1 to 25 of 90 Permanent SOC 2 Jobs in London

Information Security Analyst II (GRC)

Hiring Organisation
Checkout.com
Location
London, United Kingdom
Salary
£ 80 K
trusted point of contact for internal teams and external assessors.You will work across Checkout's core compliance frameworks including PCI DSS v4.0.1, ISO 27001, SOC 2, and emerging regulatory obligations such as DORA and the EU AI Act, supporting our global footprint across Europe, MENA, APAC, and … audit, or a closely related function, ideally within payments, financial services, or fintech.Practical working knowledge of PCI DSS (v4.0.1 preferred), ISO 27001, and SOC 2. Familiarity with DORA, NIST CSF, or the EU AI Act is a plus.Experience supporting or directly managing external audits and assessments, including evidence collation ...

Director, Compliance Audit – iLottery & Interactive

Hiring Organisation
Aristocrat Technologies
Location
London, United Kingdom
Salary
£ 80 K
operational, security, technology, and service delivery controls.Coordinate and lead all aspects of external audits and certifications supporting lottery customers, including but not limited to SOC 1, SOC 2, ISO 27001, WLA-SCS, PCI-DSS, and jurisdiction-specific requirements.Maintain audit readiness throughout all iLottery regions by conducting proactive … executive leadership and customer collaborators.Strong understanding of audit methodologies, internal controls, risk management, and governance frameworks.Experience with recognized industry benchmarks and certifications such as SOC 1, SOC 2, ISO 27001, PCI-DSS, WLA-SCS, NIST, COBIT, or comparable frameworks.Strong analytical, problem-solving, and decision-making capabilities.Excellent communication ...

Head of Information Security

Hiring Organisation
Duco
Location
London, United Kingdom
Salary
£ 100 K
Define and own the GRC programme, including the ISMS, policy framework, risk registers, and audit readiness– Implement and maintain compliance with ISO 27001, SOC 1, SOC 2, NIST CSF, GDPR, and relevant financial services regulations– Understand the GRC landscape, implement appropriate controls, and adapt as the threat … progressive experience in information security, with at least 3 years in a senior or leadership role- Hands-on experience owning ISO 27001 and SOC 1 and SOC 2 programmes, not just supporting them- Demonstrated experience managing security incidents end-to-end, including client and regulatory communications- Strong ...

Global Risk and Compliance Manager

Hiring Organisation
Elixirr International
Location
London, United Kingdom
Salary
£ 80 K
including horizon scanning across jurisdictions.Reduce cyber risk exposure and strengthen cybersecurity governance in partnership with the CISO, aligning to global standards e.g. ISO 27001, SOC 2.Contribute to Board, Audit Committee and Annual Report risk disclosures.Risk & Compliance OperationsLead the Group’s risk and compliance programme, ensuring controls are well-designed … operational and scalable, particularly for SOC 2 Type 2 and ISO 27001.Maintain a centralised, audit-ready evidence repository and coordinate internal/external audits, client reviews and due diligence.Oversee remediation plans and ensure continuous evidence collection.Develop consistent, lightweight playbooks for vendor intake, audit readiness and control testing ...

Senior Trust Security Analyst

Hiring Organisation
NICE Systems
Location
London, United Kingdom
Salary
£ 80 K
track remediation activities across engineering and security teams, ensuring alignment with agreed timelines and compliance requirements.AuditAudit Interpretation: Read and interpret third-party audit reports (SOC 2 Type II, ISO 27001, penetration test summaries) and represent findings to customers in questionnaires and security responses.Communication & Stakeholder ManagementInformation Translation: Gather detailed … Hands-on experience responding to SIG, CAIQ, VSA, and bespoke enterprise/government security questionnaires.Compliance Knowledge: Working knowledge of Cyber Essentials Plus, ISO 27001, SOC 2 Type II, and at least one of PCI DSS, GDPR/UK GDPR, HIPAA, or FedRAMP.Technical Expertise: Strong technical understanding of security ...

Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

Hiring Organisation
X
Location
London, United Kingdom
Salary
£ 80 K
improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e.g., ISO 27001, SOC 2) where they overlap.Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.BASIC QUALIFICATIONS:Bachelor's degree … logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations.Familiar with GDPR concepts that commonly intersect with information security (e.g., security of processing, breach notification timelines ...

