• Home
  • Find Jobs
  • Register CV
  • Advertise jobs
  • Employer Pricing
  • IT Jobs
  • Sign in
  • Sign up
  • Home
  • Find Jobs
  • Register CV
  • Advertise jobs
  • Employer Pricing
  • IT Jobs
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

36 jobs found

Email me jobs like this
Refine Search
Current Search
cyber security auditor
Spectrum IT Recruitment
Senior Information Security Analyst (ISO, SOC2, PCI DSS)
Spectrum IT Recruitment City, London
Senior Information Security Analyst - Audit & Compliance ISO27001, SOC2, PCI-DSS, NIST, GDPR London (Barbican). Hybrid. 2 days a week onsite. Up to 100k plus 8% bonus, pension, private medical etc We're working with a global technology partner to find a certified Information Security Analyst. This is a fantastic opportunity to join a company that's setting the highest standards in cybersecurity and security compliance. You'll play a key role in ensuring compliance with leading security frameworks, preparing for and conducting audits, and contributing to security operations. You'll be joining a collaborative, ambitious team where there are genuine long-term career prospects and endless opportunities to develop. The Role Lead and conduct internal audits across ISO 27001, GDPR, DORA, Cyber Essentials & more. Prepare teams for external audits and manage the audit process end-to-end. Monitor changes in compliance frameworks and maintain alignment. Support the Cyber Security Operations Centre (CSOC) in incident monitoring and response. Develop and maintain policies, procedures, and security documentation. Collaborate with IT & Security teams to identify and remediate vulnerabilities. What We're Looking For Strong knowledge of audit & compliance frameworks (ISO 27001,SOC2, PCI DSS, Cyber Essentials) Experience with CSOC tools such as Rapid7 InsightIDR or other SIEM solutions. Hands-on experience with internal/external audits and compliance assessments. Relevant security/audit certifications (CISA, CISM, CISSP, ISO 27001 Lead Auditor, Cyber Essentials Assessor, or equivalent). Eligible for UK Security Clearance. What's In It For You? Salary approx 100,000 + 8% Bonus, Pension, Healthcare, Flexi-Working and much more. Hybrid working (2 days in the London office). Excellent long-term career growth with a global organisation. Hit apply to upload your CV Spectrum IT Recruitment (South) Limited is acting as an Employment Agency in relation to this vacancy. Spectrum IT Recruitment (South) Limited is acting as an Employment Agency in relation to this vacancy.
Aug 08, 2026
Full time
Senior Information Security Analyst - Audit & Compliance ISO27001, SOC2, PCI-DSS, NIST, GDPR London (Barbican). Hybrid. 2 days a week onsite. Up to 100k plus 8% bonus, pension, private medical etc We're working with a global technology partner to find a certified Information Security Analyst. This is a fantastic opportunity to join a company that's setting the highest standards in cybersecurity and security compliance. You'll play a key role in ensuring compliance with leading security frameworks, preparing for and conducting audits, and contributing to security operations. You'll be joining a collaborative, ambitious team where there are genuine long-term career prospects and endless opportunities to develop. The Role Lead and conduct internal audits across ISO 27001, GDPR, DORA, Cyber Essentials & more. Prepare teams for external audits and manage the audit process end-to-end. Monitor changes in compliance frameworks and maintain alignment. Support the Cyber Security Operations Centre (CSOC) in incident monitoring and response. Develop and maintain policies, procedures, and security documentation. Collaborate with IT & Security teams to identify and remediate vulnerabilities. What We're Looking For Strong knowledge of audit & compliance frameworks (ISO 27001,SOC2, PCI DSS, Cyber Essentials) Experience with CSOC tools such as Rapid7 InsightIDR or other SIEM solutions. Hands-on experience with internal/external audits and compliance assessments. Relevant security/audit certifications (CISA, CISM, CISSP, ISO 27001 Lead Auditor, Cyber Essentials Assessor, or equivalent). Eligible for UK Security Clearance. What's In It For You? Salary approx 100,000 + 8% Bonus, Pension, Healthcare, Flexi-Working and much more. Hybrid working (2 days in the London office). Excellent long-term career growth with a global organisation. Hit apply to upload your CV Spectrum IT Recruitment (South) Limited is acting as an Employment Agency in relation to this vacancy. Spectrum IT Recruitment (South) Limited is acting as an Employment Agency in relation to this vacancy.
Opus Recruitment Solutions
Security Onboarding Specialist
Opus Recruitment Solutions
Role: Security Onboarding Specialist Location: London (Hybrid - Once in a month onsite) Type: Contract (Inside IR35) Duration: 9 Months Role Overview We are seeking an experienced Security Onboarding Specialist to join a high-profile digital services programme. This role will be responsible for ensuring that external partner organisations meet the required security, assurance and trust framework standards before integrating with secure digital services. Acting as the primary security contact for partner onboarding activities, you will assess security controls, perform gap analyses, review evidence submissions, and provide assurance recommendations to support onboarding decisions. You will play a key role in maintaining consistency of security assessments while ensuring compliance with evolving trust framework and organisational requirements. Key Responsibilities Lead security assurance and onboarding assessments for external partners and suppliers. Perform gap analyses against Trust Framework requirements, security standards, policies and controls. Review and evaluate security documentation, policies, procedures and evidence submitted by partner organisations. Identify control deficiencies, security risks and compliance gaps, providing clear remediation recommendations. Act as the primary security point of contact throughout the partner onboarding lifecycle. Produce security assessment reports, recommendations and onboarding assurance outcomes. Work closely with security, architecture, delivery and governance teams to support onboarding decisions. Monitor and track remediation activities through to completion. Ensure consistent application of security assurance processes and assessment criteria. Maintain awareness of changes to Trust Frameworks, security policies and regulatory requirements, updating assessment approaches where required. Support ongoing assurance activities and periodic reviews of onboarded partners. Required Skills & Experience Proven experience in Security Assurance, Security Governance, Risk & Compliance (GRC), Third-Party Risk Management, or Information Security. Strong understanding of security control frameworks and assurance methodologies. Experience conducting security assessments, compliance reviews and gap analyses. Ability to review and assess security evidence and documentation against defined requirements. Knowledge of information security principles, risk management and security governance practices. Strong stakeholder management skills with the ability to engage effectively with both technical and non-technical audiences. Experience producing clear, concise assessment reports and risk-based recommendations. Excellent communication, analytical and problem-solving skills. Desirable Experience Experience working within government, public sector or highly regulated environments. Knowledge of Digital Identity and Trust Frameworks. Familiarity with standards and frameworks such as: ISO 27001 NIST Cyber Security Framework Cyber Essentials / Cyber Essentials Plus Supplier and Third-Party Assurance frameworks Experience supporting digital identity, authentication or secure digital services programmes. Security-related certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor or equivalent. Key Competencies Security Assurance Governance, Risk & Compliance (GRC) Third-Party Risk Management Security Assessments Risk Analysis Stakeholder Management Information Security Audit & Compliance Trust Framework Compliance Security Governance This is an excellent opportunity for a Security Assurance professional who enjoys working with stakeholders, assessing security controls, and ensuring robust onboarding standards within a large-scale digital service environment.
Aug 08, 2026
Contractor
Role: Security Onboarding Specialist Location: London (Hybrid - Once in a month onsite) Type: Contract (Inside IR35) Duration: 9 Months Role Overview We are seeking an experienced Security Onboarding Specialist to join a high-profile digital services programme. This role will be responsible for ensuring that external partner organisations meet the required security, assurance and trust framework standards before integrating with secure digital services. Acting as the primary security contact for partner onboarding activities, you will assess security controls, perform gap analyses, review evidence submissions, and provide assurance recommendations to support onboarding decisions. You will play a key role in maintaining consistency of security assessments while ensuring compliance with evolving trust framework and organisational requirements. Key Responsibilities Lead security assurance and onboarding assessments for external partners and suppliers. Perform gap analyses against Trust Framework requirements, security standards, policies and controls. Review and evaluate security documentation, policies, procedures and evidence submitted by partner organisations. Identify control deficiencies, security risks and compliance gaps, providing clear remediation recommendations. Act as the primary security point of contact throughout the partner onboarding lifecycle. Produce security assessment reports, recommendations and onboarding assurance outcomes. Work closely with security, architecture, delivery and governance teams to support onboarding decisions. Monitor and track remediation activities through to completion. Ensure consistent application of security assurance processes and assessment criteria. Maintain awareness of changes to Trust Frameworks, security policies and regulatory requirements, updating assessment approaches where required. Support ongoing assurance activities and periodic reviews of onboarded partners. Required Skills & Experience Proven experience in Security Assurance, Security Governance, Risk & Compliance (GRC), Third-Party Risk Management, or Information Security. Strong understanding of security control frameworks and assurance methodologies. Experience conducting security assessments, compliance reviews and gap analyses. Ability to review and assess security evidence and documentation against defined requirements. Knowledge of information security principles, risk management and security governance practices. Strong stakeholder management skills with the ability to engage effectively with both technical and non-technical audiences. Experience producing clear, concise assessment reports and risk-based recommendations. Excellent communication, analytical and problem-solving skills. Desirable Experience Experience working within government, public sector or highly regulated environments. Knowledge of Digital Identity and Trust Frameworks. Familiarity with standards and frameworks such as: ISO 27001 NIST Cyber Security Framework Cyber Essentials / Cyber Essentials Plus Supplier and Third-Party Assurance frameworks Experience supporting digital identity, authentication or secure digital services programmes. Security-related certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor or equivalent. Key Competencies Security Assurance Governance, Risk & Compliance (GRC) Third-Party Risk Management Security Assessments Risk Analysis Stakeholder Management Information Security Audit & Compliance Trust Framework Compliance Security Governance This is an excellent opportunity for a Security Assurance professional who enjoys working with stakeholders, assessing security controls, and ensuring robust onboarding standards within a large-scale digital service environment.
Fuel Recruitment Limited
Operations and Assurance Security Manager
Fuel Recruitment Limited Farnborough, Hampshire
Our client in the Defence industry is looking for an Operation and Assurance Security Manager who will be responsible for developing, implementing and maintaining information security, risk management, and compliance frameworks. You will ensure that systems, processes and data are protected against threats whilst meeting regulatory and corporate governance requirements. In this role, you will set the direction for development of security policies, standards and procedures. You will oversee cybersecurity strategy, support security incidents and lead incident response. Driving continuous improvement, conducting regular vulnerability assessments. There is also a stakeholder engagement aspect which will require you to collaborate with IT, operations and business teams to embed security practices, provide training and awareness programs to promote a security-first culture and manage relationships with external partners, vendors, and auditors when leading internal and external audits. You will need to be familiar with industry standards such as ISO 27001, Cyber Essentials, JSP 453 and JSP 440 Secure by Design. Due to the nature of this role, candidates must be sole British nationals and either hold or be eligible to hold SC clearance.
Aug 08, 2026
Full time
Our client in the Defence industry is looking for an Operation and Assurance Security Manager who will be responsible for developing, implementing and maintaining information security, risk management, and compliance frameworks. You will ensure that systems, processes and data are protected against threats whilst meeting regulatory and corporate governance requirements. In this role, you will set the direction for development of security policies, standards and procedures. You will oversee cybersecurity strategy, support security incidents and lead incident response. Driving continuous improvement, conducting regular vulnerability assessments. There is also a stakeholder engagement aspect which will require you to collaborate with IT, operations and business teams to embed security practices, provide training and awareness programs to promote a security-first culture and manage relationships with external partners, vendors, and auditors when leading internal and external audits. You will need to be familiar with industry standards such as ISO 27001, Cyber Essentials, JSP 453 and JSP 440 Secure by Design. Due to the nature of this role, candidates must be sole British nationals and either hold or be eligible to hold SC clearance.
