Bobster Falvey-Bid Manager
Experience
Bid Manager
Confidential
- Bid Manager for 33kV/ (HV) DNO RFP.
- Connecting critical sites like data centres to the grid, BESS, LNG, & renewables.
Mambu
- Researched and wrote whitepaper responses to the EU’s Digital Op Resilience Act (DORA) demonstrating internal IT and risk controls & self-assessment (RCSA).
- Addressed FCA PS21/3 (Op resilience), TLTP, and governance and third-party risk management (TPRM) for Cloud (AWS, GCP, and Azure) Kubernetes container and security infrastructure, components and environments (e.g., Dev., Test, Production).
Syensqo
- Wrote OT/IT Resilience, Cybersecurity, AI Governance IT Controls.
- Mapped controls to ISO27001/2, NIS2 (CyFUN), NIST CSF, TISAX, and EU AI Reg and Operational RMF.
- Produced policies supporting internal audits, risk, compliance, and GRC oversight.
Traded Risk (Basel III) FinReg
HSBC
- FRTB IMA/CVA implementation and regulatory submission to the PRA (supporting MAS, HKMA, EBA submission) under Basel III (implemented through the EU’s CRR – 575/2013) around liquidity, stress testing, and risk.
- AI Ambassador programme.
Illumina
- NHS ‘Our Future Health’ bid for national gene database and genetic research programme.
- Focus was on Government Digital Services (GDS)-compliant RESTful API, systems / test environment, cloud infra, data protection, payment (PSD2), and access model.
Omnicom
- Wrote NIST & ISO27001:2022 compliant GRC security policies covering Cybersecurity risk management, Classification (Mitre ATT&CK), IT security, PAM, IDAM, Risk, Assumptions, Issues, and Dependencies (RAID) policies defining ownership and controls.
PES-4 TA / Data Scientist
HSBC
- Worked on a financial crime risk mitigation project.
- Created governance and project docs for crime detection modelling and a global code rollout (test phase).
- Design and UI for Confluence and SharePoint (SP) sites.
Rapier Communications
- Developed Security Requirement mapping.
- Wrote and implemented risk, cybersecurity, and ESG policies for ISO27001.
- Produced process and data flow mapping.
- Conducted gap analysis for Azure Cloud Security (IDAM, encryption, etc.) for Marketing API.
European Central Bank (ECB)
- Successful IDAM Oracle migration & IT/Cloud Security project including mapping user journeys, and writing use case and on-boarding documentation.
- User Access Review (UAR) to support EU accessibility requirements.
- Built Confluence & SP sites for internal users and did UX/UI for external of API.
- Wrote third-party user management (3UM) controls, requirements & SLAs for third-party compliance.
- Investigative phase of the digital Euro (pros & cons of Central Bank Digital Currencies).
- Improved understanding of global secure payment regulations (e.g. EU PSD2, SWIFT/ISO 20022) to ensure alignment with SCA and MFA requirements.
Bid & UX Consultant
Olive Jar
- Gov Digital Services (GDS) ‘Data Engineering Capability Build’ (Cloud Security) bid for the Dept. for Ed.
TP ICAP
- Delivered IT and fintech regulatory risk implementation of Riskonnect RMS to assess current and potential future exposure, mitigation and control effectiveness in line with ISO 31000 and controls to support Audit & Compliance.
- Wrote Standards, Policies, Procedures, Processes, and High- & Low-Level Design.
- Created DMS/KMS and supported CFTC resubmission.
- Advised on Financial Reg compliance, Change Management & SDLC.
- Wrote Operation guidelines and processes for On-boarding (AML / KYC), ERP/SAP, CI/CD dev, Payments, Access Management, Operational Data Market Information, and Data mapping (reference data, jurisdiction, input schema) & Governance.
- Developed Trading platform, Clearing, and Settlements guides, and Transactional Reporting (e.g., MiFID II, Basel, CSDR).
- OTC Front Office API ‘change of use’ submission to the US’s CFTC.
