1 to 25 of 28 ISO 27001 Lead Auditor Jobs in the UK excluding London

Supplier Assurance Lead

Hiring Organisation
Morson Edge
Location
Greater Manchester, North West, United Kingdom
Employment Type
Contract
Supplier Assurance Lead / Cyber Security Risk Manager / Third Party Cyber Risk Lead £500 per day - Outside IR35 - North West Based - Hybrid My client is looking for an experienced Supplier Assurance Lead to join their Cyber Security team, taking … lead role in identifying, assessing and managing cyber security risks across a complex supplier and third-party ecosystem. This is a senior position requiring someone who can go beyond standard supplier due diligence exercises. Youll be expected to understand the underlying cyber security risks within the supply ...

Information Security & GRC Specialist

Location
Manchester, England, United Kingdom
ISMS), helping ensure Vix remains compliant, audit-ready and continually improving. Working across Security, Engineering, Technology and the wider business, you’ll coordinate ISO 27001 activities, prepare for internal and external audits, manage evidence and help drive remediation actions through to completion. … help get things fixed. What You’ll Be Doing Own the day-to-day coordination and continuous improvement of our ISMS. Support ISO 27001 certification, surveillance and internal audits. Coordinate audit evidence and work with stakeholders to close findings and remediation actions. Maintain security ...

Security Manager

Location
Bradford, England, United Kingdom
technical security requirements with governance, compliance, and stakeholder engagement. Key Responsibilities Manage and maintain compliance with security standards and accreditations including PCI DSS, ISO 27001, ISO 22301, Cyber Essentials Plus and IT Health Checks. Conduct internal audits, control reviews, and risk … Security Manager or similar information security role. Strong understanding of cyber security, governance, risk, and compliance frameworks. Extensive knowledge of PCI DSS, ISO 27001, Cyber Essentials Plus, and data protection requirements. Experience with Microsoft 365, Azure, AWS, vulnerability management, and SIEM tools. Strong communication ...

Information Security Analyst

Location
Nottingham, England, United Kingdom
practitioner against their outputs. The role also requires genuine compliance capability, you will contribute to internal audit and risk assessment cycles and support ISO 27001 compliance activity. You will provide ad-hoc expert input to the IT function where security judgement is needed … programme, including coordination of internal and external penetration testing Conducting internal security audits and risk assessments, producing findings reports and tracking remediation Supporting ISO 27001 compliance activity, including contributing to control evidence and audit cycles Producing clear written outputs -- findings reports, risk registers, policy ...

Security Manager (PCI DSS)

Hiring Organisation
ISR Recruitment Ltd
Location
Leeds, Yorkshire, United Kingdom
Employment Type
Permanent
Salary
GBP 60,000 - 70,000 Annual
responsible for supporting and improving the organisation's security and compliance posture, with responsibilities including: Managing compliance with PCI DSS, ISO 27001, ISO 22301 and Cyber Essentials Plus Conducting security risk assessments, internal audits and control reviews Maintaining and monitoring … Manager, GRC Manager or similar role Demonstrable experience leading PCI DSS compliance / certification, including audits, remediation and ongoing compliance Demonstrable experience leading ISO 27001 certification and ongoing ISMS compliance Experience with Cyber Essentials Plus Experience maintaining and managing security risk registers Experience coordinating ...

GRC Engineer

Location
Belfast City District, Northern Ireland, United Kingdom
querying, and control automation. You'll be a key player in maintaining our compliance posture across frameworks like SOC 2, NIST CSF, and ISO 27001, while also helping modernize how we monitor and evidence controls using platforms like Anecdotes. This role suits someone … preparation for and execution of SOC 2 (Type I / II) audits, working directly with external auditors to scope, evidence, and remediate findings Lead or support NIST CSF assessments and gap analyses, translating results into actionable remediation plans Support alignment and readiness activities for ISO ...

