Stay up-to-date with relevant frameworks and regulatory requirements. Required Skills, Qualifications, and Experience Bachelor’s degree in Information Security, or related field. Relevant certifications (e.g., ISO27001 LeadImplementer, CIPP, CRISC etc.) are a plus. At least 2-3 years of experience in GRC, Information Security, or related fields. Hands-on experience with … GRC platforms, OneTrust is a bonus. Experience with risk management and risk assessment methodologies. Knowledge of frameworks like CIS 8.0, ISO27001, NIST CSF, GDPR, NIS2, or similar. Experience in auditing, reporting, and investigating privacy breaches. Ability to interpret and apply complex legal and regulatory requirements. Experience working with cross-functional teams to implement More ❯
Bristol, England, United Kingdom Hybrid / WFH Options
Actica
leading to nationally recognised qualifications, such as chartered or principal status with the UK Cyber Security Council, or certifications such as CompTIA, NIST, PCiIAA, CISMP, CISSP, CREST, ISO27001 LeadImplementer/ Auditor, SABSA, and TOGAF. A Mentor will be on hand to provide support and guidance throughout your journey with Actica. You will also More ❯
Responsibilities: Assess, document, and communicate information security risks Develop and implement risk mitigation plans Maintain and evolve governance and compliance frameworks Monitor compliance against standards and regulations like ISO27001, NIST, GDPR Coordinate audits (internal and external) Requirements: Degree in Computer Science / IT or relevant industry certifications such as CISA, CRISC, CISMP, ISO27001Lead Auditor /Implementer Working knowledge with legal / security needs in housing association sector and its regulatory environment Solid grasp of ISO27001, NIST, GDPR, and risk management frameworks Experience with risk assessments and developing mitigation plans Experience producing internal … audits, reports, gap analyses Experience maintaining compliance with frameworks like ISO27001, PCI-DSS If you are interested, please apply immediately as first stage interviews will be taking place next week. Alternatively, feel free to reach me directly on h.barmi @ ioassociates . co . uk. #J-18808-Ljbffr More ❯
Social network you want to login / join with: Security Manager – Digital Transformation (Inside IR35) We’re looking for a proactive and highly experienced Security Manager to lead the security strategy for a major UK Public Sector digital programme. If you’re passionate about embedding security by design, managing risks at scale, and ensuring alignment with governance … privacy frameworks, this role will put you at the heart of a high-impact transformation. ? Location: UK, Remote ? Contract Type: Inside IR35 Responsibilities ?️ Acting as the primary security lead for the Digitalisation programme and associated digital solutions ? Producing and presenting monthly security governance reports, risk registers, and security cases ️ Leading risk assessments, managing mitigation controls, and contributing … / NHSE and government design principles ️ Hands-on experience in Agile / DevOps settings using tools like Jira and Confluence Bonus Points ? ? Certifications such as CISSP, CISM, or ISO27001LeadImplementer/ Auditor ? Familiarity with NHS-specific or healthcare-related data protection requirements Deadline for applications is More ❯
Social network you want to login / join with: Security Manager – Digital Transformation (Inside IR35) We’re looking for a proactive and highly experienced Security Manager to lead the security strategy for a major UK Public Sector digital programme. If you’re passionate about embedding security by design, managing risks at scale, and ensuring alignment with governance … privacy frameworks, this role will put you at the heart of a high-impact transformation. ? Location: UK, Remote ? Contract Type: Inside IR35 Responsibilities ?️ Acting as the primary security lead for the Digitalisation programme and associated digital solutions ? Producing and presenting monthly security governance reports, risk registers, and security cases ️ Leading risk assessments, managing mitigation controls, and contributing … / NHSE and government design principles ️ Hands-on experience in Agile / DevOps settings using tools like Jira and Confluence Bonus Points ? ? Certifications such as CISSP, CISM, or ISO27001LeadImplementer/ Auditor ? Familiarity with NHS-specific or healthcare-related data protection requirements Deadline for applications is More ❯
