We are seeking an experienced Technology and Cyber Employee Platforms Risk Executive Director to lead the development and... Read more
We are seeking an experienced Technology and Cyber Employee Platforms Risk Executive Director to lead the development and execution of risk management strategies across technology, cybersecurity, and employee-facing platforms. This senior role will provide independent challenge and expert guidance to technology and business leaders, ensuring that risks are identified, assessed, managed, and reported in line with regulatory expectations and organisational risk appetite. The successful candidate will operate across a complex, highly regulated environment and influence decisions at executive and board level.
Key responsibilities include setting the strategic direction for technology and cyber risk oversight; maintaining effective risk and control frameworks; reviewing risk assessments, control designs, and remediation plans; and monitoring emerging threats, vulnerabilities, resilience concerns, and third-party exposures. You will oversee risk reporting, ensure material issues are escalated appropriately, and provide clear analysis and recommendations to senior governance forums. The role will also support audits, regulatory reviews, incident investigations, control testing, and transformational programmes involving employee platforms, identity and access management, cloud services, data protection, and operational resilience. Success will require close collaboration with technology, cybersecurity, compliance, legal, internal audit, and business stakeholders.
Applicants should bring significant experience in technology risk, cyber risk, operational risk, internal controls, or a related discipline, ideally gained within a large, complex, or regulated organisation. A strong understanding of cybersecurity principles, technology architecture, risk governance, control frameworks, and relevant regulatory requirements is essential. You will be an influential communicator with the confidence to challenge constructively, simplify complex issues, and engage effectively with executive audiences. Strong analytical, decision-making, stakeholder management, and written communication skills are required, together with a proven ability to lead through ambiguity and deliver practical, sustainable outcomes. Professional qualifications in risk, technology, cybersecurity, audit, or information security would be advantageous.
Read lessBournemouth, England, United KingdomPermanent
We are seeking a Cyber Risk Analyst to support the identification, assessment and management of information security and... Read more
We are seeking a Cyber Risk Analyst to support the identification, assessment and management of information security and technology risks across the organisation. The successful candidate will help strengthen the cyber risk framework, improve visibility of the threat landscape and provide clear, practical advice to stakeholders. This role will work closely with technology, security, compliance, audit and business teams to ensure that cyber risks are understood, appropriately prioritised and managed in line with internal policies and regulatory expectations.
Key responsibilities will include maintaining risk registers, conducting cyber and information security risk assessments, reviewing control effectiveness and supporting the remediation of identified weaknesses. You will monitor emerging threats, vulnerabilities and changes in the regulatory environment, assessing their potential impact on business operations. The role will also contribute to risk reporting, management information and governance forums, translating technical findings into concise updates for senior audiences. Additional duties may include supporting third-party and supplier risk assessments, assisting with control testing, tracking remediation actions and contributing to incident reviews, resilience assessments and assurance activities.
Applicants should have experience in cyber security, technology risk, information security, internal controls, audit or a related discipline. A sound understanding of risk management principles, security frameworks and common control standards is required, along with the ability to analyse complex information and identify practical improvements. Familiarity with frameworks such as ISO 27001, NIST Cybersecurity Framework, COBIT or CIS Controls would be advantageous. Relevant professional qualifications or certifications, such as CISA, CRISC, CISSP, CISM or equivalent experience, are desirable. Strong written and verbal communication skills are essential, as is the confidence to engage with both technical and non-technical stakeholders. You will be organised, analytical and detail-oriented, with the ability to manage competing priorities, challenge constructively and work collaboratively in a changing environment.
Read lessStirling, Scotland, United KingdomPermanent
We are seeking a Cyber Risk Analyst to support the identification, assessment, and management of information and cyber... Read more
We are seeking a Cyber Risk Analyst to support the identification, assessment, and management of information and cyber security risks across the organisation. In this role, you will work with technology, security, compliance, and business teams to maintain a clear view of the cyber risk landscape and help ensure that appropriate controls are designed, implemented, and monitored. You will contribute to risk assessments for systems, applications, suppliers, projects, and business processes, providing practical recommendations that support informed decision-making.
