Be at the heart of actionFly remote-controlled drones into enemy territory to gather vital information.

Apply Now

Senior InfoSec Advisor (IRM Manager)

Aberdeen
1 day ago
Create job alert

We have a current opportunity for a Senior InfoSec Advisor (IRM Manager) on a 12 month PAYE contract basis. The position will be based in Aberdeen and will have a 3/2 hybrid working pattern  

Key ResponsibilitiesRisk Assessment & Secure by Design

Perform structured IT and information security risk assessments and threat modelling for new IT platforms, systems, and applications and for material changes.
Provide security architecture advice (patterns, guardrails) aligned to NIST CSF / ISO 27001 and company standards.
Define and agree control selection (prevent/detect/correct) proportionate to risk, including identity, data and platform controls.
Conduct IT control walkthroughs to validate design and operating effectiveness; document evidence and issues.LOD2 Assurance & Critical Assets

Own the LOD2 assurance plan with specific focus on critical assets and safety-related systems; define test scopes, frequency and metrics.
Track high-risk deviations and risk acceptances; drive remediation and report residual risk to the CISO, CIO and business risk owners.OT / ICS Security

Own the LOD2 assurance plan across OT sites against the OT security standard, deciding the order and frequency of assessments aligned to risk and risk appetite.
Provide OT security advisory in relation to OT security standards alignment across all OT sites, advocating for segmentation, zoning, secure remote access, security monitoring and patching controls in line with ISA/IEC 62443.Supplier & Third-Party Assurance (with Procurement)

Run supplier assurance in collaboration Procurement including, pre contract due diligence, control reviews, and ongoing attestation for Suppliers and Third Parties.
Collaborate with Legal to ensure that contractual SLAs/KPIs include security requirements and be involved in remediation where gaps exist.Reporting & Governance

Maintain risk registers, control libraries and test plans; provide CIO-ready reporting on issues and residual risk.
Coordinate with the Business and 1st Line risk owners, as well as with the Assurance parties such as Internal Audit (LOD3) and the major IT and SOC managed service providers to close control gaps, and feed lessons learnt into standards and patterns.Role Dimensions
Organisation-wide information security remit across corporate IT and OT; frequent engagement with IT Operations, OT Engineering, HSSE, Finance, Procurement and Legal.
Direct influence on risk mitigation options and plans, acting as a trusted advisor.
Mix of advisory, oversight and hands-on walkthroughs; pragmatic, proportionate risk approach.Role Requirements
7+ years in information risk, security assurance or IT audit within regulated, safety-critical or industrial environments (energy/oil & gas preferred).
Strong knowledge of NIST CSF, ISO 27001, UK GDPR and supplier assurance practices; familiarity with the UK CAF is desirable.
Proven experience running compliance and assurance functions, Secure-by-Design reviews, and control testing (for design & operating effectiveness).
Solid grasp of OT/ICS risk and understanding of SCADA/PI/EC interfaces.
Skilled at stakeholder management and risk communication to senior audiences (clear, concise, business-outcome focused).
Tooling familiarity: GRC/IRM platforms (e.g., ServiceNow), and common cloud services (M365/Azure) for workflows and evidence capture.
Advantageous Certifications:
Governance & Audit: ISO 27001 Lead Auditor, CISM
Architecture & Design: SABSA, CISSP
OT/ICS: SANS GICSP, ISA/IEC 62443

Our role in supporting diversity and inclusion
As an international workforce business, we are committed to sourcing personnel that reflects the diversity and values of our client base but also that of Orion Group. We welcome the wide range of experiences and viewpoints that potential workers bring to our business and our clients, including those based on nationality, gender, culture, educational and professional backgrounds, race, ethnicity, sexual orientation, gender identity and expression, disability, and age differences, job classification and religion. In our inclusive workplace, regardless of your employment status as staff or contract, everyone is assured the right of equitable, fair and respectful treatment

Related Jobs

View all jobs

Penetration Tester

Penetration Tester

Information Security Analyst

Senior Reward and Payroll Specialist

Senior Operating System Performance Expert

Senior Mission Systems Engineer (Onboard Computing)

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Cyber Security Recruitment Trends 2025 (UK): What Job Seekers Must Know About Today’s Hiring Process

Summary: UK cyber security hiring has shifted from title‑led CV screens to capability‑driven assessments that emphasise incident readiness, cloud & identity security, detection engineering, governance/risk/compliance (GRC), measurable MTTR/coverage gains & secure‑by‑default engineering. This guide explains what’s changed, what to expect in interviews, & how to prepare—especially for SOC analysts, detection engineers, blue/purple teamers, penetration testers, cloud security engineers, DFIR, AppSec, GRC & security architecture. Who this is for: SOC & detection engineers, security operations leads, DFIR analysts, penetration testers/red teamers, purple teamers, AppSec/DevSecOps engineers, security architects, cloud security engineers, identity/IAM engineers, vulnerability managers, GRC/compliance specialists, product security & security programme managers targeting roles in the UK.

Why Cyber Security Careers in the UK Are Becoming More Multidisciplinary

Cyber security used to be viewed primarily as a technical discipline: firewalls, encryption, intrusion detection, penetration testing. In the UK today, it’s far broader. Organisations now face complex legal frameworks, ethical dilemmas, human-behaviour risks, communication challenges & usability hurdles. This shift means cyber security careers are becoming more multidisciplinary. From protecting NHS patient records to defending financial services, securing supply chains & safeguarding national infrastructure, cyber security now touches every sector. Employers increasingly want professionals who understand law, ethics, psychology, linguistics & design alongside traditional technical skills. In this article, we’ll explore why UK cyber security careers are expanding in this way, how these five disciplines shape the profession, and what job-seekers & employers need to know to thrive in this new landscape.

Cyber Security Team Structures Explained: Who Does What in a Modern Cyber Security Department

Cyber security has become a top priority for UK organisations of all sizes. From small businesses to financial institutions, healthcare providers, and government bodies, the risk of cyber attack is now a constant concern. Threats are more sophisticated, regulations more demanding, and customers more aware of data privacy than ever before. But defending against cyber threats isn’t simply about having the right tools — it’s about having the right team. A modern cyber security department relies on clearly defined roles and responsibilities to ensure that defences are proactive, incidents are managed swiftly, and compliance is maintained. This article explains the structure of a modern cyber security team, the roles you’ll typically find within it, how they collaborate, and what skills, qualifications, and salaries are expected in the UK job market.