TA / BA
Walk & Win
- White paper on an App combining Blockchain with smartphone technologies, e.g. Augmented Reality, Geolocation, and Token Wallet to support marketing campaigns and understand customer usage and experience.
ING
- IT Risk and Security audit for ING’s new SOC in Brussels, reducing IT risk within appetite by 10% (2.8 to 2.4).
- Reviewed SOX, GDPR, and data protection controls (ISO17799), business continuity (ISO22301 DR/BCP), and regulatory reporting.
- Delivered TOM/BPMN models, and L1–3 escalation procedures.
- Authored hardware, software, middleware BIA/CIA docs (e.g. Wolters Kluwer, $Universe, AD, Apache, AWS) ITSM, operational security, SOD, & SharePoint guides.
- Supported business change & CI/CD hardening.
TA
ARRIS
- Captured As-Is/To-Be processes to write User Manual / QA playbooks (Design/Build/Test) to integrate Cisco’s converged broadband router (cBR-8) server (cabling/electrical diagrams) rollout to support data, broadband and telephony across their network hubs.
SC Bid Writer
BAE Systems / Serco
- JV for MoD Engineering, F&M of RAF bases.
- Servicing of BAe146 aircraft at Northolt.
Bid Writer
Amec Foster Wheeler
- Dounreay nuclear power plant decommission.
- EDF smart-meter code-testing bid.
Bid Writer & Graphic Designer
Babcock
- Welsh Air Ambulance service and medical fit-out (MDR).
- Police fleet maintenance.
Central & NW London NHS Foundation Trust
- Bid for the provision of Cardiology Services (including MDR).
BA / UX Consultant
Cisco/IMImobile
- Information gathering and process & workflow mapping customer journeys.
- Stakeholder management; UX/UI campaign platform development (Agile), and testing (including A/B & multivariate testing, UML / Visio).
- Wrote CRM/Marketing user manuals and SDK docs for SaaS platforms analysing social media metrics for clients including EE, BBC, & Barclays.
Bid Editor, DTP, Design, and Proof-Reader
National Express Trains / KPMG
- East Anglia rail franchise bid.
TA/BA
Initial Rewards
- Pitched an on-line ecommerce store for US client.
- Loyalty programme for Skrill (e-commerce transactions platform) to comply within ISO27001 and quality framework.
- Bids covered data protection (now GDPR); failover, DR, & BCP of AWS cloud.
UK Broadband Network
- Telecoms bid for Network Rail to install 3G, 4G, GSM, ESN, (TETRA & RAN) and WiFi infrastructure.
Tullett Prebon
- Led CFTC SEF registration for Tullett’s US swaps platforms, protecting a core interest-rate-derivatives franchise.
- Delivered 4000+ pages covering process flow and full trade lifecycle for OTC trade.
- Authored onboarding/process docs, and supported AML, KYC, Basel, and MiFID II compliance.
- Managed SharePoint site migration and build.
- On-prem to cloud server / data lake project.
- Mapped global trading systems architecture (FO – MO – BO) to assess critical dependencies, legacy risk, and support integration and upgrades.
Director / Consultant (Business Analyst, Technical Author, GRC/AI/Cyber Consultant)
LOUD & Clear Consultancy
As an Irish-Australian dual national running LOUD & Clear Consultancy, I deliver expert governance, risk, compliance (GRC), business analysis, technical authorship, and bid writing services to leading European and UK organisations—primarily remotely, with hybrid options.
I spearheaded the European Central Bank's IGAM implementation and digital Euro investigations, drove risk management and operational offshoring at TP ICAP (including Tullett Prebon), and handled Basel, MiFID, SEF, and REMIT regulatory reporting for HSBC, Tullett Prebon, and TP ICAP. At ING Belgium, I led SOX compliance, system architecture, and SOC migrations, while securing over £1 billion bids for Bechtel and BAE Systems (SC-cleared). Recent cybersecurity, operational risk, and resilience projects span Syensqo, Mambu, Omnicom Group, and Rapier.
