Join Us as Chief Information Officer and help shape the Future of Cancer Care at The Christie The Christie NHS Foundation Trust is seeking an exceptional Chief Information Officer (CIO) to lead our digital transformation and information strategy. This is a unique opportunity to lead Digital Services and drive innovation at one of Europe's leading cancer centres, as we deliver our ambitious Future Christie programme - a 10-year vision to create a patient and staff focussed, intelligent, data-driven hospital. As CIO, you will provide strategic and operational leadership for digital services, ensuring technology and data are harnessed to deliver safe, efficient, and personalised care. You will champion cutting-edge initiatives such as Joint Analytics for Cancer (JAC) - our flagship platform unlocking real-time insights for clinical decision-making, research, and operational excellence. Working at the heart of our digital strategy, you will shape systems that integrate care, research, and innovation, enabling The Christie to remain at the forefront of cancer treatment. If you are passionate about transforming healthcare through digital innovation and want to make a lasting impact on patient outcomes, join us and help build the hospital of the future. Main duties of the job What You'll Do Lead the development and delivery of a Trust-wide digital strategy aligned with national priorities. Develop and implement the Trust's digital strategy, ensuring systems support integrated care, research, and performance improvement. Champion innovation, including AI and machine learning, to enable evidence-based decision-making and personalised care and deliver the ambition of the Future Christie programme. Lead digital service delivery across software development, clinical applications, infrastructure, user support, and cybersecurity Ensure robust digital governance and compliance with NHS and legal standards. Provide assurance to the Senior Management Committee and act as delegated Senior Information Risk Owner (SIRO) when required Manage and support the Digital Services team, including deputy CIO, Chief Clinical Information Officers, and departmental leads. Foster a culture of collaboration and digital literacy across clinical and operational teams What We're Looking For We're seeking a visionary leader with proven digital experience in senior data leadership, ideally in healthcare or public sector. You will have strategic insight and technical expertise in data platforms, governance, and analytics and a passion for innovation, curiosity, and solving complex system-wide challenges. You will have the ability to influence at executive level and inspire multidisciplinary teams and a commitment to equity and sustainability. About us The Christie is one of Europe's leading cancer centres, treating over 60,000 patients a year. We are based in Manchester and serve a population of 3.2 million across Greater Manchester & Cheshire, but as a national specialist around 15% patients are referred to us from other parts of the country. We provide radiotherapy through one of the largest radiotherapy departments in the world; chemotherapy on site and through 14 other hospitals; highly specialist surgery for complex and rare cancer; and a wide range of support and diagnostic services. We are also an international leader in research, with world first breakthroughs for over 100 years. We run one of the largest early clinical trial units in Europe with over 300 trials every year. Cancer research in Manchester, most of which is undertaken on the Christie site, has been officially ranked the best in the UK. Job responsibilities CORPORATE Contribute effectively as a member of the Senior Management Committee ensuring all relevant matters are brought to the attention of the meetings. Provide updates to the board of directors as required on the digital strategy, programmes and risks. Undertake the role (delegated by the Director of Future Christie) of SIRO and support the work of the Information Governance and Caldicott panels providing expert knowledge and assurance ensuring that highly sensitive and confidential data is managed appropriately. Ensure that the Senior Management Committee and Future Christie Director/Medical Director are briefed on the benefits and risks of new digital related projects. Ensure effective working relationships and engagement within the organisation particularly with all divisional, corporate, clinical, and operational teams. Provide digital leadership to the Greater Manchester (GM) Cancer Alliance, support the development of GM system digital cancer strategy Ensure effective working relationships and engagement outside the organisation particularly with third party suppliers, NHS bodies, academic institutions, and other external bodies. Participate effectively in local and national CIO networks. Produce action plans and implement policies to meet all requirements for risk management, audit, controls assurance, health & safety and information governance relating to the work of the digital service. Ensure there is continual improvement and learning within the digital service and that all decisions are based on an assessment of risk. STRATEGY Develop and lead implementation of a digital strategy which supports the overall trust strategy and the associated strategies for clinical services, research and innovation and education. Remain up to date on digital trends and emerging technologies. Identify opportunities for increasing the effectiveness and efficiency of services through changes to digital services and technology. Contribute actively to the development of strategies and plans for other departments ensuring that the contribution of digital technology is incorporated DIGITAL SERVICES PROVISION Ensure provision of modern digital infrastructure, software, and services that fully support the operational, clinical, and business needs of the trust. Oversee the delivery of an effective digital service desk and set of comprehensive and proactive digital support services. Ensure the effective management of digital assets, including all hardware and software, ensuring that these are actively monitored. Ensure the provision of effective digital security measures to adequately protect and maintain systems and data. Ensure the support, maintenance, and development of the core clinical systems, including the procurement and implementation of clinical systems ensuring that benefits are maximised, and functionality fully supports the delivery of excellent patient care. INFORMATION MANAGEMENT Work collaboratively with the Chief Data Officer to develop an information management service and oversee the infrastructure required for data storage. Manage and develop approaches to data integration, including for clinical systems. Oversee relationships with external vendors, suppliers and developers. Manage the project management services that support the delivery of the digital strategy and trust service transformation activities GOVERNANCE Ensure implementation of appropriate digital governance systems which conform to legal and NHS requirements and fit within the wider governance systems of the trust. Ensure maintenance of an effective digital risk register, manage identified risks and escalate risks as required. Ensure the reduction, identification, management, and reporting of untoward digital incidents. Ensure compliance with the requirements of information governance, data protection and freedom of information guidance and legislation. Ensure that the Trust complies with the requirements of the Data Security and Protection Toolkit (DSPT). Ensure that Disaster Recovery and Business Continuity plans are in place for all digital services and that these are routinely tested, weakness identified, and appropriate improvement plans developed and implemented. Ensure compliance of the clinical systems with Safety of Health Systems standards, appropriate NHS Information Standards Notices (ISNs) and National Patient Safety Agency (NPSA) notices. As SIRO, oversee Information Asset Owners (IAOs) providing assurance on risks and compliance ensuring adherence to legal and regulatory requirements (including GDPR and NHS standards) and promote good information governance practices across the organisation. Working with the CDO, maintain an Information Asset Register, and oversee data security, integrity, and availability. MANAGEMENT OF THE DIGITAL SERVICE Manage and lead the digital services team in line with the trusts workforce and related policies, standing financial instructions and scheme of delegation, and other relevant policies and procedures. Develop and achieve annual objectives for digital services within the framework of the Trusts objectives and agreed digital strategy. Manage the digital budget within the requirements of the Trusts Scheme of Delegation and Standing Financial Instructions. Produce an annual rolling investment plan for digital infrastructure including capital, revenue and staffing resource. Plan, deploy, and maintain the Trusts digital systems and operations. Manage the Trusts software development needs. Develop and implement digital policies and procedures in line with requirements and best practice. PERSONAL DEVELOPMENT AND CONDUCT Adhere to impeccable standards of personal conduct and demonstrate commitment to the Trusts Values and Behaviours. Ensure personal professional knowledge is regularly updated and keep abreast of relevant developments. Adhere to the Code of Conduct for NHS Managers. Implement systems and processes, so that in the event of absence . click apply for full job details
Mar 06, 2026
Full time
Join Us as Chief Information Officer and help shape the Future of Cancer Care at The Christie The Christie NHS Foundation Trust is seeking an exceptional Chief Information Officer (CIO) to lead our digital transformation and information strategy. This is a unique opportunity to lead Digital Services and drive innovation at one of Europe's leading cancer centres, as we deliver our ambitious Future Christie programme - a 10-year vision to create a patient and staff focussed, intelligent, data-driven hospital. As CIO, you will provide strategic and operational leadership for digital services, ensuring technology and data are harnessed to deliver safe, efficient, and personalised care. You will champion cutting-edge initiatives such as Joint Analytics for Cancer (JAC) - our flagship platform unlocking real-time insights for clinical decision-making, research, and operational excellence. Working at the heart of our digital strategy, you will shape systems that integrate care, research, and innovation, enabling The Christie to remain at the forefront of cancer treatment. If you are passionate about transforming healthcare through digital innovation and want to make a lasting impact on patient outcomes, join us and help build the hospital of the future. Main duties of the job What You'll Do Lead the development and delivery of a Trust-wide digital strategy aligned with national priorities. Develop and implement the Trust's digital strategy, ensuring systems support integrated care, research, and performance improvement. Champion innovation, including AI and machine learning, to enable evidence-based decision-making and personalised care and deliver the ambition of the Future Christie programme. Lead digital service delivery across software development, clinical applications, infrastructure, user support, and cybersecurity Ensure robust digital governance and compliance with NHS and legal standards. Provide assurance to the Senior Management Committee and act as delegated Senior Information Risk Owner (SIRO) when required Manage and support the Digital Services team, including deputy CIO, Chief Clinical Information Officers, and departmental leads. Foster a culture of collaboration and digital literacy across clinical and operational teams What We're Looking For We're seeking a visionary leader with proven digital experience in senior data leadership, ideally in healthcare or public sector. You will have strategic insight and technical expertise in data platforms, governance, and analytics and a passion for innovation, curiosity, and solving complex system-wide challenges. You will have the ability to influence at executive level and inspire multidisciplinary teams and a commitment to equity and sustainability. About us The Christie is one of Europe's leading cancer centres, treating over 60,000 patients a year. We are based in Manchester and serve a population of 3.2 million across Greater Manchester & Cheshire, but as a national specialist around 15% patients are referred to us from other parts of the country. We provide radiotherapy through one of the largest radiotherapy departments in the world; chemotherapy on site and through 14 other hospitals; highly specialist surgery for complex and rare cancer; and a wide range of support and diagnostic services. We are also an international leader in research, with world first breakthroughs for over 100 years. We run one of the largest early clinical trial units in Europe with over 300 trials every year. Cancer research in Manchester, most of which is undertaken on the Christie site, has been officially ranked the best in the UK. Job responsibilities CORPORATE Contribute effectively as a member of the Senior Management Committee ensuring all relevant matters are brought to the attention of the meetings. Provide updates to the board of directors as required on the digital strategy, programmes and risks. Undertake the role (delegated by the Director of Future Christie) of SIRO and support the work of the Information Governance and Caldicott panels providing expert knowledge and assurance ensuring that highly sensitive and confidential data is managed appropriately. Ensure that the Senior Management Committee and Future Christie Director/Medical Director are briefed on the benefits and risks of new digital related projects. Ensure effective working relationships and engagement within the organisation particularly with all divisional, corporate, clinical, and operational teams. Provide digital leadership to the Greater Manchester (GM) Cancer Alliance, support the development of GM system digital cancer strategy Ensure effective working relationships and engagement outside the organisation particularly with third party suppliers, NHS bodies, academic institutions, and other external bodies. Participate effectively in local and national CIO networks. Produce action plans and implement policies to meet all requirements for risk management, audit, controls assurance, health & safety and information governance relating to the work of the digital service. Ensure there is continual improvement and learning within the digital service and that all decisions are based on an assessment of risk. STRATEGY Develop and lead implementation of a digital strategy which supports the overall trust strategy and the associated strategies for clinical services, research and innovation and education. Remain up to date on digital trends and emerging technologies. Identify opportunities for increasing the effectiveness and efficiency of services through changes to digital services and technology. Contribute actively to the development of strategies and plans for other departments ensuring that the contribution of digital technology is incorporated DIGITAL SERVICES PROVISION Ensure provision of modern digital infrastructure, software, and services that fully support the operational, clinical, and business needs of the trust. Oversee the delivery of an effective digital service desk and set of comprehensive and proactive digital support services. Ensure the effective management of digital