UK leading food distributor within the catering industry are seeking an experienced IT Compliance & Audit Manager to support and drive the compliance and risk standards throughout the business. Working closely with the leadership team while reporting direct to the Vice President of IT, you will lead the implementation of policies and security controls ensuring all are maintained. Proactively plan and deliver on business-critical compliance and IT Audits. The right candidate will have in-depth experience managing PCI DSS, Risk management and IT Audit while implementing cyber governance. The Role: Lead and maintain PCI DSS compliances and standard practices Manage and maintain IT risk register and IT contracts Work closely with both IT SecOps teams and senior IT management to develop and ensure all information system security for all business-critical systems are secure Lead Quarterly It Audits Oversee functional testing of cyber security controls The Requirements: Proven experience with PCI DSS and Cyber Essentials Plus Come from an IT security compliance background or similar Ability to communicate with all levels of stakeholders and IT technical teams Strong knowledge Microsoft Azure Cloud Security PCI ISA Qualification desirable Confidence to plan and implement new procedures while managing operational duties Full UK right to work required; no sponsorship options available The Overview: Up to £75,000 depending on experience Fulltime permanent position Hybrid role, 3 days in office Bath area, parking available
Jun 03, 2023
Full time
UK leading food distributor within the catering industry are seeking an experienced IT Compliance & Audit Manager to support and drive the compliance and risk standards throughout the business. Working closely with the leadership team while reporting direct to the Vice President of IT, you will lead the implementation of policies and security controls ensuring all are maintained. Proactively plan and deliver on business-critical compliance and IT Audits. The right candidate will have in-depth experience managing PCI DSS, Risk management and IT Audit while implementing cyber governance. The Role: Lead and maintain PCI DSS compliances and standard practices Manage and maintain IT risk register and IT contracts Work closely with both IT SecOps teams and senior IT management to develop and ensure all information system security for all business-critical systems are secure Lead Quarterly It Audits Oversee functional testing of cyber security controls The Requirements: Proven experience with PCI DSS and Cyber Essentials Plus Come from an IT security compliance background or similar Ability to communicate with all levels of stakeholders and IT technical teams Strong knowledge Microsoft Azure Cloud Security PCI ISA Qualification desirable Confidence to plan and implement new procedures while managing operational duties Full UK right to work required; no sponsorship options available The Overview: Up to £75,000 depending on experience Fulltime permanent position Hybrid role, 3 days in office Bath area, parking available
UK leading food distributor within the catering industry are seeking an experienced IT Compliance & Audit Manager to support and drive the compliance and risk standards throughout the business. Working closely with the leadership team while reporting direct to the Vice President of IT, you will lead the implementation of policies and security controls ensuring all are maintained. Proactively plan and deliver on business-critical compliance and IT Audits. The right candidate will have in-depth experience managing PCI DSS, Risk management and IT Audit while implementing cyber governance. The Role: Lead and maintain PCI DSS compliances and standard practices Manage and maintain IT risk register and IT contracts Work closely with both IT SecOps teams and senior IT management to develop and ensure all information system security for all business-critical systems are secure Lead Quarterly It Audits Oversee functional testing of cyber security controls The Requirements: Proven experience with PCI DSS and Cyber Essentials Plus Come from an IT security compliance background or similar Ability to communicate with all levels of stakeholders and IT technical teams Strong knowledge Microsoft Azure Cloud Security PCI ISA Qualification desirable Confidence to plan and implement new procedures while managing operational duties Full UK right to work required; no sponsorship options available The Overview: Up to £75,000 depending on experience Fulltime permanent position Hybrid role, 3 days in office Bath area, parking available
Jun 03, 2023
Full time
UK leading food distributor within the catering industry are seeking an experienced IT Compliance & Audit Manager to support and drive the compliance and risk standards throughout the business. Working closely with the leadership team while reporting direct to the Vice President of IT, you will lead the implementation of policies and security controls ensuring all are maintained. Proactively plan and deliver on business-critical compliance and IT Audits. The right candidate will have in-depth experience managing PCI DSS, Risk management and IT Audit while implementing cyber governance. The Role: Lead and maintain PCI DSS compliances and standard practices Manage and maintain IT risk register and IT contracts Work closely with both IT SecOps teams and senior IT management to develop and ensure all information system security for all business-critical systems are secure Lead Quarterly It Audits Oversee functional testing of cyber security controls The Requirements: Proven experience with PCI DSS and Cyber Essentials Plus Come from an IT security compliance background or similar Ability to communicate with all levels of stakeholders and IT technical teams Strong knowledge Microsoft Azure Cloud Security PCI ISA Qualification desirable Confidence to plan and implement new procedures while managing operational duties Full UK right to work required; no sponsorship options available The Overview: Up to £75,000 depending on experience Fulltime permanent position Hybrid role, 3 days in office Bath area, parking available
IT Security Operations Manager London/Hybrid Circa £100k + bonus + benefits IT Security Operations Manager is sought by highly prestigious International London Market Insurer. You will operate business as usual technical security controls, and support security services. You will also play an important role in supporting the Head of Infrastructure & Operations and the Chief Information Security Officer and will help to implement the security strategy, and actively participate in the Security Community. They have a clear Cyber Security strategy which focusses on increased use of automation, Real Time reporting, integrated tools, and above all, making security a priority for their entire organisation. Key Responsibilities Perform access provisioning and access review activities (including privileged access) for systems and applications. Segregate critical assets and networks from untrusted networks. Manage, optimise and/or implement operational network, end-point, cloud configuration, and collaboration security controls/technologies. Maintain an ongoing schedule of patch deployment based on vulnerability identification and associated prioritisation. Provide support and maintenance for security monitoring tools and solutions. Adopt best practice network standards and participate in reviews of network architectural designs, with a focus on embedding security by design. Test and maintain network infrastructure including software and End User hardware devices. Drive security testing to identify vulnerabilities, measuring effectiveness of systems and network configurations against known vulnerabilities. Conduct oversight of vulnerability remediation and assurance of supplier vulnerability management. Determine and document rules for patch management. Oversee AD User Account (De-)Provisioning Ensure the execution of IT disaster recovery and continuity of operations and participate in testing of IT disaster recovery plans, as required Key Requirements Significant experience in a security operations role with knowledge of security controls Deep knowledge of potential IT security vulnerabilities kept up-to-date through knowledge of the internal and external landscape. Strong knowledge of patch management techniques. Broad infrastructure knowledge including systems, storage, cloud and virtualisation. Industry knowledge of the technology landscape that drives best practice security frameworks. Deep practical knowledge of the people, process and technology components of Information Security Robust understanding of how different cyber risks can materialise across the layers of defence. Knowledge of good security practice, including ISO 27000 series. Knowledge of financial services and governance processes. Awareness of information security governance and compliance Extensive experience in running a complex schedule of patch deployment according to a prioritised set of vulnerabilities. Experience working with industry popular network, intrusion prevention systems (IPS), intrusion detection systems (IDS) and Firewall devices. Experience in effectively communicating security topics at a senior level in a large organisation. Experience in a regulated business environment, ideally gained in the Financial Services industry. Experience in building and managing an IT Security team Proven ability to perform access provisioning and access review activities (including privileged access) for systems and applications. Ability to manage a complex schedule of patch deployment according to a prioritised set of vulnerabilities. Ability to establish and maintain reference model artefacts for security controls and technologies. Ability to produce detailed design documents and diagrams for security controls and technologies. For a full consultation on this role please send your CV to Arc IT Recruitment.
Jun 02, 2023
Full time
IT Security Operations Manager London/Hybrid Circa £100k + bonus + benefits IT Security Operations Manager is sought by highly prestigious International London Market Insurer. You will operate business as usual technical security controls, and support security services. You will also play an important role in supporting the Head of Infrastructure & Operations and the Chief Information Security Officer and will help to implement the security strategy, and actively participate in the Security Community. They have a clear Cyber Security strategy which focusses on increased use of automation, Real Time reporting, integrated tools, and above all, making security a priority for their entire organisation. Key Responsibilities Perform access provisioning and access review activities (including privileged access) for systems and applications. Segregate critical assets and networks from untrusted networks. Manage, optimise and/or implement operational network, end-point, cloud configuration, and collaboration security controls/technologies. Maintain an ongoing schedule of patch deployment based on vulnerability identification and associated prioritisation. Provide support and maintenance for security monitoring tools and solutions. Adopt best practice network standards and participate in reviews of network architectural designs, with a focus on embedding security by design. Test and maintain network infrastructure including software and End User hardware devices. Drive security testing to identify vulnerabilities, measuring effectiveness of systems and network configurations against known vulnerabilities. Conduct oversight of vulnerability remediation and assurance of supplier vulnerability management. Determine and document rules for patch management. Oversee AD User Account (De-)Provisioning Ensure the execution of IT disaster recovery and continuity of operations and participate in testing of IT disaster recovery plans, as required Key Requirements Significant experience in a security operations role with knowledge of security controls Deep knowledge of potential IT security vulnerabilities kept up-to-date through knowledge of the internal and external landscape. Strong knowledge of patch management techniques. Broad infrastructure knowledge including systems, storage, cloud and virtualisation. Industry knowledge of the technology landscape that drives best practice security frameworks. Deep practical knowledge of the people, process and technology components of Information Security Robust understanding of how different cyber risks can materialise across the layers of defence. Knowledge of good security practice, including ISO 27000 series. Knowledge of financial services and governance processes. Awareness of information security governance and compliance Extensive experience in running a complex schedule of patch deployment according to a prioritised set of vulnerabilities. Experience working with industry popular network, intrusion prevention systems (IPS), intrusion detection systems (IDS) and Firewall devices. Experience in effectively communicating security topics at a senior level in a large organisation. Experience in a regulated business environment, ideally gained in the Financial Services industry. Experience in building and managing an IT Security team Proven ability to perform access provisioning and access review activities (including privileged access) for systems and applications. Ability to manage a complex schedule of patch deployment according to a prioritised set of vulnerabilities. Ability to establish and maintain reference model artefacts for security controls and technologies. Ability to produce detailed design documents and diagrams for security controls and technologies. For a full consultation on this role please send your CV to Arc IT Recruitment.
Cyber Security Analyst Organisation: NHS Trust (West Midlands) Type: Permanent Salary: £29,827.35 - £36,310.05 per annum No Positions: 03 Hybrid: 1 day per month in the office Job Summary With primary responsibility for ensuring the security, validity and provision of our systems and services, the post holder, through monitoring, evaluation and in collaboration with Senior Cyber Security Analyst, will lead on IT Security activities within the Trust. You The post holder will assist and support the Cyber Security team in ensuring that the Trusts IT network, computer systems and services remain secure, resilient and robust. The post holder will be responsible for ensuring that cyber security is aligned with business security and information governance. Ensuring that cyber security is effectively managed in all service and IT service management activities. Undertake IT security investigations and computer forensic work across the Trust. The post holder is responsible for: Resolving and delivering cyber security incidents, problems, and service requests, working with other members of the cyber security team Deploying, maintaining, monitoring, and troubleshooting systems (operating or applications) and hardware in use by the trust Ensuring IT infrastructure that is deployed meets current cyber security standards, as defined by Trust policy Ensuring the ongoing management, maintenance and use of cyber security Standard operating Procedures (SOPs) Key Responsibilities 1. Resolve incidents and complete service requests relating to all aspects of cyber security in accordance with defined processes and service level agreements (SLAs) and key performance indicators (KPIs). 2. Monitor changes in cyber security threats and appropriately respond to changes in threat profile. 3. Monitor cyber security services, systems and related infrastructure for signs of compromise. 4. Ensure that IT assets and resources are protected from malicious software (ie malware) and other emerging threats 5. Identify and address any potential and actual vulnerabilities in applications, infrastructure, services, software and systems 6. To work with various stakeholders including external partners, to build, maintain and promote effective working relationships. 7. Provide specialist advice and guidance across network, security, server, and desktop infrastructures. 8. Provide technical guidance and support to Trust employees on the use and interpretation of the information security management system policies and standards applicable to the use of IT. 9. Provide technical guidance and support to Trust employees on a range of cyber security issues, including computer viruses, spam e-mail, malware and hoaxes. Contribute to cyber security support functions such as creating and defining cyber security processes on a wide and varied range of tasks. 10. Assist with investigations into potential and reported misuse of the Trust IT facilities. Provide advice and updates to managers and human resource teams, ensuring that the correct investigation procedures are adhered to and that all documentation is recorded completely and accurately. 11. Perform technical cyber security risk assessments on user requests for access to systems, use of new software or hardware facilities. 12. Provide regular management information on cyber security matters, eg on the e-mail and Internet monitoring systems and identify the need for any new controls based on this Information. 13. Prepare reports based on cyber security incident statistics and organisational compliance with cyber security targets. 14. Assist in the coordination and management of cyber incident response activities 15. Support the cyber security team in the provision of service delivery, ensuring the team shares knowledge and works flexibly. Key Skills Expert Cyber security skills ie malware analysis, risk analysis, intrusion detection, reverse engineering, data analytics Excellent interpersonal skills, demonstrated by communicating with colleagues, Partners and non-technical professionals on a daily basis Able to work individually without direct supervision, and work in an agile environment Key Experience Experience of providing good advice and support to a range of customers/users. Experience of working in a confidential environment and in a customer-focused ICT organisation. Experience of delivering excellent service to a wide range of stakeholders Evidence of delivering ICT solutions to a diverse workforce. Understanding of relevant ICT standards, legislation and regulations including compliance standards In-depth knowledge of current and emerging security threats and technologies. Good knowledge of cyber security best practice toolsets and methodologies including system management tools. Basic knowledge of database and application security. Knowledge of how to set up and maintain administrative procedures and systems. Knowledge of information management and reporting.
