26 to 50 of 310 PCI DSS Jobs

Senior Security Engineer

Hiring Organisation
Eligo Recruitment
Location
London, UK
Employment Type
Full-time
Landing Zone security and connectivity, collaborating with Network Engineering to validate secure firewall and VPN configurations. Compliance & Risk: Support audit readiness for ISO 27001, PCI DSS, and Cyber Essentials Plus, ensuring all remediation progress is tracked and documented. Essential Skills & Experience: Experience: 5–10 years in cloud … CSPM tools, and vulnerability management platforms. Security Principles: Practical understanding of Zero Trust architecture and secure-by-design methodologies. Compliance Knowledge: Familiarity with PCI DSS, NIST, and ISO 27001 frameworks. Desirable Skills: Awareness of AWS security fundamentals (Guard Duty, KMS, IAM Identity Center).Experience with Infrastructure as Code ...

Information Security GRC Lead

Location
Chippenham, England, United Kingdom
Good Energy Change Advisory Board, and ensuring security and resilience impacts are considered and that technical owners complete agreed actions before implementation where required. PCI-DSS Compliance: Coordinate and support PCI-DSS control activity, evidence gathering, control testing and remediation tracking where technology controls … ideally while working alongside technical teams who own implementation. Awareness of recognised security standards or frameworks such as ISO27001, Cyber Essentials, NCSC CAF and PCI-DSS. Strong verbal and written communication skills, with the ability to explain technical matters clearly to non-technical audiences. Demonstrable attention to detail ...

Information Security Officer

Location
Reading, England, United Kingdom
organisation's Information Security Management System (ISMS) , including policies, procedures and controls. Support the implementation and ongoing management of ISO 27001, Cyber Essentials Plus, PCI-DSS, NIST/CIS Controls and other relevant security requirements. Conduct security assessments across infrastructure, networks, endpoints, applications and data. Identify, assess … Experience with security audits, control testing, risk assessments and remediation . Knowledge of frameworks and standards including ISO 27001/27002, NIST, CIS Controls, PCI-DSS and Cyber Essentials Plus . Experience developing and maintaining security policies and procedures. Experience with third-party/vendor risk management ...

Information Security Architecture & Engineering Lead (UK-based)

Location
Greater London, England, United Kingdom
Information Security Architecture & Engineering Lead (UK-based) The Information Security Architecture & Engineering Lead forms the technical heart of PCI Pal’s Information Security function. The role owns cloud architecture review, DevSecOps and secure SDLC practice, security automation and tooling, and security architecture strategy for the organisation, replacing reactive, post … secure coding practices. Experience threat-modelling applications and cloud workloads at the design stage, not just reviewing them after deployment. Working knowledge of PCI DSS v4.0.1. ISO/IEC 27001:2022; familiarity with ISO/IEC 42001:2023 is an advantage. Experience triaging and remediating findings from ...

Cyber Security Architect

Location
Newport, Wales, United Kingdom
Design and maintain enterprise security architecture aligned with business objectives and government security frameworks. Ensure compliance with security standards and regulations including ISO 27001 , PCI DSS , GDPR , GovAssure , NCSC Cyber Assessment Framework , and Secure by Design principles. Develop and manage the security architecture compliance roadmap in collaboration with … external partners, and stakeholders to develop secure, resilient, and compliant solutions. Requirements Enterprise Security Architecture Cloud Security (Azure, Hybrid and On-Premises) ISO 27001 PCI DSS GDPR GovAssure Framework NCSC Cyber Assessment Framework (CAF) Secure by Design Governance, Risk and Compliance (GRC) Risk Assessment and Risk Management Identity ...

Head of Information Security

Location
Greater London, England, United Kingdom
Foundations, establishing centralized monitoring and alerting (via Wiz/Security Hub). Data Privacy & Compliance End-to-End Privacy: Own the GDPR and PCI-DSS compliance programmes, embedding "Privacy by Design" and data minimization directly into our delivery processes. Legal Partnership: Collaborate with Legal to manage DPAs, transfer … information security, including leadership-level responsibility Proven experience building and scaling security and privacy programmes within growing organisations Strong hands-on knowledge of GDPR, PCI-DSS, incident response, and resilience planning Experience working within cloud-first environments, ideally AWS Strong understanding of security within e-commerce, fintech ...

