1 to 25 of 288 Permanent SOC 2 Jobs in London

HIPAA Security Engineer

Hiring Organisation
Flo Health
Location
London, United Kingdom
Salary
£ 80 K
lead the design and operation of our US Healthcare security controls. You'll work directly with Product and Engineering teams to translate HIPAA and SOC 2 requirements into technical security controls across Flo's AWS multi-account environment - including EKS, Lambda, RDS, S3, VPC networking, IAM, and KMS.You … roadmap for HIPAA compliance and SOC 2 Type II certification, working closely with external auditors and professional services partners, and partnering with Engineering and Legal to build a secure, compliant platform for millions of users.Your ExperienceMust have:7+ years in security, compliance, or risk management (3+ ...

Global Compliance Manager

Location
Greater London, England, United Kingdom
Manager role You’ll own compliance execution at Light. Reporting to the Head of Finance & Core Ops , you’ll be responsible for running our SOC 1, SOC 2, and PCI programmes end to end, keeping us audit-ready, and making sure controls actually work in practice. This … Kubernetes via Tanka/Jsonnet Datadog and CloudWatch for logging and monitoring 25 engineers scaling to 50+, distributed team What you’ll own Run SOC 1, SOC 2 (Type I & II), and PCI DSS etc compliance programmes Plan and manage audits, timelines, and auditor relationships Own evidence ...

Security GRC Manager

Location
Greater London, England, United Kingdom
these tools daily and know how to get real leverage from them. You'll own the operating rhythm for frameworks like ISO 27001, SOC 1, SOC 2, HIPAA and future standards that matter to our customers. You'll keep evidence organised, controls running, policies up to date … drive action across teams, and keep the bar high. Focus/Ownership You'll own Humaans' security compliance programme end‐to‐end, including ISO, SOC 1, SOC 2, HIPAA and future frameworks we choose to pursue. You'll manage audit cycles throughout the year, coordinating with external ...

Head of Information Security

Location
Greater London, England, United Kingdom
Valarian’s Zero-Trust security roadmap, policies, risk assessments, and executive reporting for leadership and the board Own end-to-end audit readiness for SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53 Embed DevSecOps and secure SDLC practices into CI/CD pipelines … Manager, Architect, or Director stepping into a first CISO-level leadership role Experience with Zero-Trust security roadmaps, policies, and risk assessments Experience with SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53 Experience embedding DevSecOps and secure SDLC practices into CI/ ...

Senior Security Engineer

Location
Greater London, England, United Kingdom
security design and architecture reviews, paired with the governance and process work that scales the program. You will partner on customer due‐diligence and SOC 2 evidence and turn security controls into repeatable workflows that fit how the business already works. You will apply that lens across … and DevOps to reduce risk through secure design and simplicity, not just added controls. Governance, Risk & Compliance Partner on customer due‐diligence (DDQ) and SOC 2 Type II evidence gathering, keeping compliance sustainable rather than fire‐drilled. Build repeatable security workflows that embed controls into existing engineering processes ...

SecOps Engineer

Hiring Organisation
WeDo Technology Solutions Limited
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £75,000 per annum
reducing technical debt and strengthening the overall cloud platform. Security currently sits within the DevOps/Platform function, and with the business working towards SOC 2 compliance by Q1 2027, they’re looking for someone who can bring together strong DevOps fundamentals with a security-first mindset. Responsibilities … processes Supporting ongoing client migrations into AWS and Azure Working alongside the wider Platform/DevOps and Compliance functions as the business progresses towards SOC 2 compliance Helping shift security further left within the engineering lifecycle Required Skills You don't need to be a career Security Engineer. ...

