1 to 25 of 138 Permanent PCI DSS Jobs in London

Security and Compliance Manager

Location
Greater London, England, United Kingdom
security expert to lead the development and maintenance of our compliance framework. You’ll be the driving force behind our adherence to ISO27001 , PCI-DSS , and GDPR , ensuring Neve Jewels remains a trusted leader in luxury retail. You’ll work hand-in-hand with our tech and business … Security Architecture & Governance: Design, implement, maintain compliance and manage the Neve Jewels IT security framework, ensuring technical alignment with ISO27001 , Cyber Essentials Plus , and PCI-DSS 4.0 . Infrastructure Protection: Oversee the security of all corporate and boutique networks, including firewalls, VPNs, end-point protection, and cloud environments ...

PCI DSS Retail Payments pecialist

Hiring Organisation
Taylor James Resourcing Limited
Location
East London, London, United Kingdom
Employment Type
Permanent
Salary
£85,000
commercially effective payment services while leading a small technical team and delivering key business initiatives. Payment Processing Expertise, Fintech Knowledge, Technical Architecture, Vendor Management PCI DSS & P2PE Compliance, Mobile Application Management, Loyalty Platform Management, Commercial Awareness Key Responsibilities Payment Platform Ownership * Own the end-to-end payment card … senior escalation point for complex incidents and service issues. * Maintain operational procedures, technical documentation, and support models. * Ensure compliance with industry standards, including PCI DSS and P2PE requirements. Team Leadership Project and Change Management * Lead the delivery of payment-related projects and strategic initiatives. * Coordinate internal stakeholders, suppliers ...

PCI DSS Retail Payments pecialist

Hiring Organisation
Taylor James Resourcing
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£80,000 - £85,000 per annum
commercially effective payment services while leading a small technical team and delivering key business initiatives. Payment Processing Expertise, Fintech Knowledge, Technical Architecture, Vendor Management PCI DSS & P2PE Compliance, Mobile Application Management, Loyalty Platform Management, Commercial Awareness Key Responsibilities Payment Platform Ownership * Own the end-to-end payment card … senior escalation point for complex incidents and service issues. * Maintain operational procedures, technical documentation, and support models. * Ensure compliance with industry standards, including PCI DSS and P2PE requirements. Team Leadership Project and Change Management * Lead the delivery of payment-related projects and strategic initiatives. * Coordinate internal stakeholders, suppliers ...

Data Privacy Manager

Location
Greater London, England, United Kingdom
rigorous where it needs to be and practical everywhere it can be. There is also an opportunity to help build the function’s PCI DSS capability over time. Key Responsibilities Advise product and business teams on privacy implications of new products, changes and customer journeys. Translate UK privacy … business, technology, legal, risk and security stakeholders. Lead and develop high-performing teams with accountability and continuous improvement. Nice to haves Bring hands-on PCI DSS knowledge and want to help build this capability across the function. Know PCI DSS requirements and their practical application ...

Head of Security (CISO)

Location
Greater London, England, United Kingdom
security governance, operations, compliance, and risk management across a complex technology estate spanning payments, healthcare, and B2B SaaS. With ongoing M&A activity, active PCI‐DSS obligations, and a rapidly evolving platform landscape, you'll play a critical role in protecting our customers, supporting business growth, and embedding … Oversee security operations, including threat detection, incident response, and remediation Act as the executive lead during security incidents and manage external stakeholder communications Own PCI‐DSS compliance across ClearAccept and ClearDebit payment platforms Lead the Group's Governance, Risk and Compliance (GRC) function, including ISO 27001, Cyber Essentials ...

Staff / Senior Staff Security Engineer, Vinted Pay

Location
Greater London, England, United Kingdom
multi‐region AWS infrastructure, payment pipelines and payment pages, wallets holding members' money, the cardholder and personal data behind them, and a regulatory perimeter - PCI DSS, DORA, Bank of Lithuania and FCA rules - that rises every year. Working at staff/senior staff level as an individual contributor … roadmap that shapes how Vinted Pay defends its infrastructure and payment assets, rather than reacting to the next audit. Turn regulation into engineering: map PCI DSS, DORA, and Bank of Lithuania and FCA requirements into practical, automated security controls and engineering guardrails - compliance as a by‐product ...