Social network you want to login / join with: Security Manager – Digital Transformation (Inside IR35) We’re looking for a proactive and highly experienced Security Manager to lead the security strategy for a major UK Public Sector digital programme. If you’re passionate about embedding security by design, managing risks at scale, and ensuring alignment with governance … privacy frameworks, this role will put you at the heart of a high-impact transformation. ? Location: UK, Remote ? Contract Type: Inside IR35 Responsibilities ?️ Acting as the primary security lead for the Digitalisation programme and associated digital solutions ? Producing and presenting monthly security governance reports, risk registers, and security cases ️ Leading risk assessments, managing mitigation controls, and contributing … / NHSE and government design principles ️ Hands-on experience in Agile / DevOps settings using tools like Jira and Confluence Bonus Points ? ? Certifications such as CISSP, CISM, or ISO27001LeadImplementer/ Auditor ? Familiarity with NHS-specific or healthcare-related data protection requirements Deadline for applications is More ❯
Social network you want to login / join with: Security Manager – Digital Transformation (Inside IR35) We’re looking for a proactive and highly experienced Security Manager to lead the security strategy for a major UK Public Sector digital programme. If you’re passionate about embedding security by design, managing risks at scale, and ensuring alignment with governance … privacy frameworks, this role will put you at the heart of a high-impact transformation. ? Location: UK, Remote ? Contract Type: Inside IR35 Responsibilities ?️ Acting as the primary security lead for the Digitalisation programme and associated digital solutions ? Producing and presenting monthly security governance reports, risk registers, and security cases ️ Leading risk assessments, managing mitigation controls, and contributing … / NHSE and government design principles ️ Hands-on experience in Agile / DevOps settings using tools like Jira and Confluence Bonus Points ? ? Certifications such as CISSP, CISM, or ISO27001LeadImplementer/ Auditor ? Familiarity with NHS-specific or healthcare-related data protection requirements Deadline for applications is More ❯
ll Be Working On: ️ Managing and enforcing information security policies, procedures, and standards to safeguard organizational data ️ Conducting risk assessments and ensuring compliance with relevant security frameworks (e.g., ISO27001, NIST, GDPR) ️ Performing audits and security assessments to identify vulnerabilities and recommending appropriate mitigations ️ Collaborating with other teams to implement and maintain secure information … re Looking For: ️ Proven experience as an Information Assurance Specialist or in a similar role focused on data protection and compliance ️ Strong understanding of information assurance frameworks (e.g., ISO27001, NIST SP 800-53, COBIT) ️ Experience with security assessments, audits, and vulnerability management ️ Knowledge of regulatory standards such as GDPR, HIPAA, and PCI-DSS … Certifications such as CISSP, CISM, or ISO27001LeadImplementer are highly desirable More ❯
manage responses to customer security audits and assurance inquiries. Monitor regulatory changes and contribute to compliance initiatives such as DORA , NIS2 , and other applicable standards and frameworks (e.g., ISO27001, SOC 2, GDPR). Assist in the development, maintenance, and improvement of internal GRC processes, policies, and documentation. Collaborate with cross-functional teams (Security … a related field. Experience supporting sales processes, including responding to RFx security assessments. Solid understanding of cybersecurity principles, information security best practices, and regulatory requirements (DORA, NIS2, GDPR, ISO27001, SOC 2, etc.). Excellent written and verbal communication skills; able to translate technical concepts for non-technical audiences. Strong organizational skills with the … a proactive approach to problem-solving and attention to detail. Experience working in a SaaS, cloud, or technology-driven company is preferred. Professional certifications (such as CISM, CRISC, ISO27001LeadImplementer/ Auditor, or similar) are a plus Additional Information We are proud to foster a diverse More ❯
we do. About the Role As an Information Security Analyst , you will help shape and execute our security and compliance strategy. You will support compliance frameworks such as ISO/IEC27001, SOC 2, HIPAA, and GDPR , help manage risk, and ensure that security practices are embedded in our daily operations. You’ll … within the team, taking ownership of operational security work while contributing to strategic initiatives over time. Things you will do: Support and manage Typeform’s compliance programs, including ISO, SOC 2, and HIPAA. Assist in third-party risk assessments, vendor security reviews, and customer security inquiries. Work closely with Vanta (our compliance automation platform) to manage security … the organization. What you already bring to the table: Experience in information security, risk management, or compliance, preferably in a SaaS environment. Understanding of security frameworks such as ISO/IEC27001, SOC 2, HIPAA, and GDPR . Experience with security compliance automation tools (e.g., Vanta, Drata, or similar platforms). Ability to More ❯
