1 to 25 of 401 SOC 2 Jobs in England

Information Security Lead

Location
Wallingford, England, United Kingdom
Information Security Lead/ISO27001/SOC/GRC/Permanent At Dexory, we are transforming the warehousing and logistics industry through data intelligence. We're currently recruiting for an Information Security Lead to own and drive our compliance programmes (ISO 27001, SOC 1 Type 2, SOC … 2 Type 2), act as the primary responder to customer security due diligence, and build the systems and knowledge base that allow Dexory to scale securely without friction. You'll work closely with the Head of IT & Security, embedding good security practice across engineering, product, and operations. Offices ...

Senior IT Internal Auditor

Location
Leeds, England, United Kingdom
many of the world’s largest hedge fund managers, private equity firms and international corporations. Our distinction flows from our carefully curated team: 2,500+ professionals characterised by tenacity, ethics and exacting excellence. Operating in key financial centres across the Americas, Asia, Europe and the Middle East, our international … Audit Committees, and to the development and continuous improvement of audit methodologies, processes and services; Examining and assessing IT policies and procedures; Contributing to SOC 1 Type 2 and SOC 2 Type 2 readiness reviews and generally assisting with the SOC 1 Type 2 ...

Senior GRC Analyst

Location
Greater London, England, United Kingdom
small, high-impact Cybersecurity team. The role will be central to maintaining and expanding our risk management program, sustaining compliance with industry standards (especially SOC 2 Type 2), and building scalable governance processes to reduce identified risks. You’ll work cross-functionally with Legal, Engineering, Security, Product … developing and maintaining security, AI, and compliance policies in collaboration with Legal, Security, and Data teams, embedding governance checks into everyday business operations. Drive SOC 2 and beyond. Support compliance initiatives for SOC 2 Type 2, with potential expansion to ISO 27001, ensuring controls ...

Senior Security & Compliance Engineer

Location
Greater London, England, United Kingdom
scale. This is a broad, hands-on role spanning cloud and application security, vulnerability management, identity and access management, incident response, secure software delivery, SOC 2, risk management, and customer security assurance. You'll be the internal owner for security: maintaining a clear view of our security posture … clear actions with owners and deadlines, and follow them through to remediation or explicit risk acceptance. You’ll also own our day-to-day SOC 2 programme and audit readiness. That means making sure our controls reflect how Lantern actually operates, maintaining Vanta, coordinating evidence and auditor requests ...

Global Compliance Manager

Location
Greater London, England, United Kingdom
Manager role You’ll own compliance execution at Light. Reporting to the Head of Finance & Core Ops , you’ll be responsible for running our SOC 1, SOC 2, and PCI programmes end to end, keeping us audit-ready, and making sure controls actually work in practice. This … Kubernetes via Tanka/Jsonnet Datadog and CloudWatch for logging and monitoring 25 engineers scaling to 50+, distributed team What you’ll own Run SOC 1, SOC 2 (Type I & II), and PCI DSS etc compliance programmes Plan and manage audits, timelines, and auditor relationships Own evidence ...

Remote Consultant, SOC Assessment

Location
Lancashire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … experience as an IT Consultant, IT auditor, Business Analyst, or similar role Knowledge of Audit procedures and IT security especially as it relates to SOC 1 and SOC 2 Experience with SOC 1 and SOC 2 security audits/assessment with some experience ...

Remote Consultant, SOC Assessment

Location
Windsor, Berkshire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … experience as an IT Consultant, IT auditor, Business Analyst, or similar role Knowledge of Audit procedures and IT security especially as it relates to SOC 1 and SOC 2 Experience with SOC 1 and SOC 2 security audits/assessment with some experience ...

Remote Consultant, SOC Assessment

Location
Stafford, Staffordshire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … experience as an IT Consultant, IT auditor, Business Analyst, or similar role Knowledge of Audit procedures and IT security especially as it relates to SOC 1 and SOC 2 Experience with SOC 1 and SOC 2 security audits/assessment with some experience ...

Remote Consultant, SOC Assessment

Location
Derby, Derbyshire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … experience as an IT Consultant, IT auditor, Business Analyst, or similar role Knowledge of Audit procedures and IT security especially as it relates to SOC 1 and SOC 2 Experience with SOC 1 and SOC 2 security audits/assessment with some experience ...

