fully remote UK-based role, you will conduct IT security audits and assessments for clients across the United Kingdom and the European region, ensuring compliance with PCI DSS, ISO27001/ 2, GDPR, NIS2, DORA, and other relevant frameworks. This position offers the opportunity to become a PCI QSA (training and certification sponsored by … ControlCase) while working in an international, collaborative, and growth-focused environment. Responsibilities Lead client audits and compliance assessments across multiple frameworks. Review and analyze systems, applications, databases, and network devices. Assess cloud environments including AWS, Azure, and GCP. Define audit scope, identify risks, and recommend improvements. Provide compliance consulting to help clients meet regulatory requirements. Produce final … experience. Bachelors degree in information security or related field. Deep knowledge of IT security controls, access management, logging, vulnerability assessment, and secure system configuration. Experience with PCI DSS, ISO27001/ 2, GDPR, NIS2, DORA, or similar compliance frameworks. Strong understanding of cloud environments and network architectures. Excellent English communication skills; fluency in German More ❯
Central London / West End, London, United Kingdom Hybrid / WFH Options
CONTROLCASE LIMITED
fully remote UK-based role, you will conduct IT security audits and assessments for clients across the United Kingdom and the European region, ensuring compliance with PCI DSS, ISO27001/ 2, GDPR, NIS2, DORA, and other relevant frameworks. This position offers the opportunity to become a PCI QSA (training and certification sponsored by … ControlCase) while working in an international, collaborative, and growth-focused environment. Responsibilities • Lead client audits and compliance assessments across multiple frameworks. • Review and analyze systems, applications, databases, and network devices. • Assess cloud environments including AWS, Azure, and GCP. • Define audit scope, identify risks, and recommend improvements. • Provide compliance consulting to help clients meet regulatory requirements. • Produce final … Bachelor’s degree in information security or related field. • Deep knowledge of IT security controls, access management, logging, vulnerability assessment, and secure system configuration. • Experience with PCI DSS, ISO27001/ 2, GDPR, NIS2, DORA, or similar compliance frameworks. • Strong understanding of cloud environments and network architectures. • Excellent English communication skills; fluency in German More ❯
City of London, London, United Kingdom Hybrid / WFH Options
CONTROLCASE LIMITED
fully remote UK-based role, you will conduct IT security audits and assessments for clients across the United Kingdom and the European region, ensuring compliance with PCI DSS, ISO27001/ 2, GDPR, NIS2, DORA, and other relevant frameworks. This position offers the opportunity to become a PCI QSA (training and certification sponsored by … ControlCase) while working in an international, collaborative, and growth-focused environment. Responsibilities • Lead client audits and compliance assessments across multiple frameworks. • Review and analyze systems, applications, databases, and network devices. • Assess cloud environments including AWS, Azure, and GCP. • Define audit scope, identify risks, and recommend improvements. • Provide compliance consulting to help clients meet regulatory requirements. • Produce final … Bachelor’s degree in information security or related field. • Deep knowledge of IT security controls, access management, logging, vulnerability assessment, and secure system configuration. • Experience with PCI DSS, ISO27001/ 2, GDPR, NIS2, DORA, or similar compliance frameworks. • Strong understanding of cloud environments and network architectures. • Excellent English communication skills; fluency in German More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Ryder Reid Legal
London-Based) Permanent | Hybrid Working | Competitive Salary I am working with a leading international law firm to support their search for an experienced and proactive Information Security Officer (ISO) to lead their global information and data security programme. This senior-level role offers the opportunity to shape the firm’s long-term security strategy … drive ISO27001 certification, and ensure the resilience of systems and data across offices in the UK, US, and Europe. The position reports to the Director of IT and works closely with regional IT teams and external partners. Key Responsibilities: Lead the firm’s information security governance framework across all offices … and platforms Maintain and enhance the ISO27001-aligned Information Security Management System (ISMS) Ensure compliance with frameworks including CIS Controls, NIST, ISO 27701, and GDPR Oversee incident response, threat detection, and access governance across systems such as iManage, Intapp, Aderant, Microsoft 365, and Azure Drive firm-wide security awareness and More ❯
london (city of london), south east england, united kingdom Hybrid / WFH Options
Ryder Reid Legal
London-Based) Permanent | Hybrid Working | Competitive Salary I am working with a leading international law firm to support their search for an experienced and proactive Information Security Officer (ISO) to lead their global information and data security programme. This senior-level role offers the opportunity to shape the firm’s long-term security strategy … drive ISO27001 certification, and ensure the resilience of systems and data across offices in the UK, US, and Europe. The position reports to the Director of IT and works closely with regional IT teams and external partners. Key Responsibilities: Lead the firm’s information security governance framework across all offices … and platforms Maintain and enhance the ISO27001-aligned Information Security Management System (ISMS) Ensure compliance with frameworks including CIS Controls, NIST, ISO 27701, and GDPR Oversee incident response, threat detection, and access governance across systems such as iManage, Intapp, Aderant, Microsoft 365, and Azure Drive firm-wide security awareness and More ❯