Morgan Philips Group
Cyber Security Analyst - Watford
Morgan Philips Group Watford, Hertfordshire
Job specification for the position of : Cyber Security Analyst Reporting to : IT Governance and Security Manager OFFICE BASED IN WATFORD - FIVE DAYS PER WEEK - NON-NEGOTIABLE Must have a British passport or ILR (Indefinite leave to remain) - no sponsorship available Purpose of the role : The cyber security analyst is responsible for the day-to-day tasks which protect the business from cyber threats and attacks. Based in Watford, at head office, this role gives an opportunity to contribute to cyber response and to identify cyber risks, helping IT to protect the company's systems. Role overview : working closely with the IT governance and security manager, contributing to cyber strategy administering IT security systems identifying, mitigating and escalating IT security incidents identifying deviations from IT security standards analysing logs and reporting relevant information reporting trends and threats in e-mail and web traffic, as appropriate analysing security information and producing relevant reports administering and evaluating cyber security questionnaires co-ordinating and scheduling penetration tests managing third-party forensic investigations completing cyber security posture-reporting supporting excellent cyber security design, with the ability to contribute to good cyber security practices In detail, the role will involve : log-analysing security posture-monitoring Trellix antivirus-reporting and some EPO management tasks secure physical and electronic destruction of sensitive data helping the business to protect sensitive information (e.g. encrypting data) educating and awareness through spam-testing; supporting the training teams with e-learning monitoring public and third-party feeds for emerging cyber trends performing cyber risk assessments co-ordinating cyber security incidents defining cyber policies and cyber standards assessing third-party suppliers' cyber standards keeping abreast of current and emerging threats Skills required : understanding log management (at an analysis level only): Microsoft Windows and AD log structure network system log, e.g. Cisco and Checkpoint Office 365 and Defender security knowledge of Splunk the SIEM platform understanding of systems and integrity: Netwrix security solutions administration, including AD Auditor and Change Tracker Trellix and SkyHigh reporting and management, including Trellix antivirus-reporting and DLP using EPO operational security and incident management: experience of cyber security quickly analysing data and making decisions on security threats Salary and benefits : competitive salary 25 days' paid holiday (plus bank holidays) pro rata; head-office bonus scheme; free shares (after 18 months with the company); private medical insurance; contributory pension scheme Please note you will receive an automated response advising you that we have received your CV. Morgan Philips Group is a global talent solutions business that disrupts conventional thinking in executive search, recruitment and talent consulting. We operate in over 18 markets in Europe, North & South America, Asia, and the Middle East & Africa. We understand that the future is digital and social, so we embrace the latest technology, including video ads and CVs, as well as social recruiting. Our innovative services are tailored to the new world of work yet we do not lose sight of the fact that employees be they existing and potential are ultimately human beings. We are committed to ensuring that all job applicants are treated equally, without discrimination because of gender, sexual orientation, marital or civil partner status, gender reassignment, race, colour, nationality, ethnic or national origin, religion or belief, disability or age.
Aug 08, 2026
Full time
Job specification for the position of : Cyber Security Analyst Reporting to : IT Governance and Security Manager OFFICE BASED IN WATFORD - FIVE DAYS PER WEEK - NON-NEGOTIABLE Must have a British passport or ILR (Indefinite leave to remain) - no sponsorship available Purpose of the role : The cyber security analyst is responsible for the day-to-day tasks which protect the business from cyber threats and attacks. Based in Watford, at head office, this role gives an opportunity to contribute to cyber response and to identify cyber risks, helping IT to protect the company's systems. Role overview : working closely with the IT governance and security manager, contributing to cyber strategy administering IT security systems identifying, mitigating and escalating IT security incidents identifying deviations from IT security standards analysing logs and reporting relevant information reporting trends and threats in e-mail and web traffic, as appropriate analysing security information and producing relevant reports administering and evaluating cyber security questionnaires co-ordinating and scheduling penetration tests managing third-party forensic investigations completing cyber security posture-reporting supporting excellent cyber security design, with the ability to contribute to good cyber security practices In detail, the role will involve : log-analysing security posture-monitoring Trellix antivirus-reporting and some EPO management tasks secure physical and electronic destruction of sensitive data helping the business to protect sensitive information (e.g. encrypting data) educating and awareness through spam-testing; supporting the training teams with e-learning monitoring public and third-party feeds for emerging cyber trends performing cyber risk assessments co-ordinating cyber security incidents defining cyber policies and cyber standards assessing third-party suppliers' cyber standards keeping abreast of current and emerging threats Skills required : understanding log management (at an analysis level only): Microsoft Windows and AD log structure network system log, e.g. Cisco and Checkpoint Office 365 and Defender security knowledge of Splunk the SIEM platform understanding of systems and integrity: Netwrix security solutions administration, including AD Auditor and Change Tracker Trellix and SkyHigh reporting and management, including Trellix antivirus-reporting and DLP using EPO operational security and incident management: experience of cyber security quickly analysing data and making decisions on security threats Salary and benefits : competitive salary 25 days' paid holiday (plus bank holidays) pro rata; head-office bonus scheme; free shares (after 18 months with the company); private medical insurance; contributory pension scheme Please note you will receive an automated response advising you that we have received your CV. Morgan Philips Group is a global talent solutions business that disrupts conventional thinking in executive search, recruitment and talent consulting. We operate in over 18 markets in Europe, North & South America, Asia, and the Middle East & Africa. We understand that the future is digital and social, so we embrace the latest technology, including video ads and CVs, as well as social recruiting. Our innovative services are tailored to the new world of work yet we do not lose sight of the fact that employees be they existing and potential are ultimately human beings. We are committed to ensuring that all job applicants are treated equally, without discrimination because of gender, sexual orientation, marital or civil partner status, gender reassignment, race, colour, nationality, ethnic or national origin, religion or belief, disability or age.
Chesterfield Poultry
Finance Manager
Chesterfield Poultry Doncaster, Yorkshire
Chinese speaking Finance Manager Location: Coulman Street, Thorne, Doncaster, South Yorkshire - Fully on site - no remote working Salary: Negotiable, dependant on experience The Finance Manager is responsible for the day-to-day management of the finance function, ensuring the integrity, accuracy and timeliness of financial reporting while supporting strategic decision making across the business. The role provides financial leadership through effective budgeting, forecasting, cost control, statutory compliance and continuous improvement. Working closely with operational departments, the Finance Manager will provide commercially focused financial analysis to maximise profitability, improve efficiencies and support sustainable business growth. Duties: Financial Management Lead the daily finance operations and ensure accurate maintenance of the general ledger. Produce timely monthly accounts and prepare P&L accounts, balance sheets and cash flow forecasts. Maintain robust financial controls across all departments. Review and approve journals, reconciliations and adjustments. Ensure financial records comply with UK accounting standards. Financial Reporting Prepare monthly board reports and produce departmental performance reports. Analyse financial trends and key business drivers and present financial information to senior leadership. Support strategic planning with financial modelling and develop meaningful KPI dashboards. Budgeting & Forecasting Lead the annual budgeting process and prepare rolling forecasts. Monitor departmental expenditure and identify financial risks and opportunities. Challenge budget assumptions and recommend cost saving initiatives. Cash Flow Management Manage daily cash flow and forecast working capital requirements. Monitor debtor and creditor balances and ensure sufficient liquidity. Manage banking relationships and authorise supplier payment runs. Cost Control Analyse manufacturing costs and review labour costs and overheads. Monitor production variances and support operational efficiency initiatives. Identify waste reduction opportunities and recommend improvements to profitability. Commercial Finance: Partner with operational managers by providing: Margin analysis, Product costing, Customer profitability, Capital investment appraisals and ROI. Business case preparation and pricing support Compliance Ensure compliance with: UK GAAP Companies Act HMRC requirements / VAT regulations / Corporation Tax / PAYE legislation Internal financial controls and external audit requirements Audit: Assist: Year-end audit preparation & internal audit activity Financial control reviews & external auditor liaison and action plan implementation Payroll Oversight Review payroll calculations and ensure statutory deductions are correct. Reconcile payroll journals and ensure pension compliance. Maintain confidentiality. Team Leadership Conduct performance reviews and develop colleagues whilst allocating workloads. Support succession planning and promote continuous improvement. Information Security & GDPR Handle confidential financial information securely and comply with UK GDPR. Protect commercially sensitive information. Maintain confidentiality at all times. Follow company cyber security procedures. Person Specification Essential Qualifications Qualified Accountant (ACA, ACCA, CIMA or equivalent) Degree in Finance, Accounting or Business (desirable) Essential Experience Finance management experience in a manufacturing environment. Management accounting, financial reporting alongside budget preparation. Cash flow forecasting, Cost accounting, Financial reporting. Team management. Audit preparation. ERP systems. Advanced Excel Desirable Experience Food manufacturing. SAP, Microsoft Dynamics or Sage. Continuous Improvement. Project accounting. Capital expenditure planning. Must be authorised to work in the UK. To Apply If you feel you are a suitable candidate and would like to work for Chesterfield Poultry, please do not hesitate to apply.
Aug 07, 2026
Full time
Chinese speaking Finance Manager Location: Coulman Street, Thorne, Doncaster, South Yorkshire - Fully on site - no remote working Salary: Negotiable, dependant on experience The Finance Manager is responsible for the day-to-day management of the finance function, ensuring the integrity, accuracy and timeliness of financial reporting while supporting strategic decision making across the business. The role provides financial leadership through effective budgeting, forecasting, cost control, statutory compliance and continuous improvement. Working closely with operational departments, the Finance Manager will provide commercially focused financial analysis to maximise profitability, improve efficiencies and support sustainable business growth. Duties: Financial Management Lead the daily finance operations and ensure accurate maintenance of the general ledger. Produce timely monthly accounts and prepare P&L accounts, balance sheets and cash flow forecasts. Maintain robust financial controls across all departments. Review and approve journals, reconciliations and adjustments. Ensure financial records comply with UK accounting standards. Financial Reporting Prepare monthly board reports and produce departmental performance reports. Analyse financial trends and key business drivers and present financial information to senior leadership. Support strategic planning with financial modelling and develop meaningful KPI dashboards. Budgeting & Forecasting Lead the annual budgeting process and prepare rolling forecasts. Monitor departmental expenditure and identify financial risks and opportunities. Challenge budget assumptions and recommend cost saving initiatives. Cash Flow Management Manage daily cash flow and forecast working capital requirements. Monitor debtor and creditor balances and ensure sufficient liquidity. Manage banking relationships and authorise supplier payment runs. Cost Control Analyse manufacturing costs and review labour costs and overheads. Monitor production variances and support operational efficiency initiatives. Identify waste reduction opportunities and recommend improvements to profitability. Commercial Finance: Partner with operational managers by providing: Margin analysis, Product costing, Customer profitability, Capital investment appraisals and ROI. Business case preparation and pricing support Compliance Ensure compliance with: UK GAAP Companies Act HMRC requirements / VAT regulations / Corporation Tax / PAYE legislation Internal financial controls and external audit requirements Audit: Assist: Year-end audit preparation & internal audit activity Financial control reviews & external auditor liaison and action plan implementation Payroll Oversight Review payroll calculations and ensure statutory deductions are correct. Reconcile payroll journals and ensure pension compliance. Maintain confidentiality. Team Leadership Conduct performance reviews and develop colleagues whilst allocating workloads. Support succession planning and promote continuous improvement. Information Security & GDPR Handle confidential financial information securely and comply with UK GDPR. Protect commercially sensitive information. Maintain confidentiality at all times. Follow company cyber security procedures. Person Specification Essential Qualifications Qualified Accountant (ACA, ACCA, CIMA or equivalent) Degree in Finance, Accounting or Business (desirable) Essential Experience Finance management experience in a manufacturing environment. Management accounting, financial reporting alongside budget preparation. Cash flow forecasting, Cost accounting, Financial reporting. Team management. Audit preparation. ERP systems. Advanced Excel Desirable Experience Food manufacturing. SAP, Microsoft Dynamics or Sage. Continuous Improvement. Project accounting. Capital expenditure planning. Must be authorised to work in the UK. To Apply If you feel you are a suitable candidate and would like to work for Chesterfield Poultry, please do not hesitate to apply.