Jun 02, 2023
Full time
Cyber Security Analyst Organisation: NHS Trust (West Midlands) Type: Permanent Salary: £29,827.35 - £36,310.05 per annum No Positions: 03 Hybrid: 1 day per month in the office Job Summary With primary responsibility for ensuring the security, validity and provision of our systems and services, the post holder, through monitoring, evaluation and in collaboration with Senior Cyber Security Analyst, will lead on IT Security activities within the Trust. You The post holder will assist and support the Cyber Security team in ensuring that the Trusts IT network, computer systems and services remain secure, resilient and robust. The post holder will be responsible for ensuring that cyber security is aligned with business security and information governance. Ensuring that cyber security is effectively managed in all service and IT service management activities. Undertake IT security investigations and computer forensic work across the Trust. The post holder is responsible for: Resolving and delivering cyber security incidents, problems, and service requests, working with other members of the cyber security team Deploying, maintaining, monitoring, and troubleshooting systems (operating or applications) and hardware in use by the trust Ensuring IT infrastructure that is deployed meets current cyber security standards, as defined by Trust policy Ensuring the ongoing management, maintenance and use of cyber security Standard operating Procedures (SOPs) Key Responsibilities 1. Resolve incidents and complete service requests relating to all aspects of cyber security in accordance with defined processes and service level agreements (SLAs) and key performance indicators (KPIs). 2. Monitor changes in cyber security threats and appropriately respond to changes in threat profile. 3. Monitor cyber security services, systems and related infrastructure for signs of compromise. 4. Ensure that IT assets and resources are protected from malicious software (ie malware) and other emerging threats 5. Identify and address any potential and actual vulnerabilities in applications, infrastructure, services, software and systems 6. To work with various stakeholders including external partners, to build, maintain and promote effective working relationships. 7. Provide specialist advice and guidance across network, security, server, and desktop infrastructures. 8. Provide technical guidance and support to Trust employees on the use and interpretation of the information security management system policies and standards applicable to the use of IT. 9. Provide technical guidance and support to Trust employees on a range of cyber security issues, including computer viruses, spam e-mail, malware and hoaxes. Contribute to cyber security support functions such as creating and defining cyber security processes on a wide and varied range of tasks. 10. Assist with investigations into potential and reported misuse of the Trust IT facilities. Provide advice and updates to managers and human resource teams, ensuring that the correct investigation procedures are adhered to and that all documentation is recorded completely and accurately. 11. Perform technical cyber security risk assessments on user requests for access to systems, use of new software or hardware facilities. 12. Provide regular management information on cyber security matters, eg on the e-mail and Internet monitoring systems and identify the need for any new controls based on this Information. 13. Prepare reports based on cyber security incident statistics and organisational compliance with cyber security targets. 14. Assist in the coordination and management of cyber incident response activities 15. Support the cyber security team in the provision of service delivery, ensuring the team shares knowledge and works flexibly. Key Skills Expert Cyber security skills ie malware analysis, risk analysis, intrusion detection, reverse engineering, data analytics Excellent interpersonal skills, demonstrated by communicating with colleagues, Partners and non-technical professionals on a daily basis Able to work individually without direct supervision, and work in an agile environment Key Experience Experience of providing good advice and support to a range of customers/users. Experience of working in a confidential environment and in a customer-focused ICT organisation. Experience of delivering excellent service to a wide range of stakeholders Evidence of delivering ICT solutions to a diverse workforce. Understanding of relevant ICT standards, legislation and regulations including compliance standards In-depth knowledge of current and emerging security threats and technologies. Good knowledge of cyber security best practice toolsets and methodologies including system management tools. Basic knowledge of database and application security. Knowledge of how to set up and maintain administrative procedures and systems. Knowledge of information management and reporting.
Services and Control Senior Analyst - Insurance Market Competitive Salary + Bonus + Benefits The Service and Controls Senior Analyst is part of the Technology Service Management function and helps leads and enable the definition and improvement of ITSM capability. This role enables our Technology Change Delivery Portfolios as well as BAU service delivery teams by driving and owning appropriate ITSM Controls and Governance to assure secure, stable, and performing technology services. The role leverages existing enterprise service management process and controls capability, owning their localized implementation to support the GRSI Tech's strategy. As well, the role leads on the necessary improvements to address gaps and recommendations across the wider Audit, Cyber and IT controls frameworks. Key Responsibilities: Responsible for ITSM Controls and Governance enabling secure, stable and performing technology services. Implement and improve ITSM capability, reporting, controls, service integration and process support Provide appropriate service reporting on a regular basis to achieve targets, continuously improve and deliver excellent customer service Develop quality, exec-ready management information, presentations, proposals, and reports Helps drive the ITSM Strategy for GRSI Technology working in coordination with Enterprise SMO, as well as GRS Tech. Engineering, Resilience and support teams Drive the necessary improvements to address gaps and recommendations relating to ITSM across the wider Audit, DT Cyber and IT controls frameworks Compliance & Strategic Alignment Ensure appropriate technology controls are implemented and regularly tested in line with the client, GRSI, GRS and GDS practices Align to Company and GRS technology delivery functions to ensure the service management team operates in compliance with all relevant standards, processes and procedures Demonstrate behaviours as set out in the Conduct Risk Policy in alignment with company commitment to placing customers at the centre of our business and behaving with integrity Service Management Support Service Delivery Team leads and Managers with robust ITSM practices and process support Oversee and evolve Major and High Priority Incident Management Drive adoption of Problem Management and Continual Improvement Engage with business leaders to ensure Services are understood and appropriate, evolving our service catalogue and service level agreement framework Ensure appropriate service level reporting and dashboards as required Enhance the Supplier Management practices, ensuring formal inventory of vendor contracts and active management of all contracts with a strong commercial mindset Service Operations Support Act as an escalation point for major incident and problem management; Take ownership of critical incidents, coordinating with resolution parties, and establishing effective communication between stakeholders for post-incident reviews Ensure appropriate risk and impact assessments are Embedded and performed in Change Management and CAB processes Collaborate with the Desktop Support, Cloud and Infrastructure Engineering Managers to ensure team priorities are aligned with the ITSM strategy Information Security Management Devise measures to protect company data from both internal and external threats Take part in day-to-day monitoring for activities, implement defensive protocols, and report incidents in line with security best practices Contribute to security guidelines, procedures, standards, and controls documentation Continuous Improvement, Governance & Delivery Own ITSM capability and service improvement roadmaps, enhancing service management processes, governance, tools, reporting and compliance Act as Product Owner for ITSM Processes and Tooling maintain a backlog of all related initiatives aligned to the Agile Portfolio Office Actively manage risks and issues in the ITSM area, developing mitigation plans/actions and remediation planning sessions, logging and escalating where appropriate Review practices to ensure consistency with policies, compliance regulations and control requirements, providing direction and changes as needed and ensuring alignment with business objectives and industry trends Champion, coach and promote the sharing of best practice on ITSM, increasing the internal capability and body of knowledge Develop and maintain Service management operational policies, standards, procedures, and guidelines where applicable Skills and Experience Experienced Service Management professional with years of relevant experience, ideally in a dynamic, demanding and highly regulated financial services environment. ITIL qualifications Excellent interpersonal and customer service skills with a passion for service excellence and a track record of continuous service improvement Strong leadership ability and team spirit with exceptional skills in motivating, coaching, and supporting team members to deliver success outcomes. Excellent written and verbal communication and presentation skills, including the production of quality, visually appealing, exec-ready PowerPoint slides and reports as required. Demonstrable experience of internal and external stakeholder engagement Exposure to financial and vendor management Strong organisational skills with an ability to balance and prioritise multiple initiatives at once, and to work under pressure when necessary. Apply today with your most up to date CV. If this role isn't quite what you are after but know someone who may be relevant, we offer a referral scheme for any successful recommendations. Carbon60, Lorien & SRG - The Impellam Group STEM Portfolio are acting as an Employment Business in relation to this vacancy.
Jun 02, 2023
Full time
Services and Control Senior Analyst - Insurance Market Competitive Salary + Bonus + Benefits The Service and Controls Senior Analyst is part of the Technology Service Management function and helps leads and enable the definition and improvement of ITSM capability. This role enables our Technology Change Delivery Portfolios as well as BAU service delivery teams by driving and owning appropriate ITSM Controls and Governance to assure secure, stable, and performing technology services. The role leverages existing enterprise service management process and controls capability, owning their localized implementation to support the GRSI Tech's strategy. As well, the role leads on the necessary improvements to address gaps and recommendations across the wider Audit, Cyber and IT controls frameworks. Key Responsibilities: Responsible for ITSM Controls and Governance enabling secure, stable and performing technology services. Implement and improve ITSM capability, reporting, controls, service integration and process support Provide appropriate service reporting on a regular basis to achieve targets, continuously improve and deliver excellent customer service Develop quality, exec-ready management information, presentations, proposals, and reports Helps drive the ITSM Strategy for GRSI Technology working in coordination with Enterprise SMO, as well as GRS Tech. Engineering, Resilience and support teams Drive the necessary improvements to address gaps and recommendations relating to ITSM across the wider Audit, DT Cyber and IT controls frameworks Compliance & Strategic Alignment Ensure appropriate technology controls are implemented and regularly tested in line with the client, GRSI, GRS and GDS practices Align to Company and GRS technology delivery functions to ensure the service management team operates in compliance with all relevant standards, processes and procedures Demonstrate behaviours as set out in the Conduct Risk Policy in alignment with company commitment to placing customers at the centre of our business and behaving with integrity Service Management Support Service Delivery Team leads and Managers with robust ITSM practices and process support Oversee and evolve Major and High Priority Incident Management Drive adoption of Problem Management and Continual Improvement Engage with business leaders to ensure Services are understood and appropriate, evolving our service catalogue and service level agreement framework Ensure appropriate service level reporting and dashboards as required Enhance the Supplier Management practices, ensuring formal inventory of vendor contracts and active management of all contracts with a strong commercial mindset Service Operations Support Act as an escalation point for major incident and problem management; Take ownership of critical incidents, coordinating with resolution parties, and establishing effective communication between stakeholders for post-incident reviews Ensure appropriate risk and impact assessments are Embedded and performed in Change Management and CAB processes Collaborate with the Desktop Support, Cloud and Infrastructure Engineering Managers to ensure team priorities are aligned with the ITSM strategy Information Security Management Devise measures to protect company data from both internal and external threats Take part in day-to-day monitoring for activities, implement defensive protocols, and report incidents in line with security best practices Contribute to security guidelines, procedures, standards, and controls documentation Continuous Improvement, Governance & Delivery Own ITSM capability and service improvement roadmaps, enhancing service management processes, governance, tools, reporting and compliance Act as Product Owner for ITSM Processes and Tooling maintain a backlog of all related initiatives aligned to the Agile Portfolio Office Actively manage risks and issues in the ITSM area, developing mitigation plans/actions and remediation planning sessions, logging and escalating where appropriate Review practices to ensure consistency with policies, compliance regulations and control requirements, providing direction and changes as needed and ensuring alignment with business objectives and industry trends Champion, coach and promote the sharing of best practice on ITSM, increasing the internal capability and body of knowledge Develop and maintain Service management operational policies, standards, procedures, and guidelines where applicable Skills and Experience Experienced Service Management professional with years of relevant experience, ideally in a dynamic, demanding and highly regulated financial services environment. ITIL qualifications Excellent interpersonal and customer service skills with a passion for service excellence and a track record of continuous service improvement Strong leadership ability and team spirit with exceptional skills in motivating, coaching, and supporting team members to deliver success outcomes. Excellent written and verbal communication and presentation skills, including the production of quality, visually appealing, exec-ready PowerPoint slides and reports as required. Demonstrable experience of internal and external stakeholder engagement Exposure to financial and vendor management Strong organisational skills with an ability to balance and prioritise multiple initiatives at once, and to work under pressure when necessary. Apply today with your most up to date CV. If this role isn't quite what you are after but know someone who may be relevant, we offer a referral scheme for any successful recommendations. Carbon60, Lorien & SRG - The Impellam Group STEM Portfolio are acting as an Employment Business in relation to this vacancy.
A UK leading food supplier within the catering industry are seeking an experienced IT Compliance & Audit Manager to support and drive the compliance and risk standards throughout the business. Working closely with the leadership team while reporting direct to the Vice President of IT, you will ensure policies and security controls are maintained while proactively plan and deliver on business-critical compliance and IT Audits. The right candidate will have an in-depth experience managing PCI DSS, Risk Managers and IT Audit implementing cyber governance. The Role: Lead and maintain PCI DSS compliances and standard practices Manage and maintain IT risk register and IT contracts Work closely with both IT SecOps teams and senior IT management to develop and ensure all information system security for all business-critical systems are secure Lead Quarterly It Audits Oversee functional testing of cyber security controls The Requirements: Proven experience with PCI DSS and Cyber Essentials Plus Come from an IT security compliance background or similar Ability to communicate with all levels of stakeholders and IT technical teams Strong knowledge Microsoft Azure Cloud Security PCI ISA Qualification desirable The Overview: Up to £65,000 depending on experience Fulltime permanent position Hybrid role, 3 days in office Bath area, parking available
Jun 02, 2023
Full time
A UK leading food supplier within the catering industry are seeking an experienced IT Compliance & Audit Manager to support and drive the compliance and risk standards throughout the business. Working closely with the leadership team while reporting direct to the Vice President of IT, you will ensure policies and security controls are maintained while proactively plan and deliver on business-critical compliance and IT Audits. The right candidate will have an in-depth experience managing PCI DSS, Risk Managers and IT Audit implementing cyber governance. The Role: Lead and maintain PCI DSS compliances and standard practices Manage and maintain IT risk register and IT contracts Work closely with both IT SecOps teams and senior IT management to develop and ensure all information system security for all business-critical systems are secure Lead Quarterly It Audits Oversee functional testing of cyber security controls The Requirements: Proven experience with PCI DSS and Cyber Essentials Plus Come from an IT security compliance background or similar Ability to communicate with all levels of stakeholders and IT technical teams Strong knowledge Microsoft Azure Cloud Security PCI ISA Qualification desirable The Overview: Up to £65,000 depending on experience Fulltime permanent position Hybrid role, 3 days in office Bath area, parking available
Senior Information Security Analyst Hybrid working Our client, a leading financial services organisation have an exciting opportunity for a Senior Information Security Analyst to join on a permanent basis. The Senior Information Security Specialist is primarily responsible for day-to-day security monitoring, response, reporting and the management of the security toolset. The role should ensure that the Bank is able to protect and respond to security incidents and manage threats appropriately. The Security Specialist is accountable for protecting all sensitive information within the company and ensuring all networks have adequate security to prevent unauthorised access. Role responsibilities: Develop and implement IT risk and information security strategy, policies, shared security services and action plans. Support the organisations overall regulatory commitments, providing appropriate operational security information, KPI/KRI and reporting. Identify and analyse risks, recommend appropriate mitigations, and document all components in clear, business intelligible language. Serve as a SME to senior management and the executive in the management, implementation and maintenance of cyber risk and security. Support the organisations adoption of Payment Card Industry Data Security Standard (PCI DSS), SWIFT compliance and alignment to an Information Security Standard such a ISO 27001/NIST and ensure effective implementation and monitoring of controls. Governance and management of 3rd party suppliers by performing supplier reviews and periodic due diligence, liaising with the business owners for remediation of any issues. Take an active role in both security incident investigation, as well as proactive investigation of security log data, the changing threats and vulnerabilities deemed important. Ensure completion of scheduled security checks on core systems including access control, functional system security and technical compliance, such as hardening standards. Engage with our external Security Operations Centre to support and manage event identification and incident response. Provide advice, guidance, and training, such as the provision of security awareness training and Phishing exercises. Manage associated governance of security services, by ensuring simple and clear documentation on standards, process and procedures is maintained to a good standard. Deputise for the IT Operations Manager on Information Security matters as and when required Skills required: Significant experience of developing and implementing risk and information security strategy, policies, shared security services and action plans. Microsoft 365 E5 Security Toolset, Data Loss Prevention, Conditional Access, IAM, Azure Services. Full understanding and experience of Payment Card Industry Data Security Standard (PCI DSS), SWIFT and Information Security Standards such as ISO 27001/NIST controls. Strong technical understanding of Unix/Linux and Microsoft environments Experience overseeing and managing third party relationships and proven track record of working with penetration testing partners, organizing pen-tests, and defining remediation SLAs. Maintain positive attitude and enthusiasm in challenging situations; motivate and partner with the business units to meet information security objectives. Ability and willingness to adopt a flexible approach to demands and challenges. Strong organisational and personal effectiveness skills, including time and project management. Excellent oral and written communication, facilitation skills and ability to present confidently and to engage, influence and manage stakeholders, developing effective relationships at all levels effectively. Senior Information Security Analyst Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