McFall Recruitment are partnering with a Financial Services company seeking a pragmatic and experienced Head of Cyber Security Governance, Risk & Compliance to lead and evolve our global Information Security control framework. This pivotal role will shape the resilience, responsiveness, and maturity of our Information Security function across all regions and business units. Reporting directly to the Chief … you’ll play a key leadership role in transforming Cyber Security —enhancing people, processes, and technology to protect the business and maintain operational resilience. What you’ll do Lead the global Cyber Security risk management programme , driving best-in-class governance and compliance. Develop and maintain cybersecurity policies, standards, and procedures aligned with regulatory requirements and business … evaluations, and oversee treatment planning. Embed cyber risk into enterprise risk frameworks through collaboration with global teams. Oversee vendor risk management and ensure third-party compliance. Chair and lead the Cyber Security Digital Resilience Forum . Support the NIST maturity uplift programme and alignment with ISO27001:2022 . Ensure compliance More ❯
london (city of london), south east england, united kingdom
McFall Recruitment Limited
McFall Recruitment are partnering with a Financial Services company seeking a pragmatic and experienced Head of Cyber Security Governance, Risk & Compliance to lead and evolve our global Information Security control framework. This pivotal role will shape the resilience, responsiveness, and maturity of our Information Security function across all regions and business units. Reporting directly to the Chief … you’ll play a key leadership role in transforming Cyber Security —enhancing people, processes, and technology to protect the business and maintain operational resilience. What you’ll do Lead the global Cyber Security risk management programme , driving best-in-class governance and compliance. Develop and maintain cybersecurity policies, standards, and procedures aligned with regulatory requirements and business … evaluations, and oversee treatment planning. Embed cyber risk into enterprise risk frameworks through collaboration with global teams. Oversee vendor risk management and ensure third-party compliance. Chair and lead the Cyber Security Digital Resilience Forum . Support the NIST maturity uplift programme and alignment with ISO27001:2022 . Ensure compliance More ❯
you enjoy simplifying regulatory challenges, designing pragmatic governance models, and influencing security strategy at scale this could be your next move. Key Responsibilities Translate international standards (NIST CSF, ISO27001, GDPR, SOC 2, PCI DSS, CSA CCM) into actionable policies and controls. Design and implement unified compliance frameworks across cloud, hybrid, and enterprise systems. … Lead internal and external audits, certification readiness, and regulatory assurance activities. Conduct risk assessments, control testing, and third-party assurance programs. Stay ahead of evolving regulations, standards, and automation opportunities. Prepare and deliver executive-level compliance reports and dashboards. Mentor junior consultants and collaborate closely with cross-functional teams. What We’re Looking For 6–8+ years … knowledge of compliance automation tools (ServiceNow GRC, OneTrust, Archer, or similar). Excellent communication and stakeholder management skills, including C-level engagement. Preferred Certifications CISM, CISA, CRISC, CISSP, ISO27001LeadImplementer/ Auditor, CCSK, AWS Security Specialty, GDPR Practitioner. If you’re a cybersecurity professional passionate about More ❯
london (city of london), south east england, united kingdom
Discovered MENA
you enjoy simplifying regulatory challenges, designing pragmatic governance models, and influencing security strategy at scale this could be your next move. Key Responsibilities Translate international standards (NIST CSF, ISO27001, GDPR, SOC 2, PCI DSS, CSA CCM) into actionable policies and controls. Design and implement unified compliance frameworks across cloud, hybrid, and enterprise systems. … Lead internal and external audits, certification readiness, and regulatory assurance activities. Conduct risk assessments, control testing, and third-party assurance programs. Stay ahead of evolving regulations, standards, and automation opportunities. Prepare and deliver executive-level compliance reports and dashboards. Mentor junior consultants and collaborate closely with cross-functional teams. What We’re Looking For 6–8+ years … knowledge of compliance automation tools (ServiceNow GRC, OneTrust, Archer, or similar). Excellent communication and stakeholder management skills, including C-level engagement. Preferred Certifications CISM, CISA, CRISC, CISSP, ISO27001LeadImplementer/ Auditor, CCSK, AWS Security Specialty, GDPR Practitioner. If you’re a cybersecurity professional passionate about More ❯
City of London, London, United Kingdom Hybrid / WFH Options
55 Exec Search
in regulated or high-availability environments (e.g., aviation, manufacturing, critical infrastructure) is advantageous but not essential. Desirable certifications: CISSP, CISM, or CISA. SABSA, TOGAF, or other architecture certifications. ISO27001Lead Auditor / Implementer. Azure cloud certifications. Why join our client: You’ll be part of a forward-thinking consultancy where More ❯