years of experience in Information Security, Compliance, or IT Risk Management. Experience with regulatory frameworks in UK & EU : GDPR (General Data Protection Regulation) ISO 27001 (Information Security Management Systems) CyberEssentials Plus (UK government-backed security framework) DORA (Digital Operational Resilience Act) - EU financial sector PCI-DSS (if handling payment data) Experience in: Managing vendor risk assessments for … Deep understanding of data protection laws (UK GDPR, EU GDPR, DPA 2018) . Familiarity with risk management frameworks like NIST CSF, CIS Controls, and ISO 27005 . Experience with cyber security tools (e.g., SIEM, Malware Protection, Firewalls and others) is a plus. Strong reporting and communication skills-ability to brief executives and regulators. Ability to design, implement, and enforce … security policies . Key Responsibilities: Ensure compliance with GDPR, CyberEssentials Plus, PCI-DSS, and other applicable standards. Align ISMS activities with ISO 27001 framework. Develop and implement security policies, controls, and procedures. Conduct security risk assessments & compliance audits. Manage incident response & data breach reporting (ICO & EU authorities). Liaise with regulators, legal teams, and third-party auditors. More ❯
Southampton, Hampshire, United Kingdom Hybrid / WFH Options
NICE
will light a fire within you. So, what's the role all about? The Information Security Analyst is primarily responsible for ensuring compliance with information security frameworks such as CyberEssentials, CyberEssentials Plus, ISO 27001, ISO 27701, ISO 42001, GDPR, and DORA. This role focuses on internal audits, regulatory compliance, and readiness for external audits … audits. Gap Assessments: Facilitate and/or conduct internal gap assessments and audit readiness evaluations for frameworks such as ISO 27001, GDPR, and DORA. Framework Tracking: Monitor updates to CyberEssentials, ISO, and regulatory frameworks and ensure internal alignment. Control Documentation: Develop and maintain control narratives, walkthroughs, and documentation of compliance processes. Audit Findings: Identify control deficiencies and … coordination with IT and Security Operations teams. Have you got what it takes? Strong expertise in audit and compliance frameworks, including ISO 27001, ISO 27701, ISO 42001, GDPR, DORA, CyberEssentials, and CyberEssentials Plus. Familiarity with CSOC tools such as Rapid7 InsightIDR or other SIEM solutions. Hands-on experience in internal and external audits, compliance More ❯
Huntingdon, Cambridgeshire, United Kingdom Hybrid / WFH Options
Huntingdonshire District Council
Job details About the role Are you driven by a strong sense of integrity and a passion for safeguarding digital infrastructure? We are looking for a proactive and experienced Cyber/Information Security Lead to join our 3C ICT Shared Services team. In this pivotal role, you will uphold the highest standards of confidentiality, integrity, and availability across our … councils with professionalism and care. You will collaborate closely with the Technical Architect and key stakeholders to embed a 'Secure by Design' approach, aligned with the UK Government's Cyber Security Strategy. Your leadership will reflect our commitment to excellence, supporting a culture of accountability and respect while delivering robust, forward-thinking security measures. Key responsibilities Develop, implement, and … Monitor IT systems for threats and vulnerabilities, producing detailed reports Lead forensic investigations and liaise with relevant bodies in the event of breaches Represent 3C ICT at public sector cyber security forums such as WARP and CyberUK Deliver training and raise awareness of cyber security best practices Support disaster recovery planning and ensure systems are patched and compliant More ❯
Farnborough, Hampshire, South East, United Kingdom
Gama Group Limited
Security & Compliance Manager Location: Farnborough HQ Working Hours: Full-Time, 40 Hours per week We are looking for a hands-on Information Security & Compliance Manager to take ownership of cyber security and data privacy across myairops. This role balances strategic oversight with practical, day-to-day security operations. Youll be central to maintaining our SOC 2 Type II accreditation … and service availability. Collaborate with the Group CIO and DPO, contributing to wider organisational security and data privacy initiatives. Skills, Qualifications and Experience required: Essential A solid background in cyber or informationsecurity, with experience operating at a similar level in cloud environments (ideally Azure) OR possess a degree within cyber or information security with the ability to demonstrate … cloud native Experience of successfully achieving ISO27001 or preferably SOC2 Type 2 Strong understanding of application security, cloud infrastructure, and DevOps practices Awareness of industry frameworks, such as NCSC Cyber Assessment Framework, CyberEssentials Plus and OWASP Experience managing and selecting 3rd party vendors for audit and penetration testing Experience interacting with customer security and data privacy More ❯