Jun 01, 2023
Full time
Senior Information Security Analyst Hybrid working Our client, a leading financial services organisation have an exciting opportunity for a Senior Information Security Analyst to join on a permanent basis. The Senior Information Security Specialist is primarily responsible for day-to-day security monitoring, response, reporting and the management of the security toolset. The role should ensure that the Bank is able to protect and respond to security incidents and manage threats appropriately. The Security Specialist is accountable for protecting all sensitive information within the company and ensuring all networks have adequate security to prevent unauthorised access. Role responsibilities: Develop and implement IT risk and information security strategy, policies, shared security services and action plans. Support the organisations overall regulatory commitments, providing appropriate operational security information, KPI/KRI and reporting. Identify and analyse risks, recommend appropriate mitigations, and document all components in clear, business intelligible language. Serve as a SME to senior management and the executive in the management, implementation and maintenance of cyber risk and security. Support the organisations adoption of Payment Card Industry Data Security Standard (PCI DSS), SWIFT compliance and alignment to an Information Security Standard such a ISO 27001/NIST and ensure effective implementation and monitoring of controls. Governance and management of 3rd party suppliers by performing supplier reviews and periodic due diligence, liaising with the business owners for remediation of any issues. Take an active role in both security incident investigation, as well as proactive investigation of security log data, the changing threats and vulnerabilities deemed important. Ensure completion of scheduled security checks on core systems including access control, functional system security and technical compliance, such as hardening standards. Engage with our external Security Operations Centre to support and manage event identification and incident response. Provide advice, guidance, and training, such as the provision of security awareness training and Phishing exercises. Manage associated governance of security services, by ensuring simple and clear documentation on standards, process and procedures is maintained to a good standard. Deputise for the IT Operations Manager on Information Security matters as and when required Skills required: Significant experience of developing and implementing risk and information security strategy, policies, shared security services and action plans. Microsoft 365 E5 Security Toolset, Data Loss Prevention, Conditional Access, IAM, Azure Services. Full understanding and experience of Payment Card Industry Data Security Standard (PCI DSS), SWIFT and Information Security Standards such as ISO 27001/NIST controls. Strong technical understanding of Unix/Linux and Microsoft environments Experience overseeing and managing third party relationships and proven track record of working with penetration testing partners, organizing pen-tests, and defining remediation SLAs. Maintain positive attitude and enthusiasm in challenging situations; motivate and partner with the business units to meet information security objectives. Ability and willingness to adopt a flexible approach to demands and challenges. Strong organisational and personal effectiveness skills, including time and project management. Excellent oral and written communication, facilitation skills and ability to present confidently and to engage, influence and manage stakeholders, developing effective relationships at all levels effectively. Senior Information Security Analyst Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
Role Introduction The Senior Systems Engineer will workas part of an operationalsquadto support specific Managed Service (ITO)customers in the cloud, ensuring all systems and related applications and infrastructure are supported and maintained to industry best practice and agreed standards. Key to success will be a close-knit tribal culture of customer centric service. The Senior Systems Engineer willwork closely with the Technical Account Manager for each customer, contributing to overall technical governance and leadership, technical excellence, and continualservice improvement. You will be a technology specialist, capable of delivering expert skills and knowledge in at least one related Microsoft application or service, along with a keen all-round interest in current Microsoftcloud and on-premiseecosystems and relevant related technologies. You will use these skills to contribute to standardisation, optimisation, and innovation, working with others to help define and deliver standardisation within the business. Communication and collaboration is paramount in this role, you will work closelywith a variety of internal and external business stakeholders and will be continually engaged and collaborating with our clients. What You Will Do Implement solutions which drive automation to help reduce time spent by support teams and in turn, free time to innovate and drive service improvement. Where required, provide technical support, and take ownership of technical investigations into complex problems, continuing to work on them until a resolution or workaround can be implemented. Provide technical input and governance to the problem and update stakeholders at regular intervals as the technical investigation continues. Attend relevant customer specific meetings as and where required. Examples may include presenting changes to the change advisory board, providing technical feedback as part of a formal problem review and progress updates during project review meetings. Ensure compliance to relevant standards (i.e. ISO 27001, 9001) and security (i.e. CIS, STIG) to help ensure we control, report and adequately measure and handle risks the business faces. Use your specialist knowledge to contribute to and assist the relevant technical guild; a forum of your peers defining and driving standards to manage and optimise the services. As an effective and highly capable team member, you will self-manage your workload and proactively pickup requests and other work through the ITSM tool. You will also need to be able to mentor and develop other engineers in the wider technical support teams. Author new technical documentation for example for new solutions or changes in configuration required to adhere to updated security standards that is structured and relevant to the audience. Work on other tasks as required to support wider business plans and initiatives. What You Will Have Experienced senior technical resource, highly motivated and capable of understanding and resolving complex technical problems. Strong understanding of both Azure and M365 cloud services as well ason-premise Windows Server infrastructure, coupled with a general understanding of traditional hosted technologies and approach. Capability to problem solve; undertaking or designing tests to eliminate possible issues and working quickly and efficiently towards a solution Working knowledge of network andsecurity technologies as well as private cloud infrastructure such as virtualisation and storage. Excellent communication verbal and written, being able to operate at all levels and articulate messages to a variety of different audiences. Understand people and cultural differences to build good relationships with colleagues. Capability to author and update infrastructure, support and procedural documentation. Keen willingness to mentor others in the team and wider department on technologies within your field of expertise. Ability to present concepts in authoritative and clear manner through white boarding, presentations and proposals. Understanding of Incident, Problem and Change Management within the ITIL framework. Capability to project manage in an informal capacity; able to apply appropriate project methodology to plan, ex
Jun 01, 2023
Full time
Role Introduction The Senior Systems Engineer will workas part of an operationalsquadto support specific Managed Service (ITO)customers in the cloud, ensuring all systems and related applications and infrastructure are supported and maintained to industry best practice and agreed standards. Key to success will be a close-knit tribal culture of customer centric service. The Senior Systems Engineer willwork closely with the Technical Account Manager for each customer, contributing to overall technical governance and leadership, technical excellence, and continualservice improvement. You will be a technology specialist, capable of delivering expert skills and knowledge in at least one related Microsoft application or service, along with a keen all-round interest in current Microsoftcloud and on-premiseecosystems and relevant related technologies. You will use these skills to contribute to standardisation, optimisation, and innovation, working with others to help define and deliver standardisation within the business. Communication and collaboration is paramount in this role, you will work closelywith a variety of internal and external business stakeholders and will be continually engaged and collaborating with our clients. What You Will Do Implement solutions which drive automation to help reduce time spent by support teams and in turn, free time to innovate and drive service improvement. Where required, provide technical support, and take ownership of technical investigations into complex problems, continuing to work on them until a resolution or workaround can be implemented. Provide technical input and governance to the problem and update stakeholders at regular intervals as the technical investigation continues. Attend relevant customer specific meetings as and where required. Examples may include presenting changes to the change advisory board, providing technical feedback as part of a formal problem review and progress updates during project review meetings. Ensure compliance to relevant standards (i.e. ISO 27001, 9001) and security (i.e. CIS, STIG) to help ensure we control, report and adequately measure and handle risks the business faces. Use your specialist knowledge to contribute to and assist the relevant technical guild; a forum of your peers defining and driving standards to manage and optimise the services. As an effective and highly capable team member, you will self-manage your workload and proactively pickup requests and other work through the ITSM tool. You will also need to be able to mentor and develop other engineers in the wider technical support teams. Author new technical documentation for example for new solutions or changes in configuration required to adhere to updated security standards that is structured and relevant to the audience. Work on other tasks as required to support wider business plans and initiatives. What You Will Have Experienced senior technical resource, highly motivated and capable of understanding and resolving complex technical problems. Strong understanding of both Azure and M365 cloud services as well ason-premise Windows Server infrastructure, coupled with a general understanding of traditional hosted technologies and approach. Capability to problem solve; undertaking or designing tests to eliminate possible issues and working quickly and efficiently towards a solution Working knowledge of network andsecurity technologies as well as private cloud infrastructure such as virtualisation and storage. Excellent communication verbal and written, being able to operate at all levels and articulate messages to a variety of different audiences. Understand people and cultural differences to build good relationships with colleagues. Capability to author and update infrastructure, support and procedural documentation. Keen willingness to mentor others in the team and wider department on technologies within your field of expertise. Ability to present concepts in authoritative and clear manner through white boarding, presentations and proposals. Understanding of Incident, Problem and Change Management within the ITIL framework. Capability to project manage in an informal capacity; able to apply appropriate project methodology to plan, ex
Your new company Your new company is a cutting edge Marketing PLC which operates in over 10 countries, employees over 3000 people and has over 40 offices. They use data and analytics to generate organic and sustainable growth for their customers.The Marketing PLCs uses of data and technology meaning they are able to create an approach that means their customers are able to exploit opportunities in the market. The use of these new cutting edge methods means they are able to develop a much more personal and creative experience for who their customers are trying to reach, this results in higher engagement. They combine both marketing and consultancy to generate a unique and more effective experience. Your new role Your new role as Senior Data Protection Manager will be the first Data Protections professional the company has brought on as they were previously outsourcing the position. This means that you will be a key part of the organisation as they are looking for the right candidate to progress to the Data Protection Officer role.In this position you will be responsible for managing, updating and reviewing privacy governance frameworks to ensure data use is in compliance with GDPR. Managing key internal and external stakeholders will also be a key task in the role, this will involve reviewing projects to ensure compliance with local data protection laws and when needs advise on DPIAs. You will also be responsible for managing both DSARs and ROPAs. What you'll need to succeed Degree qualification Data Protection Accreditation Multiple years experience within a compliance, legal or risk function with recent privacy experience Experience working with cyber security teams Experience with Marketing firm is preferred but not ideal What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.If this job isn't quite right for you but you are looking for a new position, please contact us for a confidential discussion on your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
Jun 01, 2023
Full time
Your new company Your new company is a cutting edge Marketing PLC which operates in over 10 countries, employees over 3000 people and has over 40 offices. They use data and analytics to generate organic and sustainable growth for their customers.The Marketing PLCs uses of data and technology meaning they are able to create an approach that means their customers are able to exploit opportunities in the market. The use of these new cutting edge methods means they are able to develop a much more personal and creative experience for who their customers are trying to reach, this results in higher engagement. They combine both marketing and consultancy to generate a unique and more effective experience. Your new role Your new role as Senior Data Protection Manager will be the first Data Protections professional the company has brought on as they were previously outsourcing the position. This means that you will be a key part of the organisation as they are looking for the right candidate to progress to the Data Protection Officer role.In this position you will be responsible for managing, updating and reviewing privacy governance frameworks to ensure data use is in compliance with GDPR. Managing key internal and external stakeholders will also be a key task in the role, this will involve reviewing projects to ensure compliance with local data protection laws and when needs advise on DPIAs. You will also be responsible for managing both DSARs and ROPAs. What you'll need to succeed Degree qualification Data Protection Accreditation Multiple years experience within a compliance, legal or risk function with recent privacy experience Experience working with cyber security teams Experience with Marketing firm is preferred but not ideal What you need to do now If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.If this job isn't quite right for you but you are looking for a new position, please contact us for a confidential discussion on your career. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
Services and Control Senior Analyst - Insurance Market Competitive Salary + Bonus + Benefits The Service and Controls Lead is part of the Technology Service Management function and helps leads and enable the definition and improvement of ITSM capability. This role enables our Technology Change Delivery Portfolios as well as BAU service delivery teams by driving and owning appropriate ITSM Controls and Governance to assure secure, stable, and performing technology services. The role leverages existing the client's enterprise service management process and controls capability, owning their localized implementation to support the GRSI Tech's strategy. As well, the role leads on the necessary improvements to address gaps and recommendations across the wider Audit, Cyber and IT controls frameworks. Key Responsibilities: Responsible for ITSM Controls and Governance enabling secure, stable and performing technology services. Implement and improve ITSM capability, reporting, controls, service integration and process support Provide appropriate service reporting on a regular basis to achieve targets, continuously improve and deliver excellent customer service Share best practice and coach on ITSM, increasing the internal body of knowledge Develop quality, exec-ready management information, presentations, proposals, and reports Helps drive the ITSM Strategy for GRSI Technology working in coordination with Enterprise SMO, as well as GRS Tech. Engineering, Resilience and support teams Drive the necessary improvements to address gaps and recommendations relating to ITSM across the wider Audit, DT Cyber and IT controls frameworks Compliance & Strategic Alignment Ensure appropriate technology controls are implemented and regularly tested in line with the client, GRSI, GRS and GDS practices Align to Company and GRS technology delivery functions to ensure the service management team operates in compliance with all relevant standards, processes and procedures Demonstrate behaviours as set out in the Conduct Risk Policy in alignment with company commitment to placing customers at the centre of our business and behaving with integrity Service Management Support Service Delivery Team leads and Managers with robust ITSM practices and process support Oversee and evolve Major and High Priority Incident Management Drive adoption of Problem Management and Continual Improvement Engage with business leaders to ensure Services are understood and appropriate, evolving our service catalogue and service level agreement framework Ensure appropriate service level reporting and dashboards as required Chair the service review process with customers and key stakeholders Enhance the Supplier Management practices, ensuring formal inventory of vendor contracts and active management of all contracts with a strong commercial mindset Service Operations Support Act as an escalation point for major incident and problem management; Take ownership of critical incidents, coordinating with resolution parties, and establishing effective communication between stakeholders for post-incident reviews Ensure appropriate risk and impact assessments are embedded and performed in Change Management and CAB processes Collaborate with the Desktop Support, Cloud and Infrastructure Engineering Managers to ensure team priorities are aligned with the ITSM strategy Information Security Management Devise measures to protect company data from both internal and external threats Take part in day-to-day monitoring for activities, implement defensive protocols, and report incidents in line with security best practices Contribute to security guidelines, procedures, standards, and controls documentation Continuous Improvement, Governance & Delivery Own ITSM capability and service improvement roadmaps, enhancing service management processes, governance, tools, reporting and compliance Act as Product Owner for ITSM Processes and Tooling maintain a backlog of all related initiatives aligned to the Agile Portfolio Office Actively manage risks and issues in the ITSM area, developing mitigation plans/actions and remediation planning sessions, logging and escalating where appropriate Review practices to ensure consistency with policies, compliance regulations and control requirements, providing direction and changes as needed and ensuring alignment with business objectives and industry trends Champion, coach and promote the sharing of best practice on ITSM, increasing the internal capability and body of knowledge Develop and maintain Service management operational policies, standards, procedures, and guidelines where applicable Skills and Experience Experienced Service Management professional ITIL qualifications - preferably ITIL Expert, or Strategic Leader Excellent interpersonal and customer service skills with a passion for service excellence and a track record of continuous service improvement Strong leadership ability and team spirit with exceptional skills in motivating, coaching and supporting team members to deliver success outcomes Demonstrable experience of internal and external stakeholder engagement Exposure to financial and vendor management Strong organisational skills with an ability to balance and prioritise multiple initiatives at once, and to work under pressure when necessary Apply today with your most up to date CV. If this role isn't quite what you are after but know someone who may be relevant, we offer a referral scheme for any successful recommendations. Carbon60, Lorien & SRG - The Impellam Group STEM Portfolio are acting as an Employment Business in relation to this vacancy.
