based transaction systems, including paymentcard processing infrastructure, in a team that values collaboration, security, and reliability. You'll work closely with third-party service providers, ensure compliance with PCIDSS, and help build secure abstractions over APIs that interface with our clients. Responsibilities Maintain and expand our serverless cardpayment infrastructure built with TypeScript, Node.js, and AWS … Lambda, API Gateway, DynamoDB). Ensure continued PCIDSS compliance. Work with others to fix bugs, implement minimal new features, trace errors, and ensure security patches are applied in production and pre-production environments. Support a clean and well-documented strategy for all dependent services and infrastructure. Collaborate in daily scrum ceremonies, working closely with engineering, security, and … RESTful design, and secure authentication. Demonstrated knowledge of API security and OWASP Top 10 vulnerabilities. Experience with Docker, Linux, Git, and container-based environments. Hands-on development experience with PCIDSS, payment systems, or other regulated environments is essential Excellent communicator with a self-starter attitude and comfort working autonomously. Demonstrable expertise and understanding of API development/ More ❯
across all regions and entities. The scope includes KYC/KYB/AML vendor integrations, funnel efficiency, and cost optimization , as well as leading broader compliance projects such as PCIDSS certification, GDPR/data protection, FATF Travel Rule, and other regulatory requirements . You will be responsible for building scalable, automated solutions that support compliance operations worldwide … providers, build redundancy, and improve vendor routing to optimize both funnel performance and cost. Global Compliance Projects : Work with the compliance team to lead and deliver product solutions for PCIDSS, GDPR, FATF Travel Rule, AMLD , and other frameworks across jurisdictions. Automation & Efficiency : Identify manual workflows across compliance and risk operations, and design product-led automations with the … collaborate with engineers on backend workflows, APIs, and data pipelines. Proven success in automating compliance/risk operations and delivering compliance projects globally. Strong knowledge of global regulatory frameworks (PCIDSS, GDPR, FATF Travel Rule, AMLD, sanctions). Excellent stakeholder management; ability to align compliance, legal, operations, partnerships, engineering, and leadership. Nice-to-Haves Experience in high-growth More ❯
Oxford, Oxfordshire, United Kingdom Hybrid / WFH Options
Nomios
we offer an incredible opportunity to be part of an experienced team, build your skills, and grow professionally. Dionach by Nomios holds impressive certifications, including CREST, Cyber Scheme, CHECK, PCI QSA, SWIFT CSCF and ISO 27001. With our focus on enhancing customers' security and fostering team development,be joining a company that prioritizes both your growth and the safety … within sizeable projects, conduct ISO 27001 audits, help implement aspects of ISO 27001, and engage in risk management. Furthermore, there is potential for growth into such diverse fields as PCIDSS, privacy, and business continuity. Essential experience and skills: Recognized ISO 27001 Lead Auditor qualification. Significant experience in auditing ISO 27001 based Information Security Management Systems. Significant experience … Experience of AI governance and auditing or implementing an ISO 42001 AIMS Information security qualifications such as CISSP, CISA, or CISM. Familiarity with GRC cloud-based systems. Experience of PCIDSS or a PCI QSA. Experience auditing SWIFT CSCF. Developing and providing training. Writing policies and technical documents. Managing a team or leading teams. If you are More ❯
Sevenoaks, Kent, England, United Kingdom Hybrid / WFH Options
GerrardWhite
Contract Role: PCICardPayment Project Manager Location: Hybrid (remote and Manchester)We are seeking an experienced Project Manager with a strong background in PCI compliance and cardpayment projects to lead the delivery of a high-profile programme.Key Responsibilities: Drive end-to-end delivery of cardpayment projects, ensuring compliance with PCIDSS standards. Coordinate … project plans, budgets, risks, and reporting to senior leadership. Ensure secure, scalable, and compliant payment solutions are implemented. Essential Skills & Experience: Proven track record as a Project Manager in PCIDSS and card payments environments. Strong understanding of payment gateways, acquiring banks, and card schemes. Experience managing compliance and regulatory projects within financial services, retail, or e-commerce. More ❯
Guildford, Surrey, England, United Kingdom Hybrid / WFH Options
Sanderson
security controls catalogue, policies, and procedures aligned with NIST CSF Collaborate with business units to integrate security measures into operations Support compliance activities for frameworks such as Cyber Essentials, PCIDSS, and the Group Information Security Framework Facilitate reviews and updates to ensure controls remain effective against evolving threats Essential skills: Minimum 2 year's experience in information … controls catalogue in a financial services environment (highly desirable) Proven experience in delivering security projects within a federated organisation Desirable skills: Knowledge of NIST CSF, ISO 27001, Cyber Essentials, PCIDSS, DORA Understanding of risk methodologies and data analysis for reporting Strong documentation skills (control matrices, process flows, SOPs) Excellent communication skills for both technical and non-technical More ❯