Head of Security

Location
Greater London, England, United Kingdom
protect the confidentiality, integrity, and availability of our information assets, intellectual property, and customer data, ensuring strict compliance with regulatory frameworks including FCA, DORA, PCI DSS, and Edenred group security requirements.**Key Responsibilities:*** Lead the PayTech Information Security function with alignment to Edenred’s wider cyber risk management … Crime and Anti-Fraud teams to mitigate cyber risks related to financial crime.* Manage third-party security risk due diligence programs.* Lead and maintain PCI DSS and PCI PIN compliance and engagement with Qualified Security Assessors (QSAs).* Drive cyber awareness programs and phishing simulations to embed ...

Head of Security

Location
Greater London, England, United Kingdom
protect the confidentiality, integrity, and availability of our information assets, intellectual property, and customer data, ensuring strict compliance with regulatory frameworks including FCA, DORA, PCI DSS, and Edenred group security requirements.**Key Responsibilities:*** Lead the PayTech Information Security function with alignment to Edenred’s wider cyber risk management … Crime and Anti-Fraud teams to mitigate cyber risks related to financial crime.* Manage third-party security risk due diligence programs.* Lead and maintain PCI DSS and PCI PIN compliance and engagement with Qualified Security Assessors (QSAs).* Drive cyber awareness programs and phishing simulations to embed ...

Senior Cloud Security Engineer (GCP) - Engine by Starling

Location
City Of London, England, United Kingdom
authorisation mechanisms are in place Engineer and automate technical controls within GCP to ensure and demonstrate continuous compliance with stringent standards such as PCI DSS and 3DS Drive security infrastructure deployments across our growing environments Perform regular security assessments, audits, threat modelling and architecture design reviews to identify … market for different banks' regulators Hands‐on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSS Experience automating security controls and compliance checks against standards and frameworks including SOC 2, ISO 27001 and PCI DSS/ ...

Staff Cloud Security Engineer (GCP) - Engine by Starling

Location
Greater London, England, United Kingdom
authorisation mechanisms are in place Engineer and automate technical controls within GCP to ensure and demonstrate continuous compliance with stringent standards such as PCI DSS and 3DS Drive security infrastructure deployments across our growing environments Perform regular security assessments, audits, threat modelling and architecture design reviews to identify … market for different banks' regulators Hands-on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSS Experience automating security controls and compliance checks against standards and frameworks including SOC 2, ISO 27001 and PCI DSS/ ...

Cloud Platform Security Engineer Software engineering London

Location
Greater London, England, United Kingdom
scales without friction Defining and enforcing cloud security architecture standards, guardrails, and policy-as-code inline with industry best practices including NIST, CIS, and PCI DSS. Use Wiz or equivalent CNAPP/CSPM to continuously assess, prioritise, and drive remediation of misconfigurations and vulnerabilities against CIS, NIST, and PCI … DSS benchmarks. Security Monitoring Fine tune, and maintain modern SIEM platform (e.g. Sentinel) including KQL detection rules, workbooks, logging pipelines, and AI-assisted alert triage. Map detection coverage against MITRE ATT&CK tactics and techniques. Identify and close visibility gaps across the cloud estate. Maintain alignment to PCI ...

Data Protection and Compliance Officer

Location
Greater London, England, United Kingdom
obligations are met. The role is accountable for maintaining certification, compliance activities and reporting relating to multiple ISO standards, Cyber Essentials, Cyber Essentials Plus, PCI-DSS, NHS-DSP, NHS Evergreen Assessment, Ecovadis, UNGC, CDP, SECR, ESOS , UK GDPR, Data Protection Act 2018, PECR, privacy governance requirements, and customer … controls. Provide subject matter expertise on regulatory and certification requirements. Information Security & Cyber Compliance Coordinate annual Cyber Essentials and Cyber Essentials Plus assessments. Support PCI-DSS compliance activities and certification requirements. Coordinate annual NHS-DSP submission and external audit. Maintain security policies, standards, and awareness programmes. Assist with ...

Payment Platform Manager – Stripe

Location
Greater London, England, United Kingdom
flows. Manage dispute and chargeback processes — and configure and monitor fraud tooling (e.g. Stripe Radar, 3D Secure) to balance fraud prevention with conversion. Own PCI-DSS compliance for payment processing — and triage and resolve causes of conversion drop-off. Own and develop the commercial relationship with Stripe … rolled out to plan in target markets, with adoption and conversion tracked and reported. Disputes, chargebacks and fraud managed within agreed risk tolerances, with PCI-DSS compliance maintained at all times. Stripe and other payment vendor relationships (contract, pricing) actively managed, with cost-benefit analyses delivered to support ...