Your responsibilities will include maintaining risk registers, reviewing control effectiveness, tracking remediation activities, and preparing clear reports for risk and governance forums. You will support the development and monitoring of key risk indicators, assist with security assurance and audit activities, and help assess the impact of emerging threats, vulnerabilities, and regulatory requirements. You will also contribute to third-party risk reviews, policy and standards updates, incident lessons learned, and continuous improvement of cyber risk management processes. The role requires you to communicate complex technical and risk issues clearly to both technical and non-technical stakeholders.
Applicants should have experience in cyber security, technology risk, information security, audit, compliance, or a related discipline, together with a sound understanding of risk management principles and security frameworks such as ISO 27001, NIST, or CIS Controls. Familiarity with governance, risk, and compliance tools, vulnerability management, cloud environments, data protection, and supplier assurance would be advantageous. Strong analytical, writing, organisational, and stakeholder-management skills are essential, along with the ability to challenge constructively and prioritise competing demands. Relevant professional qualifications, such as CRISC, CISA, CISSP, or equivalent experience, are desirable. You will be expected to demonstrate integrity, attention to detail, curiosity, and a proactive approach to identifying and reducing cyber risk.
Read lessEdinburgh, Scotland, United KingdomPermanent
We are seeking a Cyber Risk Analyst to support the identification, assessment and management of information security and... Read more
We are seeking a Cyber Risk Analyst to support the identification, assessment and management of information security and technology risks across the organisation. In this role, you will work with stakeholders across technology, operations, compliance and internal audit to assess cyber risks, maintain accurate risk records and promote effective risk management practices. You will help ensure that security risks are understood, prioritised and addressed in line with business objectives, regulatory expectations and established policies.
Your responsibilities will include conducting cyber and technology risk assessments; reviewing control effectiveness; identifying gaps and recommending practical remediation actions; maintaining risk registers, issues logs and supporting documentation; and preparing clear reports for management and relevant governance forums. You will contribute to third-party and supplier risk assessments, support security reviews for projects and changes, monitor remediation progress and assist with the development of risk metrics and dashboards. You may also support incident and control reviews, policy updates, audit activity and the ongoing improvement of risk management frameworks, procedures and reporting.
The successful candidate will have experience in cyber security, information technology risk, technology controls, compliance or a related discipline, together with a sound understanding of common security principles, risk assessment methodologies and control frameworks. Familiarity with standards such as ISO 27001, NIST, COBIT or similar frameworks is desirable. You should be analytical, well organised and comfortable interpreting technical information for both technical and non-technical audiences. Strong written and verbal communication skills, sound judgement and the ability to manage competing priorities are essential. Relevant professional qualifications in information security, risk management or audit are advantageous. This role offers the opportunity to influence security outcomes, build relationships across the business and contribute to a mature, risk-aware culture.
Read lessEdinburgh, Scotland, United KingdomPermanent
We are seeking a Principal Cyber Security Risk Manager to lead the development and delivery of a mature,... Read more
We are seeking a Principal Cyber Security Risk Manager to lead the development and delivery of a mature, enterprise-wide cyber security risk management framework. In this senior role, you will provide authoritative advice on cyber risk, resilience and control effectiveness, helping business and technology leaders make informed decisions in a complex and evolving threat landscape. You will work across multiple functions to ensure that security risks are identified, assessed, recorded and managed in line with agreed risk appetite and regulatory expectations.
Your responsibilities will include defining risk management methodologies, standards and reporting practices; overseeing risk assessments for strategic initiatives, systems, suppliers and major change programmes; and challenging control owners to develop effective remediation plans. You will maintain clear oversight of cyber risk exposure, emerging threats, vulnerabilities and control gaps, providing concise reports and insights to senior governance forums. You will also support the development of key risk indicators, risk acceptance processes, scenario analysis and assurance activities, while contributing to incident, crisis and operational resilience planning where appropriate.
You will bring significant experience in cyber security, technology risk, information security or a closely related discipline, with a proven record of operating at a strategic or principal level. Strong knowledge of recognised security and risk frameworks, control principles, regulatory requirements and third-party risk management is essential. You should be confident interpreting complex technical issues and translating them into clear business impacts and practical recommendations for senior stakeholders. Excellent communication, influencing and relationship-building skills are required, alongside the ability to work independently, manage competing priorities and provide constructive challenge. Professional certifications in cyber security, audit, risk or governance would be advantageous.
