1 to 25 of 26 Permanent ISO 27001 Lead Auditor Jobs in the UK

Lead Information Security & GRC Specialist

Hiring Organisation
Zachary Daniels
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£80,000 - £100,000 per annum
Lead Information Security & GRC Specialist London (Hybrid, 3 days in office) | £80,000 - £100,000 + Benefits We're partnering with a well-established organisation that's continuing to invest in its Technology and Information Security capability. As the business continues to strengthen its security posture, they … Opportunity This is a hands-on role suited to someone who has successfully led, or played a significant role in, delivering an ISO 27001 certification programme. You'll own and continually improve the Information Security Management System (ISMS), working closely with Technology, Infrastructure, Engineering ...

Information Security Compliance Lead

Hiring Organisation
FBI &TMT
Location
United Kingdom
Employment Type
Permanent, Work From Home
Salary
£55,000
Responsibilities Leading the annual NHS DSPT submission, including evidence collection and reporting. Leading the organisation's progress towards ISO 27001 certification, including evidence gathering and audit coordination. Leading evidence gathering for Cyber Essentials Plus certification. Leading the organisation's alignment to the NIST Cybersecurity … compliance with company metrics, policies, and standards. Reviewing information security policies, standards, and procedures for currency and alignment with DSPT, Cyber Essentials Plus, ISO 27001, and NIST CSF, drafting updates for review and approval by the Head of Cyber Security, IT Risk and Compliance. ...

Information Security Manager

Hiring Organisation
Ronald James
Location
Newcastle Upon Tyne, Tyne and Wear, England, United Kingdom
Employment Type
Full-Time
Salary
£55,000 - £75,000 per annum
Information Security / GRC Manager Overview We're looking for an Information Security / Governance, Risk & Compliance (GRC) Manager to lead enterprise-wide risk, governance, and assurance across a fast-growing B2B technology business. This is a senior strategic position with responsibility spanning information security, governance, compliance … certifications such as CISM, CISSP or ISO 27001 Lead Auditor / Lead Implementer (or be working towards them). Strong commercial awareness alongside excellent judgement. Outstanding communication skills with the ability to influence both technical ...

Cyber GRC Consultant

Hiring Organisation
Halo Personnel
Location
Fareham, Hampshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£55,000
governance, manage cyber and information risks, and achieve or maintain compliance with recognised standards and frameworks including ISO / IEC 27001, Cyber Assessment Framework (CAF), Cyber Essentials, SOC-2, PCI, DSS, GDPR, and other relevant regulatory or contractual requirements. This is a customer … manage multiple client tasks or engagements, work under pressure and meet deadlines. Relevant professional certification such as ISO / IEC 27001 Lead Auditor, ISO / IEC 27001 Lead ...

Cyber Security Consultant

Hiring Organisation
Moore Kingston Smith
Location
London, United Kingdom
Salary
£ 45 K
reports, risk assessments, and advisory outputs.Collaborate with technical and business stakeholders to design or enhance security control environments aligned to frameworks such as ISO 27001, NIST CSF, CIS Controls, and Cyber Essentials.Maintain up-to-date knowledge of cyber threats, mitigation strategies, regulatory requirements … internal methodologies and security services.Build and maintain strong client relationships with a service-focused mindset.Identify client challenges and future needs that may lead to service expansion opportunities.Contribute to business development and client growth by supporting proposal creation, project scoping, thought leadership (e.g., blogs, webinars), and collaborating ...

Senior Information Security Analyst (ISO, SOC2, PCI DSS)

Hiring Organisation
Spectrum IT Recruitment
Location
City of London, London, Cripplegate, United Kingdom
Employment Type
Permanent
Salary
£90000 - £100000/annum bonus, pension, healthcare
joining a collaborative, ambitious team where there are genuine long-term career prospects and endless opportunities to develop. The Role Lead and conduct internal audits across ISO 27001, GDPR, DORA, Cyber Essentials & more. Prepare teams for external audits and manage … security documentation. Collaborate with IT & Security teams to identify and remediate vulnerabilities. What We're Looking For Strong knowledge of audit & compliance frameworks (ISO 27001,SOC2, PCI DSS, Cyber Essentials) Experience with CSOC tools such as Rapid7 InsightIDR or other SIEM solutions. Hands ...

