1 to 25 of 130 Permanent SOC 2 Jobs in London

Senior Security Engineer

Location
Greater London, England, United Kingdom
security design and architecture reviews, paired with the governance and process work that scales the program. You will partner on customer due‐diligence and SOC 2 evidence and turn security controls into repeatable workflows that fit how the business already works. You will apply that lens across … and DevOps to reduce risk through secure design and simplicity, not just added controls. Governance, Risk & Compliance Partner on customer due‐diligence (DDQ) and SOC 2 Type II evidence gathering, keeping compliance sustainable rather than fire‐drilled. Build repeatable security workflows that embed controls into existing engineering processes ...

SecOps Engineer

Hiring Organisation
WeDo Technology Solutions Limited
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £75,000 per annum
reducing technical debt and strengthening the overall cloud platform. Security currently sits within the DevOps/Platform function, and with the business working towards SOC 2 compliance by Q1 2027, they’re looking for someone who can bring together strong DevOps fundamentals with a security-first mindset. Responsibilities … processes Supporting ongoing client migrations into AWS and Azure Working alongside the wider Platform/DevOps and Compliance functions as the business progresses towards SOC 2 compliance Helping shift security further left within the engineering lifecycle Required Skills You don't need to be a career Security Engineer. ...

Security Engineer, Compliance Focus

Location
Greater London, England, United Kingdom
paperwork exercise at the edge of the business. It is a condition of doing business. We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure in several countries, and deploying into partner data centers. … actually working or only described. What You Will Be Doing Compliance Execution Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline. Operate our GRC platform (Vanta) day to day: configure and ...

Global Risk and Compliance Manager

Hiring Organisation
Elixirr International
Location
London, UK
Employment Type
Full-time
horizon scanning across jurisdictions. Reduce cyber risk exposure and strengthen cybersecurity governance in partnership with the CISO, aligning to global standards e.g. ISO 27001, SOC 2.Contribute to Board, Audit Committee and Annual Report risk disclosures. Risk & Compliance OperationsLead the Group's risk and compliance programme, ensuring controls are well … designed, operational and scalable, particularly for SOC 2 Type 2 and ISO 27001.Maintain a centralised, audit-ready evidence repository and coordinate internal/external audits, client reviews and due diligence. Oversee remediation plans and ensure continuous evidence collection. Develop consistent, lightweight playbooks for vendor intake, audit readiness ...

Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

Location
Greater London, England, United Kingdom
improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e.g., ISO 27001, SOC 2) where they overlap. Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance. BASIC QUALIFICATIONS: Bachelor … logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations. Familiar with GDPR concepts that commonly intersect with information security (e.g., security of processing, breach ...

Senior Cybersecurity Consultant

Location
Greater London, England, United Kingdom
creating operational friction. Responsibilities Lead penetration testing and vulnerability assessment engagements Design security architectures for cloud-native and hybrid environments Develop security compliance programs (SOC 2, ISO 27001, GDPR) Conduct incident response planning and tabletop exercises Advise C-level executives on security strategy and risk management Requirements 8+ … years in information security with consulting experience Deep expertise in penetration testing, vulnerability management, and threat modeling Knowledge of compliance frameworks: SOC 2, ISO 27001, GDPR, PCI-DSS Experience with cloud security (AWS Security Hub, Azure Defender, or GCP Security Command Center) CISSP, OSCP, or equivalent certification Nice ...

Head of Information Security

Location
Greater London, England, United Kingdom
assessments, and executive reporting for leadership and the board. Lead Compliance & Certifications: Own end‐to‐end audit readiness for enterprise and defense frameworks, including SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800‐53. Partner with Product & Engineering: Embed DevSecOps and secure SDLC practices into … cloud security (AWS/GCP), container isolation, cryptography, and network security. Audit & Compliance Track Record: Proven experience taking a high‐growth technology company through SOC 2 Type II or ISO 27001 certifications from start to finish. Stakeholder Management: Exceptional ability to bridge technical security requirements with business strategy ...

Senior Vulnerability Management Engineer

Hiring Organisation
HCLTech
Location
City of London, London, United Kingdom
Data Center, Network, and Application Infrastructure domains. The role is responsible for scanner architecture and tuning, risk-based prioritisation, integration with patch management and SOC functions, automation of VM workflows, and executive reporting. The engineer acts as the primary SME for vulnerability risk decisions and drives continuous improvement … escalation for L1 analysts; mentor team members and review scan configurations and reports. • Lead or support internal VM audits and contribute to ISO 27001, SOC 2, or regulatory compliance evidence. TECHNICAL SKILLS & KNOWLEDGE • Deep expertise in enterprise VM platforms: Qualys VMDR (including TruRisk), Tenable Security Centre/Tenable.io ...