Payments Systems Manager

Location
Greater London, England, United Kingdom
senior escalation point for complex incidents and service issues. Maintain operational procedures, technical documentation, and support models. Ensure compliance with industry standards, including PCI DSS and P2PE requirements. Team Leadership Project and Change Management Lead the delivery of payment-related projects and strategic initiatives. Coordinate internal stakeholders, suppliers … business value. Security and Compliance Lead the implementation and ongoing management of Point-to-Point Encryption (P2PE) across the estate. Ensure compliance with PCI DSS and other applicable payment industry standards. Support security audits, assessments, and remediation activities. Maintain awareness of emerging threats and regulatory developments. Serve ...

Identity & Infrastructure Engineer (Security-Aware)

Location
Greater London, England, United Kingdom
investigate identity‐related alerts. Support access reviews, privileged access reviews and entitlement governance. Assist with audit evidence and remediation activities relating to SOX, PCI DSS, GDPR and other applicable requirements. Support incident response by providing identity information, access logs and technical assistance with containment activities. Contribute to reducing … Identity or Microsoft Sentinel. Azure Monitor and Log Analytics. Microsoft Graph API or Azure automation. Passwordless authentication, FIDO2 and passkeys. Application SSO integration. SOX, PCI DSS, GDPR or ISO 27001 environments. General Microsoft Azure administration. Qualifications and Certifications A degree in Computer Science, Cyber Security, Infrastructure Engineering ...

Security Engineer – Cloud & On-Prem (Hybrid Security)

Location
Greater London, England, United Kingdom
secure-by-default principles to day-to-day security engineering. Implement and maintain agreed security controls and technical standards. Support security requirements relating to PCI DSS, SOX, GDPR, ISO 27001 and other applicable frameworks. Assist with audit evidence gathering, control validation and remediation activities. Maintain security documentation, procedures … security services such as GuardDuty, Security Hub, IAM or CloudTrail. Experience working with an external SOC, MSSP or security service provider. Exposure to PCI DSS, SOX, GDPR, ISO 27001, CIS or NIST environments. Qualifications & Certifications A degree in Cyber Security, Computer Science, Information Technology or a related discipline ...

Information Security Architecture & Engineering Lead (UK-based)

Location
Greater London, England, United Kingdom
Information Security Architecture & Engineering Lead (UK-based) The Information Security Architecture & Engineering Lead forms the technical heart of PCI Pal’s Information Security function. The role owns cloud architecture review, DevSecOps and secure SDLC practice, security automation and tooling, and security architecture strategy for the organisation, replacing reactive, post … secure coding practices. Experience threat-modelling applications and cloud workloads at the design stage, not just reviewing them after deployment. Working knowledge of PCI DSS v4.0.1. ISO/IEC 27001:2022; familiarity with ISO/IEC 42001:2023 is an advantage. Experience triaging and remediating findings from ...

Head of Information Security

Location
Greater London, England, United Kingdom
Foundations, establishing centralized monitoring and alerting (via Wiz/Security Hub). Data Privacy & Compliance End-to-End Privacy: Own the GDPR and PCI-DSS compliance programmes, embedding "Privacy by Design" and data minimization directly into our delivery processes. Legal Partnership: Collaborate with Legal to manage DPAs, transfer … information security, including leadership-level responsibility Proven experience building and scaling security and privacy programmes within growing organisations Strong hands-on knowledge of GDPR, PCI-DSS, incident response, and resilience planning Experience working within cloud-first environments, ideally AWS Strong understanding of security within e-commerce, fintech ...

Head of Information Security (Deputy CISO)

Location
Greater London, England, United Kingdom
Framework and other recognised standards. Maintain effective security policies, standards and controls, ensuring they are understood, embraced, evidenced and continuously improved. Support compliance with PCI DSS, UK GDPR, the Data Protection Act 2018 and relevant FCA expectations. Strengthen cyber operations and resilience Lead security monitoring, threat management, vulnerability … across security operations, governance, risk and compliance, architecture, engineering, third-party risk, assurance and operational resilience. Strong practical knowledge of ISO/IEC 27001, PCI DSS, UK GDPR, the Data Protection Act 2018 and recognised control frameworks such as NIST. A solid understanding of technology risk, risk appetite ...

