optimise payment processes, ensuring transactions run smoothly and reliably. Share your expertise with the team through code reviews, documentation, and knowledge-sharing sessions. Implement industry-standardsecurity practices, including PCIDSS considerations, fraud prevention, and rate limiting. Integrate with third-party payment gateways and APIs while ensuring compliance with local and international regulations. Partner with product managers to … issues for non-technical audiences. Collaborative mindset with openness to feedback and new ideas. Strong problem-solving skills with both critical and creative thinking. Familiarity with compliance frameworks (GDPR, PCIDSS, PSD2). Experience handling multiple currencies, sales tax, 3D Secure, tokenization, fraud prevention, and disputes/chargebacks. Bonus Points Experience with brewing PHP fixes while fending off More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Sanderson
artefacts including standards and blueprints. What You'll Bring Prior and proven experience gained as a Security Architect or in a technical cyber role. Expertise in: Security legislation (GDPR, PCIDSS, ICO) Frameworks (ISO 27001, NIST CSF, CIS Controls v8) HMG/NCSC policies and guidance Cloud security (AWS, Azure) Microservice architectures PKI, Cryptography, Privileged Access Management Certifications More ❯
Application Firewalls, Intrusion Detection/Prevention, Incident Response, and Security Information and Event Management (SIEM), Identify and Access Management (IAM) controls. Implementation experience with compliance frameworks such as NIST, PCI-DSS, ISO/IEC 27001, ISO/IEC 27017, FISC, etc Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status More ❯
finish. Bonus points if you bring: Experience with AppSec and DevSecOps. Hands-on knowledge of Azure, AWS, and/or Google Cloud. Familiarity with standards like ISO2700X, ISO31000, NIST800, PCI-DSS. Certifications such as CISSP, CCSP, CRISC, CISM, or SABSA. Why QBE? At My Best? At QBE, we want our people to feel rewarded and inspired to perform at More ❯
capabilities and infrastructure. Implementation experience with enterprise security solutions such as SSO, Federation, WAF, IPS, Anti-DDOS, and SIEM and understanding architectural implications of meeting industry standards such as PCIDSS, ISO 27001, GDPR, and NIST frameworks and relevant regulatory frameworks such as Thailand's Personal Data Protection Act B.E. 2562 (2019), BOT Notifications SorNorSor 21/ More ❯
within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCIDSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll need Proven experience More ❯
South East London, London, United Kingdom Hybrid / WFH Options
TEN10 SOLUTIONS LIMITED
Understanding of IAM, WAF, and KMS. Experience implementing best practices for securing data, ensuring compliance with industry standards and regulations. Bonus points for experience with a compliance framework (ISO27001, PCI-DSS). Infrastructure-as-Code: Mastery of Terraform, CloudFormation, CDK or equivalent tools. Scripting & Automation: Skills in a scripting language like Python, Ansible, Bash, Groovy, Powershell, or similar. More ❯
Understanding of IAM, WAF, and KMS. Experience implementing best practices for securing data, ensuring compliance with industry standards and regulations. Bonus points for experience with a compliance framework (ISO27001, PCI-DSS). Infrastructure-as-Code: Mastery of Terraform, CloudFormation, CDK or equivalent tools. Scripting & Automation: Skills in a scripting language like Python, Ansible, Bash, Groovy, Powershell, or similar. More ❯
high availability, resilience, and scalability. Develop and regularly test Disaster Recovery Plans (DRP) and business continuity frameworks. Cybersecurity and Compliance Implement and maintain standards such as ISO27001, SOC2, GDPR, PCI DSS. Ensure compliance with regulatory requirements (FCA, CySEC, FINMA, ADGM, etc.). Conduct ongoing risk monitoring and IT audits. Vendor and Outsourcing Management Manage Managed Service Providers and external More ❯
Understanding of IAM, WAF, and KMS. Experience implementing best practices for securing data, ensuring compliance with industry standards and regulations. Bonus points for experience with a compliance framework (ISO27001, PCI-DSS). I nfrastructure-as-Code: Experience with Terraform, CloudFormation, CDK or equivalent tools. Scripting & Automation: Skills in Python, Ansible, Bash, Groovy, Powershell, or similar. Bonus points if More ❯
solutions. Bachelor's degree in Computer Science, Engineering, or related field (or equivalent practical experience). Preferred Qualifications Experience verticalising conversational solutions for healthcare (HIPAA, PHI) and financial services (PCIDSS, FFIEC) regulatory environments. Deep familiarity with WhatsApp Business API, web socket or webhook architectures, and common live chat SDKs. Prior ownership of multi modal (voice+chat) conversational platforms More ❯