Platform Security & Compliance Lead | Southwest, London | Hybrid, Permanent

Location
Greater London, England, United Kingdom
cloud-native. We need someone who is as comfortable getting hands-on with IAM, infrastructure and CI/CD as they are leading a SOC 2 programme or answering an enterprise customer’s security questions. What you’ll own: The security posture of the production AWS environment, including … and software supply-chain security, including dependencies, GitHub Actions, build provenance and container security Security monitoring, penetration testing, incident response and remediation The SOC 2 programme, including controls, evidence gathering, audits and ongoing improvements UK GDPR and PECR compliance, including DPAs, sub-processors, processing records and privacy requirements ...

Enterprise Infrastructure Engineer

Hiring Organisation
Boku
Location
London, United Kingdom
Salary
£ 80 K
decisions align with a cloud-first strategy.Partner with Security to harden the Microsoft 365 tenant and infrastructure estate against relevant compliance frameworks (ISO 27001, SOC 2, DORA).Collaboration & EscalationWork closely with senior infrastructure engineers on infrastructure design decisions, escalating complex troubleshooting and design questions as needed.Change Control & DocumentationEnsure … through Intune and Kandji are compliant, patched, and enrolled to policy.The Microsoft 365 tenant and wider SaaS estate meet relevant compliance frameworks (ISO 27001, SOC 2, DORA).Infrastructure changes are documented, tested, and follow IT change control processes without exception.Technical documentation, runbooks, and architecture records are kept current ...

Head of Platform Engineering (up to £225k)

Location
Greater London, England, United Kingdom
and building the team from scratch. You'll own the architecture, scale their Azure/AKS environment, and implement the security and compliance measures (SOC 2, ISO 27001, GDPR) that enable a product handling sensitive financial data. This is a rare seat: full mandate, significant resources, and …/CD across all services (backend, frontend, data), establishing product-wide observability, on-call rotations, and incident response. Lead the company through critical SOC 2 and ISO 27001 audits, implementing robust security, secrets management, and compliance measures (GDPR, FCA). What You Bring 10+ years in infrastructure ...

Senior Security Engineer

Location
Greater London, England, United Kingdom
Intropic's security and IT running, and build the systems that secure it further. Colleagues rely on the IT you run. Our SOC 2 relies on the evidence you keep clean. Where the work repeats, you build it away. This role is built for someone with solid … quickly and courteously. Administer our core SaaS estate, including Google Workspace and GitLab access, and script away the repetitive parts. GRC - 20% Keep our SOC 2 evidence current in Drata. Chase down failing monitors and automate evidence collection wherever possible. Help prepare for the yearly Type II audit ...

Security Engineer, Compliance Focus

Location
Greater London, England, United Kingdom
paperwork exercise at the edge of the business. It is a condition of doing business. We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure in several countries, and deploying into partner data centers. … actually working or only described. What You Will Be Doing Compliance Execution Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline. Operate our GRC platform (Vanta) day to day: configure and ...

Head of Technology

Location
Greater London, England, United Kingdom
banking, trading, portfolio or other regulated financial data where security, accuracy, resilience and governance are critical Security & compliance: owning the technology side of GDPR , SOC 2 Type 2 and ISO 27001 requirements, including preparing for and navigating audits, committees and regulatory scrutiny Technology resilience: ensuring appropriate disaster … Experience working with data platforms, data processing, data models and analytics Strong understanding of GDPR, information security, resilience and regulatory governance Some experience with SOC 2 Type 2/ISO 27001, including implementing controls, preparing for or managing audits and working through compliance requirements Experience navigating risk ...

Deputy Chief Technology Officer

Location
Greater London, England, United Kingdom
group-level data capability is live with a published catalog and cross-divisional SLAs. Regulatory & Cost Control: Engineering consistently hits all MiCA, DORA, and SOC 2 milestones while managing cloud and vendor spend against clear business-unit baselines. Key Responsibilities Engineering Delivery & Cadence: Run day-to-day global … group data pipelines and governance. Cybersecurity Execution & Compliance: Own the on-the-ground execution of The Company’s security and regulatory commitments (MiCA, DORA, SOC 2). Foster a "controls-by-design" engineering culture while respecting regulated divisional information walls. Talent, Budget & Scale: Manage the global engineering budget ...

