1 to 25 of 48 ISO 27001 Lead Auditor Jobs in the UK

Security Engineer, Compliance Focus

Location
Greater London, England, United Kingdom
here is not a paperwork exercise at the edge of the business. It is a condition of doing business. We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure … control is actually working or only described. What You Will Be Doing Compliance Execution Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline. Operate our GRC platform ...

Senior Cyber Risk and Assurance Analyst

Hiring Organisation
Bank of England
Location
London, United Kingdom
Salary
£ 60 K
choices simply and effectively Relevant professional qualification (e.g. CISSP, BCS Foundation Certificate in Data Protection, BCS CISMP, ISO / IEC 27001 Foundation, BCS Foundation Certificate in Cyber Security, CompTIA Security+, ISC2 Certified in Cybersecurity, BCS Foundation Certificate in IT, CompTIA ITF+, CompTIA A+ … CompTIA Network+, ISO 31000 Foundation). Essential Criteria Attention to detail and a structured approach to workEager to learn about IT network architecture and components, software / application security, infrastructure security, cloud. Active interest in new technical concepts and / or technologies. Good stakeholder collaboration skills. Desirable ...

Cyber Security Consultant

Hiring Organisation
Moore Kingston Smith
Location
London, United Kingdom
Salary
£ 45 K
reports, risk assessments, and advisory outputs.Collaborate with technical and business stakeholders to design or enhance security control environments aligned to frameworks such as ISO 27001, NIST CSF, CIS Controls, and Cyber Essentials.Maintain up-to-date knowledge of cyber threats, mitigation strategies, regulatory requirements … internal methodologies and security services.Build and maintain strong client relationships with a service-focused mindset.Identify client challenges and future needs that may lead to service expansion opportunities.Contribute to business development and client growth by supporting proposal creation, project scoping, thought leadership (e.g., blogs, webinars), and collaborating ...

Cyber Security Consultant

Hiring Organisation
Moore Kingston Smith
Location
London, UK
Employment Type
Full-time
risk assessments, and advisory outputs. Collaborate with technical and business stakeholders to design or enhance security control environments aligned to frameworks such as ISO 27001, NIST CSF, CIS Controls, and Cyber Essentials. Maintain up-to-date knowledge of cyber threats, mitigation strategies, regulatory requirements … methodologies and security services. Build and maintain strong client relationships with a service-focused mindset. Identify client challenges and future needs that may lead to service expansion opportunities. Contribute to business development and client growth by supporting proposal creation, project scoping, thought leadership (e.g., blogs, webinars ...

Security Manager

Hiring Organisation
Emovis
Location
Leeds, England, United Kingdom
technical security requirements with governance, compliance, and stakeholder engagement. Key Responsibilities · Manage and maintain compliance with security standards and accreditations including PCI DSS, ISO 27001, ISO 22301, Cyber Essentials Plus and IT Health Checks. · Conduct internal audits, control reviews, and risk … Security Manager or similar information security role. · Strong understanding of cyber security, governance, risk, and compliance frameworks. · Extensive knowledge of PCI DSS, ISO 27001, Cyber Essentials Plus, and data protection requirements. · Experience with Microsoft 365, Azure, AWS, vulnerability management, and SIEM tools. · Strong communication ...

Security Manager (EMEA)

Hiring Organisation
Emovis operations
Location
LS1, Leeds, West Yorkshire, United Kingdom
Employment Type
Permanent
Salary
£60000 - £70000/annum
technical security requirements with governance, compliance, and stakeholder engagement. Key Responsibilities Manage and maintain compliance with security standards and accreditations including PCI DSS, ISO 27001, ISO 22301, Cyber Essentials Plus and IT Health Checks. Conduct internal audits, control reviews, and risk … Security Manager or similar information security role. Strong understanding of cyber security, governance, risk, and compliance frameworks. Extensive knowledge of PCI DSS, ISO 27001, Cyber Essentials Plus, and data protection requirements. Experience with Microsoft 365, Azure, AWS, vulnerability management, and SIEM tools. Strong communication ...