Server environments, and authentication solutions. Plan for scalability, redundancy, and high availability to support future growth. IT Security & Compliance: Ensure compliance with security and regulatory standards, including PCI DSS, Cyber Essentials+, DORA, and ISO 27001. Implement and enforce security best practices across infrastructure automation and cloud environments. Maintain accurate compliance documentation, including PCI DSS scope records and security policies. … of the following skills and experience: Strong expertise in defining, delivering, and supporting robust, resilient, and secure enterprise infrastructure. Experience with IT audits and compliance frameworks (CIS, PCI DSS, CyberEssentials, NIST, ISO 27001). In-depth understanding of network security and compliance in regulated environments. Proven ability to secure high-value data (PCI cardholder data, PII) and More ❯
Crawley, Sussex, United Kingdom Hybrid / WFH Options
Better Days Recruitment Ltd
Due to company grown within the IT area, I am recruiting for an experienced Information Security Officer and Cyber Security Lead to join an award-winning company located in the Southeast. You can be based in either the Crawley or Brighton Office and will possess demonstrable experience within Information and Cyber Security. You will play a pivotal role … in shaping and creating the companies Cyber strategy. The role involves providing guidance to stakeholders on information security matters, managing technical cybersecurity tools and operations and overseeing regulatory standards. You will lead the development and execution of the companies cyber and information security strategy ensuing it is aligned with ISO 27001, GDPR and Cyber essentials. Combining strong … Experience and attributes: A minimum of 4-5 years experience working in a similar role Strong understanding of information security principles, risk management and compliance (GDPR, ISO 27001 and CyberEssentials) Ability to talk technically then non-technically to the business Solid understanding of IT Infrastructure eg; networking, Active Directory and endpoint security, Outstanding communication skills verbally, written More ❯
Crawley, West Sussex, United Kingdom Hybrid / WFH Options
Better Days Recruitment Ltd
Due to company grown within the IT area, I am recruiting for an experienced Information Security Officer and Cyber Security Lead to join an award-winning company located in the Southeast. You can be based in either the Crawley or Brighton Office and will possess demonstrable experience within Information and Cyber Security. You will play a pivotal role … in shaping and creating the companies Cyber strategy. The role involves providing guidance to stakeholders on information security matters, managing technical cybersecurity tools and operations and overseeing regulatory standards. You will lead the development and execution of the companies cyber and information security strategy ensuing it is aligned with ISO 27001, GDPR and Cyber essentials. Combining strong … Experience and attributes: A minimum of 4-5 years’ experience working in a similar role Strong understanding of information security principles, risk management and compliance (GDPR, ISO 27001 and CyberEssentials) Ability to talk technically then non-technically to the business Solid understanding of IT Infrastructure eg; networking, Active Directory and endpoint security, Outstanding communication skills verbally, written More ❯
Employment Type: Permanent
Salary: £65000 - £70000/annum Great company benefits
Liverpool, Lancashire, United Kingdom Hybrid / WFH Options
Techwaka
Senior Cyber Security Engineer opportunity working within an established fintech firm in Liverpool Attractive benefits package Up to £60,000 per annum depending on experience Full Time - Permanent role - Hybrid working available Sector: Finance Benefits Competitive Salary - £55,000 - £60,000 per annum Generous Annual Leave Paid Sick days Company Pension A comprehensive in-house training Continued training and … development Friendly and supportive working culture About the Role: Lead on technical cyber security initiatives within the Security Operations team Ensure the implementation of robust security controls and best practices Provide specialist security support to IT teams, including infrastructure, development, and database teams Work with stakeholders to maintain compliance with industry standards such as ISO27001, CyberEssentials Plus, PCI/DSS Stay ahead of cyber threats, maintaining and improving security monitoring and risk management processes Support vulnerability management, penetration testing, and incident response Requirements for this role: 3+ years' experience in a senior cyber security role Strong knowledge of security frameworks (NIST, NCSC, CIS, MITRE ATT&CK) Hands-on experience with security tools: SIEM More ❯