Digital Third Party Assurance Assistant Manager

Hiring Organisation
BDO UK
Location
London, UK
Employment Type
Full-time
will support organisations in building trust and confidence with their customers, regulators and business partners. You will have the opportunity to work on SOC 1, SOC 2, ISAE 3402 and ISAE 3000 engagements, certification programmes such as ISO 27001 and ISO 42001, and assurance projects focused … relating to technology, cybersecurity, privacy or operational controls. Strong ITGC testing understanding. Strong understanding of assurance frameworks and standards, including one or more of: SOC 1/ISAE 3402, SOC 2, ISAE 3000, ISO 27001, PCI DSS, HITRUST or other recognised assurance or certification frameworks Understanding ...

Head of Security

Location
Greater London, England, United Kingdom
and close the coverage gaps where some products are today outside the standard tooling. Governance, risk and compliance and vendor management Own ISO 27001, SOC 1, SOC 2 and PCI DSS compliance, the audit calendar, the compliance automation platform and the relationship with our auditors. Work with … software or SaaS company serving regulated enterprise customers, and of facing those customers on security matters. Working knowledge of ISO 27001 and SOC 2, and experience of being accountable for audits and certifications. PCI DSS experience is an advantage. Practical understanding of cloud security on AWS and Azure ...

VP of Security & Infrastructure

Hiring Organisation
Flo Health
Location
London, United Kingdom
Salary
> £ 150 K
and search indexes.Regulatory & Compliance Engineering: Deliver and oversee the performance of technical controls, automated evidence extraction, and ongoing compliance for ISO 27001, ISO 27701, SOC 2 Type 2, HIPAA, EU AI Act, and Cyber Resilience Act.Third-Party & Supply-Chain Risk: Establish evaluation criteria and ongoing governance controls … Design, and Mobile/Backend Engineering teams to ship user-facing features to roadmap.Audit Track Record: Successful execution and ongoing maintenance of ISO 27001, SOC 2, HIPAA, or equivalent certification frameworks through external audits.Data Privacy Systems: Deep technical experience implementing GDPR, automated data deletion, retention policies, DPIAs, and ...

VP of Security & Infrastructure

Location
Greater London, England, United Kingdom
search indexes. Regulatory & Compliance Engineering: Deliver and oversee the performance of technical controls, automated evidence extraction, and ongoing compliance for ISO 27001, ISO 27701, SOC 2 Type 2, HIPAA, EU AI Act, and Cyber Resilience Act. Third-Party & Supply-Chain Risk: Establish evaluation criteria and ongoing governance … and Mobile/Backend Engineering teams to ship user-facing features to roadmap. Audit Track Record: Successful execution and ongoing maintenance of ISO 27001, SOC 2, HIPAA, or equivalent certification frameworks through external audits. Data Privacy Systems: Deep technical experience implementing GDPR, automated data deletion, retention policies, DPIAs ...

Global Risk and Compliance Manager

Hiring Organisation
Elixirr International
Location
London, United Kingdom
Salary
£ 80 K
including horizon scanning across jurisdictions.Reduce cyber risk exposure and strengthen cybersecurity governance in partnership with the CISO, aligning to global standards e.g. ISO 27001, SOC 2.Contribute to Board, Audit Committee and Annual Report risk disclosures.Risk & Compliance OperationsLead the Group’s risk and compliance programme, ensuring controls are well-designed … operational and scalable, particularly for SOC 2 Type 2 and ISO 27001.Maintain a centralised, audit-ready evidence repository and coordinate internal/external audits, client reviews and due diligence.Oversee remediation plans and ensure continuous evidence collection.Develop consistent, lightweight playbooks for vendor intake, audit readiness and control testing ...