Rise Technical Recruitment
GRC Analyst
Rise Technical Recruitment
GRC Analyst 45,000 - 55,000 DOE + Private Medical Insurance + Dental & Vision Cover + Enhanced Annual Leave + Pension + Wellbeing Support UK - Remote Are you a GRC professional with a strong background in cybersecurity, cloud security and compliance frameworks who wants to join a rapidly growing consultancy where you can work with a diverse client base, lead high-value security initiatives and play a key role in improving organisations' security and compliance posture? This is an exciting opportunity to join an established and expanding cybersecurity and compliance consultancy supporting clients across a variety of industries. You'll work alongside experienced security professionals, helping organisations achieve and maintain compliance while strengthening their overall security programmes. In this role, you will support clients through audits, risk assessments, compliance activities and security programme development. You will engage directly with stakeholders, manage security and compliance initiatives, conduct tabletop exercises and help clients implement security best practices across modern cloud environments. The ideal candidate will have experience across governance, risk and compliance activities, strong knowledge of frameworks such as ISO 27001, SOC 2, GDPR and DORA, and a solid understanding of cloud platforms including AWS, Azure and GCP. Strong communication skills and a customer-focused approach are essential. The Role: Deliver GRC, compliance and security consulting services to clients Conduct audits, risk assessments and compliance gap analyses Support cloud security monitoring and security tool implementation Lead compliance evidence collection and auditor engagements Facilitate incident response, business continuity and disaster recovery exercises Work directly with clients to improve security programmes and regulatory compliance The Person: Good years of experience within cybersecurity, technology or GRC Strong understanding of ISO 27001, SOC 2, GDPR, DORA and related frameworks Experience with AWS, Azure and/or GCP environments Degree qualified in Cyber Security, IT or a related discipline, or equivalent experience Reference Number: BBBH(phone number removed) Rise Technical Recruitment Ltd acts an employment agency for permanent roles and an employment business for temporary roles. The salary advertised is the bracket available for this position. The actual salary paid will be dependent on your level of experience, qualifications and skill set and will be decided by our client, the employer. Rise are not responsible or liable for any hiring decisions made by the end client. We are an equal opportunities company and welcome applications from all suitable candidates.
Aug 07, 2026
Full time
GRC Analyst 45,000 - 55,000 DOE + Private Medical Insurance + Dental & Vision Cover + Enhanced Annual Leave + Pension + Wellbeing Support UK - Remote Are you a GRC professional with a strong background in cybersecurity, cloud security and compliance frameworks who wants to join a rapidly growing consultancy where you can work with a diverse client base, lead high-value security initiatives and play a key role in improving organisations' security and compliance posture? This is an exciting opportunity to join an established and expanding cybersecurity and compliance consultancy supporting clients across a variety of industries. You'll work alongside experienced security professionals, helping organisations achieve and maintain compliance while strengthening their overall security programmes. In this role, you will support clients through audits, risk assessments, compliance activities and security programme development. You will engage directly with stakeholders, manage security and compliance initiatives, conduct tabletop exercises and help clients implement security best practices across modern cloud environments. The ideal candidate will have experience across governance, risk and compliance activities, strong knowledge of frameworks such as ISO 27001, SOC 2, GDPR and DORA, and a solid understanding of cloud platforms including AWS, Azure and GCP. Strong communication skills and a customer-focused approach are essential. The Role: Deliver GRC, compliance and security consulting services to clients Conduct audits, risk assessments and compliance gap analyses Support cloud security monitoring and security tool implementation Lead compliance evidence collection and auditor engagements Facilitate incident response, business continuity and disaster recovery exercises Work directly with clients to improve security programmes and regulatory compliance The Person: Good years of experience within cybersecurity, technology or GRC Strong understanding of ISO 27001, SOC 2, GDPR, DORA and related frameworks Experience with AWS, Azure and/or GCP environments Degree qualified in Cyber Security, IT or a related discipline, or equivalent experience Reference Number: BBBH(phone number removed) Rise Technical Recruitment Ltd acts an employment agency for permanent roles and an employment business for temporary roles. The salary advertised is the bracket available for this position. The actual salary paid will be dependent on your level of experience, qualifications and skill set and will be decided by our client, the employer. Rise are not responsible or liable for any hiring decisions made by the end client. We are an equal opportunities company and welcome applications from all suitable candidates.
Expleo UK LTD
Senior Cybersecurity Consultant (Secure by Design Lead)
Expleo UK LTD Bristol, Gloucestershire
Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments. As part of the Expleo UK Cybersecurity Practice, you will lead the delivery of product security, cyber assurance and secure-by-design activity for a major UK defence maritime programme, supporting an autonomous surface vessel capability being matured towards a whole-ship system design review. This is a senior, client-facing role requiring strong cybersecurity leadership, defence assurance experience, maritime or shipbuilding awareness, and the ability to embed security into complex engineering, platform, IT and OT environments. The platform is designed to operate crewless, which shifts the security centre of gravity from information confidentiality towards the safety and availability of operational technology, and makes the remote command-and-control link and position, navigation, and timing resilience the assets that matter most. You will act as the cyber authority within the client's integrated design team, owning the Security Management Plan and the coherence of the wider security artefact set, and directing the work of a security architect and a cybersecurity consultant. The role sits at the intersection of naval architecture, systems engineering, product security, information assurance and MOD/maritime cyber compliance. The role requires a strong blend of cybersecurity leadership, secure engineering, technical assurance, stakeholder management, governance, supplier oversight and defence regulatory experience. You will need to operate with autonomy, technical credibility and the ability to provide clear decision support to senior leaders. Own and maintain the Security Management Plan covering OT, IT and physical security, including the assurance and acceptance strategy, management of the supply chain and the route to demonstrating secure by design in accordance with UK MOD requirements. Act as the senior security authority within the client's integrated design team, providing direction, challenge and assurance across engineering and delivery activity. Develop the threat assessment and a proposed security risk appetite for agreement, in lieu of customer-supplied statements. Lead the preliminary security risk assessment and manage design risk exposure, proportionate to the design's maturity, through a live design risk register owned by and reported to the client delivery team. Produce the preliminary specification of security requirements and appropriate standards for OT, IT and physical security, including security classification and criticality assessment. Maintain traceability from threat to risk to control to requirement, so that every security requirement is justified and evidenced. Define supplier and supply chain security requirements and ensure they are embedded in specifications, delivery expectations and technical acceptance criteria. Review and assess supplier security deliverables, including security claims, compliance evidence, technical designs, assurance artefacts and software bills of materials. Direct and quality-assure the work of the security architect and cybersecurity consultant, ensuring the artefact set is coherent, traceable and defensible. Provide security input to formal engineering design reviews, including system design reviews and equivalent programme governance gates, prepare and present material, and close out resulting actions. Manage meetings with security stakeholders and represent the security position to senior client stakeholders and independent technical governance. Apply relevant MOD, NCSC, defence and maritime security frameworks to support assurance, accreditation and compliance activities, and reconcile the security position with the platform safety case. Generate a detailed scope of work for subsequent programme phases, and an outline scope for later phases. Produce clear technical assurance outputs, security design material, decision papers, risk statements, briefing notes and governance updates. Work independently as a senior subject matter expert, determining the day-to-day technical approach, stakeholder engagement and assurance rhythm required to achieve agreed outcomes. Relevant education or industry-recognised certifications in cybersecurity, information assurance, secure engineering, security architecture, risk management or a related discipline. Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CISA, CCP, ISO 27001 Lead Implementer/Lead Auditor, Security+, CySA+, SABSA, TOGAF, IEC 62443, NCSC CAF-related experience or equivalent professional experience. Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
Aug 06, 2026
Full time
Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments. As part of the Expleo UK Cybersecurity Practice, you will lead the delivery of product security, cyber assurance and secure-by-design activity for a major UK defence maritime programme, supporting an autonomous surface vessel capability being matured towards a whole-ship system design review. This is a senior, client-facing role requiring strong cybersecurity leadership, defence assurance experience, maritime or shipbuilding awareness, and the ability to embed security into complex engineering, platform, IT and OT environments. The platform is designed to operate crewless, which shifts the security centre of gravity from information confidentiality towards the safety and availability of operational technology, and makes the remote command-and-control link and position, navigation, and timing resilience the assets that matter most. You will act as the cyber authority within the client's integrated design team, owning the Security Management Plan and the coherence of the wider security artefact set, and directing the work of a security architect and a cybersecurity consultant. The role sits at the intersection of naval architecture, systems engineering, product security, information assurance and MOD/maritime cyber compliance. The role requires a strong blend of cybersecurity leadership, secure engineering, technical assurance, stakeholder management, governance, supplier oversight and defence regulatory experience. You will need to operate with autonomy, technical credibility and the ability to provide clear decision support to senior leaders. Own and maintain the Security Management Plan covering OT, IT and physical security, including the assurance and acceptance strategy, management of the supply chain and the route to demonstrating secure by design in accordance with UK MOD requirements. Act as the senior security authority within the client's integrated design team, providing direction, challenge and assurance across engineering and delivery activity. Develop the threat assessment and a proposed security risk appetite for agreement, in lieu of customer-supplied statements. Lead the preliminary security risk assessment and manage design risk exposure, proportionate to the design's maturity, through a live design risk register owned by and reported to the client delivery team. Produce the preliminary specification of security requirements and appropriate standards for OT, IT and physical security, including security classification and criticality assessment. Maintain traceability from threat to risk to control to requirement, so that every security requirement is justified and evidenced. Define supplier and supply chain security requirements and ensure they are embedded in specifications, delivery expectations and technical acceptance criteria. Review and assess supplier security deliverables, including security claims, compliance evidence, technical designs, assurance artefacts and software bills of materials. Direct and quality-assure the work of the security architect and cybersecurity consultant, ensuring the artefact set is coherent, traceable and defensible. Provide security input to formal engineering design reviews, including system design reviews and equivalent programme governance gates, prepare and present material, and close out resulting actions. Manage meetings with security stakeholders and represent the security position to senior client stakeholders and independent technical governance. Apply relevant MOD, NCSC, defence and maritime security frameworks to support assurance, accreditation and compliance activities, and reconcile the security position with the platform safety case. Generate a detailed scope of work for subsequent programme phases, and an outline scope for later phases. Produce clear technical assurance outputs, security design material, decision papers, risk statements, briefing notes and governance updates. Work independently as a senior subject matter expert, determining the day-to-day technical approach, stakeholder engagement and assurance rhythm required to achieve agreed outcomes. Relevant education or industry-recognised certifications in cybersecurity, information assurance, secure engineering, security architecture, risk management or a related discipline. Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CISA, CCP, ISO 27001 Lead Implementer/Lead Auditor, Security+, CySA+, SABSA, TOGAF, IEC 62443, NCSC CAF-related experience or equivalent professional experience. Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
Expleo UK LTD
Cybersecurity Consultant (Discovery, Threat and Requirements)
Expleo UK LTD Bristol, Gloucestershire
Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments. As part of the Expleo UK Cybersecurity Practice, you will deliver the discovery, threat, risk and requirements activity that underpins the security case for a major UK defence maritime programme, supporting an autonomous surface vessel capability being matured towards a whole-ship system design review. This is a delivery-focused consultancy role for someone methodical and evidence-driven. You will establish the asset baseline that everything else traces back to, contribute to the threat and risk picture, and capture the security requirements that the design team will build to. You will work within a small, security-cleared team alongside a Secure by Design lead and a security architect, and directly with the client's design team, in an environment where accuracy, traceability and clear documentation carry real weight. The role suits a cybersecurity consultant with a solid grounding in threat and risk methods and requirements work, who is looking to apply this in a technically demanding defence maritime programme. Lead discovery activity across documentary, logical, interview and physical sources to establish an authoritative asset baseline. Populate and maintain the initial asset register, capturing asset class, criticality, ownership, configuration state, dependencies and interfaces. Establish and maintain the platform threat landscape by drawing on credible, up-to-date threat information. Contribute to threat modelling using recognised methods such as STRIDE and MITRE ATT&CK for Industrial Control Systems, expressed as attack paths. Support the preliminary security risk assessment using NIST SP 800-30 and ISO/IEC 27005, and maintain entries in the design risk register. Capture security requirements and maintain the traceability thread from threat to risk to control to requirement. Support security classification and criticality assessment across platform systems and information. Prepare clear, well-structured documentation and evidence packs suitable for design review and client acceptance. Support the compliance crosswalk of programme artefacts against applicable standards and assurance frameworks. Support security stakeholder meetings, capture actions and drive them to closure. Produce knowledge-transfer material to enable the client design team to maintain the artefacts across subsequent phases. Work collaboratively with colleagues in engineering, architecture, IT, OT, and assurance, and promptly escalate issues and risks. Relevant education or industry-recognised certifications in cybersecurity, information assurance, risk management or a related discipline. Suitable qualifications may include BSc, MSc, CompTIA Security+, CySA+, CISM, CISSP (or associate), ISO 27001 Lead Implementer/Lead Auditor, ISO 27005 risk, ISA/IEC 62443 Cybersecurity Fundamentals Specialist, or equivalent professional experience. Candidates working towards relevant certifications alongside strong practical experience are welcome to apply. Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