Information Security Officer

Location
Reading, England, United Kingdom
continually improve the organisation's Information Security Management System (ISMS) , including policies, procedures and controls. Support the implementation and ongoing management of ISO 27001, Cyber Essentials Plus, PCI-DSS, NIST / CIS Controls and other relevant security requirements. Conduct security assessments across infrastructure, networks … endpoints, applications and data. Identify, assess and manage information security risks, including maintaining risk registers and tracking remediation. Lead and support internal and external security audits , including evidence gathering, control testing and remediation of findings. Manage technical security risks within Data Protection Impact Assessments and policy exceptions. ...

Information Security Manager

Hiring Organisation
Reed Technology
Location
Cambridge, Cambridgeshire, East Anglia, United Kingdom
Employment Type
Permanent
health organisation that develops market-leading healthcare technology used by people across international markets. We are seeking an experienced Information & Cybersecurity Manager to lead information security, product cybersecurity and cyber risk management across a growing, highly regulated technology environment. This is a unique opportunity to become … cybersecurity throughout the software and product development lifecycle. Key Responsibilities Maintain and improve the Information Security Management System (ISMS), policies, procedures and controls. Lead cybersecurity risk assessments, threat modelling and security reviews. Oversee penetration testing, vulnerability management and remediation activities. Advise on secure design, cloud security, mobile ...

Information Security Consultant

Hiring Organisation
Reed Technology
Location
Suffolk, East Anglia, United Kingdom
Employment Type
Permanent
Salary
£50,000
their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments … interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier ...

Security Governance Risk & Compliance Officer

Location
Bristol, England, United Kingdom
Design, and JSP 440 / Defence Security Policy Framework expectations. Track changes to relevant legislation, standards and guidance, including NCSC guidance, MOD requirements, ISO standards and UK GDPR / the Data Protection Act 2018. Help deliver security awareness and training, building a strong security culture. Key skills … security governance, risk and compliance, information security, audit or assurance role. A sound understanding of security governance and compliance principles. Working knowledge of ISO 27001 and information security risk management, including risk assessment and treatment. Experience maintaining policies, controls and evidence, and supporting internal ...

Cyber Security Manager

Hiring Organisation
Amtis Professional Ltd
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Permanent
Salary
£85,000
looking for an experienced Cyber Security Manager to join it's technology function. Reporting to the Head of Information Security, you'll lead the organisation's day-to-day cyber defence and information security capability. You'll protect critical systems, customer data and business operations across … communications and recovery Leading security investigations and overseeing remediation after incidents or identified risks Driving compliance with security policies, standards and regulations, including ISO 27001, Cyber Essentials and PCI-DSS Managing security audits, risk assessments and improvement plans Delivering security reporting, metrics and risk ...

SC Cleared GRC Controls & Oversight Lead

Hiring Organisation
fortice
Location
Warwick, Warwickshire, United Kingdom
Employment Type
Contract
Contract Rate
GBP 450 Daily
Controls & Oversight Lead Location:Warwick Hybrid 50 / 50 Duration: 21 / 03 / 2027 MUST BE PAYE THROUGH UMBRELLA Description: We are seeking an experienced GRC Controls & Oversight Lead to support the governance, assurance, and control environment across IT and Operational Technology … individual who can work independently, manage competing priorities, and bring structure to large volumes of assurance, compliance, and remediation activities. Key Responsibilities Lead and coordinate controls assurance and testing activities across IT and OT environments. Review, assess, and validate control effectiveness against defined policies, standards, and regulatory ...

GRC Controls & Oversight Lead

Hiring Organisation
Experis
Location
Warwickshire, United Kingdom
Employment Type
Contract
Contract Rate
£400 - £460/day
Role Title: GRC Controls & Oversight Lead Location: Warwick - Hybrid 50 / 50 Duration: 21 / 03 / 2027 Rate: £(Apply online only) per day - Umbrella only Candidates must hold active SC clearance Description: We are seeking an experienced GRC Controls & Oversight Lead to support … individual who can work independently, manage competing priorities, and bring structure to large volumes of assurance, compliance, and remediation activities. Key Responsibilities Lead and coordinate controls assurance and testing activities across IT and OT environments. Review, assess, and validate control effectiveness against defined policies, standards, and regulatory ...

