Stan 05-138, Def Stan 05-139) An understanding of MOD ISN 23/09 Secure by Design Knowledge of security frameworks, such as ISO/IEC 27001, NIST800-30, NIST800-53 or OWASP Working with risk management frameworks and methodologies (e.g., ISO 27001/2, ISO27005/31000, NIST800-30, NIST800-53) If this all sounds like something you will be interested in then simply apply and we can discuss the opportunity further! Product Security Architect Permanent role Based in Bristol Offering circa 80,000 Disclaimer: This vacancy is being advertised by either Advanced Resource Managers Limited, Advanced Resource More ❯
Stan 05-138, Def Stan 05-139) An understanding of MOD ISN 23/09 Secure by Design Knowledge of security frameworks, such as ISO/IEC 27001, NIST800-30, NIST800-53 or OWASP Working with risk management frameworks and methodologies (e.g., ISO 27001/2, ISO27005/31000, NIST800-30, NIST800-53) If this all sounds like something you will be interested in then simply apply and we can discuss the opportunity further! Product Security Architect Permanent role Based in Bristol Offering circa £80,000 Disclaimer: This vacancy is being advertised by either Advanced Resource Managers Limited, Advanced Resource More ❯
certificate management lifecycle, and drive our transition to quantum-safe cryptography and automated certificate renewal. You'll be at the forefront of modernising our cryptographic practices, aligning with NIST, NCSC, and ENISA standards, and enabling secure digital innovation. This role will influence the future direction of our cyber strategy and help us build a resilient, agile cryptographic capability. … gaps, and develop plans to close them. Oversee integration of tools such as CyberArk, Azure Key Vault, Sentinel, and Qualys. Ensure alignment with regulatory standards (e.g., NISTSP800-57, SP800-208, FIPS 140-3). Collaborate with engineering, risk, and compliance teams to embed cryptographic controls into CI/CD pipelines. Monitor More ❯
certificate management lifecycle, and drive our transition to quantum-safe cryptography and automated certificate renewal. You'll be at the forefront of modernising our cryptographic practices, aligning with NIST, NCSC, and ENISA standards, and enabling secure digital innovation. This role will influence the future direction of our cyber strategy and help us build a resilient, agile cryptographic capability. … gaps, and develop plans to close them. Oversee integration of tools such as CyberArk, Azure Key Vault, Sentinel, and Qualys. Ensure alignment with regulatory standards (e.g., NISTSP800-57, SP800-208, FIPS 140-3). Collaborate with engineering, risk, and compliance teams to embed cryptographic controls into CI/CD pipelines. Monitor More ❯
certificate management lifecycle, and drive our transition to quantum-safe cryptography and automated certificate renewal. You'll be at the forefront of modernising our cryptographic practices, aligning with NIST, NCSC, and ENISA standards, and enabling secure digital innovation. This role will influence the future direction of our cyber strategy and help us build a resilient, agile cryptographic capability. … gaps, and develop plans to close them. Oversee integration of tools such as CyberArk, Azure Key Vault, Sentinel, and Qualys. Ensure alignment with regulatory standards (e.g., NISTSP800-57, SP800-208, FIPS 140-3). Collaborate with engineering, risk, and compliance teams to embed cryptographic controls into CI/CD pipelines. Monitor More ❯
certificate management lifecycle, and drive our transition to quantum-safe cryptography and automated certificate renewal. You'll be at the forefront of modernising our cryptographic practices, aligning with NIST, NCSC, and ENISA standards, and enabling secure digital innovation. This role will influence the future direction of our cyber strategy and help us build a resilient, agile cryptographic capability. … gaps, and develop plans to close them. Oversee integration of tools such as CyberArk, Azure Key Vault, Sentinel, and Qualys. Ensure alignment with regulatory standards (e.g., NISTSP800-57, SP800-208, FIPS 140-3). Collaborate with engineering, risk, and compliance teams to embed cryptographic controls into CI/CD pipelines. Monitor More ❯
