join a growing team within an MSSP. Within this role you will be providing detailed risk assessments, implementing industry-standard security frameworks including NIST, NCSC, and NIS2 as well as actively managing SIEM tools such as QRadar and/or Sentinel. You’ll be working closely with end … regular meetings, strategic updates and consultative insights Lead comprehensive security risk assessments inline with industry standards and conduct environment reviews ensuring compliance with NIST Frameworks and related standards Oversee and implement SIEM/XDR deployments, custom rule development, and incident response processes acting as a point of escalation … perform gap analyses, and create and deliver reports on findings to end customer stakeholders Skills, Experience, and Certifications: Strong understanding of cybersecurity frameworks (NIST CSF, NCSC CAF, NIS2, NIST800-30) Confident in using risk assessment methodologies (NIST800More ❯
tooling, architecture, and implementation. Solid understanding of attacker TTPs and how to design effective, scalable defenses. Experience with ISO 27001, NIST CSF, SP800-53, Cyber Essentials, or similar frameworks. Deep knowledge of UK and global data protection and cybersecurity regulations. Certifications like CISSP , CISM , or More ❯
and security risk reviews. Risk analysis and mitigation strategies for vulnerabilities. Identifying security vulnerabilities and assessing their impact. Implementing control frameworks such as NIST800-53, ISO 27001, FedRamp, and NIST CSF. Experience with penetration testing tools for web applications. Maintaining system/application More ❯
slough, south east england, united kingdom Hybrid / WFH Options
InfoSec People Ltd
all levels, strong all round technical expertise, and a passion for security. Key Responsibilities: Lead detailed cybersecurity risk assessments aligned to frameworks (e.g., NIST, NIS2). Manage and grow client relationships through strategic engagement, consulting with C suite executives and external security leaders. Oversee SIEM/XDR deployments … guidance on threat detection best practices. Technical Skills & Experience: Proficient with SIEM/XDR tools (QRadar, Sentinel, Defender XDR). Strong knowledge of NIST CSF, NCSC CAF, and cloud security (AWS, Azure, GCP). Experienced in risk methodologies (e.g., NIST800-30). Preferred More ❯
is managed by allocated team Scrum Master. Responsibilities and Tasks Support delivery of secure Releases and Features aligned with the relevant legacy or NIST assurance processes through Security Assurance stories agreed with nominated team Scrum Master Create security assurance case for releases, including risk assessments and mitigations for … via the Security Lead or Security Assurance Lead for resolution at the security working group Knowledge, Experience and Capabilities Cyber Security Assurance ISO27001 NIST800-53 series MOD Secure by Design Information assurance Risk management High quality of written and verbal communication skills Experience of working More ❯
is managed by allocated team Scrum Master. Responsibilities and Tasks * Support delivery of secure Releases and Features aligned with the relevant legacy or NIST assurance processes through Security Assurance stories agreed with nominated team Scrum Master * Create security assurance case for releases, including risk assessments and mitigations for … via the Security Lead or Security Assurance Lead for resolution at the security working group Knowledge, Experience and Capabilities * Cyber Security Assurance * ISO27001 * NIST800-53 series * MOD Secure by Design * Information assurance * Risk management * High quality of written and verbal communication skills * Experience of working More ❯
Nice to Have: SOC certifications (e.g., GCIH, GCIA), Splunk Certified User/Admin. Familiarity with cloud logging (CloudTrail, Azure Monitor). Understanding of NIST800-61, ISO 27001. More ❯
GCP environments. Conduct cloud security assessments, risk reviews, and remediation planning. Support compliance with financial regulations (FCA, PRA, DORA) and frameworks (ISO 27001, NIST, CIS). Implement infrastructure-as-code (IaC) security, workload protection, and CI/CD pipeline hardening. Develop and enforce policies for identity and access … Azure Defender, GCP SCC). Experience supporting regulated environments, ideally within financial services. Familiar with compliance and cloud governance frameworks (e.g., CSA CCM, NIST800-53, ISO 27017). Proficiency with IaC tools (e.g., Terraform, CloudFormation) and CI/CD security. Certifications such as CCSP, AWS More ❯