assets, including all hardware and software, ensuring that these are actively monitored. Ensure the provision of effective digital security measures to adequately protect and maintain systems and data. Ensure the support, maintenance, and development of the core clinical systems, including the procurement and implementation of clinical systems ensuring that benefits are maximised, and functionality fully supports the delivery of excellent patient care. INFORMATION MANAGEMENT Work collaboratively with the Chief Data Officer to develop an information management service and oversee the infrastructure required for data storage. Manage and develop approaches to data integration, including for clinical systems. Oversee relationships with external vendors, suppliers and developers. Manage the project management services that support the delivery of the digital strategy and trust service transformation activities GOVERNANCE Ensure implementation of appropriate digital governance systems which conform to legal and NHS requirements and fit within the wider governance systems of the trust. Ensure maintenance of an effective digital risk register, manage identified risks and escalate risks as required. Ensure the reduction, identification, management, and reporting of untoward digital incidents. Ensure compliance with the requirements of information governance, data protection and freedom of information guidance and legislation. Ensure that the Trust complies with the requirements of the Data Security and Protection Toolkit (DSPT). Ensure that Disaster Recovery and Business Continuity plans are in place for all digital services and that these are routinely tested, weakness identified, and appropriate improvement plans developed and implemented. Ensure compliance of the clinical systems with Safety of Health Systems standards, appropriate NHS Information Standards Notices (ISNs) and National Patient Safety Agency (NPSA) notices. As SIRO, oversee Information Asset Owners (IAOs) providing assurance on risks and compliance ensuring adherence to legal and regulatory requirements (including GDPR and NHS standards) and promote good information governance practices across the organisation. Working with the CDO, maintain an Information Asset Register, and oversee data security, integrity, and availability. MANAGEMENT OF THE DIGITAL SERVICE Manage and lead the digital services team in line with the trusts workforce and related policies, standing financial instructions and scheme of delegation, and other relevant policies and procedures. Develop and achieve annual objectives for digital services within the framework of the Trusts objectives and agreed digital strategy. Manage the digital budget within the requirements of the Trusts Scheme of Delegation and Standing Financial Instructions. Produce an annual rolling investment plan for digital infrastructure including capital, revenue and staffing resource. Plan, deploy, and maintain the Trusts digital systems and operations. Manage the Trusts software development needs. Develop and implement digital policies and procedures in line with requirements and best practice. PERSONAL DEVELOPMENT AND CONDUCT Adhere to impeccable standards of personal conduct and demonstrate commitment to the Trusts Values and Behaviours. Ensure personal professional knowledge is regularly updated and keep abreast of relevant developments. Adhere to the Code of Conduct for NHS Managers. Implement systems and processes, so that in the event of absence . click apply for full job details
Aker Systems was founded in 2017 by a team of experienced technology professionals who recognised an opportunity to provide highly secure enterprise data platforms to large organisations. We build and operate ground breaking, ultra secure, high performance, cloud based data infrastructure for the enterprise. Our proprietary technology solutions drive performance and reduce costs while helping our clients to improve the management and sharing of data across their organisations. In 2024, Aker Systems won the Breakthrough Culture Awards highlighting growth companies putting culture first. In 2020 Aker Systems was recognised as a 'One to Watch' on the Sunday Times Tech Track. The Company was also recognised at the Thames Valley Tech Awards 2020; winning the Thames Valley Tech Company of the year, the Emerging Tech Company and High Growth Tech Business categories. We encourage people of all different backgrounds and identities to apply. We are committed to maintaining an inclusive, and supportive place for you to do your very best work. As Managing Architect, you will be passionate about digital, data and technology led transformation, unlocking innovation for our clients, and providing leadership throughout the client engagements. The applicant who possesses knowledge and experience of Public Sector (Central Government) and understands their governance and security processes, preferably across multiple government departments, is strongly preferred. A UK Government Security Check (SC) clearance is required for this role. If you don't hold SC clearance, we will support you to apply assuming you have lived and worked in the UK for a minimum of 5 years. Due to the nature of the projects, British citizenship is required. Duties & Responsibilities Aker Managing Architect is primarily a client delivery, management, and growth role, expected to be 90% or more of the time across one or more client assignments. Technical Leadership: Part of the client leadership team as the Client CTO for assigned projects/services, supporting the Client Delivery Director, Client Account Director and the delivery team to ensure we deliver against all client deliverables and payment milestones. Lead Architect: Lead solution, data, cloud, service and security architects/engineers during design and delivery projects and services, and responsible for delivering design documents and other key artefacts to support governance and delivery. Senior Influencer: Need to be a leader and able to influence through excellent communication skills. You will relish collaboration and embrace challenges. You will understand the nuances of business and be driven to find new solutions for our clients' biggest problems. Team Focused: Expected to build effective working relationships with delivery team members and Aker customers and operate without supervision as the technical lead across multiple projects and platforms and mentoring less experienced client team members as required. Capability and Growth: Aker is a fast growing business, so for any remaining % of time when not on client work, it is contributing to the future success of Aker by helping develop capabilities and supporting the other functions such as Sales and Product, and always looking to help grow existing accounts. Essential Experience and Competencies The successful candidate will need to have experience as a lead or managing architect across these core areas: Delivery - designing, delivering platforms and managed services at enterprise scale, specifically bespoke software solutions, particularly in streaming and cloud native solutions. Data Platforms - designing modern data platforms with appropriate architecture covering Data Mesh, Data Fabric, Data Lake etc. Data/Analytics - solving enterprise data and analytics problems using technology Cloud - hands on Public Cloud experience in either AWS/Azure/Google, both their 'services' and 'how' to work in the cloud such as DevOps centric approach Security - having worked in sensitive data environments and ideally have experience facing off to cyber security specialists. The successful candidate will meet all of the following essential criteria: Demonstrable experience in designing large scale cloud migration projects/programmes with open source and commercial software within AWS, Azure, GCP or hybrid Experience in operating within a multi disciplined team and clearly communicating complex technology solutions to technical and non technical people Experience designing event processing and async messaging architectures Experience applying latest technologies to solve complex problems and to develop innovative data and analytical solutions Working knowledge of cloud orchestration and containerisation technologies, such as Docker and Kubernetes Working knowledge of DevOps, CI/CD and Infrastructure as Code Understanding of NCSC Cloud Security Principles and its practical implementations Aker Systems Attributes At Aker we work as a team; we are collaborative, hardworking, open, and delivery obsessed. There is no blame culture here: try things, and take responsibility for the outcomes. You are always part of the wider Aker. We help our colleagues and take pride in successfully achieving difficult tasks. We run towards problems and help to solve them. Communicate always, do so accurately and in a timely fashion. In return, we offer a competitive salary, 25 days holiday plus bank holidays, company paid medical insurance and life assurance, pension scheme, annual training allowance, wellbeing allowance, virtual GP, Employee Assistance plan and more. Equality, Diversity & Inclusion Aker Systems fosters a diverse environment that encourages openness in its communications and is committed to providing equal employment opportunity for all people regardless of race, religion, gender or sexual orientation, age, marital status, national origin, citizenship status, disability, veteran status or other personal characteristics. We embrace differences of opinion and diversity because they help challenge us and find new groundbreaking technical solutions.
Mar 06, 2026
Full time
Aker Systems was founded in 2017 by a team of experienced technology professionals who recognised an opportunity to provide highly secure enterprise data platforms to large organisations. We build and operate ground breaking, ultra secure, high performance, cloud based data infrastructure for the enterprise. Our proprietary technology solutions drive performance and reduce costs while helping our clients to improve the management and sharing of data across their organisations. In 2024, Aker Systems won the Breakthrough Culture Awards highlighting growth companies putting culture first. In 2020 Aker Systems was recognised as a 'One to Watch' on the Sunday Times Tech Track. The Company was also recognised at the Thames Valley Tech Awards 2020; winning the Thames Valley Tech Company of the year, the Emerging Tech Company and High Growth Tech Business categories. We encourage people of all different backgrounds and identities to apply. We are committed to maintaining an inclusive, and supportive place for you to do your very best work. As Managing Architect, you will be passionate about digital, data and technology led transformation, unlocking innovation for our clients, and providing leadership throughout the client engagements. The applicant who possesses knowledge and experience of Public Sector (Central Government) and understands their governance and security processes, preferably across multiple government departments, is strongly preferred. A UK Government Security Check (SC) clearance is required for this role. If you don't hold SC clearance, we will support you to apply assuming you have lived and worked in the UK for a minimum of 5 years. Due to the nature of the projects, British citizenship is required. Duties & Responsibilities Aker Managing Architect is primarily a client delivery, management, and growth role, expected to be 90% or more of the time across one or more client assignments. Technical Leadership: Part of the client leadership team as the Client CTO for assigned projects/services, supporting the Client Delivery Director, Client Account Director and the delivery team to ensure we deliver against all client deliverables and payment milestones. Lead Architect: Lead solution, data, cloud, service and security architects/engineers during design and delivery projects and services, and responsible for delivering design documents and other key artefacts to support governance and delivery. Senior Influencer: Need to be a leader and able to influence through excellent communication skills. You will relish collaboration and embrace challenges. You will understand the nuances of business and be driven to find new solutions for our clients' biggest problems. Team Focused: Expected to build effective working relationships with delivery team members and Aker customers and operate without supervision as the technical lead across multiple projects and platforms and mentoring less experienced client team members as required. Capability and Growth: Aker is a fast growing business, so for any remaining % of time when not on client work, it is contributing to the future success of Aker by helping develop capabilities and supporting the other functions such as Sales and Product, and always looking to help grow existing accounts. Essential Experience and Competencies The successful candidate will need to have experience as a lead or managing architect across these core areas: Delivery - designing, delivering platforms and managed services at enterprise scale, specifically bespoke software solutions, particularly in streaming and cloud native solutions. Data Platforms - designing modern data platforms with appropriate architecture covering Data Mesh, Data Fabric, Data Lake etc. Data/Analytics - solving enterprise data and analytics problems using technology Cloud - hands on Public Cloud experience in either AWS/Azure/Google, both their 'services' and 'how' to work in the cloud such as DevOps centric approach Security - having worked in sensitive data environments and ideally have experience facing off to cyber security specialists. The successful candidate will meet all of the following essential criteria: Demonstrable experience in designing large scale cloud migration projects/programmes with open source and commercial software within AWS, Azure, GCP or hybrid Experience in operating within a multi disciplined team and clearly communicating complex technology solutions to technical and non technical people Experience designing event processing and async messaging architectures Experience applying latest technologies to solve complex problems and to develop innovative data and analytical solutions Working knowledge of cloud orchestration and containerisation technologies, such as Docker and Kubernetes Working knowledge of DevOps, CI/CD and Infrastructure as Code Understanding of NCSC Cloud Security Principles and its practical implementations Aker Systems Attributes At Aker we work as a team; we are collaborative, hardworking, open, and delivery obsessed. There is no blame culture here: try things, and take responsibility for the outcomes. You are always part of the wider Aker. We help our colleagues and take pride in successfully achieving difficult tasks. We run towards problems and help to solve them. Communicate always, do so accurately and in a timely fashion. In return, we offer a competitive salary, 25 days holiday plus bank holidays, company paid medical insurance and life assurance, pension scheme, annual training allowance, wellbeing allowance, virtual GP, Employee Assistance plan and more. Equality, Diversity & Inclusion Aker Systems fosters a diverse environment that encourages openness in its communications and is committed to providing equal employment opportunity for all people regardless of race, religion, gender or sexual orientation, age, marital status, national origin, citizenship status, disability, veteran status or other personal characteristics. We embrace differences of opinion and diversity because they help challenge us and find new groundbreaking technical solutions.