certificate management lifecycle, and drive our transition to quantum-safe cryptography and automated certificate renewal. You'll be at the forefront of modernising our cryptographic practices, aligning with NIST, NCSC, and ENISA standards, and enabling secure digital innovation. This role will influence the future direction of our cyber strategy and help us build a resilient, agile cryptographic capability. … gaps, and develop plans to close them. Oversee integration of tools such as CyberArk, Azure Key Vault, Sentinel, and Qualys. Ensure alignment with regulatory standards (e.g., NISTSP800-57, SP800-208, FIPS 140-3). Collaborate with engineering, risk, and compliance teams to embed cryptographic controls into CI/CD pipelines. Monitor More ❯
IOT Security SME Role: 10+ years of experience in Cyber security Designing & implementation on ICS/OT network Architectures, Cybersecurity frameworks for ICS/OT environments NISTSP800-82 and c, OT Network Communication Protocols (e.g., Ethernet, Modbus, OPC, IEC-101/104 etc.), Information Event Management (SIEM). Key Responsibilities: Designing and implementing technical More ❯
Gloucestershire, United Kingdom Hybrid / WFH Options
SSR General & Management
incident response and remediation efforts for security breaches. Provide security guidance and training to teams across the organization. Key Skills & Experience: Strong knowledge of security frameworks (ISO 27001, NIST800-30/53, OWASP) . Experience with risk management methodologies and compliance with MOD and HMG security standards (JSP, Def Stan 05-138/139). More ❯
Bristol, Kendleshire, Gloucestershire, United Kingdom Hybrid / WFH Options
SSR General & Management
incident response and remediation efforts for security breaches. Provide security guidance and training to teams across the organization. Key Skills & Experience: Strong knowledge of security frameworks (ISO 27001, NIST800-30/53, OWASP) . Experience with risk management methodologies and compliance with MOD and HMG security standards (JSP, Def Stan 05-138/139). More ❯
Nottingham, Nottinghamshire, England, United Kingdom
Salt Search
in Information Security and/or Information Technology. Professional certification such as CISA, CISM, CISSP, ISO 27001 Lead Auditor, or equivalent. Familiarity with industry standards and frameworks e.g., NIST800-53, ISO 27001/27002, CIS Controls, COBIT. Experience with control testing methodologies, risk assessments, and auditing tools. Familiarity with IT systems, and cybersecurity practices and More ❯
as well as using GRC tools and guidance developed for Risk mitigation. Practical knowledge of information security standards and risk assessment frameworks such as ISO 27001, SOC 2, NIST800-32. Strong knowledge of cyber controls, policies, and procedures. Experience of delivering metrics for senior level audiences. Demonstrate analytical and problem-solving skills. Ability to More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
Deloitte LLP
as well as using GRC tools and guidance developed for Risk mitigation. Practical knowledge of information security standards and risk assessment frameworks such as ISO 27001, SOC 2, NIST800-32. Strong knowledge of cyber controls, policies, and procedures. Experience of delivering metrics for senior level audiences. Demonstrate analytical and problem-solving skills. Ability to More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Deloitte LLP
as well as using GRC tools and guidance developed for Risk mitigation. Practical knowledge of information security standards and risk assessment frameworks such as ISO 27001, SOC 2, NIST800-32. Strong knowledge of cyber controls, policies, and procedures. Experience of delivering metrics for senior level audiences. Demonstrate analytical and problem-solving skills. Ability to More ❯
Cambridge, Cambridgeshire, United Kingdom Hybrid / WFH Options
Deloitte LLP
as well as using GRC tools and guidance developed for Risk mitigation. Practical knowledge of information security standards and risk assessment frameworks such as ISO 27001, SOC 2, NIST800-32. Strong knowledge of cyber controls, policies, and procedures. Experience of delivering metrics for senior level audiences. Demonstrate analytical and problem-solving skills. Ability to More ❯
Milton Keynes, Buckinghamshire, United Kingdom Hybrid / WFH Options
Deloitte LLP
