conducting vulnerability assessments, incident response, and forensics using tools such as Nessus Proficiency in threat hunting, malware analysis, and intrusion detection techniques Familiarity with compliance frameworks (e.g., NIST, ISO, PCI-DSS) and regulatory requirements Strong analytical skills with the ability to think like an attacker and find creative security solutions Experience of working in a hands-on role More ❯
Liverpool, Merseyside, North West, United Kingdom Hybrid / WFH Options
In Technology Group Limited
vulnerability scanners, firewalls, antivirus, and endpoint protection platforms. Familiarity with cloud security (AWS, Azure, or GCP) and hybrid environments. Good understanding of regulatory frameworks and standards (ISO 27001, NIST, PCIDSS). Professional certifications such as CISSP, CISM, CEH, or CompTIA Security+ are highly desirable. Excellent analytical, problem-solving, and communication skills. Desirable: Experience in the finance or More ❯
Bletchley, Buckinghamshire, United Kingdom Hybrid / WFH Options
In Technology Group
vulnerability scanners, firewalls, antivirus, and endpoint protection platforms. Familiarity with cloud security (AWS, Azure, or GCP) and hybrid environments. Good understanding of regulatory frameworks and standards (ISO 27001, NIST, PCIDSS). Professional certifications such as CISSP, CISM, CEH, or CompTIA Security+ are highly desirable. Excellent analytical, problem-solving, and communication skills. Desirable: Experience in the finance or More ❯
London, England, United Kingdom Hybrid / WFH Options
In Technology Group
vulnerability scanners, firewalls, antivirus, and endpoint protection platforms. Familiarity with cloud security (AWS, Azure, or GCP) and hybrid environments. Good understanding of regulatory frameworks and standards (ISO 27001, NIST, PCIDSS). Professional certifications such as CISSP, CISM, CEH, or CompTIA Security+ are highly desirable. Excellent analytical, problem–solving, and communication skills. Desirable: Experience in the finance or More ❯
Milton Keynes, Buckinghamshire, South East, United Kingdom Hybrid / WFH Options
In Technology Group Limited
vulnerability scanners, firewalls, antivirus, and endpoint protection platforms. Familiarity with cloud security (AWS, Azure, or GCP) and hybrid environments. Good understanding of regulatory frameworks and standards (ISO 27001, NIST, PCIDSS). Professional certifications such as CISSP, CISM, CEH, or CompTIA Security+ are highly desirable. Excellent analytical, problem-solving, and communication skills. Desirable: Experience in the finance or More ❯
remediation efforts. Develop and implement security controls, policies, and procedures. Respond to security alerts and escalate incidents as necessary. Conduct regular audits and compliance checks (e.g., ISO 27001, HIPAA, PCI-DSS). Collaborate with IT and engineering teams to integrate security into system architecture and DevOps pipelines. Maintain and operate security tools such as SIEM, IDS/IPS More ❯
recovery, and business continuity planning. Oversee and guide client security teams in implementing and managing security controls. Assist clients with compliance requirements related to various regulations (GDPR, CCPA, HIPAA, PCIDSS, etc.) and standards (e.g., ISO 27001, SOC 2). Manage security risk committees to support client cyber risk management practices. Track and manage remediation of security audit More ❯
London, England, United Kingdom Hybrid / WFH Options
Cifas
information security improvement program to ensure the risk profile matures in line with business objectives and the threat landscape, maintaining ongoing compliance with relevant accreditations (e.g. ISO27001, Cyber Essentials, PCIDSS). Overseeing the implementation, maintenance and assurance of security controls across the business in line with company objectives, information security strategy and security architectural principles. Supporting the More ❯
Proficiency with security tools such as SIEM, IDS/IPS, and vulnerability scanners. Strong understanding of network security, firewalls, and access control. Knowledge of regulatory frameworks like GDPR, HIPAA, PCI-DSS, or NIST. Experience in incident response and forensic analysis. Excellent analytical, problem-solving, and communication skills. Certifications such as CompTIA Security+, CEH, CISSP, or CISM. Experience with More ❯
depth understanding of cybersecurity frameworks (e.g., NIST, ISO 27001) and risk management methodologies. Experience of third-party risk management. Knowledge of regulatory requirements and compliance frameworks (e.g., GDPR, ITGC, PCI-DSS, etc.) related to IT, cybersecurity and risk management. Awareness of various operating systems including but not limited to Windows, Linux, Unix. Experience with cloud environments (AWS, Azure More ❯
Guildford, Surrey, United Kingdom Hybrid / WFH Options
Sycurio