Your new company A well-known technology organisation offers almost fully remote working to an Interim IT Security Policy Writer for 3-6 months- flexible locations, but occasional meetings will be required in Reading or London. Your new role Policy Creation & Management: Develop, publish, and maintain security policies, standards, and guidelines in a consistent, AI-friendly, metadata-driven policy format. Translate complex security and regulatory requirements into clear, concise, and structured documentation suitable for both humans and AI models. Ensure all documentation is version-controlled, accessible, and aligned to enterprise governance frameworks. ISO & Cybersecurity Alignment: Ensure policies map to and support compliance with: ISO 27001, ISO 27701, ISO 22301, ISO 31000, Cyber Essentials / CE+, NIST Cybersecurity Framework (CSF). Conduct gap analyses against new or updated standards and lead remediation activity. Audit & Assurance: Support internal and external audit activities related to policy and governance. Provide evidence, documentation mapping, and subject matter insight as required. Track non-conformities and corrective actions, ensuring timely closure. AI-Ready Documentation & Structure: Write policies using structured templates, taxonomies, tagging structures, and semantic headings optimised for AI policy ingestion. Cross-Functional Collaboration: Across several diverse teams within the business. Continuous Improvement What you'll need to succeed Demonstrable experience writing policies, standards, or governance documentation for ISO 27001, 27701, 22301, NIST, or similar frameworks. Ability to write clear, structured, unambiguous content designed for both human and AI consumption. Strong knowledge of cybersecurity principles, frameworks, and best practices. Experience of policy lifecycle management, governance workflows, and document control. Strong understanding of enterprise risk management, control design, and assurance principles. Excellent written communication skills with exceptional accuracy and attention to detail. Skilled in MS Word, Excel, and other documentation tooling (e.g., SharePoint, Confluence, GRC platforms). Experience working in complex business environments with minimal supervision What you'll get in return 3 month assignment initially - very likely to extend to 6 months.Mostly remote work - with occasional meetings required in Reading or London.Day rate £500-550 per day in scope of IR35 and via an umbrella company. What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion on your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
Mar 04, 2026
Seasonal
Your new company A well-known technology organisation offers almost fully remote working to an Interim IT Security Policy Writer for 3-6 months- flexible locations, but occasional meetings will be required in Reading or London. Your new role Policy Creation & Management: Develop, publish, and maintain security policies, standards, and guidelines in a consistent, AI-friendly, metadata-driven policy format. Translate complex security and regulatory requirements into clear, concise, and structured documentation suitable for both humans and AI models. Ensure all documentation is version-controlled, accessible, and aligned to enterprise governance frameworks. ISO & Cybersecurity Alignment: Ensure policies map to and support compliance with: ISO 27001, ISO 27701, ISO 22301, ISO 31000, Cyber Essentials / CE+, NIST Cybersecurity Framework (CSF). Conduct gap analyses against new or updated standards and lead remediation activity. Audit & Assurance: Support internal and external audit activities related to policy and governance. Provide evidence, documentation mapping, and subject matter insight as required. Track non-conformities and corrective actions, ensuring timely closure. AI-Ready Documentation & Structure: Write policies using structured templates, taxonomies, tagging structures, and semantic headings optimised for AI policy ingestion. Cross-Functional Collaboration: Across several diverse teams within the business. Continuous Improvement What you'll need to succeed Demonstrable experience writing policies, standards, or governance documentation for ISO 27001, 27701, 22301, NIST, or similar frameworks. Ability to write clear, structured, unambiguous content designed for both human and AI consumption. Strong knowledge of cybersecurity principles, frameworks, and best practices. Experience of policy lifecycle management, governance workflows, and document control. Strong understanding of enterprise risk management, control design, and assurance principles. Excellent written communication skills with exceptional accuracy and attention to detail. Skilled in MS Word, Excel, and other documentation tooling (e.g., SharePoint, Confluence, GRC platforms). Experience working in complex business environments with minimal supervision What you'll get in return 3 month assignment initially - very likely to extend to 6 months.Mostly remote work - with occasional meetings required in Reading or London.Day rate £500-550 per day in scope of IR35 and via an umbrella company. What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion on your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
Natural England Director of Digital and Data Location: Flexible across England Salary: £81,000 + Benefits Permanent Nature sits at the heart of our nation's prosperity, it is essential national infrastructure. It supports economic growth, improves our health and wellbeing, and strengthens our resilience in a rapidly changing world. Natural England's mission is to recover nature for health, wealth and security advising government, protecting our natural environment, enabling public access, and ensuring nature conservation and regulatory services are delivered effectively across the country. To deliver on this mission at scale, digital and data are fundamental. Our statutory services, our organisational reforms, our regulatory responsibilities, and our leadership of nature recovery all depend on high quality digital systems, strong data foundations and modern, user centred services. We are already on an ambitious transformation journey. We have established new governance and assurance processes, brought together a unified digital and data directorate, and built a development pipeline of significant programmes. We are now transforming Natural England into a truly digitally enabled organisation and this new role will spearhead that change, driving it further and faster. The Opportunity Reporting to the Chief Scientist, you will play a strategic and highly visible role in shaping and delivering our Destination Digital strategy. You will lead a team of around 50 specialists, setting the direction for digital and data across the organisation, embedding modern ways of working and ensuring solutions deliver sustained, measurable benefits for nature. You will work closely with colleagues across Natural England, the DEFRA group and cross government partners, strengthening relationships, influencing decisions and ensuring digital and data services are delivered in better, simpler and more effective ways. You will champion innovation, draw on expertise from public and private sectors, and push forward the adoption of leading edge technologies where they can deliver genuine value. Above all, you will be a leader for a team of committed digital and data professionals (and for the wider Natural England workforce) who share a deep passion for improving outcomes for communities, the environment and the nation. What you will bring Essential criteria: To be successful, you will be/bring: A visible, inclusive and credible leader , trusted at executive, organisational and partner levels. You inspire and mobilise others, embed cultural change and build a sustained continuous improvement mindset. Proven experience leading enterprise wide digital and data transformation , with end to end ownership for modernising services, operating models and ways of working, ensuring solutions are adopted, embedded and deliver lasting organisational value. Strong portfolio and delivery leadership , with a track record of managing large scale digital and data programmes on time and within budget, supported by robust governance and assurance. Deep digital and data expertise , applying strategic insight across digital technologies, data management, cybersecurity and IT infrastructure. Organisational and people leadership , guiding multidisciplinary teams through complexity and uncertainty, maintaining momentum and delivering at pace. A highly effective relationship builder , able to establish credibility, influence decisions based on risk and strategic priorities, and align diverse stakeholders across a complex partner ecosystem. This is a unique and exciting opportunity to make a lasting difference transforming how a national organisation operates and enabling our people to deliver better outcomes for nature, now and for the future. If you are motivated by our mission and inspired by our ambition, we would love to hear from you. To apply for this post, you will need to complete the online application process no later than 09:00 on Monday 16 March 2026 . All applications must be submitted using the link by clicking Apply on website. How to apply When applying, please ensure that you provide the following information. Your CV (pdf) A supporting statement (pdf and of not more than 2 pages) detailing how you can address the Essential criteria Contact telephone numbers as well as your personal email address A completed diversity monitoring form (this will appear on screen as part of the application process). For a confidential discussion about the role, please do contact our recruitment advisers at GatenbySanderson who will be delighted to speak with you: Sarah Luxford on Sarah. Martyn Brereton on
Mar 04, 2026
Full time
Natural England Director of Digital and Data Location: Flexible across England Salary: £81,000 + Benefits Permanent Nature sits at the heart of our nation's prosperity, it is essential national infrastructure. It supports economic growth, improves our health and wellbeing, and strengthens our resilience in a rapidly changing world. Natural England's mission is to recover nature for health, wealth and security advising government, protecting our natural environment, enabling public access, and ensuring nature conservation and regulatory services are delivered effectively across the country. To deliver on this mission at scale, digital and data are fundamental. Our statutory services, our organisational reforms, our regulatory responsibilities, and our leadership of nature recovery all depend on high quality digital systems, strong data foundations and modern, user centred services. We are already on an ambitious transformation journey. We have established new governance and assurance processes, brought together a unified digital and data directorate, and built a development pipeline of significant programmes. We are now transforming Natural England into a truly digitally enabled organisation and this new role will spearhead that change, driving it further and faster. The Opportunity Reporting to the Chief Scientist, you will play a strategic and highly visible role in shaping and delivering our Destination Digital strategy. You will lead a team of around 50 specialists, setting the direction for digital and data across the organisation, embedding modern ways of working and ensuring solutions deliver sustained, measurable benefits for nature. You will work closely with colleagues across Natural England, the DEFRA group and cross government partners, strengthening relationships, influencing decisions and ensuring digital and data services are delivered in better, simpler and more effective ways. You will champion innovation, draw on expertise from public and private sectors, and push forward the adoption of leading edge technologies where they can deliver genuine value. Above all, you will be a leader for a team of committed digital and data professionals (and for the wider Natural England workforce) who share a deep passion for improving outcomes for communities, the environment and the nation. What you will bring Essential criteria: To be successful, you will be/bring: A visible, inclusive and credible leader , trusted at executive, organisational and partner levels. You inspire and mobilise others, embed cultural change and build a sustained continuous improvement mindset. Proven experience leading enterprise wide digital and data transformation , with end to end ownership for modernising services, operating models and ways of working, ensuring solutions are adopted, embedded and deliver lasting organisational value. Strong portfolio and delivery leadership , with a track record of managing large scale digital and data programmes on time and within budget, supported by robust governance and assurance. Deep digital and data expertise , applying strategic insight across digital technologies, data management, cybersecurity and IT infrastructure. Organisational and people leadership , guiding multidisciplinary teams through complexity and uncertainty, maintaining momentum and delivering at pace. A highly effective relationship builder , able to establish credibility, influence decisions based on risk and strategic priorities, and align diverse stakeholders across a complex partner ecosystem. This is a unique and exciting opportunity to make a lasting difference transforming how a national organisation operates and enabling our people to deliver better outcomes for nature, now and for the future. If you are motivated by our mission and inspired by our ambition, we would love to hear from you. To apply for this post, you will need to complete the online application process no later than 09:00 on Monday 16 March 2026 . All applications must be submitted using the link by clicking Apply on website. How to apply When applying, please ensure that you provide the following information. Your CV (pdf) A supporting statement (pdf and of not more than 2 pages) detailing how you can address the Essential criteria Contact telephone numbers as well as your personal email address A completed diversity monitoring form (this will appear on screen as part of the application process). For a confidential discussion about the role, please do contact our recruitment advisers at GatenbySanderson who will be delighted to speak with you: Sarah Luxford on Sarah. Martyn Brereton on
At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Job Title: Senior Consultant - Data Protection About EY: At EY, we are committed to building a better working world. Our Cybersecurity Consulting Practice is rapidly expanding, and we are investing in our capabilities to meet the increasing demand for cybersecurity solutions. Join us and be part of a global team of over 13,000 professionals dedicated to delivering cutting edge security transformation programs and services. Join us and build an exceptional experience for yourself, and a better working world for all. The opportunity: As a Senior Consultant in Data Protection you will take a key position in delivering EY's data protection services, supporting and managing engagements and client delivery. You will also be expected to take a supporting role in building out EY's Data Protection Services, working with alliance partners and advising clients on the current market trends. Location - London, Manchester or Scotland The role will see you providing specialist advice as part of a variety of teams - from discrete data protection and privacy focused activities across large multi disciplinary teams, to delivering privacy and cyber security transformation programmes. Key Responsibilities Supporting end to end data protection programmes at a UK and global level from design through to build and implementation. Delivering discrete elements of programmes and projects. Conducting data protection maturity and gap assessments - this may include evaluation of the control landscape, data loss prevention/insider threat and information management solutions; user awareness and training. Data discovery programmes and data inventory management to meet regulatory and security requirements. Data Loss Prevention assessment, strategy and implementation programmes. Data governance and data ethics review, management and design. Design and configuration of specific technology solutions associated with data protection - e.g. Microsoft Purview, BigID, OneTrust. Privacy technology advisory and implementation activities. Data Classification, handling and operational engagements to support effective privacy and security strategies. You will work with colleagues in the UK and globally to develop new and innovative compliance services, focussed on emerging legislation and technology as well as maturity of existing operations in specific industry propositions that solve client problems/issues and integrate with their overall IT delivery and support strategy. In addition to the above, you will have an opportunity to work across all aspects of Cyber, Technology and business solutions. Additional Responsibilities Deliver engagements and build productive relationships with client stakeholders through project delivery. Contribute to articles and thought pieces. Work with prospective clients on the planning and delivery phase of engagements. Create high quality reports as part of a team, for review by engagement and project leaders. Work with senior practice leaders and market leaders in the creation of proposals and marketing material. Skills and Attributes for Success Be professional, quickly establishing personal credibility and demonstrating expertise. Be a good communicator with the ability to contribute assuredly to technical security and privacy discussions with peers. Be a team player who is not only looking to enhance their own career but recognises the value of teamwork, facilitating and encouraging collaboration among team members. Take a practical approach to solving issues and gaining client agreement. Be able to analyse complex problems and deliver insightful, practical and sustainable solutions. Be confident and effective in recognising and managing potential issues during client assignments. Proactively identify risks and issues that may impact delivery of day to day work. To Qualify for the Role Professional experience within a consulting or professional services organisation operating within the Data Protection and privacy space. This includes the ability to understand, assess and deliver programmes and technical implementation of data protection tooling. Experience delivering data protection programmes across the areas: classification, Data Loss Prevention, CASB and data management. Experience should range from assessment to programme redesign and implementation. Experience working with others in the development and delivery of complex client solutions and/or proposition development. A good understanding of privacy processes and requirements, from governance and data subject rights through to data mapping, privacy operations and privacy risk management. Ideally, You'll Also Have Security and Privacy relation qualifications such as CIPP/E, CIPP/M or vendor qualifications on DPP software including DLP, Classification solutions and data discovery platforms. Broader cybersecurity knowledge and skills across cyber domains including NIST, ISO 27001, cyber assessments, programmes and management. Experience with Privacy/data management tooling such as TrustArc, OneTrust and BigID. Key delivery experience in the following disciplines: security assurance, third party management, DLP, Classification. Key sector experience in one or more of the following: Government & Public sector / Energy & Utilities / Retail and Consumer products / Life sciences / Telecoms, Media and Technology / Transport. What We Look For Core consulting skills - advanced data and evidence management, client management on remediation programmes, driving innovation and continuous improvement. Proactive - an individual who can get stuck into client delivery and support the broader practice and solutions. Technical skills - strong technical insight, practical knowledge and specialist capability. Versatility - proven ability to adapt and learn in an innovative environment. Security Clearance The successful candidate must undergo and pass checks in line with SC (Security Check) clearance standards after joining EY. These checks may include, but are not limited to, verification of identity, right to work in the UK, employment history, proof of address and unspent criminal convictions. Candidates must be a UK national or have been a resident in the UK for a minimum of five years and must not have spent more than six months outside the UK. What We Offer EY is committed to being an inclusive employer and we are happy to consider flexible working arrangements. We strive to achieve the right balance for our people, enabling us to deliver excellent client service whilst allowing you to build your career without sacrificing your personal priorities. While our client facing professionals can be required to travel regularly, and at times be based at client sites, our flexible working arrangements can help you to achieve a lifestyle balance. We offer a competitive remuneration package. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well being, insurance, savings and a wide range of discounts, offers and promotions. Plus, we offer: Continuous learning: You'll develop the mindset and skills to navigate whatever comes next. Success as defined by you: We'll provide the tools and flexibility, so you can make a meaningful impact, your way. Transformative leadership: We'll give you the insights, coaching and confidence to be the leader the world needs. Diverse and inclusive culture: You'll be embraced for who you are and empowered to use your voice to help others find theirs. If you can demonstrate that you meet the criteria above, please contact us as soon as possible. The exceptional EY experience. It's yours to build. Apply now. TCCyberUKI2026 Cyber2026 EY Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
Feb 28, 2026
Full time
At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Job Title: Senior Consultant - Data Protection About EY: At EY, we are committed to building a better working world. Our Cybersecurity Consulting Practice is rapidly expanding, and we are investing in our capabilities to meet the increasing demand for cybersecurity solutions. Join us and be part of a global team of over 13,000 professionals dedicated to delivering cutting edge security transformation programs and services. Join us and build an exceptional experience for yourself, and a better working world for all. The opportunity: As a Senior Consultant in Data Protection you will take a key position in delivering EY's data protection services, supporting and managing engagements and client delivery. You will also be expected to take a supporting role in building out EY's Data Protection Services, working with alliance partners and advising clients on the current market trends. Location - London, Manchester or Scotland The role will see you providing specialist advice as part of a variety of teams - from discrete data protection and privacy focused activities across large multi disciplinary teams, to delivering privacy and cyber security transformation programmes. Key Responsibilities Supporting end to end data protection programmes at a UK and global level from design through to build and implementation. Delivering discrete elements of programmes and projects. Conducting data protection maturity and gap assessments - this may include evaluation of the control landscape, data loss prevention/insider threat and information management solutions; user awareness and training. Data discovery programmes and data inventory management to meet regulatory and security requirements. Data Loss Prevention assessment, strategy and implementation programmes. Data governance and data ethics review, management and design. Design and configuration of specific technology solutions associated with data protection - e.g. Microsoft Purview, BigID, OneTrust. Privacy technology advisory and implementation activities. Data Classification, handling and operational engagements to support effective privacy and security strategies. You will work with colleagues in the UK and globally to develop new and innovative compliance services, focussed on emerging legislation and technology as well as maturity of existing operations in specific industry propositions that solve client problems/issues and integrate with their overall IT delivery and support strategy. In addition to the above, you will have an opportunity to work across all aspects of Cyber, Technology and business solutions. Additional Responsibilities Deliver engagements and build productive relationships with client stakeholders through project delivery. Contribute to articles and thought pieces. Work with prospective clients on the planning and delivery phase of engagements. Create high quality reports as part of a team, for review by engagement and project leaders. Work with senior practice leaders and market leaders in the creation of proposals and marketing material. Skills and Attributes for Success Be professional, quickly establishing personal credibility and demonstrating expertise. Be a good communicator with the ability to contribute assuredly to technical security and privacy discussions with peers. Be a team player who is not only looking to enhance their own career but recognises the value of teamwork, facilitating and encouraging collaboration among team members. Take a practical approach to solving issues and gaining client agreement. Be able to analyse complex problems and deliver insightful, practical and sustainable solutions. Be confident and effective in recognising and managing potential issues during client assignments. Proactively identify risks and issues that may impact delivery of day to day work. To Qualify for the Role Professional experience within a consulting or professional services organisation operating within the Data Protection and privacy space. This includes the ability to understand, assess and deliver programmes and technical implementation of data protection tooling. Experience delivering data protection programmes across the areas: classification, Data Loss Prevention, CASB and data management. Experience should range from assessment to programme redesign and implementation. Experience working with others in the development and delivery of complex client solutions and/or proposition development. A good understanding of privacy processes and requirements, from governance and data subject rights through to data mapping, privacy operations and privacy risk management. Ideally, You'll Also Have Security and Privacy relation qualifications such as CIPP/E, CIPP/M or vendor qualifications on DPP software including DLP, Classification solutions and data discovery platforms. Broader cybersecurity knowledge and skills across cyber domains including NIST, ISO 27001, cyber assessments, programmes and management. Experience with Privacy/data management tooling such as TrustArc, OneTrust and BigID. Key delivery experience in the following disciplines: security assurance, third party management, DLP, Classification. Key sector experience in one or more of the following: Government & Public sector / Energy & Utilities / Retail and Consumer products / Life sciences / Telecoms, Media and Technology / Transport. What We Look For Core consulting skills - advanced data and evidence management, client management on remediation programmes, driving innovation and continuous improvement. Proactive - an individual who can get stuck into client delivery and support the broader practice and solutions. Technical skills - strong technical insight, practical knowledge and specialist capability. Versatility - proven ability to adapt and learn in an innovative environment. Security Clearance The successful candidate must undergo and pass checks in line with SC (Security Check) clearance standards after joining EY. These checks may include, but are not limited to, verification of identity, right to work in the UK, employment history, proof of address and unspent criminal convictions. Candidates must be a UK national or have been a resident in the UK for a minimum of five years and must not have spent more than six months outside the UK. What We Offer EY is committed to being an inclusive employer and we are happy to consider flexible working arrangements. We strive to achieve the right balance for our people, enabling us to deliver excellent client service whilst allowing you to build your career without sacrificing your personal priorities. While our client facing professionals can be required to travel regularly, and at times be based at client sites, our flexible working arrangements can help you to achieve a lifestyle balance. We offer a competitive remuneration package. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well being, insurance, savings and a wide range of discounts, offers and promotions. Plus, we offer: Continuous learning: You'll develop the mindset and skills to navigate whatever comes next. Success as defined by you: We'll provide the tools and flexibility, so you can make a meaningful impact, your way. Transformative leadership: We'll give you the insights, coaching and confidence to be the leader the world needs. Diverse and inclusive culture: You'll be embraced for who you are and empowered to use your voice to help others find theirs. If you can demonstrate that you meet the criteria above, please contact us as soon as possible. The exceptional EY experience. It's yours to build. Apply now. TCCyberUKI2026 Cyber2026 EY Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
Overview Location: London Other locations: Anywhere in Country Date: 28 Jan 2026 Requisition ID: At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Job Title: Senior Consultant - Data Protection About EY: At EY, we are committed to building a better working world. Our Cybersecurity Consulting Practice is rapidly expanding, and we are investing in our capabilities to meet the increasing demand for cybersecurity solutions. Join us and be part of a global team of over 13,000 professionals dedicated to delivering cutting-edge security transformation programs and services. Join us and build an exceptional experience for yourself, and a better working world for all. Responsibilities Supporting end to end data protection programmes at a UK and global level from design through to build and implementation. Delivering discrete elements of programmes and projects. Conducting data protection maturity and gap assessments, including evaluation of the control landscape - data loss prevention/ insider threat and information management solutions; user awareness and training. Data discovery programmes and data inventory management to meet regulatory and security requirements. Data Loss Prevention assessment, strategy and implementation programmes. Data governance and data ethics review, management and design. Design and configuration of specific technology solutions associated with data protection - e.g. Microsoft Purview, BigID, OneTrust. Privacy technology advisory and implementation activities. Data Classification, handling and operational engagements to support effective privacy and security strategies. Work with colleagues in the UK and globally to develop new and innovative compliance services, focusing on emerging legislation and technology as well as maturity of existing operations in specific industry propositions that solve client problems/issues and integrate with their overall IT delivery and support strategy. You will have opportunities to work across all aspects of Cyber, Technology and business solutions. Your key responsibilities - delivering engagements and building productive relationships with client stakeholders through project delivery. Contributing to articles and thought pieces. Working with prospective clients on the planning and delivery phase of engagements. Creating high quality reports as part of a team, for review by engagement and project leaders. Working with senior practice leaders and market leaders in the creation of proposals and marketing material. Qualifications To qualify for the role you must have professional experience within a consulting or professional services organisation operating within the Data Protection and privacy space. This includes ability to understand, assess and deliver programmes and technical implementation of data protection tooling. Experience of delivering data protection programmes across the areas: classification, Data Loss Prevention, CASB and data management. Experience should range from assessment to programme redesign and implementation. Experience working with others in the development and delivery of complex client solutions and/or proposition development. A good understanding of privacy processes and requirements, from governance and data subject rights through to data mapping, privacy operations and privacy risk management. Ideally, you'll also have security and privacy relation qualifications such as CIPP/E, CIPP/M or vendor qualifications on DPP software including DLP, Classification solutions and data discovery platforms. Broader cybersecurity knowledge and skills across cyber domains including NIST, ISO 27001, cyber assessments, programmes and management. Experience with Privacy/ data management tooling such as TrustArc, OneTrust and BigID. Key delivery experience in the following disciplines: security assurance, third party management, DLP, Classification. Key sector experience in Government & Public sector / Energy & Utilities / Retail and Consumer products / Life sciences / Telecoms, Media and Technology / Transport. What we look for Core consulting skills - Advanced data and evidence management, client management on remediation programmes, driving innovation and continuous improvement. Proactive - a proactive individual who can get stuck in to client delivery and support the broader practice and solutions. Technical skills - Strong technical insight, practical knowledge and specialist capability. Versatility - Proven ability to adapt and learn in an innovative environment. Security and Compliance Please note: The successful candidate must undergo and pass checks in line with SC (Security Check) clearance standards after joining EY. These checks may include, but are not limited to, verification of identity, right to work in the UK, employment history, proof of address may be required and unspent criminal convictions. Candidates must be a UK national or have been a resident in the UK for a minimum of five years and ensure that they have not spent more than six months outside the UK. What we offer EY is committed to being an inclusive employer and we are happy to consider flexible working arrangements. We strive to achieve the right balance for our people, enabling us to deliver excellent client service whilst allowing you to build your career without sacrificing your personal priorities. While our client-facing professionals can be required to travel regularly, and at times be based at client sites, our flexible working arrangements can help you to achieve a lifestyle balance. We offer a competitive remuneration package. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well-being, insurance, savings and a wide range of discounts, offers and promotions. Continuous learning: You'll develop the mindset and skills to navigate whatever comes next. Success as defined by you: We'll provide the tools and flexibility, so you can make a meaningful impact, your way. Transformative leadership: We'll give you the insights, coaching and confidence to be the leader the world needs. Diverse and inclusive culture: You'll be embraced for who you are and empowered to use your voice to help others find theirs. If you can demonstrate that you meet the criteria above, please contact us as soon as possible. The exceptional EY experience. It's yours to build. Apply now. TCCyberUKI2026 Cyber2026 EY Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
Feb 26, 2026
Full time