Remote Consultant, SOC Assessment

Location
Sandy, Bedfordshire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … experience as an IT Consultant, IT auditor, Business Analyst, or similar role Knowledge of Audit procedures and IT security especially as it relates to SOC 1 and SOC 2 Experience with SOC 1 and SOC 2 security audits/assessment with some experience ...

Remote Consultant, SOC Assessment

Location
Eastbourne, Sussex, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … experience as an IT Consultant, IT auditor, Business Analyst, or similar role Knowledge of Audit procedures and IT security especially as it relates to SOC 1 and SOC 2 Experience with SOC 1 and SOC 2 security audits/assessment with some experience ...

Remote Consultant, SOC Assessment

Location
Southampton, Hampshire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … experience as an IT Consultant, IT auditor, Business Analyst, or similar role Knowledge of Audit procedures and IT security especially as it relates to SOC 1 and SOC 2 Experience with SOC 1 and SOC 2 security audits/assessment with some experience ...

Remote Consultant, SOC Assessment

Location
Weston-super-Mare, Somerset, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … experience as an IT Consultant, IT auditor, Business Analyst, or similar role Knowledge of Audit procedures and IT security especially as it relates to SOC 1 and SOC 2 Experience with SOC 1 and SOC 2 security audits/assessment with some experience ...

Security GRC Manager

Location
Greater London, England, United Kingdom
these tools daily and know how to get real leverage from them. You'll own the operating rhythm for frameworks like ISO 27001, SOC 1, SOC 2, HIPAA and future standards that matter to our customers. You'll keep evidence organised, controls running, policies up to date … drive action across teams, and keep the bar high. Focus/Ownership You'll own Humaans' security compliance programme end‐to‐end, including ISO, SOC 1, SOC 2, HIPAA and future frameworks we choose to pursue. You'll manage audit cycles throughout the year, coordinating with external ...

Sr. Manager, Site Reliability

Location
Manchester, England, United Kingdom
services; others are fully SaaS. Some customers access us over private circuits, others over the public internet. We operate in a regulated environment — HIPAA, SOC 2, and in some engagements FedRAMP — which means reliability, security, and auditability are not separable concerns. The person we hire will be comfortable … measurable value; resist the hype where it does not. Ensure AI-assisted operations meet the auditability and explainability bar required in a HIPAA and SOC 2 environment. Coaching and team-building Coach one Engineer III SRE who joins shortly after you do. Pair on incidents. Review their design ...

Head of Information Security

Location
Greater London, England, United Kingdom
Valarian’s Zero-Trust security roadmap, policies, risk assessments, and executive reporting for leadership and the board Own end-to-end audit readiness for SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53 Embed DevSecOps and secure SDLC practices into CI/CD pipelines … Manager, Architect, or Director stepping into a first CISO-level leadership role Experience with Zero-Trust security roadmaps, policies, and risk assessments Experience with SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53 Experience embedding DevSecOps and secure SDLC practices into CI/ ...

Third Party Assurance (TPA) Senior Managers – London- Leeds- Liverpool – Manchester – Growing Team –

Location
Leeds, England, United Kingdom
excellent opportunity for an experienced assurance professional to apply and deepen their expertise across ISAE 3000 , ISAE 3402 , ISAE 3410 , AAF 01/20 , SOC 1/SOC 2 , ISRS 4400 , and emerging frameworks. You will work with clients at varying stages of their reporting journey, overseeing … internal audit , regulatory assurance , or risk advisory . Strong knowledge of recognised assurance standards: ISAE 3000 , ISAE 3402 , ISAE 3410 , AAF 01/20 , SOC 1/SOC 2 , ISRS 4400 . Proven experience leading complex assurance engagements, including planning, risk assessment, and methodology application. Strong understanding ...

Information Security Manager - Fintech - Hybrid

Location
City Of London, England, United Kingdom
Programme Maintain and continuously improve the Information Security Management System, firmwide information security programme, security policies, certifications and control framework, aligned to ISO 27001, SOC 2, DORA‐related customer obligations, applicable financial services expectations and Crédit Agricole Group requirements. Partner with Product, Engineering and Technology teams to embed … monitoring and exit arrangements. Own the client security assurance process, including security questionnaires, RFP/RFI responses, client audits, evidence packs, ISO 27001/SOC 2 artefacts, penetration test summaries, contractual security schedules and remediation tracking. Security Awareness & Planning Plan and maintain the annual security roadmap ...