Aug 06, 2026
Full time
Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments. As part of the Expleo UK Cybersecurity Practice, you will deliver the discovery, threat, risk and requirements activity that underpins the security case for a major UK defence maritime programme, supporting an autonomous surface vessel capability being matured towards a whole-ship system design review. This is a delivery-focused consultancy role for someone methodical and evidence-driven. You will establish the asset baseline that everything else traces back to, contribute to the threat and risk picture, and capture the security requirements that the design team will build to. You will work within a small, security-cleared team alongside a Secure by Design lead and a security architect, and directly with the client's design team, in an environment where accuracy, traceability and clear documentation carry real weight. The role suits a cybersecurity consultant with a solid grounding in threat and risk methods and requirements work, who is looking to apply this in a technically demanding defence maritime programme. Lead discovery activity across documentary, logical, interview and physical sources to establish an authoritative asset baseline. Populate and maintain the initial asset register, capturing asset class, criticality, ownership, configuration state, dependencies and interfaces. Establish and maintain the platform threat landscape by drawing on credible, up-to-date threat information. Contribute to threat modelling using recognised methods such as STRIDE and MITRE ATT&CK for Industrial Control Systems, expressed as attack paths. Support the preliminary security risk assessment using NIST SP 800-30 and ISO/IEC 27005, and maintain entries in the design risk register. Capture security requirements and maintain the traceability thread from threat to risk to control to requirement. Support security classification and criticality assessment across platform systems and information. Prepare clear, well-structured documentation and evidence packs suitable for design review and client acceptance. Support the compliance crosswalk of programme artefacts against applicable standards and assurance frameworks. Support security stakeholder meetings, capture actions and drive them to closure. Produce knowledge-transfer material to enable the client design team to maintain the artefacts across subsequent phases. Work collaboratively with colleagues in engineering, architecture, IT, OT, and assurance, and promptly escalate issues and risks. Relevant education or industry-recognised certifications in cybersecurity, information assurance, risk management or a related discipline. Suitable qualifications may include BSc, MSc, CompTIA Security+, CySA+, CISM, CISSP (or associate), ISO 27001 Lead Implementer/Lead Auditor, ISO 27005 risk, ISA/IEC 62443 Cybersecurity Fundamentals Specialist, or equivalent professional experience. Candidates working towards relevant certifications alongside strong practical experience are welcome to apply. Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
Expleo UK LTD
Security Architect (OT, IT, Network and Physical)
Expleo UK LTD Bristol, Gloucestershire
Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments. As part of the Expleo UK Cybersecurity Practice, you will define and ensure the security architecture for a major UK defence maritime programme, supporting an autonomous surface vessel capability that is being matured towards a whole-ship system design review. This is a hands-on architecture role for an engineer who is comfortable designing across operational technology, IT, networks, and physical security, and who can serve as a design lead to naval architects, systems engineers, a digital system integrator, and subsystem owners. Because the platform is designed to operate crewless, the architecture must be fail-safe under compromise and maintain a defined minimum-risk state upon loss of the remote command-and-control link. You will own the security architecture and the asset baseline that underpins it, working to the Security Management Plan set by the Secure by Design lead and providing architectural evidence to support formal design review. The role requires strong secure-by-design architectural skills, deep IT and OT understanding, and the ability to translate risk and consequences into segmentation, controls, and defensible design decisions. Develop the security architecture for OT and IT in coordination with the digital system integrator and sub-system owners, and produce the preliminary security architecture design. Partition the platform into zones and conduits in accordance with IEC 62443, setting target security levels based on safety and mission consequences. Review the network architecture and communications security, and provide advice, including on the resilience of remote command-and-control links and of position, navigation, and timing. Produce the network security architecture in coordination with the digital teams. Review the physical security provision in the design and develop appropriate protection measures, producing the physical security design in coordination with the arrangement team. Define trust boundaries, segregation, secure configuration baselines, identity and access management, and secure remote access requirements for shipboard and supporting systems. Build and structure the initial asset register for configuration control, capturing criticality, zone, ownership and dependency attributes. Support threat modelling and security risk assessment from an architecture perspective, and translate assessed risk into architectural controls. Define architecture-level security requirements and maintain their traceability into the wider requirements specification. Assure that architectural controls are fail-safe and do not defeat safety functions, working alongside safety and engineering colleagues. Provide architectural evidence and materials for internal and external design reviews, including system design reviews, and close out resulting actions. Contribute to supplier and interface security requirements where these bear on the architecture, including third-party payload and control-system interfaces. Produce clear high- and low-level design material, architecture views, decision records and design rationale suitable for technical scrutiny. Relevant education or industry-recognised certifications in security architecture, cybersecurity, secure engineering, operational technology security or a related discipline. Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CCP, ISA/IEC 62443 (Fundamentals Specialist, Risk Assessment Specialist, Design Specialist or Expert), SABSA, TOGAF, CCNP, OSCP, ISO 27001 Lead Implementer/Lead Auditor or equivalent professional experience. Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
Aug 06, 2026
Full time
Expleo is a trusted partner for end-to-end, integrated engineering, quality services, and management consulting for digital transformation. We help businesses harness technological change to successfully deliver innovation, improve resilience and support secure, regulated and operationally critical environments. As part of the Expleo UK Cybersecurity Practice, you will define and ensure the security architecture for a major UK defence maritime programme, supporting an autonomous surface vessel capability that is being matured towards a whole-ship system design review. This is a hands-on architecture role for an engineer who is comfortable designing across operational technology, IT, networks, and physical security, and who can serve as a design lead to naval architects, systems engineers, a digital system integrator, and subsystem owners. Because the platform is designed to operate crewless, the architecture must be fail-safe under compromise and maintain a defined minimum-risk state upon loss of the remote command-and-control link. You will own the security architecture and the asset baseline that underpins it, working to the Security Management Plan set by the Secure by Design lead and providing architectural evidence to support formal design review. The role requires strong secure-by-design architectural skills, deep IT and OT understanding, and the ability to translate risk and consequences into segmentation, controls, and defensible design decisions. Develop the security architecture for OT and IT in coordination with the digital system integrator and sub-system owners, and produce the preliminary security architecture design. Partition the platform into zones and conduits in accordance with IEC 62443, setting target security levels based on safety and mission consequences. Review the network architecture and communications security, and provide advice, including on the resilience of remote command-and-control links and of position, navigation, and timing. Produce the network security architecture in coordination with the digital teams. Review the physical security provision in the design and develop appropriate protection measures, producing the physical security design in coordination with the arrangement team. Define trust boundaries, segregation, secure configuration baselines, identity and access management, and secure remote access requirements for shipboard and supporting systems. Build and structure the initial asset register for configuration control, capturing criticality, zone, ownership and dependency attributes. Support threat modelling and security risk assessment from an architecture perspective, and translate assessed risk into architectural controls. Define architecture-level security requirements and maintain their traceability into the wider requirements specification. Assure that architectural controls are fail-safe and do not defeat safety functions, working alongside safety and engineering colleagues. Provide architectural evidence and materials for internal and external design reviews, including system design reviews, and close out resulting actions. Contribute to supplier and interface security requirements where these bear on the architecture, including third-party payload and control-system interfaces. Produce clear high- and low-level design material, architecture views, decision records and design rationale suitable for technical scrutiny. Relevant education or industry-recognised certifications in security architecture, cybersecurity, secure engineering, operational technology security or a related discipline. Suitable qualifications may include BSc, MSc, CISSP, CISM, CRISC, CCP, ISA/IEC 62443 (Fundamentals Specialist, Risk Assessment Specialist, Design Specialist or Expert), SABSA, TOGAF, CCNP, OSCP, ISO 27001 Lead Implementer/Lead Auditor or equivalent professional experience. Experience working within UK MOD, defence, maritime, shipbuilding, naval, critical national infrastructure or operationally critical environments would be highly beneficial.
IT / Network Security Engineer
Tank Recruitment
IT & Network Security Engineer Job Title: IT Security Engineer Location: Oxfordshire - Hybrid (2 days per week on-site) Industry: Enterprise SaaS / Technology Solutions About the Role We are partnering with a rapidly scaling, globally active software and data platform enterprise looking to appoint a dedicated IT Security Engineer to join their growing security operations team. In this role, you will be instrumental in defending core infrastructure, enterprise networks, and critical data against modern cyber threats. Working closely with the Head of IT Security, you will oversee threat detection, manage security appliances, enforce compliance frameworks, and ensure that robust defensive postures are embedded across the technology stack. Key Responsibilities Security Operations: Oversee network telemetry for suspicious activities, execute rapid threat detection and response, tune perimeter defenses (firewalls and virtual private networks), and direct proactive patch management cycles. Compliance & Audits: Drive internal control testing and maintain alignment with structured information security standards such as ISO 27001, supporting both internal evaluations and external auditor walkthroughs. Incident Handling: Manage the end-to-end lifecycle of security alerts or breaches, lead formal root-cause analysis, and embed corrective actions into future preventive safeguards. Third-Party Risk: Evaluate external vendors and technology partners to ensure compliance with internal security policies and benchmark security standards. Cross-Functional Collaboration: Partner directly with IT infrastructure, application support, software engineering, and legal teams to bake security-by-design principles into technical architectures. Key Requirements Experience: A minimum of 3 to 5 years of dedicated professional experience within an IT or information security function. Technical Proficiency: Deep working knowledge of core network protocols (TCP/IP, DNS, routing, switching) and architecture design. Hands-on proficiency with network analysis utilities, packet sniffers, port scanners, and SIEM monitoring suites. Working familiarity with cryptographic methods, identity controls, endpoint hardening, and multi-cloud security management (AWS, Azure, or GCP). Framework Knowledge: Solid comprehension of ISO 27001 principles, threat modelling frameworks, vulnerability scanning, risk treatment life-cycles, and secondary compliance standards (e.g., SOC 2 or PCI DSS). Qualifications: Relevant technical diploma or equivalent practical background, reinforced by desirable professional credentials (such as CISSP, CEH, CCNA Security, or ISO 27001 Lead Auditor certifications). Personal Attributes: Strong analytical problem-solving skills, clear communication capabilities, and the adaptability to thrive in a fast-moving, collaborative environment. What is on Offer Competitive base salary package. Sustainable hybrid working model (2 days on-site in Oxfordshire). Continuous professional development and training opportunities within an expanding tech organisation. If you are a proactive security professional looking to make a meaningful impact, please submit your CV to begin a confidential discussion.
Aug 05, 2026
Full time
IT & Network Security Engineer Job Title: IT Security Engineer Location: Oxfordshire - Hybrid (2 days per week on-site) Industry: Enterprise SaaS / Technology Solutions About the Role We are partnering with a rapidly scaling, globally active software and data platform enterprise looking to appoint a dedicated IT Security Engineer to join their growing security operations team. In this role, you will be instrumental in defending core infrastructure, enterprise networks, and critical data against modern cyber threats. Working closely with the Head of IT Security, you will oversee threat detection, manage security appliances, enforce compliance frameworks, and ensure that robust defensive postures are embedded across the technology stack. Key Responsibilities Security Operations: Oversee network telemetry for suspicious activities, execute rapid threat detection and response, tune perimeter defenses (firewalls and virtual private networks), and direct proactive patch management cycles. Compliance & Audits: Drive internal control testing and maintain alignment with structured information security standards such as ISO 27001, supporting both internal evaluations and external auditor walkthroughs. Incident Handling: Manage the end-to-end lifecycle of security alerts or breaches, lead formal root-cause analysis, and embed corrective actions into future preventive safeguards. Third-Party Risk: Evaluate external vendors and technology partners to ensure compliance with internal security policies and benchmark security standards. Cross-Functional Collaboration: Partner directly with IT infrastructure, application support, software engineering, and legal teams to bake security-by-design principles into technical architectures. Key Requirements Experience: A minimum of 3 to 5 years of dedicated professional experience within an IT or information security function. Technical Proficiency: Deep working knowledge of core network protocols (TCP/IP, DNS, routing, switching) and architecture design. Hands-on proficiency with network analysis utilities, packet sniffers, port scanners, and SIEM monitoring suites. Working familiarity with cryptographic methods, identity controls, endpoint hardening, and multi-cloud security management (AWS, Azure, or GCP). Framework Knowledge: Solid comprehension of ISO 27001 principles, threat modelling frameworks, vulnerability scanning, risk treatment life-cycles, and secondary compliance standards (e.g., SOC 2 or PCI DSS). Qualifications: Relevant technical diploma or equivalent practical background, reinforced by desirable professional credentials (such as CISSP, CEH, CCNA Security, or ISO 27001 Lead Auditor certifications). Personal Attributes: Strong analytical problem-solving skills, clear communication capabilities, and the adaptability to thrive in a fast-moving, collaborative environment. What is on Offer Competitive base salary package. Sustainable hybrid working model (2 days on-site in Oxfordshire). Continuous professional development and training opportunities within an expanding tech organisation. If you are a proactive security professional looking to make a meaningful impact, please submit your CV to begin a confidential discussion.
