1 to 25 of 115 Permanent SOC 2 Jobs in London

Senior Information Security Analyst (GRC)

Hiring Organisation
Appcast
Location
London, UK
while shaping how the function evolves.You will take ownership of Checkout's most complex and high-stakes compliance programmes — PCI DSS v4.0.1, ISO 27001, SOC 2, DORA, and emerging obligations across our global licensed entities — while providing expert guidance to engineering, product, legal, and compliance teams … audit, or a closely related function, ideally within payments, financial services, or fintech.- Deep working knowledge of PCI DSS (v4.0.1 required), ISO 27001, and SOC 2. Practical experience with DORA, NIST CSF, the EU AI Act, or FCA/PRA obligations is strongly preferred.- Demonstrated track record of leading ...

Senior Security Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
security design and architecture reviews, paired with the governance and process work that scales the program. You will partner on customer due‐diligence and SOC 2 evidence and turn security controls into repeatable workflows that fit how the business already works. You will apply that lens across … and DevOps to reduce risk through secure design and simplicity, not just added controls. Governance, Risk & Compliance Partner on customer due‐diligence (DDQ) and SOC 2 Type II evidence gathering, keeping compliance sustainable rather than fire‐drilled. Build repeatable security workflows that embed controls into existing engineering processes ...

GRC Engineer - Platform Team

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
processes that keep Taktile secure, compliant, and continuously audit-ready. You'll be the engineering-minded backbone of our compliance program, turning frameworks like SOC 2, ISO 27001, GDPR, and the EU AI Act into automated, continuously-monitored controls rather than one-off, point-in-time checklists. This … customer security questionnaire in the morning and scripting AWS evidence collection in the afternoon. What you'll do Own continuous compliance end-to-end ; SOC 2, ISO 27001, and customer security reviews, keeping us audit-ready year-round rather than scrambling at renewal time. Manage and evolve ...

Director, Compliance Audit – iLottery & Interactive

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
security, technology, and service delivery controls.* Coordinate and lead all aspects of external audits and certifications supporting lottery customers, including but not limited to SOC 1, SOC 2, ISO 27001, WLA-SCS, PCI-DSS, and jurisdiction-specific requirements.* Maintain audit readiness throughout all iLottery regions by conducting … and customer collaborators.* Strong understanding of audit methodologies, internal controls, risk management, and governance frameworks.* Experience with recognized industry benchmarks and certifications such as SOC 1, SOC 2, ISO 27001, PCI-DSS, WLA-SCS, NIST, COBIT, or comparable frameworks.* Strong analytical, problem-solving, and decision-making capabilities. ...

Security Engineer, Compliance Focus

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
paperwork exercise at the edge of the business. It is a condition of doing business. We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure in several countries, and deploying into partner data centers. … actually working or only described. What You Will Be Doing Compliance Execution Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline. Operate our GRC platform (Vanta) day to day: configure and ...

Head of Information Security

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
Define and own the GRC programme, including the ISMS, policy framework, risk registers, and audit readiness Implement and maintain compliance with ISO 27001, SOC 1, SOC 2, NIST CSF, GDPR, and relevant financial services regulations Understand the GRC landscape, implement appropriate controls, and adapt as the threat … progressive experience in information security, with at least 3 years in a senior or leadership role Hands‐on experience owning ISO 27001 and SOC 1 and SOC 2 programmes, not just supporting them Demonstrated experience managing security incidents end‐to‐end, including client and regulatory communications Strong ...

Senior Cybersecurity Consultant

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
creating operational friction. Responsibilities Lead penetration testing and vulnerability assessment engagements Design security architectures for cloud-native and hybrid environments Develop security compliance programs (SOC 2, ISO 27001, GDPR) Conduct incident response planning and tabletop exercises Advise C-level executives on security strategy and risk management Requirements 8+ … years in information security with consulting experience Deep expertise in penetration testing, vulnerability management, and threat modeling Knowledge of compliance frameworks: SOC 2, ISO 27001, GDPR, PCI-DSS Experience with cloud security (AWS Security Hub, Azure Defender, or GCP Security Command Center) CISSP, OSCP, or equivalent certification Nice ...

Information Security Analyst

Hiring Organisation
Appcast
Location
London, UK
programme ownership at L3 and beyond.How You'll Make ImpactGovernance, Risk and Compliance- Support workstreams within Checkout's GRC programme, including ISO 27001, SOC 2, PCI DSS, and applicable regulatory obligations across our global licensed entities.- Assist with control evidence collection activities, coordinating with internal teams to gather … updated on changes and project progress.- Contribute to security awareness initiatives, promoting a security-conscious culture across Checkout.What We're Looking forExperience- 1 to 2 years of experience in information security, IT audit, or a closely related function, ideally within payments, financial services, or fintech.- Working knowledge ...