Cyber Security Consultant

Hiring Organisation
Circle Group
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£70,000
implementation, maintenance and audit preparation. Advise clients against recognised frameworks including ISO 27001, NIST CSF and CIS Controls, as well as supporting SOC 2 and other compliance requirements. Develop and improve security policies, procedures and governance frameworks. Establish and maintain risk registers and support security governance forums. Support … reports and recommendations. Knowledge or experience in areas such as the following would be beneficial: ISO 27001/ISO 27005 NIST CSF CIS Controls SOC 2 NIS2/DORA Risk management and governance Security operations and monitoring Incident response Vulnerability management Cloud security, particularly Microsoft Azure and Microsoft ...

IT Operations & Cyber Lead

Location
Greater London, England, United Kingdom
Engineering on network separation and integration. Define and enforce IT and security standards, policies, and backup/recovery procedures that meet ISO 27001/SOC 2/GDPR expectations. Monitor and report IT and security health, highlighting risks, incidents, and KPIs to the IT Director, and feed improvements … and non-technical audiences. Comfortable in a start-up/scale-up environment — pragmatic, adaptable, and ownership-driven. Desirable Experience supporting ISO 27001 or SOC 2 certification efforts. Experience automating IT workflows via scripting (PowerShell, Python, or equivalent). Exposure to robotics, IoT, or AI product environments. Knowledge ...

Principal Security & Cryptography Lead

Location
Greater London, England, United Kingdom
What You Will Ship in Your First 90 Days Milestone 1 Day 30: Complete formal verification of ephemero RAM buffer lifecycle management. Milestone 2 Milestone 3 Day 90: Lead continuous SOC 2 Type II audit automation and publish public cryptographic attestation. Key Responsibilities Design and audit episodic … automated continuous compliance pipelines. What We Look For Deep expertise in enterprise security, applied cryptography, confidential computing, and zero-trust architectures. Extensive experience managing SOC 2 Type II, ISO/IEC 27001:2022, and HIPAA regulatory audits. Familiarity with cloud security controls (AWS, GCP, Cloudflare) and secure software ...

Global Cybersecurity Manager - Client Assurance

Hiring Organisation
The Boston Consulting Group
Location
London, UK
Employment Type
Full-time
ensure consistent and compliant responses to client inquiries. Risk & Compliance Support: Support clients in understanding BCG's compliance with relevant frameworks (e.g. ISO 27001, SOC 2, GDPR, NIST) and help translate technical security concepts into business-relevant assurance responses. Quality & Continuous Improvement: Support the continuous improvement of Client … field. Experience supporting client-facing information security, assurance, audit, compliance, or advisory activities. Strong understanding of information security frameworks and standards including ISO 27001, SOC 2, NIST CSF, GDPR, and relevant regional data protection regulations. Experience responding to client security questionnaires, due diligence requests, audits, or RFPs, with ...

Solutions Engineer (Upmarket, Pre-Sales) - EMEA

Location
Greater London, England, United Kingdom
demonstrations that showcase how Vanta solves the customer's specific problem, including how Vanta automates and operationalises their GRC programmes across frameworks such as SOC 2, ISO 27001, and HIPAA. Validate the feasibility of standard and semi-complex integrations and confirm alignment with customer environments, workflows, and architectures. … trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. Now more than ever, making ...

Cyber Security Manager

Location
Greater London, England, United Kingdom
service and facilities that sit underneath all of it. The part that makes this role unusual: we are not building a twenty-person SOC, we are building an autonomous one and we have not built it yet. The first job is to take the estate as it is, establish … standard, hold it, and be the escalation point when it is not met. Assurance and evidence Produce operational evidence for ISO 27001 and SOC 2 continuously, as a by-product of the work, not in an audit sprint. Answer the operational half of client due diligence so commercial ...

Information Security Governance Specialist

Location
Greater London, England, United Kingdom
informed decisions while supporting commercial success. You'll drive the day‐to‐day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements. You'll serve as the subject matter expert during audits and ensure our control environment remains effective … experience in information security governance, GRC, or technology risk within a SaaS or cloud environment. You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional frameworks ...

Information Security Analyst ( ISO 27001 and ISO 27018 )

Hiring Organisation
Alfa Financial Software
Location
London, UK
Employment Type
Full-time
and procedures sharp and our compliance with ISO 27001 and ISO 27018 on point. You'll get involved in SSAE 18/ISAE 3402 SOC 1 Type 2 and SSAE 18 SOC 2 Type 2 assurance audits, spot opportunities to improve our security controls and … organisational skills. You write clear documentation and reports, and you can translate complex requirements for stakeholders at every level. You'll have at least 2 years' experience in a related role. Experience in a regulated industry, familiarity with other information security frameworks and assurance reports, and exposure to Jira ...

Information Security Analyst

Hiring Organisation
FundApps
Location
Greater London, United Kingdom
Employment Type
Full Time
Salary
60000 to 65000 GBP Annually
Information Security Management System. As an Information Security Analyst, you will help operate and improve the controls that support our ISO 27001 and SOC 2 programmes, while also getting involved in the real security work that happens across a growing SaaS business. You will not be expected … helpful, trusted partner in the way FundApps builds, buys and operates technology. Taking full, end-to-end ownership of FundApps’ ISO 27001 and SOC 2 controls operation, managing every stage from initial evidence collection and control checks through to remediation tracking and comprehensive audit preparation. Organising and chairing ...

