1 to 25 of 40 ISO 27001 Lead Implementer Jobs in London

Senior Security Consultant

Location
City Of London, England, United Kingdom
Define, implement and monitor corporate information security strategies, objectives and governance frameworks. Design and implement information security management systems and security master plans. Lead risk management activities, including risk identification, assessment, treatment and reporting. Define cybersecurity action plans and oversee their execution. Ensure the protection of services … analyses and defining continuity and testing plans. Implement and maintain information security controls aligned with applicable laws, regulations, standards and best practices, including ISO 27001 / 27002, GDPR, Cyber Assessment Framework (CAF) and NIST CSF. Develop and maintain information security policies, standards and procedures ...

Security Engineer, Compliance Focus

Location
Greater London, England, United Kingdom
here is not a paperwork exercise at the edge of the business. It is a condition of doing business. We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure … control is actually working or only described. What You Will Be Doing Compliance Execution Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline. Operate our GRC platform ...

Cyber Requirements & Compliance Specialist

Location
Greater London, England, United Kingdom
engagement with regulators and external stakeholders where required. Track regulatory findings, recommendations and actions through to closure. Assist with external certification activities, including ISO 27001 and Cyber Essentials Plus. Knowledge & Skills: Strong understanding of cyber security principles, governance frameworks and compliance management practices. Knowledge … version control processes. Strong stakeholder engagement and communication skills, with the ability to work effectively across technical and business functions. Familiarity with ISO 27001 / 27002, NIST Cyber Security Framework (CSF) 2.0 and the NCSC Cyber Assessment Framework (CAF). Understanding ...

Senior Information Security Manager

Hiring Organisation
Ascend Consulting
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £65,000 per annum
Senior Information Security Manager to play a pivotal role in their Compliance team. The Reporting to the Head of Compliance, you will lead the ISO 27001-certified information security management system, strengthen processes, and help shape policy. In this role … incidents, and contributing to policy development. The key responsibilities of this role are to oversee information security standards by managing and continually improving ISO 27001-certified Information Security Management System, leading business continuity management for information and technology risks, and supporting the organisation ...

Cyber Security Controls Tester (Assurance)

Location
City Of London, England, United Kingdom
Evaluate the effectiveness of technical, procedural, and physical security controls against documented security requirements and standards. Assess security controls against recognised frameworks including ISO 27001 , NIST CSF , NIST 800-53 , and CIS Controls . Review security documentation, including High-Level Designs (HLDs), Low-Level … Required Skills & Experience Proven experience testing and assessing the effectiveness of security controls within complex enterprise environments. Strong knowledge of security frameworks including: ISO 27001 NIST Cyber Security Framework (CSF) NIST 800-53 CIS Controls Experience reviewing and testing: Network security controls Firewall configurations ...

Assistant Manager Information Security

Location
Greater London, England, United Kingdom
MAIN DUTIES Information Security & Risk Management Maintain and continuously improve the ISO 27001:2022 ISMS, including the Statement of Applicability, information security policies, standards and procedures, and the supporting documentation register, ensuring they remain current, mapped to control frameworks and audit-ready. Provide proactive … strongly preferred, for example CISM, CISSP, ISO 27001 Lead Implementer / Lead Auditor. Technology‐centric training and certification is an advantage. Experience And Skills 5+ years' experience in information and cyber security implementation, management ...

Information Security Manager - Fintech - Hybrid

Location
City Of London, England, United Kingdom
Programme Maintain and continuously improve the Information Security Management System, firmwide information security programme, security policies, certifications and control framework, aligned to ISO 27001, SOC 2, DORA‐related customer obligations, applicable financial services expectations and Crédit Agricole Group requirements. Partner with Product, Engineering … such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer / Lead Auditor or equivalent experience. Degree in cybersecurity, computer science, risk management or a related discipline, or equivalent practical experience. We believe we offer ...

GRC Security Specialist

Location
Greater London, England, United Kingdom
annual refresher, phishing simulation, role‐based training for engineers, completion tracking. Coordinate pre‐employment screening with People. What you will contribute to: The ISO 27001 ISMS , which we are building towards certification. You will draft and maintain control documentation, populate the Statement of Applicability … Security rewriting them. Six months: the trust pack exists and is being used; the risk register is live with owned treatment plans; ISO 27001 evidence collection is systematic rather than a scramble; the exception register exists. Twelve months: supplier re‐assessment runs ...

Cyber Security Architect & Engineering Lead

Location
Greater London, England, United Kingdom
Cyber Security Architect & Engineering Lead Department: IT Infrastructure Employment Type: Permanent - Full Time Location: City, London Reporting To: Head of Information Security Compensation: £75,000 / year Description We are looking for a senior, hands-on Cyber Security Architect & Engineering Lead to help shape … applications and integration platforms. Design and implement modern security controls, with a strong focus on Zero Trust, secure-by-design principles and automation. Lead security architecture reviews and threat modelling for major projects, new products, high-risk integrations and emerging technologies. Act as the technical lead ...

