1 to 25 of 185 Permanent SOC 2 Jobs in London

Senior Security & Compliance Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
sophisticated. Our stack spans Kubernetes on Azure, mobile and embedded AR, REST APIs, real‐time collaboration and AI‐powered data pipelines. We already hold SOC 2 Type II and ISO 27001, but as our product, customers and use of AI continue to evolve, we now need dedicated security … opportunity to become our first dedicated security specialist, with genuine ownership and influence across the business. While we already have established compliance activity and SOC 2 Type II and ISO 27001 certifications, security responsibilities currently sit across different teams. We’re now looking for someone who can bring ...

Information Security Analyst II (GRC)

Hiring Organisation
Checkout.com
Location
London, United Kingdom
Salary
£ 80 K
trusted point of contact for internal teams and external assessors.You will work across Checkout's core compliance frameworks including PCI DSS v4.0.1, ISO 27001, SOC 2, and emerging regulatory obligations such as DORA and the EU AI Act, supporting our global footprint across Europe, MENA, APAC, and … audit, or a closely related function, ideally within payments, financial services, or fintech.Practical working knowledge of PCI DSS (v4.0.1 preferred), ISO 27001, and SOC 2. Familiarity with DORA, NIST CSF, or the EU AI Act is a plus.Experience supporting or directly managing external audits and assessments, including evidence collation ...

Senior Security Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
security design and architecture reviews, paired with the governance and process work that scales the program. You will partner on customer due‐diligence and SOC 2 evidence and turn security controls into repeatable workflows that fit how the business already works. You will apply that lens across … and DevOps to reduce risk through secure design and simplicity, not just added controls. Governance, Risk & Compliance Partner on customer due‐diligence (DDQ) and SOC 2 Type II evidence gathering, keeping compliance sustainable rather than fire‐drilled. Build repeatable security workflows that embed controls into existing engineering processes ...

SecOps Engineer

Hiring Organisation
WeDo Technology Solutions Limited
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £75,000 per annum
reducing technical debt and strengthening the overall cloud platform. Security currently sits within the DevOps/Platform function, and with the business working towards SOC 2 compliance by Q1 2027, they’re looking for someone who can bring together strong DevOps fundamentals with a security-first mindset. Responsibilities … processes Supporting ongoing client migrations into AWS and Azure Working alongside the wider Platform/DevOps and Compliance functions as the business progresses towards SOC 2 compliance Helping shift security further left within the engineering lifecycle Required Skills You don't need to be a career Security Engineer. ...

Director, Compliance Audit – iLottery & Interactive

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
security, technology, and service delivery controls.* Coordinate and lead all aspects of external audits and certifications supporting lottery customers, including but not limited to SOC 1, SOC 2, ISO 27001, WLA-SCS, PCI-DSS, and jurisdiction-specific requirements.* Maintain audit readiness throughout all iLottery regions by conducting … and customer collaborators.* Strong understanding of audit methodologies, internal controls, risk management, and governance frameworks.* Experience with recognized industry benchmarks and certifications such as SOC 1, SOC 2, ISO 27001, PCI-DSS, WLA-SCS, NIST, COBIT, or comparable frameworks.* Strong analytical, problem-solving, and decision-making capabilities. ...

Security Engineer, Compliance Focus

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
paperwork exercise at the edge of the business. It is a condition of doing business. We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure in several countries, and deploying into partner data centers. … actually working or only described. What You Will Be Doing Compliance Execution Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline. Operate our GRC platform (Vanta) day to day: configure and ...

Senior Security & Compliance Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
sophisticated. Our stack spans Kubernetes on Azure, mobile and embedded AR, REST APIs, real-time collaboration and AI-powered data pipelines. We already hold SOC 2 Type II and ISO 27001, but as our product, customers and use of AI continue to evolve, we now need dedicated security … opportunity to become our first dedicated security specialist, with genuine ownership and influence across the business. While we already have established compliance activity and SOC 2 Type II and ISO 27001 certifications, security responsibilities currently sit across different teams. We're now looking for someone who can bring ...

Head of Information Security

Hiring Organisation
Duco
Location
London, United Kingdom
Salary
£ 100 K
Define and own the GRC programme, including the ISMS, policy framework, risk registers, and audit readiness– Implement and maintain compliance with ISO 27001, SOC 1, SOC 2, NIST CSF, GDPR, and relevant financial services regulations– Understand the GRC landscape, implement appropriate controls, and adapt as the threat … progressive experience in information security, with at least 3 years in a senior or leadership role- Hands-on experience owning ISO 27001 and SOC 1 and SOC 2 programmes, not just supporting them- Demonstrated experience managing security incidents end-to-end, including client and regulatory communications- Strong ...