to identify performance trends, flag anomalies, and propose data-backed actions that drive business impact. Stay on top of global payments regulations, card scheme rules, and industry developments (e.g. PCI-DSS, PSD2, network tokenisation) to ensure compliance and future readiness. Drive strategic initiatives such as smart retries, fallback orchestration, and alternative payment methods (e.g. wallets, open banking), building … excellence by conducting daily and monthly monitoring of KPIs across platforms such as CYBS, Stripe, and Adyen; escalate and act on irregularities promptly. Document and lead compliance efforts, including PCI user access reviews, audit prep, and implementation of regulatory bulletins or scheme mandates. Maintain hands-on fluency with systems such as Zuora, Snowflake and Tableau to extract and interpret … retry strategies, ideally on the merchant side within a subscription-based business model. Deep knowledge of card scheme rules, fraud tools (e.g. Decision Manager), and payment regulations (e.g. PSD2, PCI, 3DS2). Experience with network tokenisation, orchestration, vaulting, smart retries, and fallback routing. Strong vendor management and negotiation skills. Proficiency in analysing large volumes of transactional data and extracting More ❯
Employment Type: Permanent
Salary: £80000 - £85000/annum Plus bonus and benefits
Teradata, FIBO, or BIAN · Knowledge of data product management, data management, metadata management, data lineage management, and data definitions · Proficiency when designing with concepts and regulations such as GDPR, PCI-DSS, PII · A basic understanding of knowledge and/or property graphs, taxonomies and ontologies (OWL, SHACL) Carbon60, Lorien & SRG - The Impellam Group STEM Portfolio are acting as More ❯
Have: Experience in fintech, payments, or banking systems Exposure to serverless architecture Knowledge of event-driven systems (Kafka, SNS/SQS) Familiarity with security best practices in fintech (e.g., PCIDSS compliance) Experience with PostgreSQL or MongoDB This role offers a 2 -3 stage interview process with a 3 day a week in the office hybrid working pattern More ❯
analysis, and threat modelling. Security Operations (SOC) : Overseeing monitoring, incident response, vulnerability management, and operational resilience. Governance, Risk & Compliance (GRC) : Leading our efforts to achieve and maintain compliance with PCI, GDPR, SOC2, and ISO27001. Vendor Security : Spearheading due diligence and monitoring of third parties, integrated with our Vendor Governance Forum. Policies & Assurance : Defining and enforcing security standards, collaborating with … Operations : You have deep experience overseeing a Security Operations function, managing monitoring, incident response, and vulnerability management. Driving GRC : You're an expert in managing compliance frameworks such as PCI, GDPR, SOC2, and ISO 27001, and you're skilled at preparing for audits. Vendor Security : You have led vendor security analysis, including due diligence and ongoing monitoring. Collaboration & Execution More ❯
Participate and conduct onsite assessments of Third Parties against Visa's security framework and industrysecurity standards. Support risk/security assessments for special projects involving Third Parties. Support PCI-related activities relevant to third parties to ensure compliance with PCI requirements. Exhibit pragmatism in formulating process remediation and implementation strategies, defining work tracks, and submitting assessment findings … in cybersecurity, IT audit, or IT risk management. Experience in cybersecurity, IT audit, risk management, compliance, or related fields. Knowledge of cybersecurity frameworks and standards such as NIST, ISO, PCI, etc. Generative AI: Proven experience in developing solutions using Large Language Models and AI frameworks such as LangChain, Hugging Face, or OpenAI. Agentic AI: Experience with the concepts and More ❯
security GRC automation tooling (Vanta) and work across the business to maintain security compliance posture. Successfully lead internal and external security audits - ISO 27001/SOC2 Type II/PCI-DSS. Champion a company-wide culture of security awareness and operational resilience by playing a key role in defining, maintaining, and managing security incident response and threat intelligence procedures. … effectively to find the missing details. ISO 27001 et al - You have built and maintained an ISO 27001 certified ISMS before and led other important security audit assessments (SOC2, PCI, etc.). You may have also gained ISO 27001 Lead Auditor or alike certifications (a plus). Collaborator Extraordinaire - Strong communications skills with the ability to explain technical and More ❯
security GRC automation tooling (Vanta) and work across the business to maintain security compliance posture. Successfully lead internal and external security audits - ISO 27001/SOC2 Type II/PCI-DSS. Champion a company-wide culture of security awareness and operational resilience by playing a key role in defining, maintaining, and managing security incident response and threat intelligence procedures. … effectively to find the missing details. ISO 27001 et al - You have built and maintained an ISO 27001 certified ISMS before and led other important security audit assessments (SOC2, PCI, etc.). You may have also gained ISO 27001 Lead Auditor or alike certifications (a plus). Collaborator Extraordinaire - Strong communications skills with the ability to explain technical and More ❯