Overview Location: London Other locations: Anywhere in Country Date: 28 Jan 2026 Requisition ID: At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Job Title: Senior Consultant - Data Protection About EY: At EY, we are committed to building a better working world. Our Cybersecurity Consulting Practice is rapidly expanding, and we are investing in our capabilities to meet the increasing demand for cybersecurity solutions. Join us and be part of a global team of over 13,000 professionals dedicated to delivering cutting-edge security transformation programs and services. Join us and build an exceptional experience for yourself, and a better working world for all. Responsibilities Supporting end to end data protection programmes at a UK and global level from design through to build and implementation. Delivering discrete elements of programmes and projects. Conducting data protection maturity and gap assessments, including evaluation of the control landscape - data loss prevention/ insider threat and information management solutions; user awareness and training. Data discovery programmes and data inventory management to meet regulatory and security requirements. Data Loss Prevention assessment, strategy and implementation programmes. Data governance and data ethics review, management and design. Design and configuration of specific technology solutions associated with data protection - e.g. Microsoft Purview, BigID, OneTrust. Privacy technology advisory and implementation activities. Data Classification, handling and operational engagements to support effective privacy and security strategies. Work with colleagues in the UK and globally to develop new and innovative compliance services, focusing on emerging legislation and technology as well as maturity of existing operations in specific industry propositions that solve client problems/issues and integrate with their overall IT delivery and support strategy. You will have opportunities to work across all aspects of Cyber, Technology and business solutions. Your key responsibilities - delivering engagements and building productive relationships with client stakeholders through project delivery. Contributing to articles and thought pieces. Working with prospective clients on the planning and delivery phase of engagements. Creating high quality reports as part of a team, for review by engagement and project leaders. Working with senior practice leaders and market leaders in the creation of proposals and marketing material. Qualifications To qualify for the role you must have professional experience within a consulting or professional services organisation operating within the Data Protection and privacy space. This includes ability to understand, assess and deliver programmes and technical implementation of data protection tooling. Experience of delivering data protection programmes across the areas: classification, Data Loss Prevention, CASB and data management. Experience should range from assessment to programme redesign and implementation. Experience working with others in the development and delivery of complex client solutions and/or proposition development. A good understanding of privacy processes and requirements, from governance and data subject rights through to data mapping, privacy operations and privacy risk management. Ideally, you'll also have security and privacy relation qualifications such as CIPP/E, CIPP/M or vendor qualifications on DPP software including DLP, Classification solutions and data discovery platforms. Broader cybersecurity knowledge and skills across cyber domains including NIST, ISO 27001, cyber assessments, programmes and management. Experience with Privacy/ data management tooling such as TrustArc, OneTrust and BigID. Key delivery experience in the following disciplines: security assurance, third party management, DLP, Classification. Key sector experience in Government & Public sector / Energy & Utilities / Retail and Consumer products / Life sciences / Telecoms, Media and Technology / Transport. What we look for Core consulting skills - Advanced data and evidence management, client management on remediation programmes, driving innovation and continuous improvement. Proactive - a proactive individual who can get stuck in to client delivery and support the broader practice and solutions. Technical skills - Strong technical insight, practical knowledge and specialist capability. Versatility - Proven ability to adapt and learn in an innovative environment. Security and Compliance Please note: The successful candidate must undergo and pass checks in line with SC (Security Check) clearance standards after joining EY. These checks may include, but are not limited to, verification of identity, right to work in the UK, employment history, proof of address may be required and unspent criminal convictions. Candidates must be a UK national or have been a resident in the UK for a minimum of five years and ensure that they have not spent more than six months outside the UK. What we offer EY is committed to being an inclusive employer and we are happy to consider flexible working arrangements. We strive to achieve the right balance for our people, enabling us to deliver excellent client service whilst allowing you to build your career without sacrificing your personal priorities. While our client-facing professionals can be required to travel regularly, and at times be based at client sites, our flexible working arrangements can help you to achieve a lifestyle balance. We offer a competitive remuneration package. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well-being, insurance, savings and a wide range of discounts, offers and promotions. Continuous learning: You'll develop the mindset and skills to navigate whatever comes next. Success as defined by you: We'll provide the tools and flexibility, so you can make a meaningful impact, your way. Transformative leadership: We'll give you the insights, coaching and confidence to be the leader the world needs. Diverse and inclusive culture: You'll be embraced for who you are and empowered to use your voice to help others find theirs. If you can demonstrate that you meet the criteria above, please contact us as soon as possible. The exceptional EY experience. It's yours to build. Apply now. TCCyberUKI2026 Cyber2026 EY Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
About the role You'll lead Arm's Proactive Threat Defence function, defining and delivering a proactive assurance and threat-hunting programme that continuously tests and strengthens Arm's cyber defences and sharpens its threat-informed edge! This hands-on leadership role involves guiding a small, high-performing team, providing both technical direction and people leadership. The position partners closely with Detect & Respond, Vulnerability Management, Security Architecture, and internal customers to define and deliver a proactive defence roadmap. You will be setting strategy and remaining deeply engaged in technical design, execution, and iterative improvement. Responsibilities Design and lead red & purple team exercises Lead the strategy and delivery of red/purple team engagements aligned to real-world adversarial behaviour. Drive iterative improvement of detection, response, and resilience through defender collaboration. Ensure findings are prioritised, tracked, and remediated with clear understanding of risk and business impact. Penetration testing program (manual & autonomous) Define strategy and methodology across key technologies, platforms, and services. Embed testing into delivery lifecycles with platform owners and document risk with Governance, Risk & Compliance. Lead hypothesis-informed threat hunting Design and deliver structured hunting campaigns focused on high-value assets, emerging TTPs, and priority threat actors. Define metrics and report on coverage, effectiveness, and impact on improved detection capability. Leadership Line-manage and develop a specialist team. Foster a high-performance, psychologically safe culture. Shape the Cyber Defence Operations roadmap, aligning proactive capabilities to strategic risks and business priorities. Define and report critical metrics, reporting progress and risk to senior business leaders. Previous experience in proactive defence is a priority, however, the role will also lead development of Arm's threat intelligence capability, so any additional experience or desire to mature a threat intelligence program is favourable. Personal attributes & experience Leading proactive security functions (red teaming, pen testing, offensive engineering, intelligence). Solid understanding of modern threat actor TTPs and how to emulate them safely. Hands-on technical offensive security background (red teaming, penetration testing, exploit development, adversary emulation) with the credibility to act as a technical SME. Ability to translate technical outcomes into business-relevant risk and drive remediation at scale. Strong partnership focus, influencing at senior levels across technical and non-technical teams. Qualifications BSc or higher in a relevant field (e.g., Computer Science, Cyber Security, Digital Forensics, Information Security) or equivalent professional experience. Offensive security / threat hunting / incident response certifications advantageous (e.g., CREST, GIAC/GX, GCTI, GCFA, GCIH, GREM, GPEN, OSCP). Accommodations at Arm At Arm, we want to build extraordinary teams. If you need an adjustment or an accommodation during the recruitment process, please email . To note, by sending us the requested information, you consent to its use by Arm to arrange for appropriate accommodations. All accommodation or adjustment requests will be treated with confidentiality, and information concerning these requests will only be disclosed as necessary to provide the accommodation. Although this is not an exhaustive list, examples of support include breaks between interviews, having documents read aloud, or office accessibility. Please email us about anything we can do to accommodate you during the recruitment process. Hybrid Working at Arm Arm's approach to hybrid working is designed to create a working environment that supports both high performance and personal wellbeing. We believe in bringing people together face to face to enable us to work at pace, whilst recognizing the value of flexibility. Within that framework, we empower groups/teams to determine their own hybrid working patterns, depending on the work and the team's needs. Details of what this means for each role will be shared upon application. In some cases, the flexibility we can offer is limited by local legal, regulatory, tax, or other considerations, and where this is the case, we will collaborate with you to find the best solution. Please talk to us to find out more about what this could look like for you. Equal Opportunities at Arm Arm is an equal opportunity employer, committed to providing an environment of mutual respect where equal opportunities are available to all applicants and colleagues. We are a diverse organization of dedicated and innovative individuals, and don't discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Feb 15, 2026
Full time
About the role You'll lead Arm's Proactive Threat Defence function, defining and delivering a proactive assurance and threat-hunting programme that continuously tests and strengthens Arm's cyber defences and sharpens its threat-informed edge! This hands-on leadership role involves guiding a small, high-performing team, providing both technical direction and people leadership. The position partners closely with Detect & Respond, Vulnerability Management, Security Architecture, and internal customers to define and deliver a proactive defence roadmap. You will be setting strategy and remaining deeply engaged in technical design, execution, and iterative improvement. Responsibilities Design and lead red & purple team exercises Lead the strategy and delivery of red/purple team engagements aligned to real-world adversarial behaviour. Drive iterative improvement of detection, response, and resilience through defender collaboration. Ensure findings are prioritised, tracked, and remediated with clear understanding of risk and business impact. Penetration testing program (manual & autonomous) Define strategy and methodology across key technologies, platforms, and services. Embed testing into delivery lifecycles with platform owners and document risk with Governance, Risk & Compliance. Lead hypothesis-informed threat hunting Design and deliver structured hunting campaigns focused on high-value assets, emerging TTPs, and priority threat actors. Define metrics and report on coverage, effectiveness, and impact on improved detection capability. Leadership Line-manage and develop a specialist team. Foster a high-performance, psychologically safe culture. Shape the Cyber Defence Operations roadmap, aligning proactive capabilities to strategic risks and business priorities. Define and report critical metrics, reporting progress and risk to senior business leaders. Previous experience in proactive defence is a priority, however, the role will also lead development of Arm's threat intelligence capability, so any additional experience or desire to mature a threat intelligence program is favourable. Personal attributes & experience Leading proactive security functions (red teaming, pen testing, offensive engineering, intelligence). Solid understanding of modern threat actor TTPs and how to emulate them safely. Hands-on technical offensive security background (red teaming, penetration testing, exploit development, adversary emulation) with the credibility to act as a technical SME. Ability to translate technical outcomes into business-relevant risk and drive remediation at scale. Strong partnership focus, influencing at senior levels across technical and non-technical teams. Qualifications BSc or higher in a relevant field (e.g., Computer Science, Cyber Security, Digital Forensics, Information Security) or equivalent professional experience. Offensive security / threat hunting / incident response certifications advantageous (e.g., CREST, GIAC/GX, GCTI, GCFA, GCIH, GREM, GPEN, OSCP). Accommodations at Arm At Arm, we want to build extraordinary teams. If you need an adjustment or an accommodation during the recruitment process, please email . To note, by sending us the requested information, you consent to its use by Arm to arrange for appropriate accommodations. All accommodation or adjustment requests will be treated with confidentiality, and information concerning these requests will only be disclosed as necessary to provide the accommodation. Although this is not an exhaustive list, examples of support include breaks between interviews, having documents read aloud, or office accessibility. Please email us about anything we can do to accommodate you during the recruitment process. Hybrid Working at Arm Arm's approach to hybrid working is designed to create a working environment that supports both high performance and personal wellbeing. We believe in bringing people together face to face to enable us to work at pace, whilst recognizing the value of flexibility. Within that framework, we empower groups/teams to determine their own hybrid working patterns, depending on the work and the team's needs. Details of what this means for each role will be shared upon application. In some cases, the flexibility we can offer is limited by local legal, regulatory, tax, or other considerations, and where this is the case, we will collaborate with you to find the best solution. Please talk to us to find out more about what this could look like for you. Equal Opportunities at Arm Arm is an equal opportunity employer, committed to providing an environment of mutual respect where equal opportunities are available to all applicants and colleagues. We are a diverse organization of dedicated and innovative individuals, and don't discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Ernst & Young Advisory Services Sdn Bhd
Manchester, Lancashire
Senior Manager, Cyber Security, Identity , TC UKI Location: London Other locations: Primary Location Only Date: 13 Jan 2026 Requisition ID: At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Cyber security and its related challenges are a rapidly growing field.As such, the opportunities for careers in cyber security are also growing. Securing an organisation against cyber threats is a business priority to enable growth and successful digital transformation and we are at the heart of many of these conversations and projects. EY is rapidly expanding its cyber security consulting practice to further support these exiting opportunities At EY, we have large scale plans to expand our alreadymarket leading Cyber Security practice and anticipate continued growth throughout the next five years. We need excellent people to join us and be part of our exciting growth strategy. At EY,you'll have the chance to build a meaningful and fulfilling career, with global scale, support, inclusive culture and technology, to become the best version of you. The team you join - EY's UK & Ireland Cyber Practice - is part of a global cyber team of 5,000+ professionals focused on developing and delivering cutting edge security transformation programmes, cyber threat management, identity and access management, security architecture, data protection and privacy, and resilience services. We are part of a wider advisory organisation that collectively comprises a $4B, and growing, global consulting practice with 18,000 professionals. Join us and build an exceptional experience for yourself, and a better working world for all. Location - London, Manchester or Scotland The opportunity EY is seeking experienced team members who can review, design and deliver Cyber Identity and Access Management (IAM) services. You will take a key position in delivering EY's cyber security and IAM capabilities. You will also take a supporting role in building out EY's IAM cyber services, working with alliance partners and advising clients on current market trends. The role will see you providing specialist advice as part of large multi-discipline EY engagement teams working on the likes of cyber transformation and migration, leading specific security engagements advising on the adoption of secure architecture blueprints, secure software engineering practices, or optimising cyber defence operations. You will work with colleagues in the UK and globally to develop new and innovative IAM security solutions and specific industry propositions that solve client problems/issues and integrate with their overall IT delivery and support strategy. You will also have opportunities to work across multiple aspects of Cyber, Technology and business solutions. Responsibilities, Qualifications, Certifications - External Your key responsibilities Your responsibilities will include but are not limited to: Managing a portfolio of IAM engagements with our clients, responsible for day to day running of the engagements including meeting quality, time and budget targets Working with prospective clients to agree, scope and plan the delivery phase of engagements Contributing to developing the market for IAM across all sectors, identifying sales opportunities and working with senior practice and market leaders in the creation of proposals and marketing material Developing team members by sharing knowledge, mentoring and coaching them and leading by example Creating thought leadership and market materials for selling and promoting EY Cyber and IAM Security offering Skills and attributes for success Be professional, quicklyestablishing personal credibility and demonstrating expertise Be a good communicator with the ability to contribute assuredly to IAM business and technical security discussions with peers Be a team player who is not only looking to enhance their own career but recognising the value