26 to 50 of 401 SOC 2 Jobs in England

Security Engineer

Location
Greater London, England, United Kingdom
large case files, test arguments and produce high-quality work grounded in the full matter record. Crimson is enterprise-grade by design. We are SOC 2 Type II attested, encrypt data in transit and at rest, and maintain rigorous controls across our product, infrastructure and operations. Security … continuous learning Coordinate independent penetration testing and represent Crimson's security posture in customer security reviews Maintain the controls and evidence supporting Crimson's SOC 2 Type II attestation and enterprise customer requirements Embed practical security guidance and tooling into a fast-moving engineering environment What ...

Deputy Chief Technology Officer

Location
Greater London, England, United Kingdom
group-level data capability is live with a published catalog and cross-divisional SLAs. Regulatory & Cost Control: Engineering consistently hits all MiCA, DORA, and SOC 2 milestones while managing cloud and vendor spend against clear business-unit baselines. Key Responsibilities Engineering Delivery & Cadence: Run day-to-day global … group data pipelines and governance. Cybersecurity Execution & Compliance: Own the on-the-ground execution of The Company’s security and regulatory commitments (MiCA, DORA, SOC 2). Foster a "controls-by-design" engineering culture while respecting regulated divisional information walls. Talent, Budget & Scale: Manage the global engineering budget ...

Head of Business Systems & Security New Manchester, England, United Kingdom

Location
Manchester, England, United Kingdom
that keeps the company working. That covers NetSuite, Salesforce, Workato and DealHub among others, the integration layer and data definitions beneath them, SOC 2 and access control, and the full device and application estate across our UK, US and Portugal teams. It is a broad, senior remit with … integrations that connect them, and the data governance underneath. Set the architecture, operating model and roadmap for how Reachdesk uses its systems. Own the SOC 2 Type II programme, the security policy set and the risk register as the accountable business owner. Own identity and access management, joiner ...

Head of Business Systems & Security New Birmingham, England, United Kingdom

Location
Birmingham, England, United Kingdom
that keeps the company working. That covers NetSuite, Salesforce, Workato and DealHub among others, the integration layer and data definitions beneath them, SOC 2 and access control, and the full device and application estate across our UK, US and Portugal teams. It is a broad, senior remit with … integrations that connect them, and the data governance underneath. Set the architecture, operating model and roadmap for how Reachdesk uses its systems. Own the SOC 2 Type II programme, the security policy set and the risk register as the accountable business owner. Own identity and access management, joiner ...

IT Operations Manager

Location
Greater London, England, United Kingdom
when necessary to support them. You will own the IT strategy and roadmap, service performance, vendor procurement outcomes, and the IT control environment, including SOC 2, Cyber Essentials, and GDPR-related IT controls. You will plan and manage the project portfolio, hold vendors and the team to account … outcome, the Indeed relationship, and vendor performance Security, Risk & Compliance: Own the IT control environment and security posture, including policy, access standards, SOC 2, Cyber Essentials, GDPR-related IT controls, and audit outcomes. Direct the team's evidence gathering and control maintenance, and represent IT on security and ...

Remote Associate, SOC Assessment

Hiring Organisation
Coalfire
Location
Wiltshire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...

Remote Associate, SOC Assessment

Location
Nottinghamshire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...

Remote Associate, SOC Assessment

Location
London, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...

Remote Associate, SOC Assessment

Location
Essex, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...

Remote Associate, SOC Assessment

Location
Lewes, Sussex, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...

Remote Associate, SOC Assessment

Location
Newtown, Hampshire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...

Remote Associate, SOC Assessment

Location
Nuneaton, Warwickshire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...

Remote Associate, SOC Assessment

Location
Reading, Berkshire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...

Remote Associate, SOC Assessment

Location
Stockport, Cheshire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...

Digital Third Party Assurance Assistant Manager

Hiring Organisation
BDO UK
Location
London, United Kingdom
will support organisations in building trust and confidence with their customers, regulators and business partners. You will have the opportunity to work on SOC 1, SOC 2, ISAE 3402 and ISAE 3000 engagements, certification programmes such as ISO 27001 and ISO 42001, and assurance projects focused … engagements relating to technology, cybersecurity, privacy or operational controls. Strong ITGC testing understanding.Strong understanding of assurance frameworks and standards, including one or more of: SOC 1/ISAE 3402, SOC 2, ISAE 3000, ISO 27001, PCI DSS, HITRUST or other recognised assurance or certification frameworksUnderstanding of digital ...

Head of Security

Location
Greater London, England, United Kingdom
and close the coverage gaps where some products are today outside the standard tooling. Governance, risk and compliance and vendor management Own ISO 27001, SOC 1, SOC 2 and PCI DSS compliance, the audit calendar, the compliance automation platform and the relationship with our auditors. Work with … software or SaaS company serving regulated enterprise customers, and of facing those customers on security matters. Working knowledge of ISO 27001 and SOC 2, and experience of being accountable for audits and certifications. PCI DSS experience is an advantage. Practical understanding of cloud security on AWS and Azure ...