as well as using GRC tools and guidance developed for Risk mitigation. Practical knowledge of information security standards and risk assessment frameworks such as ISO 27001, SOC 2, NIST800-32. Strong knowledge of cyber controls, policies, and procedures. Experience of delivering metrics for senior level audiences. Demonstrate analytical and problem-solving skills. Ability to More ❯
ISC2Certified Information System Security Professional. Knowledge of UK/NATO Information Assurance standards, procedures & systems, including Government Functional Standard GovS 007: Security, HMG IS1&2, ISO27000 series standards, NIST SP800 series standards, JSP440, JSP604, guidance material provided by NCSC, CPNI and NIST. Practical experience of producing Security Accreditation documentation Practical experience of NCSC and Common Criteria security evaluation More ❯
Warwickshire, West Midlands, United Kingdom Hybrid / WFH Options
Telent Technology Services Ltd
technical assessments of all applicable standards, policies, regulation, and legislation compliance Creation of security standards and requirements documents for projects and activities to be based on ISO 27001, NIST800-53 and ISO 22301. Review risks, propose mitigation actions and solutions, and assisting ongoing risk treatment activity. Assist the security testing process from scoping, planning and More ❯
technical assessments of all applicable standards, policies, regulation, and legislation compliance Creation of security standards and requirements documents for projects and activities to be based on ISO 27001, NIST800-53 and ISO 22301. Review risks, propose mitigation actions and solutions, and assisting ongoing risk treatment activity. Assist the security testing process from scoping, planning and More ❯
day-to-day operations to major transformation projects. Main responsibilities: Leading security assurance, assessments, and advisory for IT and business projects (both Cloud and On-Prem), aligned to NIST800-53 standards. Partnering with security architecture and other teams to define and embed security patterns and controls. Developing non-functional security requirements and guiding their integration … to finish. Bonus points if you bring: Experience with AppSec and DevSecOps. Hands-on knowledge of Azure, AWS, and/or Google Cloud. Familiarity with standards like ISO2700X, ISO31000, NIST800, PCI-DSS. Certifications such as CISSP, CCSP, CRISC, CISM, or SABSA. Why QBE? At My Best? At QBE, we want our people to feel rewarded and inspired to perform at More ❯
in Information Security and/or Information Technology • Professional certification such as CISA, CISM, CISSP, ISO 27001 Lead Auditor, or equivalent• Familiarity with industry standards and frameworks e.g., NIST800-53, ISO 27001/27002, CIS Controls, COBIT• Experience with risk assessments, and familiarity with IT systems, cybersecurity practices and domain • Strong analytical, problem solving and More ❯
in Information Security and/or Information Technology. • Professional certification such as CISA, CISM, CISSP, ISO 27001 Lead Auditor, or equivalent.• Familiarity with industry standards and frameworks e.g., NIST800-53, ISO 27001/27002, CIS Controls, COBIT.• Experience with risk assessments, and familiarity with IT systems, cybersecurity practices and domains.• Strong analytical, problem solving and More ❯
Secure by Design principles Experience in system security engineering, ideally in defence, space, or critical infrastructure Familiarity with MOD, NCSC, and ISO standards (e.g. ISO 27001/2, NIST800-series, JSP 604) Competence in requirements engineering and systems thinking Practical experience with security in software and/or system development environments Effective communication and report More ❯
Secure by Design principles Experience in system security engineering, ideally in defence, space, or critical infrastructure Familiarity with MOD, NCSC, and ISO standards (e.g. ISO 27001/2, NIST800-series, JSP 604) Competence in requirements engineering and systems thinking Practical experience with security in software and/or system development environments Effective communication and report More ❯
Secure by Design principles Experience in system security engineering, ideally in defence, space, or critical infrastructure Familiarity with MOD, NCSC, and ISO standards (e.g. ISO 27001/2, NIST800-series, JSP 604) Competence in requirements engineering and systems thinking Practical experience with security in software and/or system development environments Effective communication and report More ❯