Information Security & Compliance Lead (GRC)
Tank Recruitment
Information Security & Compliance Lead (GRC) Job Title: Information Security & Compliance Lead Location: Oxfordshire - Hybrid 2 days per week on site Industry: Enterprise SaaS / Technology Solutions About the Role We are partnering with a fast-growing, globally active software and data solutions enterprise looking to appoint an experienced Lead level Information Security & Compliance specialist (GRC). In this position, you will drive the operational security initiatives necessary to achieve and maintain formal security frameworks and attestation standards (including SOC 2 Type I/II lifecycles). You will translate complex trust criteria into practical, sustainable controls, bridge operational gaps, coordinate external audits, and elevate day-to-day security engineering across cloud platforms, products, and supply chains. Collaborating closely with engineering, product, legal, and operational teams, you will ensure security measures are robust, scalable, and integrated seamlessly without causing business friction. Key Responsibilities Assurance & Audit Management: Own the compliance roadmap from initial readiness assessments through to operating effectiveness and annual recurring audits; coordinate third-party auditors and evidence gathering. Control Engineering: Design, implement, and refine technical controls covering identity and access management, cloud security architecture, encryption, logging, monitoring, and endpoint protection. Risk & Governance: Maintain risk registers, execute supplier security due diligence, manage exception workflows, and deliver targeted security awareness programmes across internal teams. Vulnerability & Incident Operations: Strengthen patching schedules, penetration test remediation, secure change management, backup validation, and incident response procedures. Cross-Functional Collaboration: Partner with engineering and product groups to embed security-by-design principles into software delivery pipelines and operational workflows. Key Requirements Experience: Proven professional background delivering or materially supporting SOC 2 compliance readiness programmes or equivalent independent security audits within a cloud-first or SaaS environment. Technical Expertise: Hands-on experience engineering and testing security controls across major cloud infrastructure, IAM systems, endpoint tools, and SIEM monitoring platforms. Framework Knowledge: Strong working familiarity with trust service criteria, information security risk models (such as ISO 27001, NIST, or CIS benchmarks), and third-party risk principles. Competencies: Strong project ownership, excellent cross-functional communication skills, analytical rigor, and the ability to translate technical risk for diverse stakeholders. Qualifications: Relevant degree in Computer Science, Cyber Security, or equivalent practical experience, backed by recognized security or auditing certifications (such as CISSP, CISA, CCSP, or similar credentials).
Aug 05, 2026
Full time
Information Security & Compliance Lead (GRC) Job Title: Information Security & Compliance Lead Location: Oxfordshire - Hybrid 2 days per week on site Industry: Enterprise SaaS / Technology Solutions About the Role We are partnering with a fast-growing, globally active software and data solutions enterprise looking to appoint an experienced Lead level Information Security & Compliance specialist (GRC). In this position, you will drive the operational security initiatives necessary to achieve and maintain formal security frameworks and attestation standards (including SOC 2 Type I/II lifecycles). You will translate complex trust criteria into practical, sustainable controls, bridge operational gaps, coordinate external audits, and elevate day-to-day security engineering across cloud platforms, products, and supply chains. Collaborating closely with engineering, product, legal, and operational teams, you will ensure security measures are robust, scalable, and integrated seamlessly without causing business friction. Key Responsibilities Assurance & Audit Management: Own the compliance roadmap from initial readiness assessments through to operating effectiveness and annual recurring audits; coordinate third-party auditors and evidence gathering. Control Engineering: Design, implement, and refine technical controls covering identity and access management, cloud security architecture, encryption, logging, monitoring, and endpoint protection. Risk & Governance: Maintain risk registers, execute supplier security due diligence, manage exception workflows, and deliver targeted security awareness programmes across internal teams. Vulnerability & Incident Operations: Strengthen patching schedules, penetration test remediation, secure change management, backup validation, and incident response procedures. Cross-Functional Collaboration: Partner with engineering and product groups to embed security-by-design principles into software delivery pipelines and operational workflows. Key Requirements Experience: Proven professional background delivering or materially supporting SOC 2 compliance readiness programmes or equivalent independent security audits within a cloud-first or SaaS environment. Technical Expertise: Hands-on experience engineering and testing security controls across major cloud infrastructure, IAM systems, endpoint tools, and SIEM monitoring platforms. Framework Knowledge: Strong working familiarity with trust service criteria, information security risk models (such as ISO 27001, NIST, or CIS benchmarks), and third-party risk principles. Competencies: Strong project ownership, excellent cross-functional communication skills, analytical rigor, and the ability to translate technical risk for diverse stakeholders. Qualifications: Relevant degree in Computer Science, Cyber Security, or equivalent practical experience, backed by recognized security or auditing certifications (such as CISSP, CISA, CCSP, or similar credentials).
CBSbutler Holdings Limited trading as CBSbutler
Junior Cyber Security Auditor
CBSbutler Holdings Limited trading as CBSbutler Corsham, Wiltshire
Cyber Security Auditor +Permanent opportunity +Hybrid working - Corsham / West Country +SC / DV clearance is essential We are looking for Cyber Security Auditors to join a growing team delivering high-impact assurance services across UK Government and Defence programmes. This role is suited to auditors already operating within NCSC-aligned frameworks , with the ability to lead and deliver audits across nationally significant cyber assurance schemes. Essential Requirements (Must Have) ISO27001 Lead Auditor qualification (or equivalent) Chartered Auditor and Assessor accreditation Active presence on the NCSC Assured Service Provider / Auditor register Proven experience delivering NCSC-aligned audits The Role You will lead the delivery of cyber security audits across frameworks such as CAF, DCC, and GovAssure , supporting government-led cyber resilience initiatives. Key responsibilities include: Leading end-to-end cyber security audits across client environments Assessing compliance against frameworks such as CAF (v3.2 / v4.0) and GovAssure Producing high-quality audit reports with clear, actionable recommendations Engaging with stakeholders to support remediation and continuous improvement Maintaining audit documentation and evidencing to regulatory standards Staying current with evolving NCSC guidance, standards, and best practice What We're Looking For Minimum 3+ years' experience in cyber auditing, compliance, or risk (Public Sector / Defence preferred) Strong working knowledge of NCSC CAF frameworks Experience leading audit engagements and managing audit teams Excellent stakeholder engagement and report writing skills Ability to operate independently in client-facing environments Due to the nature of the roles, applicants must be UK sole nationals and hold UK Security Clearance to SC level, or preferably DV. If you'd like to discuss this role in more detail, please send your updated CV to (url removed) and I will get in touch.
Aug 04, 2026
Full time
Cyber Security Auditor +Permanent opportunity +Hybrid working - Corsham / West Country +SC / DV clearance is essential We are looking for Cyber Security Auditors to join a growing team delivering high-impact assurance services across UK Government and Defence programmes. This role is suited to auditors already operating within NCSC-aligned frameworks , with the ability to lead and deliver audits across nationally significant cyber assurance schemes. Essential Requirements (Must Have) ISO27001 Lead Auditor qualification (or equivalent) Chartered Auditor and Assessor accreditation Active presence on the NCSC Assured Service Provider / Auditor register Proven experience delivering NCSC-aligned audits The Role You will lead the delivery of cyber security audits across frameworks such as CAF, DCC, and GovAssure , supporting government-led cyber resilience initiatives. Key responsibilities include: Leading end-to-end cyber security audits across client environments Assessing compliance against frameworks such as CAF (v3.2 / v4.0) and GovAssure Producing high-quality audit reports with clear, actionable recommendations Engaging with stakeholders to support remediation and continuous improvement Maintaining audit documentation and evidencing to regulatory standards Staying current with evolving NCSC guidance, standards, and best practice What We're Looking For Minimum 3+ years' experience in cyber auditing, compliance, or risk (Public Sector / Defence preferred) Strong working knowledge of NCSC CAF frameworks Experience leading audit engagements and managing audit teams Excellent stakeholder engagement and report writing skills Ability to operate independently in client-facing environments Due to the nature of the roles, applicants must be UK sole nationals and hold UK Security Clearance to SC level, or preferably DV. If you'd like to discuss this role in more detail, please send your updated CV to (url removed) and I will get in touch.
URENCO UK Ltd
Information Security Technical Assurance Lead
URENCO UK Ltd Paddington, Warrington
Help us to make a world of difference Urenco is a global leader in the production of low carbon energy. We work at the cutting edge of the transition to a sustainable, net zero world. We are seeking an Information Security Technical Assurance Lead to join our team at our Paddington Head Office. This role sits within the CISO function, which is dedicated to continuously evolving and strengthening Urenco s cyber security capabilities to protect our business, customers, and the wider public, while supporting the safe and sustainable use of nuclear technology. As part of the Cyber Security Assurance team , and reporting to the Head of Cyber Security Assurance, you will play a key role in driving improvements to Urenco s overall cyber security maturity. This position requires close collaboration with business stakeholders, as well as colleagues across IT and Information Security. With a strong focus on application security across both on-premises and cloud environments, you will lead assurance activities that help embed secure practices across the organisation. This is a hybrid role, with an expectation of a minimum of two days per week in our London Paddington office. Occasional travel may be required. The successful candidate will be required to obtain and maintain SC clearance. At Urenco we re committed to giving you opportunities to be your best. If you feel you meet some, but not all of what we're looking for, please still apply. We believe in embracing the passion and potential of our people, and to achieve this we offer market leading training and development experiences. Along with the opportunity to be mentored and coached by some of the smartest minds in the industry. What you ll do: Assure Security Designs and Solutions Produce and review technical security documentation to support secure solution delivery. Partner with business stakeholders to understand requirements and embed strong security practices across initiatives. Act as a trusted advisor and security advocate, promoting a security-first culture across the organisation. Review technical designs against security standards and policies, identifying gaps and recommending improvements to controls. Provide assurance across both on-premises and cloud environments, ensuring consistent security coverage. Assess and Manage Security Risk Collaborate with GRC teams, security architects, and business stakeholders to conduct risk assessments, define mitigations, and document outcomes. Work closely with IT teams to validate and assure the effectiveness of technical controls against identified threats. Translate business strategy and requirements into secure architectural approaches, clearly communicating risk and enabling appropriate control solutions. Conduct supplier assurance activities across on-premises, cloud, and hybrid services, providing clear, actionable recommendations. Define Security Standards, Policies and Guidance Develop and maintain application security policies, standards, and guidelines. Ensure alignment between security frameworks, architectural standards, and overall business strategy. Stay current with emerging threats, technologies, and industry best practices, continuously enhancing Urenco s security posture. What do you need to thrive in this role? Proven experience working in a global organisation, delivering against the key responsibilities outlined above. A degree in Computer Science, Information Security, or a related discipline, or equivalent industry experience. Relevant cybersecurity certifications (one or more), such as: CISSP (Certified Information Systems Security Professional) CISA (Certified Information Systems Auditor) CSSLP (Certified Secure Software Lifecycle Professional) GWAPT (GIAC Web Application Penetration Tester) GCSA (GIAC Cloud Security Automation) CASE (Certified Application Security Engineer) Certified DevSecOps Professional Strong familiarity with OWASP (including Top 10 and ASVS) At least 5 years experience in information security assurance, with a strong focus on application security. Hands-on experience with information security frameworks and regulatory compliance, such as ISO 27001 and the NIST SP 800 series / Cybersecurity Framework. Desirable Knowledge of regulatory requirements within the nuclear industry, particularly across the United States, United Kingdom, Netherlands, and Germany. Understanding of government security classifications and associated handling requirements. What can you expect from us? More than just a job, we offer a future. More than just a place to work, we provide an opportunity to prosper. As an employee of Urenco you will receive: Annual leave of 27 days per annum. A generous bonus scheme based on achievement of personal and company objectives. A diverse range of family friendly policies. A defined contribution pension scheme: contributions start at 4% (employee) and 10% (employer). Hybrid Working Pattern: up to two days working remotely on average per week. Flexible start and finish times, with a 1.30pm finish on Fridays. Flexible benefits package; including life assurance and income protection. In addition, you ll have an opportunity to purchase additional benefits that suit your lifestyle. Paid time off for volunteering. The opportunity to join our private medical and dental insurance schemes. Education and training; we take pride in helping people learn and develop by supporting, accelerating and directing your learning. As well as the completion of mandatory health and safety courses, training packages will be offered to meet your specific needs. Security vetting Due to the nature of the industry that Urenco operates in, all personnel regardless of employment status working for Urenco are required to obtain security clearance at the level required for their role. Security clearances are assessed in accordance with regulations and official guidance issued by the relevant competent authorities for national security vetting. In certain circumstances, additional enhanced security clearance considerations apply to roles within Urenco owing to the particular activities that the Urenco Group undertakes in relation to uranium enrichment. Successful candidates will need to satisfy security requirements, and all offers of appointment are made subject to the successful approval of all checks initiated. Creating a diverse and inclusive workforce As a truly global company with a presence in the UK, USA, Germany, and the Netherlands, we know that our individual differences make us stronger. Putting people at the heart of our business, we strive to create an open and inclusive workplace that allows every voice to be heard and diversity to thrive. If you require any reasonable adjustments to the recruitment process, please let our talent acquisition team know. Because together, we are one Urenco. We are enriching the world. And enriching your future.