Information Security Manager

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
engage credibly with the wider infosec team and its systems. Critically review and challenge supplier technical proposals, architectures and security testing reports (e.g. Soc 2, penetration test reports) ensuring proportionate controls are in place. Provide informed input into security testing scope (e.g. Penetration testing, configuration reviews) and review … Nist ai rmf) or developing ai use-case risk assessments. Exposure to property technology would be a distinct advantage. Experience reviewing penetration test reports, soc 2 reports, or supplier security architectures. Experience with security tooling such as siem, email security platforms or vulnerability scanning. Hands‐on experience supporting ...

Senior DevSecOps Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
and operational runbooks Manage secrets, key custody, access controls, and infrastructure governance Deliver backup, disaster recovery, and business continuity strategies Drive compliance readiness for SOC 2, ISO 27001, and regulatory audits Partner with software engineering teams to ensure applications are secure, observable, and production‐ready Lead infrastructure migration … taking systems from early‐stage development through to secure production deployment Strong background in cloud infrastructure, automation, and operational security Experience supporting or leading SOC 2 Type II and/or ISO 27001 programmes Strong documentation and communication skills with the ability to create clear technical and compliance ...

Information Security & Compliance Manager

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
and compliance posture to leadership in clear, business-oriented terms. Compliance and certifications Drive certification and attestation efforts (e.g., ISO 27001 and/or SOC 2): design and maintain the control framework, own the documentation and evidence, and lead internal and external audits. Build a sustainable, “always-audit … . Strong, practical knowledge of GDPR and UK GDPR and day-to-day data protection. Hands‐on experience with ISO 27001 and/or SOC 2 implementation and audits. Working familiarity with the Microsoft security stack (Entra ID, Defender, Purview, Intune). Experience responding to client/customer ...

Platform Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
available, and optimized for both performance and cost. Key Responsibilities Architect, implement, and maintain cloud infrastructure to support rapid product growth. Prepare infrastructure for SOC 2/ISO 27001 audits, aligning with customer expectations. Build and maintain CI/CD pipelines for backend, frontend, and data services … Experience implementing reliability, security, and compliance measures ahead of scale‐up or audit readiness. History of driving cost efficiency while enabling growth. Exposure to SOC 2, ISO 27001, or GDPR compliance processes. What We Offer You will be reporting directly to the founders, who have two successful venture ...

GRC Analyst

Hiring Organisation
Rise Technical Recruitment
Location
London, United Kingdom
Employment Type
Permanent
Salary
£45000 - £55000/annum
across modern cloud environments. The ideal candidate will have experience across governance, risk and compliance activities, strong knowledge of frameworks such as ISO 27001, SOC 2, GDPR and DORA, and a solid understanding of cloud platforms including AWS, Azure and GCP. Strong communication skills and a customer-focused … clients to improve security programmes and regulatory compliance The Person: Good years of experience within cybersecurity, technology or GRC Strong understanding of ISO 27001, SOC 2, GDPR, DORA and related frameworks Experience with AWS, Azure and/or GCP environments Degree qualified in Cyber Security ...

Global Cybersecurity Manager - Client Assurance

Hiring Organisation
Boston Consulting Group
Location
London, UK
ensure consistent and compliant responses to client inquiries. Risk & Compliance Support: Support clients in understanding BCG's compliance with relevant frameworks (e.g. ISO 27001, SOC 2, GDPR, NIST) and help translate technical security concepts into business-relevant assurance responses. Quality & Continuous Improvement: Support the continuous improvement of Client … field. Experience supporting client-facing information security, assurance, audit, compliance, or advisory activities. Strong understanding of information security frameworks and standards including ISO 27001, SOC 2, NIST CSF, GDPR, and relevant regional data protection regulations. Experience responding to client security questionnaires, due diligence requests, audits, or RFPs, with ...

Information Security Governance Specialist

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
informed decisions while supporting commercial success. You'll drive the day‐to‐day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements. You'll serve as the subject matter expert during audits and ensure our control environment remains effective … experience in information security governance, GRC, or technology risk within a SaaS or cloud environment. You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional frameworks ...

Infrastructure/DevOps Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
ready and high-performing. In this senior role, you’ll lead DevOps, observability, and compliance. Tasks include architecting cloud infrastructure for growth, prepping for SOC 2/ISO 27001 audits, and setting up CI/CD pipelines for all services. You’ll also manage logging, metrics, tracing, alerts … Security best practices knowledge. Networking concepts (VPCs, DNS, load balancers, VPNs, firewalls). Database management (PostgreSQL, MySQL, NoSQL) and storage. Python or Bash skills. SOC 2, ISO 27001, or GDPR exposure. Report directly to the founders with a chance to shape their future. Got what it takes? Apply ...