Information Assurance Analyst

Hiring Organisation
Sanderson Government and Defence
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£540 - £590 per day
assessments. Assist with the review and maintenance of recovery plans and procedures. Help ensure critical services meet resilience and recovery objectives. Continuous Improvement Lead and contribute to process improvement initiatives across multiple teams. Identify opportunities to improve assurance, governance, and quality management practices. Promote best practice … with: Business Continuity Management (BCM) Disaster Recovery Planning Operational Resilience Risk Management Frameworks Internal Audit Activities Control Assessments Process Improvement Programmes Familiarity with: ISO 27001 ISO 22301 NIST Cybersecurity Framework Cyber Assessment Framework (CAF) ITIL Governance, Risk and Compliance (GRC) tools ...

Digital Trust Lead Auditor (London and Southeast)

Hiring Organisation
BSI Group
Location
London, United Kingdom
Salary
£ 55 K
will evaluate client controls against BSI and ISO / IEC standards (e.g., ISO / IEC 27001, 27701, 27017, 27018), identify opportunities for improvement, and provide clear, value driven insights that help clients enhance their security posture and organisational resilience. … governance, risk management, data protection, cybersecurity, or related technical environments.Strong knowledge of management system frameworks, particularly ISO / IEC 27001 and related security standards.Ability to interpret technical environments (cloud, networks, applications, data flows) and map them to management system and risk requirements.Experience producing ...

Digital Trust Lead Auditor (London and Southeast)

Hiring Organisation
BSI Group
Location
London, UK
Employment Type
Full-time
will evaluate client controls against BSI and ISO / IEC standards (e.g., ISO / IEC 27001, 27701, 27017, 27018), identify opportunities for improvement, and provide clear, value driven insights that help clients enhance their security posture and organisational resilience. … governance, risk management, data protection, cybersecurity, or related technical environments. Strong knowledge of management system frameworks, particularly ISO / IEC 27001 and related security standards. Ability to interpret technical environments (cloud, networks, applications, data flows) and map them to management system and risk ...

GRC Senior Analyst

Location
Greater London, England, United Kingdom
levels and influence outcomes in support of enterprise projects. You will be confident working across the major information security frameworks and standards, including ISO 27001, NIST and SOC 2, and able to shape risk, compliance and control decisions in a way that keeps both … Client Delivery: Provide security subject matter expertise across our internal technology initiatives, collaborating with project managers, business stakeholders and operational teams, and lead client GRC engagements end to end from gap assessment and framework implementation through to audit readiness and ongoing advisory. Measurement and Insight: Maintain ...

Information Security Consultant

Hiring Organisation
Reed Technology
Location
Suffolk, East Anglia, United Kingdom
Employment Type
Permanent
Salary
£50,000
their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments … interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier ...

IT Security Compliance & Reporting Analyst

Hiring Organisation
Ricoh
Location
London, United Kingdom
Salary
£ 100 K
managed.Facilitate security and technology risk assessments, working with technical teams to identify appropriate and practical mitigation plans.Support audit, assurance and compliance activities, including ISO 27001, Cyber Essentials and internal control programmes.Translate security frameworks and regulatory requirements into practical, operational standards and controls.Analyse security … Risk, Security Governance or Security Compliance.Experience developing and maintaining security policies, standards, controls and governance documentation.A strong understanding of security frameworks such as ISO 27001 and NIST CSF.Experience producing security compliance reporting, MI or dashboards, ideally using Power BI.Experience managing or supporting IT / ...

IT Security Compliance & Reporting Analyst

Hiring Organisation
Ricoh
Location
London, UK
Employment Type
Full-time
security and technology risk assessments, working with technical teams to identify appropriate and practical mitigation plans. Support audit, assurance and compliance activities, including ISO 27001, Cyber Essentials and internal control programmes. Translate security frameworks and regulatory requirements into practical, operational standards and controls. Analyse … Governance or Security Compliance. Experience developing and maintaining security policies, standards, controls and governance documentation. A strong understanding of security frameworks such as ISO 27001 and NIST CSF.Experience producing security compliance reporting, MI or dashboards, ideally using Power BI.Experience managing or supporting IT / ...

