, reduce DPPM, and eliminate escapes. Drive supplier capability development, process control, and manufacturing robustness. Lead supplier governance including Business Reviews, scorecards, and improvement roadmaps. Introducing new methods of working through using Artificial Intelligence Implement a culture and behaviour of challenging and seeking robust resolutions to supplier issues that arise. Required Skills & Experience: Zero Defects leadership mindset. Expertise in APQP/PPAP, PFMEA, Control Plans, MSA, and SPC. Strong aerospace regulatory knowledge. Supplier development and coaching capability. Analytical, data-driven decision-making. Strong problem-solving skills Ability to lead global multifunctional teams.Lead Auditor Benefits: Every employee is critical to our success and as such we offer a range of flexible employee benefits along with career development opportunities. Flexible working within core working hours 25 days holiday (185 hrs) with the option to buy/sell 5 days (37 hrs) plus bank holidays. 4 times your annual salary in life assurance Flexible benefits package Pension Scheme - Less than 5 years' service up to 5.5% employer contributions, 5 years' service + up to 7.5% employer contributions. Sports and Social club Supportive and friendly working environment with regular team eventsYou couldn't be joining the team and Ultra at a more exciting time. Therefore if this sounds of interest, please follow the application process.# Nationality Requirements Candidates must be able to work in the UK without restrictions in accordance with UK National Law and be prepared to successfully undertake an appropriate level of UK National Security Vetting according to UK Government National Security Vetting criteria.# Diverse & Inclusive Employer Ultra PCS is an equal opportunities employer that values diversity, inclusion, equity and equality. Underpinned by our values, behaviours, and policies, we want you to feel empowered to be your best and authentic self.We promote a workplace that welcomes people from all backgrounds and cultures; believing that this will increase our diversity of thinking, and ultimately ensure we continue delivering on our commitments to our customers.We do not discriminate based on race, religion, colour, national origin, gender identity, sexual orientation, age, marital status, veteran status, or disability status and welcome applications from all candidates.
Jun 02, 2026
Full time
The Head of Supplier Performance page is loaded The Head of Supplier Performancelocations: Cheltenham, Gloucestershire, England, UKtime type: Full timeposted on: Posted Todayjob requisition id: REQ-11435# We are Ultra Precision Control Systems Ultra PCS is a leading developer of mission and safety critical equipment in the defence and aerospace industry. Our team of experts are at the heart of our success, which is why we are dedicated to fostering a safe working environment and a positive culture where every staff member feels valued and respected.We solve our customers' problems, providing engineering solutions to safety and mission critical challenges in the air and on the ground. Our solutions can be found in the latest military aircraft and vehicles, in civil aircraft, and in unmanned vehicles.We help to ensure our customers get to where they need to be safely, achieve their objectives and keep on going back.# Flexible Working Wherever possible, we will consider a variety of working options to suit your lifestyle, whether that be hybrid home/office working, flexible working and part or full time employment. It's the 'innovating' and 'empowering' values that we ASPIRE to be. We welcome the challenge to work in new ways and have trust in you when getting the job done because we recognise, our business is our people.# Job DescriptionUltra Precision Control Systems (PCS) are looking for a Head of Supplier Performance to join the team, reporting into the Supply Chain Director. The Head of Supplier Performance is responsible for defining and executing the global supplier performance and development strategy to achieve a Zero Defects culture across the supply base. This includes governance of quality, delivery, cost, cybersecurity, environmental compliance, and regulatory adherence (AS9100, EASA/CAA Part 145, Part 21J, 21G, ISO 27001, ISO 14001, Cyber Essentials Plus, CAAC). The role ensures deployment of Zero Defects tools including APQP, PPAP, PFMEA, Control Plans, SPC, and structured problem-solving. Key Responsibilities: Establish and govern the Supplier Zero Defects Strategy, embedding Zero Defects tools into supplier performance management. Lead the deployment of APQP, PPAP, DFMEA, PFMEA, Control Plans, SPC, problem-solving across suppliers. Develop Product Control Plans and supplier KPI frameworks aligned with Zero Defects expectations. Ensure supplier compliance with AS9100, AS9145, Part 145, Part 21J/G, CAAC, ISO 27001, ISO 14001. Achieve and sustain >98% On-Time Delivery, reduce DPPM, and eliminate escapes. Drive supplier capability development, process control, and manufacturing robustness. Lead supplier governance including Business Reviews, scorecards, and improvement roadmaps. Introducing new methods of working through using Artificial Intelligence Implement a culture and behaviour of challenging and seeking robust resolutions to supplier issues that arise. Required Skills & Experience: Zero Defects leadership mindset. Expertise in APQP/PPAP, PFMEA, Control Plans, MSA, and SPC. Strong aerospace regulatory knowledge. Supplier development and coaching capability. Analytical, data-driven decision-making. Strong problem-solving skills Ability to lead global multifunctional teams.Lead Auditor Benefits: Every employee is critical to our success and as such we offer a range of flexible employee benefits along with career development opportunities. Flexible working within core working hours 25 days holiday (185 hrs) with the option to buy/sell 5 days (37 hrs) plus bank holidays. 4 times your annual salary in life assurance Flexible benefits package Pension Scheme - Less than 5 years' service up to 5.5% employer contributions, 5 years' service + up to 7.5% employer contributions. Sports and Social club Supportive and friendly working environment with regular team eventsYou couldn't be joining the team and Ultra at a more exciting time. Therefore if this sounds of interest, please follow the application process.# Nationality Requirements Candidates must be able to work in the UK without restrictions in accordance with UK National Law and be prepared to successfully undertake an appropriate level of UK National Security Vetting according to UK Government National Security Vetting criteria.# Diverse & Inclusive Employer Ultra PCS is an equal opportunities employer that values diversity, inclusion, equity and equality. Underpinned by our values, behaviours, and policies, we want you to feel empowered to be your best and authentic self.We promote a workplace that welcomes people from all backgrounds and cultures; believing that this will increase our diversity of thinking, and ultimately ensure we continue delivering on our commitments to our customers.We do not discriminate based on race, religion, colour, national origin, gender identity, sexual orientation, age, marital status, veteran status, or disability status and welcome applications from all candidates.