Role This is a unique and exciting opportunity for a seasoned PCIDSS expert to take ownership of and drive the growth of the PaymentCardIndustry (PCI) service line. This role is a perfect blend of deep technical consulting, strategic client advisory, and sophisticated business development. You will act as the lead subject matter expert, guiding … mid-market clients through the complexities of achieving and maintaining PCIDSS compliance. You will also contribute and share in the rewards for the commercial success of the practice, identifying and winning new business with both existing and prospective customers by acting as a trusted, credible advisor. Key Responsibilities Consulting & Delivery (approx. 80%) Lead and deliver a range … of PCIDSS compliance services, including Gap Analyses, Scoping Workshops, Remediation Advisory, and formal assessments (Report on Compliance (RoC) and Self-Assessment Questionnaires (SAQ)). Act as a virtual CISO or trusted security advisor to key clients, providing ongoing strategic guidance on their compliance programmes. Translate complex technical PCIDSS requirements and security findings into clear More ❯
Lead Cyber Security Risk Consultant - PCI-DSS - Manchester We're seeking a strong Lead Cyber Security Risk Consultant with excellent cyber security, GRC & PCI-DSS payments experience to join our client's growing Cyber Security team. They need somebody who has excellent knowledge in PCI-DSS, ideally the subject matter expert, along with good … compliance experience You'll have a small team of GRC Specialists to do the transactional work, so we're looking for someone who is confident and can provide the PCI-DSS expertise that is needed. Experience Required: At least 5 years in a Cyber security & GRC role, at Senior, lead or manager level. Be a PCI-DSS … UK based headquarters in Manchester, so it is a great time to join a global company that is going from strength to strength. Responsibilities Cyber Governance & Frameworks within a PCI-DSS environment Develop, maintain, and evolve the cyber governance and compliance framework. Define and manage information and cyber security policies, standards, and procedures. Ensure alignment with ISO More ❯
GRC Specialist - PCI-DSS - Manchester We're seeking an experienced GRC Specialist with excellent cyber security, GRC & PCI-DSS payments experience to join our client's growing Cyber Security team. They need somebody who has excellent knowledge in PCI-DSS along with good governance, risk and compliance experience and familiarity with other standards. Experience … Required: At least 2-3 years in a Cyber security & GRC role Be a PCI-DSS expert around payments ISO 27001and GDPR Knowledge of Risk Management, including risk identification, assessment, and mitigation techniques Good experience around Audits and compliance Any penetration testing experience would be a bonus You'll work closely with both internal and external stakeholders across … UK based headquarters in Manchester, so it is a great time to join a global company that is going from strength to strength. Responsibilities Cyber Governance & Frameworks within a PCI-DSS environment Develop, maintain, and evolve the cyber governance and compliance framework. Define and manage information and cyber security policies, standards, and procedures. Ensure alignment with ISO More ❯
PCI-DSS Compliance Manager - GRC/Payments Manchester £60-80k pa A successful technology company are seeking a PCI-DSS Compliance Manager to join their growing Security team and be responsible for risk management, compliance monitoring and governance support as well as 3rd party vendor risk management. Being experienced in Payments Compliance you will ensure … the company maintains compliance with all relevant regulations including PCI-DSS, GDPR, NIS Regulations and the Data Protection Act 2018. You will be able to demonstrate Attestation of Compliance (AoC) experience alongside experience of ensuring compliance with ISO27001 and relevant organisational standards. This role will require excellent technical GRC and PCI-DSS knowledge, good organisational skills … and the ability to communicate critical security information and requirements to both internal and external stakeholders. PCI-DSS and Attestation of Compliance experience is a must have for this position. Please send a CV detailing the required experience for consideration. PCI-DSS Compliance Manager - GRC/Payments Manchester £60-80k pa More ❯
london, south east england, united kingdom Hybrid / WFH Options
PCI Pal
WELCOME TO PCI PAL PCI Pal is a leading provider of SaaS solutions that empower companies to take payments securely, adhere to strict industry governance, and remove their business from the significant risks posed by non-compliance and data loss. We are integrated and resold by some of the world's leading business communications vendors, as well as … major payment service providers. We are currently looking for a GRC & Audit Lead to join our UK team. THE OPPORTUNITY: PCI Pal's Information Security team requires a dynamic and proactive individual to lead all Governance, Risk and Compliance (GRC), audit requirements for our team and the company. We are an agile and innovative team and are responsible for … that GRC and audit requirements are suitably managed, maintained and matured. YOU WILL BE RESPONSIBLE FOR: Managing, maintaining, and maturing the already established audit lifecycles for the following frameworks: PCIDSS v4.0, ISO 27001:2022, ISO 9001:2015, ISO 14001:2015, Cyber Essentials, Cyber Essentials Plus, SOC2 Type 1 – 3 & HIPAA Working in close collaboration with other team More ❯
