Reading, England, United Kingdom Hybrid / WFH Options
Infoplus Technologies UK Limited
workflows, timelines, and action items for continuous improvement. Compliance and Risk Management: Ensure all incident response activities align with industry standards, regulations, and best practices (e.g., NIST, ISO 27001, GDPR, HIPAA). Work with legal and compliance teams to manage incidents within the scope of data privacy laws and regulations. Key skills / knowledge / experience: Bachelor's degree More ❯
Collaborate with IT and business units to ensure secure systems development and operations. Compliance & Risk Management Ensure compliance with regulatory and legal security requirements (e.g., ISO 27001, NIST, HIPAA, GDPR, SOX, etc.). Ensure compliance with applicable dataprotection laws (e.g., GDPR, CCPA, GLBA). Guide DataProtection Impact Assessments (DPIAs) for high-risk financial data … with data analytics platforms and financial data governance tooling. Strong working knowledge of financial compliance frameworks (e.g., GLBA, SOX, FFIEC CAT, NYDFS). Familiarity with privacy regulations (GDPR, CCPA) and best practices in data governance. Certifications such as CISSP, CISM, CISA, CRISC, or Certified DataProtection Officer (CDPO) are highly desirable. We offer a collaborative More ❯
Reading, England, United Kingdom Hybrid / WFH Options
Focus on SAP
Position: SOC Tier 3 Analyst Employment Type: Contract, Full time Start: ASAP Location: Reading – Hybrid Languages: English We are seeking an experienced and highly capable SOC Tier 3 Analyst to serve as a senior member of our Security Operations Center More ❯
Milton Keynes, Buckinghamshire, South East, United Kingdom Hybrid / WFH Options
In Technology Group Limited
Investigate and document security breaches, providing root cause analysis and remediation plans. Conduct security awareness training for staff and ensure compliance with internal policies and regulatory requirements (e.g., FCA, GDPR, ISO 27001). Stay up to date with the latest security technologies, trends, and threat intelligence. Essential Skills & Qualifications: Proven experience in a cyber security or information security engineering role. More ❯
procedures. Manage cybersecurity projects to ensure timely delivery within budget. Perform or coordinate security assessments, penetration tests, and vulnerability scans. Ensure compliance with frameworks like COBIT, NIST, ISO, PCI, GDPR, HIPAA, etc. Provide internal support for security issues within SLAs. Evaluate and implement CIS controls as needed. Contribute to cybersecurity strategic planning and budgeting. Follow change management policies. Qualifications Bachelor More ❯
Altrincham, England, United Kingdom Hybrid / WFH Options
Heywood
and best practices, particularly in AWS Experience in managing security incidents and leading incident response Excellent knowledge of security frameworks, standards, and regulations, including ISO 27001, SOC 2, HIPAA, GDPR, etc. Good communication and interpersonal skills, with the ability to effectively communicate security-related questions to technical and non-technical stakeholders (employees, customers, and / or partners) Project management skills More ❯
functional teams to design, implement, and maintain security controls and configurations across various systems and platforms. Oversight of compliance for regulatory compliance requirements, such as SOC2, HIPAA, ISO 27001, GDPR etc., and ensure our systems adhere to these standards. Stay updated with the latest industry trends, emerging threats, and security technologies to proactively identify and address potential risks. Conduct security More ❯
Nottingham, Nottinghamshire, United Kingdom Hybrid / WFH Options
Experian Group
internal audit methodologies, including risk assessment, execution, and reporting. Proficiency in industry standards and frameworks (e.g., NIST 800-53, ISO 27001 / 27002). Familiarity with privacy regulations (e.g., GDPR, CCPA) and breach notification laws. Experience with sector-specific frameworks (e.g., HIPAA, PCI). Technical Skills Proficiency with security tools (SailPoint, Rapid7, Wiz.io , MS Defender, SIEM, vulnerability management, penetration testing More ❯
Loughton, Essex, South East, United Kingdom Hybrid / WFH Options
Profile 29