Cyber Security & Compliance Lead

Location
Greater London, England, United Kingdom
CYBER SECURITY & COMPLIANCE LEAD Hours Full-time, 9:30am – 5.30pm with flexibility required to support system changes, upgrades and critical incidents where necessary. Department IT / Risk & Compliance The Role The Cyber Security & Compliance Lead is responsible for defining, delivering, and continuously improving … expectations. Technical skills and expertise Essential Significant experience in cyber security, information security, or IT risk roles. Experience operating at a senior or lead level within a professional services or regulated environment. Strong understanding of security frameworks (e.g. ISO 27001, NIST ...

IT Security Governance, Risk & Controls Analyst

Hiring Organisation
Ricoh
Location
London, United Kingdom
Employment Type
Permanent
plans. Assess the effectiveness of security controls and identify control gaps, weaknesses and opportunities for improvement . Translate security frameworks and requirements, including ISO 27001 and NIST CSF , into practical operational controls. Support audit, assurance and compliance activities , including ISO 27001 … principles . Experience conducting or supporting technology / security risk assessments and maintaining risk registers. Good knowledge of security control frameworks such as ISO 27001 and NIST CSF . Experience assessing control design and effectiveness , identifying gaps and supporting remediation. Understanding ...

Senior GRC Content Engineer

Location
Greater London, England, United Kingdom
Security & Compliance Consultant Mandatory GRC skills — you must be able to demonstrate: Practical, implementation‐level experience with ISO / IEC 27001 (2022 control set): scoping, risk assessment and treatment, Statement of Applicability, running or facing internal and certification audits — not just framework literacy … CISA, CRISC, CGRC, ISO / IEC 27001 Lead Implementer / Lead Auditor, CIPP / E are appreciated — practical experience matters more Benefits & Perks 100% Remote – In a fully digital world, work from anywhere ...

CLOUD SECURITY ARCHITECT

Location
Greater London, England, United Kingdom
reference architectures and reusable solution patterns Define and author enterprise‐level security policies, controls frameworks, and governance documentation aligned to industry standards Lead risk assessments, threat modelling exercises, and security posture evaluations for cloud platforms and SaaS products, utilising methodologies such as FAIR Drive compliance programmes covering … ISO 27001, Cyber Essentials Plus, PCI DSS, and other relevant regulatory frameworks Support DevSecOps adoption and integrate security tooling and controls into CI / CD pipelines across client delivery teams Engage senior stakeholders and executive teams with clear security risk reporting, remediation guidance ...

Compliance Officer

Location
Greater London, England, United Kingdom
space and trust to do the job the way they believe is best. This role is perfect for someone who wants to lead and build, not just follow a playbook. Why this role exists As the business scales, the need for structured governance, process integrity, and accountability … culture where compliance is practical, proportionate, and understood across the organisation. What we’re looking for Hands‐on SOC 2 and / or ISO 27001 experience: evidence management, direct auditor engagement. GRC platform experience (Drata, Vanta, or similar). Cloud literacy: comfortable navigating ...

Third Party Cyber Risk Lead

Location
Greater London, England, United Kingdom
Risk LeadApplylocations: UK - London ( St Botolph )time type: Full timeposted on: Posted Todayjob requisition id: 2026-628**Job Title:** Third Party Cyber Risk Lead**Reporting to:** Cyber Governance Manager**Direct Reports:** None**Position Type:** Permanent**Why** **Tokio Marine HCC?**Standing still is not an option … certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer / Lead Auditor.* Experience in regulated industries, implementing relevant regulations and expectations for third-party security risk management.* Proven experience designing, running, and improving vendor ...

Senior Security Consultant

Hiring Organisation
Akkodis
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
Cyber Security Consultant, Information Security Strong client-facing and stakeholder management skills Experience working with recognised security frameworks and standards, including: ISO 27001, NISTCyber Security Framework (CSF), CIS Controls, Cloud Security Controls, Secure by Design principles The ability to balance security best practice with … commercial realities Someone who is naturally curious, proactive and enjoys solving problems Desirable Certifications CISSP CISM CCSP ISO 27001 Lead Implementer or Lead Auditor Please note that applicants must have the right to work ...

Information Security Consultant

Location
London, United Kingdom
their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments … interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier ...

IT Security Compliance & Reporting Analyst

Hiring Organisation
Ricoh
Location
London, United Kingdom
Employment Type
Permanent
security and technology risk assessments , working with technical teams to identify appropriate and practical mitigation plans. Support audit, assurance and compliance activities , including ISO 27001, Cyber Essentials and internal control programmes. Translate security frameworks and regulatory requirements into practical, operational standards and controls . … Security Compliance . Experience developing and maintaining security policies, standards, controls and governance documentation . A strong understanding of security frameworks such as ISO 27001 and NIST CSF . Experience producing security compliance reporting, MI or dashboards , ideally using Power BI. Experience managing ...

