Loughton, Essex, South East, United Kingdom Hybrid / WFH Options
Profile 29
role. This role will focus on creating a business strategy, gap analysis and implementation, for securing their Azure-based infrastructure, integrating security automation, ensuring PCIDSS compliance, vulnerability and penetration testing and incident response. This role will focus on developing and maintaining secure, scalable Azure DevOps pipelines and … WAF) and Intrusion Prevention Systems (IPS). Vulnerability & Penetration Testing: Review Penetration Testing, vulnerability assessments, and security scanning to proactively identify and remediate risks. PCIDSS Compliance: Conduct security audits, risk assessments, and ensure regulatory compliance. DNS Security: Implement and monitor DNS security solutions to prevent cyber threats. … be found at: profile-29 .com/privacy) Profile 29 recruitment keywords: DevSecOps DevOps Azure cloud security Microsoft Defender Microsoft Sentinel WAF IPS DNS pcidsspcidsspci-dss soar loughton Debden essex London freelance contract More ❯
Employment Type: Contract, Work From Home
Rate: From £500 to £700 per day (direct contract with the client)
authentication solutions. Plan for scalability, redundancy, and high availability to support future growth. IT Security & Compliance: Ensure compliance with security and regulatory standards, including PCIDSS, Cyber Essentials+, DORA, and ISO 27001. Implement and enforce security best practices across infrastructure automation and cloud environments. Maintain accurate compliance documentation … including PCIDSS scope records and security policies. Secure high-value and high-risk data, such as cardholder (PCI) and personally identifiable information (PII). Cloud & DevOps Integration (these tools and skills will be taught): Implement and manage Infrastructure as Code (IaC) for cloud and on-premises … Cyber Essentials, NIST, ISO 27001). In-depth understanding of network security and compliance in regulated environments. Proven ability to secure high-value data (PCI cardholder data, PII) and implement security best practices. Strong networking knowledge (LAN, WAN, DNS, DHCP, VPN, TCP/IP). Proficiency in firewall and More ❯
authentication solutions. Plan for scalability, redundancy, and high availability to support future growth. IT Security & Compliance: Ensure compliance with security and regulatory standards, including PCIDSS, Cyber Essentials+, DORA, and ISO 27001. Implement and enforce security best practices across infrastructure automation and cloud environments. Maintain accurate compliance documentation … including PCIDSS scope records and security policies. Secure high-value and high-risk data, such as cardholder (PCI) and personally identifiable information (PII). Cloud & DevOps Integration (these tools and skills will be taught): Implement and manage Infrastructure as Code (IaC) for cloud and on-premises … Cyber Essentials, NIST, ISO 27001). In-depth understanding of network security and compliance in regulated environments. Proven ability to secure high-value data (PCI cardholder data, PII) and implement security best practices. Strong networking knowledge (LAN, WAN, DNS, DHCP, VPN, TCP/IP). Proficiency in firewall and More ❯
Guildford, Surrey, United Kingdom Hybrid / WFH Options
Sycurio
The Information Security Director develops, shapes, and maintains Sycurio's information security capability, driving the attainment and maintenance of the ISO27001, PCI-DSS, and SOC2 compliance. They are the subject matter expert on all things regarding security and compliance, owning the information risk management processes. They are the … parties and providing assurance of policies, procedures, and systems. Develop, maintain, and expand the information security management system ('ISMS') to optimise compliance for ISO27001, PCI-DSS, and SOC2. Identify gaps in the information security capability, both technical and operational, and propose remediation and mitigation plans and solutions. Responsible … CISSP, CISM, CISA, or equivalent. Experience: 10+ years of information security experience. Financial/Fintech services/payments desirable. Deep knowledge of security frameworks (PCI, ISO 27001, NIST) and regulations (GDPR, CCPA). Experience with PCIDSS compliance and implementation. Proven success in managing external auditors to More ❯
ANEXT Bank. Role Overview: As a GRC Lead , you will ensure alignment with European regulations (e.g., GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCIDSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party risk , outsourcing compliance , and identity governance … complementary regulations like DORA (Digital Operational Resilience Act) , ensuring alignment in areas such as incident reporting and data protection. Translate requirements from PSD2 SCA , PCIDSS , and SWIFT CSP into technical security controls. Maintain IT security governance frameworks (ISO 27001, NIST CSF, CIS Controls). Manage and maintain … we are looking for: Experience: 4+ years in GRC roles ; financial services or banking experience is a strong plus . Understanding of GDPR , DORA , PCIDSS, and outsourcing/third-party risk requirements. Hands-on experience with ISO 27001 implementation and third-party risk tools . Proficiency in More ❯