of teamwork, facilitating and encouraging collaboration amongst team members, and is capable of motivating teams to maximise performance Take a practical approach to solving issues and gaining client agreement Be able to analyse complex problems and to deliver insightful, practical and sustainable solutions. Be confident and effective in recognising and managing potential issues during client assignments Structure and manage projects which meet client expectations and mitigate any risks or issues To qualify for theroleyou must have: Exposure across one or more of the following: Identity Governance, Access Management, Privileged Access Management, Consumer Identity, OT IAM Worked with one or more of the following IAM technologies: Saviynt, Clear Skye, SailPoint, CyberArk, Entra, OneIdentity, BeyondTrust, Okta, Ping, ForgeRock Project management experience on IAM solution deployments (waterfall and/or agile) IAM controls governance frameworks over processes, controls, organisation and infrastructure Ideally,you'll also have IAM business analysis experience IAM assessment, strategy and roadmap development experience Design experience for IAM solutions on client transformations Key sector experience in one or more of the following: Government & Public sector / Energy & Utilities / Retail and Consumer products / Life sciences / Telecoms, Media and Technology / Transport Experience managing and coaching others in the development and delivery of complex client solutions and/or proposition development What we look for Core consulting skills: Advanced data and evidence management, client management on remediation programmes, driving innovation and continuous improvement Technical skills: Strong technical insight, practical knowledge and specialist capability Market/Sector knowledge: Demonstrable market/sector expertise in your field Versatility: Proven ability to adapt and learn in an innovative environment Please note The successful candidate must undergo and pass checks in line with SC (Security Check) clearance standards after joining EY. These checks may include, but are not limited to, verification of identity, right to work in the UK, employment history, proof of address may be required and unspent criminal convictions. Candidates must be a UK national or have been a resident in the UK for a minimum of five years and ensure that they have not spent more than six months outside the UK. What we offer EY is committed to being an inclusive employer and we are happy to consider flexible working arrangements. We strive to achieve the right balance for our people, enabling us to deliver excellent client service whilst allowing you to build your career without sacrificing your personal priorities. While our client-facing professionals can be required to travel regularly, and at times be based at client sites, our flexible working arrangements can help you to achieve a lifestyle balance. We offer a competitive remuneration package. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well-being, insurance, savings and a wide range of discounts, offers and promotions. Plus, we offer: Continuous learning:You'll develop the mindset and skills to navigate whatever comes next. Success as defined by you:We'll provide the tools and flexibility, so you can make a meaningful impact, your way. Transformative leadership: We'll give you the insights, coaching and confidence to be the leader the world needs. Diverse and inclusive culture:You'll be embraced for who you are and empowered to use your voice to help others find theirs. If you can demonstrate that you meet the criteria above, please contact us as soon as possible. The exceptional EY experience. It's yours to build. Apply now. TCCyberUKI2026 Cyber2026 EY Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories. Select how often (in days) to receive an alert: EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
Feb 14, 2026
Full time
Senior Manager, Cyber Security, Identity , TC UKI Location: London Other locations: Primary Location Only Date: 13 Jan 2026 Requisition ID: At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Cyber security and its related challenges are a rapidly growing field.As such, the opportunities for careers in cyber security are also growing. Securing an organisation against cyber threats is a business priority to enable growth and successful digital transformation and we are at the heart of many of these conversations and projects. EY is rapidly expanding its cyber security consulting practice to further support these exiting opportunities At EY, we have large scale plans to expand our alreadymarket leading Cyber Security practice and anticipate continued growth throughout the next five years. We need excellent people to join us and be part of our exciting growth strategy. At EY,you'll have the chance to build a meaningful and fulfilling career, with global scale, support, inclusive culture and technology, to become the best version of you. The team you join - EY's UK & Ireland Cyber Practice - is part of a global cyber team of 5,000+ professionals focused on developing and delivering cutting edge security transformation programmes, cyber threat management, identity and access management, security architecture, data protection and privacy, and resilience services. We are part of a wider advisory organisation that collectively comprises a $4B, and growing, global consulting practice with 18,000 professionals. Join us and build an exceptional experience for yourself, and a better working world for all. Location - London, Manchester or Scotland The opportunity EY is seeking experienced team members who can review, design and deliver Cyber Identity and Access Management (IAM) services. You will take a key position in delivering EY's cyber security and IAM capabilities. You will also take a supporting role in building out EY's IAM cyber services, working with alliance partners and advising clients on current market trends. The role will see you providing specialist advice as part of large multi-discipline EY engagement teams working on the likes of cyber transformation and migration, leading specific security engagements advising on the adoption of secure architecture blueprints, secure software engineering practices, or optimising cyber defence operations. You will work with colleagues in the UK and globally to develop new and innovative IAM security solutions and specific industry propositions that solve client problems/issues and integrate with their overall IT delivery and support strategy. You will also have opportunities to work across multiple aspects of Cyber, Technology and business solutions. Responsibilities, Qualifications, Certifications - External Your key responsibilities Your responsibilities will include but are not limited to: Managing a portfolio of IAM engagements with our clients, responsible for day to day running of the engagements including meeting quality, time and budget targets Working with prospective clients to agree, scope and plan the delivery phase of engagements Contributing to developing the market for IAM across all sectors, identifying sales opportunities and working with senior practice and market leaders in the creation of proposals and marketing material Developing team members by sharing knowledge, mentoring and coaching them and leading by example Creating thought leadership and market materials for selling and promoting EY Cyber and IAM Security offering Skills and attributes for success Be professional, quicklyestablishing personal credibility and demonstrating expertise Be a good communicator with the ability to contribute assuredly to IAM business and technical security discussions with peers Be a team player who is not only looking to enhance their own career but recognising the value of teamwork, facilitating and encouraging collaboration amongst team members, and is capable of motivating teams to maximise performance Take a practical approach to solving issues and gaining client agreement Be able to analyse complex problems and to deliver insightful, practical and sustainable solutions. Be confident and effective in recognising and managing potential issues during client assignments Structure and manage projects which meet client expectations and mitigate any risks or issues To qualify for theroleyou must have: Exposure across one or more of the following: Identity Governance, Access Management, Privileged Access Management, Consumer Identity, OT IAM Worked with one or more of the following IAM technologies: Saviynt, Clear Skye, SailPoint, CyberArk, Entra, OneIdentity, BeyondTrust, Okta, Ping, ForgeRock Project management experience on IAM solution deployments (waterfall and/or agile) IAM controls governance frameworks over processes, controls, organisation and infrastructure Ideally,you'll also have IAM business analysis experience IAM assessment, strategy and roadmap development experience Design experience for IAM solutions on client transformations Key sector experience in one or more of the following: Government & Public sector / Energy & Utilities / Retail and Consumer products / Life sciences / Telecoms, Media and Technology / Transport Experience managing and coaching others in the development and delivery of complex client solutions and/or proposition development What we look for Core consulting skills: Advanced data and evidence management, client management on remediation programmes, driving innovation and continuous improvement Technical skills: Strong technical insight, practical knowledge and specialist capability Market/Sector knowledge: Demonstrable market/sector expertise in your field Versatility: Proven ability to adapt and learn in an innovative environment Please note The successful candidate must undergo and pass checks in line with SC (Security Check) clearance standards after joining EY. These checks may include, but are not limited to, verification of identity, right to work in the UK, employment history, proof of address may be required and unspent criminal convictions. Candidates must be a UK national or have been a resident in the UK for a minimum of five years and ensure that they have not spent more than six months outside the UK. What we offer EY is committed to being an inclusive employer and we are happy to consider flexible working arrangements. We strive to achieve the right balance for our people, enabling us to deliver excellent client service whilst allowing you to build your career without sacrificing your personal priorities. While our client-facing professionals can be required to travel regularly, and at times be based at client sites, our flexible working arrangements can help you to achieve a lifestyle balance. We offer a competitive remuneration package. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well-being, insurance, savings and a wide range of discounts, offers and promotions. Plus, we offer: Continuous learning:You'll develop the mindset and skills to navigate whatever comes next. Success as defined by you:We'll provide the tools and flexibility, so you can make a meaningful impact, your way. Transformative leadership: We'll give you the insights, coaching and confidence to be the leader the world needs. Diverse and inclusive culture:You'll be embraced for who you are and empowered to use your voice to help others find theirs. If you can demonstrate that you meet the criteria above, please contact us as soon as possible. The exceptional EY experience. It's yours to build. Apply now. TCCyberUKI2026 Cyber2026 EY Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories. Select how often (in days) to receive an alert: EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
Compliance Lead London - Hybrid £75,000 - £80,000 Why this role exists Onsi operates in a highly regulated environment where trust, security, and regulatory integrity are foundational to our growth. As we scale our enterprise partnerships and insurance operations across markets, maintaining a robust, scalable compliance and risk framework is critical-not just to meet regulatory expectations, but to enable the business to move with confidence. This role exists to own enterprise risk, compliance, and legal governance across the business; ensuring we remain compliant, audit-ready, and resilient as we grow across markets. Why this role matters As Compliance Lead, you will be a senior steward of Onsi's regulatory posture. You'll provide governance, oversight, and assurance-ensuring that compliance, security and legal-related requirements are consistently met across the organisation. Reporting to the COO, you will partner closely with Engineering, Product (financial and digital), Operations, Information Security, and leadership teams while maintaining independent oversight and challenge. Your focus is not day to day delivery, but ensuring that what Onsi builds, sells, and operates stands up to regulatory scrutiny and best practice-particularly across financial service regulation, data protection, cybersecurity and operational risk. Why Onsi, why now With strategic backing from Zurich Insurance and investors behind Deliveroo, Zoopla, and Delivery Hero, Onsi is entering its next phase of growth. As we scale, we're intentionally building small, high-impact teams that own real problems end to end. Reporting line & team Reports to: COO Line management: 1 direct report (Compliance Specialist) Operating model: You set strategy, priorities, governance and assurance; your Compliance Specialist runs day to day programme execution (e.g., control testing coordination, evidence collection, documentation maintenance, audit preparation support), working cross functionally with Product, Engineering, Ops and InfoSec. Key Responsibilities Enterprise Risk and Compliance Framework Own and evolve a group wide compliance and risk framework that supports regulatory compliance, operational resilience, and scale. Define risk appetite/thresholds (where appropriate), maintain the enterprise risk register, and ensure clear escalation and decision making pathways. Regulatory Engagement & Horizon Scanning (FCA, AFM, DFSA) Act as Onsi's primary compliance interface with regulators (e.g., UK FCA, Dutch AFM and Danish FSA), as appropriate to our operating model and permissions. Lead horizon scanning, regulatory change management, and early response to new or evolving obligations- translating requirements into practical controls and delivery expectations. Policy, Controls & Governance Oversight Ensure clear, practical compliance, legal, and security policies are in place, understood, and operating effectively across the business. Establish a governance cadence (forums, reporting, attestations) that provides leadership with clear visibility of compliance posture and issues. Audit, Assurance & Due Diligence (Carriers / Lloyd's / Enterprise / Regulatory) Own readiness for audits and reviews by insurance carriers and Lloyd's, and support other assurance activity (enterprise security reviews, regulatory reviews, customer due diligence). Set the standard for documentation quality and evidence expectations; ensure controls are demonstrably operating and issues are remediated with pace and rigour. Oversee third party and partner risk governance from a compliance, cyber, and legal risk perspective (including outsourced service considerations). Insurance Operations Governance Oversee compliance standards, governance protocols, and regulatory obligations relating to insurance operations and partners. Ensure partner expectations and delegated requirements (where applicable) are met and evidenced. Delivery Compliance & KYC Oversight Provide oversight of KYC, onboarding, and delivery side compliance requirements, ensuring proportionate controls without slowing execution. Ensure ownership is clear across teams and that compliance requirements are embedded early in delivery, not bolted on at the end. GDPR & Data Protection Governance Own oversight of GDPR compliance, ensuring appropriate governance around privacy by design, DPIAs/assessments where required, incident readiness, and third party processing risk. Partner with Product, Engineering, and InfoSec to ensure privacy and security controls remain effective and auditable. ISO 27001 Oversight & Certification Maintenance Provide senior ownership of ISO 27001 certification maintenance and audit readiness, ensuring governance, internal assurance, management review inputs, and corrective actions are operating effectively. Work closely with InfoSec and Engineering while maintaining independence of oversight and assurance. Team Leadership & Capability Building Line manage and develop the Compliance Specialist, setting priorities, coaching on execution, and ensuring high quality programme outputs. Build scalable ways of working-tooling, templates, playbooks, and reporting-that reduce friction and improve consistency over time. Compliance Training & Culture Set direction for compliance training and promote a practical, values led compliance culture across Onsi. Enable teams to understand requirements and make good decisions without creating bottlenecks. The successful candidate is expected to follow all Onsi security policies and procedures. What you bring A recognised professional qualification in compliance, data protection, risk, or security governance (or equivalent senior experience delivering these outcomes in practice). Senior experience in compliance, risk, and/or legal governance within regulated environments (financial services, insurance, fintech, or adjacent). Strong working knowledge of regulatory, legal, cybersecurity, and data protection frameworks, including UK GDPR, ISO 27001, Cyber Essentials, and operational resilience expectations. Experience designing and operating regulatory and legal risk frameworks, including horizon scanning and regulatory change management. Credible experience preparing organisations for audits, regulatory reviews, enterprise due diligence, and legal scrutiny-and engaging confidently with regulators, insurers, auditors, and external stakeholders. Experience overseeing third party and partner risk, including compliance, cyber, and legal risk assessments. Strong judgement and communication skills, with the confidence to challenge constructively and escalat when needed, while staying pragmatic and delivery oriented. Is This Role a Fit for You? This role is a great match if you thrive on ownership, embrace ambiguity as a chance to grow, and celebrate small wins while keeping the big picture in sight. Most importantly, you believe there's no I in Onsi - we always win as a team. It's probably not for you if you prefer rigid structure, narrowly defined roles, or working fully remote. We're hands on generalists who adapt quickly and learn best by collaborating in person. What will you get in return? Compensation & Financial Benefits Pension contributions (UK) with matching up to 7% Access to Onsi ODP & Marketplace: Get hands on with our own product including early wage access and savings plus exclusive offers through Onsi Marketplace. Cycle Schemes: CycleSaver subscription: save up to 47% on shared cycles (Lime, Forest, Beryl, Dott, Voi, Santander) with flexible salary sacrifice Cycle to Work scheme buy a bike or e bike via salary sacrifice and save on tax Time Off & Leave ️ 25 days annual leave + UK bank holidays (rising to 35 days with tenure) Birthday day off Up to 3 extra days for weddings or moving house ️ 1-month paid sabbatical after 5 years of service Enhanced parental leave (enhanced pay + staggered return) Family leave: fertility treatment, appointments & growing your family Growth & Learning Personal development budget: £500 per year, increasing to £1,500 after 3 years to invest in your growth (courses, books, coaching) Learning & Development Days: 12 dedicated days each year for professional growth, training, or upskilling Knowledge sharing culture: Regular Lunch & Learns, Monthly Speaker Series, cross team workshops, and company offsites to expand your perspective and keep learning ️ Health & Wellbeing ️ PT-Link Fitness App: Personalised training plans, nutrition guidance, and habit coaching at your fingertips 24/7 GP access: Virtual doctor appointments anytime, anywhere Mental health support: Counselling, resources, and wellbeing check ins to help you Culture & Perks Hybrid working: Choose flexibility - split your time between home and our London or Amsterdam or Cape Town offices Work from abroad: up to 20 days per year Social culture: Regular team lunches, coffee catch ups, after work drinks . click apply for full job details
