• Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
  • Sign in
  • Sign up
  • Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

58 jobs found

Email me jobs like this
Refine Search
Current Search
it risk governance cyber analyst
South West Water
Cyber Security GRC Analyst
South West Water Exeter, Devon
Powered by Water, Driven by Purpose South West Water keeps the South West flowing with safe, reliable drinking water and wastewater services across some of the UK's most stunning landscapes. We're proud to be part of Pennon Group, a leader in the UK water sector, working towards a greener future. Our goals? As well as lowering our carbon footprint, we're working with partners to plant 300,000 trees, restore peatlands and supporting farmers and landowners to improve water quality and wildlife. Whether you're starting out or seeking a new challenge, our scale and ambition create opportunities for you to shape your own career. Ready to make a splash? Join our team today. Help protect critical services through effective cyber security governance Are you passionate about cyber security, data governance and compliance? Do you enjoy translating complex security requirements into practical controls that make a real difference? We're looking for a Cyber Security GRC Analyst to join our growing Cyber Security team. In this role, you'll play a key part in strengthening our cyber security posture through governance, risk management and compliance activities, while helping to ensure our information assets remain protected. A significant focus of the role will be the administration and continual improvement of Microsoft Purview, ensuring effective data protection, information governance, data classification and compliance capabilities are embedded across the organisation. Working closely with stakeholders across IT, Legal, Audit, Procurement and the wider business, you'll help shape security practices, drive compliance initiatives and support a positive security culture. What you'll be doing: As our Cyber Security GRC Analyst, you will: Administer, maintain and continuously improve Microsoft Purview capabilities, including: Data Loss Prevention (DLP) Information Protection Data Lifecycle Management Insider Risk Management Communication Compliance eDiscovery Compliance Manager Support the implementation and adoption of data classification and sensitivity labelling. Monitor security and compliance alerts, investigate findings and coordinate remediation activities. Develop and maintain security policies, controls and standards. Produce management reporting, dashboards and compliance metrics. Plan, conduct and document internal ISO 27001 audits. Support third-party risk management and supplier security assurance activities. Help maintain compliance with frameworks and regulations such as ISO 27001, NIS Regulations and Cyber Essentials. Support information security awareness initiatives and promote a strong security culture. Assist in security incident investigations and remediation activities. Work with business stakeholders to improve information governance practices and data ownership accountability. What we're looking for: Experience administering or supporting Microsoft Purview and Microsoft 365 security and compliance solutions. Knowledge of Microsoft Purview capabilities, including DLP, Information Protection, Sensitivity Labels, Insider Risk Management, eDiscovery and Compliance Manager. Experience supporting data governance, information protection and compliance activities within a Microsoft 365 environment. An understanding of cyber security risk management, governance and control frameworks. Knowledge of information security standards such as ISO 27001, NIS Regulations and Cyber Essentials. Experience producing reports, managing stakeholders and supporting audit activities. Strong communication skills with the ability to influence and build relationships across diverse teams. Essential 5 GCSEs (or equivalent), including Maths and English. Educated to degree level or able to demonstrate equivalent professional experience. Desirable Hands-on experience of Microsoft Purview administration and optimisation. Experience within information security, governance, risk or compliance functions. Knowledge of recognised security frameworks such as ISO 27001, NIST or Cyber Essentials. Ability to successfully obtain UK Government Security Clearance (SC). Why join us? This is an excellent opportunity to develop your cyber security governance and compliance career within a supportive environment. You'll gain exposure to enterprise-scale Microsoft security technologies, contribute to critical compliance programmes and play a meaningful role in protecting services, systems and data that matter. Generous holiday allowance plus bank holidays A discretionary Bonus Competitive Contributory Pension Share-save Scheme Various health benefits Wellbeing support programmes A range of Group Discounts Cycle to Work Scheme Closing Date: 1st September 2026 We may close this vacancy early if we receive a high volume of applications. We encourage you to apply as soon as possible. Please note that the successful candidate will be subject to a mandatory DBS check as part of the onboarding process. Be yourself, we like it that way. Together, we will build a culture of belonging, where inclusion is instinctive. Diversity is our strength and a reflection of our communities. We care, we value everyone, we celebrate uniqueness. Our core values, which are essential to our success, are: Be Rock Solid - Build trust and be trusted. Be the one we all look to and can depend on. Be You - We want you to bring your best everyday. Be yourself and make your mark in your individual way. Be the Future - Embrace change. Drive Progress. Own the challenge.
Aug 24, 2026
Full time
Powered by Water, Driven by Purpose South West Water keeps the South West flowing with safe, reliable drinking water and wastewater services across some of the UK's most stunning landscapes. We're proud to be part of Pennon Group, a leader in the UK water sector, working towards a greener future. Our goals? As well as lowering our carbon footprint, we're working with partners to plant 300,000 trees, restore peatlands and supporting farmers and landowners to improve water quality and wildlife. Whether you're starting out or seeking a new challenge, our scale and ambition create opportunities for you to shape your own career. Ready to make a splash? Join our team today. Help protect critical services through effective cyber security governance Are you passionate about cyber security, data governance and compliance? Do you enjoy translating complex security requirements into practical controls that make a real difference? We're looking for a Cyber Security GRC Analyst to join our growing Cyber Security team. In this role, you'll play a key part in strengthening our cyber security posture through governance, risk management and compliance activities, while helping to ensure our information assets remain protected. A significant focus of the role will be the administration and continual improvement of Microsoft Purview, ensuring effective data protection, information governance, data classification and compliance capabilities are embedded across the organisation. Working closely with stakeholders across IT, Legal, Audit, Procurement and the wider business, you'll help shape security practices, drive compliance initiatives and support a positive security culture. What you'll be doing: As our Cyber Security GRC Analyst, you will: Administer, maintain and continuously improve Microsoft Purview capabilities, including: Data Loss Prevention (DLP) Information Protection Data Lifecycle Management Insider Risk Management Communication Compliance eDiscovery Compliance Manager Support the implementation and adoption of data classification and sensitivity labelling. Monitor security and compliance alerts, investigate findings and coordinate remediation activities. Develop and maintain security policies, controls and standards. Produce management reporting, dashboards and compliance metrics. Plan, conduct and document internal ISO 27001 audits. Support third-party risk management and supplier security assurance activities. Help maintain compliance with frameworks and regulations such as ISO 27001, NIS Regulations and Cyber Essentials. Support information security awareness initiatives and promote a strong security culture. Assist in security incident investigations and remediation activities. Work with business stakeholders to improve information governance practices and data ownership accountability. What we're looking for: Experience administering or supporting Microsoft Purview and Microsoft 365 security and compliance solutions. Knowledge of Microsoft Purview capabilities, including DLP, Information Protection, Sensitivity Labels, Insider Risk Management, eDiscovery and Compliance Manager. Experience supporting data governance, information protection and compliance activities within a Microsoft 365 environment. An understanding of cyber security risk management, governance and control frameworks. Knowledge of information security standards such as ISO 27001, NIS Regulations and Cyber Essentials. Experience producing reports, managing stakeholders and supporting audit activities. Strong communication skills with the ability to influence and build relationships across diverse teams. Essential 5 GCSEs (or equivalent), including Maths and English. Educated to degree level or able to demonstrate equivalent professional experience. Desirable Hands-on experience of Microsoft Purview administration and optimisation. Experience within information security, governance, risk or compliance functions. Knowledge of recognised security frameworks such as ISO 27001, NIST or Cyber Essentials. Ability to successfully obtain UK Government Security Clearance (SC). Why join us? This is an excellent opportunity to develop your cyber security governance and compliance career within a supportive environment. You'll gain exposure to enterprise-scale Microsoft security technologies, contribute to critical compliance programmes and play a meaningful role in protecting services, systems and data that matter. Generous holiday allowance plus bank holidays A discretionary Bonus Competitive Contributory Pension Share-save Scheme Various health benefits Wellbeing support programmes A range of Group Discounts Cycle to Work Scheme Closing Date: 1st September 2026 We may close this vacancy early if we receive a high volume of applications. We encourage you to apply as soon as possible. Please note that the successful candidate will be subject to a mandatory DBS check as part of the onboarding process. Be yourself, we like it that way. Together, we will build a culture of belonging, where inclusion is instinctive. Diversity is our strength and a reflection of our communities. We care, we value everyone, we celebrate uniqueness. Our core values, which are essential to our success, are: Be Rock Solid - Build trust and be trusted. Be the one we all look to and can depend on. Be You - We want you to bring your best everyday. Be yourself and make your mark in your individual way. Be the Future - Embrace change. Drive Progress. Own the challenge.
Salt
Senior Security Analyst - Product-Based Risk Assessment (PBRA)
Salt
Senior Cyber Security Risk & Assurance Consultant - Product Risk (PBRA) (CONTRACTOR) - London Duration: 1 year contract Hybrid Working - 8 days onsite per month - the rest is remote working About the Team The Product-Based Risk Assessment (PBRA) service conducts recurring security assessments of applications, services, and technologies to identify emerging threats, evaluate control effectiveness, and drive remediation that strengthens The clients cyber resilience. The team supports business and technology stakeholders by assessing cyber security risks and ensuring alignment with The Banks security standards and risk appetite. Key Accountabilities Product-Based Risk Assessments Lead end-to-end Product-Based Risk Assessments (PBRA) for critical applications, platforms, and technology services. Analyse application architectures, business processes, information flows, and supporting infrastructure. Identify and assess cyber threats, vulnerabilities, control weaknesses, and potential business impacts. Evaluate the design and effectiveness of security controls using clients security frameworks and standards. Assess residual risks and propose actionable remediation plans. Security Risk Analysis Perform security risk assessments using recognised methodologies and industry frameworks. Evaluate risks related to infrastructure, software, cloud services, networks, third-party integrations, and information assets. Contribute to threat modelling and attack surface analysis activities. Support technology-focused assessments such as cloud, AI, and emerging technology evaluations. Stakeholder Engagement Act as the primary security assessment contact for business and IT stakeholders. Facilitate workshops, interviews, and assessment review sessions. Challenge assumptions and provide expert security guidance to delivery and operations teams. Build trusted relationships across CISO, CTO, Architecture, Risk Management, and Engineering teams. Reporting & Governance Produce high-quality assessment reports, risk summaries, and executive-level communications. Present findings and recommendations to senior management and governance bodies. Track remediation plans and risk treatment activities through closure. Support internal and external audit activities as required. Continuous Improvement Contribute to the evolution of the PBRA service, methodologies, tools, and operating model. Help drive the transition toward data-enabled and automated security assessment capabilities. Identify opportunities to improve efficiency, consistency, and risk coverage across assessments. Support knowledge sharing and mentoring of junior analysts. Required Skills & Experience Technical Skills Strong understanding of cybersecurity principles, controls, and risk management practices. Knowledge of application security, cloud security, infrastructure security, and network security. Experience conducting security assessments, threat modelling, or risk analyses. Familiarity with industry frameworks and standards such as: NIST Cyber Security Framework ISO 27001 CIS Controls Secure Controls Framework (SCF) DORA ANSSI EBIOS RM OWASP Professional Experience Minimum 7 years of experience in Information Security, Cyber Risk, Security Assurance, or Security Architecture. Experience leading complex security assessments across large technology environments. Experience working with senior business and technology stakeholders. Strong report-writing and presentation skills. Personal Competencies Strong analytical and critical-thinking capabilities. Excellent communication and stakeholder management skills. Ability to challenge constructively and influence decision-making. Self-driven with strong ownership and accountability. Pragmatic, risk-based mindset. Comfortable operating in a complex, regulated environment. Please do send across to me the most up to date CV to (url removed) Rates depend on experience and client requirements
Aug 23, 2026
Contractor
Senior Cyber Security Risk & Assurance Consultant - Product Risk (PBRA) (CONTRACTOR) - London Duration: 1 year contract Hybrid Working - 8 days onsite per month - the rest is remote working About the Team The Product-Based Risk Assessment (PBRA) service conducts recurring security assessments of applications, services, and technologies to identify emerging threats, evaluate control effectiveness, and drive remediation that strengthens The clients cyber resilience. The team supports business and technology stakeholders by assessing cyber security risks and ensuring alignment with The Banks security standards and risk appetite. Key Accountabilities Product-Based Risk Assessments Lead end-to-end Product-Based Risk Assessments (PBRA) for critical applications, platforms, and technology services. Analyse application architectures, business processes, information flows, and supporting infrastructure. Identify and assess cyber threats, vulnerabilities, control weaknesses, and potential business impacts. Evaluate the design and effectiveness of security controls using clients security frameworks and standards. Assess residual risks and propose actionable remediation plans. Security Risk Analysis Perform security risk assessments using recognised methodologies and industry frameworks. Evaluate risks related to infrastructure, software, cloud services, networks, third-party integrations, and information assets. Contribute to threat modelling and attack surface analysis activities. Support technology-focused assessments such as cloud, AI, and emerging technology evaluations. Stakeholder Engagement Act as the primary security assessment contact for business and IT stakeholders. Facilitate workshops, interviews, and assessment review sessions. Challenge assumptions and provide expert security guidance to delivery and operations teams. Build trusted relationships across CISO, CTO, Architecture, Risk Management, and Engineering teams. Reporting & Governance Produce high-quality assessment reports, risk summaries, and executive-level communications. Present findings and recommendations to senior management and governance bodies. Track remediation plans and risk treatment activities through closure. Support internal and external audit activities as required. Continuous Improvement Contribute to the evolution of the PBRA service, methodologies, tools, and operating model. Help drive the transition toward data-enabled and automated security assessment capabilities. Identify opportunities to improve efficiency, consistency, and risk coverage across assessments. Support knowledge sharing and mentoring of junior analysts. Required Skills & Experience Technical Skills Strong understanding of cybersecurity principles, controls, and risk management practices. Knowledge of application security, cloud security, infrastructure security, and network security. Experience conducting security assessments, threat modelling, or risk analyses. Familiarity with industry frameworks and standards such as: NIST Cyber Security Framework ISO 27001 CIS Controls Secure Controls Framework (SCF) DORA ANSSI EBIOS RM OWASP Professional Experience Minimum 7 years of experience in Information Security, Cyber Risk, Security Assurance, or Security Architecture. Experience leading complex security assessments across large technology environments. Experience working with senior business and technology stakeholders. Strong report-writing and presentation skills. Personal Competencies Strong analytical and critical-thinking capabilities. Excellent communication and stakeholder management skills. Ability to challenge constructively and influence decision-making. Self-driven with strong ownership and accountability. Pragmatic, risk-based mindset. Comfortable operating in a complex, regulated environment. Please do send across to me the most up to date CV to (url removed) Rates depend on experience and client requirements
IMPERIAL WAR MUSEUMS
Cyber Assurance & Risk Analyst
IMPERIAL WAR MUSEUMS Lambeth, London
Cyber Assurance & Risk Analyst Location: IWM London Salary : £42,500 to £45,000 per annum Vacancy Type: Permanent, Full Time (36hours per week) Closing Date: 8th of September 2026 At Imperial War Museums, we're driven by a shared purpose: helping people understand conflict and its impact on people's lives, from the First World War through to the present day. Our collections contain millions of items, stories and digital assets that preserve some of the most important moments in modern history. You'll join a collaborative team who work together to protect and make these collections accessible for future generations. It's a unique opportunity to combine cyber security expertise with meaningful work that supports one of the world's leading museums of conflict. Why This Role Matters Cyber security plays a vital role in protecting IWM's systems, services and information assets from an evolving threat landscape. As Cyber Assurance & Risk Analyst, you'll help strengthen the organisation's cyber resilience by ensuring compliance with government and industry security standards, embedding secure-by-design principles into projects and managing cyber risks across our supplier landscape. By delivering key assurance activities, you'll help improve organisational cyber capability and ensure IWM continues to safeguard the services relied upon by colleagues, visitors, researchers and stakeholders. What You'll Be Doing Coordinate and manage IWM's Cyber Essentials certification, including evidence gathering, submission management and remediation tracking. Lead GovAssure submissions through control mapping, evidence collation and stakeholder engagement. Manage compliance against Civil Aviation Authority (CAA) cyber security requirements and other relevant standards. Maintain assurance documentation and support continuous compliance against recognised cyber security frameworks. Embed secure-by-design principles into technology and digital projects from initiation through to delivery. Review proposed solutions and provide assurance that appropriate security controls are implemented before go-live. Own and operate IWM's third-party cyber risk management platform, supporting supplier onboarding, assessments and ongoing monitoring. Identify, assess, manage and escalate cyber risks across the supply chain, tracking remediation activities where required. Produce assurance, compliance and cyber risk reports for governance boards and senior stakeholders. Support cyber governance activities, risk management processes and the maintenance of accurate cyber risk records. Contribute to the development of cyber security policies, standards, controls and continuous improvement initiatives. Provide guidance on cyber compliance matters and work collaboratively with colleagues, suppliers and external partners to support assurance objectives. Support financial administration activities, including purchase orders, invoice processing and departmental administration where required. What We're Looking For We'd love to hear from you if you have: Experience of cyber security governance, assurance, compliance or risk management activities. Knowledge of recognised cyber security frameworks and standards such as Cyber Essentials, NCSC guidance, ISO 27001 or equivalent. Experience managing compliance evidence, audit activities or regulatory submissions. Experience of supplier or third-party cyber risk assessment and management processes. Strong analytical skills with the ability to identify risks and communicate findings clearly to a range of stakeholders. Experience producing reports, dashboards or management information for governance forums and senior audiences. Benefits The benefits listed below are discretionary and IWM reserves the right, with due notice, to vary or withdraw them at any time. Annual Leave: You'll have 25 days of annual leave, with public holidays on top. After 3 years, this increases to 27 days and after 5 years, you ll get 30 days Company Group Pension Plan: Includes competitive employer contributions to your pension starting at 7% to a maximum of 12%. Enhanced Maternity and Paternity Benefits: Celebrate life s milestones with confidence, knowing that our policies support growing families. IWM4me: Tailor your benefits to your unique needs through IWM4me. Access health, protection, and lifestyle benefits at corporate rates, ensuring your holistic well-being. Free Sanitary Products: We prioritise your comfort by providing free sanitary products across all our sites. Retail Discounts: 25% off IWM Cafes, 20% discount in on-site shops, Benefits hub offering retail discounts to several high street shops and MyActive discounts for health and wellbeing based retail discounts Free Entry to IWM Air Shows: Witness the thrill of vintage aircraft at our air shows. To Apply If you feel you are a suitable candidate and would like to work for Imperial War Museum, please click apply to be redirected to our website to complete your application.
