and Regulatory Adherence by meeting industry-specific regulations and cybersecurity standards (such as ISO/IEC 27001, NIST CSF, NISTSP800-53, NISTSP800-171, CMMC) to safeguard sensitive data and ensure business continuity Provide regular reporting on … Excellent knowledge of NIST CSF (1.1 and 2.0), ISO2700x, ISO22301 and NIS 2. Other IT-Security Standards such as NISTSP800-53, NISTSP800-171, SA/IEC 62443 and Cyber related Certification such as CMMC 2.0, Cyber More ❯
An understanding of MOD ISN 23/09 Secure by Design Knowledge of security frameworks, such as ISO/IEC 27001, NIST800-30, NIST800-53 or OWASP Working with risk management frameworks and methodologies (e.g., ISO 27001/2, ISO27005 …/31000, NIST800-30, NIST800-53) If this all sounds like something you will be interested in then simply apply and we can discuss the opportunity further More ❯
An understanding of MOD ISN 23/09 Secure by Design Knowledge of security frameworks, such as ISO/IEC 27001, NIST800-30, NIST800-53 or OWASP Working with risk management frameworks and methodologies (e.g., ISO 27001/2, ISO27005 …/31000, NIST800-30, NIST800-53) If this all sounds like something you will be interested in then simply apply and we can discuss the opportunity further! Product Security Architect Permanent role Based in Bristol Offering circa 80,000 Disclaimer More ❯
Almondsbury, Gloucestershire, United Kingdom Hybrid / WFH Options
Frontier Resourcing
My growing defence client is seeking a Security Architect with NIST framework experience. You'll join a leading organisation that develops cutting edge products and technology. Key Accountabilities : Identify security requirements and ensure the integration of security controls during the product development lifecycle. Develop and implement risk management … Stan ). An understanding of MOD ISN 23/09 Secure by Design. Knowledge of security frameworks, such as ISO/IEC 27001, NIST800-30, NIST800-53 or OWASP. Experience of working with risk management frameworks and methodologies (e.g., ISO …/2, ISO27005/31000, NIST800-30, NIST800-53) Why Join? You'll gain exposure to cutting-edge defence technology and intelligence insights, alongside good salary & benefits . The client offers flexible working options, with some hybrid/remote working. More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Frontier Resourcing Ltd
My growing defence client is seeking a Security Architect with NIST framework experience. You'll join a leading organisation that develops cutting edge products and technology. Key Accountabilities : Identify security requirements and ensure the integration of security controls during the product development lifecycle. Develop and implement risk management … . An understanding of MOD ISN 23/09 Secure by Design. Knowledge of security frameworks, such as ISO/IEC 27001, NIST800-30, NIST800-53 or OWASP. Experience of working with risk management frameworks and methodologies (e.g., ISO …/2, ISO27005/31000, NIST800-30, NIST800-53) Why Join? You'll gain exposure to cutting-edge defence technology and intelligence insights, alongside good salary & benefits . The client offers flexible working options, with some hybrid/remote working. More ❯
real-time. Operational strategy, written process, control policies, and guidelines. Deriving standard Alpha states from standard control frameworks in conformity to NISTSP800-171 and NISTSP800-160 . Creating an ecosystem of practices and preparing incremental improvements. Creating information More ❯
support). Monitor security tools and respond to alerts and incidents. COMPLIANCE ACTIVITIES: Change Management Incident Management Maintenance Vulnerability scanning Implement NISTSP800-171 for internal systems. Establish a System Security Plan (SSP) . The SSP needs to go through each NISTSP … 800-171 control and include how the control is implemented, monitored, and enforced. GOVERNANCE: Create programs and pathways for transition into cybersecurity, regulations, compliance, and GRC, translating business into technical and security risk. RISK MANAGEMENT: The goal is to understand the lifecycle of risk, apply complex critical skills … in emergent technology. Experience in architecting, building, and securing systems at scale. In-depth knowledge of cybersecurity compliance standards such as ISO, SOC, NIST, CMMC, EDRS, and ITAR. Certifications in (ISACA, CISM, CRISC, CISA, ITCA) . Certified Information Security Manager (CISM) is essential. Certified Authorization Professional (CAP) . More ❯
informed of new and updated industry frameworks and regulations: GDPR, ISO 27001/2, SANS Top 20 Critical Security Controls, NIST CSF, SP800-53, PFMI, CPMI ISOCO and FFIEC handbook. Keep informed of new and emerging security threats & assess effectiveness of current controls to identify … equivalent or working towards certification is preferred. Knowledge of Risk Management life cycles based on an established framework: ISO 27001, SANS, NISTSP800-53, CERT, ENISA. Working knowledge of the following frameworks and regulations: ISO 27001/2, SANS Top 20 Critical Security Controls, NISTMore ❯