Read lessLeeds, England, United KingdomPermanent
We are seeking a Cyber Risk Analyst to support the identification, assessment, and management of information and cyber... Read more
We are seeking a Cyber Risk Analyst to support the identification, assessment, and management of information and cyber security risks across the organisation. In this role, you will work with technology, business, and security stakeholders to evaluate risks, recommend appropriate controls, and help strengthen the overall cyber risk management framework. You will contribute to risk assessments for systems, applications, suppliers, projects, and business processes, ensuring that security considerations are embedded throughout the organisation.
Key responsibilities will include maintaining cyber risk registers, analysing threats and vulnerabilities, reviewing control effectiveness, and tracking remediation activities through to completion. You will support the development of risk reports, dashboards, and management information, highlighting key trends, emerging risks, and areas requiring attention. The role will also involve assisting with security assessments, policy and control reviews, audit activities, exception management, and the monitoring of compliance with relevant regulatory, contractual, and industry requirements. You will help promote consistent risk practices by providing guidance to stakeholders and contributing to awareness and continuous improvement initiatives.
The successful candidate will have experience in cyber security, information security, technology risk, IT audit, or a related discipline, together with a sound understanding of risk management principles and security controls. You should be comfortable interpreting technical information, assessing business impact, and communicating findings clearly to both technical and non-technical audiences. Strong analytical, organisational, and stakeholder management skills are essential, as is the ability to manage competing priorities and work collaboratively. Familiarity with recognised security and risk frameworks, such as ISO 27001, NIST, CIS Controls, or similar, would be advantageous. Relevant certifications in cyber security, audit, risk, or information security are desirable but not essential.
Read lessStirling, Scotland, United KingdomPermanent
We are seeking an experienced Principal Cyber Security Risk Manager to lead the development and continual improvement of... Read more
We are seeking an experienced Principal Cyber Security Risk Manager to lead the development and continual improvement of cyber security risk management across a complex organisation. In this senior role, you will provide expert advice to executives, technology leaders and business stakeholders, helping them understand cyber threats, make informed risk-based decisions and strengthen the organisation’s overall security posture. You will operate as a trusted authority on cyber risk, influencing strategy, governance and investment priorities across a broad range of services, systems and transformation programmes.
Your responsibilities will include establishing and maintaining cyber security risk frameworks, policies, standards and assessment methodologies. You will oversee the identification, analysis, treatment and reporting of information and cyber security risks, ensuring that key risks are clearly documented, appropriately owned and actively managed. You will lead complex risk assessments, review security controls and provide challenge and assurance across projects, suppliers, cloud services and operational environments. The role will also involve maintaining risk reporting for senior governance forums, monitoring risk appetite and tolerance, tracking remediation activity, and escalating significant or emerging concerns when required. You will contribute to incident preparedness, threat-informed decision-making, regulatory compliance and the continuous improvement of security governance.
To succeed, you will bring substantial experience in cyber security risk, governance, assurance or a closely related discipline, together with a strong understanding of security principles, control frameworks and risk management practices. Experience with recognised standards such as ISO 27001, NIST or CIS is desirable, as is knowledge of cloud security, third-party risk and modern technology environments. You will be an excellent communicator, able to translate complex technical issues into clear business impacts and practical recommendations. Strong influencing, stakeholder management, analytical and decision-making skills are essential, along with the credibility to challenge constructively at senior levels. Relevant professional qualifications in information security, risk management or audit are advantageous.
Read lessBirmingham, England, United KingdomPermanent
We are seeking an experienced technology, cyber and resilience risk leader to provide strategic oversight across a complex... Read more
We are seeking an experienced technology, cyber and resilience risk leader to provide strategic oversight across a complex and evolving risk landscape. In this senior role, you will help strengthen the organisation’s ability to identify, assess and manage risks relating to technology services, information security, cyber threats, operational resilience, third-party providers and business continuity. You will act as a trusted adviser to senior stakeholders, challenging risk decisions constructively and promoting a strong culture of accountability and continuous improvement.
Your responsibilities will include developing and maintaining effective risk frameworks, policies, standards and appetites across technology and cyber risk. You will oversee risk identification and assessment, control testing, issue remediation, risk acceptance and management reporting, ensuring that material exposures are clearly understood and escalated where appropriate. You will provide insight on emerging threats, regulatory expectations and technology developments, and support the delivery of resilience strategies, scenario testing, crisis preparedness and recovery planning. The role will also involve engaging with internal audit, regulators, assurance teams and third-party risk specialists, as well as contributing to governance forums and executive reporting.