Senior IT Infrastructure Engineer

Hiring Organisation
Nasuni
Location
London, United Kingdom
Salary
£ 80 K
cloud availability, performance, security posture, and cost efficiency through dashboards, alerts, tagging discipline, and operational reviews.Partner with Security on encryption, key management, network segmentation, SOC 2, ISO 27001, Zero Trust, and related cloud security initiatives.Collaborate with Engineering and IT Operations on migrations, SaaS/PaaS optimization, disaster recovery … and MFA.Strong troubleshooting skills across cloud, identity, networking, and SaaS environments.Clear documentation and communication skills for technical and cross-functional audiences.PreferredExperience supporting SOC 2, ISO 27001, Zero Trust, or similar compliance/security frameworks.Experience with FinOps practices, tagging policies, cost dashboards, or cloud spend optimization.Experience supporting disaster recovery ...

GRC Analyst

Hiring Organisation
Rise Technical
Location
London, United Kingdom
Salary
£ 50 K
practices across modern cloud environments.The ideal candidate will have experience across governance, risk and compliance activities, strong knowledge of frameworks such as ISO 27001, SOC 2, GDPR and DORA, and a solid understanding of cloud platforms including AWS, Azure and GCP. Strong communication skills and a customer-focused … directly with clients to improve security programmes and regulatory complianceThe Person:Good years of experience within cybersecurity, technology or GRCStrong understanding of ISO 27001, SOC 2, GDPR, DORA and related frameworksExperience with AWS, Azure and/or GCP environmentsDegree qualified in Cyber Security, IT or a related discipline ...

GRC Analyst

Hiring Organisation
Rise Technical Recruitment
Location
London, United Kingdom
Employment Type
Permanent
Salary
£45000 - £55000/annum
across modern cloud environments. The ideal candidate will have experience across governance, risk and compliance activities, strong knowledge of frameworks such as ISO 27001, SOC 2, GDPR and DORA, and a solid understanding of cloud platforms including AWS, Azure and GCP. Strong communication skills and a customer-focused … clients to improve security programmes and regulatory compliance The Person: Good years of experience within cybersecurity, technology or GRC Strong understanding of ISO 27001, SOC 2, GDPR, DORA and related frameworks Experience with AWS, Azure and/or GCP environments Degree qualified in Cyber Security ...

Security GRC Analyst

Hiring Organisation
Lendable
Location
London, United Kingdom
Salary
£ 80 K
organisation.What You’ll Be DoingFramework & Regulatory Alignment: Help maintain, improve, and scale our security compliance programmes, ensuring ongoing alignment with standards such as SOC 2, ISO 27001, and PCI-DSS, as well as regulator expectations and UK GDPR.Risk & Mitigation: Collaborate on identifying security risks across the business - including … Expertise: A strong, foundational understanding of security risk management principles and hands-on experience working with compliance frameworks (e.g. ISO 27001, PCI-DSS, or SOC 2).Risk-First & Pragmatic Mindset: A natural tendency to start with the "why" (the risk) rather than the checklist. You possess the ability ...

Senior Information Security Specialist

Hiring Organisation
Deliveroo
Location
London, United Kingdom
Salary
£ 80 K
mature DoorDash’s risk register, compliance reporting, dashboards, metrics and executive-level risk communications.Support control mapping and harmonization across frameworks such as ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, UK GDPR, NIS2, DORA, and emerging AI governance requirements.Promote a risk-based, pragmatic compliance culture that enables … workshops, control self-assessments and remediation planning with cross-functional stakeholders.You have strong working knowledge of security and privacy frameworks such as ISO 27001, SOC 2, GDPR or CCPA, and you can quickly assess applicability of new frameworks or regulatory requirements.You understand how security and privacy controls operate ...

Information Security Governance Specialist

Hiring Organisation
Frontify
Location
London, United Kingdom
Salary
£ 80 K
make informed decisions while supporting commercial success.You'll drive the day-to-day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements.You'll serve as the subject matter expert during audits and ensure our control environment remains effective and … years of experience in information security governance, GRC, or technology risk within a SaaS or cloud environment.You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional ...

