1 to 25 of 104 Permanent SOC 2 Jobs in London

Information Security GRC Engineering Consultant

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
assurance toward scalable, repeatable control‐based implementation. Acting as a hands‐on, solutions‐driven GRC engineering consultant, translating regulatory and control requirements (PCI DSS, SOC 2, Visa KCX) into practical, implementable controls within our products, teams and cloud environments. Designing and implementing automation where it adds genuine value … providing appropriate responses to customer RFP questions and customer audits on topics such as cybersecurity, technology operations, and compliance with standards (e.g., PCI DSS, SOC 2). Responsibilities As a company we hire people with a willingness to adapt to a variable role, so along with ...

Senior Security Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
security design and architecture reviews, paired with the governance and process work that scales the program. You will partner on customer due‐diligence and SOC 2 evidence and turn security controls into repeatable workflows that fit how the business already works. You will apply that lens across … and DevOps to reduce risk through secure design and simplicity, not just added controls. Governance, Risk & Compliance Partner on customer due‐diligence (DDQ) and SOC 2 Type II evidence gathering, keeping compliance sustainable rather than fire‐drilled. Build repeatable security workflows that embed controls into existing engineering processes ...

Director, Compliance Audit – iLottery & Interactive

Hiring Organisation
Aristocrat
Location
Greater London, United Kingdom
Employment Type
Full Time
security, technology, and service delivery controls. Coordinate and lead all aspects of external audits and certifications supporting lottery customers, including but not limited to SOC 1, SOC 2, ISO 27001, WLA-SCS, PCI-DSS, and jurisdiction-specific requirements. Maintain audit readiness throughout all iLottery regions by conducting … and customer collaborators. Strong understanding of audit methodologies, internal controls, risk management, and governance frameworks. Experience with recognized industry benchmarks and certifications such as SOC 1, SOC 2, ISO 27001, PCI-DSS, WLA-SCS, NIST, COBIT, or comparable frameworks. Strong analytical, problem-solving, and decision-making capabilities. ...

Director, Compliance Audit – iLottery & Interactive

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
security, technology, and service delivery controls.* Coordinate and lead all aspects of external audits and certifications supporting lottery customers, including but not limited to SOC 1, SOC 2, ISO 27001, WLA-SCS, PCI-DSS, and jurisdiction-specific requirements.* Maintain audit readiness throughout all iLottery regions by conducting … and customer collaborators.* Strong understanding of audit methodologies, internal controls, risk management, and governance frameworks.* Experience with recognized industry benchmarks and certifications such as SOC 1, SOC 2, ISO 27001, PCI-DSS, WLA-SCS, NIST, COBIT, or comparable frameworks.* Strong analytical, problem-solving, and decision-making capabilities. ...

GRC Engineer - Platform Team

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
processes that keep Taktile secure, compliant, and continuously audit-ready. You'll be the engineering-minded backbone of our compliance program, turning frameworks like SOC 2, ISO 27001, GDPR, and the EU AI Act into automated, continuously-monitored controls rather than one-off, point-in-time checklists. This … customer security questionnaire in the morning and scripting AWS evidence collection in the afternoon. What you'll do Own continuous compliance end-to-end ; SOC 2, ISO 27001, and customer security reviews, keeping us audit-ready year-round rather than scrambling at renewal time. Manage and evolve ...

Head of Information Security

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
Define and own the GRC programme, including the ISMS, policy framework, risk registers, and audit readiness Implement and maintain compliance with ISO 27001, SOC 1, SOC 2, NIST CSF, GDPR, and relevant financial services regulations Understand the GRC landscape, implement appropriate controls, and adapt as the threat … progressive experience in information security, with at least 3 years in a senior or leadership role Hands‐on experience owning ISO 27001 and SOC 1 and SOC 2 programmes, not just supporting them Demonstrated experience managing security incidents end‐to‐end, including client and regulatory communications Strong ...