Aug 03, 2026
Full time
Help us to make a world of difference Urenco is a global leader in the production of low carbon energy. We work at the cutting edge of the transition to a sustainable, net zero world. We are seeking an Information Security Technical Assurance Lead to join our team at our Paddington Head Office. This role sits within the CISO function, which is dedicated to continuously evolving and strengthening Urenco s cyber security capabilities to protect our business, customers, and the wider public, while supporting the safe and sustainable use of nuclear technology. As part of the Cyber Security Assurance team , and reporting to the Head of Cyber Security Assurance, you will play a key role in driving improvements to Urenco s overall cyber security maturity. This position requires close collaboration with business stakeholders, as well as colleagues across IT and Information Security. With a strong focus on application security across both on-premises and cloud environments, you will lead assurance activities that help embed secure practices across the organisation. This is a hybrid role, with an expectation of a minimum of two days per week in our London Paddington office. Occasional travel may be required. The successful candidate will be required to obtain and maintain SC clearance. At Urenco we re committed to giving you opportunities to be your best. If you feel you meet some, but not all of what we're looking for, please still apply. We believe in embracing the passion and potential of our people, and to achieve this we offer market leading training and development experiences. Along with the opportunity to be mentored and coached by some of the smartest minds in the industry. What you ll do: Assure Security Designs and Solutions Produce and review technical security documentation to support secure solution delivery. Partner with business stakeholders to understand requirements and embed strong security practices across initiatives. Act as a trusted advisor and security advocate, promoting a security-first culture across the organisation. Review technical designs against security standards and policies, identifying gaps and recommending improvements to controls. Provide assurance across both on-premises and cloud environments, ensuring consistent security coverage. Assess and Manage Security Risk Collaborate with GRC teams, security architects, and business stakeholders to conduct risk assessments, define mitigations, and document outcomes. Work closely with IT teams to validate and assure the effectiveness of technical controls against identified threats. Translate business strategy and requirements into secure architectural approaches, clearly communicating risk and enabling appropriate control solutions. Conduct supplier assurance activities across on-premises, cloud, and hybrid services, providing clear, actionable recommendations. Define Security Standards, Policies and Guidance Develop and maintain application security policies, standards, and guidelines. Ensure alignment between security frameworks, architectural standards, and overall business strategy. Stay current with emerging threats, technologies, and industry best practices, continuously enhancing Urenco s security posture. What do you need to thrive in this role? Proven experience working in a global organisation, delivering against the key responsibilities outlined above. A degree in Computer Science, Information Security, or a related discipline, or equivalent industry experience. Relevant cybersecurity certifications (one or more), such as: CISSP (Certified Information Systems Security Professional) CISA (Certified Information Systems Auditor) CSSLP (Certified Secure Software Lifecycle Professional) GWAPT (GIAC Web Application Penetration Tester) GCSA (GIAC Cloud Security Automation) CASE (Certified Application Security Engineer) Certified DevSecOps Professional Strong familiarity with OWASP (including Top 10 and ASVS) At least 5 years experience in information security assurance, with a strong focus on application security. Hands-on experience with information security frameworks and regulatory compliance, such as ISO 27001 and the NIST SP 800 series / Cybersecurity Framework. Desirable Knowledge of regulatory requirements within the nuclear industry, particularly across the United States, United Kingdom, Netherlands, and Germany. Understanding of government security classifications and associated handling requirements. What can you expect from us? More than just a job, we offer a future. More than just a place to work, we provide an opportunity to prosper. As an employee of Urenco you will receive: Annual leave of 27 days per annum. A generous bonus scheme based on achievement of personal and company objectives. A diverse range of family friendly policies. A defined contribution pension scheme: contributions start at 4% (employee) and 10% (employer). Hybrid Working Pattern: up to two days working remotely on average per week. Flexible start and finish times, with a 1.30pm finish on Fridays. Flexible benefits package; including life assurance and income protection. In addition, you ll have an opportunity to purchase additional benefits that suit your lifestyle. Paid time off for volunteering. The opportunity to join our private medical and dental insurance schemes. Education and training; we take pride in helping people learn and develop by supporting, accelerating and directing your learning. As well as the completion of mandatory health and safety courses, training packages will be offered to meet your specific needs. Security vetting Due to the nature of the industry that Urenco operates in, all personnel regardless of employment status working for Urenco are required to obtain security clearance at the level required for their role. Security clearances are assessed in accordance with regulations and official guidance issued by the relevant competent authorities for national security vetting. In certain circumstances, additional enhanced security clearance considerations apply to roles within Urenco owing to the particular activities that the Urenco Group undertakes in relation to uranium enrichment. Successful candidates will need to satisfy security requirements, and all offers of appointment are made subject to the successful approval of all checks initiated. Creating a diverse and inclusive workforce As a truly global company with a presence in the UK, USA, Germany, and the Netherlands, we know that our individual differences make us stronger. Putting people at the heart of our business, we strive to create an open and inclusive workplace that allows every voice to be heard and diversity to thrive. If you require any reasonable adjustments to the recruitment process, please let our talent acquisition team know. Because together, we are one Urenco. We are enriching the world. And enriching your future.
Conventus Solutions Ltd
Junior Cyber Audit Consultant - Contract
Conventus Solutions Ltd
Location: Hybrid with travel to Corsham and other South Military sites. Duration: 12 months+ Security Clearance: SC Conventus requires a Junior Cyber Audit Consultant to work on a 12 month contract to join a Defence focused Cyber Assurance team, playing a supporting role to senior consultants delivering audits across customer processes and systems. This is a great opportunity for someone to deliver Defence Cyber Risk Profile (CRP) audit work. Responsibilities: Plan and conduct audits of customer processes and systems to ensure compliance with regulatory requirements such as the NCSC Cyber Assessment Framework (CAF) and GovAssure. Support and, over time, help lead audit activity, ensuring findings are properly documented and reported. Communicate audit findings and recommendations, working collaboratively with management to help develop and implement effective corrective actions. Maintain accurate and current records of audit activities, including audit reports and documentation of corrective actions taken. Stay current with regulatory requirements and industry best practice relating to auditing, compliance and risk management. Contribute to cyber report writing and the production of Cyber Risk Profiles (CRP) Skills/Experience: Experience of ISO 27001, the NCSC Cyber Assessment Framework (CAF), DCC and Cyber Risk Profile (CRP) work. Experience of cyber report writing. Relevant ISO certification (for example ISO 27001 Lead Auditor or equivalent) is desirable. Experience in auditing, compliance or risk management, ideally gained in the Public Sector, particularly Defence. Understanding of NCSC CAF v3.2/v4.0. Some MoD experience is desirable but not essential. Strong analytical and problem solving skills. Excellent communication and interpersonal skills. Ability to work independently and as part of a team. Initial 12 month contract position for a Cyber Audit Consultant, paying up to 500 per day (depending on experience). Due to the nature of the work, applicants must hold or be eligible to hold UK Security clearance to SC level. Please familiarise yourself with the security vetting process before applying.
Jul 31, 2026
Contractor
Location: Hybrid with travel to Corsham and other South Military sites. Duration: 12 months+ Security Clearance: SC Conventus requires a Junior Cyber Audit Consultant to work on a 12 month contract to join a Defence focused Cyber Assurance team, playing a supporting role to senior consultants delivering audits across customer processes and systems. This is a great opportunity for someone to deliver Defence Cyber Risk Profile (CRP) audit work. Responsibilities: Plan and conduct audits of customer processes and systems to ensure compliance with regulatory requirements such as the NCSC Cyber Assessment Framework (CAF) and GovAssure. Support and, over time, help lead audit activity, ensuring findings are properly documented and reported. Communicate audit findings and recommendations, working collaboratively with management to help develop and implement effective corrective actions. Maintain accurate and current records of audit activities, including audit reports and documentation of corrective actions taken. Stay current with regulatory requirements and industry best practice relating to auditing, compliance and risk management. Contribute to cyber report writing and the production of Cyber Risk Profiles (CRP) Skills/Experience: Experience of ISO 27001, the NCSC Cyber Assessment Framework (CAF), DCC and Cyber Risk Profile (CRP) work. Experience of cyber report writing. Relevant ISO certification (for example ISO 27001 Lead Auditor or equivalent) is desirable. Experience in auditing, compliance or risk management, ideally gained in the Public Sector, particularly Defence. Understanding of NCSC CAF v3.2/v4.0. Some MoD experience is desirable but not essential. Strong analytical and problem solving skills. Excellent communication and interpersonal skills. Ability to work independently and as part of a team. Initial 12 month contract position for a Cyber Audit Consultant, paying up to 500 per day (depending on experience). Due to the nature of the work, applicants must hold or be eligible to hold UK Security clearance to SC level. Please familiarise yourself with the security vetting process before applying.
