skills to interpret data and provide insights into threats facing the bank. Awareness of common Cyber Incidents and Security breaches (OWASP). Knowledge or experience in SOC2, ISO 27001, PCIDSS and GDPR. Previous experience working within an organisations Cyber Incident Response function. Hands on experience with Information Security tools. About you: Team player with the ability to … Effective time management and ability to prioritize tasks. Strong analytical and problem-solving skills. Proficiency in Microsoft Office. Interested? Please Apply! SOC ISO ISAO CISSP NIST CSF ISO27000 ISO27001 PCIDSS GDPR Cybersecurity Cyber Security Information Security Infosec Cybersec Risk Infrastructure ISMS 2LOD 2 LOD Second Line of Defence More ❯
South East London, England, United Kingdom Hybrid / WFH Options
SR2 | Socially Responsible Recruitment | Certified B Corporation™
Risk Management: Identify and manage risks to information assets and IT systems. Lead enterprise risk assessments and mitigation planning. Compliance & Regulatory: Ensure adherence to global data protection regulations (GDPR, PCI-DSS, etc.), working closely with legal and data protection teams. Leadership & Stakeholder Engagement: Act as the subject matter expert on cybersecurity at the board and executive level. Communicate … experience building and scaling a GRC function in a complex environment. Deep knowledge of information security standards (ISO 27001, NIST, CIS), risk frameworks (COSO, FAIR), and regulatory obligations (GDPR, PCI-DSS, SOX). Proven track record of managing enterprise-level security programs, including incident response and business continuity. Excellent stakeholder management skills, with experience reporting at board level. More ❯
South East London, England, United Kingdom Hybrid / WFH Options
The Curve Group
degree, preferably in Computer Science, Cyber Security or Cyber Security Professional Qualifications/Certifications Desirable: General understanding of IT Security principles, standards and regulations (e.g. ISO 27001, NIST, CIS, PCIDSS and GDPR) CISM/CISSP Patch Management Applications, EDR/XDR systems. Antivirus, NAC - Forescout Vulnerability Scanning Tool e. Tenable One, Qualisys Knowledge of vulnerability scoring systems More ❯
security integrations. Investigate security incidents, prioritise remediation and guide teams on secure development practices. Ensure applications meet industry standards (OWASP Top 10, NIST, ISO 27001) and regulatory requirements (GDPR, PCI-DSS, etc.) Educate engineers and stakeholders on security threats, vulnerabilities and secure coding practices. Skills 5+ years of experience in application security, penetration testing, or software security engineering. More ❯
Antom, WorldFirst and ANEXT Bank. Role Overview: As a Lead Cyber Security Specialist, you will ensure alignment with European regulations (e.g., GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCIDSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party risk , outsourcing compliance , and identity governance to safeguard operational resilience. What … Support compliance with GDPR and complementary regulations like DORA (Digital Operational Resilience Act) , ensuring alignment in areas such as incident reporting and data protection. Translate requirements from PSD2 SCA , PCIDSS , and SWIFT CSP into technical security controls. Maintain IT security governance frameworks (ISO 27001, NIST CSF, CIS Controls). Manage and maintain Security Policies and procerdures Third … with least privilege principles and regulatory requirements. Security awareness management experience. What we are looking for: 5+ years in GRC roles ; financial services or banking. Understanding of GDPR , DORA , PCIDSS, and outsourcing/third-party risk requirements. Hands-on experience with ISO 27001 implementation and third-party risk tools . Proficiency in IAM (Identity and Access Management More ❯
South East London, England, United Kingdom Hybrid / WFH Options
Stott and May
process, working closely with development teams to review, design, and implement infrastructure decisions. Maintain documentation for platforms, services, and pipelines. Audit activities to ensure compliance with security policies (including PCIDSS, GDPR, and PII). Perform root‐cause analysis and implement improvements to prevent incidents and optimize performance. Maintain and evolve monitoring platforms, including synthetic and application monitoring More ❯
South East London, England, United Kingdom Hybrid / WFH Options
Next Ventures
particularly using the Microsoft security stack Familiarity with vulnerability management tools Experience delivering cyber security training and awareness initiatives Demonstrated support of compliance/certification projects such as PSN, PCIDSS, or Cyber Essentials Plus Excellent communication and stakeholder engagement skills Apply Now More ❯
within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCIDSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll need Proven experience More ❯
Security Compliance Manager - Payments, PCIDSS, SOC2 - £100,000 A rapidly growing payments technology company that has established itself as a major player in the UK market, is seeking a Security Compliance Manager to drive their critical compliance initiatives and strengthen their security posture as they continue their expansion across multiple markets. This is a great opportunity for … an experienced Security Compliance Manager to take ownership of comprehensive compliance programs within a dynamic payments environment. You'll be the go-to expert for PCI certifications, leading compliance strategy, and building robust security control frameworks that enable business growth while maintaining customer trust. Working within the Product Security team, you'll collaborate closely with engineering and product development … to embed security compliance from the ground up. The Security Compliance Manager's responsibilities: Leading and managing all PCI compliance initiatives including PCIDSS, PCI PIN, PCI P2PE certifications, with responsibility for achieving new certifications such as PCI MPoC and PCI SSF. Serving as the primary liaison with Qualified Security Assessors (QSAs) and More ❯
South East London, England, United Kingdom Hybrid / WFH Options
Gravitas Recruitment Group (Global) Ltd
approach Desirables: Experience with event-driven architecture and queues (e.g. SQS, Kafka) Previous work with payment platforms, Open Banking, or fintech APIs Understanding of data privacy and compliance (e.g. PCI-DSS, GDPR) Experience in startup or high-growth environments Interest in financial empowerment and supporting small businesses More ❯
Manager Location: London (Paddington), onsite 4 days/week Salary: Up to £110K + Excellent benefits Are you an experienced Security Compliance professional with a strong track record in PCI‐DSS, SOC 2 and GDPR? A growing fintech expanding across Spain and Italy is seeking someone like you to drive their compliance function forward. What you’ll be … doing: Lead and maintain PCI‐DSS, PCI PIN, PCI P2PE, and SOC 2 certifications Develop and test internal security controls and remediation plans Manage GDPR and emerging EU mandates (e.g. DORA, NIS2, NIST) Act as liaison with QSAs, external auditors, and internal stakeholders Keep the IT estate compliant and future-ready What we’re looking for … 3+ years of hands‐on experience managing PCI, SOC 2 & GDPR controls Proven expertise in internal auditing, gap analysis and remediation Up-to-date with European/DORA regulations, risk‐averse mindset Flexible, collaborative communicator with onsite availability Spanish/Italian speaker or willing to travel is a plus Why join? Bring security to life across multiple EU markets More ❯
South East London, England, United Kingdom Hybrid / WFH Options
Reward
API and data pipeline testing Identifying and documenting defects across multiple test environments Estimating testing effort and supporting planning across sprints Collaborating closely with engineers and product managers Supporting PCI compliance and maintaining documentation Contributing to client training sessions (optional, but a bonus!) Tech we use (experience with any of these is a plus) While frameworks may change, we … like Postman Test automation frameworks (Cypress, Selenium) SQL/no-SQL databases for querying and validation Issue tracking systems (we use Jira) Data pipeline testing in cloud-based environments PCI compliance understanding is helpful Client training experience is a nice bonus Who this role is perfect for Testers who love quality, structure, and solving real user problems Curious minds More ❯