Global Risk and Compliance Manager

Hiring Organisation
Elixirr International
Location
London, UK
Employment Type
Full-time
horizon scanning across jurisdictions. Reduce cyber risk exposure and strengthen cybersecurity governance in partnership with the CISO, aligning to global standards e.g. ISO 27001, SOC 2.Contribute to Board, Audit Committee and Annual Report risk disclosures. Risk & Compliance OperationsLead the Group's risk and compliance programme, ensuring controls are well … designed, operational and scalable, particularly for SOC 2 Type 2 and ISO 27001.Maintain a centralised, audit-ready evidence repository and coordinate internal/external audits, client reviews and due diligence. Oversee remediation plans and ensure continuous evidence collection. Develop consistent, lightweight playbooks for vendor intake, audit readiness ...

Technical IT Manager/Leader

Location
Greater London, England, United Kingdom
meeting spaces, video conferencing and AV technology remain fully operational Troubleshoot network, hardware, software and endpoint issues Support IT security and compliance requirements, including SOC 2 and ISO 27001 Assist with technology projects and initiatives, including M&A integrations What we’re looking for Experience managing IT operations … managing endpoints and Mac environments Knowledge of core networking principles and troubleshooting Experience with conference room, Zoom/Teams and AV technology Experience with SOC 2 Type 2 and/or ISO 27001 compliance frameworks Strong organisational and project management skills Comfortable working with users at every ...

Senior Cloud Security Engineer (GCP) - Engine by Starling

Hiring Organisation
Starling Bank
Location
London, United Kingdom
Salary
£ 80 K
and Access Transparency, relevant to deploying per-market for different banks' regulatorsHands-on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSSExperience automating security controls and compliance checks against standards and frameworks including SOC 2 ...

Staff Cloud Security Engineer (GCP) - Engine by Starling

Location
Greater London, England, United Kingdom
Access Transparency, relevant to deploying per-market for different banks' regulators Hands-on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSS Experience automating security controls and compliance checks against standards and frameworks including SOC 2 ...

Staff Cloud Security Engineer, GCP

Location
Greater London, England, United Kingdom
and hybrid GCP/on-premise connectivity Desirable: data-residency and regulated-workload controls such as Assured Workloads and Access Transparency Desirable: NIST, SOC 2, ISO 27001 and PCI DSS experience Desirable: container image provenance, container runtimes and software development lifecycle security Desirable: secure code reviews and SAST … Collaboration Certifications & Qualifications CISSP CCSP CISM GCP Professional Cloud Security Engineer CKA CKS Industry Keywords PCI DSS OWASP Top 10 MITRE ATT&CK Framework SOC 2 ISO 27001 Network Security Hybrid GCP Connectivity Data Residency Controls Secure Code Reviews Cryptography Management Tools & Technologies Terraform Security Command Center Cloud ...

Senior Cloud Security Engineer, GCP

Location
Greater London, England, United Kingdom
/IP, BGP, VPNs, firewalls, WAFs, IDS/IPS and hybrid GCP/on‐premise connectivity Desirable: Assured Workloads and Access Transparency Desirable: NIST, SOC 2, ISO 27001 and PCI DSS experience Desirable: container provenance, Sigstore, Notary, container runtimes and software development lifecycle security Desirable: SAST/DAST … Skills Problem-Solving Communication Active Listening Certifications & Qualifications CISSP CCSP CISM GCP Professional Cloud Security Engineer AWS Security Specialty Industry Keywords PCI DSS NIST SOC 2 ISO 27001 OWASP Top 10 MITRE ATT&CK Framework Network Security Threat Detection Cryptography Management Container Security Tools & Technologies GCP Cloud ...

Sr. Security Engineer - GRC Fintech & Financial Services EU/UK

Hiring Organisation
X
Location
London, United Kingdom
Salary
£ 80 K
improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e.g., ISO 27001, SOC 2) where they overlap.Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.BASIC QUALIFICATIONS:Bachelor's degree … logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations.Familiar with GDPR concepts that commonly intersect with information security (e.g., security of processing, breach notification timelines ...