Information Security Analyst ( ISO 27001 and ISO 27018 )

Hiring Organisation
Alfa Financial Software
Location
London, United Kingdom
Salary
£ 80 K
and procedures sharp and our compliance with ISO 27001 and ISO 27018 on point. You'll get involved in SSAE 18/ISAE 3402 SOC 1 Type 2 and SSAE 18 SOC 2 Type 2 assurance audits, spot opportunities to improve our security controls and … organisational skills. You write clear documentation and reports, and you can translate complex requirements for stakeholders at every level. You'll have at least 2 years' experience in a related role. Experience in a regulated industry, familiarity with other information security frameworks and assurance reports, and exposure to Jira ...

Head of Information Security

Hiring Organisation
MOO
Location
London, United Kingdom
Salary
£ 80 K
after-action reviews.Plan, facilitate and participate directly in tabletop cyber exercises and live cyber simulations at least quarterly.For any incident classified Severity 1 or 2, act as deputy incident decision-maker, holding delegated authority from the CFO to make time-critical operational decisions.Data Privacy & RegulatoryPartner with Legal … data.Embed Privacy by Design and data minimisation into discovery, design and delivery processes.Own the roadmap towards enterprise assurance frameworks, including UK Cyber Essentials and SOC 2 readiness.Prepare for external audits and assessments and ensure customer security questionnaire responses reflect actual control status.Third-Party & Cloud SecurityEstablish and ...

Senior Manager – Application Security

Hiring Organisation
Miro
Location
London, United Kingdom
Salary
£ 100 K
metrics for secure development adoption, vulnerability resolution, and developer engagement.Collaborate with Privacy, Legal, and Compliance teams to ensure alignment with regulatory requirements (ISO 27001, SOC 2, GDPR, and emerging AI regulations).Foster a strong team culture based on collaboration, learning, and continuous improvement.What you’ll need10+ years … scaling developer engagement.Experience leading offensive security programs (penetration testing, red teaming, bug bounty).Practical understanding of governance and assurance frameworks such as ISO 27001, SOC 2, and OWASP SAMM.Familiarity with AI/LLM tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations) and the associated security and governance considerations.Experience ...

HIPAA Security Engineer

Hiring Organisation
Flo Health
Location
London, United Kingdom
Salary
£ 80 K
Security Architecture team, you will lead the design and operation of our US Healthcare security controls. You will own the roadmap for HIPAA compliance and SOC2 Type II certification, partnering with Engineering and Legal to build a secure, compliant platform for millions of users.Key ResponsibilitiesCompliance Leadership: Lead annual SOC2 and HIPAA certifications, managing interfaces with external auditors and professional services.Policy & Risk: Define and maintain security policies; embed risk assessment activities within engineering processes and vendor management.Operational Excellence: Partner with control owners to automate evidence gathering and ensure controls reduce friction rather than creating it.Stakeholder Management: Serve ...

Applied AI Security Architect

Hiring Organisation
Humanloop
Location
London, United Kingdom
Salary
> £ 150 K
architects, compliance teams, and DPOs to understand their security requirements and design solutions that meet European regulatory standards (GDPR, EU AI Act, DORA, NIS2, SOC 2, PCI-DSS, and national regulator expectations).Lead technical deep-dives on network architecture, EU data residency, data retention and Zero Data Retention … familiarity with the EU AI Act as it applies to foundation models.Experience navigating compliance frameworks relevant to European financial services and insurance (DORA, NIS2, SOC 2, PCI-DSS, and national regulators' guidance on AI/ML such as FCA/PRA, BaFin, ACPR, FINMA).A track record ...

IT Auditor & Controls Analyst

Hiring Organisation
DGH Recruitment
Location
City of London, London, United Kingdom
Employment Type
Permanent
Salary
£40,000
Auditor & Controls Analyst Key Experience: IT Audit, Technology Risk, ITGC, IT Application Controls, ISA 315, SOC 1, SOC 2. Required Skills/Experience: - Deliver testing over ITGCs, IT application controls, interface controls, automated controls and IPE with limited supervision. - Support ISA 315-aligned IT understanding and risk assessment … and risks arising from IT. * Prepare clear, review-ready workpapers, testing templates, issue summaries and RACMs. * Support financial statement audit-related technology controls assurance, SOC 1, SOC 2 and regulatory assurance engagements as required. Required Skills/Experience: - Experience in IT audit, technology risk, controls assurance ...