The Information Security Director develops, shapes and maintains Sycurio's information security capability, driving the attainment and maintenance of the ISO27001; PCI-DSS and SOC2 compliance. They are the subject matter of all things regarding security and compliance, owning the information risk management processes. They are the thought … assurance of policies, procedures, and systems Develop, maintain, and expand the information security management system ('ISMS') in line with an optimise compliance for ISO27001, PCI-DSSS and SOC2 compliance. Identify gaps in the information security capability, both technical and operational, and propose remediation and mitigation plans and solutions. Responsible … CISSP, CISM, CISA, or equivalent Experience : 10+ years of information security experience. Financial/Fintech services/payments desirable Deep knowledge of security frameworks (PCI, ISO 27001, NIST) and regulations (GDPR, CCPA) Experience with PCIDSS compliance and implementation Proven success in managing external auditors to achieve More ❯
across functions to support operational resilience and maintain alignment with global security and regulatory frameworks including: - ISO/IEC 27001:2022 - NIST Cybersecurity Framework - PCI-DSS 4.0.1 - UK GDPR, NIS2 Directive, CAP1753, and related sector obligations . This makes it a great development role for those looking to … relevant stakeholders Colloborate with procurement and key suppliers to ensure their ongoing security posture meets Virgin Atlantic requirements Conduct internal reviews against ISO, NIST, PCI, UK GDPR, and emerging requirements Support internal/external audits, evidence readiness, and corrective action tracking Maintain the policy and control framework, identifying non … ISO 27001 Lead Implementer/Auditor certification Sound knowledge of information security governance practices, working knowledge of ISO/IEC 27001:2022, NIST CSF, PCI-DSS, UK GDPR, and NIS2 and other aviation related legislation.Awareness of Business Continuity, IT Service Continuity and IT Disaster Recovery (ISO25999, COBIT, PAS More ❯
across functions to support operational resilience and maintain alignment with global security and regulatory frameworks including: ISO/IEC 27001:2022 NIST Cybersecurity Framework PCI-DSS 4.0.1 UK GDPR, NIS2 Directive, CAP1753, and related sector obligations This makes it a great development role for those looking to step … relevant stakeholders. Collaborates with procurement and key suppliers to ensure their ongoing security posture meets Virgin Atlantic requirements. Conducts internal reviews against ISO, NIST, PCI, UK GDPR, and emerging requirements. Supports internal/external audits, evidence readiness, and corrective action tracking. Maintains the policy and control framework, identifying non … ISO 27001 Lead Implementer/Auditor certification. Sound knowledge of information security governance practices, working knowledge of ISO/IEC 27001:2022, NIST CSF, PCI-DSS, UK GDPR, and NIS2, and other aviation-related legislation. Awareness of Business Continuity, IT Service Continuity, and IT Disaster Recovery (ISO25999, COBIT More ❯
ensure high availability and performance. Secure IT Systems by implementing security policies, monitoring for threats, and ensuring compliance with relevant regulations (e.g. GDPR, SOX, PCIDSS) and industry standards. Support physical network infrastructure by configuring and maintaining servers, appliances, L2/L3 switches, VLANs, and network security. Optimise … for all areas of responsibility to enable efficient controls and ways of working. Ensure IT compliance and governance is adhered to for GDPR, SOX, PCIDSS and other regulatory framework the company adheres to, ensuring that commitments and deadlines are met or exceeded. Take ownership of any escalated More ❯
ensure high availability and performance. Secure IT Systems by implementing security policies, monitoring for threats, and ensuring compliance with relevant regulations (e.g. GDPR, SOX, PCIDSS) and industry standards. Support physical network infrastructure by configuring and maintaining servers, appliances, L2/L3 switches, VLANs, and network security. Optimise … for all areas of responsibility to enable efficient controls and ways of working. Ensure IT compliance and governance is adhered to for GDPR, SOX, PCIDSS and other regulatory framework the company adheres to, ensuring that commitments and deadlines are met or exceeded. Take ownership of any escalated More ❯
the aforementioned processes and integrations, providing clear and comprehensive guides for internal use and compliance purposes and enforce procedures to comply with/improve PCI-DSS, PCI-PIN, and PCI-3DS standards Maintain our testing environments and become experts in International Payment Schemes' test environments If … problem-solving skills to troubleshoot technical issues effectively Think creatively and insightfully about business problems Familiarity with industry standards and compliance requirements, such as PCI-DSS. Strong communication and interpersonal skills to build relationships with internal and external stakeholders. Detail-oriented mindset with a focus on quality and accuracy More ❯
knowledge of cloud security architecture, specifically within Azure (or other Cloud platforms). Familiarity with security frameworks and compliance standards such as NIST, GDPR, PCI-DSS, DESC ISR. Strong problem-solving skills, with the ability to think creatively to solve complex security challenges. BENEFITS: Competitive Salary: Base salary More ❯