GRC Controls - Active SC Clearance

Hiring Organisation
eTeam Workforce Limited
Location
Warwick, Warwickshire, United Kingdom
Employment Type
Contract
Contract Rate
GBP Daily
/ 50 Duration: 21 / 03 / 2027 Rate: 447GBP / Day(Inside IR35) Description: We are seeking an experienced GRC Controls & Oversight Lead to support the governance, assurance, and control environment across IT and Operational Technology (OT) domains. This role will play a key part … individual who can work independently, manage competing priorities, and bring structure to large volumes of assurance, compliance, and remediation activities. Key Responsibilities Lead and coordinate controls assurance and testing activities across IT and OT environments. Review, assess, and validate control effectiveness against defined policies, standards, and regulatory ...

Compliance Enablement Technical Program Manager

Location
Oxford, England, United Kingdom
Strong program and project management skills, with a track record of delivering across multiple teams. Solid knowledge of cybersecurity frameworks (NIST 800-53, ISO 27001, SOC 2, and / or FedRAMP) and hands‐on audit experience. Enough technical depth to be the team … APIs, and data flows, and interpreting technical work with AI assistance, even if you do not write code. Proven ability to lead technical discussions with engineers and subject‐matter experts and ask the right questions to understand how controls and systems work. Hands‐on experience with ...

IT Risks & Control Manager

Location
Eastleigh, England, United Kingdom
experienced IT Risk and Controls Manager to join our Information Security Governance, Risk and Compliance team. In this senior specialist role, you’ll lead the identification, assessment, management and reporting of IT risks across Ageas, helping ensure technology risks are clearly understood, documented and managed in line … with our risk appetite. Reporting to the Governance, Risk and Compliance Lead, you’ll own the IT risk register, facilitate senior IT risk discussions and provide clear, high-quality reporting for governance forums and second-line risk teams. Main Responsibilities as IT Risks & Control Manager Lead ...

Cyber Security Manager

Location
Brighton, England, United Kingdom
regulatory compliance and operational resilience. Every day you will ... Own and develop the organisation’s Vulnerability Management Strategy, Framework, Policies and Standards Lead the delivery and continuous improvement of vulnerability management capabilities across the organisation Drive governance processes covering vulnerability identification, assessment, prioritisation, remediation, exception management … Ability to challenge constructively and drive accountability. Strong organisational and prioritisation skills. Desirable qualifications: CISSP, CISM, CRISC, GIAC certification, ITIL Foundation, SIAM Foundation, ISO 27001 Lead Auditor or Lead Implementer, Cyber Assessment Framework (CAF) knowledge ...

Cyber Security Manager

Location
Nottingham, England, United Kingdom
regulatory compliance and operational resilience. Every day you will ... Own and develop the organisation's Vulnerability Management Strategy, Framework, Policies and Standards Lead the delivery and continuous improvement of vulnerability management capabilities across the organisation Drive governance processes covering vulnerability identification, assessment, prioritisation, remediation, exception management … Ability to challenge constructively and drive accountability. Strong organisational and prioritisation skills. Desirable qualifications: CISSP, CISM, CRISC, GIAC certification, ITIL Foundation, SIAM Foundation, ISO 27001 Lead Auditor or Lead Implementer, Cyber Assessment Framework (CAF) knowledge ...

Cyber Data Engineer

Hiring Organisation
Robert Walters
Location
Manchester, North West, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
£600 - £700 per day + Outside IR35
range of bespoke services and solutions. Due to several projects, they are keen to appoint a Cyber Security Risk & Assurance SME to lead a number of Data Driven and Cyber Data Assurance projects. Cyber Security Risk & Assurance SME: Duties Provide cyber risk and assurance input across … Lead Auditor / Implementer or equivalent experience. Knowledge of NIST CSF, ISO / IEC 27001, COBIT, CIS Controls or enterprise risk frameworks. Experience with SQL, JSON / CSV, APIs, Power BI or data quality controls. Experience with ...