The Information Security Director develops, shapes, and maintains Sycurio's information security capability, driving the attainment and maintenance of the ISO27001, PCI-DSS, and SOC2 compliance. They are the subject matter expert on all things regarding security and compliance, owning the information risk management processes. They are the thought leader on all matters within the security and compliance … information security strategy to relevant parties and providing assurance of policies, procedures, and systems. Develop, maintain, and expand the information security management system ('ISMS') to optimise compliance for ISO27001, PCI-DSS, and SOC2. Identify gaps in the information security capability, both technical and operational, and propose remediation and mitigation plans and solutions. Responsible for the Company's information … . Industry certifications such as CISSP, CISM, CISA, or equivalent. Experience: 10+ years of information security experience. Financial/Fintech services/payments desirable. Deep knowledge of security frameworks (PCI, ISO 27001, NIST) and regulations (GDPR, CCPA). Experience with PCIDSS compliance and implementation. Proven success in managing external auditors to achieve positive outcomes. Expert in More ❯
London, England, United Kingdom Hybrid / WFH Options
CloudBees
essentia l, if you also had one or more of Practical experience of ISO27001/27004/27005 or NIST Risk Management Framework (RMF); Experience in security accreditation e.g. PCI-DSS, FedRAMP, SSDF (NIST SP800-218), FISMA/NIST SP800-53, ISO 27001, DORA Cyber security certification e.g. Certified Information System Security Professional (CISSP), Cloud Certified Security Professional More ❯
London, England, United Kingdom Hybrid / WFH Options
CloudBees
essentia l, if you also had one or more of Practical experience of ISO27001/27004/27005 or NIST Risk Management Framework (RMF); Experience in security accreditation e.g. PCI-DSS, FedRAMP, SSDF (NIST SP800-218), FISMA/NIST SP800-53, ISO 27001, DORA Cyber security certification e.g. Certified Information System Security Professional (CISSP), Cloud Certified Security Professional More ❯
application platforms and foster a security-aware culture. Participate in incident response activities from detection to recovery and lessons learned. Ensure compliance with security standards and regulations such as PCIDSS SAQ-A. Candidate Profile Bachelor's degree in Computer Science, Cybersecurity, or a related field. Proven experience in cybersecurity, especially cloud security. Familiarity with cloud platforms (AWS More ❯
endpoints, applications, and databases meet security standards. Security Audits: Support internal and external audits of information security practices and systems, ensuring compliance with industry regulations (e.g., GDPR, SOC2, CE+, PCI-DSS, ISO). Collaboration: Work closely with ANS technical teams to integrate security best practices into all aspects of system architecture and development lifecycles, as well as managing … and problem-solving skills with attention to detail. Excellent communication skills, both written and verbal, with the ability to convey complex security concepts to non-technical stakeholders. Experience with PCIDSS requirements and the implementation of these within a business. Preferred Skills: Experience with cloud security in AWS or Azure Cloud environments. Experience with incident response frameworks and More ❯
an outsourced Security Operations Centre (SOC) team and Cyber Security Analysts. Collaborate with internal teams and external vendors to optimise cybersecurity operations. Compliance & Risk Management Plan and conduct annual PCIDSS compliance assessments in collaboration with qualified security assessors, maintaining and communicating cybersecurity risk registers to business stakeholders. Perform third-party risk assessments to evaluate vendor security postures … configuring a range of cybersecurity tooling and hardening cloud environments, particularly Microsoft Azure. Well-versed knowledge of cybersecurity and data protection frameworks including NIST, ISO27001 and DPA. Experience managing PCIDSS compliance for an organisation is preferred. Proficient at articulating technical cybersecurity concepts and risks to the business in a simple and effective manner, whilst advocating to do More ❯
London, England, United Kingdom Hybrid / WFH Options
JN Bank UK
excellent service seven days a week. Duties & Responsibilities: · Develop, implement, and maintain information security policies, procedures, and standards aligned with industry best practices (NCSC recommendations, UK DPA, ISO 27001, PCIDSS, NIST etc.). · Lead and support risk assessments, vulnerability scans, and security audits. · Manage day-to-day security operations, including monitoring, incident detection, investigation, and response. · Manage More ❯
Join Us At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to More ❯