Gloucestershire, United Kingdom Hybrid / WFH Options
SSR General & Management
ensure secure-by-design principles. Conduct threat modelling exercises to identify and mitigate potential risks. Ensure compliance with security regulations such as ISO27001, NIST800-30/37/53, JSP 440, 604, and Defence Standards. Develop and maintain security documentation (e.g., RMADS, Security Assurance Documents … and remediation activities. The Person Key Skills & Experience: Strong knowledge of risk management frameworks and methodologies (ISO 27001/2, ISO27005/31000, NIST800-30, NIST800-53). Experience with defence and government security standards (JSPs, Def Stan More ❯
Bristol, Kendleshire, Gloucestershire, United Kingdom Hybrid / WFH Options
SSR General & Management
ensure secure-by-design principles. Conduct threat modelling exercises to identify and mitigate potential risks. Ensure compliance with security regulations such as ISO27001, NIST800-30/37/53, JSP 440, 604, and Defence Standards. Develop and maintain security documentation (e.g., RMADS, Security Assurance Documents … and remediation activities. The Person Key Skills & Experience: Strong knowledge of risk management frameworks and methodologies (ISO 27001/2, ISO27005/31000, NIST800-30, NIST800-53). Experience with defence and government security standards (JSPs, Def Stan More ❯
North Lanarkshire, Scotland, United Kingdom Hybrid / WFH Options
Net Talent
global security standards. You'll also drive cyber awareness and training initiatives for commercial teams, support regulatory compliance (e.g., ISO 27001, NISTSP800-53, GDPR), and handle incident response, triage, and escalations per internal policies. You'll contribute to investigations, the annual NIST … analytical security professional with a strong technical background and excellent communication skills. You bring: Proven experience with ISO 27001, NIST CSF/SP800-53, GDPR compliance, and risk management Strong technical expertise in implementing security controls aligned with ISMS Ability to create clear, audience-tailored More ❯
Conduct threat modelling exercises to prioritise potential risks and develop mitigation strategies to reduce risks Ensure products meet regulatory standards such as ISO27001, NIST800-30/37/53, Joint Standards Publications (JSP) such as JSP 440, 604 and Defence Standards (Def stans) Produce security … remediation activities Your skillset may include: Understanding and application of risk management frameworks and methodologies (e.g., ISO 27001/2, ISO27005/31000, NIST800-30, NIST800-53) Working knowledge of Defence Standards (e.g., JSPs, HMG, Def Stan 05-138, Def More ❯
Conduct threat modelling exercises to prioritise potential risks and develop mitigation strategies to reduce risks Ensure products meet regulatory standards such as ISO27001, NIST800-30/37/53, Joint Standards Publications (JSP) such as JSP 440, 604 and Defence Standards (Def stans) Produce security … remediation activities Your skillset may include: Understanding and application of risk management frameworks and methodologies (e.g., ISO 27001/2, ISO27005/31000, NIST800-30, NIST800-53) Working knowledge of Defence Standards (e.g., JSPs, HMG, Def Stan 05-138, Def More ❯
cybersecurity and AI governance frameworks. This role is pivotal in ensuring our customers receive accurate, clear, and timely answers to their questions regarding NIST (CSF, 800-53, etc.), SOC2 (Type 1 & 2), ISO 27001, and the emerging ISO 42001 standard. The ideal candidate possesses deep subject … do Compliance Subject Matter Expert: Serve as the go-to expert for customer inquiries related to the interpretation, requirements, and best practices of NIST, SOC2, ISO 27001, and ISO 42001 frameworks Query Resolution: Directly address and resolve customer questions regarding these compliance standards, ensuring accuracy and clarity in … with a strong focus on specific frameworks Deep, demonstrable understanding and practical knowledge of NIST frameworks (e.g., Cybersecurity Framework, NISTSP800-53). Must be able to explain core concepts and requirements accurately Deep, demonstrable understanding and practical knowledge of SOC2 (Trust Services More ❯
, ISO 27001, or similar. General understanding of operational risk and risk-related control frameworks and practices such (ISO 27001, NISTSP800-53, NIST CSF, COBIT, ITIL, etc.). Experience with IAM tools and technologies, such as Microsoft Entra ID (formerly Azure More ❯
City Of Bristol, England, United Kingdom Hybrid / WFH Options
Matchtech
Looking For Technical Experience & Knowledge Experience with risk management frameworks and methodologies such as ISO/IEC 27001/2, ISO27005/31000, NIST800-30, NIST800-53. Strong understanding of security standards and frameworks including OWASP, Secure by Design … . Familiarity with HMG security principles and assurance frameworks is advantageous. Comfortable using threat modelling tools and implementing mitigation strategies. Experience with NIST standards. (this is an absolute must) Key Competencies Strong communicator with the ability to present complex information clearly and confidently. Proactive problem solver who approaches More ❯