protection of personnel, physical and information assets. Management and development of a team delivering security to the business across all security domains to facilitate policy and strategy implementation. Lead and direct technical professionals in Information Security. Accountable for the ongoing certification to ISO 27001. Reviewing, rationalising, revising and aligning ISMS policies with business strategy. … include comprehensive experience of working with HMG information assets in a secure environment. Working knowledge of Government Functional Standard GovS007 – Security and International Standard for Information Security Management – ISO 27001. Detailed understanding of HMG personnel vetting processes. Experience of driving continuous improvements in business processes and the ability to identify root cause corrective actions. Highest ethical standards … relationships in a multi-discipline environment, including the ability to brief up to Board Level directors. Strong, effective leadership, mentoring and conflict resolution skills. Additional Skills and Experience: ISO27001LeadImplementer or Lead Auditor is desirable. Member of DISA and other professional IA bodies More ❯
vaardigheden : - Ervaring met het ontwikkelen en implementeren van informatiebeveiligingsbeleid en -procedures. - Bekendheid met risicomanagement en het uitvoeren van risicoanalyses en audits. - Kennis van relevante beveiligingsstandaarden en -normen, zoals ISO27001, NIST, CIS en de BIO. - Ervaring met compliance en wet- en regelgeving, waaronder AVG, NIS2 en DORA. - Ervaring met Security Operations en incident response … processen. - Kennis van tooling zoals SIEM, vulnerability management en identity & access management. Certificeringen : In het bezit van relevante certificeringen zoals CISSP, CISM, CISA of ISO27001LeadImplementer/ Auditor. Soft skills : Sterke communicatieve vaardigheden, het vermogen om complexe beveiligingsvraagstukken helder uit te leggen aan stakeholders en een More ❯
My client is hiring an Information Security Lead to help shape and implement its cybersecurity operations, governance, and risk framework. Reporting to the IT Operations & Security Manager, this role is critical in maintaining the organisation's security posture, ensuring compliance, and supporting ongoing IT service resilience. Key Responsibilities Oversee third-party security tools and services (e.g. firewalls … IDS / IPS, endpoint protection) and monitor vendor SLA adherence. Conduct risk assessments, maintain the security risk register, and manage remediation activities. Lead incident response processes including detection, containment, investigation, and resolution. Develop, implement, and maintain information security policies, procedures, and standards. Ensure compliance with ISO27001, NIS2, and other regulatory … Degree in Computer Science, Information Security, or a related field. Minimum 5 years' experience in IT security roles, ideally within regulated or public sector environments. Solid knowledge of ISO27001 and related frameworks; experience with certified environments. Strong understanding of risk, incident, and change management. Familiarity with security technologies such as SIEM, MFA, encryption More ❯
London, England, United Kingdom Hybrid / WFH Options
Bridewell Consulting Limited
client-facing projects both independently and as a team, enhancing your practical experience in the field. During this time, you will focus on completing essential certifications, including the ISO27001LeadImplementer and Auditor courses, as well as the Certificate in Information Security Management Principles (CISMP). Achieving More ❯
ability to implement solutions yourself Knowledge & experience working with ISO27001 and other relevant frameworks Organising and communicating, hit the ground running independent Desired Relevant certifications e.g. CISM, ISO27001 Lead Auditor /Implementer Benefits Join a company thriving in the media industry Have the freedom to shape your position as you see fit Work with More ❯
Edinburgh, Scotland, United Kingdom Hybrid / WFH Options
Head Resourcing Ltd
items. Ability to work independently and in agile teams. Excellent communication and stakeholder management skills are a must as always. Any formal certifications like CISA, CISM , or ISO27001 LeadImplementer/ Auditor would be highly advantageous With a hybrid-working approach, my client is ideally seeking candidates from local Scottish-Market who can commit More ❯
City of London, England, United Kingdom Hybrid / WFH Options
Parser
high caliber of our experts, we have enjoyed triple digit growth over the past five years, creating amazing career opportunities for our people. As a Cyber Delivery Assurance Lead, you will champion “security-by-design” across every BA product release. You will provide independent assurance to the Head of Cyber & IT Risk that delivery teams align with … in threat and risk assessments across cloud, network, and infrastructure stacks. Strong working knowledge of NIST, PCI DSS, GDPR, NIS, and NCSC guidance. Relevant certifications such as CISSP, ISO27001LeadImplementer, or SANS GIAC (or equivalent). Proven track record of influencing senior colleagues and third-party More ❯