Jun 01, 2023
Full time
Services and Control Senior Analyst - Insurance Market Competitive Salary + Bonus + Benefits The Service and Controls Lead is part of the Technology Service Management function and helps leads and enable the definition and improvement of ITSM capability. This role enables our Technology Change Delivery Portfolios as well as BAU service delivery teams by driving and owning appropriate ITSM Controls and Governance to assure secure, stable, and performing technology services. The role leverages existing the client's enterprise service management process and controls capability, owning their localized implementation to support the GRSI Tech's strategy. As well, the role leads on the necessary improvements to address gaps and recommendations across the wider Audit, Cyber and IT controls frameworks. Key Responsibilities: Responsible for ITSM Controls and Governance enabling secure, stable and performing technology services. Implement and improve ITSM capability, reporting, controls, service integration and process support Provide appropriate service reporting on a regular basis to achieve targets, continuously improve and deliver excellent customer service Share best practice and coach on ITSM, increasing the internal body of knowledge Develop quality, exec-ready management information, presentations, proposals, and reports Helps drive the ITSM Strategy for GRSI Technology working in coordination with Enterprise SMO, as well as GRS Tech. Engineering, Resilience and support teams Drive the necessary improvements to address gaps and recommendations relating to ITSM across the wider Audit, DT Cyber and IT controls frameworks Compliance & Strategic Alignment Ensure appropriate technology controls are implemented and regularly tested in line with the client, GRSI, GRS and GDS practices Align to Company and GRS technology delivery functions to ensure the service management team operates in compliance with all relevant standards, processes and procedures Demonstrate behaviours as set out in the Conduct Risk Policy in alignment with company commitment to placing customers at the centre of our business and behaving with integrity Service Management Support Service Delivery Team leads and Managers with robust ITSM practices and process support Oversee and evolve Major and High Priority Incident Management Drive adoption of Problem Management and Continual Improvement Engage with business leaders to ensure Services are understood and appropriate, evolving our service catalogue and service level agreement framework Ensure appropriate service level reporting and dashboards as required Chair the service review process with customers and key stakeholders Enhance the Supplier Management practices, ensuring formal inventory of vendor contracts and active management of all contracts with a strong commercial mindset Service Operations Support Act as an escalation point for major incident and problem management; Take ownership of critical incidents, coordinating with resolution parties, and establishing effective communication between stakeholders for post-incident reviews Ensure appropriate risk and impact assessments are embedded and performed in Change Management and CAB processes Collaborate with the Desktop Support, Cloud and Infrastructure Engineering Managers to ensure team priorities are aligned with the ITSM strategy Information Security Management Devise measures to protect company data from both internal and external threats Take part in day-to-day monitoring for activities, implement defensive protocols, and report incidents in line with security best practices Contribute to security guidelines, procedures, standards, and controls documentation Continuous Improvement, Governance & Delivery Own ITSM capability and service improvement roadmaps, enhancing service management processes, governance, tools, reporting and compliance Act as Product Owner for ITSM Processes and Tooling maintain a backlog of all related initiatives aligned to the Agile Portfolio Office Actively manage risks and issues in the ITSM area, developing mitigation plans/actions and remediation planning sessions, logging and escalating where appropriate Review practices to ensure consistency with policies, compliance regulations and control requirements, providing direction and changes as needed and ensuring alignment with business objectives and industry trends Champion, coach and promote the sharing of best practice on ITSM, increasing the internal capability and body of knowledge Develop and maintain Service management operational policies, standards, procedures, and guidelines where applicable Skills and Experience Experienced Service Management professional ITIL qualifications - preferably ITIL Expert, or Strategic Leader Excellent interpersonal and customer service skills with a passion for service excellence and a track record of continuous service improvement Strong leadership ability and team spirit with exceptional skills in motivating, coaching and supporting team members to deliver success outcomes Demonstrable experience of internal and external stakeholder engagement Exposure to financial and vendor management Strong organisational skills with an ability to balance and prioritise multiple initiatives at once, and to work under pressure when necessary Apply today with your most up to date CV. If this role isn't quite what you are after but know someone who may be relevant, we offer a referral scheme for any successful recommendations. Carbon60, Lorien & SRG - The Impellam Group STEM Portfolio are acting as an Employment Business in relation to this vacancy.
Role Introduction The Senior Network Engineer will work as part of an operational squad to support specific Managed Services (ITO) customers in the cloud, ensuring all systems and related applications and infrastructure are supported and maintained to industry best practice and agreed standards. Key to success will be a close-knit tribal culture of customer centric service. The Senior Network Engineer will work closely with the Technical Account Manager for each customer, contributing to overall technical governance and leadership, technical excellence, and continual service improvement. You will be comfortable working at CCNP or CCIE level or have the equivalent experience in designing and configuring network and security technologies. You will be experienced in delivering complex technical projects and defining technical direction. You will use these skills to contribute to standardisation, optimisation, and innovation, working with others to help define and deliver standardisation within the business. Communication and collaboration are paramount in this role, you will work closely with a variety of internal and external business stakeholders and will be continually engaged and collaborating with our clients. What You Will Do • Implement solutions which drive automation to help reduce time spent by support teams and in turn, free time to innovate and drive service improvement.• Where required, provide technical support, and take ownership of technical investigations into complex problems, continuing to work on them until a resolution or workaround can be implemented. Provide technical input and governance to the problem and update stakeholders at regular intervals as the technical investigation continues.• Attend relevant customer specific meetings as and where required. Examples may include presenting changes to the change advisory board, providing technical feedback as part of a formal problem review and progress updates during project review meetings.• Ensure compliance to relevant standards (i.e. ISO 27001, 9001) and security (i.e. CIS, STIG) to help ensure we control, report and adequately measure and handle risks the business faces.• Use your specialist knowledge to contribute to and assist the relevant technical guild; a forum of your peers defining and driving standards to manage and optimise the services.• As an effective and highly capable team member, you will self-manage your workload and proactively pickup requests and other work through the ITSM tool. You will also need to be able to mentor and develop other engineers in the wider technical support teams.• Author new technical documentation, for example, for new solutions or changes in configuration required to adhere to updated security standards that is structured and relevant to the audience.• Work on other tasks as required to support wider business plans and initiatives. What You Will Have • Experienced senior technical resource, highly motivated and capable of understanding and resolving complex technical problems.• Strong understanding of both Network and Security principles including routing and switching protocols.• Capability to problem solve ; undertaking or designing tests to eliminate possible issues and working quickly and efficiently towards a solution• Excellent communication verbal and written, being able to operate at all levels and articulate messages to a variety of different audiences. Understand people and cultural differences to build good relationships with colleagues. • Capability to author and update infrastructure, support and procedural documentation .• Keen willingness to mentor others in the team and wider department on technologies within your field of expertise.• Ability to present concepts in authoritative and clear manner through white boarding, presentations and proposals.• Understanding of Incident, Problem and Change Management within the ITIL framework .• Capability to project manage in an informal capacity; able to apply appropriate project methodology to plan, execute and report on work in a structured way.• Strong consultancy skills with the capacity to be an excellent motivator in order to meet deadlines and handle change. • Experience of operating within a multi-supplier / SIAM support model.• Ability to obtain and maintain UK Government Security Check (SC).Technical skills and experience One or more of these would accreditations be desirable: • Cisco CCNP/CCIE • Knowledge of other proprietry vendors (HP, Aruba, Juniper etc) Extensive experience in several of the following network areas and technologies: • Comprehensive knowledge of network infrastructure , including the ability to analyse and debug layers 1-7• Extensive experience of troubleshooting enterprise LAN's• Extensive experience of troubleshooting enterprise WAN's• VPNs including MPLS • Extensive experience with layer 2 and 3 switches • Experience with administering and troubleshooting Wireless products• Experience with troubleshooting Firewalls (Cisco ASA, NGFW - IDS/IPS & DDos)• Extensive experience with content switching/network load balancing with technologies such as F5, Kemp or Citrix NetScalers • Experience of Palo Alto• Cisco ISE• Monitoring Tools (such as Solarwinds/Logic Monitor). What We Do For You Wellbeing focussed - Our people are our greatest assets, and ensuring everyone feels their best self to come to work is integral Generous Annual Leave - 25 days of annual leave, plus public holidays and the ability to buy additional days Employee Assistance Programme - Free advice, support, and confidential counselling available 24/7 through Care First Personal Growth - Regardless of where you are at in your career, we're committed to enabling your growth personally and professionally Development Programmes - From Future Managers to Leadership Training, our development programmes help you get where you need to go Profit Share - Our Group-wide bonus scheme enables you to reap the rewards of your success Financial wellbeing - We understand as well as your mental wellbeing, your financial wellbeing is really important Pension Scheme - Our plan with Scottish Widows offers 5% matched contribution by the company Income protection insurance - Providing you with support and assistance when you need it most
Jun 01, 2023
Full time
Role Introduction The Senior Network Engineer will work as part of an operational squad to support specific Managed Services (ITO) customers in the cloud, ensuring all systems and related applications and infrastructure are supported and maintained to industry best practice and agreed standards. Key to success will be a close-knit tribal culture of customer centric service. The Senior Network Engineer will work closely with the Technical Account Manager for each customer, contributing to overall technical governance and leadership, technical excellence, and continual service improvement. You will be comfortable working at CCNP or CCIE level or have the equivalent experience in designing and configuring network and security technologies. You will be experienced in delivering complex technical projects and defining technical direction. You will use these skills to contribute to standardisation, optimisation, and innovation, working with others to help define and deliver standardisation within the business. Communication and collaboration are paramount in this role, you will work closely with a variety of internal and external business stakeholders and will be continually engaged and collaborating with our clients. What You Will Do • Implement solutions which drive automation to help reduce time spent by support teams and in turn, free time to innovate and drive service improvement.• Where required, provide technical support, and take ownership of technical investigations into complex problems, continuing to work on them until a resolution or workaround can be implemented. Provide technical input and governance to the problem and update stakeholders at regular intervals as the technical investigation continues.• Attend relevant customer specific meetings as and where required. Examples may include presenting changes to the change advisory board, providing technical feedback as part of a formal problem review and progress updates during project review meetings.• Ensure compliance to relevant standards (i.e. ISO 27001, 9001) and security (i.e. CIS, STIG) to help ensure we control, report and adequately measure and handle risks the business faces.• Use your specialist knowledge to contribute to and assist the relevant technical guild; a forum of your peers defining and driving standards to manage and optimise the services.• As an effective and highly capable team member, you will self-manage your workload and proactively pickup requests and other work through the ITSM tool. You will also need to be able to mentor and develop other engineers in the wider technical support teams.• Author new technical documentation, for example, for new solutions or changes in configuration required to adhere to updated security standards that is structured and relevant to the audience.• Work on other tasks as required to support wider business plans and initiatives. What You Will Have • Experienced senior technical resource, highly motivated and capable of understanding and resolving complex technical problems.• Strong understanding of both Network and Security principles including routing and switching protocols.• Capability to problem solve ; undertaking or designing tests to eliminate possible issues and working quickly and efficiently towards a solution• Excellent communication verbal and written, being able to operate at all levels and articulate messages to a variety of different audiences. Understand people and cultural differences to build good relationships with colleagues. • Capability to author and update infrastructure, support and procedural documentation .• Keen willingness to mentor others in the team and wider department on technologies within your field of expertise.• Ability to present concepts in authoritative and clear manner through white boarding, presentations and proposals.• Understanding of Incident, Problem and Change Management within the ITIL framework .• Capability to project manage in an informal capacity; able to apply appropriate project methodology to plan, execute and report on work in a structured way.• Strong consultancy skills with the capacity to be an excellent motivator in order to meet deadlines and handle change. • Experience of operating within a multi-supplier / SIAM support model.• Ability to obtain and maintain UK Government Security Check (SC).Technical skills and experience One or more of these would accreditations be desirable: • Cisco CCNP/CCIE • Knowledge of other proprietry vendors (HP, Aruba, Juniper etc) Extensive experience in several of the following network areas and technologies: • Comprehensive knowledge of network infrastructure , including the ability to analyse and debug layers 1-7• Extensive experience of troubleshooting enterprise LAN's• Extensive experience of troubleshooting enterprise WAN's• VPNs including MPLS • Extensive experience with layer 2 and 3 switches • Experience with administering and troubleshooting Wireless products• Experience with troubleshooting Firewalls (Cisco ASA, NGFW - IDS/IPS & DDos)• Extensive experience with content switching/network load balancing with technologies such as F5, Kemp or Citrix NetScalers • Experience of Palo Alto• Cisco ISE• Monitoring Tools (such as Solarwinds/Logic Monitor). What We Do For You Wellbeing focussed - Our people are our greatest assets, and ensuring everyone feels their best self to come to work is integral Generous Annual Leave - 25 days of annual leave, plus public holidays and the ability to buy additional days Employee Assistance Programme - Free advice, support, and confidential counselling available 24/7 through Care First Personal Growth - Regardless of where you are at in your career, we're committed to enabling your growth personally and professionally Development Programmes - From Future Managers to Leadership Training, our development programmes help you get where you need to go Profit Share - Our Group-wide bonus scheme enables you to reap the rewards of your success Financial wellbeing - We understand as well as your mental wellbeing, your financial wellbeing is really important Pension Scheme - Our plan with Scottish Widows offers 5% matched contribution by the company Income protection insurance - Providing you with support and assistance when you need it most
Role Introduction The Senior Infrastructure Engineer will work as part of an operational squad to support our customers, ensuring all systems and related applications and infrastructure are managed and maintained to industry best practice and agreed standards. Key to success will be a close-knit tribal culture of customer centric service . The Senior Infrastructure Engineer plays a key part in the overall technical governance and leadership, technical excellence, and continual service improvement. You will be a technology specialist , capable of delivering expert skills and knowledge in a range of traditional hosted infrastructure (i.e. backup, monitoring, storage etc.) along with a keen all-round interest in current cloud and on-premise ecosystems and relevant related technologies. You will use these skills to contribute to standardisation, optimisation, and innovation, working with others to help define and deliver standardisation within the business. Communication and collaboration is paramount in this role, you will work closely with a variety of internal and external business stakeholders and will be continually engaged and collaborating with our clients. What You Will Do Implement solutions that drive automation to help reduce time spent by support teams and in turn, free time to innovate and drive service improvement.? Where required,?provide technical support, and?take ownership of technical investigations into complex problems, continuing to work on them until a resolution or workaround can be implemented. Attend relevant customer specific meetings as and where required. Examples may include presenting changes to the change advisory board, providing technical feedback as part of a formal problem review and progress updates during project review meetings.? As an effective and highly capable team member , you will self-manage your workload and proactively pickup requests and other work through the ITSM tool. You will also need to be able to mentor and develop other engineers in the wider?technical?support teams.? Author new technical documentation for example for new solutions or changes in configuration required to adhere to updated security standards that is structured and relevant to the audience.? Ensure compliance to relevant standards (i.e.?ISO 27001, 9001) and security (i.e.?CIS, STIG) to help ensure we control, report and adequately measure and handle risks the business faces.? What You Will Have Experienced senior technical resource, highly motivated and capable of understanding and resolving complex technical problems.? Capability?to? problem solve ;?undertaking or designing tests to eliminate possible issues and working quickly and efficiently towards a solution. Excellent communication verbal and written, being able to operate at all levels and articulate messages to a variety of different audiences. Understand people and cultural differences to build good relationships with colleagues. Capability to author and update infrastructure, support and procedural documentation.? Keen willingness to? mentor others in the team and wider department?on technologies within your field of expertise.? Ability to? present concepts in an authoritative and clear manner through white boarding, presentations and proposals.? Understanding?of Incident, Problem and Change Management?within the? ITIL?framework . Technical experience in one or more of the following: Disaster?Recovery, Backup and Replication? Microsoft applications?and services? Enterprise storage (IBM, NetApp, Dell, HPE etc.) Enterprise monitoring and automation tools Virtualisation (VMware and/or Hyper-V) Scripting and reporting tools (PowerShell, Puppet, PowerBI, Excel etc.) What We Do For You Wellbeing focussed - Our people are our greatest assets, and ensuring everyone feels their best self to come to work is integral Generous Annual Leave - 25 days of annual leave, plus public holidays and the ability to buy additional days Employee Assistance Programme - Free advice, support, and confidential counselling available 24/7 through Care First Personal Growth - Regardless of where you are at in your career, we're committed to enabling your growth personally and professionally Development Programmes - From Future Managers to Leadership Training, our development programmes help you get where you need to go Profit Share - Our Group-wide bonus scheme enables you to reap the rewards of your success Financial wellbeing - We understand as well as your mental wellbeing, your financial wellbeing is really important Pension Scheme - Our plan with Scottish Widows offers 5% matched contribution by the company Income protection insurance - Providing you with support and assistance when you need it most Recognition - Highlighting and rewarding the great work our people do Values Awards - Our quarterly employee-driven initative to highlight and reward the people in the organisation who embody our values the most Clear Review - Our own technology platform that allows you to get real-time feedback, conversations and goals to help you become your best self Making a Difference - we provide opportunities to help our people make a difference to the causes they care about MatchIt! - Fundraise for a cause close to your heart and Advanced will match part of the funding Volunteering Time - Our volunteering leave scheme allows you to use your time to help those who need it Pennies from Heaven - donate the pennies from your pay check to help make a difference without lifting a finger Who We Are We are one the UK's largest tech companies, and our products sit at the heart of some of the country's best-known businesses. We've grown phenomenally quickly with a £275m turnover and 2,800 employees supporting over 25,000 customers. We hire for potential. We want to make sure we have the best people for the job and provide genuinely equal opportunities for our people to thrive. Our recruitment process is designed with inclusion and equity at its core.