IT / Network Security Engineer

Hiring Organisation
Tank Recruitment
Location
Oxfordshire, United Kingdom
Employment Type
Permanent
Salary
£45000 - £55000/annum
networks), and direct proactive patch management cycles. Compliance & Audits: Drive internal control testing and maintain alignment with structured information security standards such as ISO 27001, supporting both internal evaluations and external auditor walkthroughs. Incident Handling: Manage the end-to-end lifecycle … security alerts or breaches, lead formal root-cause analysis, and embed corrective actions into future preventive safeguards. Third-Party Risk: Evaluate external vendors and technology partners to ensure compliance with internal security policies and benchmark security standards. Cross-Functional Collaboration: Partner directly with IT infrastructure, application support ...

Senior Trust Security Analyst

Hiring Organisation
NICE Systems
Location
London, United Kingdom
Salary
£ 80 K
security teams, ensuring alignment with agreed timelines and compliance requirements.AuditAudit Interpretation: Read and interpret third-party audit reports (SOC 2 Type II, ISO 27001, penetration test summaries) and represent findings to customers in questionnaires and security responses.Communication & Stakeholder ManagementInformation Translation: Gather detailed technical information … Expertise: Hands-on experience responding to SIG, CAIQ, VSA, and bespoke enterprise / government security questionnaires.Compliance Knowledge: Working knowledge of Cyber Essentials Plus, ISO 27001, SOC 2 Type II, and at least one of PCI DSS, GDPR / UK GDPR, HIPAA, or FedRAMP.Technical Expertise ...

Infrastructure & Security Manager

Hiring Organisation
Jobheron
Location
Egham, Surrey, England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
Doing As the Infrastructure & Security Manager, you'll play a pivotal role in keeping systems secure, resilient and scalable. You'll lead infrastructure strategy while remaining hands-on with day-to-day technical delivery. Key responsibilities include: Managing cloud infrastructure, networking, firewalls, servers, storage and security technologies. … acting as the first point of contact for security incidents. Managing backup and disaster recovery solutions to ensure business continuity. Driving and maintaining ISO 27001 compliance, audits and security improvements. Developing infrastructure roadmaps and implementing technical change. Supporting colleagues with internal IT infrastructure issues ...

Managing Cyber Security Consultant

Hiring Organisation
Addition
Location
Central London, London, England, United Kingdom
Employment Type
Full-Time
Salary
£75,000 - £85,000 per annum
Security Consultant Join a fast-growing technology consultancy helping organisations strengthen their cyber resilience through expert advisory services. This is an opportunity to lead high-profile consulting engagements, mentor talented consultants, and play a key role in shaping the growth of an ambitious Cyber Security practice. Role … Hybrid (2 days per week on site) Package: £75,000- £95,000pa & benefits Industry: Cyber Security / Consultancy What You'll Be Doing Lead the successful delivery of cyber security consulting engagements across a broad range of industries. Manage multiple client projects, ensuring high-quality delivery, commercial ...

Cloud Security Architect

Hiring Organisation
Reply
Location
United Kingdom
Salary
£ 70 K
risk assessments, threat modelling exercises, and security posture evaluations for cloud platforms and SaaS products, utilising methodologies such as FAIRDrive compliance programmes covering ISO 27001, Cyber Essentials Plus, PCI DSS, and other relevant regulatory frameworksSupport DevSecOps adoption and integrate security tooling and controls into … Cloud Security Architect or Senior Security Consultant roleAWS Certified Security – Specialty (required), with CISSP, CRISC, or CCSP strongly preferred; additional certifications such as ISO 27001 Lead Implementer / Auditor, Azure Security Engineer, or GCP Security Engineer are advantageousHands ...

Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

Hiring Organisation
X
Location
London, United Kingdom
Salary
£ 80 K
Engineering Leads to bake EU / UK information security and regulatory requirements into design early; translate complex obligations into concrete technical implementations and auditor- or supervisor-ready narratives without slowing development.Design, implement, and validate technical information security controls relevant to regulated EU / UK environments (access control … continuously improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e.g., ISO 27001, SOC 2) where they overlap.Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.BASIC ...

