risks, regulatory exposure, and investment priorities to support long-term growth. Governance & Compliance Own company-wide security governance, including data protection, access control, and insider risk. Ensure compliance with SOC2, ISO 27001, GDPR, and other relevant frameworks. Oversee security audits and third-party risk programs. Risk Management & Threat Intelligence Lead threat modelling, risk assessments, and security reviews … Deep understanding of cloud security (especially AWS), application security, and modern DevSecOps. Proven experience securing systems involving digital assets, cryptographic components, or distributed infrastructure. Strong grasp of regulatory frameworks: SOC2, ISO 27001, GDPR, NIST, etc. Background in threat modeling, incident response, and risk management. Excellent leadership, communication, and stakeholder skills. Bachelor's or advanced degree in Computer More ❯
stakeholders across our business. What you'll get to do: Compliance Management: Support the day-to-day management of our compliance programs, with a primary focus on ISO 27001 , SOC2 , and PCI DSS/3DS . Audit Support: Act as a key liaison for internal and external auditors, helping to gather evidence, prepare for audits, and track … GRC program and related processes. Essential A minimum of 3 years of experience in an information security role. Proven experience in supporting and managing compliance efforts for ISO 27001, SOC2, and PCI DSS. Strong skills in security metrics and reporting. Experience with audit processes and evidence collection. A proactive, organized, and detail-oriented approach to your work. … come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team: Stage 1 - 45 mins with BISO Stage 2 - 60 min with Team Members Stage 3 - Final with CTO 33 days holiday (including public holidays, which you can take when it works best for you) An extra day More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Starling Bank Limited
stakeholders across our business. What you'll get to do: Compliance Management: Support the day-to-day management of our compliance programs, with a primary focus on ISO 27001 , SOC2 , and PCI DSS/3DS . Audit Support: Act as a key liaison for internal and external auditors, helping to gather evidence, prepare for audits, and track … GRC program and related processes. Essential A minimum of 3 years of experience in an information security role. Proven experience in supporting and managing compliance efforts for ISO 27001, SOC2, and PCI DSS. Strong skills in security metrics and reporting. Experience with audit processes and evidence collection. A proactive, organized, and detail-oriented approach to your work. … come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team: Stage 1 - 45 mins with BISO Stage 2 - 60 min with Team Members Stage 3 - Final with CTO 33 days holiday (including public holidays, which you can take when it works best for you) An extra day More ❯
and expansion opportunities within your book of business Become a product expert on Vanta and how our platform can be used to improve security posture through our compliance offerings (SOC2, ISO 27001, GDPR, HIPAA, USDP and Custom Frameworks), Trust Reports, and Risk Management solution. Guide implementation, configuration, and optimization of Vanta Trust Management Platform Provide professional advice … inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security.From our early days automating security monitoring for compliance standards like SOC2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. Now more than ever, making security continuous-not just a More ❯
and expansion opportunities within your book of business Become a product expert on Vanta and how our platform can be used to improve security posture through our compliance offerings (SOC2, ISO 27001, GDPR, HIPAA, USDP and Custom Frameworks), Trust Reports, and Risk Management solution. Guide implementation, configuration, and optimization of Vanta Trust Management Platform Provide professional advice … inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security.From our early days automating security monitoring for compliance standards like SOC2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. Now more than ever, making security continuous-not just a More ❯
Access, Entra ID, and Identity Governance setups Implement Data Loss Prevention (DLP) and sensitivity labels Work with Azure Key Vault and manage encryption and certificate strategies Collaborate with our SOCand managed Sentinel provider on incident handling Compliance & Governance Help ensure compliance with ISO 27001, SOC2, GDPR, and NIS2 Support configuration and monitoring in Microsoft Compliance More ❯
Define service level objectives (SLOs) and key performance indicators (KPIs) for all security services. Compliance, Governance & Risk Management: Ensure alignment with global compliance requirements such as ISO 27001, NIST, SOC2, GDPR, and others. Partner with governance, legal, and ISRM teams to implement enforceable policies and standards across identity, endpoint, and data domains. Operationalize policy enforcement through automated More ❯