Feb 11, 2026
Full time
Compliance Lead London - Hybrid £75,000 - £80,000 Why this role exists Onsi operates in a highly regulated environment where trust, security, and regulatory integrity are foundational to our growth. As we scale our enterprise partnerships and insurance operations across markets, maintaining a robust, scalable compliance and risk framework is critical-not just to meet regulatory expectations, but to enable the business to move with confidence. This role exists to own enterprise risk, compliance, and legal governance across the business; ensuring we remain compliant, audit-ready, and resilient as we grow across markets. Why this role matters As Compliance Lead, you will be a senior steward of Onsi's regulatory posture. You'll provide governance, oversight, and assurance-ensuring that compliance, security and legal-related requirements are consistently met across the organisation. Reporting to the COO, you will partner closely with Engineering, Product (financial and digital), Operations, Information Security, and leadership teams while maintaining independent oversight and challenge. Your focus is not day to day delivery, but ensuring that what Onsi builds, sells, and operates stands up to regulatory scrutiny and best practice-particularly across financial service regulation, data protection, cybersecurity and operational risk. Why Onsi, why now With strategic backing from Zurich Insurance and investors behind Deliveroo, Zoopla, and Delivery Hero, Onsi is entering its next phase of growth. As we scale, we're intentionally building small, high-impact teams that own real problems end to end. Reporting line & team Reports to: COO Line management: 1 direct report (Compliance Specialist) Operating model: You set strategy, priorities, governance and assurance; your Compliance Specialist runs day to day programme execution (e.g., control testing coordination, evidence collection, documentation maintenance, audit preparation support), working cross functionally with Product, Engineering, Ops and InfoSec. Key Responsibilities Enterprise Risk and Compliance Framework Own and evolve a group wide compliance and risk framework that supports regulatory compliance, operational resilience, and scale. Define risk appetite/thresholds (where appropriate), maintain the enterprise risk register, and ensure clear escalation and decision making pathways. Regulatory Engagement & Horizon Scanning (FCA, AFM, DFSA) Act as Onsi's primary compliance interface with regulators (e.g., UK FCA, Dutch AFM and Danish FSA), as appropriate to our operating model and permissions. Lead horizon scanning, regulatory change management, and early response to new or evolving obligations- translating requirements into practical controls and delivery expectations. Policy, Controls & Governance Oversight Ensure clear, practical compliance, legal, and security policies are in place, understood, and operating effectively across the business. Establish a governance cadence (forums, reporting, attestations) that provides leadership with clear visibility of compliance posture and issues. Audit, Assurance & Due Diligence (Carriers / Lloyd's / Enterprise / Regulatory) Own readiness for audits and reviews by insurance carriers and Lloyd's, and support other assurance activity (enterprise security reviews, regulatory reviews, customer due diligence). Set the standard for documentation quality and evidence expectations; ensure controls are demonstrably operating and issues are remediated with pace and rigour. Oversee third party and partner risk governance from a compliance, cyber, and legal risk perspective (including outsourced service considerations). Insurance Operations Governance Oversee compliance standards, governance protocols, and regulatory obligations relating to insurance operations and partners. Ensure partner expectations and delegated requirements (where applicable) are met and evidenced. Delivery Compliance & KYC Oversight Provide oversight of KYC, onboarding, and delivery side compliance requirements, ensuring proportionate controls without slowing execution. Ensure ownership is clear across teams and that compliance requirements are embedded early in delivery, not bolted on at the end. GDPR & Data Protection Governance Own oversight of GDPR compliance, ensuring appropriate governance around privacy by design, DPIAs/assessments where required, incident readiness, and third party processing risk. Partner with Product, Engineering, and InfoSec to ensure privacy and security controls remain effective and auditable. ISO 27001 Oversight & Certification Maintenance Provide senior ownership of ISO 27001 certification maintenance and audit readiness, ensuring governance, internal assurance, management review inputs, and corrective actions are operating effectively. Work closely with InfoSec and Engineering while maintaining independence of oversight and assurance. Team Leadership & Capability Building Line manage and develop the Compliance Specialist, setting priorities, coaching on execution, and ensuring high quality programme outputs. Build scalable ways of working-tooling, templates, playbooks, and reporting-that reduce friction and improve consistency over time. Compliance Training & Culture Set direction for compliance training and promote a practical, values led compliance culture across Onsi. Enable teams to understand requirements and make good decisions without creating bottlenecks. The successful candidate is expected to follow all Onsi security policies and procedures. What you bring A recognised professional qualification in compliance, data protection, risk, or security governance (or equivalent senior experience delivering these outcomes in practice). Senior experience in compliance, risk, and/or legal governance within regulated environments (financial services, insurance, fintech, or adjacent). Strong working knowledge of regulatory, legal, cybersecurity, and data protection frameworks, including UK GDPR, ISO 27001, Cyber Essentials, and operational resilience expectations. Experience designing and operating regulatory and legal risk frameworks, including horizon scanning and regulatory change management. Credible experience preparing organisations for audits, regulatory reviews, enterprise due diligence, and legal scrutiny-and engaging confidently with regulators, insurers, auditors, and external stakeholders. Experience overseeing third party and partner risk, including compliance, cyber, and legal risk assessments. Strong judgement and communication skills, with the confidence to challenge constructively and escalat when needed, while staying pragmatic and delivery oriented. Is This Role a Fit for You? This role is a great match if you thrive on ownership, embrace ambiguity as a chance to grow, and celebrate small wins while keeping the big picture in sight. Most importantly, you believe there's no I in Onsi - we always win as a team. It's probably not for you if you prefer rigid structure, narrowly defined roles, or working fully remote. We're hands on generalists who adapt quickly and learn best by collaborating in person. What will you get in return? Compensation & Financial Benefits Pension contributions (UK) with matching up to 7% Access to Onsi ODP & Marketplace: Get hands on with our own product including early wage access and savings plus exclusive offers through Onsi Marketplace. Cycle Schemes: CycleSaver subscription: save up to 47% on shared cycles (Lime, Forest, Beryl, Dott, Voi, Santander) with flexible salary sacrifice Cycle to Work scheme buy a bike or e bike via salary sacrifice and save on tax Time Off & Leave ️ 25 days annual leave + UK bank holidays (rising to 35 days with tenure) Birthday day off Up to 3 extra days for weddings or moving house ️ 1-month paid sabbatical after 5 years of service Enhanced parental leave (enhanced pay + staggered return) Family leave: fertility treatment, appointments & growing your family Growth & Learning Personal development budget: £500 per year, increasing to £1,500 after 3 years to invest in your growth (courses, books, coaching) Learning & Development Days: 12 dedicated days each year for professional growth, training, or upskilling Knowledge sharing culture: Regular Lunch & Learns, Monthly Speaker Series, cross team workshops, and company offsites to expand your perspective and keep learning ️ Health & Wellbeing ️ PT-Link Fitness App: Personalised training plans, nutrition guidance, and habit coaching at your fingertips 24/7 GP access: Virtual doctor appointments anytime, anywhere Mental health support: Counselling, resources, and wellbeing check ins to help you Culture & Perks Hybrid working: Choose flexibility - split your time between home and our London or Amsterdam or Cape Town offices Work from abroad: up to 20 days per year Social culture: Regular team lunches, coffee catch ups, after work drinks . click apply for full job details
Hi, we're PEXA! We know you'll Google us before applying, so let's keep this brief. PEXA revolutionised the way that property is settled in Australia, turning a paper-based process into a digital one. Our solution is a world-first, with over 500 people across Australia and an expanding international team, we're helping 20,000+ families into their homes each week. We're passionate about solving problems for our customers - always striving to set the standard for how property is bought and sold. Being awarded as one of the best places to work in Australia is a recognition of our culture and commitment to innovation, customers and our community. We're growing fast, that is where you come in. We believe our success in Australia is worth sharing and that our proven technology will advance how the UK buys and sells homes. Establishing ourselves within the UK in late 2020, we are committed to collaborating with lawyers, conveyancers, lenders, government and the property industry, to set the new standard for both remortgages and buying and selling property. We are seeking a commercially minded, second line Risk Partner to join the UK group risk function where technology risk management plays a critical role in safeguarding the group. This is a hands on role with responsibility for advice, overseeing regulatory change and monitoring and embedding a strong risk & compliance culture across these functional lines. This is a second line risk partner role that oversees technology and cyber risks - it does not design or operate cyber security controls. This role will work in close partnership with senior leadership teams across Product, IT, Cyber, Information Security and Operational Resilience with the IT and Product functions. You will provide independent advice, oversight, monitoring and constructive challenge to these functions on their management of technology and cyber security risks. The role acts as a specialist advisor to ensure risk remain with UK defined risk appetite. The role holder will be expected to take end to end ownership across risk advisory & guidance, risk oversight and support with regulatory returns (including REP0018 submission on IT Security & Operational Risk). Key Accountabilities Second Line Oversight: Provide oversight, review and challenge of the cyber risk profile and cyber control environment. Highlight control gaps and collaborate with control owners on remediation plans. Review & assess changes to technology platform and products that impact UK group risks & risk profile. Contribute towards the development and enhancement of technology risk framework and ensure alignment with evolving regulatory expectations. Business Partnering & Advisory: Be the subject matter expert to IT and Product functional leaders, providing guidance on risk identification, controls improvements and risk mitigation for new product features, projects, contracts or business change. Proactive risk engagement and early intervention by engaging early during solution design, procurement etc for IT and product changes to assess risks. Risk Framework Embedding: Drive the adoption of the UK Risk Framework, ensuring processes align with standards. Risk & Control Self Assessments (RCSAs): Reporting & Governance: Controls, Compliance & Regulation: Incident & Issue Management: Support the resolution of risk events, perform root cause analysis and ensure learnings are translated into actionable improvements. Monitoring & Assurance: Track Key Risk Indicators (KRIs) to identify emerging trends. Conduct in depth reviews of the Product, IT & Cyber function, their adoption & implementation of technology and reporting to risk matters to oversight committees. Perform risk based deep dives to identify and understand product, technology and cyber security related risk drivers and work in partnership with the first line function to identify key programmes/tasks to address these. This is expected across core technology risk domains of resilience and continuity, cloud and third party, data governance and protection, generative AI and broader AI adoption, technology delivery and change. Design, recommend and complete assurance programmes and controls testing, feeding results into risk assessments and reporting. Skills & Experience At least 5 years' experience within second line risk management with an EMI, payments or fintech. Prior experience in technology risk management and compliance within regulated environment. Strong understanding of technology, cyber risk, resilience, IT controls & governance frameworks. Familiarity with frameworks and standards such as SOC 2 and ISO 27001. Deep understanding of risk management principles (eg ISO 31000, COSO). Strong working knowledge of FCA regulation for EMIs and UK regulatory landscape, including ICO. Practical, commercial approach to risk management. Ability to manage complex analysis, interpret regulatory standards and provide high quality oversight. Demonstrable ability to integrate risk management and control frameworks with sharp commercial insight, enabling responsible and scalable business growth. Excellent analytical & problem solving skills, with a track record of driving root cause analysis and effective solutions. Excellent written and verbal communication skills with the ability to influence and challenge constructively. Strong organisational skills & experience working in a fast paced, dynamic environment with tight deadlines. Strong analysis skills to translate complex risk issues into actionable business insights. Professional qualification in Risk Management desirable. £90,000 - £100,000 a year + Bonus + Benefits Why become a PEXArian? Great question! Being a PEXArian is so much more than just a job. We're a passionate, motivated and unashamedly enthusiastic bunch at PEXA - we love what we do and we're proud to admit it! Creating brilliant experiences for our members and their clients wouldn't be possible without ensuring we deliver an exceptional employee experience. Your growth We encourage you to hit your personal and professional learning and development goals with our tailored programs and tools. Your wellness We care about your holistic wellbeing. Your work/life blend We know that work is just one aspect of your life - we want to help you create your ideal work/life blend, rather than squeezing in life around work. Sounds like you? We at PEXA are ready so if this role sounds like you apply today. To be conducted as part of post offer employment checks: The personal information we have collected from you will be shared with Cifas who will use it to prevent fraud, other unlawful or dishonest conduct, malpractice, and other seriously improper conduct. If any of these are detected, you could be refused certain services or employment. Your personal information will also be used to verify your identity. Further details of how your information will be used by us and Cifas, and your data protection rights, can be found at GDPR Compliance Digital Completion UK Limited (trading name "PEXA"), Optima Legal Services Limited (trading name "Optima Legal") and Smoove Limited(a holding company which comprises of the following wholly owned trading Subsidiary companies: United Legal Services Limited, United Home Services Limited, Legal-Eye Limited, and Amity Law Limited) are all owned directly by DigCom UK Holdings Limited, which is a wholly owned Subsidiary of PEXA Group Limited in Australia (ACN ; ASX: PXA) (referred tocollectively as"PEXA Group"). When we process your applicant personal data for recruitment purposes, we do so as a controller. If as part of the recruitment process, we share your personal data with another company within the PEXA Group, that company may process your personal data as either an independent controller or, in certain circumstances, a joint controller. By applying for this role, you consent to us processing your personal data in accordance with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, and further information can be found in our privacy notice.
