1 to 25 of 201 Permanent SOC 2 Jobs in London

Global Compliance Manager

Location
Greater London, England, United Kingdom
Manager role You’ll own compliance execution at Light. Reporting to the Head of Finance & Core Ops , you’ll be responsible for running our SOC 1, SOC 2, and PCI programmes end to end, keeping us audit-ready, and making sure controls actually work in practice. This … Kubernetes via Tanka/Jsonnet Datadog and CloudWatch for logging and monitoring 25 engineers scaling to 50+, distributed team What you’ll own Run SOC 1, SOC 2 (Type I & II), and PCI DSS etc compliance programmes Plan and manage audits, timelines, and auditor relationships Own evidence ...

Security GRC Manager

Location
Greater London, England, United Kingdom
these tools daily and know how to get real leverage from them. You'll own the operating rhythm for frameworks like ISO 27001, SOC 1, SOC 2, HIPAA and future standards that matter to our customers. You'll keep evidence organised, controls running, policies up to date … drive action across teams, and keep the bar high. Focus/Ownership You'll own Humaans' security compliance programme end‐to‐end, including ISO, SOC 1, SOC 2, HIPAA and future frameworks we choose to pursue. You'll manage audit cycles throughout the year, coordinating with external ...

Head of Information Security

Location
Greater London, England, United Kingdom
Valarian’s Zero-Trust security roadmap, policies, risk assessments, and executive reporting for leadership and the board Own end-to-end audit readiness for SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53 Embed DevSecOps and secure SDLC practices into CI/CD pipelines … Manager, Architect, or Director stepping into a first CISO-level leadership role Experience with Zero-Trust security roadmaps, policies, and risk assessments Experience with SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53 Experience embedding DevSecOps and secure SDLC practices into CI/ ...

Information Security Manager - Fintech - Hybrid

Location
City Of London, England, United Kingdom
Programme Maintain and continuously improve the Information Security Management System, firmwide information security programme, security policies, certifications and control framework, aligned to ISO 27001, SOC 2, DORA‐related customer obligations, applicable financial services expectations and Crédit Agricole Group requirements. Partner with Product, Engineering and Technology teams to embed … monitoring and exit arrangements. Own the client security assurance process, including security questionnaires, RFP/RFI responses, client audits, evidence packs, ISO 27001/SOC 2 artefacts, penetration test summaries, contractual security schedules and remediation tracking. Security Awareness & Planning Plan and maintain the annual security roadmap ...

Senior Security Engineer

Location
Greater London, England, United Kingdom
security design and architecture reviews, paired with the governance and process work that scales the program. You will partner on customer due‐diligence and SOC 2 evidence and turn security controls into repeatable workflows that fit how the business already works. You will apply that lens across … and DevOps to reduce risk through secure design and simplicity, not just added controls. Governance, Risk & Compliance Partner on customer due‐diligence (DDQ) and SOC 2 Type II evidence gathering, keeping compliance sustainable rather than fire‐drilled. Build repeatable security workflows that embed controls into existing engineering processes ...

SecOps Engineer

Hiring Organisation
WeDo Technology Solutions Limited
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £75,000 per annum
reducing technical debt and strengthening the overall cloud platform. Security currently sits within the DevOps/Platform function, and with the business working towards SOC 2 compliance by Q1 2027, they’re looking for someone who can bring together strong DevOps fundamentals with a security-first mindset. Responsibilities … processes Supporting ongoing client migrations into AWS and Azure Working alongside the wider Platform/DevOps and Compliance functions as the business progresses towards SOC 2 compliance Helping shift security further left within the engineering lifecycle Required Skills You don't need to be a career Security Engineer. ...

Enterprise Infrastructure Engineer

Location
Greater London, England, United Kingdom
align with a cloud-first strategy. Partner with Security to harden the Microsoft 365 tenant and infrastructure estate against relevant compliance frameworks (ISO 27001, SOC 2, DORA). Work closely with senior infrastructure engineers on infrastructure design decisions, escalating complex troubleshooting and design questions as needed. Change Control … Intune and Kandji are compliant, patched, and enrolled to policy. The Microsoft 365 tenant and wider SaaS estate meet relevant compliance frameworks (ISO 27001, SOC 2, DORA). Infrastructure changes are documented, tested, and follow IT change control processes without exception. Technical documentation, runbooks, and architecture records ...

Member of Technical Staff (Platform Leaning)

Location
Greater London, England, United Kingdom
deploy, operate and support wherever it needs to run. We expect you to be relentlessly AI native about it: instead of triaging alerts at 2 am, you'll build or deploy the agent that does it. Instead of reacting to scaling bottlenecks, you'll create systems that spot them … agentic tooling handles a growing share of the toil, and the infrastructure work you touch is compliant by default, keeping our ISO 27001 and SOC 2 journey unblocked. What you'll do No two days will be the same at Tessl! You'll have a high level ...

