Middlesbrough, North Yorkshire, North East, United Kingdom Hybrid / WFH Options
Reed Technology
proactive and detail-focused Compliance Analyst to support our information assurance and dataprotection efforts. This is a great opportunity for someone with a solid foundation in GDPR and data governance who's ready to take ownership of compliance processes and contribute to wider information security initiatives. You'll work closely with teams across IT, HR, and … practices meet legal and regulatory standards, while helping to embed a culture of privacy and security across the organisation. What You'll Be Doing Monitor and support compliance with GDPR and other dataprotection regulations. Conduct and document DataProtection Impact Assessments (DPIAs) for new systems and processes. Maintain and update the Register of Processing Activities … subject access requests (DSARs) and regulatory queries. What We're Looking For Experience in a compliance, dataprotection, or information governance role. Good working knowledge of GDPR and UK dataprotection laws. Familiarity with DPIAs , ROPA, and data classification frameworks. Understanding of basic information security principles. Strong communication and documentation skills. A collaborative approach More ❯
Middlesbrough, England, United Kingdom Hybrid / WFH Options
Reed Technology
proactive and detail-focused Compliance Analyst to support our information assurance and dataprotection efforts. This is a great opportunity for someone with a solid foundation in GDPR and data governance who's ready to take ownership of compliance processes and contribute to wider information security initiatives. You'll work closely with teams across IT, HR, and … practices meet legal and regulatory standards, while helping to embed a culture of privacy and security across the organisation. What You'll Be Doing Monitor and support compliance with GDPR and other dataprotection regulations. Conduct and document DataProtection Impact Assessments (DPIAs) for new systems and processes. Maintain and update the Register of Processing Activities … subject access requests (DSARs) and regulatory queries. What We're Looking For Experience in a compliance, dataprotection, or information governance role. Good working knowledge of GDPR and UK dataprotection laws. Familiarity with DPIAs , ROPA, and data classification frameworks. Understanding of basic information security principles. Strong communication and documentation skills. A collaborative approach More ❯
practices. Collaboration with Security Teams – Work with cybersecurity teams to ensure compliance with data security regulations. Regulatory Compliance & Auditing – Ensure DLP policies align with compliance frameworks such as GDPR, ISO 27001, and industry standards . Documentation & Reporting – Maintain detailed logs of DLP incidents, policies, security reports, and system configurations. Continuous Improvement – Research and implement new DLP solutions, techniques, and … Microsoft Purview DLP, Symantec DLP, Forcepoint DLP, or similar solutions. Incident Response & Troubleshooting – Ability to investigate security alerts, analyze logs, and resolve issues efficiently. Regulatory Compliance Knowledge – Understanding of GDPR, ISO 27001, and other industry standards related to data protection. Risk Assessment & Mitigation – Experience identifying data security risks and implementing necessary preventive measures. Technical Documentation & Reporting – Strong ability More ❯
practices. Collaboration with Security Teams – Work with cybersecurity teams to ensure compliance with data security regulations. Regulatory Compliance & Auditing – Ensure DLP policies align with compliance frameworks such as GDPR, ISO 27001, and industry standards . Documentation & Reporting – Maintain detailed logs of DLP incidents, policies, security reports, and system configurations. Continuous Improvement – Research and implement new DLP solutions, techniques, and … Microsoft Purview DLP, Symantec DLP, Forcepoint DLP, or similar solutions. Incident Response & Troubleshooting – Ability to investigate security alerts, analyze logs, and resolve issues efficiently. Regulatory Compliance Knowledge – Understanding of GDPR, ISO 27001, and other industry standards related to data protection. Risk Assessment & Mitigation – Experience identifying data security risks and implementing necessary preventive measures. Technical Documentation & Reporting – Strong ability More ❯
monitoring, detection, and response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. Oversee endpoint security, cloud network and API security for robust protection across all … Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign-On (SSO), and Privileged Access Management (PAM). Threat Management & Incident Response More ❯