You will bring significant experience in technology risk, cyber risk, operational resilience, information security or a closely related discipline, gained within a complex or highly regulated environment. Strong knowledge of recognised risk, security, continuity and resilience frameworks is expected, together with the ability to translate technical issues into clear business and executive-level advice. You should be confident influencing senior stakeholders, challenging decisions, managing competing priorities and leading through change. Relevant professional qualifications in technology, cyber security, risk management, audit or business continuity would be advantageous. The successful candidate will be analytical, pragmatic and collaborative, with excellent communication skills and a clear commitment to sound governance, proportionate risk management and continual improvement.
Read lessLondon, England, United KingdomPermanent
We are seeking a Vulnerability Management Lead to develop and oversee a proactive, risk-based vulnerability management programme across... Read more
We are seeking a Vulnerability Management Lead to develop and oversee a proactive, risk-based vulnerability management programme across a complex technology estate. You will provide strategic direction while remaining engaged with the operational detail required to identify, assess, prioritise and remediate vulnerabilities across infrastructure, applications, cloud services, endpoints and third-party environments. Working closely with security, technology, engineering and business stakeholders, you will help reduce exposure to cyber threats and strengthen the organisation’s overall security posture.
Key responsibilities will include defining vulnerability management standards, processes and performance measures; managing vulnerability scanning, assessment and validation activities; and ensuring findings are accurately risk-rated, assigned and tracked through to remediation. You will establish appropriate remediation timeframes, challenge exceptions and overdue actions, and produce clear reporting for technical teams and senior leadership. The role will also involve improving tooling and automation, coordinating penetration testing and exposure assessments, supporting incident response where vulnerabilities are actively exploited, and contributing to security architecture, risk assessments and audit activity. You will lead a team or virtual community of specialists, promote consistent ways of working and help embed secure-by-design principles across delivery and operational teams.
The successful candidate will have substantial experience in vulnerability management, cyber security or a closely related discipline, with a strong understanding of vulnerability assessment methodologies, CVSS, threat intelligence and remediation practices. Experience working with enterprise vulnerability management platforms, cloud environments, application security tools and security information sources is highly desirable. You will be comfortable interpreting technical findings, translating risk for non-technical audiences and influencing stakeholders at all levels. Strong leadership, communication, organisation and problem-solving skills are essential, along with the ability to manage competing priorities in a fast-moving environment. Relevant professional certifications or equivalent practical experience will be welcomed.
Read lessCorby, England, United KingdomPermanent
We are seeking a Business Information Risk Analyst to support the identification, assessment and management of information and... Read more
We are seeking a Business Information Risk Analyst to support the identification, assessment and management of information and technology risks across a complex business environment. In this role, you will work with stakeholders across business operations, technology, security, compliance and audit to help ensure that information assets are protected and that risk is managed within agreed appetite and regulatory expectations. You will contribute to a proactive risk culture by providing clear, practical advice and promoting consistent risk management practices.
Key responsibilities will include maintaining risk and control registers, supporting risk assessments, reviewing business processes and identifying potential vulnerabilities, control weaknesses and emerging threats. You will assist with the development and monitoring of risk treatment plans, track remediation activity and prepare clear reports for management and governance forums. The role will also involve supporting information security reviews, third-party and supplier assessments, policy and control updates, audit activity, incident analysis and the production of management information. You will be expected to challenge assumptions constructively, escalate significant issues appropriately and help embed effective controls across projects, systems and operational processes.
The successful candidate will have experience in information risk, technology risk, cybersecurity, information governance, internal controls or a related discipline. You should have a good understanding of risk assessment methodologies, control frameworks, data protection principles and common information security threats. Experience with frameworks such as ISO 27001, NIST, COBIT or similar would be advantageous, as would relevant professional qualifications. Strong analytical, organisational and communication skills are essential, together with the ability to interpret complex information and present it clearly to both technical and non-technical audiences. You will be collaborative, detail-oriented and comfortable managing multiple priorities while working independently. A practical, commercially aware approach and a commitment to continuous improvement will be highly valued.
Read lessLondon, England, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria