London, England, United Kingdom Hybrid / WFH Options
Onyx-Conseil
coordinates internal security assessments, penetration tests, vulnerability scans, and assess organization cybersecurity maturity Complying with frameworks and regulations such as COBIT, NIST (800-53, cybersecurity), ISO, ITIL, PCI, GLBA, GDPR, HIPAA, and other data privacy and security standards and regulations. • Provides internal customer support via assigned tickets for security-related issues, while ensuring assignments are resolved within assigned SLAs. More ❯
London, England, United Kingdom Hybrid / WFH Options
VML
annual external audits required to support certification. Ensure data security and compliance with relevant legal, regulatory, contractual and policy requirements. Ensure process and requirements are met to support GDPR compliance and protection of personal data. Maintain and improve level of compliance with ISO 27001:2022 and Cyber Essentials Plus requirements. Work in partnership with development staff to embed More ❯
Collaborate with IT and business units to ensure secure systems development and operations. Compliance & Risk Management Ensure compliance with regulatory and legal security requirements (e.g., ISO 27001, NIST, HIPAA, GDPR, SOX, etc.). Ensure compliance with applicable dataprotection laws (e.g., GDPR, CCPA, GLBA). Guide DataProtection Impact Assessments (DPIAs) for high-risk financial data … with data analytics platforms and financial data governance tooling. Strong working knowledge of financial compliance frameworks (e.g., GLBA, SOX, FFIEC CAT, NYDFS). Familiarity with privacy regulations (GDPR, CCPA) and best practices in data governance. Certifications such as CISSP, CISM, CISA, CRISC, or Certified DataProtection Officer (CDPO) are highly desirable. We offer a collaborative More ❯
London, England, United Kingdom Hybrid / WFH Options
State Street
revocation, and decommissioning. Build monitoring and alerting mechanisms to detect cryptographic anomalies and improve operational efficiency. Ensure automation and integrations align with cryptographic policies, compliance, and regulations (PCI DSS, GDPR, FIPS 140-2 / 3), and security best practices. Work closely with risk and compliance teams to provide audit trails and access control mechanisms for key and certificate operations. Assist More ❯
Reading, England, United Kingdom Hybrid / WFH Options
Focus on SAP
Position: SOC Tier 3 Analyst Employment Type: Contract, Full time Start: ASAP Location: Reading – Hybrid Languages: English We are seeking an experienced and highly capable SOC Tier 3 Analyst to serve as a senior member of our Security Operations Center More ❯
Reading, England, United Kingdom Hybrid / WFH Options
Focus on SAP
3 days ago Be among the first 25 applicants Direct message the job poster from Focus on SAP SAP Recruitment Consultant at Focus on SAP (part of the Focus Cloud Group) Position: SOC Tier 3 Analyst Employment Type: Contract, Full More ❯
London, England, United Kingdom Hybrid / WFH Options
NTT DATA
consumption. Data Management and Governance: Strong knowledge of data management principles and best practices, including data governance frameworks. Experience with data security and compliance regulations (GDPR, CCPA, HIPAA, etc.) Leadership and Communication: Exceptional leadership skills to manage and guide a team of architects and technical experts. Excellent communication and interpersonal skills, with a proven ability to More ❯
Milton Keynes, Buckinghamshire, South East, United Kingdom Hybrid / WFH Options
In Technology Group Limited
Investigate and document security breaches, providing root cause analysis and remediation plans. Conduct security awareness training for staff and ensure compliance with internal policies and regulatory requirements (e.g., FCA, GDPR, ISO 27001). Stay up to date with the latest security technologies, trends, and threat intelligence. Essential Skills & Qualifications: Proven experience in a cyber security or information security engineering role. More ❯
procedures. Manage cybersecurity projects to ensure timely delivery within budget. Perform or coordinate security assessments, penetration tests, and vulnerability scans. Ensure compliance with frameworks like COBIT, NIST, ISO, PCI, GDPR, HIPAA, etc. Provide internal support for security issues within SLAs. Evaluate and implement CIS controls as needed. Contribute to cybersecurity strategic planning and budgeting. Follow change management policies. Qualifications Bachelor More ❯
and recommend new security tools and technologies based on organizational needs. Define and maintain security reference architectures, standards, and best practices. Support compliance efforts (e.g., ISO 27001, NIS 2, GDPR) through architectural guidance and documentation. Conduct risk assessments, security reviews, and threat modeling at the architectural level for new systems and changes. Assist in the development of automated provisioning, monitoring More ❯