Computappoint
Supplier Security Assurance Manager (SC Cleared)
Computappoint
Supplier Security Assurance Manager (SC Cleared) Employment Type : Contract Day Rate: £550 to £580 p/d Inside IR35 (based on candidate experience) IR35 Status : Inside IR35 Contract Length: 6-months (likely to extend indefinitely) Hybrid Model (Subject to customer requirement): Mostly remote, may occasionally require 1-2 days per week on-site in London office, as well as attendance to client sites for audits/essential meetings etc. Office/Customer Locations: Office locations are spread throughout the country (mostly London, occasionally Leeds, Manchester, Newcastle). Travel to Customer Sites: Expensed by client. Security Clearance : Active SC Clearance (Essential) About the Client and Role: My client, a leading Cyber Security Services provider that specialise in supporting security services to the public sector, such as Police, Government & Defence, is seeking a Supplier Security Assurance Manager to lend their expertise of Security Supplier Assurance. The candidate will be expected to support the delivery of the Supplier Security Assurance process throughout all stages of procurement/contract interactions. Responsibilities will include identifying risks, reporting, security reviews & auditing and ensuring minimum security standards are consistently met. Security Clearance: Active SC is essential Highly Desirable: Experience in Central Government/providing services to government departments Main Responsibilities: Auditing of suppliers for security purposes. Candidates must have outstanding skill producing clear and well documented audits. Ensure security due diligence is conducted on all bid applications as part of the procurement process. Identify physical, personnel and information security risks and/or vulnerabilities and report these prior to contract award. Work with business to provide suppliers with early insight into the mandatory minimums security requirements expected of them during the life of a contract. Supporting and ensuring consistency in approach for the delivery of Supplier Security Assurance across Commercial Directorate Conduct on-going assurance activities post contract award to ensure supplier maintain compliance with minimum security requirements. Conduct on-site supplier security assessments/reports/audits Desirable Certifications: Certified Cyber Professional (CCP) Security Information Risk Advisor (SIRA) Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) Certification in Information Security Management Principles (CISMP) Governance Risk & Compliance Professional (GRCP) ISO27001 Lead Auditor
Oct 08, 2025
Contractor
Supplier Security Assurance Manager (SC Cleared) Employment Type : Contract Day Rate: £550 to £580 p/d Inside IR35 (based on candidate experience) IR35 Status : Inside IR35 Contract Length: 6-months (likely to extend indefinitely) Hybrid Model (Subject to customer requirement): Mostly remote, may occasionally require 1-2 days per week on-site in London office, as well as attendance to client sites for audits/essential meetings etc. Office/Customer Locations: Office locations are spread throughout the country (mostly London, occasionally Leeds, Manchester, Newcastle). Travel to Customer Sites: Expensed by client. Security Clearance : Active SC Clearance (Essential) About the Client and Role: My client, a leading Cyber Security Services provider that specialise in supporting security services to the public sector, such as Police, Government & Defence, is seeking a Supplier Security Assurance Manager to lend their expertise of Security Supplier Assurance. The candidate will be expected to support the delivery of the Supplier Security Assurance process throughout all stages of procurement/contract interactions. Responsibilities will include identifying risks, reporting, security reviews & auditing and ensuring minimum security standards are consistently met. Security Clearance: Active SC is essential Highly Desirable: Experience in Central Government/providing services to government departments Main Responsibilities: Auditing of suppliers for security purposes. Candidates must have outstanding skill producing clear and well documented audits. Ensure security due diligence is conducted on all bid applications as part of the procurement process. Identify physical, personnel and information security risks and/or vulnerabilities and report these prior to contract award. Work with business to provide suppliers with early insight into the mandatory minimums security requirements expected of them during the life of a contract. Supporting and ensuring consistency in approach for the delivery of Supplier Security Assurance across Commercial Directorate Conduct on-going assurance activities post contract award to ensure supplier maintain compliance with minimum security requirements. Conduct on-site supplier security assessments/reports/audits Desirable Certifications: Certified Cyber Professional (CCP) Security Information Risk Advisor (SIRA) Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) Certification in Information Security Management Principles (CISMP) Governance Risk & Compliance Professional (GRCP) ISO27001 Lead Auditor
Ashdown Group
Head of Information Security
Ashdown Group
A well-established business is looking for an accomplished Head of Information Security to join its team based in London. Please note this is an office-based role, so you will work from the office 5 days per week. In this role of significant responsibility, you will design and lead the information security strategy for the organisation. Supported by a Cyber Security Analyst you will provide InfoSec expertise, ensuring that the business has a secure, resilient and robust technology estate, and will also ensure that effective security governance policies and procedures are in place. In order to be suitable for this role, you must be a highly capable information security leader with a proven track record of delivering secure, compliant and robust systems and procedures. CISSP or similar accreditation would be highly advantageous to your application. Key responsibilities will include:- Evolving a cyber and information security strategy aligned with ISO27001 standards and business objectives. - Lead the design, implementation, and continuous improvement of the Information Security Management System (ISMS) - Oversee risk management activities, including risk assessments, mitigation planning, and incident response.You will work with senior stakeholders to ensure alignment between security initiatives and organisational priorities and strive to continually harden and enhance the organisation's IT systems. You will be effective at managing relationships with third party suppliers and external auditors and will deliver awareness training, enhance and test the businesses disaster recovery, continuity and incident response plans, and carry our internal audits for the InfoSec governance frameworks. This is an excellent opportunity for a Head of Information Security to join a market leading business.
Oct 07, 2025
Full time
A well-established business is looking for an accomplished Head of Information Security to join its team based in London. Please note this is an office-based role, so you will work from the office 5 days per week. In this role of significant responsibility, you will design and lead the information security strategy for the organisation. Supported by a Cyber Security Analyst you will provide InfoSec expertise, ensuring that the business has a secure, resilient and robust technology estate, and will also ensure that effective security governance policies and procedures are in place. In order to be suitable for this role, you must be a highly capable information security leader with a proven track record of delivering secure, compliant and robust systems and procedures. CISSP or similar accreditation would be highly advantageous to your application. Key responsibilities will include:- Evolving a cyber and information security strategy aligned with ISO27001 standards and business objectives. - Lead the design, implementation, and continuous improvement of the Information Security Management System (ISMS) - Oversee risk management activities, including risk assessments, mitigation planning, and incident response.You will work with senior stakeholders to ensure alignment between security initiatives and organisational priorities and strive to continually harden and enhance the organisation's IT systems. You will be effective at managing relationships with third party suppliers and external auditors and will deliver awareness training, enhance and test the businesses disaster recovery, continuity and incident response plans, and carry our internal audits for the InfoSec governance frameworks. This is an excellent opportunity for a Head of Information Security to join a market leading business.
Hays
IT Internal Auditor / Audit Manager
Hays
IT Specialist Internal Auditor needed to drive innovation - London-based - £70k+ Your new company This company is looking to transform their audit team by gaining an IT audit specialist to create robust IT systems to ensure compliance with industry standards. They are looking for a skilled IT Specialist Internal Auditor to join our team. This role is crucial in evaluating and improving our IT controls and ensuring the integrity of our information systems. Key Responsibilities: Conduct comprehensive IT audits, including planning, execution, and reporting. Assess the effectiveness of IT controls and identify areas for improvement. Evaluate IT systems and processes to ensure compliance with regulatory requirements and industry best practices. Utilise data analytics to streamline audit plans and enhance audit efficiency. Collaborate with IT and business teams to address audit findings and implement corrective actions. Prepare detailed audit reports and present findings to senior management. Stay updated on emerging IT risks, technologies, and regulatory changes. Provide guidance and training to junior audit staff on IT audit methodologies. Qualifications: Traditional accounting qualifications i.e. ACA/ACCA/CIMA or CISA, CISSP, or other relevant certification preferred. Minimum of 3 years of experience in IT auditing or a related field. Strong understanding of IT control frameworks Excellent analytical, problem-solving, and communication skills. Ability to work independently and as part of a team. Proficiency in audit software and Microsoft Office Suite. Operational Audit Experience: Proven experience in conducting operational audits to assess the efficiency and effectiveness of business processes. Technical Skills (some of these include): Operating Systems: Proficiency on Windows, Linux, and Unix environments. Database Management: Knowledge of SQL, Oracle, and other database management systems. Cybersecurity: Experience with vulnerability assessments, penetration testing, and incident response. IT Governance: Knowledge of ITIL, ISO 27001, and other IT governance frameworks. Software Development: Understanding of SDLC, DevOps practices, and application security. Data Analytics: Proficiency in data analytics tools and techniques to enhance audit processes. For example: Excel: Advanced skills in data manipulation, pivot tables, and data visualisation. SQL: Ability to query and analyse large datasets. Python/R: Experience with programming languages for data analysis and automation. Tableau/Power BI: Expertise in creating interactive dashboards and visualisations. ACL/Galvanize: Familiarity with audit-specific data analytics tools. What We Offer: Competitive salary and benefits package. Opportunities for professional growth and development. A collaborative and supportive work environment. Flexible work arrangements, including remote work options. What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now. If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. #
Oct 04, 2025
Full time
IT Specialist Internal Auditor needed to drive innovation - London-based - £70k+ Your new company This company is looking to transform their audit team by gaining an IT audit specialist to create robust IT systems to ensure compliance with industry standards. They are looking for a skilled IT Specialist Internal Auditor to join our team. This role is crucial in evaluating and improving our IT controls and ensuring the integrity of our information systems. Key Responsibilities: Conduct comprehensive IT audits, including planning, execution, and reporting. Assess the effectiveness of IT controls and identify areas for improvement. Evaluate IT systems and processes to ensure compliance with regulatory requirements and industry best practices. Utilise data analytics to streamline audit plans and enhance audit efficiency. Collaborate with IT and business teams to address audit findings and implement corrective actions. Prepare detailed audit reports and present findings to senior management. Stay updated on emerging IT risks, technologies, and regulatory changes. Provide guidance and training to junior audit staff on IT audit methodologies. Qualifications: Traditional accounting qualifications i.e. ACA/ACCA/CIMA or CISA, CISSP, or other relevant certification preferred. Minimum of 3 years of experience in IT auditing or a related field. Strong understanding of IT control frameworks Excellent analytical, problem-solving, and communication skills. Ability to work independently and as part of a team. Proficiency in audit software and Microsoft Office Suite. Operational Audit Experience: Proven experience in conducting operational audits to assess the efficiency and effectiveness of business processes. Technical Skills (some of these include): Operating Systems: Proficiency on Windows, Linux, and Unix environments. Database Management: Knowledge of SQL, Oracle, and other database management systems. Cybersecurity: Experience with vulnerability assessments, penetration testing, and incident response. IT Governance: Knowledge of ITIL, ISO 27001, and other IT governance frameworks. Software Development: Understanding of SDLC, DevOps practices, and application security. Data Analytics: Proficiency in data analytics tools and techniques to enhance audit processes. For example: Excel: Advanced skills in data manipulation, pivot tables, and data visualisation. SQL: Ability to query and analyse large datasets. Python/R: Experience with programming languages for data analysis and automation. Tableau/Power BI: Expertise in creating interactive dashboards and visualisations. ACL/Galvanize: Familiarity with audit-specific data analytics tools. What We Offer: Competitive salary and benefits package. Opportunities for professional growth and development. A collaborative and supportive work environment. Flexible work arrangements, including remote work options. What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now. If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career. #
BAE Systems
Principal Cyber Security Engineer
BAE Systems Ulverston, Cumbria
Job Title: Principal Cyber Security Engineer Location: Barrow-In-Furness - We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Negotiable, depending on experience What you'll be doing: Manage and deliver a Submarines Business Unit Product Security Assurance Audit schedule within the scope of EPAD Be able to plan and manage work concurrently across multiple security work programmes Be able to select appropriate Product Security Assurance techniques which are consistent and repeatable for use across a programme Represent the EPAD at Design Reviews and other various engagements, to ensure that Product Security is appropriately considered at each stage of the design lifecycle Be able to contribute and influence the development of Product Security strategies, policies, guidance, good practices and awareness Ensure that Product Security activities within a programme, a project, system or equipment, are delivered and managed using recognised techniques and in accordance with the Submarines Product Security Management System (PsecMS) Provide regular updates on assurance status/progress in accordance with programme/project specific reporting cycles Your skills and experiences: Essential: Degree (or equivalent experience) in a relevant STEM subject or Information Security related. Relevant Professional certification such as CISSP, CISM or CCP SIRA status (or able to achieve) Desirable: Experience in Cyber Security in relation to DEFCON 658, DEFSTAN 05-138, MOD Accreditation/Secure by Design ISO 27001 Lead Auditor or Implementer Benefits: As well as a competitive pension scheme, BAE Systems also offers employee share plans, an extensive range of flexible discounted health, wellbeing and lifestyle benefits, including a green car scheme, private health plans and shopping discounts - you may also be eligible for an annual incentive. The Engineering Product Assurance Department: The Product Security Assurance Principal Engineer will be a focal point for security and information risk matters within the Engineering Product Assurance Department (EPAD). They will have Governance, Risk and Compliance (GRC) subject matter expertise and will be responsible for development of the strategy within the scope of EPAD. The Principal Engineer will be able to apply their deep level of subject matter expertise and experience to ensure that submarine systems and products are delivered and can be managed and supported through-life. Why BAE Systems? This is a place where you'll be able to make a real difference. You'll be part of an inclusive culture that values diversity of thought, rewards integrity, and merit, and where you'll be empowered to fulfil your potential. We welcome people from all backgrounds and want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role, to allow for meaningful security vetting checks. Closing Date: 7 th October 2025 We reserve the right to close this vacancy early if we receive sufficient applications for the role. Therefore, if you are interested, please submit your application as early as possible.