Aug 22, 2026
Full time
Cyber Assurance & Risk Analyst Location: IWM London Salary : £42,500 to £45,000 per annum Vacancy Type: Permanent, Full Time (36hours per week) Closing Date: 8th of September 2026 At Imperial War Museums, we're driven by a shared purpose: helping people understand conflict and its impact on people's lives, from the First World War through to the present day. Our collections contain millions of items, stories and digital assets that preserve some of the most important moments in modern history. You'll join a collaborative team who work together to protect and make these collections accessible for future generations. It's a unique opportunity to combine cyber security expertise with meaningful work that supports one of the world's leading museums of conflict. Why This Role Matters Cyber security plays a vital role in protecting IWM's systems, services and information assets from an evolving threat landscape. As Cyber Assurance & Risk Analyst, you'll help strengthen the organisation's cyber resilience by ensuring compliance with government and industry security standards, embedding secure-by-design principles into projects and managing cyber risks across our supplier landscape. By delivering key assurance activities, you'll help improve organisational cyber capability and ensure IWM continues to safeguard the services relied upon by colleagues, visitors, researchers and stakeholders. What You'll Be Doing Coordinate and manage IWM's Cyber Essentials certification, including evidence gathering, submission management and remediation tracking. Lead GovAssure submissions through control mapping, evidence collation and stakeholder engagement. Manage compliance against Civil Aviation Authority (CAA) cyber security requirements and other relevant standards. Maintain assurance documentation and support continuous compliance against recognised cyber security frameworks. Embed secure-by-design principles into technology and digital projects from initiation through to delivery. Review proposed solutions and provide assurance that appropriate security controls are implemented before go-live. Own and operate IWM's third-party cyber risk management platform, supporting supplier onboarding, assessments and ongoing monitoring. Identify, assess, manage and escalate cyber risks across the supply chain, tracking remediation activities where required. Produce assurance, compliance and cyber risk reports for governance boards and senior stakeholders. Support cyber governance activities, risk management processes and the maintenance of accurate cyber risk records. Contribute to the development of cyber security policies, standards, controls and continuous improvement initiatives. Provide guidance on cyber compliance matters and work collaboratively with colleagues, suppliers and external partners to support assurance objectives. Support financial administration activities, including purchase orders, invoice processing and departmental administration where required. What We're Looking For We'd love to hear from you if you have: Experience of cyber security governance, assurance, compliance or risk management activities. Knowledge of recognised cyber security frameworks and standards such as Cyber Essentials, NCSC guidance, ISO 27001 or equivalent. Experience managing compliance evidence, audit activities or regulatory submissions. Experience of supplier or third-party cyber risk assessment and management processes. Strong analytical skills with the ability to identify risks and communicate findings clearly to a range of stakeholders. Experience producing reports, dashboards or management information for governance forums and senior audiences. Benefits The benefits listed below are discretionary and IWM reserves the right, with due notice, to vary or withdraw them at any time. Annual Leave: You'll have 25 days of annual leave, with public holidays on top. After 3 years, this increases to 27 days and after 5 years, you ll get 30 days Company Group Pension Plan: Includes competitive employer contributions to your pension starting at 7% to a maximum of 12%. Enhanced Maternity and Paternity Benefits: Celebrate life s milestones with confidence, knowing that our policies support growing families. IWM4me: Tailor your benefits to your unique needs through IWM4me. Access health, protection, and lifestyle benefits at corporate rates, ensuring your holistic well-being. Free Sanitary Products: We prioritise your comfort by providing free sanitary products across all our sites. Retail Discounts: 25% off IWM Cafes, 20% discount in on-site shops, Benefits hub offering retail discounts to several high street shops and MyActive discounts for health and wellbeing based retail discounts Free Entry to IWM Air Shows: Witness the thrill of vintage aircraft at our air shows. To Apply If you feel you are a suitable candidate and would like to work for Imperial War Museum, please click apply to be redirected to our website to complete your application.
Global Category Manager
Hiscox Underwriting Group Services Ltd (HUGS) City, York
Job Type: Permanent. Build a brilliant future with Hiscox. Role: Global Category Manager. Reporting to: Head of Business Services Sourcing. Position Overview Following a period of rapid growth, Hiscox has around 3,000 employees across a number of business units and countries and is deploying a new platform Hiscox Marketplace for procurement, vendor management and payments across all regions. It is an exciting time to be joining Hiscox. With sponsorship from the Board, Procurement has a key role in supporting the delivery of the Fit for 10X program, a plan to ensure Hiscox is best placed for significant expansion over the next 5 years. The Global Category Manager (Legal Services and Insurance) will lead the end to end category strategy, sourcing and commercial governance for legal services spend as well as the Insurance policies for the Hiscox Group (notably Cyber, Professional Indemnity and Directors and Officers). The role delivers measurable value through cost optimisation, demand management, service quality and innovation, while ensuring compliance with internal policies and applicable regulations. The role will be supported with Category Analysts based in Lisbon. The role will establish relationships with stakeholders across the UK and Europe/US to ensure that procurement is aligned to deliver the benefits of Hiscox Marketplace and the Fit For 10X business objectives. Where sourcing activity is material, high profile or high risk then the Global Category Manager will lead the procurement activity from market analysis through to contract signature. They will also provide advice and support to the business when managing vendors on a day to day basis. The role will be accountable for improving spend management in the Legal Services and Group Insurance categories as well as contributing to Group procurement strategy, supporting the use of Hiscox Marketplace the global procurement platform used across the business in all regions and to provide consistent and professional procurement practice. As well as maintaining and developing the Global Category Plans for Legal Services. Responsibilities Category Strategy: Develop and maintain a multi year category strategy and pipeline aligned to business priorities, demand management, and financial plans. Team Contribution: Coach junior colleagues, share best practice, and contribute to procurement standards, playbooks and training. Stakeholders: Maintain good working relationships with key stakeholders in Finance, London Market, UK Retail, US and Europe by providing expertise on contracts and Statements of Work. Influence demand, shape requirements, and drive adherence to sourcing and spend control processes via the use of the Legal Services panel and other supplier panels as appropriate. Sourcing & Tendering: Plan and execute end to end sourcing activities (RFI/RFP/RFQ/Spot Bid), evaluation, negotiation and contract award in line with governance requirements. Commercial Leadership: Negotiate commercials (rates, discounts, value adds, KPIs, gainshare), define statements of work (SoWs), and ensure clear deliverables and acceptance criteria. Hiscox Marketplace: embed the use of Hiscox Marketplace and policies as required to deploy best practice based processes. Contracting & Compliance: Use of A.I. and partner with Legal and Risk to implement appropriate contractual terms (IP, confidentiality, data protection, liability, conflicts of interest, anti bribery) and ensure policy compliance. Governance: Implement appropriate controls for legal services engagements (SoW approvals, rate cards, time & materials governance, change control, and invoice validation). Supplier Management: Own strategic supplier relationships, QBRs, performance scorecards, continuous improvement plans, and issue resolution/escalations. Reporting: Use of A.I. to undertake and input into the creation of procurement MI as required and reporting such as savings and volumes of requests. Carry out any other tasks or requirements as required by Hiscox from time to time. Required Skills Commercial acumen: Strong negotiation skills; able to structure deals, manage risk/reward, and agree measurable outcomes. Analytical capability: Rate benchmarking, total cost of ownership thinking, financial modelling, and data driven decision making. Stakeholder influence: Credible at senior levels; able to challenge constructively and build alignment across competing priorities. Supplier relationship management: Balances partnership and performance; manages escalations with pace and professionalism. Contract literacy: Strong understanding of key legal services contract terms (IP, confidentiality, data protection, conflicts, liability, audit rights). Project management: Plans and executes sourcing projects to deadlines; manages evaluation, governance and approvals. Communication: Clear, concise written and verbal communication; able to present recommendations and business cases. Integrity and judgement: Applies strong ethical standards; manages confidential information appropriately. Necessary: Strong leadership skills across matrix structures. Team player at executive level: collaborate with Business Units and functional partners in Finance, and Operations across the Hiscox Business Units. Solid operational management and general business skills to project manage business teams to support delivery of procurement activity as required. Excellent communication skills in order to get the 'voice of the internal customer' and to understand the company culture and how to best communicate procurement's value to it. Qualifications and Training Degree (or equivalent experience) in business, procurement, finance, law or a related discipline. Professional procurement qualification preferred (e.g., CIPS Level 5/6 or equivalent). Desirable Contract management qualification and/or relevant compliance training (e.g., anti bribery, modern slavery, data protection). Negotiation Training. Diversity and flexible working We are committed to diversity and creating a truly inclusive culture, which we believe drives success. Hybrid working is encouraged to support a healthy work life balance; it is set by the team rather than the business to enable you to manage your own personal work life balance. This best of both worlds; structure and sociability on one hand, and independence and flexibility on the other.