Senior Cyber Security Consultant (Defence)

Location
Cheltenham, England, United Kingdom
remediation strategies and residual risks to stakeholders. Supporting governance, risk and compliance activities within secure and regulated environments. Depending on experience, you may: Lead consultancy engagements and workstreams. Mentor and support the development of colleagues. Act as a trusted adviser to senior client stakeholders. Contribute to business … controls. Understanding of Defence procurement and capability delivery programmes. Beneficial Knowledge Government and industry security frameworks such as HMG Security Policy Framework (SPF), ISO 27001 and NIST. Risk management methodologies and security assurance frameworks. Enterprise and security architecture approaches including TOGAF and SABSA. Cloud ...

Senior Cyber Security Consultant (Defence)

Hiring Organisation
Hackajob Ltd
Location
Guildford, Surrey, South East, United Kingdom
Employment Type
Permanent, Work From Home
remediation strategies and residual risks to stakeholders. Supporting governance, risk and compliance activities within secure and regulated environments. Depending on experience, you may: Lead consultancy engagements and workstreams. Mentor and support the development of colleagues. Act as a trusted adviser to senior client stakeholders. Contribute to business … controls. Understanding of Defence procurement and capability delivery programmes. Beneficial Knowledge Government and industry security frameworks such as HMG Security Policy Framework (SPF), ISO 27001 and NIST. Risk management methodologies and security assurance frameworks. Enterprise and security architecture approaches including TOGAF and SABSA. Cloud ...

Cyber GRC Analyst (Cyber Policy & Governance)

Hiring Organisation
IBEX RECRUITMENT LTD
Location
Greater Manchester, North West, United Kingdom
Employment Type
Permanent
Salary
£50,000
have: Experience developing, reviewing or managing cyber security policies, standards, procedures or governance frameworks. Strong knowledge of recognised cyber security frameworks such as ISO 27001, NIST, or the Cyber Assessment Framework (CAF). Experience supporting compliance, risk management, governance or information assurance programmes. Excellent … Industrial Control Systems (ICS) security. Knowledge of cyber resilience requirements within critical national infrastructure environments. Professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer / Auditor. What's on Offer Opportunity to influence cyber strategy within a nationally significant organisation. ...

AMS Manager

Location
Penarth, Wales, United Kingdom
Description We are seeking an experienced SAP AMS Manager to lead post-go-live Application Management Services for a large-scale SAP S / 4HANA environment. The role will own the AMS operating model, service delivery, SLA / KPI performance, support organisation, transition to steady state … support structure. Manage incident, problem, change, and release management processes. Own SLA / KPI performance, service reporting, penalties, and service credits. Lead the transition from project hypercare to steady-state AMS, including knowledge transfer, runbooks, and CMDB establishment. Manage AMS teams, on-call rosters, escalations, and coordination ...

AMS Manager

Location
High Street, England, United Kingdom
Description We are seeking an experienced SAP AMS Manager to lead post-go-live Application Management Services for a large-scale SAP S / 4HANA environment. The role will own the AMS operating model, service delivery, SLA / KPI performance, support organisation, transition to steady state … support structure. Manage incident, problem, change, and release management processes. Own SLA / KPI performance, service reporting, penalties, and service credits. Lead the transition from project hypercare to steady-state AMS, including knowledge transfer, runbooks, and CMDB establishment. Manage AMS teams, on-call rosters, escalations, and coordination ...

Control Testing Automation & Monitoring Lead

Location
Reading, England, United Kingdom
Control Testing Automation & Monitoring Lead As a Control Testing Automation & Monitoring Lead, you will be responsible for designing and delivering automated control testing and monitoring solutions across IT, OT, and business environments at Thames Water. Working closely with the Control Testing & Assurance Manager, digital … obtain security clearance to a minimum of Counter Terrorist Check (CTC) level. What you’ll be doing as a Control Testing Automation & Monitoring Lead Identify and assess opportunities to automate control testing across IT, OT, and business functions. Design, develop, and implement automation plans and workflows ...