London, England, United Kingdom Hybrid / WFH Options
Nadara
Familiarity with DevOps / MLOps principles, CI / CD pipelines, and infrastructure as code (e.g., Terraform, CloudFormation). Basic understanding of data security measures, encryption, IAM, and compliance (GDPR, CCPA); ability to evaluate potential vulnerabilities and recommend mitigations. Ability to identify technical risks and performance bottlenecks, then devise strategies to mitigate or optimize. Understanding of data lineage, metadata More ❯
London, England, United Kingdom Hybrid / WFH Options
NTT DATA
consumption. Data Management and Governance: Strong knowledge of data management principles and best practices, including data governance frameworks. Experience with data security and compliance regulations (GDPR, CCPA, HIPAA, etc.). Leadership and Communication: Exceptional leadership skills to manage and guide a team of architects and technical experts. Excellent communication and interpersonal skills, with a proven ability More ❯
Manchester, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
and best practices, particularly in AWS Experience in managing security incidents and leading incident response Excellent knowledge of security frameworks, standards, and regulations, including ISO 27001, SOC 2, HIPAA, GDPR, etc. Good communication and interpersonal skills, with the ability to effectively communicate security-related questions to technical and non-technical stakeholders (employees, customers, and / or partners) Project management skills More ❯
Edinburgh, Scotland, United Kingdom Hybrid / WFH Options
State Street
revocation and decommissioning. Build monitoring and alerting mechanisms to detect cryptographic anomalies and improve operational efficiency. Ensure automation and integrations align with cryptographic policies, compliance and regulations (PCI DSS, GDPR, FIPS 140-2 / 3), and security best practices. Work closely with risk and compliance teams to provide audit trails and access control mechanisms for key and certificate operations. Assist More ❯
Altrincham, England, United Kingdom Hybrid / WFH Options
Heywood
and best practices, particularly in AWS Experience in managing security incidents and leading incident response Excellent knowledge of security frameworks, standards, and regulations, including ISO 27001, SOC 2, HIPAA, GDPR, etc. Good communication and interpersonal skills, with the ability to effectively communicate security-related questions to technical and non-technical stakeholders (employees, customers, and / or partners) Project management skills More ❯
Altrincham, England, United Kingdom Hybrid / WFH Options
Heywood Limited
and best practices, particularly in AWS Experience in managing security incidents and leading incident response Excellent knowledge of security frameworks, standards, and regulations, including ISO 27001, SOC 2, HIPAA, GDPR, etc. Good communication and interpersonal skills, with the ability to effectively communicate security-related questions to technical and non-technical stakeholders (employees, customers, and / or partners) Project management skills More ❯
City of London, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
security. Identify and manage risks to information assets and IT systems. Lead enterprise risk assessments and mitigation planning. Compliance & Regulatory: Ensure adherence to global dataprotection regulations (GDPR, PCI-DSS, etc.), working closely with legal and dataprotection teams. Leadership & Stakeholder Engagement: Act as the subject matter expert on cybersecurity at the board and executive level. … Demonstrable experience building and scaling a GRC function in a complex environment. Deep knowledge of information security standards (ISO 27001, NIST, CIS), risk frameworks (COSO, FAIR), and regulatory obligations (GDPR, PCI-DSS, SOX). Proven track record of managing enterprise-level security programs, including incident response and business continuity. Excellent stakeholder management skills, with experience reporting at board level. Strong More ❯
London, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
security. Identify and manage risks to information assets and IT systems. Lead enterprise risk assessments and mitigation planning. Compliance & Regulatory: Ensure adherence to global dataprotection regulations (GDPR, PCI-DSS, etc.), working closely with legal and dataprotection teams. Leadership & Stakeholder Engagement: Act as the subject matter expert on cybersecurity at the board and executive level. … Demonstrable experience building and scaling a GRC function in a complex environment. Deep knowledge of information security standards (ISO 27001, NIST, CIS), risk frameworks (COSO, FAIR), and regulatory obligations (GDPR, PCI-DSS, SOX). Proven track record of managing enterprise-level security programs, including incident response and business continuity. Excellent stakeholder management skills, with experience reporting at board level. Strong More ❯