laws, particularly within cybersecurity, data protection, and operational risk. What you will do: Lead and support the implementation of key compliance and cybersecurity frameworks (e.g. UK GDPR, ISO 27001, CyberEssentials), while developing regulatory risk frameworks that track and operationalise emerging obligations. Conduct and coordinate risk assessments, internal reviews, audits, and control testing to ensure compliance with regulations … for external audits, regulatory reviews, and due diligence processes, particularly in relation to regulatory risk and operational resilience. Oversee third-party vendor and partner assessments from a compliance and cyber risk perspective. Work cross-functionally with Compliance, Product, Engineering, and Operations to identify, assess, and mitigate risks. Maintain clear ownership of security-related compliance obligations, working alongside (not under … apply regulatory frameworks (e.g. UK GDPR, ISO 27001) and translate them into business-friendly policies, controls, and processes. Confidence working with regulatory frameworks like UK GDPR, ISO 27001, and CyberEssentials, and a willingness to navigate evolving guidance such as Network and Information Systems Regulations 2018 (NIC) or Payment Card Industry Data Security Standards (PCI DSS) Strong communication More ❯
excellent problem-solving skills Ability to manage competing priorities and deliver under pressure A full UK driving license and access to a business-insured vehicle Desirable Skills Familiarity with CyberEssentials, NCSC, NIST and ISO 27001 standards Experience with cloud platforms (e.g., Azure, AWS) Knowledge of cybersecurity frameworks and tools Strong communication and stakeholder engagement skills About us … configuration, security and management Large scale multi-site wireless deployment Patch management and configuration solutions Desktop Imaging and deployment Active Directory, DNS, Public Key Infrastructure and Group Policy management Cyber security principles Anti-Virus products Microsoft Office 365 Microsoft Azure Configuration and Management Detailed knowledge of hardware and software in a corporate IT environment Ability to analyse complex issues More ❯
PO15, Whiteley, Hampshire, United Kingdom Hybrid / WFH Options
Stratospherec Ltd
of the following skills and experience: Strong expertise in defining, delivering, and supporting robust, resilient, and secure enterprise infrastructure. Experience with IT audits and compliance frameworks (CIS, PCI DSS, CyberEssentials, NIST, ISO 27001). In-depth understanding of network security and compliance in regulated environments. Proven ability to secure high-value data (PCI cardholder data, PII) and More ❯
Kendal, Cumbria, North West, United Kingdom Hybrid / WFH Options
Des Scanlan IT Recruitment Ltd
Directory, Azure AD, Entra ID, Intune, software & cloud deployment, Microsoft365, Exchange Online Administration, A good understanding of industry standards and cybersecurity, e.g. including but not limited to ISO9001, ISO027001, CyberEssentials and ITIL. Understanding of project management principles. Excellent coordination skills. Ongoing technical skills developments and certification where required. As a team member, how you go about your More ❯
Role: Cyber Security Engineer Location: Leeds, West Yorkshire Salary: £55,000 - £70,000 PLUS 25 Days Holiday, Vendor Certifications, International Travel, Private Pension About the Company: Our client, a global leader in Sustainability Consulting, is looking for a Cyber Security Engineer to join their growing Information Security Team. This exciting role provides an opportunity to shape and strengthen … organization. If you are passionate about cybersecurity, have a strong technical background, and thrive in a fast-paced environment, we want to hear from you. Position Overview: As a Cyber Security Engineer, you will collaborate with the IT Security Team to advise, develop, and maintain security processes and policies. Your expertise will guide the organization in enhancing security capabilities … across its global infrastructure. This role offers a chance to make a real impact by ensuring the integrity and resilience of the company’s IT environment against evolving cyber threats. Key Responsibilities: Support incident management and security response efforts, providing expertise to address and resolve security incidents quickly and effectively. Perform regular security checks, including daily, weekly, and monthly More ❯