Aug 22, 2026
Full time
Job Type: Permanent. Build a brilliant future with Hiscox. Role: Global Category Manager. Reporting to: Head of Business Services Sourcing. Position Overview Following a period of rapid growth, Hiscox has around 3,000 employees across a number of business units and countries and is deploying a new platform Hiscox Marketplace for procurement, vendor management and payments across all regions. It is an exciting time to be joining Hiscox. With sponsorship from the Board, Procurement has a key role in supporting the delivery of the Fit for 10X program, a plan to ensure Hiscox is best placed for significant expansion over the next 5 years. The Global Category Manager (Legal Services and Insurance) will lead the end to end category strategy, sourcing and commercial governance for legal services spend as well as the Insurance policies for the Hiscox Group (notably Cyber, Professional Indemnity and Directors and Officers). The role delivers measurable value through cost optimisation, demand management, service quality and innovation, while ensuring compliance with internal policies and applicable regulations. The role will be supported with Category Analysts based in Lisbon. The role will establish relationships with stakeholders across the UK and Europe/US to ensure that procurement is aligned to deliver the benefits of Hiscox Marketplace and the Fit For 10X business objectives. Where sourcing activity is material, high profile or high risk then the Global Category Manager will lead the procurement activity from market analysis through to contract signature. They will also provide advice and support to the business when managing vendors on a day to day basis. The role will be accountable for improving spend management in the Legal Services and Group Insurance categories as well as contributing to Group procurement strategy, supporting the use of Hiscox Marketplace the global procurement platform used across the business in all regions and to provide consistent and professional procurement practice. As well as maintaining and developing the Global Category Plans for Legal Services. Responsibilities Category Strategy: Develop and maintain a multi year category strategy and pipeline aligned to business priorities, demand management, and financial plans. Team Contribution: Coach junior colleagues, share best practice, and contribute to procurement standards, playbooks and training. Stakeholders: Maintain good working relationships with key stakeholders in Finance, London Market, UK Retail, US and Europe by providing expertise on contracts and Statements of Work. Influence demand, shape requirements, and drive adherence to sourcing and spend control processes via the use of the Legal Services panel and other supplier panels as appropriate. Sourcing & Tendering: Plan and execute end to end sourcing activities (RFI/RFP/RFQ/Spot Bid), evaluation, negotiation and contract award in line with governance requirements. Commercial Leadership: Negotiate commercials (rates, discounts, value adds, KPIs, gainshare), define statements of work (SoWs), and ensure clear deliverables and acceptance criteria. Hiscox Marketplace: embed the use of Hiscox Marketplace and policies as required to deploy best practice based processes. Contracting & Compliance: Use of A.I. and partner with Legal and Risk to implement appropriate contractual terms (IP, confidentiality, data protection, liability, conflicts of interest, anti bribery) and ensure policy compliance. Governance: Implement appropriate controls for legal services engagements (SoW approvals, rate cards, time & materials governance, change control, and invoice validation). Supplier Management: Own strategic supplier relationships, QBRs, performance scorecards, continuous improvement plans, and issue resolution/escalations. Reporting: Use of A.I. to undertake and input into the creation of procurement MI as required and reporting such as savings and volumes of requests. Carry out any other tasks or requirements as required by Hiscox from time to time. Required Skills Commercial acumen: Strong negotiation skills; able to structure deals, manage risk/reward, and agree measurable outcomes. Analytical capability: Rate benchmarking, total cost of ownership thinking, financial modelling, and data driven decision making. Stakeholder influence: Credible at senior levels; able to challenge constructively and build alignment across competing priorities. Supplier relationship management: Balances partnership and performance; manages escalations with pace and professionalism. Contract literacy: Strong understanding of key legal services contract terms (IP, confidentiality, data protection, conflicts, liability, audit rights). Project management: Plans and executes sourcing projects to deadlines; manages evaluation, governance and approvals. Communication: Clear, concise written and verbal communication; able to present recommendations and business cases. Integrity and judgement: Applies strong ethical standards; manages confidential information appropriately. Necessary: Strong leadership skills across matrix structures. Team player at executive level: collaborate with Business Units and functional partners in Finance, and Operations across the Hiscox Business Units. Solid operational management and general business skills to project manage business teams to support delivery of procurement activity as required. Excellent communication skills in order to get the 'voice of the internal customer' and to understand the company culture and how to best communicate procurement's value to it. Qualifications and Training Degree (or equivalent experience) in business, procurement, finance, law or a related discipline. Professional procurement qualification preferred (e.g., CIPS Level 5/6 or equivalent). Desirable Contract management qualification and/or relevant compliance training (e.g., anti bribery, modern slavery, data protection). Negotiation Training. Diversity and flexible working We are committed to diversity and creating a truly inclusive culture, which we believe drives success. Hybrid working is encouraged to support a healthy work life balance; it is set by the team rather than the business to enable you to manage your own personal work life balance. This best of both worlds; structure and sociability on one hand, and independence and flexibility on the other.
Matchtech
Cyber Security Contractors - SC Cleared
Matchtech
Cyber Security Contractors (Multiple Opportunities) SC Cleared 594/day Remote UK Location: UK Remote (occasional client-site visits required) Contract: Inside IR35 Rate: 594 per day (Umbrella) Duration: Until March 2027 Security Clearance: Active SC Clearance Required We are supporting a major, long-term Cyber Security Programme and are seeking experienced SC-cleared professionals across several specialist disciplines. These are excellent opportunities to join a high-profile programme delivering critical security services within a complex environment. Opportunities Available Security Architect (Cloud Security) Key responsibilities include: Cloud security architecture and design assurance Security assessments and risk reviews Development and implementation of security standards, patterns, and best practices Collaboration with technical and business stakeholders to ensure secure-by-design solutions Experience required: Strong cloud security architecture background Experience with enterprise cloud platforms (AWS, Azure, or GCP) Security design and assurance expertise Knowledge of security frameworks and standards Security Operations Analyst Key responsibilities include: Security operations monitoring and analysis Cyber threat intelligence assessment Threat modelling and risk identification Incident investigation and security event analysis Experience required: Security Operations Centre (SOC) or cyber defence experience Hands-on threat intelligence and analysis capability Threat modelling expertise Strong understanding of cyber security technologies and processes Threat Intelligence Analyst Key responsibilities include: Production of threat intelligence reports and assessments Analysis of Indicators of Compromise (IOCs) and Tactics, Techniques & Procedures (TTPs) Tracking emerging cyber threats and threat actors Supporting security architecture and operational security decision-making Experience required: Proven cyber threat intelligence background Experience analysing threat actor activity and attack methodologies Strong reporting and stakeholder engagement skills Knowledge of intelligence frameworks such as MITRE ATT&CK Information Assurance Consultant Key responsibilities include: Information Assurance (IA) and Governance, Risk & Compliance (GRC) activities Quality assurance and quality management support Business Continuity and Disaster Recovery (BCDR) planning and assessment Policy, controls, and compliance reviews Experience required: Strong IA/GRC experience Knowledge of security governance frameworks Experience in quality management and assurance activities BCDR planning and implementation expertise Essential Requirements Active SC Clearance (mandatory) Proven experience within the relevant cyber security discipline Ability to work effectively in complex stakeholder environments Strong communication and reporting skills
Aug 20, 2026
Contractor
Cyber Security Contractors (Multiple Opportunities) SC Cleared 594/day Remote UK Location: UK Remote (occasional client-site visits required) Contract: Inside IR35 Rate: 594 per day (Umbrella) Duration: Until March 2027 Security Clearance: Active SC Clearance Required We are supporting a major, long-term Cyber Security Programme and are seeking experienced SC-cleared professionals across several specialist disciplines. These are excellent opportunities to join a high-profile programme delivering critical security services within a complex environment. Opportunities Available Security Architect (Cloud Security) Key responsibilities include: Cloud security architecture and design assurance Security assessments and risk reviews Development and implementation of security standards, patterns, and best practices Collaboration with technical and business stakeholders to ensure secure-by-design solutions Experience required: Strong cloud security architecture background Experience with enterprise cloud platforms (AWS, Azure, or GCP) Security design and assurance expertise Knowledge of security frameworks and standards Security Operations Analyst Key responsibilities include: Security operations monitoring and analysis Cyber threat intelligence assessment Threat modelling and risk identification Incident investigation and security event analysis Experience required: Security Operations Centre (SOC) or cyber defence experience Hands-on threat intelligence and analysis capability Threat modelling expertise Strong understanding of cyber security technologies and processes Threat Intelligence Analyst Key responsibilities include: Production of threat intelligence reports and assessments Analysis of Indicators of Compromise (IOCs) and Tactics, Techniques & Procedures (TTPs) Tracking emerging cyber threats and threat actors Supporting security architecture and operational security decision-making Experience required: Proven cyber threat intelligence background Experience analysing threat actor activity and attack methodologies Strong reporting and stakeholder engagement skills Knowledge of intelligence frameworks such as MITRE ATT&CK Information Assurance Consultant Key responsibilities include: Information Assurance (IA) and Governance, Risk & Compliance (GRC) activities Quality assurance and quality management support Business Continuity and Disaster Recovery (BCDR) planning and assessment Policy, controls, and compliance reviews Experience required: Strong IA/GRC experience Knowledge of security governance frameworks Experience in quality management and assurance activities BCDR planning and implementation expertise Essential Requirements Active SC Clearance (mandatory) Proven experience within the relevant cyber security discipline Ability to work effectively in complex stakeholder environments Strong communication and reporting skills
DFIR Lead Cyber Operations Analyst
慨正橡扯 Knutsford, Cheshire
Join Barclays as a DFIR Lead Cyber Operations Analyst, a VP-level role at the centre of the bank's cyber defence, delivering advanced digital forensics and incident response. You will analyse malware, malicious samples and network activity to support complex investigations, working closely with internal teams, external partners and law enforcement. This is a highly technical, hands on position suited to an experienced cyber or digital forensics professional, with passion for deep investigation, and the ability to produce clear, high quality reporting in a fast paced, high pressure environment. Please note that this role includes an on call support rotation. Occasional additional support may be required, including extended hours and weekend work. To be successful in this role, you will need the following: Digital forensics and incident response expertise, including host, network, cloud and live forensic analysis, supported by rigorous documentation practices. Excellent written and verbal communication skills, with the ability to clearly articulate complex technical findings to senior stakeholders and non technical business teams. Proven leadership under pressure, including coordinating investigations, managing cross functional stakeholders, and operating effectively within a regulated banking environment. Some other highly valued skills may include: Cloud investigation experience across platforms such as AWS, Azure, or Google Cloud. Scripting and automation capabilities, using languages such as Python, PowerShell, Bash, or JavaScript. Relevant industry certifications, such as GCFA, GNFA, GCFE, or GREM. You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking and digital and technology, as well as job specific technical skills. The successful candidate will be based in Knutsford (Radbroke Hall). Purpose of the role To monitor the performance of operational controls, implement and manage security controls and consider lessons learned in order to protect the bank from potential cyber attacks and respond to threats. Accountabilities Management of security monitoring systems, including intrusive prevention and detection systems, to alert, detect and block potential cyber security incidents, and provide a prompt response to restore normal operations with minimised system damage. Identification of emerging cyber security threats, attack techniques and technologies to detect/prevent incidents, and collaborate with networks and conferences to gain industry knowledge and expertise. Management and analysis of security information and event management systems to collect, correlate and analyse security logs, events and alerts/potential threats. Triage of data loss prevention alerts to identify and prevent sensitive data for being exfiltrated from the banks network. Management of cyber security incidents including remediation & driving to closure. Vice President Expectations To contribute or set strategy, drive requirements and make recommendations for change. Plan resources, budgets, and policies; manage and maintain policies/processes; deliver continuous improvements and escalate breaches of policies/procedures. If managing a team, they define jobs and responsibilities, planning for the department's future needs and operations, counselling employees on performance and contributing to employee pay decisions/changes. They may also lead a number of specialists to influence the operations of a department, in alignment with strategic as well as tactical priorities, while balancing short and long term goals and ensuring that budgets and schedules meet corporate requirements. If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L - Listen and be authentic, E - Energise and inspire, A - Align across the enterprise, D - Develop others. OR for an individual contributor, they will be a subject matter expert within own discipline and will guide technical direction. They will lead collaborative, multi year assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions. Advise key stakeholders, including functional leadership teams and senior management on functional and cross functional areas of impact and alignment. Manage and mitigate risks through assessment, in support of the control and governance agenda. Demonstrate leadership and accountability for managing risk and strengthening controls in relation to the work your team does. Demonstrate comprehensive understanding of the organisation functions to contribute to achieving the goals of the business. Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategies. Create solutions based on sophisticated analytical thought comparing and selecting complex alternatives. In depth analysis with interpretative thinking will be required to define problems and develop innovative solutions. Adopt and include the outcomes of extensive research in problem solving processes. Seek out, build and maintain trusting relationships and partnerships with internal and external stakeholders in order to accomplish key business objectives, using influencing and negotiating skills to achieve outcomes. All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship - our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset - to Empower, Challenge and Drive - the operating manual for how we behave.
Aug 19, 2026
Full time
Join Barclays as a DFIR Lead Cyber Operations Analyst, a VP-level role at the centre of the bank's cyber defence, delivering advanced digital forensics and incident response. You will analyse malware, malicious samples and network activity to support complex investigations, working closely with internal teams, external partners and law enforcement. This is a highly technical, hands on position suited to an experienced cyber or digital forensics professional, with passion for deep investigation, and the ability to produce clear, high quality reporting in a fast paced, high pressure environment. Please note that this role includes an on call support rotation. Occasional additional support may be required, including extended hours and weekend work. To be successful in this role, you will need the following: Digital forensics and incident response expertise, including host, network, cloud and live forensic analysis, supported by rigorous documentation practices. Excellent written and verbal communication skills, with the ability to clearly articulate complex technical findings to senior stakeholders and non technical business teams. Proven leadership under pressure, including coordinating investigations, managing cross functional stakeholders, and operating effectively within a regulated banking environment. Some other highly valued skills may include: Cloud investigation experience across platforms such as AWS, Azure, or Google Cloud. Scripting and automation capabilities, using languages such as Python, PowerShell, Bash, or JavaScript. Relevant industry certifications, such as GCFA, GNFA, GCFE, or GREM. You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking and digital and technology, as well as job specific technical skills. The successful candidate will be based in Knutsford (Radbroke Hall). Purpose of the role To monitor the performance of operational controls, implement and manage security controls and consider lessons learned in order to protect the bank from potential cyber attacks and respond to threats. Accountabilities Management of security monitoring systems, including intrusive prevention and detection systems, to alert, detect and block potential cyber security incidents, and provide a prompt response to restore normal operations with minimised system damage. Identification of emerging cyber security threats, attack techniques and technologies to detect/prevent incidents, and collaborate with networks and conferences to gain industry knowledge and expertise. Management and analysis of security information and event management systems to collect, correlate and analyse security logs, events and alerts/potential threats. Triage of data loss prevention alerts to identify and prevent sensitive data for being exfiltrated from the banks network. Management of cyber security incidents including remediation & driving to closure. Vice President Expectations To contribute or set strategy, drive requirements and make recommendations for change. Plan resources, budgets, and policies; manage and maintain policies/processes; deliver continuous improvements and escalate breaches of policies/procedures. If managing a team, they define jobs and responsibilities, planning for the department's future needs and operations, counselling employees on performance and contributing to employee pay decisions/changes. They may also lead a number of specialists to influence the operations of a department, in alignment with strategic as well as tactical priorities, while balancing short and long term goals and ensuring that budgets and schedules meet corporate requirements. If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L - Listen and be authentic, E - Energise and inspire, A - Align across the enterprise, D - Develop others. OR for an individual contributor, they will be a subject matter expert within own discipline and will guide technical direction. They will lead collaborative, multi year assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions. Advise key stakeholders, including functional leadership teams and senior management on functional and cross functional areas of impact and alignment. Manage and mitigate risks through assessment, in support of the control and governance agenda. Demonstrate leadership and accountability for managing risk and strengthening controls in relation to the work your team does. Demonstrate comprehensive understanding of the organisation functions to contribute to achieving the goals of the business. Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategies. Create solutions based on sophisticated analytical thought comparing and selecting complex alternatives. In depth analysis with interpretative thinking will be required to define problems and develop innovative solutions. Adopt and include the outcomes of extensive research in problem solving processes. Seek out, build and maintain trusting relationships and partnerships with internal and external stakeholders in order to accomplish key business objectives, using influencing and negotiating skills to achieve outcomes. All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship - our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset - to Empower, Challenge and Drive - the operating manual for how we behave.
Brimstone-Recruitment
Digital Forensics Manager
Brimstone-Recruitment
Forensic Technology/ Digital Forensics Manager London (hybrid) Opportunity to work for an outstanding company in the field. You will have a strong commercial background and client facing communication skills. Your experience is likely from a service provider or advisory firm. You will have an ability to collect data from various devices (Desktop, laptop, phones) but also from the cloud and more commercial enterprise wide systems e.g. global email etc. You will have experience with leading Digital Forensic tools e.g. EnCase, FTK, Cellebrite etc. You will have a strong academic background and likely a degree in a related subject. You will be able to attend the office and when required visit client sites. There are initially no direct reportees. You will collect data in a compliant manner so be familiar with ACPO and chain of custody. About Brimstone Consulting: We specialise in finding highly qualified staff in the following areas:Forensic Accounting & Fraud - (AML/CTF, Investigation, CFE s etc.); Legal and LegalTech (E-Discovery, Digital Forensics, EDRM); Big Data and Data Analytics- (MI/BI/CI);InfoSec and Cyber Crime; Audit; Accountancy and Finance; FinTech (Payments etc.);Risk - (Credit, Regulatory, Liquidity, Market, Analysts-SAS, SPSS etc.);Compliance/Corporate Governance ;IT- (full SDLC- BA s PM s , Architects, Developers etc.); Brimstone Consulting acts as an employment agency (permanent) and as an employment business (temporary) - a free and confidential service to candidates. Brimstone Consulting is an equal opportunities employer. Due to time constraints we can only reply to applicants that match our clients specifications. We may store applications in our cloud storage facilities that may include dropbox.
Aug 17, 2026
Full time
Forensic Technology/ Digital Forensics Manager London (hybrid) Opportunity to work for an outstanding company in the field. You will have a strong commercial background and client facing communication skills. Your experience is likely from a service provider or advisory firm. You will have an ability to collect data from various devices (Desktop, laptop, phones) but also from the cloud and more commercial enterprise wide systems e.g. global email etc. You will have experience with leading Digital Forensic tools e.g. EnCase, FTK, Cellebrite etc. You will have a strong academic background and likely a degree in a related subject. You will be able to attend the office and when required visit client sites. There are initially no direct reportees. You will collect data in a compliant manner so be familiar with ACPO and chain of custody. About Brimstone Consulting: We specialise in finding highly qualified staff in the following areas:Forensic Accounting & Fraud - (AML/CTF, Investigation, CFE s etc.); Legal and LegalTech (E-Discovery, Digital Forensics, EDRM); Big Data and Data Analytics- (MI/BI/CI);InfoSec and Cyber Crime; Audit; Accountancy and Finance; FinTech (Payments etc.);Risk - (Credit, Regulatory, Liquidity, Market, Analysts-SAS, SPSS etc.);Compliance/Corporate Governance ;IT- (full SDLC- BA s PM s , Architects, Developers etc.); Brimstone Consulting acts as an employment agency (permanent) and as an employment business (temporary) - a free and confidential service to candidates. Brimstone Consulting is an equal opportunities employer. Due to time constraints we can only reply to applicants that match our clients specifications. We may store applications in our cloud storage facilities that may include dropbox.
TRIA
Principle Identity and Access Management Lead
TRIA Bletchley, Buckinghamshire
Principal Identity & Access Lead London or Milton Keynes (2 days on site) 75 - 85k + 15% bonus We are working with an established organisation who are embarking on a significant digital transformation programme and are seeking a Principal Identity & Access Lead to shape and deliver their enterprise Identity and Access Management (IAM) strategy. The role will play a pivotal role in protecting critical systems, data, and business services by leading the evolution of the organisation's IAM capability. Working closely with the CISO and senior stakeholders, you will design, implement, and continuously enhance IAM and Privileged Access Management (PAM) solutions that strengthen resilience, support regulatory compliance, and enable secure business transformation. Key responsibilities include: Own and drive the enterprise IAM vision, roadmap and strategy, ensuring identity security capabilities support organisational goals and regulatory expectations Lead the selection, deployment, integration and ongoing optimisation of IAM and PAM solutions Champion identity governance and access management best practices across the organisation, influencing stakeholders at all levels Lead the design and operation of robust IAM and PAM controls that protect critical systems, data and business services Drive a culture of least privilege, accountability and access governance through effective control frameworks and stakeholder engagement Deliver insightful reporting and executive-level briefings on IAM risk, compliance, maturity and control effectiveness Lead a team of IAM Analysts Experience with IAM and PAM tools such as SailPoint, CyberArk, Delinea or similar is essential. If you're passionate about building secure, scalable identity services and enjoy working across technology, architecture and business teams, please apply now.
Jul 31, 2026
Full time
Principal Identity & Access Lead London or Milton Keynes (2 days on site) 75 - 85k + 15% bonus We are working with an established organisation who are embarking on a significant digital transformation programme and are seeking a Principal Identity & Access Lead to shape and deliver their enterprise Identity and Access Management (IAM) strategy. The role will play a pivotal role in protecting critical systems, data, and business services by leading the evolution of the organisation's IAM capability. Working closely with the CISO and senior stakeholders, you will design, implement, and continuously enhance IAM and Privileged Access Management (PAM) solutions that strengthen resilience, support regulatory compliance, and enable secure business transformation. Key responsibilities include: Own and drive the enterprise IAM vision, roadmap and strategy, ensuring identity security capabilities support organisational goals and regulatory expectations Lead the selection, deployment, integration and ongoing optimisation of IAM and PAM solutions Champion identity governance and access management best practices across the organisation, influencing stakeholders at all levels Lead the design and operation of robust IAM and PAM controls that protect critical systems, data and business services Drive a culture of least privilege, accountability and access governance through effective control frameworks and stakeholder engagement Deliver insightful reporting and executive-level briefings on IAM risk, compliance, maturity and control effectiveness Lead a team of IAM Analysts Experience with IAM and PAM tools such as SailPoint, CyberArk, Delinea or similar is essential. If you're passionate about building secure, scalable identity services and enjoy working across technology, architecture and business teams, please apply now.
Brimstone-Recruitment
eDiscovery Senior Technical Project Manager
Brimstone-Recruitment
eDiscovery Senior Technical Project Manager London/hybrid (but remote from UK could be considered for an exceptional person) The Firm: Highly reputable international Legal Practice undergoing expansion in the eDiscovery Practice. The Role: Provide the eDiscovery team with technical, strategic and practical know how on eDiscovery services. Successfully deliver and assist others in the delivery of eDiscovery projects. Assist with the management of the eDiscovery team The Individual: Have proven experience of successfully supporting projects with all aspects of eDiscovery processes. Experience of using eDiscovery products such as Relativity, Reveal, Disco, Axcelerate, Nuix, and also know or happy to learn Sharedo or Opus2. You will be very technically adept and if not a Relativity Master be well on your way with an understanding across the tool and other tools (mentioned above). Delivery: Accountable for ensuring quality control process is adhered to in delivery of all services Ensure your Manager is made aware of all tasks, projects and the approach to delivery is discussed and confirmed with them Create recommendations, project plans, cost estimates, procedures and specifications, ensuring quotes are provided and instructions are agreed in writing Data processing of material received in various formats including native and load file mapping and ingestion, as well as exception handling Setup and customisation of Relativity , running searches and culling data, creating review batches, customising coding templates, creating user roles and related permission settings Carry out native and load file productions according to specifications Resolve 1st line support queries and work with our 2nd & 3rd line support to ensure technical issues are resolved Be a reference point for service issues, escalating any complaints from the Practice immediately to the team Manager and working with the Manager to address these Ensure defensible processes and data security procedures are adhered to at all times Administration of software and hardware used by the eDiscovery team Responsible for the successful end-to-end delivery of eDiscovery projects, including processing data, creating productions for disclosure/investigation, leveraging TAR functionality, Early Case Assessment tools. Also GenAI solutions, eBundling and case management solutions Keep up to date with developments by attending seminars and presentations on relevant services and technology, ensuring knowledge is shared and training is provided to all team members About Brimstone Consulting: We specialise in finding highly qualified staff in the following areas: E-Discovery and Digital Forensics; Payments; Fraud - (AML/CTF, Investigation, CFE s etc.); Risk - (Credit, Regulatory, Liquidity, Market, Analysts-SAS, SPSS etc.); Compliance/Corporate Governance ; IT - (full SDLC- BA s PM s , Architects, Developers etc.); Big Data and Data Analytics - (MI/BI/CI); InfoSec and Cyber Crime; Audit; Accountancy and Finance Brimstone Consulting acts as an employment agency (permanent) and as an employment business (temporary) - a free and confidential service to candidates. Brimstone Consulting is an equal opportunities employer. Due to time constraints we can only reply to applicants that match our clients specifications. Our Data Protection number: ZA(phone number removed)
Jul 30, 2026
Full time
eDiscovery Senior Technical Project Manager London/hybrid (but remote from UK could be considered for an exceptional person) The Firm: Highly reputable international Legal Practice undergoing expansion in the eDiscovery Practice. The Role: Provide the eDiscovery team with technical, strategic and practical know how on eDiscovery services. Successfully deliver and assist others in the delivery of eDiscovery projects. Assist with the management of the eDiscovery team The Individual: Have proven experience of successfully supporting projects with all aspects of eDiscovery processes. Experience of using eDiscovery products such as Relativity, Reveal, Disco, Axcelerate, Nuix, and also know or happy to learn Sharedo or Opus2. You will be very technically adept and if not a Relativity Master be well on your way with an understanding across the tool and other tools (mentioned above). Delivery: Accountable for ensuring quality control process is adhered to in delivery of all services Ensure your Manager is made aware of all tasks, projects and the approach to delivery is discussed and confirmed with them Create recommendations, project plans, cost estimates, procedures and specifications, ensuring quotes are provided and instructions are agreed in writing Data processing of material received in various formats including native and load file mapping and ingestion, as well as exception handling Setup and customisation of Relativity , running searches and culling data, creating review batches, customising coding templates, creating user roles and related permission settings Carry out native and load file productions according to specifications Resolve 1st line support queries and work with our 2nd & 3rd line support to ensure technical issues are resolved Be a reference point for service issues, escalating any complaints from the Practice immediately to the team Manager and working with the Manager to address these Ensure defensible processes and data security procedures are adhered to at all times Administration of software and hardware used by the eDiscovery team Responsible for the successful end-to-end delivery of eDiscovery projects, including processing data, creating productions for disclosure/investigation, leveraging TAR functionality, Early Case Assessment tools. Also GenAI solutions, eBundling and case management solutions Keep up to date with developments by attending seminars and presentations on relevant services and technology, ensuring knowledge is shared and training is provided to all team members About Brimstone Consulting: We specialise in finding highly qualified staff in the following areas: E-Discovery and Digital Forensics; Payments; Fraud - (AML/CTF, Investigation, CFE s etc.); Risk - (Credit, Regulatory, Liquidity, Market, Analysts-SAS, SPSS etc.); Compliance/Corporate Governance ; IT - (full SDLC- BA s PM s , Architects, Developers etc.); Big Data and Data Analytics - (MI/BI/CI); InfoSec and Cyber Crime; Audit; Accountancy and Finance Brimstone Consulting acts as an employment agency (permanent) and as an employment business (temporary) - a free and confidential service to candidates. Brimstone Consulting is an equal opportunities employer. Due to time constraints we can only reply to applicants that match our clients specifications. Our Data Protection number: ZA(phone number removed)
CapGemini
Technical Analyst
CapGemini Manchester, Lancashire
Security Clearance: To be successfully appointed to this role, must be eligible to obtain Security Check (SC) clearance. To obtain SC clearance, the successful applicant must have resided continuously within the United Kingdom for the last 5 years, along with other criteria and requirements. Throughout the recruitment process, you will be asked questions about your security clearance eligibility such as, but not limited to, country of residence and nationality. Some posts are restricted to sole UK Nationals for security reasons; therefore, you may be asked about your citizenship in the application process. Hybrid working: The places that you work from day to day will vary according to your role, your needs, and those of the business; it will be a blend of Company offices, client sites, and your home; noting that you will be unable to work at home 100% of the time. If you are successfully offered this position, you will go through a series of pre-employment checks, including identity, nationality (single or dual) or immigration status, employment history going back three continuous years, and unspent criminal record check (known as Disclosure and Barring Service) What we will offer you You will be encouraged to have a positive work-life balance. Our hybrid-first way of working means we embed hybrid working in all that we do and make flexible working arrangements the day-to-day reality for our people. All UK employees are eligible to request flexible working arrangements. You will be empowered to explore, innovate, and progress. You will benefit from Capgemini's 'learning for life' mindset, meaning you will have countless training and development opportunities from thinktanks to hackathons, and access to 250,000 courses with numerous external certifications from AWS, Microsoft, Harvard Manage Mentor, Cybersecurity qualifications and much more. Why we are different At Capgemini, we help organisations across the world become more agile, more competitive, and more successful. Smart, tailored, often ground-breaking technical solutions to complex problems are the norm. But so, too, is a culture that is as collaborative as it is forward thinking. Working closely with each other, and with our clients, we get under the skin of businesses and to the heart of their goals. You will too. Capgemini is proud to represent nearly 130 nationalities and its cultural diversity. Our holistic definition of diversity extends beyond gender, gender identity, sexual orientation, disability, ethnicity, race, age, and religion. Capgemini views diversity as everything that makes us who we are as an organization, including our social background, our experiences in life and work, our communication styles and even our personality. These dimensions contribute to the type of diversity we value the most: diversity of thought. Who you will be working with You will join the Data Trust Capability in Capgemini's Insights and Data (I&D) business unit. Insights and Data is a global business unit covering Enterprise Data Management, Cloud Platforms, Enterprise Content Management and AI & Analytics. Our team is one of the largest and most successful Data Management teams in the UK delivering innovative Data Management and Governance thought leadership to our clients. The Enterprise Data Management provides services on Information Strategy, Data Governance, Master Data Management, Data Architecture, Data Migration and Lifecycle Management. We help our clients build an enterprise-class data platform that allows them to move ahead in their journey of data and insights. Primarily working with leading software vendors like SAP, Informatica, IBM, Oracle et al, the team are primarily Consultants, putting client requirements and industry best practices at the heart of delivery. The focus of your role Configure and maintain Microsoft Purview features, including: Information Protection (sensitivity labels, auto-labelling), Data Loss Prevention (M365, Endpoint, Cloud Apps), Data Governance (catalogue, scanning, classification), Records Management (retention labels & policies), Insider Risk Management, eDiscovery (Standard & Premium) Manage scanning rules, data connectors, metadata sources, and catalog assets. Support integration with M365, Azure, Power Platform, and on premises data sources Monitor Purview alerts, DLP incidents, policy matches, and governance activity logs