Information Security Consultant

Hiring Organisation
Digital Waffle
Location
Newcastle Upon Tyne, Tyne and Wear, England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £80,000 per annum
best practices. Conduct security risk assessments, gap analyses and audits. Support clients in achieving and maintaining compliance with standards and regulations such as ISO 27001, NIST and GDPR . Develop and review security policies, procedures and documentation. Perform vulnerability assessments and coordinate remediation efforts. … processes. Required Skills & Experience Proven experience working as an Information Security Consultant or in a similar role. Strong understanding of security frameworks including ISO 27001, NIST and CIS Controls . Experience conducting threat modelling exercises and risk-based security assessments. Strong client-facing ...

Junior Cyber Audit Consultant

Hiring Organisation
Conventus Recruitment
Location
Corsham, Wiltshire, South West, United Kingdom
Employment Type
Permanent
Salary
£50,000
systems to ensure compliance with regulatory requirements such as the NCSC Cyber Assessment Framework (CAF) and GovAssure. Support and, over time, help lead audit activity, ensuring findings are properly documented and reported. Communicate audit findings and recommendations, working collaboratively with management to help develop and implement effective … auditing, compliance and risk management. Contribute to cyber report writing and the production of Cyber Risk Profiles (CRP) Skills / Experience: Experience of ISO 27001, the NCSC Cyber Assessment Framework (CAF), DCC and Cyber Risk Profile (CRP) work. Experience of cyber report writing. Relevant ...

Head of GRC

Hiring Organisation
THAMES 360
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
Title: Head of Governance, Risk & Compliance (GRC) – MSP Practice Lead Location: London Hybrid (3 Days Onsite, 2 Remote) Job Type: Full-time, Permanent The Opportunity Are you a senior GRC expert ready to step out of a corporate cost-center and run your own practice … market clients across cyber security, risk, and resilience. Core Frameworks: Lead client assessments and certifications across Cyber Essentials / CE+, ISO 27001, and UK GDPR . Innovation: Build next-generation AI Governance and operational resilience (BC / DR) frameworks. Internal Audit ...

AI Security Consultant

Hiring Organisation
PA Consulting
Location
London, United Kingdom
Salary
£ 70 K
assurance.Familiarity with frameworks and guidance such as NIST AI RMF, OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, MITRE ATLAS, ISO 27001, NIST CSF, CIS Controls or cloud security frameworks.Experience with SOC operations, SIEM / SOAR platforms, detection engineering, threat intelligence … guardrails for autonomous systems, including least privilege, approval workflows, action limits, logging, monitoring and rollback mechanisms.Relevant certifications such as CISSP, CISM, CCSP, GIAC, ISO 27001 Lead Implementer / Auditor, cloud security certifications or AI / security-focused training.Please ...

Security & Information Officer

Hiring Organisation
Compass UK & Ireland
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Permanent
/ or DV Clearance Join Us in Protecting Critical Defence Operations We are seeking a highly motivated and experienced Security & Information Officer to lead the security and information assurance agenda across our Defence, Marine & Aerospace business. This is an exciting opportunity to play a pivotal role … deliver governance excellence, and support business growth in a highly regulated environment. What You'll Be Doing As Security & Information Officer, you will: Lead and coordinate information security activities across Defence, Marine & Aerospace operations. Manage and maintain security accreditation programmes including Cyber Essentials Plus, Secure by Design ...

Specialist, security regulatory compliance

Hiring Organisation
Colt Technology Services UK
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
looking for a Security Regulatory Compliance Specialist to lead and manage compliance with key security regulations such as NIS2, DORA, Telecom Security Act , and other applicable laws and standards. This role is responsible for monitoring evolving regulatory requirements, translating them into actionable controls, and ensuring the organization … Strong organizational and stakeholder management skills Proactive mindset with high attention to detail Might haves: Professional certifications such as: CISM, CISSP, CRISC, CISA ISO 27001 Lead Implementer / Auditor Experience working with regulators or in regulated industries (e.g. ...

Specialist, security regulatory compliance

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£90,000
their business goals instead of the underlying infrastructure. Why we need this role We are looking for a Security Regulatory Compliance Specialist to lead and manage compliance with key security regulations such as NIS2, DORA, Telecom Security Act , and other applicable laws and standards. This role … Strong organizational and stakeholder management skills Proactive mindset with high attention to detail Might haves: Professional certifications such as: CISM, CISSP, CRISC, CISA ISO 27001 Lead Implementer / Auditor Experience working with regulators or in regulated industries (e.g. ...

Information Security Lead

Hiring Organisation
Babcock
Location
Plymouth, Devon, United Kingdom
Salary
£ 70 K
working to create a safe and secure world, together, and if you join us, you can play your part as an Information Security Lead at our Devonport Royal Dockyard site.The roleAs an Information Security Lead, you’ll play a vital role in safeguarding critical … infrastructure and major defence programmes. Working across key projects within the Defence Nuclear Enterprise, you’ll lead the delivery of robust information security assurance, ensuring systems, data, and operations remain secure and compliant.Day-to-day, you’ll collaborate with technical specialists, programme teams, and external stakeholders ...

Information Security Lead

Hiring Organisation
Babcock
Location
Torpoint, Cornwall, United Kingdom
Salary
£ 60 K
working to create a safe and secure world, together, and if you join us, you can play your part as an Information Security Lead at our Devonport Royal Dockyard site.The roleAs an Information Security Lead, you’ll play a vital role in safeguarding critical … infrastructure and major defence programmes. Working across key projects within the Defence Nuclear Enterprise, you’ll lead the delivery of robust information security assurance, ensuring systems, data, and operations remain secure and compliant.Day-to-day, you’ll collaborate with technical specialists, programme teams, and external stakeholders ...

Director, Technology, Cyber & Resilience Risk

Hiring Organisation
London Stock Exchange Group
Location
London, United Kingdom
Salary
£ 100 K
influencing culture, behaviours, and delivery outcomes.Required ExperienceSenior leadership in technology risk within regulated financial services.Ownership of control frameworks aligned to recognised standards (NIST, ISO, COBIT).Strong track record in risk governance and remediation of systemic issues.Operational resilience and incident management expertise.Experience engaging with regulators and executive stakeholders.Cloud … third-party risk oversight.Qualifications & Certifications (preferred)CRISC, CISM, CISSP, ISO 27001 Lead Auditor / Implementer, ITIL Expert.Degree in Computer Science / Engineering or equivalent experience.Skills & AttributesCombines deep risk expertise with engineering credibility.Strong decision-making and challenge capability ...

Junior Cyber Security Auditor

Hiring Organisation
CBSbutler Holdings Limited trading as CBSbutler
Location
Corsham, Wiltshire, United Kingdom
Employment Type
Permanent
Salary
GBP 45,000 - 60,000 Annual
Cyber Security Auditor +Permanent opportunity +Hybrid working - Corsham / West Country +SC / DV clearance is essential We are looking for Cyber Security Auditors to join a growing team delivering high-impact assurance services across UK Government and Defence programmes. This role is suited to auditors already … operating within NCSC-aligned frameworks , with the ability to lead and deliver audits across nationally significant cyber assurance schemes. Essential Requirements (Must Have) ISO27001 Lead Auditor qualification (or equivalent) Chartered Auditor and Assessor accreditation Active presence ...

Senior Cyber Security Consultant

Hiring Organisation
Control Risks
Location
London, United Kingdom
Salary
£ 80 K
security challenges facing our clients. RequirementsRole Tasks and ResponsibilitiesManaging and delivering client projectsDelivering projects (e.g., conducting asset identification exercises, cyber risk assessments against ISO and NIST CSF 2.0 standards, and demonstrating cyber audit expertise).Managing different types of client meetings and maintaining positive and respectful client relationships.Line … issues impacting clients in EuropeUndergraduate or post graduate degree in a field related to security, information security, intelligence, or computer science.CISSP, CISM, ISO27001 lead auditor, SANs or similar industry qualifications / certifications would be preferredBenefitsControl Risks offers a competitively positioned compensation and benefits package ...

Compliance Manager

Hiring Organisation
Matched Group
Location
Reading, Berkshire, England, United Kingdom
Employment Type
Full-Time
Salary
£65,000 - £80,000 per annum
brilliant opportunity to be part of a collaborative business where you'll embed compliance; giving you opportunity to influence growth. Compliance Manager - Responsibilities Lead GDPR and data protection operations, processes and documentation Act as DPO Maintain and operate ISO27001 and ISMS artefacts Oversee internal compliance policies whilst … environments Experience of ISO27001 audit readiness and maintenance Experience working with technology and engineering teams Certified Data Protection Officer (DPO) Ideal qualifications - ISO27001 Lead Auditor, GDPR practitioner certification Strong written and verbal English communication Energetic and dynamic individual who enjoys collaborating and being pragmatic ...