Senior GRC Content Engineer

Location
Greater London, England, United Kingdom
auditors ask for, how evidence is collected and presented, findings and management responses Familiarity with third‐party/vendor risk: due‐diligence questionnaires, reading SOC 2 reports, contractual security requirements A solid understanding of the technical side of security (networks, systems, cloud, common attack patterns) — enough to keep … taught this material to real audiences (workshops, bootcamps, internal training, university teaching) Experience designing or facilitating tabletop exercises or crisis simulations Exposure to SOC 2 (Type 2) readiness or audit support, PCI‐DSS, or sector frameworks (HIPAA, CMMC, Cyber Essentials) Familiarity with GRC platforms (Drata, Vanta, OneTrust ...

VP of Security & Infrastructure

Location
Greater London, England, United Kingdom
search indexes. Regulatory & Compliance Engineering: Deliver and oversee the performance of technical controls, automated evidence extraction, and ongoing compliance for ISO 27001, ISO 27701, SOC 2 Type 2, HIPAA, EU AI Act, and Cyber Resilience Act. Third-Party & Supply-Chain Risk: Establish evaluation criteria and ongoing governance … and Mobile/Backend Engineering teams to ship user-facing features to roadmap. Audit Track Record: Successful execution and ongoing maintenance of ISO 27001, SOC 2, HIPAA, or equivalent certification frameworks through external audits. Data Privacy Systems: Deep technical experience implementing GDPR, automated data deletion, retention policies, DPIAs ...

Senior GRC & Compliance Lead (SOC 2 Focus)

Location
Greater London, England, United Kingdom
Preply is seeking a Senior GRC Analyst to join our Cybersecurity team. You will shape and scale the governance, risk, and compliance program, ensuring SOC 2 Type 2 readiness and expanding into ISO 27001. You’ll partner with Legal, Engineering, Security, Product, and Finance to translate regulations ...

Staff Cloud Security Engineer (GCP) - Engine by Starling

Hiring Organisation
Starling Bank
Location
London, UK
Employment Type
Full-time
and Access Transparency, relevant to deploying per-market for different banks' regulatorsHands-on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSSExperience automating security controls and compliance checks against standards and frameworks including SOC 2 ...

Senior Cloud Security Engineer (GCP) - Engine by Starling

Location
City Of London, England, United Kingdom
Access Transparency, relevant to deploying per-market for different banks' regulators Hands‐on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSS Experience automating security controls and compliance checks against standards and frameworks including SOC 2 ...

Staff Cloud Security Engineer (GCP) - Engine by Starling

Location
Greater London, England, United Kingdom
Access Transparency, relevant to deploying per-market for different banks' regulators Hands-on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSS Experience automating security controls and compliance checks against standards and frameworks including SOC 2 ...

Security & Compliance Lead: ISO27001/SOC Expert – Hybrid

Location
Wallingford, England, United Kingdom
Dexory is transforming warehousing and logistics with data intelligence in the UK. We seek an Information Security Lead to own ISO 27001, SOC 1 Type 2, and SOC 2 Type 2 programmes, and to respond to customer security due diligence across engineering, product and operations. ...

Senior Trust Security Analyst

Location
Greater London, England, United Kingdom
activities across engineering and security teams, ensuring alignment with agreed timelines and compliance requirements. Audit Audit Interpretation: Read and interpret third-party audit reports (SOC 2 Type II, ISO 27001, penetration test summaries) and represent findings to customers in questionnaires and security responses. Communication & Stakeholder Management Information Translation … experience responding to SIG, CAIQ, VSA, and bespoke enterprise/government security questionnaires. Compliance Knowledge: Working knowledge of Cyber Essentials Plus, ISO 27001, SOC 2 Type II, and at least one of PCI DSS, GDPR/UK GDPR, HIPAA, or FedRAMP. Technical Expertise: Strong technical understanding of security ...

Senior Cybersecurity Consultant

Location
Greater London, England, United Kingdom
creating operational friction. Responsibilities Lead penetration testing and vulnerability assessment engagements Design security architectures for cloud-native and hybrid environments Develop security compliance programs (SOC 2, ISO 27001, GDPR) Conduct incident response planning and tabletop exercises Advise C-level executives on security strategy and risk management Requirements 8+ … years in information security with consulting experience Deep expertise in penetration testing, vulnerability management, and threat modeling Knowledge of compliance frameworks: SOC 2, ISO 27001, GDPR, PCI-DSS Experience with cloud security (AWS Security Hub, Azure Defender, or GCP Security Command Center) CISSP, OSCP, or equivalent certification Nice ...