Perform investigation of policy violations, insider risk alerts, and data protection events Track and escape issues to engineering or architecture teams as required Maintain audit trails, compliance dashboards, and monthly reporting Assist with maintaining data classification schemas, taxonomy, and metadata models Support data owners and stewards in cataloguing and tagging data assets Run data scans, quality checks, and lineage validation tasks Produce and maintain operational runbooks, configuration documentation, and governance processes Create user guides for end users, compliance officers, and IT support teams Document incident response processes related to Purview alerts Work closely with Compliance, Security, Data Governance, and IT teams to implement policies into Purview Support end users by troubleshooting classification, labelling, and access issues Provide training sessions and knowledge transfer on Purview features Identify gaps in data governance and compliance processes; recommend improvements You may also offer insights to the wider community through blogs, articles, and social media. At Capgemini, we believe in bringing your whole self to work. Equity, diversity, and inclusion are woven into our everyday culture, creating a welcoming and supportive environment for everyone. What You Will Bring As a Technical Purview Analyst, you will have 7 years plus experience in data governance, security, compliance, or Microsoft 365 administration. You will have hands on experience with Microsoft Purview or related compliance/security platforms, with exposure to operational support, incident management, or compliance monitoring. Experience Microsoft Purview Information Protection - labels, policies, auto labelling, encryption Data Loss Prevention - endpoint, SharePoint/OneDrive/Teams, Exchange, cloud apps Purview Data Governance - cataloguing, scanning, metadata management Records Management & Retention Labelling eDiscovery workflows and case management Defender for Cloud Apps Wider integration with SharePoint, OneDrive, Exchange, Azure Storage, SQL, Synapse, Data Factory, and Power BI Understanding of classification, metadata, and governance principles Knowledge of Microsoft 365 security & compliance capabilities Basic understanding of Azure Active Directory / Entra ID identity and access concepts Familiarity with ITSM/incident management processes Understanding of regulatory compliance basics How compliance and data protection teams use Purview outputs Data sensitivity models and how they map to business processes Governance best practices, including cataloguing and lineage use cases Ability to configure and manage Purview policies and scanning tools Strong analytical and troubleshooting skills Familiarity with KQL, PowerShell, or Microsoft Graph Ability to interpret logs, alerts, and governance reporting Strong documentation and verbal communication skills Ability to work collaboratively with cross functional teams Good organisational and time management abilities Certifications (Desirable)
Jun 03, 2026
Full time
Security Clearance: To be successfully appointed to this role, must be eligible to obtain Security Check (SC) clearance. To obtain SC clearance, the successful applicant must have resided continuously within the United Kingdom for the last 5 years, along with other criteria and requirements. Throughout the recruitment process, you will be asked questions about your security clearance eligibility such as, but not limited to, country of residence and nationality. Some posts are restricted to sole UK Nationals for security reasons; therefore, you may be asked about your citizenship in the application process. Hybrid working: The places that you work from day to day will vary according to your role, your needs, and those of the business; it will be a blend of Company offices, client sites, and your home; noting that you will be unable to work at home 100% of the time. If you are successfully offered this position, you will go through a series of pre-employment checks, including identity, nationality (single or dual) or immigration status, employment history going back three continuous years, and unspent criminal record check (known as Disclosure and Barring Service) What we will offer you You will be encouraged to have a positive work-life balance. Our hybrid-first way of working means we embed hybrid working in all that we do and make flexible working arrangements the day-to-day reality for our people. All UK employees are eligible to request flexible working arrangements. You will be empowered to explore, innovate, and progress. You will benefit from Capgemini's 'learning for life' mindset, meaning you will have countless training and development opportunities from thinktanks to hackathons, and access to 250,000 courses with numerous external certifications from AWS, Microsoft, Harvard Manage Mentor, Cybersecurity qualifications and much more. Why we are different At Capgemini, we help organisations across the world become more agile, more competitive, and more successful. Smart, tailored, often ground-breaking technical solutions to complex problems are the norm. But so, too, is a culture that is as collaborative as it is forward thinking. Working closely with each other, and with our clients, we get under the skin of businesses and to the heart of their goals. You will too. Capgemini is proud to represent nearly 130 nationalities and its cultural diversity. Our holistic definition of diversity extends beyond gender, gender identity, sexual orientation, disability, ethnicity, race, age, and religion. Capgemini views diversity as everything that makes us who we are as an organization, including our social background, our experiences in life and work, our communication styles and even our personality. These dimensions contribute to the type of diversity we value the most: diversity of thought. Who you will be working with You will join the Data Trust Capability in Capgemini's Insights and Data (I&D) business unit. Insights and Data is a global business unit covering Enterprise Data Management, Cloud Platforms, Enterprise Content Management and AI & Analytics. Our team is one of the largest and most successful Data Management teams in the UK delivering innovative Data Management and Governance thought leadership to our clients. The Enterprise Data Management provides services on Information Strategy, Data Governance, Master Data Management, Data Architecture, Data Migration and Lifecycle Management. We help our clients build an enterprise-class data platform that allows them to move ahead in their journey of data and insights. Primarily working with leading software vendors like SAP, Informatica, IBM, Oracle et al, the team are primarily Consultants, putting client requirements and industry best practices at the heart of delivery. The focus of your role Configure and maintain Microsoft Purview features, including: Information Protection (sensitivity labels, auto-labelling), Data Loss Prevention (M365, Endpoint, Cloud Apps), Data Governance (catalogue, scanning, classification), Records Management (retention labels & policies), Insider Risk Management, eDiscovery (Standard & Premium) Manage scanning rules, data connectors, metadata sources, and catalog assets. Support integration with M365, Azure, Power Platform, and on premises data sources Monitor Purview alerts, DLP incidents, policy matches, and governance activity logs Perform investigation of policy violations, insider risk alerts, and data protection events Track and escape issues to engineering or architecture teams as required Maintain audit trails, compliance dashboards, and monthly reporting Assist with maintaining data classification schemas, taxonomy, and metadata models Support data owners and stewards in cataloguing and tagging data assets Run data scans, quality checks, and lineage validation tasks Produce and maintain operational runbooks, configuration documentation, and governance processes Create user guides for end users, compliance officers, and IT support teams Document incident response processes related to Purview alerts Work closely with Compliance, Security, Data Governance, and IT teams to implement policies into Purview Support end users by troubleshooting classification, labelling, and access issues Provide training sessions and knowledge transfer on Purview features Identify gaps in data governance and compliance processes; recommend improvements You may also offer insights to the wider community through blogs, articles, and social media. At Capgemini, we believe in bringing your whole self to work. Equity, diversity, and inclusion are woven into our everyday culture, creating a welcoming and supportive environment for everyone. What You Will Bring As a Technical Purview Analyst, you will have 7 years plus experience in data governance, security, compliance, or Microsoft 365 administration. You will have hands on experience with Microsoft Purview or related compliance/security platforms, with exposure to operational support, incident management, or compliance monitoring. Experience Microsoft Purview Information Protection - labels, policies, auto labelling, encryption Data Loss Prevention - endpoint, SharePoint/OneDrive/Teams, Exchange, cloud apps Purview Data Governance - cataloguing, scanning, metadata management Records Management & Retention Labelling eDiscovery workflows and case management Defender for Cloud Apps Wider integration with SharePoint, OneDrive, Exchange, Azure Storage, SQL, Synapse, Data Factory, and Power BI Understanding of classification, metadata, and governance principles Knowledge of Microsoft 365 security & compliance capabilities Basic understanding of Azure Active Directory / Entra ID identity and access concepts Familiarity with ITSM/incident management processes Understanding of regulatory compliance basics How compliance and data protection teams use Purview outputs Data sensitivity models and how they map to business processes Governance best practices, including cataloguing and lineage use cases Ability to configure and manage Purview policies and scanning tools Strong analytical and troubleshooting skills Familiarity with KQL, PowerShell, or Microsoft Graph Ability to interpret logs, alerts, and governance reporting Strong documentation and verbal communication skills Ability to work collaboratively with cross functional teams Good organisational and time management abilities Certifications (Desirable)
Cadeler
IT Governance Analyst - Offshore Wind Industry
Cadeler Norwich, Norfolk
IT Governance Analyst - Offshore Wind Industry Location: Copenhagen HQ, Norwich, Vejle Salary : Competitive Vacancy Type: Permanent, Full Time Are you passionate about IT governance, cyber security, risk management, and building structured, compliant processes that strengthen organizational resilience? Do you want to work in the offshore wind industry where your skills and expertise will help secure a sustainable future based on renewable energy? Then keep reading - Cadeler is looking for a IT Governance Analyst with your skills and interests! Cadeler is a global partner in the offshore wind industry, specializing in wind farm construction and maintenance. We are part of an industry that is now, more than ever, both relevant and play a critical role in the energy transition with a strong long-term outlook. As our industry continues to develop, so do we! What will you do? As our new IT Governance Analyst, you will support and strengthen our IT governance, cyber security, and risk management framework. You will help structure and maintain IT risk and control processes, support audits and reporting activities, and contribute to improving how compliance and security information is managed across the organization. Your main tasks include: Supporting and maturing the IT governance and cyber security processes aligned with NIS2 requirements Maintaining and structuring the IT Risk & Control Matrix (RCM) and IT risk register Supporting IT risk assessments and Business Impact Analysis (BIA) activities Ensuring risks, controls, and documentation are maintained in a clear and audit-ready manner Collaborating with IT suppliers on security-related matters and client security assessments Contributing to reporting on IT risk, governance, and cyber security posture Identifying opportunities to simplify, standardize, and automate governance and compliance processes Supporting continuous improvement of IT risk and compliance frameworks across the organization To succeed in this role Being part of the Cadeler community means you will have a natural interest and care for the environment and our shared mission to speed up the green energy transition. Your environmental considerations and the safety of our people and the planet will be a key priority in your daily work. We are looking for a structured and solution-oriented profile, who is curious, detail-oriented, and motivated to support and improve IT governance and cyber security processes across the organization. We think you will be a good match if you: Hold a relevant educational background within IT, Information Security, Governance, Risk Management, or similar Have around 1-3 years of experience within cyber security, IT risk, compliance, or governance-related areas Have knowledge of security frameworks and regulations such as ISO 27001, NIST, CIS18 Controls, NIS2, GDPR, or similar Are comfortable working with Microsoft tools such as M365, SharePoint, Power BI, Purview, and Azure environments Have an interest in process improvement, data structuring, and automation Communicate clearly and professionally in English, both written and spoken It is considered an advantage if you have experience with supplier risk assessments, automation tools such as Power Automate, or knowledge of maritime and OT environments. Come work with us! By becoming a Cadeler employee, you will be part of a rapidly growing company with a diverse and energetic team. We offer an exciting position focused on delivering excellence in the face of interesting new challenges, within a positive and rewarding work environment in an international company with great development possibilities. Cadeler is headquartered in Copenhagen, but we also have offices in Vejle, UK, US, and Taiwan, as well as colleagues working offshore aboard our fleet of Wind Farm Installation Vessels (WFIV). To Apply If you feel you are a suitable candidate and would like to work for Cadeler, please click apply to be redirected to their website to complete your application.
Jun 01, 2026
Full time
IT Governance Analyst - Offshore Wind Industry Location: Copenhagen HQ, Norwich, Vejle Salary : Competitive Vacancy Type: Permanent, Full Time Are you passionate about IT governance, cyber security, risk management, and building structured, compliant processes that strengthen organizational resilience? Do you want to work in the offshore wind industry where your skills and expertise will help secure a sustainable future based on renewable energy? Then keep reading - Cadeler is looking for a IT Governance Analyst with your skills and interests! Cadeler is a global partner in the offshore wind industry, specializing in wind farm construction and maintenance. We are part of an industry that is now, more than ever, both relevant and play a critical role in the energy transition with a strong long-term outlook. As our industry continues to develop, so do we! What will you do? As our new IT Governance Analyst, you will support and strengthen our IT governance, cyber security, and risk management framework. You will help structure and maintain IT risk and control processes, support audits and reporting activities, and contribute to improving how compliance and security information is managed across the organization. Your main tasks include: Supporting and maturing the IT governance and cyber security processes aligned with NIS2 requirements Maintaining and structuring the IT Risk & Control Matrix (RCM) and IT risk register Supporting IT risk assessments and Business Impact Analysis (BIA) activities Ensuring risks, controls, and documentation are maintained in a clear and audit-ready manner Collaborating with IT suppliers on security-related matters and client security assessments Contributing to reporting on IT risk, governance, and cyber security posture Identifying opportunities to simplify, standardize, and automate governance and compliance processes Supporting continuous improvement of IT risk and compliance frameworks across the organization To succeed in this role Being part of the Cadeler community means you will have a natural interest and care for the environment and our shared mission to speed up the green energy transition. Your environmental considerations and the safety of our people and the planet will be a key priority in your daily work. We are looking for a structured and solution-oriented profile, who is curious, detail-oriented, and motivated to support and improve IT governance and cyber security processes across the organization. We think you will be a good match if you: Hold a relevant educational background within IT, Information Security, Governance, Risk Management, or similar Have around 1-3 years of experience within cyber security, IT risk, compliance, or governance-related areas Have knowledge of security frameworks and regulations such as ISO 27001, NIST, CIS18 Controls, NIS2, GDPR, or similar Are comfortable working with Microsoft tools such as M365, SharePoint, Power BI, Purview, and Azure environments Have an interest in process improvement, data structuring, and automation Communicate clearly and professionally in English, both written and spoken It is considered an advantage if you have experience with supplier risk assessments, automation tools such as Power Automate, or knowledge of maritime and OT environments. Come work with us! By becoming a Cadeler employee, you will be part of a rapidly growing company with a diverse and energetic team. We offer an exciting position focused on delivering excellence in the face of interesting new challenges, within a positive and rewarding work environment in an international company with great development possibilities. Cadeler is headquartered in Copenhagen, but we also have offices in Vejle, UK, US, and Taiwan, as well as colleagues working offshore aboard our fleet of Wind Farm Installation Vessels (WFIV). To Apply If you feel you are a suitable candidate and would like to work for Cadeler, please click apply to be redirected to their website to complete your application.