Compliance Officer

Location
Greater London, England, United Kingdom
ensuring that nothing falls through the gaps as the business grows. What you’ll be responsible for Audit & Certification You’ll own the ongoing SOC 2 Type II and ISO 27001:2022 audit lifecycle for an already‐certified organisation: surveillance and recertification audit planning, evidence readiness, auditor liaison … regulatory changes or operational changes, and advising leadership on required updates. Vendor & Third‐Party Risk Conduct and support structured vendor risk assessments, review SOC 2 reports, ISO certificates, and DPAs, maintain the vendor register, and ensure periodic reviews are completed on schedule. Infrastructure & Evidence Navigate AWS, Microsoft Entra ...

Security Engineer, Compliance Focus

Location
Greater London, England, United Kingdom
paperwork exercise at the edge of the business. It is a condition of doing business. We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure in several countries, and deploying into partner data centers. … actually working or only described. What You Will Be Doing Compliance Execution Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline. Operate our GRC platform (Vanta) day to day: configure and ...

Deputy Chief Technology Officer

Location
Greater London, England, United Kingdom
group-level data capability is live with a published catalog and cross-divisional SLAs. Regulatory & Cost Control: Engineering consistently hits all MiCA, DORA, and SOC 2 milestones while managing cloud and vendor spend against clear business-unit baselines. Key Responsibilities Engineering Delivery & Cadence: Run day-to-day global … group data pipelines and governance. Cybersecurity Execution & Compliance: Own the on-the-ground execution of The Company’s security and regulatory commitments (MiCA, DORA, SOC 2). Foster a "controls-by-design" engineering culture while respecting regulated divisional information walls. Talent, Budget & Scale: Manage the global engineering budget ...

IT Operations Manager

Location
Greater London, England, United Kingdom
when necessary to support them. You will own the IT strategy and roadmap, service performance, vendor procurement outcomes, and the IT control environment, including SOC 2, Cyber Essentials, and GDPR-related IT controls. You will plan and manage the project portfolio, hold vendors and the team to account … outcome, the Indeed relationship, and vendor performance Security, Risk & Compliance: Own the IT control environment and security posture, including policy, access standards, SOC 2, Cyber Essentials, GDPR-related IT controls, and audit outcomes. Direct the team's evidence gathering and control maintenance, and represent IT on security and ...

Head of Security

Location
Greater London, England, United Kingdom
and close the coverage gaps where some products are today outside the standard tooling. Governance, risk and compliance and vendor management Own ISO 27001, SOC 1, SOC 2 and PCI DSS compliance, the audit calendar, the compliance automation platform and the relationship with our auditors. Work with … software or SaaS company serving regulated enterprise customers, and of facing those customers on security matters. Working knowledge of ISO 27001 and SOC 2, and experience of being accountable for audits and certifications. PCI DSS experience is an advantage. Practical understanding of cloud security on AWS and Azure ...

Senior GRC Content Engineer

Location
Greater London, England, United Kingdom
auditors ask for, how evidence is collected and presented, findings and management responses Familiarity with third‐party/vendor risk: due‐diligence questionnaires, reading SOC 2 reports, contractual security requirements A solid understanding of the technical side of security (networks, systems, cloud, common attack patterns) — enough to keep … taught this material to real audiences (workshops, bootcamps, internal training, university teaching) Experience designing or facilitating tabletop exercises or crisis simulations Exposure to SOC 2 (Type 2) readiness or audit support, PCI‐DSS, or sector frameworks (HIPAA, CMMC, Cyber Essentials) Familiarity with GRC platforms (Drata, Vanta, OneTrust ...

VP of Security & Infrastructure

Location
Greater London, England, United Kingdom
search indexes. Regulatory & Compliance Engineering: Deliver and oversee the performance of technical controls, automated evidence extraction, and ongoing compliance for ISO 27001, ISO 27701, SOC 2 Type 2, HIPAA, EU AI Act, and Cyber Resilience Act. Third-Party & Supply-Chain Risk: Establish evaluation criteria and ongoing governance … and Mobile/Backend Engineering teams to ship user-facing features to roadmap. Audit Track Record: Successful execution and ongoing maintenance of ISO 27001, SOC 2, HIPAA, or equivalent certification frameworks through external audits. Data Privacy Systems: Deep technical experience implementing GDPR, automated data deletion, retention policies, DPIAs ...

Technical IT Manager/Leader

Location
Greater London, England, United Kingdom
meeting spaces, video conferencing and AV technology remain fully operational Troubleshoot network, hardware, software and endpoint issues Support IT security and compliance requirements, including SOC 2 and ISO 27001 Assist with technology projects and initiatives, including M&A integrations What we’re looking for Experience managing IT operations … managing endpoints and Mac environments Knowledge of core networking principles and troubleshooting Experience with conference room, Zoom/Teams and AV technology Experience with SOC 2 Type 2 and/or ISO 27001 compliance frameworks Strong organisational and project management skills Comfortable working with users at every ...

Staff Cloud Security Engineer (GCP) - Engine by Starling

Location
Greater London, England, United Kingdom
Access Transparency, relevant to deploying per-market for different banks' regulators Hands‐on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSS Experience automating security controls and compliance checks against standards and frameworks including SOC 2 ...