Senior Cybersecurity Consultant

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
creating operational friction. Responsibilities Lead penetration testing and vulnerability assessment engagements Design security architectures for cloud-native and hybrid environments Develop security compliance programs (SOC 2, ISO 27001, GDPR) Conduct incident response planning and tabletop exercises Advise C-level executives on security strategy and risk management Requirements 8+ … years in information security with consulting experience Deep expertise in penetration testing, vulnerability management, and threat modeling Knowledge of compliance frameworks: SOC 2, ISO 27001, GDPR, PCI-DSS Experience with cloud security (AWS Security Hub, Azure Defender, or GCP Security Command Center) CISSP, OSCP, or equivalent certification Nice ...

Information Security Manager

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
engage credibly with the wider infosec team and its systems. Critically review and challenge supplier technical proposals, architectures and security testing reports (e.g. Soc 2, penetration test reports) ensuring proportionate controls are in place. Provide informed input into security testing scope (e.g. Penetration testing, configuration reviews) and review … Nist ai rmf) or developing ai use-case risk assessments. Exposure to property technology would be a distinct advantage. Experience reviewing penetration test reports, soc 2 reports, or supplier security architectures. Experience with security tooling such as siem, email security platforms or vulnerability scanning. Hands‐on experience supporting ...

Senior DevSecOps Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
and operational runbooks Manage secrets, key custody, access controls, and infrastructure governance Deliver backup, disaster recovery, and business continuity strategies Drive compliance readiness for SOC 2, ISO 27001, and regulatory audits Partner with software engineering teams to ensure applications are secure, observable, and production‐ready Lead infrastructure migration … taking systems from early‐stage development through to secure production deployment Strong background in cloud infrastructure, automation, and operational security Experience supporting or leading SOC 2 Type II and/or ISO 27001 programmes Strong documentation and communication skills with the ability to create clear technical and compliance ...

Information Security & Compliance Manager

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
and compliance posture to leadership in clear, business-oriented terms. Compliance and certifications Drive certification and attestation efforts (e.g., ISO 27001 and/or SOC 2): design and maintain the control framework, own the documentation and evidence, and lead internal and external audits. Build a sustainable, “always-audit … . Strong, practical knowledge of GDPR and UK GDPR and day-to-day data protection. Hands‐on experience with ISO 27001 and/or SOC 2 implementation and audits. Working familiarity with the Microsoft security stack (Entra ID, Defender, Purview, Intune). Experience responding to client/customer ...

Platform Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
available, and optimized for both performance and cost. Key Responsibilities Architect, implement, and maintain cloud infrastructure to support rapid product growth. Prepare infrastructure for SOC 2/ISO 27001 audits, aligning with customer expectations. Build and maintain CI/CD pipelines for backend, frontend, and data services … Experience implementing reliability, security, and compliance measures ahead of scale‐up or audit readiness. History of driving cost efficiency while enabling growth. Exposure to SOC 2, ISO 27001, or GDPR compliance processes. What We Offer You will be reporting directly to the founders, who have two successful venture ...

Senior Security Engineer

Hiring Organisation
Jobleads-UK
Location
City Of London, England, United Kingdom
Compliance, Certification and Audit Readiness Own or co‐own delivery of compliance programmes, including ISO 27001, Cyber Essentials+, NHS DSPT, and the journey toward SOC 2 readiness. Support and contribute to ISO 42001 implementation as AI governance matures. Define and track pragmatic security KPIs such as time … authz patterns, secrets management, encryption, and cloud‐native security controls. Experience with compliance frameworks, particularly ISO 27001; familiarity with Cyber Essentials+, NHS DSPT, or SOC 2 is a strong advantage. Practical understanding of AI security risks, including prompt injection, LLM vulnerabilities, and agentic system threats, and ...