Jam Management Consultancy Limited T/A JAM RECRUITMENT
Role Our client, a leading organisation in Berkshire, is seeking an experienced Information Security Specialist with in-depth knowledge of ISO 9001, ISO 14001, ISO 22301, ISO 27001, and PCI-DSS compliance. This role will be central to designing, implementing, and maintaining best-in-class security and compliance frameworks, ensuring that all information assets and operational processes are … safeguarded to the highest standards. Key Responsibilities Develop, implement, and maintain compliance with ISO , and PCI-DSS standards. Conduct risk assessments, security audits, and vulnerability testing across systems and processes. Lead incident response activities, ensuring rapid and effective mitigation. Collaborate with internal stakeholders and external auditors to achieve and maintain certifications. Deliver organisation-wide security and compliance awareness … and report on security performance, providing actionable recommendations. Essential Skills & Qualifications ISO 27001 Lead Implementer or Lead Auditor certification (or equivalent). Demonstrable experience managing compliance for ISO , and PCI-DSS. Strong understanding of governance, risk management, and regulatory compliance. Proficiency with security monitoring tools and incident management processes. Excellent analytical, communication, and leadership skills. Desirable Knowledge of GDPR More ❯
assessments to identify material gaps, analyzing potential risks, and monitoring progress on maturity uplifting across security functions. Supporting compliance activities with the Group Information Security Framework, Cyber Essentials, and PCIDSS attestation. Collaborating with the wider organization to integrate control testing and risk management activities into the existing governance framework. Assisting cross-functional teams and business units in … record of security transformation and delivery of security projects, particularly within a federated organisation. Strong knowledge of Information Security and compliance frameworks, including NIST CSF, ISO 27001, Cyber Essentials, PCIDSS, and DORA, and the ability to design controls that align with these standards. Ability to analyse data and generate reports using tools like Excel and Power BI More ❯
assessments to identify material gaps, analyzing potential risks, and monitoring progress on maturity uplifting across security functions. Supporting compliance activities with the Group Information Security Framework, Cyber Essentials, and PCIDSS attestation. Collaborating with the wider organization to integrate control testing and risk management activities into the existing governance framework. Assisting cross-functional teams and business units in … record of security transformation and delivery of security projects, particularly within a federated organisation. Strong knowledge of Information Security and compliance frameworks, including NIST CSF, ISO 27001, Cyber Essentials, PCIDSS, and DORA, and the ability to design controls that align with these standards. Ability to analyse data and generate reports using tools like Excel and Power BI More ❯
assessments to identify material gaps, analyzing potential risks, and monitoring progress on maturity uplifting across security functions. Supporting compliance activities with the Group Information Security Framework, Cyber Essentials, and PCIDSS attestation. Collaborating with the wider organization to integrate control testing and risk management activities into the existing governance framework. Assisting cross-functional teams and business units in … record of security transformation and delivery of security projects, particularly within a federated organisation. Strong knowledge of Information Security and compliance frameworks, including NIST CSF, ISO 27001, Cyber Essentials, PCIDSS, and DORA, and the ability to design controls that align with these standards. Ability to analyse data and generate reports using tools like Excel and Power BI More ❯
assessments to identify material gaps, analyzing potential risks, and monitoring progress on maturity uplifting across security functions. Supporting compliance activities with the Group Information Security Framework, Cyber Essentials, and PCIDSS attestation. Collaborating with the wider organization to integrate control testing and risk management activities into the existing governance framework. Assisting cross-functional teams and business units in … record of security transformation and delivery of security projects, particularly within a federated organisation. Strong knowledge of Information Security and compliance frameworks, including NIST CSF, ISO 27001, Cyber Essentials, PCIDSS, and DORA, and the ability to design controls that align with these standards. Ability to analyse data and generate reports using tools like Excel and Power BI More ❯
london (city of london), south east england, united kingdom
Sanderson