Solus Accident Repair Centres
IT Governance Risk and Compliance Analyst
Solus Accident Repair Centres Birchanger, Hertfordshire
Overview At Solus, we are strengthening our technology governance and cyber resilience as we continue to grow. We are looking for an IT Governance, Risk and Compliance (GRC) Analyst to help us maintain a secure, well governed and compliant technology environment across the business. This is a great role for someone who enjoys analysing detail, challenging constructively, influencing stakeholders and helping teams make confident, risk-based decisions. About the role As our IT GRC Analyst, you will support the Cyber Security, Risk and Assurance function with a mixture of governance activity, assurance reviews, supplier assessments and compliance oversight. You will help us meet Aviva Group requirements, regulatory expectations and industry standards while ensuring our technology risks are understood and well managed. Location: Hybrid (Stansted - 3 days per week, 2 days remote) Responsibilities Maintain and improve our IT risk register, ensuring risks are clear, evidenced and tracked Support risk owners with guidance on controls, remediation and governance requirements Complete compliance reviews, control testing and assurance activities Produce risk and compliance reporting for leadership forums Carry out supplier assurance assessments, recommend improvements and escalate risk where needed Keep IT policies and standards up to date and aligned with Aviva and recognised frameworks Provide clear insight to non technical colleagues on risk, controls and potential impacts Support Group assurance activity and represent Solus in relevant forums This is an individual contributor role with a high level of ownership and plenty of opportunity to influence how we operate. Qualifications You will thrive in this role if you have: Knowledge of GRC frameworks such as ISO 27001, NIST CSF, Cyber Essentials or DPA Experience in risk management, governance or cyber/security assurance The ability to analyse complex information and turn it into clear, meaningful insight Confidence challenging and advising colleagues at all levels Strong communication and stakeholder management skills Certifications such as CISM, CRISC or CGRC are desirable but not essential. Who are Solus? Solus, who are owned by Aviva, are one of the UK leaders in vehicle repairs, returning cars to the road in just 11 days on average and a 4.6/5 star customer rating. With an award-winning apprenticeship programme and winners of other recognised industry awards Solus are proud to be shaping the future of vehicle repair. Why Join Solus? We have so much to offer when it comes to being a Solus colleague: Competitive salary based on location, skills, experience, and qualifications. Bonus opportunity tied to your performance and the overall success of Solus. Company pension scheme with employer contributions. 33 days' holiday (including bank holidays), with the option to buy or sell up to 5 days. Save money with up to 40% discount on Aviva products and other retailer discounts. Share in Aviva's success through the Aviva Save As You Earn scheme. Supportive policies including parental and carer's leave. Wellbeing focus with tools like Group Income Protection and 24/7 GP access. At Solus, we value inclusivity and welcome all applicants. If you're excited but don't tick every box, we encourage you to apply-your unique skills might be just what we need. We guarantee an interview for disabled applicants meeting the minimum criteria-just email us after applying to let us know. Ready to join us? Apply online today, and our team will be in touch within 14 days.
May 31, 2026
Full time
Overview At Solus, we are strengthening our technology governance and cyber resilience as we continue to grow. We are looking for an IT Governance, Risk and Compliance (GRC) Analyst to help us maintain a secure, well governed and compliant technology environment across the business. This is a great role for someone who enjoys analysing detail, challenging constructively, influencing stakeholders and helping teams make confident, risk-based decisions. About the role As our IT GRC Analyst, you will support the Cyber Security, Risk and Assurance function with a mixture of governance activity, assurance reviews, supplier assessments and compliance oversight. You will help us meet Aviva Group requirements, regulatory expectations and industry standards while ensuring our technology risks are understood and well managed. Location: Hybrid (Stansted - 3 days per week, 2 days remote) Responsibilities Maintain and improve our IT risk register, ensuring risks are clear, evidenced and tracked Support risk owners with guidance on controls, remediation and governance requirements Complete compliance reviews, control testing and assurance activities Produce risk and compliance reporting for leadership forums Carry out supplier assurance assessments, recommend improvements and escalate risk where needed Keep IT policies and standards up to date and aligned with Aviva and recognised frameworks Provide clear insight to non technical colleagues on risk, controls and potential impacts Support Group assurance activity and represent Solus in relevant forums This is an individual contributor role with a high level of ownership and plenty of opportunity to influence how we operate. Qualifications You will thrive in this role if you have: Knowledge of GRC frameworks such as ISO 27001, NIST CSF, Cyber Essentials or DPA Experience in risk management, governance or cyber/security assurance The ability to analyse complex information and turn it into clear, meaningful insight Confidence challenging and advising colleagues at all levels Strong communication and stakeholder management skills Certifications such as CISM, CRISC or CGRC are desirable but not essential. Who are Solus? Solus, who are owned by Aviva, are one of the UK leaders in vehicle repairs, returning cars to the road in just 11 days on average and a 4.6/5 star customer rating. With an award-winning apprenticeship programme and winners of other recognised industry awards Solus are proud to be shaping the future of vehicle repair. Why Join Solus? We have so much to offer when it comes to being a Solus colleague: Competitive salary based on location, skills, experience, and qualifications. Bonus opportunity tied to your performance and the overall success of Solus. Company pension scheme with employer contributions. 33 days' holiday (including bank holidays), with the option to buy or sell up to 5 days. Save money with up to 40% discount on Aviva products and other retailer discounts. Share in Aviva's success through the Aviva Save As You Earn scheme. Supportive policies including parental and carer's leave. Wellbeing focus with tools like Group Income Protection and 24/7 GP access. At Solus, we value inclusivity and welcome all applicants. If you're excited but don't tick every box, we encourage you to apply-your unique skills might be just what we need. We guarantee an interview for disabled applicants meeting the minimum criteria-just email us after applying to let us know. Ready to join us? Apply online today, and our team will be in touch within 14 days.
Senior Technology Risk & AI Governance Analyst
Pacific Asset Management, LLC
Senior Technology Risk AnalystApplylocations: London, UKtime type: Full timeposted on: Posted Todayjob requisition id: R17061 Job Title Senior Technology Risk Analyst Job Description We collaborate with clients across Europe, Asia, Australia and North America, specialising in risks associated with Life, Critical Illness, Income Protection, Hospital Cash and Longevity products. Our clients are insurance or reinsurance companies looking for a new and innovative approach to taking risks.With the security and financial strength of a parent company that has been around for over 145 years and a mutual holding company as our ultimate parent, we are not constrained by short-term thinking; therefore, allowing us to be free to pursue the right course for our clients and our business.Underlying our philosophy is an intelligent approach to taking risks. By recruiting top quality staff and investing in the latest analytical technologies, we believe we are well placed to make those decisions. The Role We have an exciting permanent opportunity available within the Division Centre Technology Risk team, based out of our London office.This role is suited to an experienced professional seeking to deepen their expertise in Technology Risk within a global organisation. You will play a key role in delivering risk management activities, providing subject matter expertise, and driving improvements across technology, risk frameworks, and emerging areas such as AI.Primary responsibilities will include providing technology risk subject matter expertise, support and guidance to the global Technology team, specifically:• Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Analyse and manage incidents and operational events, identify root causes and systemic control weaknesses using data analytics, and drive action plans to completion with effective monitoring, escalation, and senior management reporting, focusing on optimisation and efficiency. • Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Helping to define and maintain key risk indicators, including exploring automated data feeds and AI-driven insights, assisting in the preparation of reporting to divisional senior Technology management, Operational Risk & Resilience, and the Operational Risk Management Committee. • Participating in working groups on specific technology risk topics (e.g. cyber, IT asset management, data management and governance), including the safe adoption of emerging technologies such as AI. • Providing SME input and support to the Technology team with regards to risks, issues and operational events logged in our GRC platform, including opportunities to enhance data quality and workflow automation. • Supporting Technology by acting as a point of contact and "bridge" between them and other lines of defence, such as Operational Risk, Internal Audit, and External Audit. • Driving the modernisation of technology risk processes through the use of automation, data analytics and AI-enabled solutions (e.g. process automation, intelligent risk assessments, enhanced reporting). • Identifying opportunities to improve efficiency, scalability and consistency of risk processes, and supporting the design and implementation of solutions where appropriate. • Supporting client engagement teams through responding to technical due diligence requests from current and potential clients. • Performing risk assessments of new technologies entering the environment, including AI/ML solutions, ensuring that risks are identified and appropriate controls are in place. Skills, Knowledge & Experience Required- Minimum 4 years' experience of working within a risk / audit function - A solid understanding of current technology capabilities, including AI/ML concepts and their associated risks, and a keen interest in staying abreast of emerging technology trends (e.g. AI, automation, quantum computing). - Knowledge of and experience of implementing leading Technology risk framework and practices e.g. ISO27001, COBIT, NIST and supporting methodologies. - Experience or demonstrable interest in applying data analytics, automation, or AI tools to improve risk management processes and reporting. - Ability to manage own time and to work to strict deadlines - Strong organisational, analytical and stakeholder management skills - Detail oriented and well-organised with ability to work independently - Experienced in collaborating at all levels of an enterprise - Effective written and verbal communication from technical team direction to senior management presentations - Experience with undertaking RCSA or similar risk and controls assessments / audits - Creativity and initiative in work product, positive and helpful attitude proposing solutions to resolve problems - Ability to work flexibly to support colleagues that operate out of multiple locations / time-zones - Proficiency in using standard work environment software, such as Microsoft Office Suite Desired - Risk/IT professional certification such as CISA, CRISC, CPA, CISM, Six Sigma - Experience of working within the Insurance / Reinsurance industries - Degree within an IT related or similar discipline - Understanding of GRC platforms (e.g. Archer) - Comfortable operating in a dynamic, evolving environment with competing priorities - Confidence working with incomplete information and forming reasoned risk based conclusions - Experience applying judgement over checklist driven compliance, with an ability to prioritise risk proportionately - Exposure to AI governance, model risk management, or emerging regulatory expectations relating to AI Working For Pacific Life Re Every person in our global team is valued for the unique qualities they bring to our business and we seek to build their expertise and support their individual ambitions at every step. Of course, we take our work seriously and we know our team can operate under great pressure. We work hard and thrive on achievement, but we also know how to have fun and relax too. We regularly host a range of team building days to strengthen our team's connection with each other and reflect on their successes.Providing employees with a healthy work-life balance is very important to our culture. We have a wide range of employee benefits and we host regular social activities and well being initiatives. We are also committed to supporting our employee's involvement in their communities, by actively fundraising, hosting charity events and overseeing volunteering opportunities. Benefits (Only for Permanent and Fixed Term Employees) Leave 25 days of annual leave with option to buy/sell more days Adoption and fertility leave Generous enhanced parental leaveHealthcare Comprehensive private insurance coverage for employee and dependents Group Life Insurance coverage of 9x basic annual salary and Group Income Protection up to 75% of basic annual salary Optical benefitsSavings & Retirement 15% combined employee/employer contributionsWellness Subsidized gym membership Access to Employee Assistance Program Cycle to Work and Electric Car Salary Sacrifice Scheme Time off for volunteering Charitable matching of employee donations You Can Be Who You Are We are committed to a culture of diversity and inclusion that embraces the authenticity of all employees, partners and communities. We support all employees to thrive and achieve their fullest potential.As part of our commitment to diversity and inclusion, we will provide reasonable adjustments during the recruitment process to ensure equal access to applicants with disabilities. Please contact us about your needs so that we can discuss these with you to make sure that suitable adjustments are made, where possible. Pacific Life Re Values Please click here to view our company values
May 29, 2026
Full time
Senior Technology Risk AnalystApplylocations: London, UKtime type: Full timeposted on: Posted Todayjob requisition id: R17061 Job Title Senior Technology Risk Analyst Job Description We collaborate with clients across Europe, Asia, Australia and North America, specialising in risks associated with Life, Critical Illness, Income Protection, Hospital Cash and Longevity products. Our clients are insurance or reinsurance companies looking for a new and innovative approach to taking risks.With the security and financial strength of a parent company that has been around for over 145 years and a mutual holding company as our ultimate parent, we are not constrained by short-term thinking; therefore, allowing us to be free to pursue the right course for our clients and our business.Underlying our philosophy is an intelligent approach to taking risks. By recruiting top quality staff and investing in the latest analytical technologies, we believe we are well placed to make those decisions. The Role We have an exciting permanent opportunity available within the Division Centre Technology Risk team, based out of our London office.This role is suited to an experienced professional seeking to deepen their expertise in Technology Risk within a global organisation. You will play a key role in delivering risk management activities, providing subject matter expertise, and driving improvements across technology, risk frameworks, and emerging areas such as AI.Primary responsibilities will include providing technology risk subject matter expertise, support and guidance to the global Technology team, specifically:• Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Analyse and manage incidents and operational events, identify root causes and systemic control weaknesses using data analytics, and drive action plans to completion with effective monitoring, escalation, and senior management reporting, focusing on optimisation and efficiency. • Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Helping to define and maintain key risk indicators, including exploring automated data feeds and AI-driven insights, assisting in the preparation of reporting to divisional senior Technology management, Operational Risk & Resilience, and the Operational Risk Management Committee. • Participating in working groups on specific technology risk topics (e.g. cyber, IT asset management, data management and governance), including the safe adoption of emerging technologies such as AI. • Providing SME input and support to the Technology team with regards to risks, issues and operational events logged in our GRC platform, including opportunities to enhance data quality and workflow automation. • Supporting Technology by acting as a point of contact and "bridge" between them and other lines of defence, such as Operational Risk, Internal Audit, and External Audit. • Driving the modernisation of technology risk processes through the use of automation, data analytics and AI-enabled solutions (e.g. process automation, intelligent risk assessments, enhanced reporting). • Identifying opportunities to improve efficiency, scalability and consistency of risk processes, and supporting the design and implementation of solutions where appropriate. • Supporting client engagement teams through responding to technical due diligence requests from current and potential clients. • Performing risk assessments of new technologies entering the environment, including AI/ML solutions, ensuring that risks are identified and appropriate controls are in place. Skills, Knowledge & Experience Required- Minimum 4 years' experience of working within a risk / audit function - A solid understanding of current technology capabilities, including AI/ML concepts and their associated risks, and a keen interest in staying abreast of emerging technology trends (e.g. AI, automation, quantum computing). - Knowledge of and experience of implementing leading Technology risk framework and practices e.g. ISO27001, COBIT, NIST and supporting methodologies. - Experience or demonstrable interest in applying