Jun 01, 2023
Full time
Role Introduction The Senior Infrastructure Engineer will work as part of an operational squad to support our customers, ensuring all systems and related applications and infrastructure are managed and maintained to industry best practice and agreed standards. Key to success will be a close-knit tribal culture of customer centric service . The Senior Infrastructure Engineer plays a key part in the overall technical governance and leadership, technical excellence, and continual service improvement. You will be a technology specialist , capable of delivering expert skills and knowledge in a range of traditional hosted infrastructure (i.e. backup, monitoring, storage etc.) along with a keen all-round interest in current cloud and on-premise ecosystems and relevant related technologies. You will use these skills to contribute to standardisation, optimisation, and innovation, working with others to help define and deliver standardisation within the business. Communication and collaboration is paramount in this role, you will work closely with a variety of internal and external business stakeholders and will be continually engaged and collaborating with our clients. What You Will Do Implement solutions that drive automation to help reduce time spent by support teams and in turn, free time to innovate and drive service improvement.? Where required,?provide technical support, and?take ownership of technical investigations into complex problems, continuing to work on them until a resolution or workaround can be implemented. Attend relevant customer specific meetings as and where required. Examples may include presenting changes to the change advisory board, providing technical feedback as part of a formal problem review and progress updates during project review meetings.? As an effective and highly capable team member , you will self-manage your workload and proactively pickup requests and other work through the ITSM tool. You will also need to be able to mentor and develop other engineers in the wider?technical?support teams.? Author new technical documentation for example for new solutions or changes in configuration required to adhere to updated security standards that is structured and relevant to the audience.? Ensure compliance to relevant standards (i.e.?ISO 27001, 9001) and security (i.e.?CIS, STIG) to help ensure we control, report and adequately measure and handle risks the business faces.? What You Will Have Experienced senior technical resource, highly motivated and capable of understanding and resolving complex technical problems.? Capability?to? problem solve ;?undertaking or designing tests to eliminate possible issues and working quickly and efficiently towards a solution. Excellent communication verbal and written, being able to operate at all levels and articulate messages to a variety of different audiences. Understand people and cultural differences to build good relationships with colleagues. Capability to author and update infrastructure, support and procedural documentation.? Keen willingness to? mentor others in the team and wider department?on technologies within your field of expertise.? Ability to? present concepts in an authoritative and clear manner through white boarding, presentations and proposals.? Understanding?of Incident, Problem and Change Management?within the? ITIL?framework . Technical experience in one or more of the following: Disaster?Recovery, Backup and Replication? Microsoft applications?and services? Enterprise storage (IBM, NetApp, Dell, HPE etc.) Enterprise monitoring and automation tools Virtualisation (VMware and/or Hyper-V) Scripting and reporting tools (PowerShell, Puppet, PowerBI, Excel etc.) What We Do For You Wellbeing focussed - Our people are our greatest assets, and ensuring everyone feels their best self to come to work is integral Generous Annual Leave - 25 days of annual leave, plus public holidays and the ability to buy additional days Employee Assistance Programme - Free advice, support, and confidential counselling available 24/7 through Care First Personal Growth - Regardless of where you are at in your career, we're committed to enabling your growth personally and professionally Development Programmes - From Future Managers to Leadership Training, our development programmes help you get where you need to go Profit Share - Our Group-wide bonus scheme enables you to reap the rewards of your success Financial wellbeing - We understand as well as your mental wellbeing, your financial wellbeing is really important Pension Scheme - Our plan with Scottish Widows offers 5% matched contribution by the company Income protection insurance - Providing you with support and assistance when you need it most Recognition - Highlighting and rewarding the great work our people do Values Awards - Our quarterly employee-driven initative to highlight and reward the people in the organisation who embody our values the most Clear Review - Our own technology platform that allows you to get real-time feedback, conversations and goals to help you become your best self Making a Difference - we provide opportunities to help our people make a difference to the causes they care about MatchIt! - Fundraise for a cause close to your heart and Advanced will match part of the funding Volunteering Time - Our volunteering leave scheme allows you to use your time to help those who need it Pennies from Heaven - donate the pennies from your pay check to help make a difference without lifting a finger Who We Are We are one the UK's largest tech companies, and our products sit at the heart of some of the country's best-known businesses. We've grown phenomenally quickly with a £275m turnover and 2,800 employees supporting over 25,000 customers. We hire for potential. We want to make sure we have the best people for the job and provide genuinely equal opportunities for our people to thrive. Our recruitment process is designed with inclusion and equity at its core.
A charity who works with community organisations across the UK to help transform young people's lives through sport are looking for a Governance & Compliance Manager to assist the Director of Finance & Resources in developing, implementing, monitoring, and maintaining an appropriate and effective governance framework.About the role This is a full time (35 hours per week) permanent contract. The role offers a hybrid working system if based in the Manchester and can offer full remote working if located outside the region. You will be required to travel occasionally to attend meetings. (Committee meetings are a mixture of online and in person in London) The salary £45,000 per annum.As the Governance & Compliance Manager you will play an important role within the charity and will be responsible for managing a broad range of disciplines including corporate governance, risk management, information management and security, contracts management.You will organise in conjunction with the Chair, the Chief Executive and the Director of Finance & Resources, the annual programme of meetings of the Board and its Committees, ensuring appropriate preparation and agenda setting.You will also attend and act as Secretary to all Board and Committee meetings, including the Audit Committee, Finance Committee and Fundraising Committee and lead on the collation of papers for the meetings.About you Strong experience providing strategic and operational advice in matters relating to governance and compliance to senior internal stakeholders. Company secretariat experience Experience engaging with regulatory bodies, internal auditors, legal/professional advisor's. Sound knowledge of good governance principles in relation to charities Understands what it means to work to the highest standards of probity and conduct. Excellent organisation and planning capability, managing multiple cyclical priorities alongside longer-term projects.If you are interested in finding out more about this exciting opportunity, please get in touch now for a more detailed job description. We want you to have every opportunity to demonstrate your skills, ability and potential; please contact us if you require any assistance or adjustment so that we can help with making the application process work for you.
Jun 01, 2023
Full time
A charity who works with community organisations across the UK to help transform young people's lives through sport are looking for a Governance & Compliance Manager to assist the Director of Finance & Resources in developing, implementing, monitoring, and maintaining an appropriate and effective governance framework.About the role This is a full time (35 hours per week) permanent contract. The role offers a hybrid working system if based in the Manchester and can offer full remote working if located outside the region. You will be required to travel occasionally to attend meetings. (Committee meetings are a mixture of online and in person in London) The salary £45,000 per annum.As the Governance & Compliance Manager you will play an important role within the charity and will be responsible for managing a broad range of disciplines including corporate governance, risk management, information management and security, contracts management.You will organise in conjunction with the Chair, the Chief Executive and the Director of Finance & Resources, the annual programme of meetings of the Board and its Committees, ensuring appropriate preparation and agenda setting.You will also attend and act as Secretary to all Board and Committee meetings, including the Audit Committee, Finance Committee and Fundraising Committee and lead on the collation of papers for the meetings.About you Strong experience providing strategic and operational advice in matters relating to governance and compliance to senior internal stakeholders. Company secretariat experience Experience engaging with regulatory bodies, internal auditors, legal/professional advisor's. Sound knowledge of good governance principles in relation to charities Understands what it means to work to the highest standards of probity and conduct. Excellent organisation and planning capability, managing multiple cyclical priorities alongside longer-term projects.If you are interested in finding out more about this exciting opportunity, please get in touch now for a more detailed job description. We want you to have every opportunity to demonstrate your skills, ability and potential; please contact us if you require any assistance or adjustment so that we can help with making the application process work for you.
Senior Information Security Analyst Hybrid working Our client, a leading financial services organisation have an exciting opportunity for a Senior Information Security Analyst to join on a permanent basis. The Senior Information Security Specialist is primarily responsible for day-to-day security monitoring, response, reporting and the management of the security toolset. The role should ensure that the Bank is able to protect and respond to security incidents and manage threats appropriately. The Security Specialist is accountable for protecting all sensitive information within the company and ensuring all networks have adequate security to prevent unauthorised access. Role responsibilities: Develop and implement IT risk and information security strategy, policies, shared security services and action plans. Support the organisations overall regulatory commitments, providing appropriate operational security information, KPI/KRI and reporting. Identify and analyse risks, recommend appropriate mitigations, and document all components in clear, business intelligible language. Serve as a SME to senior management and the executive in the management, implementation and maintenance of cyber risk and security. Support the organisations adoption of Payment Card Industry Data Security Standard (PCI DSS), SWIFT compliance and alignment to an Information Security Standard such a ISO 27001/NIST and ensure effective implementation and monitoring of controls. Governance and management of 3rd party suppliers by performing supplier reviews and periodic due diligence, liaising with the business owners for remediation of any issues. Take an active role in both security incident investigation, as well as proactive investigation of security log data, the changing threats and vulnerabilities deemed important. Ensure completion of scheduled security checks on core systems including access control, functional system security and technical compliance, such as hardening standards. Engage with our external Security Operations Centre to support and manage event identification and incident response. Provide advice, guidance, and training, such as the provision of security awareness training and Phishing exercises. Manage associated governance of security services, by ensuring simple and clear documentation on standards, process and procedures is maintained to a good standard. Deputise for the IT Operations Manager on Information Security matters as and when required Skills required: Significant experience of developing and implementing risk and information security strategy, policies, shared security services and action plans. Microsoft 365 E5 Security Toolset, Data Loss Prevention, Conditional Access, IAM, Azure Services. Full understanding and experience of Payment Card Industry Data Security Standard (PCI DSS), SWIFT and Information Security Standards such as ISO 27001/NIST controls. Strong technical understanding of Unix/Linux and Microsoft environments Experience overseeing and managing third party relationships and proven track record of working with penetration testing partners, organizing pen-tests, and defining remediation SLAs. Maintain positive attitude and enthusiasm in challenging situations; motivate and partner with the business units to meet information security objectives. Ability and willingness to adopt a flexible approach to demands and challenges. Strong organisational and personal effectiveness skills, including time and project management. Excellent oral and written communication, facilitation skills and ability to present confidently and to engage, influence and manage stakeholders, developing effective relationships at all levels effectively. Senior Information Security Analyst Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
Jun 01, 2023
Full time
Senior Information Security Analyst Hybrid working Our client, a leading financial services organisation have an exciting opportunity for a Senior Information Security Analyst to join on a permanent basis. The Senior Information Security Specialist is primarily responsible for day-to-day security monitoring, response, reporting and the management of the security toolset. The role should ensure that the Bank is able to protect and respond to security incidents and manage threats appropriately. The Security Specialist is accountable for protecting all sensitive information within the company and ensuring all networks have adequate security to prevent unauthorised access. Role responsibilities: Develop and implement IT risk and information security strategy, policies, shared security services and action plans. Support the organisations overall regulatory commitments, providing appropriate operational security information, KPI/KRI and reporting. Identify and analyse risks, recommend appropriate mitigations, and document all components in clear, business intelligible language. Serve as a SME to senior management and the executive in the management, implementation and maintenance of cyber risk and security. Support the organisations adoption of Payment Card Industry Data Security Standard (PCI DSS), SWIFT compliance and alignment to an Information Security Standard such a ISO 27001/NIST and ensure effective implementation and monitoring of controls. Governance and management of 3rd party suppliers by performing supplier reviews and periodic due diligence, liaising with the business owners for remediation of any issues. Take an active role in both security incident investigation, as well as proactive investigation of security log data, the changing threats and vulnerabilities deemed important. Ensure completion of scheduled security checks on core systems including access control, functional system security and technical compliance, such as hardening standards. Engage with our external Security Operations Centre to support and manage event identification and incident response. Provide advice, guidance, and training, such as the provision of security awareness training and Phishing exercises. Manage associated governance of security services, by ensuring simple and clear documentation on standards, process and procedures is maintained to a good standard. Deputise for the IT Operations Manager on Information Security matters as and when required Skills required: Significant experience of developing and implementing risk and information security strategy, policies, shared security services and action plans. Microsoft 365 E5 Security Toolset, Data Loss Prevention, Conditional Access, IAM, Azure Services. Full understanding and experience of Payment Card Industry Data Security Standard (PCI DSS), SWIFT and Information Security Standards such as ISO 27001/NIST controls. Strong technical understanding of Unix/Linux and Microsoft environments Experience overseeing and managing third party relationships and proven track record of working with penetration testing partners, organizing pen-tests, and defining remediation SLAs. Maintain positive attitude and enthusiasm in challenging situations; motivate and partner with the business units to meet information security objectives. Ability and willingness to adopt a flexible approach to demands and challenges. Strong organisational and personal effectiveness skills, including time and project management. Excellent oral and written communication, facilitation skills and ability to present confidently and to engage, influence and manage stakeholders, developing effective relationships at all levels effectively. Senior Information Security Analyst Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
Summary Job Description for Application Operational Lead: There's never been a more exciting time to be part of the nuclear sector. New opportunities are being created all the time. At NNL, you'll be in the ideal place to capitalise on this momentum, face new challenges and develop a long, successful and meaningful career. We're an organisation that's here to experiment and push the limits of what's possible. So, if you're keen to excel in your chosen field, this is the place to do it. Because at NNL, anything is possible. The Applications Operational Lead is responsible for the maintenance and compliance of the NNL Application estate. They will lead the Application support team for doing/managing checks, patches, upgrades, and improvements, supporting roadmap planning to ensure the NNL Application estate is working well for business, aligned with governance and follow best industry practice. Main Responsibilities Main Responsibilities for Application Operational Lead: Responsible for the management and deployment of the Enterprise Applications strategy, lifecycle, upgrades and configuration changes in line with good industry practice and governance processes. Responsible for Hybrid, on Premise and Cloud Applications and Service with business and Supplier Support. Responsible for the line management of the Application Support Analyst team. Accountable for building and configuring applications as required or validating other's work. Responsible for troubleshooting and remediating problems within applications estate. Accountable for escalations from Application Support Analysts or Service Delivery Manager and engaging with senior IT stakeholders as appropriate for resolutions Responsible for prioritising workloads and resource management for the Application Support Analysts. Supporting other IT teams with developing new application designs, service transition and training. Responsible for Operational reporting around SLAs, Task Closure, Application status. Ideal Candidate Essential Criteria for Application Operational Lead: Experienced Applications Operational Analyst with team lead experience. Highly experienced in both On-premises and Cloud Services such as Office 365, SharePoint, Power Platform, Web Applications (IIS), P6, ERP. Experience of managing vendor relationships and holding Service reviews. Worked within an IT Support team, providing technical support of applications & its environments. Experience of Change Management and approval processes. Good working knowledge of PowerShell, PowerBI, Automation, Azure and M365 etc. Ability to learn and adapt quickly to new technologies and changing business requirements. Ability to obtain SC level security clearance (this includes but is not limited to identity, employment, financial and criminal record checks plus 5 years' worth of UK residency). Desirable Criteria for Application Operational Lead: Demonstrable experience in information technology sector. Self-motivated, proactive and customer focused with excellent communication and organisational skills. Experience of working in accredited / regulated environments and required documentation, with knowledge of balancing business benefit with technology risk. Experienced in complex business and application environments and interdependencies. Degree in information technology or engineering related subjects with relevant technology certification.