assessments to identify material gaps, analyzing potential risks, and monitoring progress on maturity uplifting across security functions. Supporting compliance activities with the Group Information Security Framework, Cyber Essentials, and PCIDSS attestation. Collaborating with the wider organization to integrate control testing and risk management activities into the existing governance framework. Assisting cross-functional teams and business units in … record of security transformation and delivery of security projects, particularly within a federated organisation. Strong knowledge of Information Security and compliance frameworks, including NIST CSF, ISO 27001, Cyber Essentials, PCIDSS, and DORA, and the ability to design controls that align with these standards. Ability to analyse data and generate reports using tools like Excel and Power BI More ❯
role An exciting opportunity has arisen to join our InfoSec team as a Security GRC Analyst, to assist in the delivery of security compliance assurance to frameworks such as PCI-DSS and NIST Cyber Security Framework. You will be managing security governance processes including Third Party Security Risk Management, and delivering controls assurance. What you'll be doing … Assisting in meeting compliance requirements within HL, such as PCI-DSS and in line with frameworks such as SWIFT CSCF, CSA CCM and NIST CSF. Assist with the technical security aspects of third-party security risk by conducting security due diligence and risk assessments for vendors, suppliers, partners, and contractors. Develop and mature processes and procedures for third … business areas to meet compliance requirements. Demonstrable experience of working with compliance and risk management in a NIST CSF (Preferable) or ISO27001 aligned environment, along with an understanding of PCI-DSS. Experience in managing supply chain risk, including due diligence, risk escalation and treatment. Good writing capabilities, analytical skills, including demonstrated experience identifying and communicating opportunities for improvement. Experience More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
role An exciting opportunity has arisen to join our InfoSec team as a Security GRC Analyst, to assist in the delivery of security compliance assurance to frameworks such as PCI-DSS and NIST Cyber Security Framework. You will be managing security governance processes including Third Party Security Risk Management, and delivering controls assurance. What you'll be doing … Assisting in meeting compliance requirements within HL, such as PCI-DSS and in line with frameworks such as SWIFT CSCF, CSA CCM and NIST CSF. Assist with the technical security aspects of third-party security risk by conducting security due diligence and risk assessments for vendors, suppliers, partners, and contractors. Develop and mature processes and procedures for third … business areas to meet compliance requirements. Demonstrable experience of working with compliance and risk management in a NIST CSF (Preferable) or ISO27001 aligned environment, along with an understanding of PCI-DSS. Experience in managing supply chain risk, including due diligence, risk escalation and treatment. Good writing capabilities, analytical skills, including demonstrated experience identifying and communicating opportunities for improvement. Experience More ❯
Employment Type: Permanent, Part Time, Work From Home
Snelshall West, Milton Keynes, Buckinghamshire, England, United Kingdom
DS Smith
is well defined. Engage risk review and assurance activities across existing suppliers. Provide IT and business advice on aspects of security standards and regulations such as ISO27001, NIST CSF, PCIDSS, NISD and NIS2. Engage with I&T system owners to provide training in relation to information security, cyber resilience, phishing, and facilitation of cyber scenario desktop simulations … consequences across both IT and manufacturing environments in manufacturing or similar industries. Experience working with information security standards and frameworks such as and regulations such as ISO27001, NIST CSF, PCIDSS, NISD and NIS2. Proven analytical, problem-solving, planning, project delivery and supplier work packages management skills. Demonstrable experience of engaging across all levels of a company in More ❯
Ludlow, Shropshire, England, United Kingdom Hybrid / WFH Options
REDTECH RECRUIT
troubleshoot across Windows, Active Directory, and complex cloud setups Experience with SQL Server, SMTP, IIS, and CI/CD pipelines Knowledge of cloud security standards such as ISO27001 and PCI-DSS Experience using ticketing systems (e.g. Jira) and improving support workflows Excellent communication skills, able to explain technical concepts to non-technical stakeholders Passion for automation and an … Systems Engineer/Azure/AWS/Terraform/Ansible/Windows/Active Directory/SQL Server/CI/CD/VPN/Firewalls/ISO27001/PCI-DSSMore ❯
Salford, Greater Manchester, North West, United Kingdom
Xn protel Systems Ltd
TCP-level integrations). Implement secure coding practices aligned with industry standards. Contribute to architecture discussions ensuring systems remain stateless where possible. Develop solutions that maintain systems out of PCIDSS scope , with an understanding of compliance requirements. Support projects involving credit card processing systems , focusing on cardholder present transaction scenarios . Work with POS systems , Engage with … development on Microsoft IIS . Practical knowledge of network programming and common web service architectures (XML, JSON). Understanding of secure software development standards and practices . Awareness of PCIDSS principles , with the focus on maintaining systems outside PCI scope. General understanding of the credit cardindustry , including transaction types and workflows. Desirable (Nice to Have More ❯