Senior Security Engineer

Location
Greater London, England, United Kingdom
security design and architecture reviews, paired with the governance and process work that scales the program. You will partner on customer due‐diligence and SOC 2 evidence and turn security controls into repeatable workflows that fit how the business already works. You will apply that lens across … and DevOps to reduce risk through secure design and simplicity, not just added controls. Governance, Risk & Compliance Partner on customer due‐diligence (DDQ) and SOC 2 Type II evidence gathering, keeping compliance sustainable rather than fire‐drilled. Build repeatable security workflows that embed controls into existing engineering processes ...

Enterprise Infrastructure Engineer

Location
Greater London, England, United Kingdom
align with a cloud-first strategy. Partner with Security to harden the Microsoft 365 tenant and infrastructure estate against relevant compliance frameworks (ISO 27001, SOC 2, DORA). Work closely with senior infrastructure engineers on infrastructure design decisions, escalating complex troubleshooting and design questions as needed. Change Control … Intune and Kandji are compliant, patched, and enrolled to policy. The Microsoft 365 tenant and wider SaaS estate meet relevant compliance frameworks (ISO 27001, SOC 2, DORA). Infrastructure changes are documented, tested, and follow IT change control processes without exception. Technical documentation, runbooks, and architecture records ...

Member of Technical Staff (Platform Leaning)

Location
Greater London, England, United Kingdom
deploy, operate and support wherever it needs to run. We expect you to be relentlessly AI native about it: instead of triaging alerts at 2 am, you'll build or deploy the agent that does it. Instead of reacting to scaling bottlenecks, you'll create systems that spot them … agentic tooling handles a growing share of the toil, and the infrastructure work you touch is compliant by default, keeping our ISO 27001 and SOC 2 journey unblocked. What you'll do No two days will be the same at Tessl! You'll have a high level ...

Lead Security Engineer

Location
Greater London, England, United Kingdom
play a key role in protecting our leadership team from targeted attacks, serve as the technical backbone of our ISO 27001 and SOC 2 programmes, and partner with our DevOps and Platform teams on cloud security. Above all, you'll help us stay safe while keeping our pace. … from targeted phishing, impersonation, business email compromise, and AI-enabled fraud such as deepfakes. Act as the technical owner of our ISO 27001 and SOC 2 controls, from policies and evidence through to auditor walkthroughs. Lead third-party and vendor risk assessments. Respond to and lead security incidents ...

Chief Information Security Officer (CISO)

Location
Greater London, England, United Kingdom
Remanence with confidence. This is a hands‐on role. What you'll work on Build our security program and lead ISO 27001 certification and SOC 2 Type II audits, expanding to additional frameworks as needed. Manage compliance requirements, including GDPR and the EU AI Act, alongside sector‐specific … business continuity, and occasionally support internal IT security, including identity, device management and employee access. Relevant frameworks and technologies Core certifications: ISO 27001 and SOC 2 Type II. You must have led at least one certification or audit end to end. Additional frameworks: Experience with AI, privacy ...

Compliance Officer

Location
Greater London, England, United Kingdom
ensuring that nothing falls through the gaps as the business grows. What you’ll be responsible for Audit & Certification You’ll own the ongoing SOC 2 Type II and ISO 27001:2022 audit lifecycle for an already‐certified organisation: surveillance and recertification audit planning, evidence readiness, auditor liaison … regulatory changes or operational changes, and advising leadership on required updates. Vendor & Third‐Party Risk Conduct and support structured vendor risk assessments, review SOC 2 reports, ISO certificates, and DPAs, maintain the vendor register, and ensure periodic reviews are completed on schedule. Infrastructure & Evidence Navigate AWS, Microsoft Entra ...

Security Engineer, Compliance Focus

Location
Greater London, England, United Kingdom
paperwork exercise at the edge of the business. It is a condition of doing business. We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure in several countries, and deploying into partner data centers. … actually working or only described. What You Will Be Doing Compliance Execution Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline. Operate our GRC platform (Vanta) day to day: configure and ...