Head of Information Security (Deputy CISO)

Location
Greater London, England, United Kingdom
Framework and other recognised standards. Maintain effective security policies, standards and controls, ensuring they are understood, embraced, evidenced and continuously improved. Support compliance with PCI DSS, UK GDPR, the Data Protection Act 2018 and relevant FCA expectations. Strengthen cyber operations and resilience Lead security monitoring, threat management, vulnerability … across security operations, governance, risk and compliance, architecture, engineering, third-party risk, assurance and operational resilience. Strong practical knowledge of ISO/IEC 27001, PCI DSS, UK GDPR, the Data Protection Act 2018 and recognised control frameworks such as NIST. A solid understanding of technology risk, risk appetite ...

Information Security Manager (UK/Remote) room London home work

Location
Greater London, England, United Kingdom
ideally within financial services, banking, or payments. Experience in InfoSec and Cyber Security. Experience setting up policies and processes in InfoSec area. Familiarity with PCI-DSS, ISO27001, SOC 2/3 or other global standards. Familiarity with regulatory requirements (DORA, PCI-DSS, PSD2, GDPR). Understanding … identify areas for improvement. Performing security risk and control assessments for new products or initiatives. Working with third party InfoSec auditors (penetration testing, PCI compliance etc.). Conduct regular risk assessments and vulnerability assessments to identify security gaps and develop appropriate mitigation plans. Conducting regulatory gap analysis for regulations ...

Security Manager

Location
Bradford, England, United Kingdom
enjoys balancing technical security requirements with governance, compliance, and stakeholder engagement. Key Responsibilities Manage and maintain compliance with security standards and accreditations including PCI DSS, ISO 27001, ISO 22301, Cyber Essentials Plus and IT Health Checks. Conduct internal audits, control reviews, and risk assessments. Maintain and monitor … years' experience in a Security Manager or similar information security role. Strong understanding of cyber security, governance, risk, and compliance frameworks. Extensive knowledge of PCI DSS, ISO 27001, Cyber Essentials Plus, and data protection requirements. Experience with Microsoft 365, Azure, AWS, vulnerability management, and SIEM tools. Strong communication ...

GRC Engineer

Location
Belfast City District, Northern Ireland, United Kingdom
assessments and gap analyses, translating results into actionable remediation plans Support alignment and readiness activities for ISO 27001 and other relevant frameworks (e.g., PCI DSS, GLBA, state/federal financial regulations as applicable) Maintain a unified control framework that maps overlapping requirements across multiple standards to reduce duplicate … audits (as a practitioner preparing evidence, not just an auditor) Working knowledge of NIST CSF and ISO 27001 (or similar frameworks like PCI DSS, HITRUST) Experience with a GRC automation platform (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC, or similar) Comfort working with API integrations to ingest data ...

Cyber Risk & Security Manager

Location
Greater London, England, United Kingdom
technical levels, supporting board-level decision‐making while driving operational security improvements aligned to recognised standards such as NIST CSF, ISO 27001, DORA, PCI‐DSS, and MITRE ATT&CK. Reporting To: Director/Head of Cyber Security Location: London (Hybrid) Employment Type: Full‐Time Salary … OWASP Top 10). Oversee DLP and DDA monitoring strategies. Compliance & Regulatory Alignment Support ISMS implementation aligned with ISO 27001. Ensure alignment with GDPR, PCI‐DSS, DORA, NIST CSF, COBIT, SANS, and related frameworks. Develop security policies, SOPs, and governance documentation. Conduct IT resilience and cloud security audits. ...

Head of Security

Location
Greater London, England, United Kingdom
where some products are today outside the standard tooling. Governance, risk and compliance and vendor management Own ISO 27001, SOC 1, SOC 2 and PCI DSS compliance, the audit calendar, the compliance automation platform and the relationship with our auditors. Work with legal and the Data Protection Officer … facing those customers on security matters. Working knowledge of ISO 27001 and SOC 2, and experience of being accountable for audits and certifications. PCI DSS experience is an advantage. Practical understanding of cloud security on AWS and Azure, Kubernetes-based platforms, infrastructure as code and modern CI/ ...