Feb 11, 2026
Full time
Hi, we're PEXA! We know you'll Google us before applying, so let's keep this brief. PEXA revolutionised the way that property is settled in Australia, turning a paper-based process into a digital one. Our solution is a world-first, with over 500 people across Australia and an expanding international team, we're helping 20,000+ families into their homes each week. We're passionate about solving problems for our customers - always striving to set the standard for how property is bought and sold. Being awarded as one of the best places to work in Australia is a recognition of our culture and commitment to innovation, customers and our community. We're growing fast, that is where you come in. We believe our success in Australia is worth sharing and that our proven technology will advance how the UK buys and sells homes. Establishing ourselves within the UK in late 2020, we are committed to collaborating with lawyers, conveyancers, lenders, government and the property industry, to set the new standard for both remortgages and buying and selling property. We are seeking a commercially minded, second line Risk Partner to join the UK group risk function where technology risk management plays a critical role in safeguarding the group. This is a hands on role with responsibility for advice, overseeing regulatory change and monitoring and embedding a strong risk & compliance culture across these functional lines. This is a second line risk partner role that oversees technology and cyber risks - it does not design or operate cyber security controls. This role will work in close partnership with senior leadership teams across Product, IT, Cyber, Information Security and Operational Resilience with the IT and Product functions. You will provide independent advice, oversight, monitoring and constructive challenge to these functions on their management of technology and cyber security risks. The role acts as a specialist advisor to ensure risk remain with UK defined risk appetite. The role holder will be expected to take end to end ownership across risk advisory & guidance, risk oversight and support with regulatory returns (including REP0018 submission on IT Security & Operational Risk). Key Accountabilities Second Line Oversight: Provide oversight, review and challenge of the cyber risk profile and cyber control environment. Highlight control gaps and collaborate with control owners on remediation plans. Review & assess changes to technology platform and products that impact UK group risks & risk profile. Contribute towards the development and enhancement of technology risk framework and ensure alignment with evolving regulatory expectations. Business Partnering & Advisory: Be the subject matter expert to IT and Product functional leaders, providing guidance on risk identification, controls improvements and risk mitigation for new product features, projects, contracts or business change. Proactive risk engagement and early intervention by engaging early during solution design, procurement etc for IT and product changes to assess risks. Risk Framework Embedding: Drive the adoption of the UK Risk Framework, ensuring processes align with standards. Risk & Control Self Assessments (RCSAs): Reporting & Governance: Controls, Compliance & Regulation: Incident & Issue Management: Support the resolution of risk events, perform root cause analysis and ensure learnings are translated into actionable improvements. Monitoring & Assurance: Track Key Risk Indicators (KRIs) to identify emerging trends. Conduct in depth reviews of the Product, IT & Cyber function, their adoption & implementation of technology and reporting to risk matters to oversight committees. Perform risk based deep dives to identify and understand product, technology and cyber security related risk drivers and work in partnership with the first line function to identify key programmes/tasks to address these. This is expected across core technology risk domains of resilience and continuity, cloud and third party, data governance and protection, generative AI and broader AI adoption, technology delivery and change. Design, recommend and complete assurance programmes and controls testing, feeding results into risk assessments and reporting. Skills & Experience At least 5 years' experience within second line risk management with an EMI, payments or fintech. Prior experience in technology risk management and compliance within regulated environment. Strong understanding of technology, cyber risk, resilience, IT controls & governance frameworks. Familiarity with frameworks and standards such as SOC 2 and ISO 27001. Deep understanding of risk management principles (eg ISO 31000, COSO). Strong working knowledge of FCA regulation for EMIs and UK regulatory landscape, including ICO. Practical, commercial approach to risk management. Ability to manage complex analysis, interpret regulatory standards and provide high quality oversight. Demonstrable ability to integrate risk management and control frameworks with sharp commercial insight, enabling responsible and scalable business growth. Excellent analytical & problem solving skills, with a track record of driving root cause analysis and effective solutions. Excellent written and verbal communication skills with the ability to influence and challenge constructively. Strong organisational skills & experience working in a fast paced, dynamic environment with tight deadlines. Strong analysis skills to translate complex risk issues into actionable business insights. Professional qualification in Risk Management desirable. £90,000 - £100,000 a year + Bonus + Benefits Why become a PEXArian? Great question! Being a PEXArian is so much more than just a job. We're a passionate, motivated and unashamedly enthusiastic bunch at PEXA - we love what we do and we're proud to admit it! Creating brilliant experiences for our members and their clients wouldn't be possible without ensuring we deliver an exceptional employee experience. Your growth We encourage you to hit your personal and professional learning and development goals with our tailored programs and tools. Your wellness We care about your holistic wellbeing. Your work/life blend We know that work is just one aspect of your life - we want to help you create your ideal work/life blend, rather than squeezing in life around work. Sounds like you? We at PEXA are ready so if this role sounds like you apply today. To be conducted as part of post offer employment checks: The personal information we have collected from you will be shared with Cifas who will use it to prevent fraud, other unlawful or dishonest conduct, malpractice, and other seriously improper conduct. If any of these are detected, you could be refused certain services or employment. Your personal information will also be used to verify your identity. Further details of how your information will be used by us and Cifas, and your data protection rights, can be found at GDPR Compliance Digital Completion UK Limited (trading name "PEXA"), Optima Legal Services Limited (trading name "Optima Legal") and Smoove Limited(a holding company which comprises of the following wholly owned trading Subsidiary companies: United Legal Services Limited, United Home Services Limited, Legal-Eye Limited, and Amity Law Limited) are all owned directly by DigCom UK Holdings Limited, which is a wholly owned Subsidiary of PEXA Group Limited in Australia (ACN ; ASX: PXA) (referred tocollectively as"PEXA Group"). When we process your applicant personal data for recruitment purposes, we do so as a controller. If as part of the recruitment process, we share your personal data with another company within the PEXA Group, that company may process your personal data as either an independent controller or, in certain circumstances, a joint controller. By applying for this role, you consent to us processing your personal data in accordance with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, and further information can be found in our privacy notice.
Lead Cyber Security Solution Architect - Banking - London - Up to 120,000 Basic Salary + Hybrid Working Overview We are seeking an experienced Lead Cyber Security Solution Architect to lead a team of Governance, Risk, and Control (GRC) specialists. This team is responsible for conducting Secure-by-Design assessments on technology projects, ensuring compliance with IT security policies and requirements. Role and Responsibilities Lead and manage the Secure-by-Design team across multiple business entities. Oversee security reviews for technology projects prior to implementation. Define KPIs for the team and monitor performance. Engage with business and technology stakeholders to assess technical and non-technical controls. Review reports and validate evidence of control effectiveness. Develop and implement testing strategies for IT security controls. Identify and document risks, gaps, findings, and recommend actions. Ensure timely completion of security assessments and manage team workload effectively. Essential Skills & Experience Proven ability to manage complex tasks with broad scope and ambiguity. Strong background in cybersecurity assurance, policies, and standards. Expertise across IT security domains: Governance, IAM, Risk Management, Security Testing, Incident Management, Vulnerability Management. Experience in senior stakeholder engagement and management reporting. Ability to coach and mentor team members. Deep understanding of IT security frameworks (SOX, FFIEC, ISO27001, NIST, PCI-DSS, Cloud Security Alliance). Strong managerial and leadership skills. Hands-on experience as an IT auditor, security auditor, or GRC analyst. Excellent planning, prioritization, and documentation skills. Broad technical knowledge of IT systems (OS, databases, firewalls, SIEM, DLP). Cloud Platforms: AWS and Azure. AI Knowledge: Understanding of AI principles and security implications. Solutions / Technical Network Architecture: Ability to design secure technical solutions and network architectures. Controls Experience: Strong background in implementing and assessing security controls. Splunk Knowledge: Familiarity with SIEM tools and log analysis. CyberArk: Experience with privileged access management solutions. Package Salary: Up to 120,000 Up to 20% Bonus Hybrid, with travel to London Career Development Opportunities Benefits: Pension scheme, professional training, paid holiday Lead Cyber Security Solution Architect - Banking - London - Up to 120,000 Basic Salary + Hybrid Working
Jan 21, 2026
Full time
Lead Cyber Security Solution Architect - Banking - London - Up to 120,000 Basic Salary + Hybrid Working Overview We are seeking an experienced Lead Cyber Security Solution Architect to lead a team of Governance, Risk, and Control (GRC) specialists. This team is responsible for conducting Secure-by-Design assessments on technology projects, ensuring compliance with IT security policies and requirements. Role and Responsibilities Lead and manage the Secure-by-Design team across multiple business entities. Oversee security reviews for technology projects prior to implementation. Define KPIs for the team and monitor performance. Engage with business and technology stakeholders to assess technical and non-technical controls. Review reports and validate evidence of control effectiveness. Develop and implement testing strategies for IT security controls. Identify and document risks, gaps, findings, and recommend actions. Ensure timely completion of security assessments and manage team workload effectively. Essential Skills & Experience Proven ability to manage complex tasks with broad scope and ambiguity. Strong background in cybersecurity assurance, policies, and standards. Expertise across IT security domains: Governance, IAM, Risk Management, Security Testing, Incident Management, Vulnerability Management. Experience in senior stakeholder engagement and management reporting. Ability to coach and mentor team members. Deep understanding of IT security frameworks (SOX, FFIEC, ISO27001, NIST, PCI-DSS, Cloud Security Alliance). Strong managerial and leadership skills. Hands-on experience as an IT auditor, security auditor, or GRC analyst. Excellent planning, prioritization, and documentation skills. Broad technical knowledge of IT systems (OS, databases, firewalls, SIEM, DLP). Cloud Platforms: AWS and Azure. AI Knowledge: Understanding of AI principles and security implications. Solutions / Technical Network Architecture: Ability to design secure technical solutions and network architectures. Controls Experience: Strong background in implementing and assessing security controls. Splunk Knowledge: Familiarity with SIEM tools and log analysis. CyberArk: Experience with privileged access management solutions. Package Salary: Up to 120,000 Up to 20% Bonus Hybrid, with travel to London Career Development Opportunities Benefits: Pension scheme, professional training, paid holiday Lead Cyber Security Solution Architect - Banking - London - Up to 120,000 Basic Salary + Hybrid Working