Cyber Risk & Security Manager

Location
Greater London, England, United Kingdom
technical levels, supporting board-level decision‐making while driving operational security improvements aligned to recognised standards such as NIST CSF, ISO 27001, DORA, PCI‐DSS, and MITRE ATT&CK. Reporting To: Director/Head of Cyber Security Location: London (Hybrid) Employment Type: Full‐Time Salary … OWASP Top 10). Oversee DLP and DDA monitoring strategies. Compliance & Regulatory Alignment Support ISMS implementation aligned with ISO 27001. Ensure alignment with GDPR, PCI‐DSS, DORA, NIST CSF, COBIT, SANS, and related frameworks. Develop security policies, SOPs, and governance documentation. Conduct IT resilience and cloud security audits. ...

Head of Security

Location
Greater London, England, United Kingdom
where some products are today outside the standard tooling. Governance, risk and compliance and vendor management Own ISO 27001, SOC 1, SOC 2 and PCI DSS compliance, the audit calendar, the compliance automation platform and the relationship with our auditors. Work with legal and the Data Protection Officer … facing those customers on security matters. Working knowledge of ISO 27001 and SOC 2, and experience of being accountable for audits and certifications. PCI DSS experience is an advantage. Practical understanding of cloud security on AWS and Azure, Kubernetes-based platforms, infrastructure as code and modern CI/ ...

Information Security GRC Analyst (UK-based)

Location
Greater London, England, United Kingdom
Information Security GRC Analyst (UK-based) The GRC Analyst strengthens PCI Pal's central Information Security function by providing structured governance, risk and compliance analysis across audit, assurance, control management and strategic change. The role turns requirements, evidence, risks and delivery updates into accurate, traceable information that supports timely … requirements Relevant experience in GRC, information security compliance, risk management, internal audit or assurance. Working knowledge of at least one major framework, such as PCI DSS, ISO/IEC 27001, SOC 2 or NIST CSF, with the ability to apply requirements in practice. Experience reviewing policies, audit reports ...

Solution Architect (Principal Consultant)

Location
City Of London, England, United Kingdom
using Databricks, Snowflake, ETL pipelines, and Big Data tools. Champion Data Governance practices including classification, cataloging, and lineage. Ensure compliance with ISO 27001, GDPR, PCI DSS, and other security standards. Embed DevSecOps principles into CI/CD pipelines and platform delivery. Produce High-Level and Low-Level Designs … teams for seamless integration. Support business development initiatives, contributing to bids and proposals. Business Analysis experience and stakeholder engagement skills. Security - ISO 27001, GDPR, PCI DSS, IDAM, DevSecOps Agile - SAFe, DevOps, Scrum Collaboration - Stakeholder Engagement, Governance, Team Mentoring Business - Business Analysis, Bid Support, Multi-sector Delivery Upon employment ...

Applied AI Security Architect

Location
Greater London, England, United Kingdom
teams, and DPOs to understand their security requirements and design solutions that meet European regulatory standards (GDPR, EU AI Act, DORA, NIS2, SOC 2, PCI-DSS, and national regulator expectations). Lead technical deep-dives on network architecture, EU data residency, data retention and Zero Data Retention … applies to foundation models. Experience navigating compliance frameworks relevant to European financial services and insurance (DORA, NIS2, SOC 2, PCI-DSS, and national regulators' guidance on AI/ML such as FCA/PRA, BaFin, ACPR, FINMA). A track record of leading complex, high‐stakes engagements with ...

Senior Technical Programme Manager

Location
Greater London, England, United Kingdom
driving adoption of new platforms or ways of working across multiple teams. Experience working in regulated environments or with strict compliance requirements (e.g., GDPR, PCI‐DSS, SOC 2, DMA, and EU AI Act). Demonstrated ability to establish programme governance and operating models from scratch in ambiguous … Skills Excellent Communication Leadership Skills Decision‐Making Influencing Stakeholders Navigating Complexity Certifications & Qualifications PMP Agile Project Management Certification AWS Cloud Practitioner Industry Keywords GDPR PCI‐DSS SOC 2 DMA EU AI Act Tools & Technologies Jira Confluence Smartsheet Cloud‐Native Designs Microservices #J-18808-Ljbffr ...