Engage me to transform your regulatory challenges into compliant, efficient operations across Europe.
Consultant, Technical Author (TA), Analyst (BA), GRC, PM
LOUD & Clear Consultancy
- GRC / Cybersecurity consultant producing audit-ready documentation and controls for regulated, safety-critical digital environments, aligned to ISO 27001/2, ISO 42001, SOC 2, NIST and related frameworks.
- Partners with engineers, architects and SMEs to translate complex technical and operational requirements into controlled artefacts, including process maps, data flows, architecture, controls, SOPs and reports.
- Designed and implemented GRC frameworks aligned to ISO 27001/27002, ISO 31000, NIST (CSF/800-53), DORA, NIS2, CAF, TISAX, CIS, and key regulators (FCA/PRA/EBA), embedding governance and audit readiness through RACI, KPIs, and traceable controls.
- Developed target operating models, business process maps and governance artefacts with explicit data-journey, integration and migration work to support architecture, risk and compliance.
- Developed security standards, policies and procedures for vulnerability management, incident response (LoD 1–3), SOC migration, DR/BCP/Data Loss Prevention (DLP) and broader IT resilience.
- Documented processes for Vulnerability Identification, Management and Analysis using tools such as Qualys and Defender to validate findings and filter false positives.
- Used data analytics, SIEM tooling, CMDBs and Info Asset Register for evidence-based incident response, threat detection, and asset management.
- Worked with on-premises & cloud (AWS, GCP, & Azure) environments, covering infrastructure, IAM, cryptography, patching, service migration and associated risks.
- Managed end-to-end projects across regulatory and technology environments, from business development and briefing through planning, forecasting, stakeholder management, delivery, and version-controlled documentation.
- Applied PRINCE2, Agile, Scrum, PMBOK, SAFe, Waterfall, SDLC, TOGAF, and Lean, Six Sigma, Kaizen methodologies.
- Produced and maintained technical documentation, including user guides, SDKs, runbooks, API style guides, and process/CAD diagrams.
- Managed document review, referencing, and style briefs through on-screen and desk editing/proofreading to ensure quality and compliance with editorial and regulatory standards.
- Clients include The Financial Times (Foreign Direct Investment), Bechtel, Springer-Verlag/Copenhagen Uni, EMAP, PIE Media, Incisive Media, Vitesse Media, Sicos, Victorian National Parks Association, United Business Media (CMPi), MSM International, The Jewish Chronicle, Trinity Mirror Group, Deakin University, University of Melbourne, City of Glen Eira (Melbourne), Rhodia Pharmaceutical, Airwallex, Accent, Museum of Victoria, AdNet Media, and the Australian New Zealand Association for the Advancement of Science.
Business Developer, Editor, and Designer (Financial Industry)
Trinston Financial
- Edited and designed research reports for UAE financial research house focussing on Saudi Arabia, GCC, and MENA.
- Met clients in Saudi & UAE promoting services.
Tutor
Deakin University
- Bachelor of Arts’ unit Electronic PR (social media, video production, broadcast etc).
Lecturer
Holmesglen TAFE
- Printing Industry; Design Principles; Graphics & Web Design (Adobe CS and Quark packages).
Broadcast journalist, Producer, and DJ
Public Radio Stations (Southern FM, EAR FM, Rusden Radio)
- Broadcast journalist, Producer, and DJ on public radio stations.
Lecturer
Swinburne University
- Professional Writing and Editing, Technical Writing, and Writing for Business.
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Banking and Finance, Information Technology, Professional Services, Advertising, Government and Administration, and Aerospace and Defense.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Audit, Information Technology, Project Management, Business Intelligence, Sales, and Research and Development.