Team Development Build, mentor, and lead engineering and technology teams. Establish a culture of excellence, innovation, and accountability. Security, Risk & Compliance Ensure full compliance with international regulatory standards. Oversee PCIDSS, PCI PIN and local data protection adherence. Oversee fraud prevention, risk management, and transaction monitoring in the technology flows. Partner with compliance teams to proactively address … experience with local switch integrations and payment network connectivity. Proven track record in vendor selection, implementation, and delivery across SaaS, Cloud, and On-Prem. Strong knowledge of regulatory frameworks, PCIDSS, and PCI PIN. Experience building and scaling engineering teams in regulated environments. For a discreet and confidential conversation, please do feel free to either PM me More ❯
own the strategic and operational delivery of all information and cyber security activities. You'll develop and implement robust security policies, oversee incident response, and ensure compliance with GDPR, PCIDSS, ISO 27001, and Cyber Essentials Plus. You will be the single point of accountability for all security matters, reporting directly to the executive team and influencing critical … projects, platforms, data flows, and product development. Lead enterprise-wide information, cyber, and datasecurity governance. Define and implement security frameworks, policies, and operating models. Ensure compliance with GDPR, PCIDSS, Cyber Essentials Plus, and ISO/IEC 27001:2022 aligned practices. Lead Data Protection Impact Assessments (DPIAs), data mapping, classification, and retention programs. Oversee incident response, vulnerability … Proven senior leadership experience in information, cyber, or data security. CISSP, CISM, or CISA certified (or equivalent). Track record of delivering security programs aligned to ISO 27001, NIST, PCIDSS, and Cyber Essentials Plus. Hands-on experience with cloud platforms (Azure, AWS), on-premise networks, and hybrid architectures. Strong experience in Zero Trust security models. Experienced in More ❯
own the strategic and operational delivery of all information and cyber security activities. You'll develop and implement robust security policies, oversee incident response, and ensure compliance with GDPR, PCIDSS, ISO 27001, and Cyber Essentials Plus. You will be the single point of accountability for all security matters, reporting directly to the executive team and influencing critical … projects, platforms, data flows, and product development. Lead enterprise-wide information, cyber, and datasecurity governance. Define and implement security frameworks, policies, and operating models. Ensure compliance with GDPR, PCIDSS, Cyber Essentials Plus, and ISO/IEC 27001:2022 aligned practices. Lead Data Protection Impact Assessments (DPIAs), data mapping, classification, and retention programs. Oversee incident response, vulnerability … Proven senior leadership experience in information, cyber, or data security. CISSP, CISM, or CISA certified (or equivalent). Track record of delivering security programs aligned to ISO 27001, NIST, PCIDSS, and Cyber Essentials Plus. Hands-on experience with cloud platforms (Azure, AWS), on-premise networks, and hybrid architectures. Strong experience in Zero Trust security models. Experienced in More ❯
own the strategic and operational delivery of all information and cyber security activities. You'll develop and implement robust security policies, oversee incident response, and ensure compliance with GDPR, PCIDSS, ISO 27001, and Cyber Essentials Plus. You will be the single point of accountability for all security matters, reporting directly to the executive team and influencing critical … projects, platforms, data flows, and product development. Lead enterprise-wide information, cyber, and datasecurity governance. Define and implement security frameworks, policies, and operating models. Ensure compliance with GDPR, PCIDSS, Cyber Essentials Plus, and ISO/IEC 27001:2022 aligned practices. Lead Data Protection Impact Assessments (DPIAs), data mapping, classification, and retention programs. Oversee incident response, vulnerability … Proven senior leadership experience in information, cyber, or data security. CISSP, CISM, or CISA certified (or equivalent). Track record of delivering security programs aligned to ISO 27001, NIST, PCIDSS, and Cyber Essentials Plus. Hands-on experience with cloud platforms (Azure, AWS), on-premise networks, and hybrid architectures. Strong experience in Zero Trust security models. Experienced in More ❯
Milton Keynes, Buckinghamshire, South East, United Kingdom
Oscar Associates (UK) Limited