to test our customer's incident response capabilities. Security Operations Oversee the continuous monitoring and detection of security threats and vulnerabilities to ensure a proactive stance to security. Lead the investigation and resolution of security incidents, promptly and effectively. Evaluate, select, and deploy security tools to enhance our customer's security infrastructure. Compliance Management Ensure compliance with … / IPS, DLP). Knowledge of regulatory requirements and, governance and compliance frameworks. Project management skills to oversee and manage security initiatives effectively. Preferably certified as NIS 2 LeadImplementer, DORA Lead Manager, ISO27001LeadImplementer or LeadMore ❯
ll Be Working On: ️ Developing, implementing, and maintaining security governance frameworks, policies, and procedures ️ Conducting regular security audits and assessments to ensure compliance with regulatory standards (e.g., GDPR, ISO27001) ️ Collaborating with IT and legal teams to ensure that security strategies meet compliance requirements and industry best practices ️ Supporting risk management and mitigation strategies … security policies, and best practices What We’re Looking For: ️ Proven experience as a Security Governance Specialist or in a similar role ️ Strong knowledge of security frameworks (e.g., ISO27001, NIST, COBIT) and relevant industry regulations (e.g., GDPR, PCI-DSS, HIPAA) ️ Experience conducting security audits, risk assessments, and compliance reporting ️ Expertise in implementing and … managing governance structures, security policies, and controls ️ Certifications such as CISM, CISSP, or ISO27001LeadImplementer are highly desirable #J-18808-Ljbffr More ❯
London, England, United Kingdom Hybrid / WFH Options
Bridewell Consulting Limited
client-facing projects both independently and as a team, enhancing your practical experience in the field. During this time, you will focus on completing essential certifications, including the ISO27001LeadImplementer and Auditor courses, as well as the Certificate in Information Security Management Principles (CISMP). Achieving More ❯
s comprehensive cybersecurity strategy and roadmap Establish, implement, and maintain security policies, risk management frameworks, and incident response procedures Continuously monitor for security threats, vulnerabilities, and incidents, and lead timely response efforts Perform regular security risk assessments and internal audits to identify and mitigate risks Ensure ongoing compliance with relevant regulations (e.g., GDPR, NIS2, ISO27001, where applicable … ISO27001, NIST, CIS Controls) and regulatory standards (e.g., GDPR, NIS2) Strong analytical skills, with excellent communication and stakeholder engagement capabilities Professional certifications such as CISSP, CISM, or ISO27001 LeadImplementer are highly desirable Proficiency in both Dutch and English is required Interested in this opportunity? Feel free to apply or send us your updated More ❯
to work on own initiative. Applicants must have the Right to Work in the UK. Desirable knowledge, skills and experience Qualifications such as CompTIA Security+, CEH or ISO27001 Lead Implementer. Experience of senior management engagement and relationship management. Experience in dealing with Information Security incidents. Experience conducting penetration tests and working with vulnerability management tools. This role More ❯
to work on own initiative. Applicants must have the Right to Work in the UK. Desirable knowledge, skills and experience Qualifications such as CompTIA Security+, CEH or ISO27001 Lead Implementer. Experience of senior management engagement and relationship management. Experience in dealing with Information Security incidents. Experience conducting penetration tests and working with vulnerability management tools. This role More ❯
to work on own initiative. Applicants must have the Right to Work in the UK. Desirable knowledge, skills and experience Qualifications such as CompTIA Security+, CEH or ISO27001 Lead Implementer. Experience of senior management engagement and relationship management. Experience in dealing with Information Security incidents. Experience conducting penetration tests and working with vulnerability management tools. Benefits This More ❯
hunting. Conduct in-depth vulnerability assessments, manage remediation efforts, and contribute to the development of strategies to address security weaknesses. Ensure ongoing adherence to information security standards, particularly ISO27001 and NIS2 directives, and support audit processes. Participate in the full lifecycle of security incident response, from detection and analysis to containment, eradication, recovery … Strong understanding of cybersecurity concepts, network security protocols, cloud security principles, and common attack vectors. Certifications (Strongly Preferred): Relevant certifications such as CompTIA Security+, CySA+, CEH, or equivalent. ISO27001LeadImplementer/ Auditor certification is a significant advantage. Language Proficiency: Fluent in Dutch, English, and French (written More ❯