Security Architect

Location
Livingston, Scotland, United Kingdom
security architecture standards, patterns, blueprints, and reference architectures Ensure solutions align with organisational security policies, regulatory obligations, and industry frameworks including ISO 27001, NIS2, PCI DSS, and Zero Trust principles where applicable. What you’ll bring Hands-on experience conducting architecture risk assessments and creation of business cases. … Google Cloud is desirable. Understanding of DevSecOps, automation, and modern software delivery practices is desirable. Experience supporting regulatory requirements such as NIS2, PCI DSS, GDPR, SOX, or similar frameworks. Relevant industry certifications such as CISSP, SABSA, TOGAF, CCSP, Azure Security Engineer, or equivalent qualifications is desirable. Benefits ...

Cyber Security Compliance Manager

Hiring Organisation
Reed Technology
Location
Manchester, United Kingdom
Employment Type
Permanent
Salary
£65000 - £75000/annum
governance. Key responsibilities include: Managing and enhancing cyber security governance and compliance frameworks. Owning and developing the organisation's GRC platform. Leading PCI DSS compliance activities and supporting audit requirements. Managing supplier security assurance and third-party risk assessments. Advising projects and stakeholders on cyber security and compliance … requirements. Supporting frameworks and standards including ISO 27001, ISO 42001, NIST, CAF, CIS Benchmarks and PCI DSS. Producing meaningful risk and compliance reporting for senior stakeholders. Supporting governance activities around AI, Purview and other strategic technology initiatives. We're keen to speak with cyber security, risk, governance and compliance ...

Cyber Security Manager

Hiring Organisation
Amtis Professional Ltd
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Permanent
Salary
£85,000
security investigations and overseeing remediation after incidents or identified risks Driving compliance with security policies, standards and regulations, including ISO 27001, Cyber Essentials and PCI-DSS Managing security audits, risk assessments and improvement plans Delivering security reporting, metrics and risk updates to senior stakeholders and governance forums Working … response, risk management and security governance Experience developing and implementing security policies, controls and improvement programmes A strong understanding of ISO:27001, Cyber Essentials, PCI-DSS and wider security best practice Excellent stakeholder management and communication skills, and the ability to influence at all levels Experience leading teams ...

Group Information Security Risk Analyst

Location
Manchester, England, United Kingdom
effectiveness of information security controls and identify opportunities for improvement. Apply recognised security frameworks and standards including ISO27001, NIST Cybersecurity Framework, CIS Controls, PCI-DSS, and other relevant best practices in a proportionate and risk-based manner. Liaise with Cyber Security, IT, Business Continuity, Data Protection, Risk, Compliance … risk assessments, control reviews, audits, or assurance activities. Technical knowledge of information security frameworks and standards including ISO27001, NIST Cybersecurity Framework, CIS Controls, DORA, PCI-DSS, and related security practices. Strong communicator with positive influencing and interpersonal skills. Ability to synthesise complex technical and business information and present ...

Senior Cloud Security Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
through to completion. Document and uphold secure-by-design principles and architecture governance, and enforce policy-as-code frameworks aligned with NIST, CIS, and PCI DSS.Set the monitoring scope and priorities for CNAPP/CSPM tooling (e.g. Wiz or equivalent), defining which misconfigurations and vulnerabilities matter most against … NIST, and PCI DSS benchmarks, and holding engineering teams accountable to remediation outcomes. Work with Security Operations to shape cloud logging and detection requirements, ensuring our SIEM has the right visibility across the estate. Collaborate with senior stakeholders to articulate security risks and mitigations in terms that support ...

Security Specialist - EMEA (location flexible)

Location
United Kingdom
production readiness. Be the field's authority on our compliance posture - SOC 2 Type II, ISO 27001, GDPR and EU data residency, HIPAA, PCI DSS , and the European regulatory picture including DORA and NIS2. Raise the quality and speed of security questionnaires, RFP security sections, DPIAs, and third … isolation, secure multi-tenancy, threat modelling, and audit. Working command of the frameworks that gate enterprise data deals - SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS - and comfort with EU regulation. Credibility with security buyers. You've held your own in front of a CISO and know ...

Solution Architect (Principal Consultant)

Location
City Of London, England, United Kingdom
using Databricks, Snowflake, ETL pipelines, and Big Data tools. Champion Data Governance practices including classification, cataloging, and lineage. Ensure compliance with ISO 27001, GDPR, PCI DSS, and other security standards. Embed DevSecOps principles into CI/CD pipelines and platform delivery. Produce High-Level and Low-Level Designs … teams for seamless integration. Support business development initiatives, contributing to bids and proposals. Business Analysis experience and stakeholder engagement skills. Security - ISO 27001, GDPR, PCI DSS, IDAM, DevSecOps Agile - SAFe, DevOps, Scrum Collaboration - Stakeholder Engagement, Governance, Team Mentoring Business - Business Analysis, Bid Support, Multi-sector Delivery Upon employment ...