Are you currently working for an IT provider but ready to step into the world of dedicated Cyber Security? We have an exciting opportunity for an Information Security Consultant looking to elevate their career. We're looking for someone with hands-on experience in ISO 27001 implementation and auditing, and expertise in NIST to drive our Compliance Team's … service offerings forward. Work with a innovative, industry-leading Cyber Security team Play a key role in the development of internal and client security programs Contribute to significant projects that support clients' compliance and risk management goals If you're ready to make an impact in Cyber Security, this role is for you! Responsibilities: Ensure protection of information …/Must have: Extensive experience in Information Security Governance, Risk, and Compliance (GRC) Experience contributing to an Information Security Management System (ISMS) certified to ISO27001 standards Knowledge of the CyberEssentials Plus Scheme, GDPR, and Data Protection Act (2018) Strong communication skills and the ability to build relationships with internal and external stakeholders Hands-on experience in ISO27001 More ❯
Role: Cyber Security Consultant Location: Leeds, West Yorkshire Salary: £60,000 - £75,000 PLUS 25 Days Holiday, Vendor Certifications, International Travel, Private Pension About the Company: Our client, a global leader in Sustainability Consulting, is looking for a Cybersecurtiy Consultant to join their growing Information Security Team. This exciting role provides an opportunity to shape and strengthen security practices … capabilities across its global infrastructure. This role offers a chance to make a real impact by ensuring the integrity and resilience of the company’s IT environment against evolving cyber threats. Key Responsibilities: Support incident management and security response efforts, providing expertise to address and resolve security incidents quickly and effectively. Perform regular security checks, including daily, weekly, and … Essential Skills & Experience: At least 2 years of hands-on experience in information security or IT infrastructure within an enterprise environment. Familiarity with security standards such as ISO 27001, CyberEssentials, GDPR, and Data Protection Act. Experience with Microsoft O365 Security solutions and network security operations. Understanding of security testing principles, including vulnerability scanning, risk identification, and mitigation. More ❯
Join our Cyber Security Team as a Governance, Risk and Compliance Analyst. If you have been involved in practical aspects of GRC including ISO270001, want to work with a team of dedicated professionals and are able to understand wider business impacts of GRC on a business, please read more and apply. Location We operate a flexible, hybrid working environment … Assist with internal audits and help prepare for external audits to maintain compliance with ISO27001 and other standards Help identify and assess information security risks, working closely with the Cyber Risk Manager Provide guidance to colleagues on basic security best practices and requirements Contribute to reporting on the ISMS performance and improvement plans Support continual improvement initiatives and track … Good analytical and problem-solving skills A proactive and collaborative approach Integrity and a commitment to confidentiality and professionalism Qualifications A bachelor's degree in computer science, information technology, cyber security, or a related field Experience and knowledge Familiarity with information security frameworks, especially ISO27001 (2013 or 2022) Basic understanding of risk management principles and security controls Interest in More ❯
Winchester, Hampshire, United Kingdom Hybrid / WFH Options
Arqiva
Join our Cyber Security Team as a Governance, Risk and Compliance Analyst. If you have been involved in practical aspects of GRC including ISO270001, want to work with a team of dedicated professionals and are able to understand wider business impacts of GRC on a business, please read more and apply. Location We operate a flexible, hybrid working environment … Assist with internal audits and help prepare for external audits to maintain compliance with ISO27001 and other standards Help identify and assess information security risks, working closely with the Cyber Risk Manager Provide guidance to colleagues on basic security best practices and requirements Contribute to reporting on the ISMS performance and improvement plans Support continual improvement initiatives and track … Good analytical and problem-solving skills A proactive and collaborative approach Integrity and a commitment to confidentiality and professionalism Qualifications A bachelor's degree in computer science, information technology, cyber security, or a related field Experience and knowledge Familiarity with information security frameworks, especially ISO27001 (2013 or 2022) Basic understanding of risk management principles and security controls Interest in More ❯
capabilities across its global infrastructure. This role offers a chance to make a real impact by ensuring the integrity and resilience of the company’s IT environment against evolving cyber threats. Key Responsibilities: Support incident management and security response efforts, providing expertise to address and resolve security incidents quickly and effectively. Perform regular security checks, including daily, weekly, and … Essential Skills & Experience: At least 2 years of hands-on experience in information security or IT infrastructure within an enterprise environment. Familiarity with security standards such as ISO 27001, CyberEssentials, GDPR, and Data Protection Act. Experience with Microsoft O365 Security solutions and network security operations. Understanding of security testing principles, including vulnerability scanning, risk identification, and mitigation. More ❯