Global Risk and Compliance Manager

Hiring Organisation
Elixirr International
Location
London, United Kingdom
Salary
£ 80 K
including horizon scanning across jurisdictions.Reduce cyber risk exposure and strengthen cybersecurity governance in partnership with the CISO, aligning to global standards e.g. ISO 27001, SOC 2.Contribute to Board, Audit Committee and Annual Report risk disclosures.Risk & Compliance OperationsLead the Group’s risk and compliance programme, ensuring controls are well-designed … operational and scalable, particularly for SOC 2 Type 2 and ISO 27001.Maintain a centralised, audit-ready evidence repository and coordinate internal/external audits, client reviews and due diligence.Oversee remediation plans and ensure continuous evidence collection.Develop consistent, lightweight playbooks for vendor intake, audit readiness and control testing ...

Senior Trust Security Analyst

Hiring Organisation
NICE Systems
Location
London, United Kingdom
Salary
£ 80 K
track remediation activities across engineering and security teams, ensuring alignment with agreed timelines and compliance requirements.AuditAudit Interpretation: Read and interpret third-party audit reports (SOC 2 Type II, ISO 27001, penetration test summaries) and represent findings to customers in questionnaires and security responses.Communication & Stakeholder ManagementInformation Translation: Gather detailed … Hands-on experience responding to SIG, CAIQ, VSA, and bespoke enterprise/government security questionnaires.Compliance Knowledge: Working knowledge of Cyber Essentials Plus, ISO 27001, SOC 2 Type II, and at least one of PCI DSS, GDPR/UK GDPR, HIPAA, or FedRAMP.Technical Expertise: Strong technical understanding of security ...

Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

Hiring Organisation
X
Location
London, United Kingdom
Salary
£ 80 K
improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e.g., ISO 27001, SOC 2) where they overlap.Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.BASIC QUALIFICATIONS:Bachelor's degree … logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations.Familiar with GDPR concepts that commonly intersect with information security (e.g., security of processing, breach notification timelines ...

Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e.g., ISO 27001, SOC 2) where they overlap. Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance. BASIC QUALIFICATIONS: Bachelor … logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations. Familiar with GDPR concepts that commonly intersect with information security (e.g., security of processing, breach ...

Senior Cybersecurity Consultant

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
creating operational friction. Responsibilities Lead penetration testing and vulnerability assessment engagements Design security architectures for cloud-native and hybrid environments Develop security compliance programs (SOC 2, ISO 27001, GDPR) Conduct incident response planning and tabletop exercises Advise C-level executives on security strategy and risk management Requirements 8+ … years in information security with consulting experience Deep expertise in penetration testing, vulnerability management, and threat modeling Knowledge of compliance frameworks: SOC 2, ISO 27001, GDPR, PCI-DSS Experience with cloud security (AWS Security Hub, Azure Defender, or GCP Security Command Center) CISSP, OSCP, or equivalent certification Nice ...

Senior Vulnerability Management Engineer

Hiring Organisation
HCLTech
Location
City of London, London, United Kingdom
Data Center, Network, and Application Infrastructure domains. The role is responsible for scanner architecture and tuning, risk-based prioritisation, integration with patch management and SOC functions, automation of VM workflows, and executive reporting. The engineer acts as the primary SME for vulnerability risk decisions and drives continuous improvement … escalation for L1 analysts; mentor team members and review scan configurations and reports. • Lead or support internal VM audits and contribute to ISO 27001, SOC 2, or regulatory compliance evidence. TECHNICAL SKILLS & KNOWLEDGE • Deep expertise in enterprise VM platforms: Qualys VMDR (including TruRisk), Tenable Security Centre/Tenable.io ...

GRC Pre-Sales Consultant / Solutions Engineer – EMEA

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
showcase how the company solves the customer's specific problem, including how the company automates and operationalises their GRC programmes across frameworks such as SOC 2, ISO 27001, and HIPAA. Validate the feasibility of standard and semi-complex integrations and confirm alignment with customer environments, workflows, and architectures. … trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. Now more than ever, making ...

Platform Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
available, and optimized for both performance and cost. Key Responsibilities Architect, implement, and maintain cloud infrastructure to support rapid product growth. Prepare infrastructure for SOC 2/ISO 27001 audits, aligning with customer expectations. Build and maintain CI/CD pipelines for backend, frontend, and data services … Experience implementing reliability, security, and compliance measures ahead of scale‐up or audit readiness. History of driving cost efficiency while enabling growth. Exposure to SOC 2, ISO 27001, or GDPR compliance processes. What We Offer You will be reporting directly to the founders, who have two successful venture ...

GRC Analyst

Hiring Organisation
Rise Technical
Location
London, United Kingdom
Salary
£ 50 K
practices across modern cloud environments.The ideal candidate will have experience across governance, risk and compliance activities, strong knowledge of frameworks such as ISO 27001, SOC 2, GDPR and DORA, and a solid understanding of cloud platforms including AWS, Azure and GCP. Strong communication skills and a customer-focused … directly with clients to improve security programmes and regulatory complianceThe Person:Good years of experience within cybersecurity, technology or GRCStrong understanding of ISO 27001, SOC 2, GDPR, DORA and related frameworksExperience with AWS, Azure and/or GCP environmentsDegree qualified in Cyber Security, IT or a related discipline ...