Oct 04, 2025
Full time
Job Title: Principal Cyber Security Engineer Location: Barrow-In-Furness - We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Negotiable, depending on experience What you'll be doing: Manage and deliver a Submarines Business Unit Product Security Assurance Audit schedule within the scope of EPAD Be able to plan and manage work concurrently across multiple security work programmes Be able to select appropriate Product Security Assurance techniques which are consistent and repeatable for use across a programme Represent the EPAD at Design Reviews and other various engagements, to ensure that Product Security is appropriately considered at each stage of the design lifecycle Be able to contribute and influence the development of Product Security strategies, policies, guidance, good practices and awareness Ensure that Product Security activities within a programme, a project, system or equipment, are delivered and managed using recognised techniques and in accordance with the Submarines Product Security Management System (PsecMS) Provide regular updates on assurance status/progress in accordance with programme/project specific reporting cycles Your skills and experiences: Essential: Degree (or equivalent experience) in a relevant STEM subject or Information Security related. Relevant Professional certification such as CISSP, CISM or CCP SIRA status (or able to achieve) Desirable: Experience in Cyber Security in relation to DEFCON 658, DEFSTAN 05-138, MOD Accreditation/Secure by Design ISO 27001 Lead Auditor or Implementer Benefits: As well as a competitive pension scheme, BAE Systems also offers employee share plans, an extensive range of flexible discounted health, wellbeing and lifestyle benefits, including a green car scheme, private health plans and shopping discounts - you may also be eligible for an annual incentive. The Engineering Product Assurance Department: The Product Security Assurance Principal Engineer will be a focal point for security and information risk matters within the Engineering Product Assurance Department (EPAD). They will have Governance, Risk and Compliance (GRC) subject matter expertise and will be responsible for development of the strategy within the scope of EPAD. The Principal Engineer will be able to apply their deep level of subject matter expertise and experience to ensure that submarine systems and products are delivered and can be managed and supported through-life. Why BAE Systems? This is a place where you'll be able to make a real difference. You'll be part of an inclusive culture that values diversity of thought, rewards integrity, and merit, and where you'll be empowered to fulfil your potential. We welcome people from all backgrounds and want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role, to allow for meaningful security vetting checks. Closing Date: 7 th October 2025 We reserve the right to close this vacancy early if we receive sufficient applications for the role. Therefore, if you are interested, please submit your application as early as possible.
BAE Systems
Principal Cyber Security Engineer
BAE Systems Dalton-in-furness, Cumbria
Job Title: Principal Cyber Security Engineer Location: Barrow-In-Furness - We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Negotiable, depending on experience What you'll be doing: Manage and deliver a Submarines Business Unit Product Security Assurance Audit schedule within the scope of EPAD Be able to plan and manage work concurrently across multiple security work programmes Be able to select appropriate Product Security Assurance techniques which are consistent and repeatable for use across a programme Represent the EPAD at Design Reviews and other various engagements, to ensure that Product Security is appropriately considered at each stage of the design lifecycle Be able to contribute and influence the development of Product Security strategies, policies, guidance, good practices and awareness Ensure that Product Security activities within a programme, a project, system or equipment, are delivered and managed using recognised techniques and in accordance with the Submarines Product Security Management System (PsecMS) Provide regular updates on assurance status/progress in accordance with programme/project specific reporting cycles Your skills and experiences: Essential: Degree (or equivalent experience) in a relevant STEM subject or Information Security related. Relevant Professional certification such as CISSP, CISM or CCP SIRA status (or able to achieve) Desirable: Experience in Cyber Security in relation to DEFCON 658, DEFSTAN 05-138, MOD Accreditation/Secure by Design ISO 27001 Lead Auditor or Implementer Benefits: As well as a competitive pension scheme, BAE Systems also offers employee share plans, an extensive range of flexible discounted health, wellbeing and lifestyle benefits, including a green car scheme, private health plans and shopping discounts - you may also be eligible for an annual incentive. The Engineering Product Assurance Department: The Product Security Assurance Principal Engineer will be a focal point for security and information risk matters within the Engineering Product Assurance Department (EPAD). They will have Governance, Risk and Compliance (GRC) subject matter expertise and will be responsible for development of the strategy within the scope of EPAD. The Principal Engineer will be able to apply their deep level of subject matter expertise and experience to ensure that submarine systems and products are delivered and can be managed and supported through-life. Why BAE Systems? This is a place where you'll be able to make a real difference. You'll be part of an inclusive culture that values diversity of thought, rewards integrity, and merit, and where you'll be empowered to fulfil your potential. We welcome people from all backgrounds and want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role, to allow for meaningful security vetting checks. Closing Date: 7 th October 2025 We reserve the right to close this vacancy early if we receive sufficient applications for the role. Therefore, if you are interested, please submit your application as early as possible.
Oct 04, 2025
Full time
Job Title: Principal Cyber Security Engineer Location: Barrow-In-Furness - We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Negotiable, depending on experience What you'll be doing: Manage and deliver a Submarines Business Unit Product Security Assurance Audit schedule within the scope of EPAD Be able to plan and manage work concurrently across multiple security work programmes Be able to select appropriate Product Security Assurance techniques which are consistent and repeatable for use across a programme Represent the EPAD at Design Reviews and other various engagements, to ensure that Product Security is appropriately considered at each stage of the design lifecycle Be able to contribute and influence the development of Product Security strategies, policies, guidance, good practices and awareness Ensure that Product Security activities within a programme, a project, system or equipment, are delivered and managed using recognised techniques and in accordance with the Submarines Product Security Management System (PsecMS) Provide regular updates on assurance status/progress in accordance with programme/project specific reporting cycles Your skills and experiences: Essential: Degree (or equivalent experience) in a relevant STEM subject or Information Security related. Relevant Professional certification such as CISSP, CISM or CCP SIRA status (or able to achieve) Desirable: Experience in Cyber Security in relation to DEFCON 658, DEFSTAN 05-138, MOD Accreditation/Secure by Design ISO 27001 Lead Auditor or Implementer Benefits: As well as a competitive pension scheme, BAE Systems also offers employee share plans, an extensive range of flexible discounted health, wellbeing and lifestyle benefits, including a green car scheme, private health plans and shopping discounts - you may also be eligible for an annual incentive. The Engineering Product Assurance Department: The Product Security Assurance Principal Engineer will be a focal point for security and information risk matters within the Engineering Product Assurance Department (EPAD). They will have Governance, Risk and Compliance (GRC) subject matter expertise and will be responsible for development of the strategy within the scope of EPAD. The Principal Engineer will be able to apply their deep level of subject matter expertise and experience to ensure that submarine systems and products are delivered and can be managed and supported through-life. Why BAE Systems? This is a place where you'll be able to make a real difference. You'll be part of an inclusive culture that values diversity of thought, rewards integrity, and merit, and where you'll be empowered to fulfil your potential. We welcome people from all backgrounds and want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role, to allow for meaningful security vetting checks. Closing Date: 7 th October 2025 We reserve the right to close this vacancy early if we receive sufficient applications for the role. Therefore, if you are interested, please submit your application as early as possible.
BAE Systems
Principal Cyber Security Engineer
BAE Systems Barrow-in-furness, Cumbria
Job Title: Principal Cyber Security Engineer Location: Barrow-In-Furness - We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Negotiable, depending on experience What you'll be doing: Manage and deliver a Submarines Business Unit Product Security Assurance Audit schedule within the scope of EPAD Be able to plan and manage work concurrently across multiple security work programmes Be able to select appropriate Product Security Assurance techniques which are consistent and repeatable for use across a programme Represent the EPAD at Design Reviews and other various engagements, to ensure that Product Security is appropriately considered at each stage of the design lifecycle Be able to contribute and influence the development of Product Security strategies, policies, guidance, good practices and awareness Ensure that Product Security activities within a programme, a project, system or equipment, are delivered and managed using recognised techniques and in accordance with the Submarines Product Security Management System (PsecMS) Provide regular updates on assurance status/progress in accordance with programme/project specific reporting cycles Your skills and experiences: Essential: Degree (or equivalent experience) in a relevant STEM subject or Information Security related. Relevant Professional certification such as CISSP, CISM or CCP SIRA status (or able to achieve) Desirable: Experience in Cyber Security in relation to DEFCON 658, DEFSTAN 05-138, MOD Accreditation/Secure by Design ISO 27001 Lead Auditor or Implementer Benefits: As well as a competitive pension scheme, BAE Systems also offers employee share plans, an extensive range of flexible discounted health, wellbeing and lifestyle benefits, including a green car scheme, private health plans and shopping discounts - you may also be eligible for an annual incentive. The Engineering Product Assurance Department: The Product Security Assurance Principal Engineer will be a focal point for security and information risk matters within the Engineering Product Assurance Department (EPAD). They will have Governance, Risk and Compliance (GRC) subject matter expertise and will be responsible for development of the strategy within the scope of EPAD. The Principal Engineer will be able to apply their deep level of subject matter expertise and experience to ensure that submarine systems and products are delivered and can be managed and supported through-life. Why BAE Systems? This is a place where you'll be able to make a real difference. You'll be part of an inclusive culture that values diversity of thought, rewards integrity, and merit, and where you'll be empowered to fulfil your potential. We welcome people from all backgrounds and want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role, to allow for meaningful security vetting checks. Closing Date: 7 th October 2025 We reserve the right to close this vacancy early if we receive sufficient applications for the role. Therefore, if you are interested, please submit your application as early as possible.
Oct 04, 2025
Full time
Job Title: Principal Cyber Security Engineer Location: Barrow-In-Furness - We offer a range of hybrid and flexible working arrangements - please speak to your recruiter about the options for this particular role. Salary: Negotiable, depending on experience What you'll be doing: Manage and deliver a Submarines Business Unit Product Security Assurance Audit schedule within the scope of EPAD Be able to plan and manage work concurrently across multiple security work programmes Be able to select appropriate Product Security Assurance techniques which are consistent and repeatable for use across a programme Represent the EPAD at Design Reviews and other various engagements, to ensure that Product Security is appropriately considered at each stage of the design lifecycle Be able to contribute and influence the development of Product Security strategies, policies, guidance, good practices and awareness Ensure that Product Security activities within a programme, a project, system or equipment, are delivered and managed using recognised techniques and in accordance with the Submarines Product Security Management System (PsecMS) Provide regular updates on assurance status/progress in accordance with programme/project specific reporting cycles Your skills and experiences: Essential: Degree (or equivalent experience) in a relevant STEM subject or Information Security related. Relevant Professional certification such as CISSP, CISM or CCP SIRA status (or able to achieve) Desirable: Experience in Cyber Security in relation to DEFCON 658, DEFSTAN 05-138, MOD Accreditation/Secure by Design ISO 27001 Lead Auditor or Implementer Benefits: As well as a competitive pension scheme, BAE Systems also offers employee share plans, an extensive range of flexible discounted health, wellbeing and lifestyle benefits, including a green car scheme, private health plans and shopping discounts - you may also be eligible for an annual incentive. The Engineering Product Assurance Department: The Product Security Assurance Principal Engineer will be a focal point for security and information risk matters within the Engineering Product Assurance Department (EPAD). They will have Governance, Risk and Compliance (GRC) subject matter expertise and will be responsible for development of the strategy within the scope of EPAD. The Principal Engineer will be able to apply their deep level of subject matter expertise and experience to ensure that submarine systems and products are delivered and can be managed and supported through-life. Why BAE Systems? This is a place where you'll be able to make a real difference. You'll be part of an inclusive culture that values diversity of thought, rewards integrity, and merit, and where you'll be empowered to fulfil your potential. We welcome people from all backgrounds and want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments. Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions mean that factors such as your nationality, any nationalities you may have previously held, and your place of birth can restrict the roles you are eligible to perform within the organisation. All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years of continuous residency in the UK depending on the vetting level required for the role, to allow for meaningful security vetting checks. Closing Date: 7 th October 2025 We reserve the right to close this vacancy early if we receive sufficient applications for the role. Therefore, if you are interested, please submit your application as early as possible.

Modal Window

  • Blog
  • Contact
  • About Us
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • Facebook
  • Twitter
  • Instagram
  • Pinterest
  • Youtube
Parent and Partner sites: IT Job Board | Search Jobs Near Me | RightTalent.co.uk | Quantity Surveyor jobs | Building Surveyor jobs | Construction Recruitment | Talent Recruiter | London Jobs | Property jobs
© 2008-2026 Jobs Hiring Near Me