Senior Endpoint & Security Engineer, London office

Hiring Organisation
8x8
Location
London, United Kingdom
Salary
£ 80 K
office. You handledevice provisioning, AV, asset management, and general on-site support.If you like the idea of setting the endpoint security direction for a 2,000-person global company while also being the person a colleague can walk up to when their laptop won't behave, this role … laptop backup coverage, policy, and periodic recovery testing.• Partner with 8x8's Security team on EDR/XDR endpoint tuning and incident triage• Produce SOC 2 and ISO 27001 evidence for endpoint controls during audit cyclesLondon Site Support• Provide walk-up and desk-side support for London office ...

Product Security Specialist for Medical Devices (Cyber Security)

Hiring Organisation
PA Consulting
Location
London, United Kingdom
Salary
£ 80 K
align with what you want to do. Hybrid working - our approach is to be in the office or on client site a minimum of 2 days per week. Work on a broad variety of projects and tech stacks for clients across seven sectors - no project is ever the same … residual risk after applying compensating security controls Experience implementing and demonstrating compliance to security frameworks such as NIST, IEC, HITRUST, HIPAA, GDPR, ISO 27001, SOC 2 Type 2 and familiarity working with Quality Management Systems Experience working with teams in a structured software development lifecycle process Excellent ...

Incident Management

Hiring Organisation
Bounteous
Location
London, United Kingdom
Salary
£ 70 K
LondonOperations – Operations/Contract/RemoteIncident Manager/Commander with SOC 1 or SOC 2 Audit experienceJob Description – Incident CommanderUK - RemoteDepartment: Service Management/Technology Operations.About the RoleWe are seeking a highly skilled Incident Commander to join our Fintech operations team. This role is critical in ensuring … processes, policies, runbooks, standard operating procedures (SOPs), and control frameworks (e.g., Risk Control Matrices).• Actively participate in internal and external audit cycles, including SOC Type 1 & Type 2 audits and regulatory examinations (e.g., CFTC, where applicable).• Join audit calls and walkthroughs with auditors, providing evidence, clarifications ...

Security Engineer - Security Operations

Hiring Organisation
Perk
Location
London, United Kingdom
Salary
£ 80 K
evolving security best practices.Secure SaaS applications and infrastructure by implementing security best practices, access controls, and continuous monitoring.Ensure compliance with security frameworks (ISO 27001, SOC 2, PCI-DSS) by developing governance, implementing necessary controls, and securing business processes.Collaborate with both non-engineering teams and IT to drive improvements … Technology, or a related field.You’re an accomplished Security Operations Engineer with a track record of threat detection engineering within a security operations center (SOC) or similar environment.You bring hands-on experience with SIEM solutions, EDR, intrusion detection/prevention systems, and other security tools.You're proficient in scripting ...

Business Security Director

Hiring Organisation
WPP
Location
London, United Kingdom
Salary
£ 70 K
innovation and business objectives.Nice to HaveExperience securing AI-enabled products, platforms or digital services.Familiarity with recognised security frameworks such as ISO 27001, ISO 42001, SOC2, NIST AI RMF or OWASP AI Top 10.Experience working with cloud environments including Azure, AWS or Google Cloud.Security certifications such as CISSP, CISM, CCSP ...

Professional Services Consultant - AI Security

Hiring Organisation
Cato Networks
Location
London, United Kingdom
Salary
£ 70 K
observability and monitoring stacks (e.g., CloudWatch, Prometheus, Grafana, Datadog)Knowledge of data sovereignty, residency requirements and compliance frameworks relevant to AI workloads (e.g., FedRAMP, SOC 2, ISO 27001, NIST 800-53, HIPPA, PCI, HITRUST, GDPR)Familiarity with data protection regulations and AI Security frameworks (e.g., GDPR, NIST ...

Senior Cloud Security Engineer

Hiring Organisation
Checkout.com
Location
London, United Kingdom
Salary
£ 80 K
alert triage.Map detection coverage against MITRE ATT&CK tactics and techniques. Identify and close visibility gaps across the cloud estate.Maintain alignment to PCI DSS, SOC2, ISO27001 NIST, and CIS frameworks. Produce documentation and evidence to support audit and assurance activities.AI SecurityDesign and implement guardrails for AI/LLM systems, covering … and frameworks: OWASP LLM Top 10, NIST AI RMF.Scripting proficiency in Python, PowerShell, or Bash for security automation.Strong grasp of PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud.Nice to haveAZ-500, AWS Certified Security – Specialty, or equivalent cloud security certification.Experience integrating ...