Jun 01, 2023
Full time
Summary Job Description for Application Operational Lead: There's never been a more exciting time to be part of the nuclear sector. New opportunities are being created all the time. At NNL, you'll be in the ideal place to capitalise on this momentum, face new challenges and develop a long, successful and meaningful career. We're an organisation that's here to experiment and push the limits of what's possible. So, if you're keen to excel in your chosen field, this is the place to do it. Because at NNL, anything is possible. The Applications Operational Lead is responsible for the maintenance and compliance of the NNL Application estate. They will lead the Application support team for doing/managing checks, patches, upgrades, and improvements, supporting roadmap planning to ensure the NNL Application estate is working well for business, aligned with governance and follow best industry practice. Main Responsibilities Main Responsibilities for Application Operational Lead: Responsible for the management and deployment of the Enterprise Applications strategy, lifecycle, upgrades and configuration changes in line with good industry practice and governance processes. Responsible for Hybrid, on Premise and Cloud Applications and Service with business and Supplier Support. Responsible for the line management of the Application Support Analyst team. Accountable for building and configuring applications as required or validating other's work. Responsible for troubleshooting and remediating problems within applications estate. Accountable for escalations from Application Support Analysts or Service Delivery Manager and engaging with senior IT stakeholders as appropriate for resolutions Responsible for prioritising workloads and resource management for the Application Support Analysts. Supporting other IT teams with developing new application designs, service transition and training. Responsible for Operational reporting around SLAs, Task Closure, Application status. Ideal Candidate Essential Criteria for Application Operational Lead: Experienced Applications Operational Analyst with team lead experience. Highly experienced in both On-premises and Cloud Services such as Office 365, SharePoint, Power Platform, Web Applications (IIS), P6, ERP. Experience of managing vendor relationships and holding Service reviews. Worked within an IT Support team, providing technical support of applications & its environments. Experience of Change Management and approval processes. Good working knowledge of PowerShell, PowerBI, Automation, Azure and M365 etc. Ability to learn and adapt quickly to new technologies and changing business requirements. Ability to obtain SC level security clearance (this includes but is not limited to identity, employment, financial and criminal record checks plus 5 years' worth of UK residency). Desirable Criteria for Application Operational Lead: Demonstrable experience in information technology sector. Self-motivated, proactive and customer focused with excellent communication and organisational skills. Experience of working in accredited / regulated environments and required documentation, with knowledge of balancing business benefit with technology risk. Experienced in complex business and application environments and interdependencies. Degree in information technology or engineering related subjects with relevant technology certification.
YellowBricks is hiring an experienced Information Security Analyst to join our client, a global organisation with centralised services. Within this role, our candidate will know ITIL and ISO 7001. This is a hybrid role where you will be expected in the Windsor, Berkshire office 3 days per week. In this job, you will coordinate internal and external IT Audits working with the Information Security Officer and other senior managers to ensure Information and Cyber Security is of highest priority within the IT division managing security and project tasks required by the wider business. Duties: Review and evidence and annual schedule of information security controls (ISO27001 & ICT) identifying and reporting on ineffective controls or control gaps. Responsible for conducting, reporting, and remediating monthly/quarterly access governance reviews. Manage a schedule of security testing and oversee remediation plans promptly. Collate and submit evidence for the Integrated Risk Management Framework on time to ensure compliance against specified controls. Monitoring, analysing, documenting, and resolving security breaches and vulnerability issues accurately and reporting these to the ISO. Assess and challenge security tasks for ServiceDesk requests to ensure they are fulfilled within SLA. Assist in delivering regular information security awareness training to maximize end-user awareness. Conduct supplier assurance and risk assessments as required. Act as an Information Security role model by ensuring awareness of responsibilities and by motivating others across the whole business to do the same. Manage the review and agreement of management responses to audit findings and create remediation plans. Produce audit reference documentation to facilitate common audit requests. Required knowledge & experience Experience in service management best practices e.g. ITIL Experience with Information and Cyber Security standards (ISO/IEC 27001 & 27002) Experience of Information and Cyber Security Administration Experience in IT Service Delivery operations, preferably within an enterprise environment. Understanding of Windows Active Directory and Azure AD, Windows Servers, IBM iSeries and application user management, access rights and roles. Ability to work in a structured and organised manner with excellent time management to produce reports meeting regular deadlines. Excellent written, and spoken communication skills Good analytical skills ITIL Foundation Certificate in Information Security Principles If you have the skills required and are able to commit to a hybrid role, apply now.
Jun 01, 2023
Full time
YellowBricks is hiring an experienced Information Security Analyst to join our client, a global organisation with centralised services. Within this role, our candidate will know ITIL and ISO 7001. This is a hybrid role where you will be expected in the Windsor, Berkshire office 3 days per week. In this job, you will coordinate internal and external IT Audits working with the Information Security Officer and other senior managers to ensure Information and Cyber Security is of highest priority within the IT division managing security and project tasks required by the wider business. Duties: Review and evidence and annual schedule of information security controls (ISO27001 & ICT) identifying and reporting on ineffective controls or control gaps. Responsible for conducting, reporting, and remediating monthly/quarterly access governance reviews. Manage a schedule of security testing and oversee remediation plans promptly. Collate and submit evidence for the Integrated Risk Management Framework on time to ensure compliance against specified controls. Monitoring, analysing, documenting, and resolving security breaches and vulnerability issues accurately and reporting these to the ISO. Assess and challenge security tasks for ServiceDesk requests to ensure they are fulfilled within SLA. Assist in delivering regular information security awareness training to maximize end-user awareness. Conduct supplier assurance and risk assessments as required. Act as an Information Security role model by ensuring awareness of responsibilities and by motivating others across the whole business to do the same. Manage the review and agreement of management responses to audit findings and create remediation plans. Produce audit reference documentation to facilitate common audit requests. Required knowledge & experience Experience in service management best practices e.g. ITIL Experience with Information and Cyber Security standards (ISO/IEC 27001 & 27002) Experience of Information and Cyber Security Administration Experience in IT Service Delivery operations, preferably within an enterprise environment. Understanding of Windows Active Directory and Azure AD, Windows Servers, IBM iSeries and application user management, access rights and roles. Ability to work in a structured and organised manner with excellent time management to produce reports meeting regular deadlines. Excellent written, and spoken communication skills Good analytical skills ITIL Foundation Certificate in Information Security Principles If you have the skills required and are able to commit to a hybrid role, apply now.
Role Description The role holder: The Application Architect is responsible for the overall design of an application, or several applications, ensuring that the application meets its functional and non-functional requirements. The individual would typically be an experienced software Engineer, expert in one or more development languages and is therefore able to set the direction of the design, development and methods used for a development team. The individual may work as part of a development or architecture team, depending upon project size, and is capable of managing a team of System Developers/Designers or Application Architects. They will be involved in aspects of estimation, planning and risk management, ensuring delivery to agreed timescales and quality standards. Application architects select and tailor the processes appropriate to govern the technical quality of applications development as it is executed. Typically architects will work with senior client stakeholders to understand, influence and shape requirements and solution approaches. They will deploy an excellent understanding of mainstream and emerging applications and providers with a flair for evangelism where they can apply innovative solutions involving both COTS and bespoke applications. Application Architects must deliver solutions with consideration of through-life operation such as operational support and management, integration, change and extension, migration and re-platforming, productisation, re-use, withdrawal/retirement and disposal. Key Accountabilities The role holder: The primary accountabilities of the Application Architect include: The design of an Application (the complete set of software components that make it) to ensure that it meets all functional and non-functional requirements. Overseeing the implementation of the application design in collaboration with other team members such as System and Software Designers, Data Architects, Security Architects and Functional Architects. The production of estimates, costs and delivery timescales at appropriate points in the development lifecycle The quality of the Application, with a particular focus upon the non-functional "ities" of the design including Security, Scalability, Reliability, Deployability Internal stakeholder management within the project (e.g. solution architects, implementation team lead, test team lead) Taking overall ownership of all application component(s); being known as subject-matter expert in all areas relating to application development design and implementation techniques, patterns and technology stacks. Working as part of a team of Architects (larger projects) or System Developers/Designers (smaller projects) and has responsibility for managing other members in these teams Acts as a Method Practitioner and Champion for application development methodologies Defines the project engineering approach on projects Supports the Solution Architect in producing estimates, costs and delivery timescales at appropriate points in the development lifecycle Develops and polices automated quality, test and continuous integration capabilities to ensure that the approaches and test strategies are followed and only high-quality, maintainable solutions are developed. Contributes to external and internal technology-related technical forums (e.g. Open Source communities, Practices and Professions, SIGs, Technical Forums) and demonstrates innovation and thought leadership Expertise in one or more software / vendor domains, for example: Web & XML (HTML5), WS/SOA/REST, Integration (MOM, Spring), Containers (OSGi, JEE, WebLogic), Persistence and databases (Hibernate, NoSQL, Oracle, MySQL), CEP, Networking (Caching, Load balancing) and deployment models (SaaS, Cloud, Virtualisation) Identifies and evaluates suitable application technologies, frameworks and application standards. Produce high-level and low-level designs for application components, employing formal design techniques such as modelling (UML), simulation and modelling where necessary Works with Functional Architects and Test Managers to ensure that requirements are suitable to be developed and tests are appropriate to verify them May be responsible for code reviews and code quality (depending on the governance of the particular project or engagement) May have limited responsibility for development of one or more software components (depending on the governance of the particular project or engagement) Depending on the particular job being performed, seniority and experience an architect may typically have a range of these specific accountabilities: Core Architecture - mid-level accountabilities Able to define / apply and enforce the usage of modern engineering best practices and automated application lifecycle management (ALM) approaches including Configuration Management (SCM, branching strategies, release strategies), Build and Dependency Management (Maven, Ivy), Continuous Integration (CI) and deployment, Automated testing (Unit, Functional, Integration, Performance and Acceptance) and quality reporting (code coverage, standards compliance, systems complexity / heuristics) Carries out / contributes to assurance and due diligence activities relating to products and suppliers. Understands and leverages existing BAE experience, IP and expertise in similar providing solutions - working with other client teams, market, product and proposition experts Helps define standards and patterns for the Software Development teams to use, reducing costs and increasing quality and re-uses BAE and industry standards where available Contributes to external and internal technology-related technical forums (e.g. Open Source communities, Practices and Professions, SIGs, Technical Forums) and demonstrates innovation and thought leadership Understands infrastructure and middleware technologies to a level that requirements can be specified to an Infrastructure Architect and decisions can be made as to the most appropriate platform for the Application Works with Service Architects to ensure the designed application meets the Supportability needs and can be transitioned easily into Live Service Core Architecture - top-level accountabilities Responsible for the design and control of very large or complex Applications. Works with suppliers and industry to influence design models for the development of new technology applications. Works with partners and 3rd parties to develop effective implementation and procurement strategies. Works proactively to determine ways in which the overall application estate can be improved in terms of its operational and cost performance. Pre-sales Works with Account Management and Sales functions to ensure that key sales messages for BAE solutions are accurately and authoritatively communicated within bids and pitches and to develop or qualify new opportunities Understands and leverages existing BAE experience, IP and expertise in similar providing similar solutions - working with other client teams, marketing, product and proposition experts to incorporate the reuse of solution elements from multiple service lines. Undertakes architecture activities for applications as part of response to RFI and RFP requests for clients Consults with clients to evolve early solutions Delivery/lifecycle management accountabilities Shepherds all architectural activity related to applications through the project development lifecycle paying particular care to ensure that all quality processes, gates and controls are followed. Sets standards for tools and techniques, advises on their application and ensures compliance. Takes technical responsibility for all stages in the architectural and engineering process. Prepares project and quality plans and advises systems development teams. Provides advice, guidance and assistance to less experienced colleagues as required. Team leadership Accountabilities Nurtures and guides the technical ability of lower grade Architects. Manages a team of architects in architectural activities Provides input into the performance reviews of development staff Provides career guidance to development staff Competencies Please refer to the Engineering Career Development Framework for a detailed description of the technical competencies required within your Capability area. This will include an outline of the required: Knowledge Skillls Qualifications Behaviours Information on the BAE Systems Company Behaviours is available here . For further insight into how BAE Systems Behaviours can be applied to each grade within Engineering please refer to the Engineering Career Development Framework The 3 key behaviours of focus for this role are: Courage Creativity Integrity
Jun 01, 2023
Full time