employment status. If you are utilising a work visa this must allow you to work in the UK unrestricted for at least the next 5 years. In accordance with GDPR by applying you give Profile 29 consent to use your data for recruitment purposes only (details of Profile 29s privacy policy can be found at: profile-29 .com /More ❯
Loughton, England, United Kingdom Hybrid / WFH Options
Profile 29
employment status. If you are utilising a work visa this must allow you to work in the UK unrestricted for at least the next 5 years. In accordance with GDPR by applying you give Profile 29 consent to use your data for recruitment purposes only (details of Profile 29s privacy policy can be found at: profile-29 .com /More ❯
or Fintech environment. Educated to degree level in a relevant subject and / or hold a technology professional qualification. Deep technical knowledge of technology related regulation (e.g., DORA, GDPR, EU AI Act). Experience with third-party and outsourcing risk, AI and digital transformation risks. Experience of developing and operating Technology Risk Management Frameworks such as ITIL, COBIT More ❯
Southampton, Hampshire, United Kingdom Hybrid / WFH Options
Aztec
or Fintech environment. Educated to degree level in a relevant subject and / or hold a technology professional qualification. Deep technical knowledge of technology related regulation (e.g., DORA, GDPR, EU AI Act). Experience with third-party and outsourcing risk, AI and digital transformation risks. Experience of developing and operating Technology Risk Management Frameworks such as ITIL, COBIT More ❯
London, England, United Kingdom Hybrid / WFH Options
McCabe & Barton
engagement skills. Financial services / FCA experience Desirable: Experience with Microsoft Azure Security tools (Defender for Endpoint, Sentinel, Purview). Understanding of ITIL, dataprotection laws (UK GDPR), and payment card security. Security certifications such as CISSP, CISM, CISMP or equivalent. More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Deloitte LLP
implement secure and scalable digital solutions Strong communication and stakeholder management skills Experience in leading and mentoring technical teams Knowledge of data privacy and protection regulations (e.g. GDPR) Understanding of enterprise architecture frameworks (e.g. TOGAF) Familiarity with agile and DevOps practices in a public sector context Proficiency in event-driven architecture and its application in digital solutions Proven More ❯
Newcastle Upon Tyne, Tyne And Wear, United Kingdom Hybrid / WFH Options
Deloitte LLP
implement secure and scalable digital solutions Strong communication and stakeholder management skills Experience in leading and mentoring technical teams Knowledge of data privacy and protection regulations (e.g. GDPR) Understanding of enterprise architecture frameworks (e.g. TOGAF) Familiarity with agile and DevOps practices in a public sector context Proficiency in event-driven architecture and its application in digital solutions Proven More ❯
Southampton, Hampshire, United Kingdom Hybrid / WFH Options
NICE
all about? The Information Security Analyst is primarily responsible for ensuring compliance with information security frameworks such as Cyber Essentials, Cyber Essentials Plus, ISO 27001, ISO 27701, ISO 42001, GDPR, and DORA. This role focuses on internal audits, regulatory compliance, and readiness for external audits while also contributing to Cybersecurity Operations Center (CSOC) activities, including incident monitoring and response. How … in scoping appropriate evidence and preparing for external audits. Gap Assessments: Facilitate and / or conduct internal gap assessments and audit readiness evaluations for frameworks such as ISO 27001, GDPR, and DORA. Framework Tracking: Monitor updates to Cyber Essentials, ISO, and regulatory frameworks and ensure internal alignment. Control Documentation: Develop and maintain control narratives, walkthroughs, and documentation of compliance processes. … vulnerabilities in coordination with IT and Security Operations teams. Have you got what it takes? Strong expertise in audit and compliance frameworks, including ISO 27001, ISO 27701, ISO 42001, GDPR, DORA, Cyber Essentials, and Cyber Essentials Plus. Familiarity with CSOC tools such as Rapid7 InsightIDR or other SIEM solutions. Hands-on experience in internal and external audits, compliance assessments, and More ❯