Leadership Own and evolve our ISMS (Information Security Management System), ensuring it remains fit for purpose as we scale. Maintain and advance compliance across ISO 27001, SOC2, Cyber Essentials, GDPR, and any emerging frameworks (e.g. PCI DSS, AI governance), ensuring we are audit-ready. Identify, assess, and mitigate security risks across infrastructure, systems, and vendors - flagging and resolving vulnerabilities before … they become problems. Own security documentation, policies and access protocols, ensuring regular audits and updates. Lead on GDPR compliance (or arrange the appropriate support and tools) to manage data privacy obligations, including DSARs, DPIAs and risk assessments. Maintain a clear and up-to-date sub-processor list and lead on third-party risk management. Act as primary contact for … access reviews and alerting. Governance and Process Clarity Ensure security policies are clearly documented, visible, and adopted company-wide. Support the business in navigating legal and regulatory change (e.g. GDPR, international expansion, AI etc). Run awareness sessions, training and security onboarding to embed a culture of ownership and care. Partner with leadership to ensure policies align with the day More ❯
disaster recovery. Identify key risks and control weaknesses, providing practical and strategic recommendations for remediation. Evaluate compliance with internal policies, industry best practices, and regulatory requirements (e.g., FCA, PRA, GDPR, ISO 27001, PCI-DSS). Collaborate with business and IT stakeholders to understand operational processes and system architecture. Prepare detailed audit reports and present findings to senior management. Support external More ❯
OS . Knowledge of network perimeter security, including firewalls, WAF, anti-virus, and O365 compliance & security centre . Familiarity with NIST (CSF Framework 2.0), ISO 27001, PCI-DSS, and GDPR . Experience operating and managing SIEM solutions , vulnerability management tools, and secure configuration tooling. Ability to use PowerShell and Python scripting for security automation. Experience working in or with agile More ❯
/ Skills: Comprehensive Understanding of the Financial Services Industry : Wealth Management, Private Banking & Commercial Banking. While not essential, this knowledge is highly desirable. Familiarity with Financial Services Regulations : Including GDPR/DataProtection, Vulnerable Clients, and related compliance requirements. Experience with Fintech Systems : understanding or experience with Core Banking systems, client-facing banking platforms, investment platforms, and CRM More ❯
Group Technology) - Group IT Security. Stay up-to-date with the latest cybersecurity threats and trends and escalate risks promptly. Ensure compliance with relevant industry regulations and standards (e.g., GDPR and any other applicable to the IT). Evaluate GT s compliance with relevant regulatory standards (eg ISO 27001) as part of critical vendor performance assessment ensuring operational resilience is More ❯
in large, complex technology programmes involving multiple concurrent projects with significant experience of delivering through offshore / nearshore strategic vendors. Knowledge of security frameworks & standards (ISO 27001, NIST, CIS, GDPR, SOC 2) Be experienced in 'hands on' technology software delivery from initiation to implementation. Have knowledge of programme and project management methodology and managing full lifecycle of programmes from definition More ❯
Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
LA International Computer Consultants Ltd
are taken to block further attacks. 5. Compliance and Risk Management: o Ensure all incident response activities align with industry standards, regulations, and best practices (e.g., NIST, ISO 27001, GDPR, HIPAA). o Work with legal and compliance teams to manage incidents within the scope of data privacy laws and regulations. Key Skills & Experience: o Proficient in incident response More ❯
At Tombola, we take security seriously - but we also like to have a bit of fun while we're at it! As our Cloud Security Engineer, you'll be building on our existing operational security, with a special focus on More ❯
or similar). Experience with monitoring tools (SolarWinds SentryOne, Zabbix etc.). Excellent problem-solving, communication, and documentation skills. Some familiarity with financial services regulations and compliance (PCI DSS, GDPR, DORA) would be useful. Desirable / bonus skills and experience: Some interest in learning and using automation tools such as Azure DevOps, Terraform, Node-Red, Packer. Scripting and automation skills More ❯