regulatory compliance oversight. The ideal candidate will establish and maintain security standards across the product portfolio, oversee secure system environments, and act as the primary contact for ISO 27001, PCIDSS, and GDPR compliance. Additionally, this role will support our commercial teams by contributing to tender responses and ensuring client security assurance. The Company: They are a technology … management and penetration testing programs. Maintain strong identity, access, and privilege management controls. Compliance & Assurance (30%) Manage and maintain ISO 27001 certification and audit processes. Ensure ongoing compliance with PCIDSS for payment-related systems. Oversee GDPR compliance across products, services, and internal operations. Complete HECVAT assessments and respond to security questionnaires for higher education tenders. Support sales … SaaS or cloud environments (ISV or B2B preferred). Proven track record managing ISO 27001 certification and compliance. Hands-on experience implementing GDPR in software products. Working knowledge of PCIDSS and securing payment systems. Deep understanding of cloud security across Azure and/or AWS. Skilled in application security and the secure development lifecycle (SDLC). Experienced More ❯
impact projects within a forward-thinking, supportive environment that values expertise, innovation, and growth. KEY RESPONSIBILITIES: Deliver high-quality GRC services, including: ISO 27001 NIST Gap Analysis CAF Assessments PCIDSS CSMA, ISF, and CIS Assessments Develop and maintain in-house methodologies, templates, and delivery playbooks for core GRC services. Conduct client workshops, interviews, and assessments to gather … Computer Science, Risk Management, or a related field, or equivalent professional experience. - ESSENTIAL Professional Experience One or more of the following: ISO 27001 Lead Auditor or Lead Implementer certification PCIDSS Qualified Security Assessor (QSA) or Internal Security Assessor (ISA) NIST Cybersecurity Framework or CAF-related training/accreditation Certified Information Systems Security Professional (CISSP) Certified Information Security … tabletop exercises, or assurance testing engagements. - DESIRABLE Other Requirements Strong understanding of governance, risk, and compliance principles, including key frameworks and regulations such as ISO 27001, NIST CSF, CAF, PCIDSS, and GDPR. - ESSENTIAL Excellent written and verbal communication skills, with the ability to translate technical requirements into business language. - ESSENTIAL Ability to travel to client sites as More ❯
ross-on-wye, midlands, united kingdom Hybrid / WFH Options
DCS Technology
an experienced Information Security Analyst to join our client who will play a key role in driving compliance, governance, and continual improvement across key security frameworks including ISO 27001, PCIDSS, and Cyber Essentials Plus. Key Responsibilities: • Lead on the operation and continual improvement of the Information Security Management System (ISMS) • Coordinate internal and external audit readiness for … ISO 27001, PCIDSS, and Cyber Essentials Plus • Draft and update information security policies, procedures, and technical standards • Work with procurement and commercial teams to support supplier assurance and risk assessment • Contribute to tender responses and bid processes, ensuring security and compliance requirements are met • Promote good security practices and raise awareness across departments • Act as an escalation … and standards relating to information and cyber security Key Skills & Experience: Essential: • Background in IT, Cyber Security, Information Systems, or a related discipline • Strong working knowledge of ISO 27001, PCIDSS, and Cyber Essentials Plus • Proven ability to support and prepare for audits, including evidence collation and audit readiness • Excellent attention to detail and ability to produce high More ❯
Hereford, Herefordshire, England, United Kingdom Hybrid / WFH Options
DCS Recruitment
an experienced Information Security Analyst to join our client who will play a key role in driving compliance, governance, and continual improvement across key security frameworks including ISO 27001, PCIDSS, and Cyber Essentials Plus. Key Responsibilities: * Lead on the operation and continual improvement of the Information Security Management System (ISMS) * Coordinate internal and external audit readiness for … ISO 27001, PCIDSS, and Cyber Essentials Plus * Draft and update information security policies, procedures, and technical standards * Work with procurement and commercial teams to support supplier assurance and risk assessment * Contribute to tender responses and bid processes, ensuring security and compliance requirements are met * Promote good security practices and raise awareness across departments * Act as an escalation … and standards relating to information and cyber security Key Skills & Experience: Essential: * Background in IT, Cyber Security, Information Systems, or a related discipline * Strong working knowledge of ISO 27001, PCIDSS, and Cyber Essentials Plus * Proven ability to support and prepare for audits, including evidence collation and audit readiness * Excellent attention to detail and ability to produce high More ❯
Carlisle, Cumbria, England, United Kingdom Hybrid / WFH Options
Cumberland Building Society
your whole self to work bringing your energy and creativity to make a positive difference, then this is the job for you. We have an exciting opportunity for a PCI and Compliance Lead to join our Information Security team for a fixed term of 18 months. The Benefits Salary - up to £64,898 p.a. – depending on skills and experience. … community organisations. The Role Reporting to our Information Security Assurance Manager, you’ll be responsible for oversight, management and continuous compliance of the PaymentCardIndustryDataSecurityStandard (PCIDSS) requirements across the Society within the Information Security Assurance Team. You’ll assist in the oversight and control of all aspects of the Information Security Management System … line risk colleagues, Payments and Technology. You’ll manage the relationship with Qualified Security Assessors (QSAs); coordinating annual assessment and remediation activities, Regulatory Bodies; providing evidence and reporting for PCI compliance, and Third-Party Service Providers; completing assurance reviews and compliance verifications for suppliers handling PCI data. About You We’re looking for someone with significant experience in More ❯
Liverpool, Lancashire, United Kingdom Hybrid / WFH Options
Love2shop
examples of working in a service critical environment are advantageous. As a DevOps Engineer you will be responsible for ensuring all deployment processes and automation meet regulatory requirements, namely PCIDSS, ISO27001, and Cyber Security Essentials. This will include the introduction of standards to ensure conformity within the PayPoint development and deployment workflows. This role is Hybrid with … and firewall management • Certification in Azure, AWS, or DevOps methodologies • Experience with chaos engineering and resilience testing • Familiarity with service mesh technologies (Istio, Linkerd, cilium) Really Nice to Have: • PCI-DSS compliance experience • Experience in financial services or regulated industries • Knowledge of ITIL or similar service management frameworks • Experience with automated testing frameworks and test automation • Understanding of More ❯
Liverpool, England, United Kingdom Hybrid / WFH Options
Love2shop
examples of working in a service critical environment are advantageous. As a DevOps Engineer you will be responsible for ensuring all deployment processes and automation meet regulatory requirements, namely PCIDSS, ISO27001, and Cyber Security Essentials. This will include the introduction of standards to ensure conformity within the PayPoint development and deployment workflows. This role is Hybrid with … and firewall management • Certification in Azure, AWS, or DevOps methodologies • Experience with chaos engineering and resilience testing • Familiarity with service mesh technologies (Istio, Linkerd, cilium) Really Nice to Have: • PCI-DSS compliance experience • Experience in financial services or regulated industries • Knowledge of ITIL or similar service management frameworks • Experience with automated testing frameworks and test automation • Understanding of More ❯
birkenhead, north west england, united kingdom Hybrid / WFH Options
Love2shop
examples of working in a service critical environment are advantageous. As a DevOps Engineer you will be responsible for ensuring all deployment processes and automation meet regulatory requirements, namely PCIDSS, ISO27001, and Cyber Security Essentials. This will include the introduction of standards to ensure conformity within the PayPoint development and deployment workflows. This role is Hybrid with … and firewall management • Certification in Azure, AWS, or DevOps methodologies • Experience with chaos engineering and resilience testing • Familiarity with service mesh technologies (Istio, Linkerd, cilium) Really Nice to Have: • PCI-DSS compliance experience • Experience in financial services or regulated industries • Knowledge of ITIL or similar service management frameworks • Experience with automated testing frameworks and test automation • Understanding of More ❯
old swan, north west england, united kingdom Hybrid / WFH Options
Love2shop
examples of working in a service critical environment are advantageous. As a DevOps Engineer you will be responsible for ensuring all deployment processes and automation meet regulatory requirements, namely PCIDSS, ISO27001, and Cyber Security Essentials. This will include the introduction of standards to ensure conformity within the PayPoint development and deployment workflows. This role is Hybrid with … and firewall management • Certification in Azure, AWS, or DevOps methodologies • Experience with chaos engineering and resilience testing • Familiarity with service mesh technologies (Istio, Linkerd, cilium) Really Nice to Have: • PCI-DSS compliance experience • Experience in financial services or regulated industries • Knowledge of ITIL or similar service management frameworks • Experience with automated testing frameworks and test automation • Understanding of More ❯
warrington, cheshire, north west england, united kingdom Hybrid / WFH Options
Love2shop
examples of working in a service critical environment are advantageous. As a DevOps Engineer you will be responsible for ensuring all deployment processes and automation meet regulatory requirements, namely PCIDSS, ISO27001, and Cyber Security Essentials. This will include the introduction of standards to ensure conformity within the PayPoint development and deployment workflows. This role is Hybrid with … and firewall management • Certification in Azure, AWS, or DevOps methodologies • Experience with chaos engineering and resilience testing • Familiarity with service mesh technologies (Istio, Linkerd, cilium) Really Nice to Have: • PCI-DSS compliance experience • Experience in financial services or regulated industries • Knowledge of ITIL or similar service management frameworks • Experience with automated testing frameworks and test automation • Understanding of More ❯
Welwyn Garden City, England, United Kingdom Hybrid / WFH Options
PayPoint plc
examples of working in a service critical environment are advantageous. As a DevOps Engineer you will be responsible for ensuring all deployment processes and automation meet regulatory requirements, namely PCIDSS, ISO27001, and Cyber Security Essentials. This will include the introduction of standards to ensure conformity within the PayPoint development and deployment workflows. This role is Hybrid with … and firewall management • Certification in Azure, AWS, or DevOps methodologies • Experience with chaos engineering and resilience testing • Familiarity with service mesh technologies (Istio, Linkerd, cilium) Really Nice to Have: • PCI-DSS compliance experience • Experience in financial services or regulated industries • Knowledge of ITIL or similar service management frameworks • Experience with automated testing frameworks and test automation • Understanding of More ❯
welwyn garden city, east anglia, united kingdom Hybrid / WFH Options
PayPoint plc
examples of working in a service critical environment are advantageous. As a DevOps Engineer you will be responsible for ensuring all deployment processes and automation meet regulatory requirements, namely PCIDSS, ISO27001, and Cyber Security Essentials. This will include the introduction of standards to ensure conformity within the PayPoint development and deployment workflows. This role is Hybrid with … and firewall management Certification in Azure, AWS, or DevOps methodologies Experience with chaos engineering and resilience testing Familiarity with service mesh technologies (Istio, Linkerd, cilium) Really Nice to Have: PCI-DSS compliance experience Experience in financial services or regulated industries Knowledge of ITIL or similar service management frameworks Experience with automated testing frameworks and test automation Understanding of More ❯
watford, hertfordshire, east anglia, united kingdom Hybrid / WFH Options
PayPoint plc
examples of working in a service critical environment are advantageous. As a DevOps Engineer you will be responsible for ensuring all deployment processes and automation meet regulatory requirements, namely PCIDSS, ISO27001, and Cyber Security Essentials. This will include the introduction of standards to ensure conformity within the PayPoint development and deployment workflows. This role is Hybrid with … and firewall management • Certification in Azure, AWS, or DevOps methodologies • Experience with chaos engineering and resilience testing • Familiarity with service mesh technologies (Istio, Linkerd, cilium) Really Nice to Have: • PCI-DSS compliance experience • Experience in financial services or regulated industries • Knowledge of ITIL or similar service management frameworks • Experience with automated testing frameworks and test automation • Understanding of More ❯
made available to all staff and volunteers increasing awareness among these groups. Develop policies and procedures in accordance with industry regulations and standards such as Data Protection Act 2018, PCI-DSS, and ISO27001. Monitor tools for data governance, datasecurity, and compliance to manage information security risks and regulatory requirements and detect and investigate possible information security incidents. … management. Familiarity with ITIL practices and risk management methodologies. Significant proven experience with cyber security incident management and response Strong knowledge of security standards and regulations, such as GDPR, PCI-DSS, and ISO27001 Experience of delivering data protections specifically data loss prevention, sensitivity labelling and retention (using Microsoft Purview) Experience of managing projects through to completion Skills & Attributes More ❯
made available to all staff and volunteers increasing awareness among these groups. Develop policies and procedures in accordance with industry regulations and standards such as Data Protection Act 2018, PCI-DSS, and ISO27001. Monitor tools for data governance, datasecurity, and compliance to manage information security risks and regulatory requirements and detect and investigate possible information security incidents. … management. Familiarity with ITIL practices and risk management methodologies. Significant proven experience with cyber security incident management and response Strong knowledge of security standards and regulations, such as GDPR, PCI-DSS, and ISO27001 Experience of delivering data protections specifically data loss prevention, sensitivity labelling and retention (using Microsoft Purview) Experience of managing projects through to completion Skills & Attributes More ❯
team. In this fully remote UK-based role, you will conduct IT security audits and assessments for clients across the United Kingdom and the European region, ensuring compliance with PCIDSS, ISO 27001/2, GDPR, NIS2, DORA, and other relevant frameworks. This position offers the opportunity to become a PCI QSA (training and certification sponsored by … auditing or consulting experience. Bachelors degree in information security or related field. Deep knowledge of IT security controls, access management, logging, vulnerability assessment, and secure system configuration. Experience with PCIDSS, ISO 27001/2, GDPR, NIS2, DORA, or similar compliance frameworks. Strong understanding of cloud environments and network architectures. Excellent English communication skills; fluency in German strongly More ❯