testing activities acrossIT operations, systems, and processes, including: - Cybersecurity controls (e.g., firewalls, encryption, accessmanagement). - Cloud computing controls (e.g., AWS, Azure, GoogleCloud). - Dataprotection controls (e.g., GDPR compliance, databackups). - Incident management processes and disaster recoverytesting. Test both the design and operating effectiveness of ITcontrols. Prioritise control testing activities based on risk assessments, focusing on high-risk More ❯
Basingstoke, Hampshire, United Kingdom Hybrid / WFH Options
InstaVolt
external vendors, MSPs, and technology partners to ensure cost-effective and reliable service delivery. Collaborate with InfoSec and Legal teams to ensure compliance with relevant regulations (e.g., ISO 27001, GDPR). Lead incident response and disaster recovery planning / testing for internal platforms and operational IT. Requirements Needed: Bachelor's degree in information technology, Computer Science, or related experience. 10+ More ❯
City of London, London, United Kingdom Hybrid / WFH Options
FairPlay Sports Media
comprehensive and accurate SCV, enabling a holistic understanding of our customers. Data Governance & Compliance: Ensure data quality, accuracy, and compliance with relevant data privacy regulations (e.g., GDPR) within the CDP and SCV. Implement and maintain data governance policies and procedures. Internal Product Integration: Define how data from the CDP / SCV can be integrated into … experience with Google Cloud Platform (GCP) and BigQuery. Experience with data visualization tools, particularly Power BI. Strong understanding of API integrations. Solid understanding of data privacy regulations (GDPR and other data capture regulations). Stakeholder Management: Proven ability to effectively manage and influence stakeholders across different departments and levels of seniority. Communication Skills: Excellent written and verbal More ❯
comprehensive and accurate SCV, enabling a holistic understanding of our customers. Data Governance & Compliance: Ensure data quality, accuracy, and compliance with relevant data privacy regulations (e.g., GDPR) within the CDP and SCV. Implement and maintain data governance policies and procedures. Internal Product Integration: Define how data from the CDP / SCV can be integrated into … experience with Google Cloud Platform (GCP) and BigQuery. Experience with data visualization tools, particularly Power BI. Strong understanding of API integrations. Solid understanding of data privacy regulations (GDPR and other data capture regulations). Stakeholder Management: Proven ability to effectively manage and influence stakeholders across different departments and levels of seniority. Communication Skills: Excellent written and verbal More ❯
implementation of designed solutions, ensuring adherence to the architecture and best practices. Security and Compliance : Ensure that all solutions comply with internal security standards and relevant regulatory requirements (eg, GDPR, HIPAA), including data privacy, security, and disaster recovery considerations. Qualifications Experience : Proven experience designing complex enterprise-level solutions across multiple platforms and technologies. Demonstrated expertise in architecting cloud-based More ❯
Leadership Own and evolve our ISMS (Information Security Management System), ensuring it remains fit for purpose as we scale. Maintain and advance compliance across ISO 27001, SOC2, Cyber Essentials, GDPR, and any emerging frameworks (e.g. PCI DSS, AI governance), ensuring we are audit-ready. Identify, assess, and mitigate security risks across infrastructure, systems, and vendors - flagging and resolving vulnerabilities before … they become problems. Own security documentation, policies and access protocols, ensuring regular audits and updates. Lead on GDPR compliance (or arrange the appropriate support and tools) to manage data privacy obligations, including DSARs, DPIAs and risk assessments. Maintain a clear and up-to-date sub-processor list and lead on third-party risk management. Act as primary contact for … access reviews and alerting. Governance and Process Clarity Ensure security policies are clearly documented, visible, and adopted company-wide. Support the business in navigating legal and regulatory change (e.g. GDPR, international expansion, AI etc). Run awareness sessions, training and security onboarding to embed a culture of ownership and care. Partner with leadership to ensure policies align with the day More ❯