data analytics, automation, or AI tools to improve risk management processes and reporting. - Ability to manage own time and to work to strict deadlines - Strong organisational, analytical and stakeholder management skills - Detail oriented and well-organised with ability to work independently - Experienced in collaborating at all levels of an enterprise - Effective written and verbal communication from technical team direction to senior management presentations - Experience with undertaking RCSA or similar risk and controls assessments / audits - Creativity and initiative in work product, positive and helpful attitude proposing solutions to resolve problems - Ability to work flexibly to support colleagues that operate out of multiple locations / time-zones - Proficiency in using standard work environment software, such as Microsoft Office Suite Desired - Risk/IT professional certification such as CISA, CRISC, CPA, CISM, Six Sigma - Experience of working within the Insurance / Reinsurance industries - Degree within an IT related or similar discipline - Understanding of GRC platforms (e.g. Archer) - Comfortable operating in a dynamic, evolving environment with competing priorities - Confidence working with incomplete information and forming reasoned risk based conclusions - Experience applying judgement over checklist driven compliance, with an ability to prioritise risk proportionately - Exposure to AI governance, model risk management, or emerging regulatory expectations relating to AI Working For Pacific Life Re Every person in our global team is valued for the unique qualities they bring to our business and we seek to build their expertise and support their individual ambitions at every step. Of course, we take our work seriously and we know our team can operate under great pressure. We work hard and thrive on achievement, but we also know how to have fun and relax too. We regularly host a range of team building days to strengthen our team's connection with each other and reflect on their successes.Providing employees with a healthy work-life balance is very important to our culture. We have a wide range of employee benefits and we host regular social activities and well being initiatives. We are also committed to supporting our employee's involvement in their communities, by actively fundraising, hosting charity events and overseeing volunteering opportunities. Benefits (Only for Permanent and Fixed Term Employees) Leave 25 days of annual leave with option to buy/sell more days Adoption and fertility leave Generous enhanced parental leaveHealthcare Comprehensive private insurance coverage for employee and dependents Group Life Insurance coverage of 9x basic annual salary and Group Income Protection up to 75% of basic annual salary Optical benefitsSavings & Retirement 15% combined employee/employer contributionsWellness Subsidized gym membership Access to Employee Assistance Program Cycle to Work and Electric Car Salary Sacrifice Scheme Time off for volunteering Charitable matching of employee donations You Can Be Who You Are We are committed to a culture of diversity and inclusion that embraces the authenticity of all employees, partners and communities. We support all employees to thrive and achieve their fullest potential.As part of our commitment to diversity and inclusion, we will provide reasonable adjustments during the recruitment process to ensure equal access to applicants with disabilities. Please contact us about your needs so that we can discuss these with you to make sure that suitable adjustments are made, where possible. Pacific Life Re Values Please click here to view our company values
Universal Music Group
IAM Analyst: Identity & Access Security Specialist
Universal Music Group
IAM AnalystApplylocations: Kings Cross, Londontime type: Full timeposted on: Posted 8 Days Agojob requisition id: UMG-23757Music is Universal It's the passionate and dedicated team at Universal Music who help make us the world's leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email . Job Summary: We are UMG, the Universal Music Group. We are the world's leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world.We are currently seeking an IAM Analyst to join our Global Tech Security team. The ideal candidate will have exposure across the Identity & Access Management (IAM) stack. Primary focus will be on providing data analysis and reporting on enterprise-grade solutions across Privileged Access Management (PAM), Identity Governance and Administration (IGA), Public Key Infrastructure (PKI), Directory Services, Federation, and more. This role requires a combination of strong communication and critical thinking skills with strong attention to detail. Job Functions: Research and provide data analyst for IAM tools across the enterprise including CyberArk, Ping DaVinci, Microsoft EntraID (formerly Azure AD), HashiCorp Vault, Digicert, and Saviynt. Support the implementation and enhancement of IAM services including: - SSO/Federation (SAML, OIDC, WS-Fed) - MFA/Passwordless - Privileged Access Management (PAM) - Identity Governance (IGA) - PKI and certificate lifecycle automation - Directory services (AD, EntraID). Track automation scripts and integrations for IAM workflows using tools such as PowerShell, Python, or Terraform. Communicate design and implement access controls and policies that align with security and compliance standards (SOX, GDPR, etc.). Evaluate AI-powered tools and methodologies to improve identity lifecycle efficiency, risk detection, and operational decision-making. Participate in lifecycle management processes for accounts, credentials, roles, and policies across systems and applications. Collaborate with InfoSec, Infrastructure, and App teams to ensure secure identity architecture for on-prem and cloud environments. Maintain high-quality documentation and architectural diagrams. Monitor and report metrics on IAM system performance, adoption, and audit readiness. Job Requirements: Essential Qualifications 2+ years of experience in IAM engineering teams. Some proficiency of technical expertise in one or more of the following: CyberArk, Ping Identity, Microsoft EntraID, Saviynt, HashiCorp Vault, Digicert, Onfido. Understanding of IAM protocols and standards: SAML, OIDC, OAuth2, LDAP, Kerberos, SCIM, JIT. Familiarity with cloud platforms (Azure, AWS, GCP) and IAM integrations. Proven ability to work independently and cross-functionally in a global team. Strong troubleshooting, documentation, and communication skills. Strong communication skills for both technical details and business acumen.Desirable Bachelor's Degree in Computer Science, Engineering, or a related technical field. Professional certifications such as: CISSP, Security+, Microsoft Certified: Identity and Access Administrator, CyberArk Defender, Ping Identity Certified Professional. Experience with AI/ML integration into IAM workflows or security analytics. Experience supporting IAM functions in media or entertainment industry environments. Experience working on a global team covering multiple time zones.Just So You Know The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder's specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.
May 29, 2026
Full time
IAM AnalystApplylocations: Kings Cross, Londontime type: Full timeposted on: Posted 8 Days Agojob requisition id: UMG-23757Music is Universal It's the passionate and dedicated team at Universal Music who help make us the world's leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email . Job Summary: We are UMG, the Universal Music Group. We are the world's leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world.We are currently seeking an IAM Analyst to join our Global Tech Security team. The ideal candidate will have exposure across the Identity & Access Management (IAM) stack. Primary focus will be on providing data analysis and reporting on enterprise-grade solutions across Privileged Access Management (PAM), Identity Governance and Administration (IGA), Public Key Infrastructure (PKI), Directory Services, Federation, and more. This role requires a combination of strong communication and critical thinking skills with strong attention to detail. Job Functions: Research and provide data analyst for IAM tools across the enterprise including CyberArk, Ping DaVinci, Microsoft EntraID (formerly Azure AD), HashiCorp Vault, Digicert, and Saviynt. Support the implementation and enhancement of IAM services including: - SSO/Federation (SAML, OIDC, WS-Fed) - MFA/Passwordless - Privileged Access Management (PAM) - Identity Governance (IGA) - PKI and certificate lifecycle automation - Directory services (AD, EntraID). Track automation scripts and integrations for IAM workflows using tools such as PowerShell, Python, or Terraform. Communicate design and implement access controls and policies that align with security and compliance standards (SOX, GDPR, etc.). Evaluate AI-powered tools and methodologies to improve identity lifecycle efficiency, risk detection, and operational decision-making. Participate in lifecycle management processes for accounts, credentials, roles, and policies across systems and applications. Collaborate with InfoSec, Infrastructure, and App teams to ensure secure identity architecture for on-prem and cloud environments. Maintain high-quality documentation and architectural diagrams. Monitor and report metrics on IAM system performance, adoption, and audit readiness. Job Requirements: Essential Qualifications 2+ years of experience in IAM engineering teams. Some proficiency of technical expertise in one or more of the following: CyberArk, Ping Identity, Microsoft EntraID, Saviynt, HashiCorp Vault, Digicert, Onfido. Understanding of IAM protocols and standards: SAML, OIDC, OAuth2, LDAP, Kerberos, SCIM, JIT. Familiarity with cloud platforms (Azure, AWS, GCP) and IAM integrations. Proven ability to work independently and cross-functionally in a global team. Strong troubleshooting, documentation, and communication skills. Strong communication skills for both technical details and business acumen.Desirable Bachelor's Degree in Computer Science, Engineering, or a related technical field. Professional certifications such as: CISSP, Security+, Microsoft Certified: Identity and Access Administrator, CyberArk Defender, Ping Identity Certified Professional. Experience with AI/ML integration into IAM workflows or security analytics. Experience supporting IAM functions in media or entertainment industry environments. Experience working on a global team covering multiple time zones.Just So You Know The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder's specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.
Senior Information Security Analyst
Circle Group
Senior Information Security Analyst Birmingham (Hybrid) Starting Salary £50-75k We are seeking a motivated individual to join our client's growing cyber team, supporting the delivery of an expanding portfolio of cyber governance, risk, and advisory services. This role offers excellent exposure to a wide range of cybersecurity, risk management, and business operations activities, working alongside e click apply for full job details
May 29, 2026
Full time
Senior Information Security Analyst Birmingham (Hybrid) Starting Salary £50-75k We are seeking a motivated individual to join our client's growing cyber team, supporting the delivery of an expanding portfolio of cyber governance, risk, and advisory services. This role offers excellent exposure to a wide range of cybersecurity, risk management, and business operations activities, working alongside e click apply for full job details
Senior Technology Risk Analyst
Pacific Asset Management, LLC
Senior Technology Risk AnalystApplylocations: London, UKtime type: Full timeposted on: Posted Todayjob requisition id: R17061 Job Title Senior Technology Risk Analyst Job Description We collaborate with clients across Europe, Asia, Australia and North America, specialising in risks associated with Life, Critical Illness, Income Protection, Hospital Cash and Longevity products. Our clients are insurance or reinsurance companies looking for a new and innovative approach to taking risks.With the security and financial strength of a parent company that has been around for over 145 years and a mutual holding company as our ultimate parent, we are not constrained by short-term thinking; therefore, allowing us to be free to pursue the right course for our clients and our business.Underlying our philosophy is an intelligent approach to taking risks. By recruiting top quality staff and investing in the latest analytical technologies, we believe we are well placed to make those decisions. The Role We have an exciting permanent opportunity available within the Division Centre Technology Risk team, based out of our London office.This role is suited to an experienced professional seeking to deepen their expertise in Technology Risk within a global organisation. You will play a key role in delivering risk management activities, providing subject matter expertise, and driving improvements across technology, risk frameworks, and emerging areas such as AI.Primary responsibilities will include providing technology risk subject matter expertise, support and guidance to the global Technology team, specifically:• Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Analyse and manage incidents and operational events, identify root causes and systemic control weaknesses using data analytics, and drive action plans to completion with effective monitoring, escalation, and senior management reporting, focusing on optimisation and efficiency. • Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Helping to define and maintain key risk indicators, including exploring automated data feeds and AI-driven insights, assisting in the preparation of reporting to divisional senior Technology management, Operational Risk & Resilience, and the Operational Risk Management Committee. • Participating in working groups on specific technology risk topics (e.g. cyber, IT asset management, data management and governance), including the safe adoption of emerging technologies such as AI. • Providing SME input and support to the Technology team with regards to risks, issues and operational events logged in our GRC platform, including opportunities to enhance data quality and workflow automation. • Supporting Technology by acting as a point of contact and "bridge" between them and other lines of defence, such as Operational Risk, Internal Audit, and External Audit. • Driving the modernisation of technology risk processes through the use of automation, data analytics and AI-enabled solutions (e.g. process automation, intelligent risk assessments, enhanced reporting). • Identifying opportunities to improve efficiency, scalability and consistency of risk processes, and supporting the design and implementation of solutions where appropriate. • Supporting client engagement teams through responding to technical due diligence requests from current and potential clients. • Performing risk assessments of new technologies entering the environment, including AI/ML solutions, ensuring that risks are identified and appropriate controls are in place. Skills, Knowledge & Experience Required- Minimum 4 years' experience of working within a risk / audit function - A solid understanding of current technology capabilities, including AI/ML concepts and their associated risks, and a keen interest in staying abreast of emerging technology trends (e.g. AI, automation, quantum computing). - Knowledge of and experience of implementing leading Technology risk framework and practices e.g. ISO27001, COBIT, NIST and supporting methodologies. - Experience or demonstrable interest in applying data analytics, automation, or AI tools to improve risk management processes and reporting. - Ability to manage own time and to work to strict deadlines - Strong organisational, analytical and stakeholder management skills - Detail oriented and well-organised with ability to work independently - Experienced in collaborating at all levels of an enterprise - Effective written and verbal communication from technical team direction to senior management presentations - Experience with undertaking RCSA or similar risk and controls assessments / audits - Creativity and initiative in work product, positive and helpful attitude proposing solutions to resolve problems - Ability to work flexibly to support colleagues that operate out of multiple locations / time-zones - Proficiency in using standard work environment software, such as Microsoft Office Suite Desired - Risk/IT professional certification such as CISA, CRISC, CPA, CISM, Six Sigma - Experience of working within the Insurance / Reinsurance industries - Degree within an IT related or similar discipline - Understanding of GRC platforms (e.g. Archer) - Comfortable operating in a dynamic, evolving environment with competing priorities - Confidence working with incomplete information and forming reasoned risk based conclusions - Experience applying judgement over checklist driven compliance, with an ability to prioritise risk proportionately - Exposure to AI governance, model risk management, or emerging regulatory expectations relating to AI Working For Pacific Life Re Every person in our global team is valued for the unique qualities they bring to our business and we seek to build their expertise and support their individual ambitions at every step. Of course, we take our work seriously and we know our team can operate under great pressure. We work hard and thrive on achievement, but we also know how to have fun and relax too. We regularly host a range of team building days to strengthen our team's connection with each other and reflect on their successes.Providing employees with a healthy work-life balance is very important to our culture. We have a wide range of employee benefits and we host regular social activities and well being initiatives. We are also committed to supporting our employee's involvement in their communities, by actively fundraising, hosting charity events and overseeing volunteering opportunities. Benefits (Only for Permanent and Fixed Term Employees) Leave 25 days of annual leave with option to buy/sell more days Adoption and fertility leave Generous enhanced parental leaveHealthcare Comprehensive private insurance coverage for employee and dependents Group Life Insurance coverage of 9x basic annual salary and Group Income Protection up to 75% of basic annual salary Optical benefitsSavings & Retirement 15% combined employee/employer contributionsWellness Subsidized gym membership Access to Employee Assistance Program Cycle to Work and Electric Car Salary Sacrifice Scheme Time off for volunteering Charitable matching of employee donations You Can Be Who You Are We are committed to a culture of diversity and inclusion that embraces the authenticity of all employees, partners and communities. We support all employees to thrive and achieve their fullest potential.As part of our commitment to diversity and inclusion, we will provide reasonable adjustments during the recruitment process to ensure equal access to applicants with disabilities. Please contact us about your needs so that we can discuss these with you to make sure that suitable adjustments are made, where possible. Pacific Life Re Values Please click here to view our company values