Information Security Governance Specialist

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
informed decisions while supporting commercial success. You'll drive the day‐to‐day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements. You'll serve as the subject matter expert during audits and ensure our control environment remains effective … experience in information security governance, GRC, or technology risk within a SaaS or cloud environment. You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional frameworks ...

Infrastructure/DevOps Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
ready and high-performing. In this senior role, you’ll lead DevOps, observability, and compliance. Tasks include architecting cloud infrastructure for growth, prepping for SOC 2/ISO 27001 audits, and setting up CI/CD pipelines for all services. You’ll also manage logging, metrics, tracing, alerts … Security best practices knowledge. Networking concepts (VPCs, DNS, load balancers, VPNs, firewalls). Database management (PostgreSQL, MySQL, NoSQL) and storage. Python or Bash skills. SOC 2, ISO 27001, or GDPR exposure. Report directly to the founders with a chance to shape their future. Got what it takes? Apply ...

InfoSec Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
work closely with Engineering, Product, Legal, and Leadership to embed security into everything we build, while evolving our compliance posture across ISO-27001 and SOC-2 (including expansion into additional controls). What you’ll do: Own and execute Valarian’s end-to-end information security strategy Lead and … mature our security posture across compliance frameworks, including ISO-27001, SOC 2, and expansion into additional control frameworks Design and implement scalable security architecture across cloud, infrastructure, and applications Partner with Engineering to embed secure‐by‐design principles into development workflows Build, manage, and continuously improve security policies ...

Senior Information Security Specialist

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
DoorDash’s risk register, compliance reporting, dashboards, metrics and executive-level risk communications. Support control mapping and harmonisation across frameworks such as ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, UK GDPR, NIS2, DORA, and emerging AI governance requirements. Promote a risk-based, pragmatic compliance culture that … control self‐assessments and remediation planning with cross‐functional stakeholders. You have strong working knowledge of security and privacy frameworks such as ISO 27001, SOC 2, GDPR or CCPA, and you can quickly assess applicability of new frameworks or regulatory requirements. You understand how security and privacy controls ...

Senior Sales Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
improve processes, thrive without rigid playbooks. Comfortable operating in scale‐up environments where customer needs inform product direction. Security & Compliance Acumen: Understand security requirements, SOC 2/ISO 27001, data residency, audit logging, encryption. Trusted conduit between Sales and Technology – able to articulate product capabilities on security RFPs … task management, audit trails, reporting), how they integrate with risk management systems, and typical architecture patterns in Financial Services and Payments. Security Concepts: Understand SOC 2/ISO 27001, data residency and sovereignty, encryption at‐rest/in‐transit, audit logging, and role‐based access control. Troubleshooting Mindset ...

Head of Security

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
security engineering, thoughtful governance and AI-first operations to ensure our customers, employees and partners can confidently rely on Geordie as we scale. With SOC 2 Type II and ISO 27001 already in place, your mission is to build an effective AI-native security programme that keeps certifications … hands-on individual contributor while building security functions from first principles. Experience maintaining security programs aligned to frameworks such as ISO 27001 and SOC 2. Strong understanding of modern software development, cloud infrastructure and secure engineering practices. Experience partnering closely with engineering organisations to build secure-by-design systems. ...

Senior Technical Programme Manager

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
platforms or ways of working across multiple teams. Experience working in regulated environments or with strict compliance requirements (e.g., GDPR, PCI‐DSS, SOC 2, DMA, and EU AI Act). Demonstrated ability to establish programme governance and operating models from scratch in ambiguous or fast‐moving environments. Experience … Communication Leadership Skills Decision‐Making Influencing Stakeholders Navigating Complexity Certifications & Qualifications PMP Agile Project Management Certification AWS Cloud Practitioner Industry Keywords GDPR PCI‐DSS SOC 2 DMA EU AI Act Tools & Technologies Jira Confluence Smartsheet Cloud‐Native Designs Microservices #J-18808-Ljbffr ...