Information Security Risk & Assurance Specialist

Location
Reading, England, United Kingdom
internal security requirements and external commitments, including certification and regulatory requirements. Provide subject matter expertise in the application of established standards such as NIST, PCI-DSS, GDPR, COBIT, ISO 27001 and Cyber Essentials to current and future programs of work. Prepare for and support internal and external compliance … governance across the company. Qualifications One of the risk or security certifications (CISSP, CRISC, CISM). Good knowledge and practical experience of NIST, PCI-DSS, GDPR, COBIT, ISO 27001 or Cyber Essentials. Previous experience in a similar role with the ability to work in a dynamic and changing ...

Applied AI Security Architect

Location
Greater London, England, United Kingdom
teams, and DPOs to understand their security requirements and design solutions that meet European regulatory standards (GDPR, EU AI Act, DORA, NIS2, SOC 2, PCI-DSS, and national regulator expectations). Lead technical deep-dives on network architecture, EU data residency, data retention and Zero Data Retention … applies to foundation models. Experience navigating compliance frameworks relevant to European financial services and insurance (DORA, NIS2, SOC 2, PCI-DSS, and national regulators' guidance on AI/ML such as FCA/PRA, BaFin, ACPR, FINMA). A track record of leading complex, high‐stakes engagements with ...

Lead Penetration Tester

Hiring Organisation
Morson Edge
Location
United Kingdom
Employment Type
Contract
accepted. Ensure penetration testing and remediation activities align with relevant security standards, regulatory requirements and industry best practice, including OWASP, NIST, ISO 27001, PCI-DSS, GDPR and CAF. Ensure appropriate governance, documentation and evidence is maintained throughout the testing lifecycle. Provide assurance over the quality and effectiveness … network, infrastructure and/or cloud penetration testing. Familiarity with vulnerability management and security operations processes. Experience working within environments subject to ISO 27001, PCI-DSS, GDPR or CAF requirements. What We're Looking For The successful candidate will be someone who can combine strong technical penetration testing ...

Lead Penetration Tester

Location
Chesterfield, England, United Kingdom
accepted. Ensure penetration testing and remediation activities align with relevant security standards, regulatory requirements and industry best practice, including OWASP, NIST, ISO 27001, PCI-DSS, GDPR and CAF. Ensure appropriate governance, documentation and evidence is maintained throughout the testing lifecycle. Provide assurance over the quality and effectiveness … network, infrastructure and/or cloud penetration testing. Familiarity with vulnerability management and security operations processes. Experience working within environments subject to ISO 27001, PCI-DSS, GDPR or CAF requirements. What We’re Looking For The successful candidate will be someone who can combine strong technical penetration testing ...

Lead Penetration Tester

Location
Greater London, England, United Kingdom
accepted. Ensure penetration testing and remediation activities align with relevant security standards, regulatory requirements and industry best practice, including OWASP, NIST, ISO 27001, PCI-DSS, GDPR and CAF. Ensure appropriate governance, documentation and evidence is maintained throughout the testing lifecycle. Provide assurance over the quality and effectiveness … network, infrastructure and/or cloud penetration testing. Familiarity with vulnerability management and security operations processes. Experience working within environments subject to ISO 27001, PCI-DSS, GDPR or CAF requirements. What We’re Looking For The successful candidate will be someone who can combine strong technical penetration testing ...

Investigation Specialist, Veeqo

Location
Swansea, Wales, United Kingdom
professional experience Collaborate cross‐functionally with Product, Engineering, Legal, and Compliance to identify process gaps, propose improvements, and ensure regulatory adherence (e.g., GDPR, PCI DSS) Deliver regular fraud trend reports and risk assessments to leadership, quantifying financial impact and proposing mitigation tactics Investigate and resolve account-level issues … Experience with quality assessment frameworks and performance management in security contexts Knowledge of regulatory compliance requirements related to fraud prevention and data security (GDPR, PCI DSS) Experience developing and delivering training programmes for investigation teams Amazon is an equal‐opportunity employer. We believe passionately that employing a diverse ...