Infrastructure & Security Manager

Hiring Organisation
JobHeron
Location
Egham, Surrey, South East, United Kingdom
Employment Type
Permanent
Doing As the Infrastructure & Security Manager, you'll play a pivotal role in keeping systems secure, resilient and scalable. You'll lead infrastructure strategy while remaining hands-on with day-to-day technical delivery. Key responsibilities include: Managing cloud infrastructure, networking, firewalls, servers, storage and security technologies. … acting as the first point of contact for security incidents. Managing backup and disaster recovery solutions to ensure business continuity. Driving and maintaining ISO 27001 compliance, audits and security improvements. Developing infrastructure roadmaps and implementing technical change. Supporting colleagues with internal IT infrastructure issues ...

GRC Assurance Manager

Hiring Organisation
wayve
Location
London, United Kingdom
Salary
£ 80 K
design and operate the processes, methodologies, and relationships that enable continuous validation of our security controls, supporting certifications such as TISAX and ISO 21434, meeting customer contractual commitments, and strengthening trust across the organisation.This is an opportunity to build a security assurance capability from the ground up. … mindset, balancing strong governance with the realities of a fast-moving engineering-led organisation.DesirableExperience supporting security assurance programmes for frameworks such as TISAX, ISO 21434, ISO 27001, SOC 2, or similar.Experience helping organisations evolve from periodic assurance towards continuous assurance.Familiarity with ...

CLOUD SECURITY ARCHITECT

Location
Greater London, England, United Kingdom
reference architectures and reusable solution patterns Define and author enterprise‐level security policies, controls frameworks, and governance documentation aligned to industry standards Lead risk assessments, threat modelling exercises, and security posture evaluations for cloud platforms and SaaS products, utilising methodologies such as FAIR Drive compliance programmes covering … ISO 27001, Cyber Essentials Plus, PCI DSS, and other relevant regulatory frameworks Support DevSecOps adoption and integrate security tooling and controls into CI / CD pipelines across client delivery teams Engage senior stakeholders and executive teams with clear security risk reporting, remediation guidance ...

Managing Cyber Security Consultant

Hiring Organisation
Addition
Location
London Area, United Kingdom
Security Consultant Join a fast-growing technology consultancy helping organisations strengthen their cyber resilience through expert advisory services. This is an opportunity to lead high-profile consulting engagements, mentor talented consultants, and play a key role in shaping the growth of an ambitious Cyber Security practice. Role … Hybrid (2 days per week on site) Package: £75,000- £95,000pa & benefits Industry: Cyber Security / Consultancy What You'll Be Doing Lead the successful delivery of cyber security consulting engagements across a broad range of industries. Manage multiple client projects, ensuring high-quality delivery, commercial ...

Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

Location
Greater London, England, United Kingdom
Engineering Leads to bake EU / UK information security and regulatory requirements into design early; translate complex obligations into concrete technical implementations and auditor‐ or supervisor‐ready narratives without slowing development. Design, implement, and validate technical information security controls relevant to regulated EU / UK environments (access … compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk under EU / UK supervisory expectations. Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes that affect the EU / UK regulated attack ...

Cloud Security Architect

Hiring Organisation
Reply
Location
United Kingdom
Salary
£ 70 K
risk assessments, threat modelling exercises, and security posture evaluations for cloud platforms and SaaS products, utilising methodologies such as FAIRDrive compliance programmes covering ISO 27001, Cyber Essentials Plus, PCI DSS, and other relevant regulatory frameworksSupport DevSecOps adoption and integrate security tooling and controls into … Cloud Security Architect or Senior Security Consultant roleAWS Certified Security – Specialty (required), with CISSP, CRISC, or CCSP strongly preferred; additional certifications such as ISO 27001 Lead Implementer / Auditor, Azure Security Engineer, or GCP Security Engineer are advantageousHands ...