Birmingham, Staffordshire, United Kingdom Hybrid / WFH Options
SYSTRA
perform cyber security audits. Experience in producing Zones and Conduits Partitioning Diagrams, Cyber Security Requirements definition and cyber security Assurance. ISO 27005/NIST800-82/NIST800-53 Knowledge. NIS/NIS2 knowledge. Railway industry experience and TS 50701 Knowledge. More ❯
, ISO27001, COBIT, etc.). Operational Technology - Ensure the security of critical infrastructure aligns with industry standards and regulatory requirements (e.g. NISTSP800-82, CAF, DPA 2018, etc.). Operational Resilience - Shaping and/or transforming client operational resilience capabilities in compliance with leading regulatory … standards (e.g., DORA, Bank of England, FCA, NIST, etc.). Cybersecurity Operating Model Transformation - Assessing, designing and implementing effective and outcome orientated security operating models. As an experienced consultant in the business you'll help set the direction, grow our business, model our values and behaviours, and coach … SOC teams, OT Security, Security Architecture, Security Op Model Transformation projects and Cybersecurity Assessments. Familiarity with core Cybersecurity frameworks and industry frameworks (e.g., NIST CSF, ISO27001, CIS Critical Controls), regulations (e.g., NIS2) and financial regulations (e.g., DORA, FCA, Bank of England, etc.). Have an understanding of the More ❯
e.g., NIST, ISO27001, CIS). Operational Technology Security : Protect critical infrastructure through robust OT security assessments and frameworks (e.g., NISTSP800-82, CAF). What We’re Looking For Proven experience in cybersecurity, technology risk, or security architecture consulting. Expertise in one or More ❯
london, south east england, United Kingdom Hybrid / WFH Options
Consulting Point
e.g., NIST, ISO27001, CIS). Operational Technology Security : Protect critical infrastructure through robust OT security assessments and frameworks (e.g., NISTSP800-82, CAF). What We’re Looking For Proven experience in cybersecurity, technology risk, or security architecture consulting. Expertise in one or More ❯
and operational teams to mitigate threats. Security Assessments & Compliance: Conduct OT security assessments, evaluate risk, and ensure compliance with IEC 62443, NISTSP800-82, NERC CIP, ISO 27001, and NIS2 frameworks. Vulnerability & Risk Management: Perform vulnerability analysis and penetration testing, and implement risk mitigation strategies … Network Security: Hands-on experience with firewalls, IDS/IPS, VPNs, authentication systems, PKI, log management, and content filtering. Cybersecurity Frameworks: Familiarity with NIST, IEC 62443, ISO 27001, NERC CIP, GSMA IoT Security Guidelines, and other industry security standards. Incident Response & Risk Management: Experience in security monitoring, incident More ❯
ZPA ZTMA, CrowdStrike, CyberArk, SailPoint, Ping, and ability to design and build a controls dashboard from evidence outputs from MS solutions, using ISO27K, NIST, NIS 2, DORA, TISAX, PCI, and/or equivalent. Exposure to Threat Methodology and Incident Response: Identify, analyze, and respond to security events and … team exposure and cyber threat mitigation. Security Assessments & Compliance: Exposure to security assessments, evaluate risk, and ensure compliance with IEC 62443, NISTSP800-82, NERC CIP, ISO 27001, and NIS2 frameworks or combination. Vulnerability & Risk Management: Able to implement risk mitigation strategies tailored for ICS … related field. Network Security: Exposure to Firewalls, IDS/IPS, VPNs, authentication systems, PKI, log management, and content filtering. Cybersecurity Frameworks: Familiarity with NIST, IEC 62443, ISO 27001, NERC CIP, GSMA IoT Security Guidelines, and other industry security standards. Incident Response & Risk Management: Experience in security monitoring, incident More ❯
Industry Standards including ISO27000, ISO28000, and NIST Cyber Security Framework. Experience or awareness of security control baselines such as NISTSP800-53, CIS Benchmark, DISA STIGs. A broad understanding of computer and network technical architecture. Qualifications for the Information Security Specialist Relevant higher More ❯
Industry Standards including ISO27000, ISO28000, and NIST Cyber Security Framework. Experience or awareness of security control baselines such as NISTSP800-53, CIS Benchmark, DISA STIGs. A broad understanding of computer and network technical architecture. Qualifications for the Information Security Specialist Relevant higher More ❯
Corsham, Wiltshire, United Kingdom Hybrid / WFH Options
Babcock Mission Critical Services España SA
Industry Standards including ISO27000, ISO28000, and NIST Cyber Security Framework. Experience or awareness of security control baselines such as NISTSP800-53, CIS Benchmark, DISA STIGs. A broad understanding of computer and network technical architecture. Qualifications for the Information Security Specialist Relevant higher More ❯