Summary
GRC / Cybersecurity consultant (EU national) producing audit-ready documentation and controls for regulated, safety-critical digital environments, aligned to ISO 27001/2, ISO 42001, SOC 2, NIST and related frameworks. Partners with engineers, architects and SMEs to translate complex technical and operational requirements into controlled artefacts, including process maps, data flows, architecture, controls, SOPs and reports.
Skills
Business Packages: Msoffice/o365, Defender, Google Docs, Dropbox, Skype, Zoom, Citrix, Vpn, Saas, Crm / Salesforce, Atlassian Suite (Jira, Confluence), Saas, Paas, Daas, Erp Like Sap / Oracle / Workday, Servicenow, Purview, Qualys
Pam / Idam: Okta, Cyberark, Oracle Identity Governance, Active Directory (Ad)
Ai & Large Language Models (Llm): Chatgpt, Claude, Perplexity, Napkin.ai, Llm Notebooks, Google Gemini, Gamma, Lm Studio, Lovable, Midjourney, Otter.ai, Synthesia, Veed
Writing, Editing, Knowledge Management, Desktop And Dynamic Publishing: Adobe Indesign, Framemaker, Incopy, Quarkxpress, Madcap Flare, Dita, Docs-as-code, Sharepoint, Pdfxchange, Texworks, Asciidoctor, Gathercontent, Content / Document / Knowledge Management Systems
Graphic And Web Design (Ux, Ui, Ua, Seo): Adobe Creative Suite (Express, Illustrator, Photoshop, Firefly), Affinity, Canva, Imageready, Coreldraw, Fontographer, Freehand, Sketch, Inkscape, Gimp, Conceptdraw, Invision, Bbedit/notepad, Figma, Sharepoint Designer, Stylizer, Cssedit, Dreamweaver, Balsamiq, Axure, Analytics And Seo
Project Management, Change Management, Tools, And Methods: Microsoft Project / Pmo365, Servicenow, Merlin 2, Visio, Mindnode, Itsm / Servicenow, Copywrite, Slack, Github, Lucidchart, Trello, Loopio, Rfpio (Bid Tool)
Languages
Education
Deakin University
Graduate Diploma in Education, English, ICT and Science · Education (English, ICT and Science) · Melbourne, Australia
Deakin University
Bachelor of Science, Information Management (IT and Science) · Information Management (IT and Science) · Melbourne, Australia
Certifications & licenses
Prince2:2009 Foundation/Practitioner (Cert. P2R/727681)
APM-Group / Office of Government Commerce (UK)
Associate (0835385)
Association For Computer Machining (ACM)
Certificate Advanced Global Project Management Strategies And Implementation Methodologies
Certificate In Advanced Bid Skills
Bid Perfect
Certificate In Brush Up Your Editing
Certificate In Editing Medical Text
Certificate In Magazine Writing, Editing And Production
Royal Melbourne Institute Of Technology (Australia)
Certificate In Project Management
Society For Editors And Proofreaders (SfEP)
Certificate In Small Business Management
Box Hill TAFE, Melbourne, Australia
Copilot
Generative AI For Digital Marketing Certs
MCC Learning
Microsoft’s AI Ambassador Programme
HSBC
Security Operations Cert
Blue Team Training
Statistics
Experience
Global Experience
Expertise
Qualifications
Profile
Frequently asked questions
Do you have questions? Here you can find further information.
Where is Bobster based?
What languages does Bobster speak?
How many years of experience does Bobster have?
What roles would Bobster be best suited for?
What is Bobster's latest experience?
What companies has Bobster worked for in recent years?
Which industries is Bobster most experienced in?
Which business areas is Bobster most experienced in?
Which industries has Bobster worked in recently?
Which business areas has Bobster worked in recently?
What is Bobster's education?
Does Bobster have any certificates?
What is the availability of Bobster?
What is the rate of Bobster?
How to hire Bobster?
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Bid Manager
Nearby freelancers
Professionals working in or nearby Forest Hill, United Kingdom
Most recent projects
FRATCH works with many companies and recruitment agencies. Here you will find our recently posted projects and opportunities.