Role Description The role holder: The Application Architect is responsible for the overall design of an application, or several applications, ensuring that the application meets its functional and non-functional requirements. The individual would typically be an experienced software Engineer, expert in one or more development languages and is therefore able to set the direction of the design, development and methods used for a development team. The individual may work as part of a development or architecture team, depending upon project size, and is capable of managing a team of System Developers/Designers or Application Architects. They will be involved in aspects of estimation, planning and risk management, ensuring delivery to agreed timescales and quality standards. Application architects select and tailor the processes appropriate to govern the technical quality of applications development as it is executed. Typically architects will work with senior client stakeholders to understand, influence and shape requirements and solution approaches. They will deploy an excellent understanding of mainstream and emerging applications and providers with a flair for evangelism where they can apply innovative solutions involving both COTS and bespoke applications. Application Architects must deliver solutions with consideration of through-life operation such as operational support and management, integration, change and extension, migration and re-platforming, productisation, re-use, withdrawal/retirement and disposal. Key Accountabilities The role holder: The primary accountabilities of the Application Architect include: The design of an Application (the complete set of software components that make it) to ensure that it meets all functional and non-functional requirements. Overseeing the implementation of the application design in collaboration with other team members such as System and Software Designers, Data Architects, Security Architects and Functional Architects. The production of estimates, costs and delivery timescales at appropriate points in the development lifecycle The quality of the Application, with a particular focus upon the non-functional "ities" of the design including Security, Scalability, Reliability, Deployability Internal stakeholder management within the project (e.g. solution architects, implementation team lead, test team lead) Taking overall ownership of all application component(s); being known as subject-matter expert in all areas relating to application development design and implementation techniques, patterns and technology stacks. Working as part of a team of Architects (larger projects) or System Developers/Designers (smaller projects) and has responsibility for managing other members in these teams Acts as a Method Practitioner and Champion for application development methodologies Defines the project engineering approach on projects Supports the Solution Architect in producing estimates, costs and delivery timescales at appropriate points in the development lifecycle Develops and polices automated quality, test and continuous integration capabilities to ensure that the approaches and test strategies are followed and only high-quality, maintainable solutions are developed. Contributes to external and internal technology-related technical forums (e.g. Open Source communities, Practices and Professions, SIGs, Technical Forums) and demonstrates innovation and thought leadership Expertise in one or more software / vendor domains, for example: Web & XML (HTML5), WS/SOA/REST, Integration (MOM, Spring), Containers (OSGi, JEE, WebLogic), Persistence and databases (Hibernate, NoSQL, Oracle, MySQL), CEP, Networking (Caching, Load balancing) and deployment models (SaaS, Cloud, Virtualisation) Identifies and evaluates suitable application technologies, frameworks and application standards. Produce high-level and low-level designs for application components, employing formal design techniques such as modelling (UML), simulation and modelling where necessary Works with Functional Architects and Test Managers to ensure that requirements are suitable to be developed and tests are appropriate to verify them May be responsible for code reviews and code quality (depending on the governance of the particular project or engagement) May have limited responsibility for development of one or more software components (depending on the governance of the particular project or engagement) Depending on the particular job being performed, seniority and experience an architect may typically have a range of these specific accountabilities: Core Architecture - mid-level accountabilities Able to define / apply and enforce the usage of modern engineering best practices and automated application lifecycle management (ALM) approaches including Configuration Management (SCM, branching strategies, release strategies), Build and Dependency Management (Maven, Ivy), Continuous Integration (CI) and deployment, Automated testing (Unit, Functional, Integration, Performance and Acceptance) and quality reporting (code coverage, standards compliance, systems complexity / heuristics) Carries out / contributes to assurance and due diligence activities relating to products and suppliers. Understands and leverages existing BAE experience, IP and expertise in similar providing solutions - working with other client teams, market, product and proposition experts Helps define standards and patterns for the Software Development teams to use, reducing costs and increasing quality and re-uses BAE and industry standards where available Contributes to external and internal technology-related technical forums (e.g. Open Source communities, Practices and Professions, SIGs, Technical Forums) and demonstrates innovation and thought leadership Understands infrastructure and middleware technologies to a level that requirements can be specified to an Infrastructure Architect and decisions can be made as to the most appropriate platform for the Application Works with Service Architects to ensure the designed application meets the Supportability needs and can be transitioned easily into Live Service Core Architecture - top-level accountabilities Responsible for the design and control of very large or complex Applications. Works with suppliers and industry to influence design models for the development of new technology applications. Works with partners and 3rd parties to develop effective implementation and procurement strategies. Works proactively to determine ways in which the overall application estate can be improved in terms of its operational and cost performance. Pre-sales Works with Account Management and Sales functions to ensure that key sales messages for BAE solutions are accurately and authoritatively communicated within bids and pitches and to develop or qualify new opportunities Understands and leverages existing BAE experience, IP and expertise in similar providing similar solutions - working with other client teams, marketing, product and proposition experts to incorporate the reuse of solution elements from multiple service lines. Undertakes architecture activities for applications as part of response to RFI and RFP requests for clients Consults with clients to evolve early solutions Delivery/lifecycle management accountabilities Shepherds all architectural activity related to applications through the project development lifecycle paying particular care to ensure that all quality processes, gates and controls are followed. Sets standards for tools and techniques, advises on their application and ensures compliance. Takes technical responsibility for all stages in the architectural and engineering process. Prepares project and quality plans and advises systems development teams. Provides advice, guidance and assistance to less experienced colleagues as required. Team leadership Accountabilities Nurtures and guides the technical ability of lower grade Architects. Manages a team of architects in architectural activities Provides input into the performance reviews of development staff Provides career guidance to development staff Competencies Please refer to the Engineering Career Development Framework for a detailed description of the technical competencies required within your Capability area. This will include an outline of the required: Knowledge Skillls Qualifications Behaviours Information on the BAE Systems Company Behaviours is available here . For further insight into how BAE Systems Behaviours can be applied to each grade within Engineering please refer to the Engineering Career Development Framework The 3 key behaviours of focus for this role are: Courage Creativity Integrity
Cyber Security Compliance Associate Location: London, Hybrid Grade: 3B Salary: Competitive plus excellent benefits Contract type: Permanent Purpose of the role: The Post Office is undergoing a Retail and Technology transformation, one of the largest in Europe.As our technology platform is currently transitioning to Amazon Web Services the scope and breadth of our own technology is changing to further strengthen our internal capability. If you are passionate Cyber Compliance professional that thrives in a dynamic and change oriented environment, we would be keen to speak with you. Principle Accountabilities : As a Cyber Security Compliance Associate, you will be under the management of the Senior Cyber Security Compliance Manager. You will be supporting the maintenance of the Cyber Security Policy and standard suite as well as making sure the controls are in alignment with our GRC tools. In this role you be managing third party assurance. This will include conducting cyber security reviews on suppliers, contract reviews on existing and new third parties and providing security attestations to internal and external contacts when required. Therefore, a fundamental aspect of the role will be establishing cohesive and supportive relationships to be developed both within and outside of the team. The role will support the function to build a successful brand and be known as a 'go-to' team for all matters relating to information security compliance. Our people are the driving force behind our business, we are proud of the energy, commitment and customer focus we have in common. In addition to the competitive salary we offer, in return for your hard work, you will also receive: 25 days annual leave that increases with tenure. Up to 10% on target bonus opportunity Private healthcare Generous pension contribution Life assurance Income protection after 12 months service Qualifications, Experience & Skills: To be successful in this role, you will demonstrate a significant track record across the following Tech Stack: Maintain the Cyber Security Policy and Standard set to ensure that it is kept up to date and change control applied. These documents would also need to be uploaded to the intranet site and changes communicated both internally and to our suppliers. Manage changes in modifying the scope of the ISMS based on the business needs, providing our clients, partners, and suppliers' assurance of our security governance. Identify shortfalls within business processes and advise the business on the resolution along with the appropriate timescales. Conduct cyber risk assessments, both rapid and in depth, for third parties, depending of business needs. Lead and maintain the mitigation plans for the various third parties that ensures compliance to POL policies and standards. Conduct contract reviews for ongoing and new suppliers. Relationship management with leaders of other functions and business units. Manage and deliver the ongoing Security Awareness Campaign and defining value through metrics, both for the back office and within the branches. Support business areas in developing a positive security culture. Be visible to Post Office staff and stakeholders and regularly activities to build trust with people involved in security, demonstrate insight, knowledge and add value. Escalate issues to the Head of Cyber Security Compliance. Support supplier reviews and internal Post Office projects, which will feed into the supplier management framework to assess suppliers against a maturity scale. About Post Office: The Post Office has thrived at the heart of high streets and local communities across the UK for over 370 years. As one of the country's most trusted brands, we take our commitment to providing essential services to customers across the UK very seriously. We're the UK's largest retail network, as well as the largest financial services provider in the UK, with over 11,600 branches nationwide - more than all the UK's banks and building societies put together. We are working hard to ensure that the next chapter of the Post Office's history is a bright one. We are the current guardians of an iconic business, and we want to hand over a thriving network of branches which can continue to provide essential products and services for our customers for many years to come. This is a uniquely exciting and challenging time for the Post Office - we're shaping the future and creating a business we can all be proud of. The Post Office embraces diversity and inclusion in the workplace and actively promote working without discrimination. We are also a Disability Confident Employer and are committed to interviewing disabled people who meet our minimum criteria for the job.
Jun 01, 2023
Full time
Cyber Security Compliance Associate Location: London, Hybrid Grade: 3B Salary: Competitive plus excellent benefits Contract type: Permanent Purpose of the role: The Post Office is undergoing a Retail and Technology transformation, one of the largest in Europe.As our technology platform is currently transitioning to Amazon Web Services the scope and breadth of our own technology is changing to further strengthen our internal capability. If you are passionate Cyber Compliance professional that thrives in a dynamic and change oriented environment, we would be keen to speak with you. Principle Accountabilities : As a Cyber Security Compliance Associate, you will be under the management of the Senior Cyber Security Compliance Manager. You will be supporting the maintenance of the Cyber Security Policy and standard suite as well as making sure the controls are in alignment with our GRC tools. In this role you be managing third party assurance. This will include conducting cyber security reviews on suppliers, contract reviews on existing and new third parties and providing security attestations to internal and external contacts when required. Therefore, a fundamental aspect of the role will be establishing cohesive and supportive relationships to be developed both within and outside of the team. The role will support the function to build a successful brand and be known as a 'go-to' team for all matters relating to information security compliance. Our people are the driving force behind our business, we are proud of the energy, commitment and customer focus we have in common. In addition to the competitive salary we offer, in return for your hard work, you will also receive: 25 days annual leave that increases with tenure. Up to 10% on target bonus opportunity Private healthcare Generous pension contribution Life assurance Income protection after 12 months service Qualifications, Experience & Skills: To be successful in this role, you will demonstrate a significant track record across the following Tech Stack: Maintain the Cyber Security Policy and Standard set to ensure that it is kept up to date and change control applied. These documents would also need to be uploaded to the intranet site and changes communicated both internally and to our suppliers. Manage changes in modifying the scope of the ISMS based on the business needs, providing our clients, partners, and suppliers' assurance of our security governance. Identify shortfalls within business processes and advise the business on the resolution along with the appropriate timescales. Conduct cyber risk assessments, both rapid and in depth, for third parties, depending of business needs. Lead and maintain the mitigation plans for the various third parties that ensures compliance to POL policies and standards. Conduct contract reviews for ongoing and new suppliers. Relationship management with leaders of other functions and business units. Manage and deliver the ongoing Security Awareness Campaign and defining value through metrics, both for the back office and within the branches. Support business areas in developing a positive security culture. Be visible to Post Office staff and stakeholders and regularly activities to build trust with people involved in security, demonstrate insight, knowledge and add value. Escalate issues to the Head of Cyber Security Compliance. Support supplier reviews and internal Post Office projects, which will feed into the supplier management framework to assess suppliers against a maturity scale. About Post Office: The Post Office has thrived at the heart of high streets and local communities across the UK for over 370 years. As one of the country's most trusted brands, we take our commitment to providing essential services to customers across the UK very seriously. We're the UK's largest retail network, as well as the largest financial services provider in the UK, with over 11,600 branches nationwide - more than all the UK's banks and building societies put together. We are working hard to ensure that the next chapter of the Post Office's history is a bright one. We are the current guardians of an iconic business, and we want to hand over a thriving network of branches which can continue to provide essential products and services for our customers for many years to come. This is a uniquely exciting and challenging time for the Post Office - we're shaping the future and creating a business we can all be proud of. The Post Office embraces diversity and inclusion in the workplace and actively promote working without discrimination. We are also a Disability Confident Employer and are committed to interviewing disabled people who meet our minimum criteria for the job.
ABOUT THE ROLE The Society recognises that a key part of its cyber security defences is having a well-rounded and strategically focussed approach to Security Culture through People Cyber Risk Management (PCRM). This role will provide dedicated focus and expertise on organisational cyber culture change and supports the Senior Manager in all such activities. It is widely recognised within industry that people cyber risk management needs to be built as part of an organisation's culture and this role is key to helping embed these good behaviours and monitoring these. It also includes contributing to the PCRM Strategy and delivering intervention campaigns with associated industry technology tools. ABOUT YOU We are looking for someone who has direct experience of delivering security culture change and delivering a dramatic shift away from compliance driven behaviours towards a more rounded Embedded approach to people cyber risk management. You need to be able to deliver cultural change within an organisation and work independently and act as a subject matter expert on security culture issues. REQUIREMENTS: To be successful in this role you need to have: Experience of what good looks like in terms of security culture for a financial institution. Excellent communication skills and able to effectively communicate through to Senior Management and the Executive. Experience in planning and supporting the development of the PCRM capability. Effectively research and contribute to a PCRM Strategy covering the employee life cycle throughout their employment. Experience with industry technical tools and methods associated with security culture and deliver these throughout the organisation - this includes training Board members and NEDs. Experience in delivering cultural change in organisations and have demonstrable experience in this area. Be able to build strong relationships with relevant areas in IT and change functions and across the business areas to gain an understanding of their requirements and deliver within their context Experience of defining measurements for security culture campaign effectiveness. The skills to assess and challenge cultural barriers which may prohibit the success of a security culture campaign. Familiar with Scaled Agile ways of working YOUR KEY RESPONSIBILITIES . (Additional detailed performance objectives will be set by your manager) General Profile Contributes to, and communicates the PCRM policy, standards and guidelines and ensures security principles are understood and applied across the business. Drives adoption of and adherence to policies and standards through the provision of expert advice and guidance as well as intervention campaigns in order to ensure security risks are captured and communicated. Generates and drives forward on ample creative ideas to deliver engaging and exciting campaigns and events Identifies opportunities for PCRM to be effectively incorporated into business activities Acts as a focal point and core driver of all security culture activities for the Society. People & Relationships Acts as an exemplar in the security team for delivering cultural change within the organisation for security. Builds strong relationships with stakeholders at all levels. Engages with stakeholders externally to identify key areas of weakness within the organisation in terms of security culture and owns the actions to remediate those both tactically and strategically. Governance, Risk & Controls Contributes to developing the metric set for PCRM and the effectiveness of activities, and measures against these metrics Responsibility for the delivery of PCRM related controls and supporting campaigns within the organisation and the definition of those controls. Impact, Scale & Influence Works with business leaders to identify areas for improvement in their business units for security culture. Drives forward good security culture practices and interventions within the organisation. Responsible for preparing and where necessary delivering, robust, objective and accurate Senior Management and Executive papers. Challenges the organisational thinking in terms of its approach to security culture and behaviours. Decision Making/Problem Solving Drives a strategic approach to security culture through PCRM. Establishes and manages analytics methods, techniques and capabilities to enable the organisation to analyse data, to generate insights, create value and drive decision-making for information security risk. Contributes to the PCRM strategy and the drives delivery of the PCRM strategy and addresses issues accordingly. Identifies the ongoing commitments required by the organisation to build a sustainable security culture change commitment. Carbon60, Lorien & SRG - The Impellam Group STEM Portfolio are acting as an Employment Business in relation to this vacancy.