Bexhill-On-Sea, East Sussex, South East, United Kingdom Hybrid / WFH Options
Hastings Direct
Bicep, ARM templates, Terraform). Hands-on experience with SIEM tools, ideally Azure Sentinel. Understanding of regulatory and compliance frameworks (e.g., CIS Benchmarks, HIPAA, PCI-DSS). Excellent problem-solving skills, communication, and the ability to explain technical concepts to non-technical stakeholders. Desirable: Relevant certifications such as More ❯
bexhill, south east england, united kingdom Hybrid / WFH Options
Hastings Direct
Bicep, ARM templates, Terraform). Hands-on experience with SIEM tools, ideally Azure Sentinel. Understanding of regulatory and compliance frameworks (e.g., CIS Benchmarks, HIPAA, PCI-DSS). Excellent problem-solving skills, communication, and the ability to explain technical concepts to non-technical stakeholders. Desirable: Relevant certifications such as More ❯
brighton, south east england, united kingdom Hybrid / WFH Options
Hastings Direct
Bicep, ARM templates, Terraform). Hands-on experience with SIEM tools, ideally Azure Sentinel. Understanding of regulatory and compliance frameworks (e.g., CIS Benchmarks, HIPAA, PCI-DSS). Excellent problem-solving skills, communication, and the ability to explain technical concepts to non-technical stakeholders. Desirable: Relevant certifications such as More ❯
pseudonymisation. Detailed understanding of the information lifecycle and the self assurance framework for Records Management. Experience of implementing datasecurity standards such as ISO27001, PCIDSS, NIST CSF, CAA CAF etc. Ability to effectively manage cyber security risks and can clearly communicate with key stakeholders to minimise the More ❯
Guildford, Surrey, United Kingdom Hybrid / WFH Options
Deloitte LLP
Event Management (SIEM) data, which includes: Provide Deloitte firms with cybersecurity data. Assist Deloitte Global and Deloitte firms with data extraction for ISO and PCI audit requirements. Support eDiscovery teams by providing data relating to insider threats and legal matters. Build and maintain PowerBI dashboards. Support the cyber risk More ❯
london, south east england, united kingdom Hybrid / WFH Options
The Curve Group
Cyber Security or Cyber Security Professional Qualifications/Certifications Desirable: General understanding of IT Security principles, standards and regulations (e.g. ISO 27001, NIST, CIS, PCIDSS and GDPR) CISM/CISSP Patch Management Applications, EDR/XDR systems. Antivirus, NAC - Forescout Vulnerability Scanning Tool e. Tenable One, Qualisys More ❯
london, south east england, united kingdom Hybrid / WFH Options
The Curve Group
Cyber Security or Cyber Security Professional Qualifications/Certifications Desirable: General understanding of IT Security principles, standards and regulations (e.g. ISO 27001, NIST, CIS, PCIDSS and GDPR) CISM/CISSP Patch Management Applications, EDR/XDR systems. Antivirus, NAC - Forescout Vulnerability Scanning Tool e. Tenable One, Qualisys More ❯
for automated, scalable deployments. AWS Cloud Security & Compliance: Expertise in encryption, IAM policies, network security, and transit security, ensuring adherence to financial services regulations (PCIDSS, FCA, GDPR). Database & Data Services: Expertise in how data services connect, function and integrate within AWS, such as Athena, Redshift and More ❯
Thatcham, Berkshire, United Kingdom Hybrid / WFH Options
Cyberfort Group
and understanding of market trends and customer needs. BA/BS degree or equivalent experience. Experience with IT compliance and risk management requirements, including PCI-DSS, ISO27001 and Cyber Essentials Plus. Behavioural & Personality Competencies Ability to navigate through ambiguity. Demonstrated ability to think strategically about business, product, and More ❯
london, south east england, united kingdom Hybrid / WFH Options
Merlin Entertainments
Azure Monitor, AppDynamics). Expert in cyber security practices, identity management, encryption, and secure API development. Familiarity with compliance frameworks such as GDPR and PCI-DSS. Excellent stakeholder management and communication skills, ideally in a global or matrixed environment. Interview Process: Recruiter Call Hiring Manager Intro 1-2 stage More ❯
Bexhill-On-Sea, East Sussex, South East, United Kingdom Hybrid / WFH Options
Hastings Direct
understanding of cyber and information security, including frameworks like NIST and ISO IEC 27002:202. It will be great if you also know about PCI-DSS V4.0 as well. Clear Communication -You'll be able to discuss these with technical and non-technical stakeholders in a way which More ❯
Milton Keynes, Buckinghamshire, South East, United Kingdom Hybrid / WFH Options
Circle Group
level Build trust with clients, challenge assumptions diplomatically, and influence senior stakeholders Provide guidance across security frameworks and standards such as ISO27001, NIST CSF, PCI-DSS, Cyber Essentials, SOC 2 Drive security maturity and risk management initiatives tailored to each client's needs Understand buyer behaviour and how … in Cyber, Cloud or Networking is useful - even if not current/up to date. Certifications such as CISSP, CISM, ISO 27001 Lead Implementer, PCI etc. are great - but your professionalism and confidence matter most You: A natural communicator and relationship builder - confident, but never arrogant Able to simplify More ❯