on time, within scope, and to a high standard. Specialist Migration Expertise: Oversee the secure migration of card credentials, encryption keys, and other sensitive financial data, ensuring compliance with PCIDSS and relevant regulatory requirements. Card Scheme Migration Processes: Manage migration activities in line with card scheme processes, procedures, and compliance standards. Liaise with scheme representatives to coordinate … reconciliation methodologies. Excellent stakeholder management skills, including board-level engagement. Strong problem-solving ability and resilience under pressure. Desirable Experience in a payments or card-issuing environment. Knowledge of PCIDSS compliance requirements. Familiarity with other card scheme migration processes (Visa, Amex). PRINCE2, PMP, or Agile project management certification. Why Apply? This is an opportunity to join More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
s Information Security Management System remains effective in protecting HL critical information assets within risk appetite. Lead assurance activities against Information Security Compliance frameworks, including but not limited to: PCI, NIST, SWIFT, GDPR Conducting analysis of cloud-based assets pertaining to information security incidents, audits, and testing while adhering to best practices. Lead engagement of Cloud Audits and remediation … CISSP, CRISC Hands on demonstratable experience and knowledge of: Carrying out security reviews against recognised security control frameworks such as CSA Cloud Control Matrix, ISO27017/27001, NIST CSF, PCI-DSS, SWIFT, AWS CAF Atlassian, IAAC Terraform, Merge Requests, GIT Ops, Git Hub, Workflow, Wiz, Security Hub, Macie, Audit Manager, Microsoft Compliance Portal/Purview, Microsoft Information Protection More ❯
Oxford, Oxfordshire, United Kingdom Hybrid / WFH Options
Nomios
we offer an incredible opportunity to be part of an experienced team, build your skills, and grow professionally. Dionach by Nomios holds impressive certifications, including CREST, Cyber Scheme, CHECK, PCI QSA, SWIFT CSCF and ISO 27001. With our focus on enhancing customers' security and fostering team development,be joining a company that prioritizes both your growth and the safety … executing compliance or governance projects within complex organisation Desirable qualifications and experience: Information security qualifications such as CISSP, CISA, or CISM. Familiarity with GRC cloud-based systems. Experience of PCIDSS or a PCI QSA. Experience auditing SWIFT CSCF. Developing and providing training. Writing policies and technical documents. Managing a team or leading teams. If you are More ❯
Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
Queen Square Recruitment Limited
Application SecurityData Protection & Encryption Kubernetes, Containers, and DevSecOps/MLOps practices SIEM, logging, and monitoring Zero Trust architectures Skilled in applying frameworks such as NIST CSF, ISO 27001, PCIDSS, CSA CCM, NIST AI RMF . Hands-on with tools for vulnerability management, secrets management, CSPM, and CWPP . Relevant certifications strongly preferred (CISSP, CCSP, TOGAF, AWS More ❯
5+ years in InfoSec, IT Security or Ops within a regulated environment Certification required: CISSP, CISM, CRISC, or equivalent Strong knowledge of ISO27001:2022, SOC2 Type II, NIST CSF, PCIDSS, GDPR, DORA Confident with security risk assessments, audit responses, and policy governance Hands-on cloud security experience: ideally with Azure and the Shared Responsibility Model Comfort with More ❯
5+ years in InfoSec, IT Security or Ops within a regulated environment Certification required: CISSP, CISM, CRISC, or equivalent Strong knowledge of ISO27001:2022, SOC2 Type II, NIST CSF, PCIDSS, GDPR, DORA Confident with security risk assessments, audit responses, and policy governance Hands-on cloud security experience: ideally with Azure and the Shared Responsibility Model Comfort with More ❯
5+ years in InfoSec, IT Security or Ops within a regulated environment Certification required: CISSP, CISM, CRISC, or equivalent Strong knowledge of ISO27001:2022, SOC2 Type II, NIST CSF, PCIDSS, GDPR, DORA Confident with security risk assessments, audit responses, and policy governance Hands-on cloud security experience: ideally with Azure and the Shared Responsibility Model Comfort with More ❯
london (city of london), south east england, united kingdom
Prism Digital
5+ years in InfoSec, IT Security or Ops within a regulated environment Certification required: CISSP, CISM, CRISC, or equivalent Strong knowledge of ISO27001:2022, SOC2 Type II, NIST CSF, PCIDSS, GDPR, DORA Confident with security risk assessments, audit responses, and policy governance Hands-on cloud security experience: ideally with Azure and the Shared Responsibility Model Comfort with More ❯
5+ years in InfoSec, IT Security or Ops within a regulated environment Certification required: CISSP, CISM, CRISC, or equivalent Strong knowledge of ISO27001:2022, SOC2 Type II, NIST CSF, PCIDSS, GDPR, DORA Confident with security risk assessments, audit responses, and policy governance Hands-on cloud security experience: ideally with Azure and the Shared Responsibility Model Comfort with More ❯