Global Cybersecurity Manager - Client Assurance

Hiring Organisation
The Boston Consulting Group
Location
London, UK
Employment Type
Full-time
ensure consistent and compliant responses to client inquiries. Risk & Compliance Support: Support clients in understanding BCG's compliance with relevant frameworks (e.g. ISO 27001, SOC 2, GDPR, NIST) and help translate technical security concepts into business-relevant assurance responses. Quality & Continuous Improvement: Support … related field. Experience supporting client-facing information security, assurance, audit, compliance, or advisory activities. Strong understanding of information security frameworks and standards including ISO 27001, SOC 2, NIST CSF, GDPR, and relevant regional data protection regulations. Experience responding to client security questionnaires, due diligence ...

AI Security Consultant

Hiring Organisation
PA Consulting
Location
London, United Kingdom
Salary
£ 70 K
assurance.Familiarity with frameworks and guidance such as NIST AI RMF, OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, MITRE ATLAS, ISO 27001, NIST CSF, CIS Controls or cloud security frameworks.Experience with SOC operations, SIEM / SOAR platforms, detection engineering, threat intelligence … guardrails for autonomous systems, including least privilege, approval workflows, action limits, logging, monitoring and rollback mechanisms.Relevant certifications such as CISSP, CISM, CCSP, GIAC, ISO 27001 Lead Implementer / Auditor, cloud security certifications or AI / security-focused training.Please ...

AI Security Consultant

Location
City of Westminster, England, United Kingdom
assurance. Familiarity with frameworks and guidance such as NIST AI RMF, OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, MITRE ATLAS, ISO 27001, NIST CSF, CIS Controls or cloud security frameworks. Experience with SOC operations, SIEM / SOAR platforms, detection engineering, threat … autonomous systems, including least privilege, approval workflows, action limits, logging, monitoring and rollback mechanisms. Relevant certifications such as CISSP, CISM, CCSP, GIAC, ISO 27001 Lead Implementer / Auditor, cloud security certifications or AI / security-focused training. Please ...

Security Consultant – Risk & Resilience - Financial Services

Location
Greater London, England, United Kingdom
cyber risk management, operational resilience, business continuity, disaster recovery, and incident response principles. Knowledge of common security and risk frameworks such as NIST, ISO 27001, COBIT, CIS Controls, and FFIEC guidance. Familiarity with financial services regulatory requirements relating to technology risk and resilience. Experience … enabled tools to improve efficiency, insight generation, or risk management outcomes. Preferred Qualifications Professional certifications such as CISSP, CISM, CRISC, CISA, CBCI, ISO 27001 Lead Implementer / Auditor, or equivalent. Experience supporting regulatory programmes involving PRA, FCA, DORA ...

Security Consultant - Risk & Resilience - Financial Services

Hiring Organisation
Accenture
Location
London, UK
Employment Type
Full-time
cyber risk management, operational resilience, business continuity, disaster recovery, and incident response principles. Knowledge of common security and risk frameworks such as NIST, ISO 27001, COBIT, CIS Controls, and FFIEC guidance. Familiarity with financial services regulatory requirements relating to technology risk and resilience. Experience … enabled tools to improve efficiency, insight generation, or risk management outcomes. Preferred Qualifications: Professional certifications such as CISSP, CISM, CRISC, CISA, CBCI, ISO 27001 Lead Implementer / Auditor, or equivalent. Experience supporting regulatory programmes involving PRA, FCA, DORA ...

Head of Information Security (Deputy CISO)

Location
Greater London, England, United Kingdom
reducing material cyber and technology risk. Own the Information Security Management System and support continued alignment with ISO / IEC 27001:2022, the NIST Cybersecurity Framework and other recognised standards. Maintain effective security policies, standards and controls, ensuring they are understood, embraced, evidenced … governance, risk and compliance, architecture, engineering, third-party risk, assurance and operational resilience. Strong practical knowledge of ISO / IEC 27001, PCI DSS, UK GDPR, the Data Protection Act 2018 and recognised control frameworks such as NIST. A solid understanding of technology risk ...

Security Operations Analyst- 6 month FTC

Location
City of Westminster, England, United Kingdom
closely with our managed SOC, you'll investigate alerts and incidents, close monitoring gaps, and keep our ISO / IEC 27001:2022 controls backed by complete, audit-ready evidence — including running customer and client security-assurance questionnaires on the business's behalf. Responsibilities … gaps by improving detection use cases, alert logic, playbooks and escalation criteria. Own the evidence cycle for ISO / IEC 27001:2022 controls — mapping, collecting and maintaining audit-ready evidence, and resolving gaps with control owners. Support internal, certification and surveillance audits, tracking ...