IT Contractors UK Profile

Bobster Falvey

Senior Business Analyst | Technical Author | GRC, Regulatory Change & Operational Resilience Available

Verified email Founding Contractor · 2026

Contractor snapshot

Primary specialism Cyber Security
Location / working location London
Current availability Available now Confirmed 11 Aug 2026
Profile status Active contractor profile

Professional profile

I work at LOUD & Clear Consultancy as a Senior Business Analyst, Technical Author and GRC Consultant with 20+ years’ experience delivering regulatory, technology and operating-model change across financial services, energy, utilities and other regulated sectors. I translate complex business, technical and regulatory requirements into clear, practical controls, processes, policies, target operating models and implementation documentation. My expertise covers regulatory change, operational resilience, business continuity, cybersecurity governance, third-party risk, data governance and risk-and-control frameworks, including DORA, Basel, MiFID/MiFIR, EMIR, SFTR, CSDR, SOX and FCA/PRA requirements. I am experienced in BPMN process modelling, requirements elicitation, stakeholder workshops, gap analysis, systems integration, migration readiness and go-live support. I also support responsible AI and AI governance, with knowledge of ISO/IEC 42001, ISO 22989, the EU AI Act and NIST AI RMF. I help organisations establish proportionate governance, human oversight, accountability and control frameworks for AI-enabled services.

Core skills

Business Analysis; GRC and Regulatory Change; AI Governance; ISO27001 Information Security Management System ISO 32001

What I’m looking for next

Target roles: Business Analyst; Technical Author; GRC and Cybersecurity Consultant; Business C
As a Business Analyst, Technical Author, and Bid Manager, I help regulated organisations turn cyber, resilience and AI-governance requirements into practical controls, operating models and audit-ready documentation. I enjoy working in structured but complex environments like financial services to help bring order to uncertainty, working with specialists (SMEs) to detect gaps in requirements and delivery then deliver the processes, documentation, KPIs, and projects to allow people to use, govern, and support the business overall.

Contract preferences

Working preferenceRemote · Hybrid · On-site
Will workLondon, the rest of the UK and Europe (for Outside IR35 roles)
IR35 preferenceOutside IR35 · Inside IR35
Active clearanceBPSS
SeniorityFlexible / depends on role
Contract lengthAny contract length
IT experience25 years
Contracting experience25 years
Available from11 Aug 2026

Relevant work experience

Cybersecurity & Risk Governance • Mambu (Dutch FinTech): Worked on Third-Party Risk and Digital Operational Resilience Act whitepapers outlining how t • Syensqo (Belgian Chemical Co.): Authored cybersecurity, AI governance and BCM controls, mapping requirements to ISO 27001/42001, NIS2, NIST CSF, TISAX to support internal audit and GRC oversight and certification • Omnicom (2022): Produced NIST and ISO 27001:2022 compliant GRC documentation, including cyber risk classification (MITRE ATT&CK) and RAID logs, plus global cyber policy style guides. • Rapier Communications (2021): Wrote risk, cybersecurity and ESG policies for an ISO 27001 submission. Identity, Access & Cloud Security • European Central Bank (2020): Led an Oracle IDAM migration and IT/cloud security project, defining IGA requirements, user journeys, onboarding documentation and User Access Reviews, alongside third-party user management controls and SCA/MFA alignment to PSD2/SWIFT. • TP ICAP (2018–2020): Implemented Riskonnect for risk/control assessment and authored access management, data mapping and governance documentation supporting M&A onboarding and CFTC resubmission. • Tullett Prebon (2013–14): SEF registration. Mapped global trading systems architecture (front-to-back office) to assess legacy risk and dependencies, supporting an on-prem to cloud migration. IT Risk, Resilience & Business Continuity • ING Belgium (2017): Delivered an IT risk and security audit for ING's new Brussels SOC, reducing IT risk by 10%, reviewing SOX, GDPR, ISO 17799 and ISO 22301 (BCP/DR) controls, and produced TOMs and L1–3 Escalations procedures. • Illumina (2022): Contributed to the NHS Our Future Health bid national gene database. GDS-compliant APIs, cloud infrastructure, data protection and access model.

Experience & credentials

Certifications, sector experience and security clearance are self-declared unless specifically marked as independently verified by IT Contractors UK.

Sector experience

Financial Services · IT · Bids and Tenders

Certifications

B. App Science in Information Management · Grad Diploma of Education (IT · Science · English) · PRINCE2 Foundation · PRINCE2 Practitioner (lapsed) · AI Content Production · Magazine Writing - Editing - and Production · Small Business Management · Advanced AI Prompting · Advanced AI Prompting for Visual Impact · Advanced Bid Skills

Professional links

Contact details are controlled by the contractor and are not displayed automatically. Profile information is self-declared unless explicitly marked as verified.

All content © 2013–2026 IT Contractors UK. All rights reserved. Unauthorised use, reproduction, or distribution of any material is strictly prohibited.