and data protection technologies. Policy & Standards Expertise: Extensive experience in writing, reviewing, and implementing information security policies, procedures, and standards. Familiarity with legal and regulatory frameworks (e.g., GDPR, HIPAA, PCI-DSS) and their impact on security practices. Communication & Collaboration: Excellent verbal and written communication skills, with the ability to translate complex technical issues into understandable language for business More ❯
Understanding the best practices, control frameworks, and applicable legal and regulatory requirements data privacy and breach notification laws, ISO 27001, NIST CSF and SP 800-53, CIS, CSA CCM, PCIDSS, etc. Demonstrable strong leadership skills, including the ability to develop, mentor and coach others Experience in working in large or federated enterprises, preferably in the Telecoms industryMore ❯
UK & EU : GDPR (General Data Protection Regulation) ISO 27001 (Information Security Management Systems) Cyber Essentials Plus (UK government-backed security framework) DORA (Digital Operational Resilience Act) - EU financial sector PCI-DSS (if handling paymentdata) Experience in: Managing vendor risk assessments for third-party compliance. Handling incident response & reporting (e.g., Data Breach Notifications under GDPR). Key Skills … Strong reporting and communication skills-ability to brief executives and regulators. Ability to design, implement, and enforce security policies . Key Responsibilities: Ensure compliance with GDPR, Cyber Essentials Plus, PCI-DSS, and other applicable standards. Align ISMS activities with ISO 27001 framework. Develop and implement security policies, controls, and procedures. Conduct security risk assessments & compliance audits. Manage incident More ❯
London, England, United Kingdom Hybrid / WFH Options
Smart Communications, Inc
team with designing, innovating, deploying, and maintaining security measures to safeguard our information assets. We operate in a highly regulated global SaaS organization that has multiple certifications such as PCI-DSS, ISO/IEC 27001, SOC2 and other standards we adhere to. In addition, we have a large, federated customer base that we strive to embed improvements for. … on a variety of challenging projects, with multiple security tools. Have a proven track record of successes. Understanding of security compliance standards relevant to the SaaS industry, such as PCI, GDPR, ISO 27001, SOC2, NIST. An understanding of application security principals, best practices, OWASP/related standards. Knowledge of security frameworks & controls, hardening standards & security best practices. An understanding More ❯
Bristol, England, United Kingdom Hybrid / WFH Options
Redefined Ltd
CISM, CISSP, GSLC (GIAC), CCP (ISSM), ISO27001, GIS A working knowledge of ISO standards (e.g. ISO 27001) Working knowledge of other security frameworks/standards/regulations, such as PCI-DSS, CyberEssentials, NIST, NIS, GDPR Your security clearance To be successfully appointed to this role, it is a requirement to obtain Security Check (SC) clearance. To obtain SC More ❯
City of London, London, United Kingdom Hybrid / WFH Options
SR2 | Socially Responsible Recruitment | Certified B Corporation™
Risk Management: Identify and manage risks to information assets and IT systems. Lead enterprise risk assessments and mitigation planning. Compliance & Regulatory: Ensure adherence to global data protection regulations (GDPR, PCI-DSS, etc.), working closely with legal and data protection teams. Leadership & Stakeholder Engagement: Act as the subject matter expert on cybersecurity at the board and executive level. Communicate … experience building and scaling a GRC function in a complex environment. Deep knowledge of information security standards (ISO 27001, NIST, CIS), risk frameworks (COSO, FAIR), and regulatory obligations (GDPR, PCI-DSS, SOX). Proven track record of managing enterprise-level security programs, including incident response and business continuity. Excellent stakeholder management skills, with experience reporting at board level. More ❯
SR2 | Socially Responsible Recruitment | Certified B Corporation™
Risk Management: Identify and manage risks to information assets and IT systems. Lead enterprise risk assessments and mitigation planning. Compliance & Regulatory: Ensure adherence to global data protection regulations (GDPR, PCI-DSS, etc.), working closely with legal and data protection teams. Leadership & Stakeholder Engagement: Act as the subject matter expert on cybersecurity at the board and executive level. Communicate … experience building and scaling a GRC function in a complex environment. Deep knowledge of information security standards (ISO 27001, NIST, CIS), risk frameworks (COSO, FAIR), and regulatory obligations (GDPR, PCI-DSS, SOX). Proven track record of managing enterprise-level security programs, including incident response and business continuity. Excellent stakeholder management skills, with experience reporting at board level. More ❯