tools (EDR, vulnerability scanners, SCA, etc.) Own and manage internal authentication (SSO, MFA, identity lifecycle) Secure endpoints, laptops, and internal systems Lead security awareness and employee training programs Drive SOC 1/2and other compliance frameworks Build internal security policies, playbooks, and operational processes Manage relationships with vendors, auditors, and pentesters We're Looking For Someone Who … or similar certification Strong knowledge of cloud security, secure software development, and common vulnerabilities Proven experience securing production environments and CI/CD systems Familiarity with security compliance frameworks (SOC2, ISO 27001) Experience deploying and operationalising security tools Excellent communication skills and the ability to collaborate across teams A pragmatic, system-oriented mindset that balances risk andMore ❯
dunfermline, north east scotland, united kingdom Hybrid / WFH Options
Kosli
Anchore) Programming and scripting languages (Python, Go, YAML, JSON etc.) A background in financial services or similar regulated industries. Familiarity with compliance frameworks, and security requirements (e.g., ISO 27001, SOC2, SOX, PCI DSS, FedRAMP, FFIEC, NYDFS, and SEC compliance requirements) A track record in consulting , solutions architecture , or technical coaching . Interest in technical sales and supporting More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
InvitISE Ltd
sector, based in London, on a permanent basis paying up to £65,000 plus great benefits. This role offers hybrid working with an expectation to be in the office 2-3 days per week. You’ll be joining a technical team focused on strengthening cloud security and ensuring compliance across Microsoft Azure environments. This role will involve hands-on … essential Microsoft Purview, Compliance Manager and related compliance tools Entra ID (Azure AD), Conditional Access and Identity Governance Data Loss Prevention, sensitivity labels and insider risk management ISO 27001, SOC2, GDPR and NIS2 frameworks PowerShell scripting and use of Microsoft Graph API Working across cloud, infrastructure and application teams Certifications required: AZ-500 SC-100 (or working More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
InvitISE Ltd
sector, based in London, on a permanent basis paying up to £70,000 plus great benefits. This role offers hybrid working with an expectation to be in the office 2–3 days per week. You’ll be joining a technical team focused on strengthening cloud security and ensuring compliance across Microsoft Azure environments. This role will involve hands-on … essential Microsoft Purview, Compliance Manager and related compliance tools Entra ID (Azure AD), Conditional Access and Identity Governance Data Loss Prevention, sensitivity labels and insider risk management ISO 27001, SOC2, GDPR and NIS2 frameworks PowerShell scripting and use of Microsoft Graph API Working across cloud, infrastructure and application teams Certifications required: AZ-500 SC-100 (or working More ❯
WC1A, Tottenham Court Road, Greater London, United Kingdom Hybrid / WFH Options
Invitise
sector, based in London, on a permanent basis paying up to £70,000 plus great benefits. This role offers hybrid working with an expectation to be in the office 2–3 days per week. You’ll be joining a technical team focused on strengthening cloud security and ensuring compliance across Microsoft Azure environments. This role will involve hands-on … essential Microsoft Purview, Compliance Manager and related compliance tools Entra ID (Azure AD), Conditional Access and Identity Governance Data Loss Prevention, sensitivity labels and insider risk management ISO 27001, SOC2, GDPR and NIS2 frameworks PowerShell scripting and use of Microsoft Graph API Working across cloud, infrastructure and application teams Certifications required: AZ-500 SC-100 (or working More ❯
Central London, London, United Kingdom Hybrid / WFH Options
Invitise Ltd
essential Microsoft Purview, Compliance Manager and related compliance tools Entra ID (Azure AD), Conditional Access and Identity Governance Data Loss Prevention, sensitivity labels and insider risk management ISO 27001, SOC2, GDPR and NIS2 frameworks PowerShell scripting and use of Microsoft Graph API Working across cloud, infrastructure and application teams Certifications required: AZ-500 SC-100 (or working More ❯
Hemel Hempstead, Hertfordshire, United Kingdom Hybrid / WFH Options
Eckoh
with message-based architectures and tools like RabbitMQ, Kafka, or Kinesis Demonstrable experience building LLM backed systems and applications Understanding of regulatory and compliance frameworks (e.g., PCI, ISO 27001, SOC2, GDPR) and how to apply them in software and cloud system design AWS certifications (e.g., Developer Associate, Data Analytics Specialty) Please click the APPLY button to send More ❯
Hemel Hempstead, Hertfordshire, South East, United Kingdom Hybrid / WFH Options
Eckoh PLC
with message-based architectures and tools like RabbitMQ, Kafka, or Kinesis Demonstrable experience building LLM backed systems and applications Understanding of regulatory and compliance frameworks (e.g., PCI, ISO 27001, SOC2, GDPR) and how to apply them in software and cloud system design AWS certifications (e.g., Developer Associate, Data Analytics Specialty) Please click the APPLY button to send More ❯
and non-technical stakeholders. Adaptive, proactive, and grounded in high-integrity problem solving. Bonus Qualifications Understanding of European regulations (e.g. MiFID II, GDPR, CASS). Familiarity with ISO 27001, SOC2, or similar frameworks. Experience with Agile, Scrum, MSP, or software product lifecycle knowledge. Enhanced leave - 38 days inclusive of 8 UK Public Holidays Private Health Care including More ❯