GRC Analyst

Hiring Organisation
Rise Technical Recruitment Limited
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£45,000 - £55,000 per annum
across modern cloud environments. The ideal candidate will have experience across governance, risk and compliance activities, strong knowledge of frameworks such as ISO 27001, SOC 2, GDPR and DORA, and a solid understanding of cloud platforms including AWS, Azure and GCP. Strong communication skills and a customer-focused … clients to improve security programmes and regulatory compliance The Person: Good years of experience within cybersecurity, technology or GRC Strong understanding of ISO 27001, SOC 2, GDPR, DORA and related frameworks Experience with AWS, Azure and/or GCP environments Degree qualified in Cyber Security ...

Information Security Governance Specialist

Hiring Organisation
Frontify
Location
London, United Kingdom
Salary
£ 80 K
make informed decisions while supporting commercial success.You'll drive the day-to-day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements.You'll serve as the subject matter expert during audits and ensure our control environment remains effective and … years of experience in information security governance, GRC, or technology risk within a SaaS or cloud environment.You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional ...

Information Security Governance Specialist

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
informed decisions while supporting commercial success. You'll drive the day‐to‐day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements. You'll serve as the subject matter expert during audits and ensure our control environment remains effective … experience in information security governance, GRC, or technology risk within a SaaS or cloud environment. You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional frameworks ...

Information Security Analyst ( ISO 27001 and ISO 27018 )

Hiring Organisation
Alfa Financial Software
Location
London, United Kingdom
Salary
£ 80 K
and procedures sharp and our compliance with ISO 27001 and ISO 27018 on point. You'll get involved in SSAE 18/ISAE 3402 SOC 1 Type 2 and SSAE 18 SOC 2 Type 2 assurance audits, spot opportunities to improve our security controls and … organisational skills. You write clear documentation and reports, and you can translate complex requirements for stakeholders at every level. You'll have at least 2 years' experience in a related role. Experience in a regulated industry, familiarity with other information security frameworks and assurance reports, and exposure to Jira ...

Head of Information Security

Hiring Organisation
MOO
Location
London, United Kingdom
Salary
£ 80 K
after-action reviews.Plan, facilitate and participate directly in tabletop cyber exercises and live cyber simulations at least quarterly.For any incident classified Severity 1 or 2, act as deputy incident decision-maker, holding delegated authority from the CFO to make time-critical operational decisions.Data Privacy & RegulatoryPartner with Legal … data.Embed Privacy by Design and data minimisation into discovery, design and delivery processes.Own the roadmap towards enterprise assurance frameworks, including UK Cyber Essentials and SOC 2 readiness.Prepare for external audits and assessments and ensure customer security questionnaire responses reflect actual control status.Third-Party & Cloud SecurityEstablish and ...

Infrastructure/DevOps Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
ready and high-performing. In this senior role, you’ll lead DevOps, observability, and compliance. Tasks include architecting cloud infrastructure for growth, prepping for SOC 2/ISO 27001 audits, and setting up CI/CD pipelines for all services. You’ll also manage logging, metrics, tracing, alerts … Security best practices knowledge. Networking concepts (VPCs, DNS, load balancers, VPNs, firewalls). Database management (PostgreSQL, MySQL, NoSQL) and storage. Python or Bash skills. SOC 2, ISO 27001, or GDPR exposure. Report directly to the founders with a chance to shape their future. Got what it takes? Apply ...

InfoSec Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
work closely with Engineering, Product, Legal, and Leadership to embed security into everything we build, while evolving our compliance posture across ISO-27001 and SOC-2 (including expansion into additional controls). What you’ll do: Own and execute Valarian’s end-to-end information security strategy Lead and … mature our security posture across compliance frameworks, including ISO-27001, SOC 2, and expansion into additional control frameworks Design and implement scalable security architecture across cloud, infrastructure, and applications Partner with Engineering to embed secure‐by‐design principles into development workflows Build, manage, and continuously improve security policies ...

Founding Engineer, Infrastructure & Platform

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
workloads Build systems for large-scale document processing Design secure execution environments for AI tools and agents Automate compliance evidence collection Build infrastructure supporting SOC 2, ISO 27001, and similar frameworks Develop internal tooling that allows engineers to ship quickly without compromising security or reliability What … with network segmentation Strong understanding of secrets management Awareness of software supply-chain security Experience designing and implementing compliance controls Hands-on ownership of SOC 2, ISO 27001, or comparable compliance programs Operational maturity from supporting production systems that matter Ability to balance rapid product delivery with security ...