good grasp of security and security controls/best practice. Required Skills: Strong knowledge of Microsoft technologies (Windows Server, Azure, Office 365). Excellent knowledge of security best practices (CyberEssentials Plus, ISO27001) Experience with virtualization (Hyper-V), networking, and security tools. Experience configuring and administering core network switching and firewalls. Experience dealing with security platforms (e.g. Barracuda More ❯
software/OS deployment Cloud Hosting (AWS, Azure) Experience with DR and Backups Technologies, in particular ArcServe Cloud Antivirud & Managed Networks Cloud managed telephony Cloud migration experience Microsoft Intune CyberEssentials Plus & ISO27001 More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Gordons
conduct Information Security risk assessments within the Surecloud GRC tool. Assist in managing the requirements for the firm to comply with ISO/IEC 27001 Policies and Standards and CyberEssentials Plus. Assisting with conducting information security audits internally and externally. Assist in remediation activities to resolve audit findings. Respond to client audit requests and understand the client More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Tussell Limited
conduct Information Security risk assessments within the Surecloud GRC tool. Assist in managing the requirements for the firm to comply with ISO/IEC 27001 Policies and Standards and CyberEssentials Plus. Assisting with conducting information security audits internally and externally. Assist in remediation activities to resolve audit findings. Respond to client audit requests and understand the client More ❯
are passionate about accelerating the UKs transition to a sustainable energy future. As part of our commitment to cybersecurity, compliance, and operational resilience, we are seeking a skilled IT & CyberEssentials Coordinator to manage our internal systems and lead the implementation and maintenance of our CyberEssentials certification. This is a key role for someone who … sector. Key Responsibilities: Oversee day-to-day IT support across the business, ensuring secure system configuration and effective user support. Lead the implementation and ongoing compliance with the UK CyberEssentials scheme. Maintain secure IT infrastructure supporting in-house and cloud systems. Ensure protection of customer data and operational technology in line with government and energy sector standards. … Manage and maintain hardware and software asset registers. Oversee device hardening, firewall configuration, endpoint protection, and patch management. Coordinate internal readiness for CyberEssentials assessments and liaise with external assessors. Develop and enforce cybersecurity policies, processes, and end-user awareness training. Monitor access controls and ensure least-privilege principles are applied consistently. Essential Skills & Experience: Proven experience in More ❯
other stakeholders across the wider business in support of Claranet’s mission building new and exciting services, enhancing, and improving existing service offerings, and delivering additional services within the Cyber Practice function. Role Mission Claranet UK’s strategy is to build long-term, trusted relationships with its customers by delivering market-leading, integrated managed services. We are seeking a … continued development of our market-leading portfolio designed to meet the growing and diverse needs of our customers. Objectives and Key Results The Security Consultant is part of the Cyber Practice. The key objectives and results will be to:• Successful delivery of customer GRC projects across the range of the Cyber Practice GRC services, in line with both … to help Claranet meet its vision Duties and Responsibilities All Security Consultants • Perform consultancy and audit/assessment activities during delivery of customer projects across the range of the Cyber Security GRC services, in line with both employee capabilities and business need• Interact professionally with customers across a variety of channels, ensuring timely progression of projects and the ongoing More ❯
compliant disposal of outdated technology. Perform routine patching, updates, and IT housekeeping to keep systems in optimal condition. Support implementation and ongoing compliance with security and management standards, currently CyberEssentials and CyberEssentials Plus. Knowledge and Experience 2+ years of experience in a support or technical analyst role. Experience supporting Microsoft Dynamics 365 applications. Exposure More ❯