IT Auditor & Controls Analyst

Hiring Organisation
DGH Recruitment
Location
City of London, London, United Kingdom
Employment Type
Permanent
Salary
£40,000
Auditor & Controls Analyst Key Experience: IT Audit, Technology Risk, ITGC, IT Application Controls, ISA 315, SOC 1, SOC 2. Required Skills/Experience: - Deliver testing over ITGCs, IT application controls, interface controls, automated controls and IPE with limited supervision. - Support ISA 315-aligned IT understanding and risk assessment … and risks arising from IT. * Prepare clear, review-ready workpapers, testing templates, issue summaries and RACMs. * Support financial statement audit-related technology controls assurance, SOC 1, SOC 2 and regulatory assurance engagements as required. Required Skills/Experience: - Experience in IT audit, technology risk, controls assurance ...

AI Security Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Build and implement controls, not writing recommendations for others to action. Own AWS security posture including account structure, IAM, RBAC, logging, and monitoring. Manage SOC 2 Type II controls and evidence for the Greenfield Product on AWS. Handle application-level hardening including authentication, API rate limiting, web security … and implementing controls, not just advising Strong AWS security knowledge: IAM, account structure, Well-Architected Framework, CloudTrail, GuardDuty, Config, Security Hub Driven a real SOC 2 Type II engagement: controls, evidence collection, and audit preparation, not just policy documentation Application security experience: auth, RBAC, common web vulnerabilities, ability ...

Security Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
among others. In addition, you will own and continuously improve Intigriti’s threat detection capabilities. This includes running day-to-day Security Operations Centre (SOC) activities, expanding log coverage, and building high-quality detections in our SIEM. You will use frameworks such as MITRE ATT&CK and MITRE D3FEND … availability of company data. Collaborate with the IT System Administrator to manage and enhance the overall network and system security. Incident Response, Threat Detection & SOC Operations Develop, maintain, and run incident response plans to address security incidents promptly and effectively. Run day-to-day SOC operations, including monitoring ...

IXI Platform Delivery Lead

Hiring Organisation
IXICO
Location
City of London, London, United Kingdom
planning, and release management Has undertaken formal training in at least one project management/process improvement discipline (e.g. Lean; Six Sigma; Agile; Prince 2) Experience working in a health-tech, medtech, or life-sciences software company Familiarity with working … within a highly regulated environment Knowledge of GCP, ISO13485, ISO27001 and/or other similar quality systems Familiarity with SOC 2 and SOC 3 frameworks and the practical controls needed to support secure, compliant platform delivery An engineering background Experience with DLPP or similar delivery lifecycle and ...

Cloud Platform Security Engineer Software engineering London

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
detection coverage against MITRE ATT&CK tactics and techniques. Identify and close visibility gaps across the cloud estate. Maintain alignment to PCI DSS, SOC2, ISO27001 NIST, and CIS frameworks. Produce documentation and evidence to support audit and assurance activities. AI Security Design and implement guardrails for AI/LLM systems … OWASP LLM Top 10, NIST AI RMF. Scripting proficiency in Python, PowerShell, or Bash for security automation. Strong grasp of PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud. Nice to have AZ-500, AWS Certified Security – Specialty, or equivalent cloud security ...

Information Security Director

Hiring Organisation
Jobleads-UK
Location
City of Westminster, England, United Kingdom
against cyber threats. We operate in a highly secure global SaaS organization that holds multiple certifications such as PCI‐DSS, ISO/IEC 27001, SOC, HIPAA, IRAP and works with a large, federated customer base. Responsibilities Develop and lead a team of Security Analysts and Engineers, providing management, mentorship … latest security threats, vulnerabilities and mitigation techniques. Advantageous Skills and Experience Experience working on projects ensuring compliance with PCI DSS, ISO/IEC 27001, SOC, HIPAA, IRAP controls. Knowledge of security compliance standards relevant to the SaaS industry such as PCI, GDPR, ISO 27001, SOC 2, NIST. ...