Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Deloitte LLP
lead every decision wemake and action we take, guiding us to deliver impact how and where it mattersmost . Connect to your opportunity The SOC2 Manager, Audit & Certification will be perform the following: Lead SOC2 audits and related projects for Deloitte Technology Liaise with … SOC2 external auditors to scope and facilitate SOC2 audits gathering and presenting evidence as required to support DT's SOC2 audits. Understand technology controls, testing of controls, and supporting evidence to meet SOC2 Trust Service Criteria. Understand technology … the confidentiality, integrity, and availability of the information technology environment for on premises as well as cloud hosted IT applications and infrastructure meet the SOC2 Trust Service Criteria. Manage audit findings; identify and track remediation activities to meet target dates for closure, and track/report progress. More ❯
and security risk assessments on suppliers, vendors, and other third parties across the supply chain. Evaluating vendor security postures using evidence-based assessments (e.g., SOC2, ISO 27001, penetration tests). Ensuring third parties meet Evelyn Partners' minimum security standards and apply effective risk mitigations where gaps are … and governance, risk, and compliance . Strong understanding of ISO 27001 (implementation, audit, and continuous improvement), Cyber Essentials, and NIST CSF. Familiarity with reviewing SOC2 Type II, ISO 27001 certifications, and other third-party assurance artefacts. Ability to analyse and evaluate technical and procedural controls in vendor More ❯
and security risk assessments on suppliers, vendors, and other third parties across the supply chain. Evaluating vendor security postures using evidence-based assessments (e.g., SOC2, ISO 27001, penetration tests). Ensuring third parties meet Evelyn Partners' minimum security standards and apply effective risk mitigations where gaps are … and governance, risk, and compliance . Strong understanding of ISO 27001 (implementation, audit, and continuous improvement), Cyber Essentials, and NIST CSF. Familiarity with reviewing SOC2 Type II, ISO 27001 certifications, and other third-party assurance artefacts. Ability to analyse and evaluate technical and procedural controls in vendor More ❯
and security risk assessments on suppliers, vendors, and other third parties across the supply chain. Evaluating vendor security postures using evidence-based assessments (e.g., SOC2, ISO 27001, penetration tests). Ensuring third parties meet Evelyn Partners' minimum security standards and apply effective risk mitigations where gaps are … and governance, risk, and compliance . Strong understanding of ISO 27001 (implementation, audit, and continuous improvement), Cyber Essentials, and NIST CSF. Familiarity with reviewing SOC2 Type II, ISO 27001 certifications, and other third-party assurance artefacts. Ability to analyse and evaluate technical and procedural controls in vendor More ❯
warrington, cheshire, north west england, united kingdom
AMS CWS
and security risk assessments on suppliers, vendors, and other third parties across the supply chain. Evaluating vendor security postures using evidence-based assessments (e.g., SOC2, ISO 27001, penetration tests). Ensuring third parties meet Evelyn Partners' minimum security standards and apply effective risk mitigations where gaps are … and governance, risk, and compliance . Strong understanding of ISO 27001 (implementation, audit, and continuous improvement), Cyber Essentials, and NIST CSF. Familiarity with reviewing SOC2 Type II, ISO 27001 certifications, and other third-party assurance artefacts. Ability to analyse and evaluate technical and procedural controls in vendor More ❯
leigh, greater manchester, north west england, United Kingdom Hybrid / WFH Options
Tenth Revolution Group
on security performance metrics to senior leadership on a monthly basis. Ensure compliance with key frameworks including ISO 27001:2022, ISO 27701:2019, andSOC2 across multiple international offices. Lead internal audits and manage responses to external security assessments. Support third-party risk management, including vendor due … organisational threat awareness. Champion secure behaviours through awareness training and internal communication. Essential: Hands-on experience with ISO 27001, ISO 27701 and/or SOC2 standards. Strong grasp of global data protection laws, particularly GDPR and CCPA. Able to work independently and coordinate with a wide range More ❯
bolton, greater manchester, north west england, United Kingdom Hybrid / WFH Options
Tenth Revolution Group
on security performance metrics to senior leadership on a monthly basis. Ensure compliance with key frameworks including ISO 27001:2022, ISO 27701:2019, andSOC2 across multiple international offices. Lead internal audits and manage responses to external security assessments. Support third-party risk management, including vendor due … organisational threat awareness. Champion secure behaviours through awareness training and internal communication. Essential: Hands-on experience with ISO 27001, ISO 27701 and/or SOC2 standards. Strong grasp of global data protection laws, particularly GDPR and CCPA. Able to work independently and coordinate with a wide range More ❯
ashton-under-lyne, north west england, United Kingdom Hybrid / WFH Options
Tenth Revolution Group
on security performance metrics to senior leadership on a monthly basis. Ensure compliance with key frameworks including ISO 27001:2022, ISO 27701:2019, andSOC2 across multiple international offices. Lead internal audits and manage responses to external security assessments. Support third-party risk management, including vendor due … organisational threat awareness. Champion secure behaviours through awareness training and internal communication. Essential: Hands-on experience with ISO 27001, ISO 27701 and/or SOC2 standards. Strong grasp of global data protection laws, particularly GDPR and CCPA. Able to work independently and coordinate with a wide range More ❯
expand globally, there’s significant scope to evolve this role into a leadership or specialist path. Real Autonomy : Drive the roadmap for frameworks like SOC2and FedRAMP. Lead audits. Own the processes — not just maintain them. High-Caliber Team : You’ll be joining a mission-led organisation … deep expertise in cybercrime disruption and a reputation for punching far above its weight. Core Responsibilities: Architect, manage, and continuously evolve compliance frameworks (e.g., SOC2, Cyber Essentials, FedRAMP). Lead the end-to-end audit lifecycle — from evidence gathering to external walkthroughs. Work closely with legal to More ❯
gaps and control weaknesses. Conduct assessments of cybersecurity frameworks, including access management, vulnerability management, incident response, and endpoint protection. Review and assess vendor-provided SOC 1 andSOC2 reports, evaluating vendor risk and control sufficiency across critical outsourced functions. Audit the full software development lifecycle (SDLC More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
TalkTalk Telecom Group PLC
and experience in security, with demonstratable experience in security risk management. Excellent knowledge in security risk frameworks and best practices such as ISO27001, ISO27005, SOC2, NIST. CISSP, CISM and/or CRISC desirable. Desirable: Telecoms experience advantageous. How we look after our employees Our brand new "PXC Flex" benefit launched More ❯
Liverpool, England, United Kingdom Hybrid / WFH Options
MFK Recruitment
team. The IT Systems Specialist will work primarily a remote role, however, will be required to commute to the office in Liverpool at least 2/3 times a month. MFK Recruitment has recruited 4 IT professionals to this company in the past 18 months. All four individuals are … and really enjoying their roles! As an IT Systems Specialist, the role will ensure seamless onboarding, lead IT infrastructure projects, and support compliance initiatives (SOC2 Type II and ISO 27001 audits). You will manage our core tools (Google Workspace, JumpCloud, HubSpot, 1Password, Jira) while collaborating across teams to optimize … Project Leadership: Migrate systems (e.g., email groups, Jira → HubSpot), implement SSO via JumpCloud, and manage tool integrations. * Compliance Support: Partner with Vanta to maintain SOC2/ISO 27001 readiness; document controls, remediate findings, and prepare audit materials. * IT Operations: Troubleshoot issues, manage device inventory, and enforce security policies (MFA, endpoint More ❯