May 29, 2026
Full time
Senior Technology Risk AnalystApplylocations: London, UKtime type: Full timeposted on: Posted Todayjob requisition id: R17061 Job Title Senior Technology Risk Analyst Job Description We collaborate with clients across Europe, Asia, Australia and North America, specialising in risks associated with Life, Critical Illness, Income Protection, Hospital Cash and Longevity products. Our clients are insurance or reinsurance companies looking for a new and innovative approach to taking risks.With the security and financial strength of a parent company that has been around for over 145 years and a mutual holding company as our ultimate parent, we are not constrained by short-term thinking; therefore, allowing us to be free to pursue the right course for our clients and our business.Underlying our philosophy is an intelligent approach to taking risks. By recruiting top quality staff and investing in the latest analytical technologies, we believe we are well placed to make those decisions. The Role We have an exciting permanent opportunity available within the Division Centre Technology Risk team, based out of our London office.This role is suited to an experienced professional seeking to deepen their expertise in Technology Risk within a global organisation. You will play a key role in delivering risk management activities, providing subject matter expertise, and driving improvements across technology, risk frameworks, and emerging areas such as AI.Primary responsibilities will include providing technology risk subject matter expertise, support and guidance to the global Technology team, specifically:• Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Analyse and manage incidents and operational events, identify root causes and systemic control weaknesses using data analytics, and drive action plans to completion with effective monitoring, escalation, and senior management reporting, focusing on optimisation and efficiency. • Coordinating with global professional colleagues to identify risks and assess potential financial, reputational, and operational impacts. • Helping to define and maintain key risk indicators, including exploring automated data feeds and AI-driven insights, assisting in the preparation of reporting to divisional senior Technology management, Operational Risk & Resilience, and the Operational Risk Management Committee. • Participating in working groups on specific technology risk topics (e.g. cyber, IT asset management, data management and governance), including the safe adoption of emerging technologies such as AI. • Providing SME input and support to the Technology team with regards to risks, issues and operational events logged in our GRC platform, including opportunities to enhance data quality and workflow automation. • Supporting Technology by acting as a point of contact and "bridge" between them and other lines of defence, such as Operational Risk, Internal Audit, and External Audit. • Driving the modernisation of technology risk processes through the use of automation, data analytics and AI-enabled solutions (e.g. process automation, intelligent risk assessments, enhanced reporting). • Identifying opportunities to improve efficiency, scalability and consistency of risk processes, and supporting the design and implementation of solutions where appropriate. • Supporting client engagement teams through responding to technical due diligence requests from current and potential clients. • Performing risk assessments of new technologies entering the environment, including AI/ML solutions, ensuring that risks are identified and appropriate controls are in place. Skills, Knowledge & Experience Required- Minimum 4 years' experience of working within a risk / audit function - A solid understanding of current technology capabilities, including AI/ML concepts and their associated risks, and a keen interest in staying abreast of emerging technology trends (e.g. AI, automation, quantum computing). - Knowledge of and experience of implementing leading Technology risk framework and practices e.g. ISO27001, COBIT, NIST and supporting methodologies. - Experience or demonstrable interest in applying data analytics, automation, or AI tools to improve risk management processes and reporting. - Ability to manage own time and to work to strict deadlines - Strong organisational, analytical and stakeholder management skills - Detail oriented and well-organised with ability to work independently - Experienced in collaborating at all levels of an enterprise - Effective written and verbal communication from technical team direction to senior management presentations - Experience with undertaking RCSA or similar risk and controls assessments / audits - Creativity and initiative in work product, positive and helpful attitude proposing solutions to resolve problems - Ability to work flexibly to support colleagues that operate out of multiple locations / time-zones - Proficiency in using standard work environment software, such as Microsoft Office Suite Desired - Risk/IT professional certification such as CISA, CRISC, CPA, CISM, Six Sigma - Experience of working within the Insurance / Reinsurance industries - Degree within an IT related or similar discipline - Understanding of GRC platforms (e.g. Archer) - Comfortable operating in a dynamic, evolving environment with competing priorities - Confidence working with incomplete information and forming reasoned risk based conclusions - Experience applying judgement over checklist driven compliance, with an ability to prioritise risk proportionately - Exposure to AI governance, model risk management, or emerging regulatory expectations relating to AI Working For Pacific Life Re Every person in our global team is valued for the unique qualities they bring to our business and we seek to build their expertise and support their individual ambitions at every step. Of course, we take our work seriously and we know our team can operate under great pressure. We work hard and thrive on achievement, but we also know how to have fun and relax too. We regularly host a range of team building days to strengthen our team's connection with each other and reflect on their successes.Providing employees with a healthy work-life balance is very important to our culture. We have a wide range of employee benefits and we host regular social activities and well being initiatives. We are also committed to supporting our employee's involvement in their communities, by actively fundraising, hosting charity events and overseeing volunteering opportunities. Benefits (Only for Permanent and Fixed Term Employees) Leave 25 days of annual leave with option to buy/sell more days Adoption and fertility leave Generous enhanced parental leaveHealthcare Comprehensive private insurance coverage for employee and dependents Group Life Insurance coverage of 9x basic annual salary and Group Income Protection up to 75% of basic annual salary Optical benefitsSavings & Retirement 15% combined employee/employer contributionsWellness Subsidized gym membership Access to Employee Assistance Program Cycle to Work and Electric Car Salary Sacrifice Scheme Time off for volunteering Charitable matching of employee donations You Can Be Who You Are We are committed to a culture of diversity and inclusion that embraces the authenticity of all employees, partners and communities. We support all employees to thrive and achieve their fullest potential.As part of our commitment to diversity and inclusion, we will provide reasonable adjustments during the recruitment process to ensure equal access to applicants with disabilities. Please contact us about your needs so that we can discuss these with you to make sure that suitable adjustments are made, where possible. Pacific Life Re Values Please click here to view our company values
Universal Music Group
IAM Analyst - Kings Cross, London
Universal Music Group
IAM AnalystApplylocations: Kings Cross, Londontime type: Full timeposted on: Posted 8 Days Agojob requisition id: UMG-23757Music is Universal It's the passionate and dedicated team at Universal Music who help make us the world's leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email . Job Summary: We are UMG, the Universal Music Group. We are the world's leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world.We are currently seeking an IAM Analyst to join our Global Tech Security team. The ideal candidate will have exposure across the Identity & Access Management (IAM) stack. Primary focus will be on providing data analysis and reporting on enterprise-grade solutions across Privileged Access Management (PAM), Identity Governance and Administration (IGA), Public Key Infrastructure (PKI), Directory Services, Federation, and more. This role requires a combination of strong communication and critical thinking skills with strong attention to detail. Job Functions: Research and provide data analyst for IAM tools across the enterprise including CyberArk, Ping DaVinci, Microsoft EntraID (formerly Azure AD), HashiCorp Vault, Digicert, and Saviynt. Support the implementation and enhancement of IAM services including: - SSO/Federation (SAML, OIDC, WS-Fed) - MFA/Passwordless - Privileged Access Management (PAM) - Identity Governance (IGA) - PKI and certificate lifecycle automation - Directory services (AD, EntraID). Track automation scripts and integrations for IAM workflows using tools such as PowerShell, Python, or Terraform. Communicate design and implement access controls and policies that align with security and compliance standards (SOX, GDPR, etc.). Evaluate AI-powered tools and methodologies to improve identity lifecycle efficiency, risk detection, and operational decision-making. Participate in lifecycle management processes for accounts, credentials, roles, and policies across systems and applications. Collaborate with InfoSec, Infrastructure, and App teams to ensure secure identity architecture for on-prem and cloud environments. Maintain high-quality documentation and architectural diagrams. Monitor and report metrics on IAM system performance, adoption, and audit readiness. Job Requirements: Essential Qualifications 2+ years of experience in IAM engineering teams. Some proficiency of technical expertise in one or more of the following: CyberArk, Ping Identity, Microsoft EntraID, Saviynt, HashiCorp Vault, Digicert, Onfido. Understanding of IAM protocols and standards: SAML, OIDC, OAuth2, LDAP, Kerberos, SCIM, JIT. Familiarity with cloud platforms (Azure, AWS, GCP) and IAM integrations. Proven ability to work independently and cross-functionally in a global team. Strong troubleshooting, documentation, and communication skills. Strong communication skills for both technical details and business acumen.Desirable Bachelor's Degree in Computer Science, Engineering, or a related technical field. Professional certifications such as: CISSP, Security+, Microsoft Certified: Identity and Access Administrator, CyberArk Defender, Ping Identity Certified Professional. Experience with AI/ML integration into IAM workflows or security analytics. Experience supporting IAM functions in media or entertainment industry environments. Experience working on a global team covering multiple time zones.Just So You Know The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder's specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.
May 29, 2026
Full time
IAM AnalystApplylocations: Kings Cross, Londontime type: Full timeposted on: Posted 8 Days Agojob requisition id: UMG-23757Music is Universal It's the passionate and dedicated team at Universal Music who help make us the world's leading music company. From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities. We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles. If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email . Job Summary: We are UMG, the Universal Music Group. We are the world's leading music company. In everything we do, we are committed to artistry, innovation and entrepreneurship. We own and operate a broad array of businesses engaged in recorded music, music publishing, merchandising, and audiovisual content in more than 60 countries. We identify and develop recording artists and songwriters, and we produce, distribute and promote the most critically acclaimed and commercially successful music to delight and entertain fans around the world.We are currently seeking an IAM Analyst to join our Global Tech Security team. The ideal candidate will have exposure across the Identity & Access Management (IAM) stack. Primary focus will be on providing data analysis and reporting on enterprise-grade solutions across Privileged Access Management (PAM), Identity Governance and Administration (IGA), Public Key Infrastructure (PKI), Directory Services, Federation, and more. This role requires a combination of strong communication and critical thinking skills with strong attention to detail. Job Functions: Research and provide data analyst for IAM tools across the enterprise including CyberArk, Ping DaVinci, Microsoft EntraID (formerly Azure AD), HashiCorp Vault, Digicert, and Saviynt. Support the implementation and enhancement of IAM services including: - SSO/Federation (SAML, OIDC, WS-Fed) - MFA/Passwordless - Privileged Access Management (PAM) - Identity Governance (IGA) - PKI and certificate lifecycle automation - Directory services (AD, EntraID). Track automation scripts and integrations for IAM workflows using tools such as PowerShell, Python, or Terraform. Communicate design and implement access controls and policies that align with security and compliance standards (SOX, GDPR, etc.). Evaluate AI-powered tools and methodologies to improve identity lifecycle efficiency, risk detection, and operational decision-making. Participate in lifecycle management processes for accounts, credentials, roles, and policies across systems and applications. Collaborate with InfoSec, Infrastructure, and App teams to ensure secure identity architecture for on-prem and cloud environments. Maintain high-quality documentation and architectural diagrams. Monitor and report metrics on IAM system performance, adoption, and audit readiness. Job Requirements: Essential Qualifications 2+ years of experience in IAM engineering teams. Some proficiency of technical expertise in one or more of the following: CyberArk, Ping Identity, Microsoft EntraID, Saviynt, HashiCorp Vault, Digicert, Onfido. Understanding of IAM protocols and standards: SAML, OIDC, OAuth2, LDAP, Kerberos, SCIM, JIT. Familiarity with cloud platforms (Azure, AWS, GCP) and IAM integrations. Proven ability to work independently and cross-functionally in a global team. Strong troubleshooting, documentation, and communication skills. Strong communication skills for both technical details and business acumen.Desirable Bachelor's Degree in Computer Science, Engineering, or a related technical field. Professional certifications such as: CISSP, Security+, Microsoft Certified: Identity and Access Administrator, CyberArk Defender, Ping Identity Certified Professional. Experience with AI/ML integration into IAM workflows or security analytics. Experience supporting IAM functions in media or entertainment industry environments. Experience working on a global team covering multiple time zones.Just So You Know The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable. However, the business operates in an environment that demands change and the jobholder's specific responsibilities and activities will vary and develop. Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.
Cyber Resilience Analyst
Iceland Food Group Deeside, Flintshire
As one of the Best Big Companies to Work For, we have a rich history of loving our customers and looking after our teams. We understand that success is achieved through our people, and we are searching for askilled and experienced Cyber Resilience Analyst to join our team. The successful candidate will report to the Cyber Governance, Risk, and Compliance Manager click apply for full job details
May 29, 2026
Full time
As one of the Best Big Companies to Work For, we have a rich history of loving our customers and looking after our teams. We understand that success is achieved through our people, and we are searching for askilled and experienced Cyber Resilience Analyst to join our team. The successful candidate will report to the Cyber Governance, Risk, and Compliance Manager click apply for full job details
Information Governance Analyst
Iceland Food Group Deeside, Flintshire
As one of the Best Big Companies to Work For, we have a rich history of loving our customers and looking after our teams. We understand that success is achieved through our people, and we are searching for an experienced and proactive Information Governance Analyst to join our Cyber Security team. The successful candidate will report to the Cyber Governance, Risk, and Compliance (GRC) Manager and wi click apply for full job details
May 29, 2026
Full time
As one of the Best Big Companies to Work For, we have a rich history of loving our customers and looking after our teams. We understand that success is achieved through our people, and we are searching for an experienced and proactive Information Governance Analyst to join our Cyber Security team. The successful candidate will report to the Cyber Governance, Risk, and Compliance (GRC) Manager and wi click apply for full job details
Senior Information Security Analyst
Circle Group
Senior Information Security Analyst Birmingham (Hybrid) Starting Salary £50-75k We are seeking a motivated individual to join our client's growing cyber team, supporting the delivery of an expanding portfolio of cyber governance, risk, and advisory services. This role offers excellent exposure to a wide range of cybersecurity, risk management, and business operations activities, working alongside e click apply for full job details
May 26, 2026
Full time
Senior Information Security Analyst Birmingham (Hybrid) Starting Salary £50-75k We are seeking a motivated individual to join our client's growing cyber team, supporting the delivery of an expanding portfolio of cyber governance, risk, and advisory services. This role offers excellent exposure to a wide range of cybersecurity, risk management, and business operations activities, working alongside e click apply for full job details

Modal Window

  • Home
  • Contact
  • About Us
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • Facebook
  • Twitter
  • Google Plus
  • LinkedIn
Parent and Partner sites: IT Job Board | Jobs Near Me | RightTalent.co.uk | Quantity Surveyor jobs | Building Surveyor jobs | Construction Recruitment | Talent Recruiter | Construction Job Board | Property jobs | myJobsnearme.com | Jobs near me
© 2008-2026 Jobsite Jobs | Designed by Web Design Agency