Senior Cloud Security Engineer (GCP) - Engine by Starling

Location
City Of London, England, United Kingdom
Access Transparency, relevant to deploying per-market for different banks' regulators Hands‐on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSS Experience automating security controls and compliance checks against standards and frameworks including SOC 2 ...

Senior Trust Security Analyst

Location
Greater London, England, United Kingdom
activities across engineering and security teams, ensuring alignment with agreed timelines and compliance requirements. Audit Audit Interpretation: Read and interpret third-party audit reports (SOC 2 Type II, ISO 27001, penetration test summaries) and represent findings to customers in questionnaires and security responses. Communication & Stakeholder Management Information Translation … experience responding to SIG, CAIQ, VSA, and bespoke enterprise/government security questionnaires. Compliance Knowledge: Working knowledge of Cyber Essentials Plus, ISO 27001, SOC 2 Type II, and at least one of PCI DSS, GDPR/UK GDPR, HIPAA, or FedRAMP. Technical Expertise: Strong technical understanding of security ...

Senior Cybersecurity Consultant

Location
Greater London, England, United Kingdom
creating operational friction. Responsibilities Lead penetration testing and vulnerability assessment engagements Design security architectures for cloud-native and hybrid environments Develop security compliance programs (SOC 2, ISO 27001, GDPR) Conduct incident response planning and tabletop exercises Advise C-level executives on security strategy and risk management Requirements 8+ … years in information security with consulting experience Deep expertise in penetration testing, vulnerability management, and threat modeling Knowledge of compliance frameworks: SOC 2, ISO 27001, GDPR, PCI-DSS Experience with cloud security (AWS Security Hub, Azure Defender, or GCP Security Command Center) CISSP, OSCP, or equivalent certification Nice ...

Head of Information Security

Location
Greater London, England, United Kingdom
assessments, and executive reporting for leadership and the board. Lead Compliance & Certifications: Own end‐to‐end audit readiness for enterprise and defense frameworks, including SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800‐53. Partner with Product & Engineering: Embed DevSecOps and secure SDLC practices into … cloud security (AWS/GCP), container isolation, cryptography, and network security. Audit & Compliance Track Record: Proven experience taking a high‐growth technology company through SOC 2 Type II or ISO 27001 certifications from start to finish. Stakeholder Management: Exceptional ability to bridge technical security requirements with business strategy ...

Senior Vulnerability Management Engineer

Location
Greater London, England, United Kingdom
Data Center, Network, and Application Infrastructure domains. The role is responsible for scanner architecture and tuning, risk-based prioritisation, integration with patch management and SOC functions, automation of VM workflows, and executive reporting. The engineer acts as the primary SME for vulnerability risk decisions and drives continuous improvement … escalation for L1 analysts; mentor team members and review scan configurations and reports. Lead or support internal VM audits and contribute to ISO 27001, SOC 2, or regulatory compliance evidence. TECHNICAL SKILLS & KNOWLEDGE Deep expertise in enterprise VM platforms: Qualys VMDR (including TruRisk), Tenable Security Centre/Tenable.io ...

Cyber Security Consultant

Hiring Organisation
Circle Group
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£70,000
implementation, maintenance and audit preparation. Advise clients against recognised frameworks including ISO 27001, NIST CSF and CIS Controls, as well as supporting SOC 2 and other compliance requirements. Develop and improve security policies, procedures and governance frameworks. Establish and maintain risk registers and support security governance forums. Support … reports and recommendations. Knowledge or experience in areas such as the following would be beneficial: ISO 27001/ISO 27005 NIST CSF CIS Controls SOC 2 NIS2/DORA Risk management and governance Security operations and monitoring Incident response Vulnerability management Cloud security, particularly Microsoft Azure and Microsoft ...

IT Operations & Cyber Lead

Location
Greater London, England, United Kingdom
Engineering on network separation and integration. Define and enforce IT and security standards, policies, and backup/recovery procedures that meet ISO 27001/SOC 2/GDPR expectations. Monitor and report IT and security health, highlighting risks, incidents, and KPIs to the IT Director, and feed improvements … and non-technical audiences. Comfortable in a start-up/scale-up environment — pragmatic, adaptable, and ownership-driven. Desirable Experience supporting ISO 27001 or SOC 2 certification efforts. Experience automating IT workflows via scripting (PowerShell, Python, or equivalent). Exposure to robotics, IoT, or AI product environments. Knowledge ...

Member of Technical Staff - Platform

Location
Greater London, England, United Kingdom
ready, highly available, and optimized for both performance and cost. Responsibilities Architect, implement, and maintain cloud infrastructure to support rapidproduct growth. Prepare infrastructure for SOC 2/ISO 27001 audits, aligning with customer expectations. Build and maintain CI/CD pipelines for backend, frontend, and data services … Experience implementing reliability, security, and compliance measures ahead of scale-up or audit readiness. History of driving cost efficiency while enabling growth. Exposure to SOC 2, ISO 27001, or GDPR compliance processes. What We Offer You will be reporting directly to the founders, who have two successfulventure-backed ...