InfoSec Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
work closely with Engineering, Product, Legal, and Leadership to embed security into everything we build, while evolving our compliance posture across ISO-27001 and SOC-2 (including expansion into additional controls). What you’ll do: Own and execute Valarian’s end-to-end information security strategy Lead and … mature our security posture across compliance frameworks, including ISO-27001, SOC 2, and expansion into additional control frameworks Design and implement scalable security architecture across cloud, infrastructure, and applications Partner with Engineering to embed secure‐by‐design principles into development workflows Build, manage, and continuously improve security policies ...

Senior Information Security Specialist

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
DoorDash’s risk register, compliance reporting, dashboards, metrics and executive-level risk communications. Support control mapping and harmonisation across frameworks such as ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, UK GDPR, NIS2, DORA, and emerging AI governance requirements. Promote a risk-based, pragmatic compliance culture that … control self‐assessments and remediation planning with cross‐functional stakeholders. You have strong working knowledge of security and privacy frameworks such as ISO 27001, SOC 2, GDPR or CCPA, and you can quickly assess applicability of new frameworks or regulatory requirements. You understand how security and privacy controls ...

GRC Consultant

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
compliance framework across the business Leading PCI DSS compliance initiatives Developing and improving GDPR processes and documentation Supporting security standards such as ISO 27001, SOC 2 and/or Cyber Essentials Creating policies, procedures and governance documentation Building and maintaining risk registers Preparing the business for future audits … roadmap to get everything where it needs to be. Ideally you'll have experience with: Governance, Risk & Compliance (GRC) PCI DSS GDPR ISO 27001, SOC 2 and/or Cyber Essentials Security governance and audit preparation Policy creation and documentation Risk management frameworks Working independently with multiple stakeholders ...

Head of Security

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
security engineering, thoughtful governance and AI-first operations to ensure our customers, employees and partners can confidently rely on Geordie as we scale. With SOC 2 Type II and ISO 27001 already in place, your mission is to build an effective AI-native security programme that keeps certifications … hands-on individual contributor while building security functions from first principles. Experience maintaining security programs aligned to frameworks such as ISO 27001 and SOC 2. Strong understanding of modern software development, cloud infrastructure and secure engineering practices. Experience partnering closely with engineering organisations to build secure-by-design systems. ...

Senior Technical Programme Manager

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
platforms or ways of working across multiple teams. Experience working in regulated environments or with strict compliance requirements (e.g., GDPR, PCI‐DSS, SOC 2, DMA, and EU AI Act). Demonstrated ability to establish programme governance and operating models from scratch in ambiguous or fast‐moving environments. Experience … Communication Leadership Skills Decision‐Making Influencing Stakeholders Navigating Complexity Certifications & Qualifications PMP Agile Project Management Certification AWS Cloud Practitioner Industry Keywords GDPR PCI‐DSS SOC 2 DMA EU AI Act Tools & Technologies Jira Confluence Smartsheet Cloud‐Native Designs Microservices #J-18808-Ljbffr ...

Senior Security & Compliance Engineer (ISO 27001 / SOC 2)

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Volta is seeking a Senior Manager, Cyber Security Engineering to lead the ISO 27001 and SOC 2 Type II program across a fast-growing, security‐minded infrastructure platform. You will own controls, evidence, and ISMS documentation while collaborating with platform engineers and external auditors. You’ll drive audit ...

Senior Endpoint & Security Engineer, London office

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
handle device provisioning, AV, asset management, and general on‐site support. If you like the idea of setting the endpoint security direction for a 2,000-person global company while also being the person a colleague can walk up to when their laptop won't behave, this role … laptop backup coverage, policy, and periodic recovery testing. Partner with 8x8's Security team on EDR/XDR endpoint tuning and incident triage Produce SOC 2 and ISO 27001 evidence for endpoint controls during audit cycles London Site Support Provide walk‐up and desk‐side support for London ...

Senior Endpoint & Security Engineer, London office

Hiring Organisation
Appcast
Location
London, UK
office. You handledevice provisioning, AV, asset management, and general on-site support.If you like the idea of setting the endpoint security direction for a 2,000-person global company while also being the person a colleague can walk up to when their laptop won't behave, this role … laptop backup coverage, policy, and periodic recovery testing.• Partner with 8x8's Security team on EDR/XDR endpoint tuning and incident triage• Produce SOC 2 and ISO 27001 evidence for endpoint controls during audit cyclesLondon Site Support• Provide walk-up and desk-side support for London office ...

Senior Manager, ITGC SOX & Internal Controls

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
controls, support remediation, and build organisational capability. You will also help drive alignment between ITGC/SOX requirements and Volta's broader ISO and SOC 2 compliance efforts. What You Will Be Doing Develop and maintain the scope of IT applications covered under SOX, and the ITGC workstream … controls and remediation efforts Deliver training and guidance to process owners and Heads of Department on key SOX requirements Support implementation of ISO and SOC 2 compliance requirements in collaboration with IT teams What You Bring 6-8 years' experience working on and leading SOX ITGC programmes Experience ...