May 31, 2023
Full time
ABOUT THE ROLE The Society recognises that a key part of its cyber security defences is having a well-rounded and strategically focussed approach to Security Culture through People Cyber Risk Management (PCRM). This role will provide dedicated focus and expertise on organisational cyber culture change and supports the Senior Manager in all such activities. It is widely recognised within industry that people cyber risk management needs to be built as part of an organisation's culture and this role is key to helping embed these good behaviours and monitoring these. It also includes contributing to the PCRM Strategy and delivering intervention campaigns with associated industry technology tools. ABOUT YOU We are looking for someone who has direct experience of delivering security culture change and delivering a dramatic shift away from compliance driven behaviours towards a more rounded Embedded approach to people cyber risk management. You need to be able to deliver cultural change within an organisation and work independently and act as a subject matter expert on security culture issues. REQUIREMENTS: To be successful in this role you need to have: Experience of what good looks like in terms of security culture for a financial institution. Excellent communication skills and able to effectively communicate through to Senior Management and the Executive. Experience in planning and supporting the development of the PCRM capability. Effectively research and contribute to a PCRM Strategy covering the employee life cycle throughout their employment. Experience with industry technical tools and methods associated with security culture and deliver these throughout the organisation - this includes training Board members and NEDs. Experience in delivering cultural change in organisations and have demonstrable experience in this area. Be able to build strong relationships with relevant areas in IT and change functions and across the business areas to gain an understanding of their requirements and deliver within their context Experience of defining measurements for security culture campaign effectiveness. The skills to assess and challenge cultural barriers which may prohibit the success of a security culture campaign. Familiar with Scaled Agile ways of working YOUR KEY RESPONSIBILITIES . (Additional detailed performance objectives will be set by your manager) General Profile Contributes to, and communicates the PCRM policy, standards and guidelines and ensures security principles are understood and applied across the business. Drives adoption of and adherence to policies and standards through the provision of expert advice and guidance as well as intervention campaigns in order to ensure security risks are captured and communicated. Generates and drives forward on ample creative ideas to deliver engaging and exciting campaigns and events Identifies opportunities for PCRM to be effectively incorporated into business activities Acts as a focal point and core driver of all security culture activities for the Society. People & Relationships Acts as an exemplar in the security team for delivering cultural change within the organisation for security. Builds strong relationships with stakeholders at all levels. Engages with stakeholders externally to identify key areas of weakness within the organisation in terms of security culture and owns the actions to remediate those both tactically and strategically. Governance, Risk & Controls Contributes to developing the metric set for PCRM and the effectiveness of activities, and measures against these metrics Responsibility for the delivery of PCRM related controls and supporting campaigns within the organisation and the definition of those controls. Impact, Scale & Influence Works with business leaders to identify areas for improvement in their business units for security culture. Drives forward good security culture practices and interventions within the organisation. Responsible for preparing and where necessary delivering, robust, objective and accurate Senior Management and Executive papers. Challenges the organisational thinking in terms of its approach to security culture and behaviours. Decision Making/Problem Solving Drives a strategic approach to security culture through PCRM. Establishes and manages analytics methods, techniques and capabilities to enable the organisation to analyse data, to generate insights, create value and drive decision-making for information security risk. Contributes to the PCRM strategy and the drives delivery of the PCRM strategy and addresses issues accordingly. Identifies the ongoing commitments required by the organisation to build a sustainable security culture change commitment. Carbon60, Lorien & SRG - The Impellam Group STEM Portfolio are acting as an Employment Business in relation to this vacancy.
Key information
Location : Manchester, Bristol, Newcastle, Nottingham, or London Hours : 37.5 hours Start date : November 2022 (we are happy to work with you and your notice period) Duration : Permanent Salary: £41,000 - £47,000 per annum if located in Bristol, Manchester, Nottingham or Newcastle. £44,000 - £50,000 if based in London. In addition, all staff receive a £312 yearly tax-free WFH allowance. Application deadline : 5pm Friday 21st October
Early applications are encouraged, as we will assess applications and schedule interviews on an ongoing basis.
About upReach
Do you think that your socio-economic background should determine your career prospects?
upReach’s vision is of a society in which everybody has an equal opportunity to realise their full career potential. Our work is important because right now a student from a less advantaged background who gains a first-class degree from a top university is less likely to secure an elite job than a more privileged student with a 2.2.
We are an award-winning charity employer working to address this issue in partnership with employers and universities. We help young people from less advantaged backgrounds achieve their career potential by providing an intensive programme of support that addresses socio-economic barriers to graduate employment.
To find out more about how we support our students, visit our website and read our Annual Report , and Impact Report .
Role overview
upReach is seeking to hire a Head of Product . This is an exciting opportunity to lead our Products & Technology Team with a strategic view of the organisation's products to develop our impact as a charity. This role would suit individuals with substantial experience in product management, developing a team, a passion for social mobility and experience operating in a fast paced environment.
You will work closely with the Senior Technology and Data Manager to manage the workload and priorities of the team; delivering products and innovating income generation. The current suite of products include REALrating , Social Mobility Network , getEmployable and our Associate (what we call the undergraduates we support) CRM. You will manage the relationship with our technology development partner and their team of developers, ensuring that our project sprints and timelines are executed on and delivered to a high standard.
Our values
upReach upholds the following values:
Perseverance
Integrity
Advocacy
Aspiration
Proactivity
Skills
The ideal candidate for Head of Product will bring with them the following skills:
Problem solving and decision making
Attention to detail
Planning and organisation
Collaboration
Passion and motivation
Communication skills
Leadership
Experience
To be successful, you will have substantial experience within product management and building a product culture while growing a team. You will be proactive, resilient and used to managing competing priorities within a varied workload, with a willingness to perform varying duties depending on the shifting needs of the charity.
Experience in managing a product portfolio and delivering a coherent product strategy through collaboration with multiple teams, including awareness of software development and systems needs;
Experience in coaching and developing Product Managers (direct reports) to help them increase their impact and develop in their careers ;
Experience managing external supplier relationships as well as working with and influencing other varied stakeholders (internal and external);
Experience in overseeing a varied product portfolio, and driving growth across several product areas at once, either as an individual contributor or through direct reports;
Experience in setting KPIs for product portfolios and measuring progress against targets over time, course correcting where necessary;
Experience working in a fast-paced environment and working independently to find solutions to problems;
Experience in managing competing priorities whilst maintaining an exceptional eye for detail;
University degree in any discipline, or equivalent experience.
Desirable experience:
Experience working with multidisciplinary teams using Agile methodology
Project management qualifications or comparable experience;
Knowledge of GDPR legislation and regulations;
Familiarity with Trello, G Suite and Zoom video conferencing software.
Responsibilities
Over the first six months, you will contribute to upReach's mission, by leading the Product Team and collaborating with the partnership and strategy teams to maximise income by identifying, ideating, validating, and delivering products & their enhancements and business development opportunities of the role. Working in a team environment; you will be an inquisitive challenger that takes the initiative, and has a fixing mindset.
Core responsibilities include:
Drive product development leading a high performing team of Product Managers, through the ideation, technical development, scaling and launching of innovative products and features.
Build, manage, coach and develop a high performing, diverse and inclusive team of Product Managers to help them increase their impact and develop in their careers by establishing clear and measurable goals.
Creating and building a product culture in the organisation, designing the product development process and seeding this within the team
Work with the relevant members of the Senior Leadership Team to establish a shared vision for the organisation by building consensus on commercial product strategies, priorities and related KPIs, and establishing executable operating plans, identifying interdependencies & risks.
Guide Product Managers to understand upReach’s strategic and competitive position to deliver products that are recognized as best in the industry; including the integration of usability studies, research and market analysis into product requirements to enhance user satisfaction.
Define and analyse KPIs to measure impact and success of the products; and establish reporting processes to demonstrate progress against targets over time to facilitate decision making and course correct where required.
Manage multiple products and priorities, while maximising team and organisation efficiency and effectiveness in a constantly evolving environment by adapting to change and offering creative solutions.
Accountable for the day-to-day management and coordination of key technology supplier relationships (including our main technology development partner); includes coordination of multiple work streams, supplier governance, SLA and contract management and input into sourcing decisions.
Supporting Head of Finance and Operations / Senior Technology and Data Manager with Data Protection and cyber security measures, ensuring compliance and implementing measures to reduce risk associated with data protection, including managing the process for an annual tech audit to assess the effectiveness of data protection policies and measures in place.
Team Culture & Benefits
By joining the upReach team, you will be joining a team who are committed to supporting you in your career journey and fostering an inclusive culture.
We offer:
Flexible and hybrid working.
Statutory Holiday Entitlement of 25 days and bank holidays. This increases to 2 additional days after 2.5 years and then to 3 additional days after 5 years of working with us.
Birthday leave.
3% Pension Contribution.
Cycle-to-work scheme.
Monthly socials.
Dedication to Staff Wellbeing through our Employee Assistance Programme and Mental Health First Aid Training.
Personal Development Budget, activated after 6 months in the role.
The opportunity to participate in our fantastic staff networks:
Disability and Inclusion Network
Ethnic Minorities Network
Green Network
LGBTQ+ Network
Mindfulness Network
Ready to apply?
CLICK HERE TO APPLY
We are committed to making our recruitment process inclusive. All applications will be blind screened, and our job packs are available in Braille, large text or another format upon request. We can provide reasonable adjustments throughout our recruitment application process and on the job, and we'll always endeavour to be as accommodating as possible. If you have particular needs or requirements, please get in touch using recruitment@upReach.org.uk .
Applications close at 5pm 21st October. Early applications are encouraged as we will be scheduling interviews on an ongoing basis.
If you have any questions regarding the role please email us at recruitment@upReach.org.uk .
Sep 28, 2022
Full time
Key information
Location : Manchester, Bristol, Newcastle, Nottingham, or London Hours : 37.5 hours Start date : November 2022 (we are happy to work with you and your notice period) Duration : Permanent Salary: £41,000 - £47,000 per annum if located in Bristol, Manchester, Nottingham or Newcastle. £44,000 - £50,000 if based in London. In addition, all staff receive a £312 yearly tax-free WFH allowance. Application deadline : 5pm Friday 21st October
Early applications are encouraged, as we will assess applications and schedule interviews on an ongoing basis.
About upReach
Do you think that your socio-economic background should determine your career prospects?
upReach’s vision is of a society in which everybody has an equal opportunity to realise their full career potential. Our work is important because right now a student from a less advantaged background who gains a first-class degree from a top university is less likely to secure an elite job than a more privileged student with a 2.2.
We are an award-winning charity employer working to address this issue in partnership with employers and universities. We help young people from less advantaged backgrounds achieve their career potential by providing an intensive programme of support that addresses socio-economic barriers to graduate employment.
To find out more about how we support our students, visit our website and read our Annual Report , and Impact Report .
Role overview
upReach is seeking to hire a Head of Product . This is an exciting opportunity to lead our Products & Technology Team with a strategic view of the organisation's products to develop our impact as a charity. This role would suit individuals with substantial experience in product management, developing a team, a passion for social mobility and experience operating in a fast paced environment.
You will work closely with the Senior Technology and Data Manager to manage the workload and priorities of the team; delivering products and innovating income generation. The current suite of products include REALrating , Social Mobility Network , getEmployable and our Associate (what we call the undergraduates we support) CRM. You will manage the relationship with our technology development partner and their team of developers, ensuring that our project sprints and timelines are executed on and delivered to a high standard.
Our values
upReach upholds the following values:
Perseverance
Integrity
Advocacy
Aspiration
Proactivity
Skills
The ideal candidate for Head of Product will bring with them the following skills:
Problem solving and decision making
Attention to detail
Planning and organisation
Collaboration
Passion and motivation
Communication skills
Leadership
Experience
To be successful, you will have substantial experience within product management and building a product culture while growing a team. You will be proactive, resilient and used to managing competing priorities within a varied workload, with a willingness to perform varying duties depending on the shifting needs of the charity.
Experience in managing a product portfolio and delivering a coherent product strategy through collaboration with multiple teams, including awareness of software development and systems needs;
Experience in coaching and developing Product Managers (direct reports) to help them increase their impact and develop in their careers ;
Experience managing external supplier relationships as well as working with and influencing other varied stakeholders (internal and external);
Experience in overseeing a varied product portfolio, and driving growth across several product areas at once, either as an individual contributor or through direct reports;
Experience in setting KPIs for product portfolios and measuring progress against targets over time, course correcting where necessary;
Experience working in a fast-paced environment and working independently to find solutions to problems;
Experience in managing competing priorities whilst maintaining an exceptional eye for detail;
University degree in any discipline, or equivalent experience.
Desirable experience:
Experience working with multidisciplinary teams using Agile methodology
Project management qualifications or comparable experience;
Knowledge of GDPR legislation and regulations;
Familiarity with Trello, G Suite and Zoom video conferencing software.
Responsibilities
Over the first six months, you will contribute to upReach's mission, by leading the Product Team and collaborating with the partnership and strategy teams to maximise income by identifying, ideating, validating, and delivering products & their enhancements and business development opportunities of the role. Working in a team environment; you will be an inquisitive challenger that takes the initiative, and has a fixing mindset.
Core responsibilities include:
Drive product development leading a high performing team of Product Managers, through the ideation, technical development, scaling and launching of innovative products and features.
Build, manage, coach and develop a high performing, diverse and inclusive team of Product Managers to help them increase their impact and develop in their careers by establishing clear and measurable goals.
Creating and building a product culture in the organisation, designing the product development process and seeding this within the team
Work with the relevant members of the Senior Leadership Team to establish a shared vision for the organisation by building consensus on commercial product strategies, priorities and related KPIs, and establishing executable operating plans, identifying interdependencies & risks.
Guide Product Managers to understand upReach’s strategic and competitive position to deliver products that are recognized as best in the industry; including the integration of usability studies, research and market analysis into product requirements to enhance user satisfaction.
Define and analyse KPIs to measure impact and success of the products; and establish reporting processes to demonstrate progress against targets over time to facilitate decision making and course correct where required.
Manage multiple products and priorities, while maximising team and organisation efficiency and effectiveness in a constantly evolving environment by adapting to change and offering creative solutions.
Accountable for the day-to-day management and coordination of key technology supplier relationships (including our main technology development partner); includes coordination of multiple work streams, supplier governance, SLA and contract management and input into sourcing decisions.
Supporting Head of Finance and Operations / Senior Technology and Data Manager with Data Protection and cyber security measures, ensuring compliance and implementing measures to reduce risk associated with data protection, including managing the process for an annual tech audit to assess the effectiveness of data protection policies and measures in place.
Team Culture & Benefits
By joining the upReach team, you will be joining a team who are committed to supporting you in your career journey and fostering an inclusive culture.
We offer:
Flexible and hybrid working.
Statutory Holiday Entitlement of 25 days and bank holidays. This increases to 2 additional days after 2.5 years and then to 3 additional days after 5 years of working with us.
Birthday leave.
3% Pension Contribution.
Cycle-to-work scheme.
Monthly socials.
Dedication to Staff Wellbeing through our Employee Assistance Programme and Mental Health First Aid Training.
Personal Development Budget, activated after 6 months in the role.
The opportunity to participate in our fantastic staff networks:
Disability and Inclusion Network
Ethnic Minorities Network
Green Network
LGBTQ+ Network
Mindfulness Network
Ready to apply?
CLICK HERE TO APPLY
We are committed to making our recruitment process inclusive. All applications will be blind screened, and our job packs are available in Braille, large text or another format upon request. We can provide reasonable adjustments throughout our recruitment application process and on the job, and we'll always endeavour to be as accommodating as possible. If you have particular needs or requirements, please get in touch using recruitment@upReach.org.uk .
Applications close at 5pm 21st October. Early applications are encouraged as we will be scheduling interviews on an ongoing basis.
If you have any questions regarding the role please email us at recruitment@upReach.org.uk .