ISO 27001 Lead Auditor Jobs in England

13 of 13 ISO 27001 Lead Auditor Jobs in England

ISO27001 Lead auditor

Central London, London, United Kingdom
Hybrid / WFH Options
Velocity Talent Ltd
Audit and Compliance Department: Information Security Certification About Us We are a UKAS-accredited certification body delivering independent audit and certification services across multiple management system standards, including ISO 9001, ISO 14001, and ISO 27001. Our goal is to help organisations demonstrate compliance, strengthen governance, and continuously improve. Were seeking a … to join our expanding audit team. Youll lead and conduct Information Security Management System (ISMS) audits in line with ISO / IEC 27001:2022 , ISO 17021 , and UKAS requirements. Key Responsibilities Plan, conduct, and report Stage 1, Stage 2, surveillance, and recertification audits for ISO 27001. Assess client ISMS implementations for conformity and effectiveness against ISO / IEC 27001:2022. Lead audits independently or as part of a multi-standard team (e.g. ISO 9001, ISO 22301, ISO 27701). Produce clear, objective audit More ❯
Employment Type: Permanent, Work From Home
Salary: £50,000
Posted:

Information Security Manager

Kemble, Gloucestershire, United Kingdom
ZeroAvia
scale operations, and maintain the trust of aviation authorities, partners, and passengers as we deliver zero-emission flight solutions. We are seeking an experienced Information Security Manager to lead our comprehensive information security programme across our UK operations. In this critical role, you will develop and implement security strategies that protect ZeroAvia's hydrogen-electric propulsion technologies … Experience: Minimum 8 years of information security experience, with at least 3 years in aerospace, aviation, or highly regulated industries Proven experience implementing and managing ISMS frameworks, preferably ISO 27001 certification Deep understanding of aviation cybersecurity regulations, including EASA requirements, CAA frameworks, or similar aviation security standards Experience with industrial control systems security, particularly … in safety-critical environments Demonstrated expertise in cybersecurity risk assessment and management methodologies specific to engineering and manufacturing environments Technical Expertise: Strong knowledge of cybersecurity frameworks (NIST, ISO 27001, aviation-specific standards) Experience with security architecture design for complex technical systems Understanding of aviation safety management systems and their integration with cybersecurity programmes Familiarity More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Information Security Analyst

Hereford, Herefordshire, England, United Kingdom
Hybrid / WFH Options
DCS Recruitment
for an experienced Information Security Analyst to join our client who will play a key role in driving compliance, governance, and continual improvement across key security frameworks including ISO 27001, PCI DSS, and Cyber Essentials Plus. Key Responsibilities: * Lead on the operation and continual improvement of the Information Security Management System … ISMS) * Coordinate internal and external audit readiness for ISO 27001, PCI DSS, and Cyber Essentials Plus * Draft and update information security policies, procedures, and technical standards * Work with procurement and commercial teams to support supplier assurance and risk assessment * Contribute to tender responses and bid processes, ensuring security and compliance requirements are met * Promote … legislation and standards relating to information and cyber security Key Skills & Experience: Essential: * Background in IT, Cyber Security, Information Systems, or a related discipline * Strong working knowledge of ISO 27001, PCI DSS, and Cyber Essentials Plus * Proven ability to support and prepare for audits, including evidence collation and audit readiness * Excellent attention to detail More ❯
Employment Type: Full-Time
Salary: £45,000 - £50,000 per annum
Posted:

GRC Consultant

England, United Kingdom
Bytes Software Services
enterprise IT, legal, or compliance roles, you will have a proven track record of delivering GRC consultancy across sectors. You will demonstrate strong knowledge of frameworks such as ISO, ISF, NIST CSF, NIS / NIS2, DORA, CIS, and Cyber Essentials, and the ability to explain complex requirements clearly to both technical and non-technical audiences. You will … the opportunity to work on high-impact projects within a forward-thinking, supportive environment that values expertise, innovation, and growth. KEY RESPONSIBILITIES: Deliver high-quality GRC services, including: ISO 27001 NIST Gap Analysis CAF Assessments PCI DSS CSMA, ISF, and CIS Assessments Develop and maintain in-house methodologies, templates, and delivery playbooks for core … SKILLS: Educational Requirements Degree in Information Security, Computer Science, Risk Management, or a related field, or equivalent professional experience. - ESSENTIAL Professional Experience One or more of the following: ISO 27001 Lead Auditor or Lead Implementer certification PCI DSS Qualified Security Assessor (QSA) or Internal Security More ❯
Posted:

IT Security Consultant

Bradford, West Yorkshire, England, United Kingdom
MLC Partners
Senior IT Security Specialist to lead and strengthen the cyber resilience of a complex public-sector programme. The postholder will play a pivotal role in developing, implementing, and governing security strategy, ensuring compliance with national standards, and embedding robust cyber practices across digital and IT estates. This is a senior strategic and technical leadership role, ideal for … local government IT environments. £700pd gross umbrella. Key Responsibilities Strategic Planning and Governance Develop, review, and maintain the IT Security Strategy aligned to organisational objectives and statutory duties. Lead the creation and enforcement of cybersecurity governance frameworks. Align security objectives with enterprise architecture and digital transformation strategy. Advise senior management and boards on cyber risk posture, incidents … security perspective. Policy, Procedure, and Guidance Oversight Review, update, and enforce security policies, standards, and guidance (e.g. Acceptable Use, Incident Response, Remote Access). Ensure compliance with NCSC, ISO 27001, NIST, Cyber Essentials, and GDPR frameworks. Clarify security roles and responsibilities across departments. Support Information Governance and Data Protection teams on policy alignment and More ❯
Employment Type: Temporary
Salary: £600 - £700 per day
Posted:

IT Risk, Controls and Security Manager

Surrey, United Kingdom
Hybrid / WFH Options
HAYS
plans (BCP). You will work closely with colleagues in IT to enhance the technology & control frameworks regarding information security compliance & cyber threat security. Risk & Compliance You will lead the development, implementation, and continuous improvement of our Information Security Management System (ISMS) in line with ISO 27001 and other regulatory standards. … Incident & Breach Management, Risk & Control Management, Vendor & System Assurance. What you'll need to succeed You will ideally have the following experience and qualifications:Professional certifications such as ISO 27001 Lead Implementer / Auditor as well as hands-on experience with auditing and maintaining accreditation for ISO 27001:2022 You will have a strong background in enterprise risk management, information governance, compliance, and risk assessment. Excellent communication skills - both written and verbal are required - with the ability to influence and educate. Knowledge of Cyber Essentials & SOC2 or other relevant standards would also be beneficial. What you'll get in return Salary More ❯
Employment Type: Permanent
Salary: GBP 50,000 - 70,000 Annual
Posted:

Senior Cyber Security Consultant

Market Harborough, Leicestershire, East Midlands, United Kingdom
Hybrid / WFH Options
4C Resourcing
our company, or if you have not taken steps to pursue Chartered Cyber Security Professional (ChCSP) status. This is a senior role for an experienced consultant who can lead engagements, provide authoritative advice, and help shape our cyber security services. You will work primarily in Audit & Assurance and Risk & Compliance, with the opportunity to contribute to Incident … and deliver client engagements across governance, risk and compliance (GRC), including audits, assessments and improvement plans aligned to frameworks such as ISO / IEC 27001, NCSC CAF, and PCI DSS. Lead independent assurance, review and test security policies, procedures and controls; identify gaps; and recommend pragmatic remediation strategies. Develop … Significant experience in cyber security consulting or assurance, ideally within the public sector. Deep knowledge of GRC frameworks and standards (e.g. CAF, ISO / IEC 27001, PCI DSS).Strong client-facing skills, able to communicate complex issues clearly to technical and non-technical audiences. Proven track record of delivering high-quality outputs on More ❯
Employment Type: Permanent, Work From Home
Salary: £90,000
Posted:

Security Risk Assurance Manager

South East, United Kingdom
Hybrid / WFH Options
Sanderson Government and Defence
of current threats, vulnerabilities, and best practices in security assurance Experience Required Experience in information security, risk management, or assurance roles. Desirable qualifications - CISM, CRISC, CISSP, CISA, CGEIT, ISO 27001 Lead Auditor (or equivalent) Hold an active and transferable SC clearance Strong analytical skills with the ability to … interpret technical and procedural evidence. Ability to work collaboratively within a multidisciplinary team. Familiarity with security frameworks and standards (e.g., ISO 27001, NIST, CIS Controls). Attention to detail and commitment to producing high-quality documentation. What's in it for You Remote / Hybrid working. Career Development: Continuous learning and professional growth. Benefits More ❯
Employment Type: Permanent, Work From Home
Posted:

Interim Cybersecurity Auditor

City of London, London, England, United Kingdom
Grant Thornton
market-leading risk, control and governance services, working with clients across a variety of industries and beyond. . Joining the Agile Talent Community as an Interim Cybersecurity Internal Auditor, you will have the freedom to work on projects that you choose, whether full or part-time within BRS and support our clients and internal teams on short … to medium-term assignments. Skills we are looking for We are seeking an experienced Cybersecurity Auditor for an interim assignment supporting client engagements across various sectors. This role involves conducting audits, assessing risk, and ensuring compliance with UK cybersecurity regulations and standards. You will work directly with our clients to evaluate their cybersecurity posture, identify gaps, and … Deliver cybersecurity audits for client organisations in line with UK regulations. Assess compliance with: UK GDPR & Data Protection Act 2018 NIS Regulations ISO / IEC 27001 Cyber Essentials / Plus Telecommunications (Security) Act 2021 Identify risks and provide actionable recommendations. Produce clear audit reports and present findings to client stakeholders. Support clients in More ❯
Employment Type: Contractor
Rate: Salary negotiable
Posted:

GRC Manager

Woking, Surrey, England, United Kingdom
Hybrid / WFH Options
Nomad Foods
a fast-paced environment, and want to make real impact at Europe’s leading frozen food company. Responsibilities: Overseeing cyber security governance efforts, ensuring alignment with frameworks like ISO 27001, NIST, NIS2 and GDPR, and regulatory standards. Identify, assess, and mitigate security risks across the organisation. Implement and maintain risk management processes, ensuring effective … skillset required for this position are: Graduate level in Cyber Security, Computer Science or similar. CRISC, CISM, CRM, CISA, CCP Practitioner SIRA, ISO / IEC 27001 Lead Auditor, or similar. 3-5 years’ experience in cyber governance, risk and compliance roles, preferably in the FMCG sector. What More ❯
Employment Type: Full-Time
Salary: Salary negotiable
Posted:

Information Security Analyst (GRC)

Hertfordshire, England, United Kingdom
Hybrid / WFH Options
ALTERED RESOURCING LTD
with a great benefit package also. This Information Security Analyst (GRC) role would suit someone with experience with information security risk assessments, reporting risks and who holds the ISO 27001 lead implementer / auditor certification. Any other certifications that you hold will be beneficial. Experience dealing with non More ❯
Employment Type: Full-Time
Salary: Competitive salary
Posted:

Head of Information Security Governance, Risk and Compliance & Awareness Arriva

England, United Kingdom
CyberNorth
Drives organisation-wide security governance and cyber maturity through standards compliance, assurance reviews, and gap analysis, be that Arriva policies and standards or industry recognised certifications such as ISO / IEC 27001, Cyber Essentials, NIS CAF, NIST CSF, CIS Controls. Oversees the development of a scalable Operational Technology (OT) Security Assurance Framework, including … Awareness Programme, including training strategy, annual compliance training content, communications plan, roadshows, and ongoing engagement. Knowledge, skills & experience Practitioner qualifications e.g. CISSP certification, CESG Listed Advisor (CLAS), ISO27001 Lead Auditor, Certified Information Security Manager (CISM) Knowledge of all areas of Cyber Security Evidencable extensive experience in information security or IT governance roles, including proven … cultural change, and increased risk literacy across organisations. Familiarity with audit lifecycles, regulatory compliance, control assurance, and data protection including a deep understanding of security control frameworks (e.g., ISO / IEC 27001, Cyber Essentials, NIS CAF, NIST CSF, CIS Controls, PCI-DSS). Knowledge of all areas of IT Security, including cyber security More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Procurement & Supply Chain Cyber Security Officer

Stevenage, Hertfordshire, England, United Kingdom
Hybrid / WFH Options
MBDA
management practices is desirable. Whilst not essential, one of the following qualifications is highly desirable: CISMP – Certificate In Information Security Management Principles CISM – Certified Information Security Manager ISO27001 Lead Auditor ISO27005 Certificated Security Risk Manager CSMP – Certified Security Management Professional Whilst not essential, understanding / experience of UK MoD Defence Conditions would be beneficial. More ❯
Employment Type: Full-Time
Salary: £45,000 - £50,000 per annum
Posted:
ISO 27001 Lead Auditor
England
10th Percentile
£54,075
25th Percentile
£60,625
Median
£67,500
75th Percentile
£75,000
90th Percentile
£85,500