America. Leverage your knowledge of financial services, employee benefits, or insurance to inform strategic decisions. Work with cloud-based platforms, data protocols, and compliance frameworks like GDPR, HIPAA, or SOC 2. Champion great user experiences by effectively translating between customer needs and UX delivery. Your Wishlist of Skills We’re excited to hear from people who can bring some More ❯
America. Leverage your knowledge of financial services, employee benefits, or insurance to inform strategic decisions. Work with cloud-based platforms, data protocols, and compliance frameworks like GDPR, HIPAA, or SOC 2. Champion great user experiences by effectively translating between customer needs and UX delivery. Your Wishlist of Skills We’re excited to hear from people who can bring some More ❯
Job Title: Head of Engineering Location: 2-3 days on site in Cambridge Salary: 130k + benefits (salary depending on experience, may be some flex for the right person). This is a rare opportunity to help shape the foundation of the next-generation fintech infrastructure! Our client, an exciting start-up within the Fintech space are looking to … with data models, APIs, service-oriented and event-driven systems. - Solid knowledge of CI/CD, automated testing, and DevOps best practices. Familiar with compliance and security standards (ISO27001, SOC2, GDPR, DORA). - Proven ability to mentor engineers, grow teams, and build an inclusive culture. - Strong communication skills with both technical and non-technical stakeholders. - Effective at More ❯
Cambridge, Impington, Cambridgeshire, United Kingdom
SoCode Limited
Job Title: Head of Engineering Location: 2-3 days on site in Cambridge Salary: £130k + benefits (salary depending on experience, may be some flex for the right person). This is a rare opportunity to help shape the foundation of the next-generation fintech infrastructure! Our client, an exciting start-up within the Fintech space are looking to … with data models, APIs, service-oriented and event-driven systems. - Solid knowledge of CI/CD, automated testing, and DevOps best practices. Familiar with compliance and security standards (ISO27001, SOC2, GDPR, DORA). - Proven ability to mentor engineers, grow teams, and build an inclusive culture. - Strong communication skills with both technical and non-technical stakeholders. - Effective at More ❯
SLAs) are met or exceeded. Manage relationships with key vendors and contractors. Compliance & Audits: Ensure the facility operates in strict adherence to industry standards and regulations (e.g., ISO 27001, SOC2, etc.). Prepare for and lead internal and external audits. Health & Safety: Be the on-site safety champion, enforcing strict health and safety protocols and conducting regular … efficiency, reduce costs, and enhance the overall performance of the facility. Candidate Requirements Proven Experience: A minimum of 5 years of experience in data centre operations, with at least 2-3 years in a lead, management or supervisory role. Technical Expertise: Strong understanding of data centre infrastructure, including high-voltage power distribution, UPS systems, generators, CRAC/CRAH units More ❯
SLAs) are met or exceeded. Manage relationships with key vendors and contractors. Compliance & Audits: Ensure the facility operates in strict adherence to industry standards and regulations (e.g., ISO 27001, SOC2, etc.). Prepare for and lead internal and external audits. Health & Safety: Be the on-site safety champion, enforcing strict health and safety protocols and conducting regular … efficiency, reduce costs, and enhance the overall performance of the facility. Candidate Requirements Proven Experience: A minimum of 5 years of experience in data centre operations, with at least 2-3 years in a lead, management or supervisory role. Technical Expertise: Strong understanding of data centre infrastructure, including high-voltage power distribution, UPS systems, generators, CRAC/CRAH units More ❯
Maidenhead, Berkshire, United Kingdom Hybrid / WFH Options
Opus Recruitment Solutions Ltd
for global collaboration Nice to Have Experience with ERP/financial integrations Swagger/OpenAPI, Azure, Power Automate, Zapier Exposure to IoT or telematics platforms Awareness of ISO 27001, SOC2 Why Join? Award-winning culture focused on respect, innovation, and growth Flexible hybrid working from our Maidenhead office Work on impactful global SaaS products Apply with an More ❯
of network security protocols and best practices. Scripting and automation experience (e.g. Python). Proven experience with incident response and threat mitigation. Familiarity with security compliance frameworks (ISO 27001, SOC2, etc.). Security certifications (e.g. Security+, CISSP, or equivalent) are a plus. You'll Thrive If You Are: Comfortable taking ownership and working autonomously in a high More ❯
Maidenhead, Berkshire, South East, United Kingdom Hybrid / WFH Options
Oscar Associates (UK) Limited
Swagger/OpenAPI documentation for Open APIs Familiarity with Azure services and automation tools like Power Automate or Zapier Exposure to IoT or Telematics platforms Awareness of ISO 27001, SOC2, or GDPR compliance standards Benefits: Competitive base salary Hybrid working Private healthcare Exciting and unique projects Pension scheme If you are a Senior .NET Developer experienced in More ❯