Information Security Consultant

Hiring Organisation
Digital Waffle
Location
Newcastle Upon Tyne, Tyne and Wear, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £80,000 per annum
best practices. Conduct security risk assessments, gap analyses and audits. Support clients in achieving and maintaining compliance with standards and regulations such as ISO 27001, NIST and GDPR . Develop and review security policies, procedures and documentation. Perform vulnerability assessments and coordinate remediation efforts. … processes. Required Skills & Experience Proven experience working as an Information Security Consultant or in a similar role. Strong understanding of security frameworks including ISO 27001, NIST and CIS Controls . Experience conducting threat modelling exercises and risk-based security assessments. Strong client-facing ...

Junior Cyber Audit Consultant - Contract

Hiring Organisation
Conventus Recruitment
Location
Corsham, Wiltshire, South West, United Kingdom
Employment Type
Contract
Contract Rate
From £450 to £500 per day (Inside IR35)
systems to ensure compliance with regulatory requirements such as the NCSC Cyber Assessment Framework (CAF) and GovAssure. Support and, over time, help lead audit activity, ensuring findings are properly documented and reported. Communicate audit findings and recommendations, working collaboratively with management to help develop and implement effective … auditing, compliance and risk management. Contribute to cyber report writing and the production of Cyber Risk Profiles (CRP) Skills / Experience: Experience of ISO 27001, the NCSC Cyber Assessment Framework (CAF), DCC and Cyber Risk Profile (CRP) work. Experience of cyber report writing. Relevant ...

Junior Cyber Audit Consultant

Hiring Organisation
Conventus Recruitment
Location
Corsham, Wiltshire, South West, United Kingdom
Employment Type
Permanent
Salary
£50,000
systems to ensure compliance with regulatory requirements such as the NCSC Cyber Assessment Framework (CAF) and GovAssure. Support and, over time, help lead audit activity, ensuring findings are properly documented and reported. Communicate audit findings and recommendations, working collaboratively with management to help develop and implement effective … auditing, compliance and risk management. Contribute to cyber report writing and the production of Cyber Risk Profiles (CRP) Skills / Experience: Experience of ISO 27001, the NCSC Cyber Assessment Framework (CAF), DCC and Cyber Risk Profile (CRP) work. Experience of cyber report writing. Relevant ...

Compliance Enablement Technical Program Manager

Hiring Organisation
Sophos
Location
United Kingdom
Salary
£ 70 K
mentoring others.Strong program and project management skills, with a track record of delivering across multiple teams.Solid knowledge of cybersecurity frameworks (NIST 800-53, ISO 27001, SOC 2, and / or FedRAMP) and hands-on audit experience.Enough technical depth to be the team's technical … Azure, or GCP), APIs, and data flows, and interpreting technical work with AI assistance, even if you do not write code.Proven ability to lead technical discussions with engineers and subject-matter experts and ask the right questions to understand how controls and systems work.Hands-on experience with ...

Security & Information Officer

Hiring Organisation
Compass UK & Ireland
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Permanent
/ or DV Clearance Join Us in Protecting Critical Defence Operations We are seeking a highly motivated and experienced Security & Information Officer to lead the security and information assurance agenda across our Defence, Marine & Aerospace business. This is an exciting opportunity to play a pivotal role … deliver governance excellence, and support business growth in a highly regulated environment. What You'll Be Doing As Security & Information Officer, you will: Lead and coordinate information security activities across Defence, Marine & Aerospace operations. Manage and maintain security accreditation programmes including Cyber Essentials Plus, Secure by Design ...

Specialist, security regulatory compliance

Hiring Organisation
Colt Technology Services UK
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
looking for a Security Regulatory Compliance Specialist to lead and manage compliance with key security regulations such as NIS2, DORA, Telecom Security Act , and other applicable laws and standards. This role is responsible for monitoring evolving regulatory requirements, translating them into actionable controls, and ensuring the organization … Strong organizational and stakeholder management skills Proactive mindset with high attention to detail Might haves: Professional certifications such as: CISM, CISSP, CRISC, CISA ISO 27001 Lead Implementer / Auditor Experience working with regulators or in regulated industries (e.g. ...