Senior Manager - Application Security

Hiring Organisation
Miro
Location
London, UK
Employment Type
Full-time
secure development adoption, vulnerability resolution, and developer engagement. Collaborate with Privacy, Legal, and Compliance teams to ensure alignment with regulatory requirements (ISO 27001, SOC 2, GDPR, and emerging AI regulations).Foster a strong team culture based on collaboration, learning, and continuous improvement. What you'll need10+ years … developer engagement. Experience leading offensive security programs (penetration testing, red teaming, bug bounty).Practical understanding of governance and assurance frameworks such as ISO 27001, SOC 2, and OWASP SAMM.Familiarity with AI/LLM tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations) and the associated security and governance considerations. ...

Applied AI Security Architect

Location
Greater London, England, United Kingdom
architects, compliance teams, and DPOs to understand their security requirements and design solutions that meet European regulatory standards (GDPR, EU AI Act, DORA, NIS2, SOC 2, PCI-DSS, and national regulator expectations). Lead technical deep-dives on network architecture, EU data residency, data retention and Zero Data … with the EU AI Act as it applies to foundation models. Experience navigating compliance frameworks relevant to European financial services and insurance (DORA, NIS2, SOC 2, PCI-DSS, and national regulators' guidance on AI/ML such as FCA/PRA, BaFin, ACPR, FINMA). A track record ...

Head of Security

Location
Greater London, England, United Kingdom
security engineering, thoughtful governance and AI-first operations to ensure our customers, employees and partners can confidently rely on Geordie as we scale. With SOC 2 Type II and ISO 27001 already in place, your mission is to build an effective AI-native security programme that keeps certifications … hands-on individual contributor while building security functions from first principles. Experience maintaining security programs aligned to frameworks such as ISO 27001 and SOC 2. Strong understanding of modern software development, cloud infrastructure and secure engineering practices. Experience partnering closely with engineering organisations to build secure-by-design systems. ...

Senior Technical Programme Manager

Location
Greater London, England, United Kingdom
platforms or ways of working across multiple teams. Experience working in regulated environments or with strict compliance requirements (e.g., GDPR, PCI‐DSS, SOC 2, DMA, and EU AI Act). Demonstrated ability to establish programme governance and operating models from scratch in ambiguous or fast‐moving environments. Experience … Communication Leadership Skills Decision‐Making Influencing Stakeholders Navigating Complexity Certifications & Qualifications PMP Agile Project Management Certification AWS Cloud Practitioner Industry Keywords GDPR PCI‐DSS SOC 2 DMA EU AI Act Tools & Technologies Jira Confluence Smartsheet Cloud‐Native Designs Microservices #J-18808-Ljbffr ...

GRC Analyst

Location
Greater London, England, United Kingdom
this role will grow with them. What You'll Do Own end-to-end project management of the compliance programme: support ISO 27001/SOC 2 audits, manage the policy lifecycle, and handle customer security questionnaires and KYC onboarding Manage data protection operations and training, with UK GDPR … work directly with Finance and Engineering/Technology leadership, not just within a compliance team Nice to Have Exposure to ISO 27001 or SOC 2 audit cycles Exposure to business continuity or major incident processes Familiarity with AI governance or emerging AI regulation Interest in health & safety, environmental ...

Senior Security & Compliance Engineer (ISO 27001 / SOC 2)

Location
Greater London, England, United Kingdom
Volta is seeking a Senior Manager, Cyber Security Engineering to lead the ISO 27001 and SOC 2 Type II program across a fast-growing, security‐minded infrastructure platform. You will own controls, evidence, and ISMS documentation while collaborating with platform engineers and external auditors. You’ll drive audit ...

Senior Endpoint & Security Engineer, London office

Location
Greater London, England, United Kingdom
handle device provisioning, AV, asset management, and general on‐site support. If you like the idea of setting the endpoint security direction for a 2,000-person global company while also being the person a colleague can walk up to when their laptop won't behave, this role … laptop backup coverage, policy, and periodic recovery testing. Partner with 8x8's Security team on EDR/XDR endpoint tuning and incident triage Produce SOC 2 and ISO 27001 evidence for endpoint controls during audit cycles London Site Support Provide walk‐up and desk‐side support for London ...

Senior Manager, ITGC SOX & Internal Controls

Location
Greater London, England, United Kingdom
controls, support remediation, and build organisational capability. You will also help drive alignment between ITGC/SOX requirements and Volta's broader ISO and SOC 2 compliance efforts. What You Will Be Doing Develop and maintain the scope of IT applications covered under SOX, and the ITGC workstream … controls and remediation efforts Deliver training and guidance to process owners and Heads of Department on key SOX requirements Support implementation of ISO and SOC 2 compliance requirements in collaboration with IT teams What You Bring 6-8 years' experience working on and leading SOX ITGC programmes Experience ...