Slough, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
security. Identify and manage risks to information assets and IT systems. Lead enterprise risk assessments and mitigation planning. Compliance & Regulatory: Ensure adherence to global dataprotection regulations (GDPR, PCI-DSS, etc.), working closely with legal and dataprotection teams. Leadership & Stakeholder Engagement: Act as the subject matter expert on cybersecurity at the board and executive level. … Demonstrable experience building and scaling a GRC function in a complex environment. Deep knowledge of information security standards (ISO 27001, NIST, CIS), risk frameworks (COSO, FAIR), and regulatory obligations (GDPR, PCI-DSS, SOX). Proven track record of managing enterprise-level security programs, including incident response and business continuity. Excellent stakeholder management skills, with experience reporting at board level. Strong More ❯
London, England, United Kingdom Hybrid / WFH Options
Stats Perform
performance, and capacity planning through robust monitoring and proactive incident management. • Cybersecurity & Compliance • Collaborate with InfoSec to ensure comprehensive threat management, dataprotection, and regulatory compliance (., GDPR, ISO 27001). • Embed security by design across all IT and video platforms. • Service Delivery & Support • Lead global IT support and service delivery teams with a focus on SLAs, user More ❯
Edinburgh, Scotland, United Kingdom Hybrid / WFH Options
State Street
quantum cryptography (PQC) readiness by evaluating and preparing for emerging threats to encryption security. Ensure compliance with NIST 800-57, PCI DSS, FIPS 140-2 / 3, ISO 27001, GDPR, FFIEC, and IoT security (NIST 800-183, ETSI EN 303 645). What We Value These skills will help you succeed in this role Developing governance frameworks for encryption and … industries. Certifications such as CISSP, CISM, AWS Security Specialty, HashiCorp Certified Vault Associate or CCSK. Familiarity with NIST 800-57, PCI DSS, FIPS 140-2 / 3, ISO 27001, GDPR, FFIEC, and IoT security (NIST 800-183, ETSI EN 303 645). Additional requirements Travel up to 10% may be required Are you the right candidate? Yes! We truly believe More ❯
a variety of challenging projects, with multiple security tools. Have a proven track record of successes. Understanding of security compliance standards relevant to the SaaS industry, such as PCI, GDPR, ISO 27001, SOC2, NIST. An understanding of application security principals, best practices, OWASP / related standards. Knowledge of security frameworks & controls, hardening standards & security best practices. An understanding of network More ❯
London, England, United Kingdom Hybrid / WFH Options
Smart Communications group
a variety of challenging projects, with multiple security tools. Have a proven track record of successes. Knowledge of security compliance standards relevant to the SaaS industry, such as PCI, GDPR, ISO 27001, SOC2, NIST. An understanding of application security principles, best practices, OWASP / related standards. Some knowledge / experience in scoping / undertaking internal pen testing and creation of More ❯
London, England, United Kingdom Hybrid / WFH Options
Allen & Overy LLP
EMEA region-specific concerns, policies, or procedures are incorporated into global information security policies (e.g., as an appendix). Ensure compliance with any relevant local information security regulations (e.g., GDPR) and industry standards within the EMEA region, whilst aligning with standards followed by the global firm (to the highest extent possible) by staying up-to-date with changing and evolving … CISA), or substantially equivalent workplace experience. Extensive experience in information security, with a strong focus on risk management and compliance. Demonstrated expertise in dataprotection regulations (e.g., GDPR) and industry standards (e.g., ISO 27001, NIST CSF, SOC 2), with a solid understanding of the regulatory landscape for information security in the EMEA region. Experience working across a global More ❯
Isleworth, England, United Kingdom Hybrid / WFH Options
Sky
Prometheus, Grafana, ELK Stack). Create and maintain comprehensive" technical documentation , including system architecture diagrams and operational runbooks. Ensure compliance with data security, privacy, and regulatory requirements (e.g., GDPR, ISO 27001). Implement best practices for dataprotection and collaborate with security teams to address potential vulnerabilities. Contribute to" disaster recovery "and" business continuity planning , ensuring robust More ❯