IT Risk Advisor

Orion
Aberdeen, City Of Aberdeen, United Kingdom
4 days ago
Job Type
Contract
Seniority
Mid
Education
Degree
Posted
26 May 2026 (4 days ago)

Benefits

38 days paid holiday Onsite car parking

Our Oil & Gas Operator client is currently recruiting for the position of IT Risk Advisor based in Aberdeen

3/2 hybrid working

Onsite Car Parking

38 days per annum paid holiday

Role overview

An IT Risk Assessment advisor that specialises in Technical Security Architecture ‘by design’ to provide technical security oversight and architectural assurance across both delivery projects and business as usual (BAU) operations.

The role sits at the heart of the company’s technology governance, ensuring secure design decisions, controlled change, and proportionate risk treatment across cloud, on premises, and hybrid environments.

You will work closely with architects, engineers, delivery teams, and operations to keep security embedded without slowing the business.

Security architecture governance and interface with enterprise architecture:

Define and maintain security architecture patterns, reference designs, and secure configuration baselines (cloud and on-prem)

Drive awareness of secure-by-design practices across engineering teams.

Attend and contribute to the Architecture Review Board (ARB)

Maintain and evolve security architecture patterns and standards (e.g. IAM, network segmentation, cloud security baselines)

Review and assess high risk security architecture exceptions, ensuring risks are clearly understood and appropriately managed

Provide technical and specialised ‘Secure by design’ and security architecture project advisory:

Provide hands-on security architecture advice to delivery teams to ensure secure patterns, reference architectures, and hardening baselines are applied.

Perform threat-informed design reviews and ensure appropriate control selection

Enable early engagement to reduce downstream risk and rework

Change and Operational security oversight (BAU):

Attend Change Advisory Boards (CABs) to provide security approval and challenge

Review and approve high risk firewall rule changes

Review high risk configuration changes across Azure and on prem environments. Perform targeted reviews of high-risk configurations (e.g. firewall, network, cloud, infrastructure). Identify misconfigurations and exposure risks against defined baselines

Risk prioritise high risk and zero-day vulnerabilities, working with technology and operations teams on remediation approach and urgency

Provide pragmatic security input to IT Teams and Infrastructure Suppliers - aligned to operational and availability requirements

Provide BAU IT teams clear, actionable recommendations to reduce attack surface and improve resilience

Skills, experience & attributes of candidate:

Strong background in technical security architecture within complex enterprise environments

Experience across cloud (Azure) and on prem infrastructure

Comfortable operating in governance forums while remaining technically credible

Confident challenging design and change decisions constructively

Able to translate technical security risk into clear business impact

Advantageous:

Bachelor’s in CS, InfoSec, or equivalent experience

Certifications: GICSP, CISSP, or equivalent qualification

Experience working as a security architect

Understanding of regulatory frameworks e.g. NIS2, Cyber Resilience Act

Contract position

If you feel that you are well suited to the above opportunity and would like to find out more then please contact Orion Group for more information or apply by forwarding your current CV quoting reference: TR/(phone number removed)

People are our business worldwide

Orion Group was founded in 1987 and is now one of the largest, independent, international recruitment companies. We have a network of 200 employees working from 24 offices, delivering a range of services – Talent Acquisition, Recruitment Outsourcing Services, Retained Search, Global Workforce Solutions, Completions & Commissioning and Materials Management – across 68 countries. As a global leader in workforce solutions, we recruit personnel across the Engineering & Technical, Office & Commercial, Scientific and Skilled Trades disciplines, for sectors including Oil & Gas, Life Science, Power & Utilities, Constructions & Infrastructure, Manufacturing and Renewables

Related Jobs

View all jobs

Security Architect

CBSbutler Holdings Limited trading as CBSbutler London, United Kingdom
£450 – £515 pd Remote Clearance Required

Principal Architect - SecOps

Palo Alto Networks London, United Kingdom
Hybrid

Principal Architect - NetSec

Palo Alto Networks London, United Kingdom

IT Infrastructure Engineer

New Resource Group Bridgwater, Somerset, United Kingdom
£39,000 – £50,000 pa On-site

Senior Penetration Tester

VIQU IT Horsham, West Sussex, United Kingdom
£70,000 – £80,000 pa Hybrid

Technology Governance Lead - GRC

Intec Select London, City And County Of the City Of London, United Kingdom
£65,000 – £80,000 pa Hybrid

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cyber Security Jobs in the UK (2026 Guide)

Where to advertise cyber security jobs UK in 2026: the specialist boards, communities and channels that reach offensive, defensive and GRC security talent. The candidate pool is small, heavily vetted and in high demand across government, financial services, critical national infrastructure and the private sector simultaneously. Many of the strongest candidates hold active security clearances, are not actively job-searching through general platforms, and move primarily through specialist networks and trusted referrals. General job boards reach a broad audience but lack the specificity that security professionals expect. Specialist platforms, government-affiliated channels and cleared candidate networks each serve a different part of the market. This guide, published by CybersecurityJobs.tech, covers where to advertise cyber security roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Cyber Security Jobs UK 2026: What to Expect Over the Next 3 Years

Cyber Security Jobs UK 2026: roles, salaries and the threat intelligence, cloud security and zero-trust hiring trends shaping UK cyber careers. Cyber security is one of the few sectors where demand for talent has never once dipped. Every major technological shift of the past decade — cloud migration, remote working, AI adoption, the proliferation of connected devices — has expanded the attack surface that security professionals are expected to defend. And every expansion of that attack surface has generated more jobs. But the cyber security jobs market of 2026 is not simply a larger version of what it was three years ago. It is a structurally different market. The threats have evolved, the technologies used to combat them have changed, the regulatory environment has tightened considerably, and the roles being created reflect all of that. A job seeker who understands only the cyber security landscape of 2023 is already working with an outdated map. The candidates who will thrive over the next three years are those who understand where the sector is heading — which specialisms are attracting the most investment, which technologies are reshaping defensive and offensive security practice, and how the definition of a cyber security professional is broadening well beyond the traditional image of a network defender in a SOC. This article breaks down what the UK cyber security jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve.