1 to 25 of 169 Permanent SOC 2 Jobs in London

Information Security Analyst II (GRC)

Hiring Organisation
Checkout.com
Location
London, UK
trusted point of contact for internal teams and external assessors.You will work across Checkout's core compliance frameworks including PCI DSS v4.0.1, ISO 27001, SOC 2, and emerging regulatory obligations such as DORA and the EU AI Act, supporting our global footprint across Europe, MENA, APAC, and … audit, or a closely related function, ideally within payments, financial services, or fintech.Practical working knowledge of PCI DSS (v4.0.1 preferred), ISO 27001, and SOC 2. Familiarity with DORA, NIST CSF, or the EU AI Act is a plus.Experience supporting or directly managing external audits and assessments, including evidence collation ...

Senior Security Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
security design and architecture reviews, paired with the governance and process work that scales the program. You will partner on customer due‐diligence and SOC 2 evidence and turn security controls into repeatable workflows that fit how the business already works. You will apply that lens across … and DevOps to reduce risk through secure design and simplicity, not just added controls. Governance, Risk & Compliance Partner on customer due‐diligence (DDQ) and SOC 2 Type II evidence gathering, keeping compliance sustainable rather than fire‐drilled. Build repeatable security workflows that embed controls into existing engineering processes ...

Director, Compliance Audit - iLottery & Interactive

Hiring Organisation
Aristocrat Technologies
Location
London, UK
operational, security, technology, and service delivery controls.Coordinate and lead all aspects of external audits and certifications supporting lottery customers, including but not limited to SOC 1, SOC 2, ISO 27001, WLA-SCS, PCI-DSS, and jurisdiction-specific requirements.Maintain audit readiness throughout all iLottery regions by conducting proactive … executive leadership and customer collaborators.Strong understanding of audit methodologies, internal controls, risk management, and governance frameworks.Experience with recognized industry benchmarks and certifications such as SOC 1, SOC 2, ISO 27001, PCI-DSS, WLA-SCS, NIST, COBIT, or comparable frameworks.Strong analytical, problem-solving, and decision-making capabilities.Excellent communication ...

Director, Compliance Audit – iLottery & Interactive

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
security, technology, and service delivery controls.* Coordinate and lead all aspects of external audits and certifications supporting lottery customers, including but not limited to SOC 1, SOC 2, ISO 27001, WLA-SCS, PCI-DSS, and jurisdiction-specific requirements.* Maintain audit readiness throughout all iLottery regions by conducting … and customer collaborators.* Strong understanding of audit methodologies, internal controls, risk management, and governance frameworks.* Experience with recognized industry benchmarks and certifications such as SOC 1, SOC 2, ISO 27001, PCI-DSS, WLA-SCS, NIST, COBIT, or comparable frameworks.* Strong analytical, problem-solving, and decision-making capabilities. ...

GRC Engineer - Platform Team

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
processes that keep Taktile secure, compliant, and continuously audit-ready. You'll be the engineering-minded backbone of our compliance program, turning frameworks like SOC 2, ISO 27001, GDPR, and the EU AI Act into automated, continuously-monitored controls rather than one-off, point-in-time checklists. This … customer security questionnaire in the morning and scripting AWS evidence collection in the afternoon. What you'll do Own continuous compliance end-to-end ; SOC 2, ISO 27001, and customer security reviews, keeping us audit-ready year-round rather than scrambling at renewal time. Manage and evolve ...

Security Engineer, Compliance Focus

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
paperwork exercise at the edge of the business. It is a condition of doing business. We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure in several countries, and deploying into partner data centers. … actually working or only described. What You Will Be Doing Compliance Execution Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline. Operate our GRC platform (Vanta) day to day: configure and ...

Head of Information Security

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
Define and own the GRC programme, including the ISMS, policy framework, risk registers, and audit readiness Implement and maintain compliance with ISO 27001, SOC 1, SOC 2, NIST CSF, GDPR, and relevant financial services regulations Understand the GRC landscape, implement appropriate controls, and adapt as the threat … progressive experience in information security, with at least 3 years in a senior or leadership role Hands‐on experience owning ISO 27001 and SOC 1 and SOC 2 programmes, not just supporting them Demonstrated experience managing security incidents end‐to‐end, including client and regulatory communications Strong ...

Head of Information Security

Hiring Organisation
Duco
Location
London, UK
Define and own the GRC programme, including the ISMS, policy framework, risk registers, and audit readiness– Implement and maintain compliance with ISO 27001, SOC 1, SOC 2, NIST CSF, GDPR, and relevant financial services regulations– Understand the GRC landscape, implement appropriate controls, and adapt as the threat … progressive experience in information security, with at least 3 years in a senior or leadership role- Hands-on experience owning ISO 27001 and SOC 1 and SOC 2 programmes, not just supporting them- Demonstrated experience managing security incidents end-to-end, including client and regulatory communications- Strong ...

Global Risk and Compliance Manager

Hiring Organisation
Elixirr International
Location
London, UK
including horizon scanning across jurisdictions.Reduce cyber risk exposure and strengthen cybersecurity governance in partnership with the CISO, aligning to global standards e.g. ISO 27001, SOC 2.Contribute to Board, Audit Committee and Annual Report risk disclosures.Risk & Compliance OperationsLead the Group’s risk and compliance programme, ensuring controls are well-designed … operational and scalable, particularly for SOC 2 Type 2 and ISO 27001.Maintain a centralised, audit-ready evidence repository and coordinate internal/external audits, client reviews and due diligence.Oversee remediation plans and ensure continuous evidence collection.Develop consistent, lightweight playbooks for vendor intake, audit readiness and control testing ...

Senior Cybersecurity Consultant

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
creating operational friction. Responsibilities Lead penetration testing and vulnerability assessment engagements Design security architectures for cloud-native and hybrid environments Develop security compliance programs (SOC 2, ISO 27001, GDPR) Conduct incident response planning and tabletop exercises Advise C-level executives on security strategy and risk management Requirements 8+ … years in information security with consulting experience Deep expertise in penetration testing, vulnerability management, and threat modeling Knowledge of compliance frameworks: SOC 2, ISO 27001, GDPR, PCI-DSS Experience with cloud security (AWS Security Hub, Azure Defender, or GCP Security Command Center) CISSP, OSCP, or equivalent certification Nice ...

Senior IT Infrastructure Engineer

Hiring Organisation
Nasuni
Location
London, UK
cloud availability, performance, security posture, and cost efficiency through dashboards, alerts, tagging discipline, and operational reviews.Partner with Security on encryption, key management, network segmentation, SOC 2, ISO 27001, Zero Trust, and related cloud security initiatives.Collaborate with Engineering and IT Operations on migrations, SaaS/PaaS optimization, disaster recovery … and MFA.Strong troubleshooting skills across cloud, identity, networking, and SaaS environments.Clear documentation and communication skills for technical and cross-functional audiences.PreferredExperience supporting SOC 2, ISO 27001, Zero Trust, or similar compliance/security frameworks.Experience with FinOps practices, tagging policies, cost dashboards, or cloud spend optimization.Experience supporting disaster recovery ...

Senior DevSecOps Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
and operational runbooks Manage secrets, key custody, access controls, and infrastructure governance Deliver backup, disaster recovery, and business continuity strategies Drive compliance readiness for SOC 2, ISO 27001, and regulatory audits Partner with software engineering teams to ensure applications are secure, observable, and production‐ready Lead infrastructure migration … taking systems from early‐stage development through to secure production deployment Strong background in cloud infrastructure, automation, and operational security Experience supporting or leading SOC 2 Type II and/or ISO 27001 programmes Strong documentation and communication skills with the ability to create clear technical and compliance ...

Information Security & Compliance Manager

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
and compliance posture to leadership in clear, business-oriented terms. Compliance and certifications Drive certification and attestation efforts (e.g., ISO 27001 and/or SOC 2): design and maintain the control framework, own the documentation and evidence, and lead internal and external audits. Build a sustainable, “always-audit … . Strong, practical knowledge of GDPR and UK GDPR and day-to-day data protection. Hands‐on experience with ISO 27001 and/or SOC 2 implementation and audits. Working familiarity with the Microsoft security stack (Entra ID, Defender, Purview, Intune). Experience responding to client/customer ...

Platform Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
available, and optimized for both performance and cost. Key Responsibilities Architect, implement, and maintain cloud infrastructure to support rapid product growth. Prepare infrastructure for SOC 2/ISO 27001 audits, aligning with customer expectations. Build and maintain CI/CD pipelines for backend, frontend, and data services … Experience implementing reliability, security, and compliance measures ahead of scale‐up or audit readiness. History of driving cost efficiency while enabling growth. Exposure to SOC 2, ISO 27001, or GDPR compliance processes. What We Offer You will be reporting directly to the founders, who have two successful venture ...

GRC Analyst

Hiring Organisation
Rise Technical Recruitment
Location
London, United Kingdom
Employment Type
Permanent
Salary
£45000 - £55000/annum
across modern cloud environments. The ideal candidate will have experience across governance, risk and compliance activities, strong knowledge of frameworks such as ISO 27001, SOC 2, GDPR and DORA, and a solid understanding of cloud platforms including AWS, Azure and GCP. Strong communication skills and a customer-focused … clients to improve security programmes and regulatory compliance The Person: Good years of experience within cybersecurity, technology or GRC Strong understanding of ISO 27001, SOC 2, GDPR, DORA and related frameworks Experience with AWS, Azure and/or GCP environments Degree qualified in Cyber Security ...

Security GRC Analyst

Hiring Organisation
Lendable
Location
London, UK
organisation.What You’ll Be DoingFramework & Regulatory Alignment: Help maintain, improve, and scale our security compliance programmes, ensuring ongoing alignment with standards such as SOC 2, ISO 27001, and PCI-DSS, as well as regulator expectations and UK GDPR.Risk & Mitigation: Collaborate on identifying security risks across the business - including … Expertise: A strong, foundational understanding of security risk management principles and hands-on experience working with compliance frameworks (e.g. ISO 27001, PCI-DSS, or SOC 2).Risk-First & Pragmatic Mindset: A natural tendency to start with the "why" (the risk) rather than the checklist. You possess the ability ...

Information Security Governance Specialist

Hiring Organisation
Frontify
Location
London, UK
make informed decisions while supporting commercial success.You'll drive the day-to-day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements.You'll serve as the subject matter expert during audits and ensure our control environment remains effective and … years of experience in information security governance, GRC, or technology risk within a SaaS or cloud environment.You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional ...

Information Security Governance Specialist

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
informed decisions while supporting commercial success. You'll drive the day‐to‐day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements. You'll serve as the subject matter expert during audits and ensure our control environment remains effective … experience in information security governance, GRC, or technology risk within a SaaS or cloud environment. You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional frameworks ...

Information Security Analyst ( ISO 27001 and ISO 27018 )

Hiring Organisation
Alfa Financial Software
Location
London, UK
and procedures sharp and our compliance with ISO 27001 and ISO 27018 on point. You'll get involved in SSAE 18/ISAE 3402 SOC 1 Type 2 and SSAE 18 SOC 2 Type 2 assurance audits, spot opportunities to improve our security controls and … organisational skills. You write clear documentation and reports, and you can translate complex requirements for stakeholders at every level. You'll have at least 2 years' experience in a related role. Experience in a regulated industry, familiarity with other information security frameworks and assurance reports, and exposure to Jira ...

Head of Information Security

Hiring Organisation
Appcast
Location
London, UK
after-action reviews.Plan, facilitate and participate directly in tabletop cyber exercises and live cyber simulations at least quarterly.For any incident classified Severity 1 or 2, act as deputy incident decision-maker, holding delegated authority from the CFO to make time-critical operational decisions.Data Privacy & RegulatoryPartner with Legal … data.Embed Privacy by Design and data minimisation into discovery, design and delivery processes.Own the roadmap towards enterprise assurance frameworks, including UK Cyber Essentials and SOC 2 readiness.Prepare for external audits and assessments and ensure customer security questionnaire responses reflect actual control status.Third-Party & Cloud SecurityEstablish and ...

Infrastructure/DevOps Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
ready and high-performing. In this senior role, you’ll lead DevOps, observability, and compliance. Tasks include architecting cloud infrastructure for growth, prepping for SOC 2/ISO 27001 audits, and setting up CI/CD pipelines for all services. You’ll also manage logging, metrics, tracing, alerts … Security best practices knowledge. Networking concepts (VPCs, DNS, load balancers, VPNs, firewalls). Database management (PostgreSQL, MySQL, NoSQL) and storage. Python or Bash skills. SOC 2, ISO 27001, or GDPR exposure. Report directly to the founders with a chance to shape their future. Got what it takes? Apply ...

InfoSec Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
work closely with Engineering, Product, Legal, and Leadership to embed security into everything we build, while evolving our compliance posture across ISO-27001 and SOC-2 (including expansion into additional controls). What you’ll do: Own and execute Valarian’s end-to-end information security strategy Lead and … mature our security posture across compliance frameworks, including ISO-27001, SOC 2, and expansion into additional control frameworks Design and implement scalable security architecture across cloud, infrastructure, and applications Partner with Engineering to embed secure‐by‐design principles into development workflows Build, manage, and continuously improve security policies ...

Senior Manager - Application Security

Hiring Organisation
Appcast
Location
London, UK
metrics for secure development adoption, vulnerability resolution, and developer engagement.Collaborate with Privacy, Legal, and Compliance teams to ensure alignment with regulatory requirements (ISO 27001, SOC 2, GDPR, and emerging AI regulations).Foster a strong team culture based on collaboration, learning, and continuous improvement.What you’ll need10+ years … scaling developer engagement.Experience leading offensive security programs (penetration testing, red teaming, bug bounty).Practical understanding of governance and assurance frameworks such as ISO 27001, SOC 2, and OWASP SAMM.Familiarity with AI/LLM tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations) and the associated security and governance considerations.Experience ...

Senior Information Security Specialist

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
DoorDash’s risk register, compliance reporting, dashboards, metrics and executive-level risk communications. Support control mapping and harmonisation across frameworks such as ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, UK GDPR, NIS2, DORA, and emerging AI governance requirements. Promote a risk-based, pragmatic compliance culture that … control self‐assessments and remediation planning with cross‐functional stakeholders. You have strong working knowledge of security and privacy frameworks such as ISO 27001, SOC 2, GDPR or CCPA, and you can quickly assess applicability of new frameworks or regulatory requirements. You understand how security and privacy controls ...

Applied AI Security Architect

Hiring Organisation
Humanloop
Location
London, UK
architects, compliance teams, and DPOs to understand their security requirements and design solutions that meet European regulatory standards (GDPR, EU AI Act, DORA, NIS2, SOC 2, PCI-DSS, and national regulator expectations).Lead technical deep-dives on network architecture, EU data residency, data retention and Zero Data Retention … familiarity with the EU AI Act as it applies to foundation models.Experience navigating compliance frameworks relevant to European financial services and insurance (DORA, NIS2, SOC 2, PCI-DSS, and national regulators' guidance on AI/ML such as FCA/PRA, BaFin, ACPR, FINMA).A track record ...