IRAP controls. Strong understanding of network protocols & practices, firewalls, intrusion detection / prevention systems and WAFs. Knowledge of security compliance standards relevant to the SaaS industry, such as PCI, GDPR, ISO 27001, SOC2, NIST. Experience of external penetration testing scopes. Experience securing code reviews and security approvals Experience in Cryptography management & enhancements We value teamwork, collaboration & technical excellence – the company More ❯
Central London, London, England, United Kingdom Hybrid / WFH Options
Bupa UK
solutions.• Strong understanding of zero-trust networking and platforms like Palo Alto Prisma.• Experience with Microsoft Azure and Google Cloud Platform networking.• Familiarity with compliance frameworks such as HIPAA, GDPR, NIST, and ISO 27001.• A data-driven mindset with a focus on user experience and operational excellence.• Experience working in a product-centric model, embedding DevSecOps and SRE principles. More ❯
Central London, London, England, United Kingdom Hybrid / WFH Options
hireful
IRAP controls. Strong understanding of network protocols & practices, firewalls, intrusion detection / prevention systems and WAFs. Knowledge of security compliance standards relevant to the SaaS industry, such as PCI, GDPR, ISO 27001, SOC2, NIST. Experience of external penetration testing scopes. Experience securing code reviews and security approvals Experience in Cryptography management & enhancements We value teamwork, collaboration & technical excellence – the company More ❯
GCP is a plus Solid understanding of SaaS platforms and their identity integration Understanding of Zero Trust Architecture principles Familiarity with IT security frameworks and compliance standards (e.g., NIST, GDPR, SOC 2, PCI DSS, HIPAA) Awareness of logging, monitoring, and alerting practices related to identity and access events Basic understanding of email security and DNS Backup and recovery awareness for More ❯
and knowledge sharing Contribute to business development by producing high-quality proposals and identifying growth opportunities Skills & Experience Extensive expertise in threat intelligence, risk management, incident response, compliance (e.g. GDPR, ISO 27001), and security architecture? Proficiency with tools such as Rapid7 InsightIDR / InsightVM, SentinelOne, Fortinet, Netskope, SOAR automation (Rapid7 InsightConnect), and cloud security (AWS / CNAPP)? Proven experience leading More ❯
and skills needed Bachelor's degree in Information Technology, Business Administration, Risk Management, or a related field. Basic understanding of GRC concepts and frameworks (e.g., ISO 27001, NIST, SOX, GDPR). Strong analytical and problem-solving skills. Project management and business analyst skills. Excellent written and verbal communication skills. Ability to work collaboratively in a team environment. Detail-oriented with More ❯
Newcastle Upon Tyne, United Kingdom Hybrid / WFH Options
NHS Business Services Authority
Strong understanding of ethical principles, including privacy, fairness, transparency, and accountability Awareness of the legislation applicable in this area, such as GeneralDataProtectionRegulation (GDPR), the DataProtection Act (DPA), Freedom of Information, Caldicott Principles, equality and other statutory legislation Good appreciation of the benefits and risks in the use of analytical, AI More ❯
trust data platform to support production services, including dashboards, new product delivery, analytics and data science development Comfortable working to high standards of compliance (inc ISO-27001, GDPR), Data Governance, and Information Security Experienced in migrating from SQL based data architectures to modern Data Engineering technologies, using PySpark, Databricks, Terraform, and Pandas Someone able to More ❯
database for future roles for up to 12 months. Here's a link to our privacy policy . In this policy, you will find information about our compliance with GDPR (dataprotection law.) You can find how to send us a request to let you access your data that we have collected, request us to delete your More ❯
and code assurance Demonstrable experience of working within Agile Delivery projects An understanding of data formats for ingest, transformation and analytics, data security, access control and authorisation, GDPR, data privacy, and information security Awareness of data models in a Medalion Architecture Experience building Semantic, Metric or Analytic models Experience of building Machine Learning models Any experience More ❯