in revenue, and supports more than 60,000 clients across a diverse range of sectors and markets. Role Purpose: An Information Security Officer (ISO) is required to support LRQA's global operations, to develop, improve and maintain the organisation's Information Security capability. Working closely with the Global … opportunities for improvement and facilitating development of pragmatic solutions. Working with the DPO to ensure appropriate security is applied to data and provide reports / subject access requests. Designing and delivering continual education and training to our colleagues to support them in identifying risks in their day-to-day … environment is a plus. Technical / Professional Qualification requirements: Proven experience in Information Security Management and IT risk management. In-depth knowledge of ISO27001 to Lead Auditor standard. Knowledge of relevant regulations (Data Protection, DORA, NIS2). Knowledge of Three Lines of Defence Model and its application. Knowledge of More ❯
in revenue, and supports more than 60,000 clients across a diverse range of sectors and markets. Role Purpose: An Information Security Officer (ISO) is required to support LRQA's global operations, to develop, improve and maintain the organisation's Information Security capability. Working closely with the Global … opportunities for improvement and facilitate development of pragmatic solutions. Work with the DPO to ensure appropriate security is applied to data and provide reports / subject access requests. Design and deliver continual education and training to our colleagues to support them in identifying risks in their day-to-day … environment is a plus. Technical / Professional Qualification requirements: Proven experience in Information Security Management and IT risk management. In-depth knowledge of ISO27001 to Lead Auditor standard. Knowledge of relevant regulations (Data Protection, DORA, NIS2). Knowledge of Three Lines of Defence Model and its application. Knowledge of More ❯
requires the functional capability and proficiency to technically augment the team capabilities (when required) and have a detailed knowledge of technical IT support roles / services as a requirement, across multiple technical areas. Security, Compliance & Risk Management • Define and enforce cloud security policies, identity management, and access controls to … response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. • Ensure compliance with cloud security frameworks and regulatory requirements (ISO27001, NIST, GDPR, SOC2, FCA). • Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. • Oversee endpoint security … Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. • Security & Compliance: Deep knowledge of security frameworks (ISO27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. • Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access More ❯
requires the functional capability and proficiency to technically augment the team capabilities (when required) and have a detailed knowledge of technical IT support roles / services as a requirement, across multiple technical areas. Security, Compliance & Risk Management • Define and enforce cloud security policies, identity management, and access controls to … response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. • Ensure compliance with cloud security frameworks and regulatory requirements (ISO27001, NIST, GDPR, SOC2, FCA). • Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. • Oversee endpoint security … Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. • Security & Compliance: Deep knowledge of security frameworks (ISO27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. • Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access More ❯
Hertford, England, United Kingdom Hybrid / WFH Options
Zoocha
building out new creative, strategic and experience capabilities to complement our industry-leading Drupal design and build offering. We are looking for seasoned UX / CX and strategy practitioners to join the team and help us realise our vision and shape the future of experience design at a vibrant … application will be disregarded. Must-have skills and experience: Minimum of 5 years’ agency experience, you’ll currently be in a senior UX design / consultancy role and looking for your next step up Exceptional UX design craft paired with a strategic, consultative mindset Passionate about all things UX … studies Solid proficiency of analysing and interpreting data (e.g. GA4, Hotjar) and experience of conversion rate optimisation approaches and tools Significant experience creating UX / CX deliverables such as wireframes, prototypes, journey / experience maps, user flows, personas, information architecture etc. Experienced creating user stories and product backlogs More ❯
ideal Information Security Lead will be responsible for: Owning and leading the information security function, working collaboratively across all departments. Maintaining and evolving ISO27001 certification and managing the Information Security Management System (ISMS) lifecycle. Performing regular risk assessments, developing and managing remediation plans, and conducting … ideal Information Security Lead will have experience with the following: 3-5 years of hands-on experience in an information security or IT risk / compliance role. Proven experience working within a SaaS company or a fast-paced startup / scale-up environment. Strong working knowledge of ISO27001 and practical experience maintaining or achieving certification. A solid understanding of cloud environments (AWS preferred) and common security risks associated with SaaS platforms. Hands-on knowledge of security tooling, including endpoint protection, SIEMs, DLP, identity and access management (IAM), and SSO. A clear understanding of More ❯
ideal Information Security Lead will be responsible for: Owning and leading the information security function, working collaboratively across all departments. Maintaining and evolving ISO27001 certification and managing the Information Security Management System (ISMS) lifecycle. Performing regular risk assessments, developing and managing remediation plans, and conducting … ideal Information Security Lead will have experience with the following: 3-5 years of hands-on experience in an information security or IT risk / compliance role. Proven experience working within a SaaS company or a fast-paced startup / scale-up environment. Strong working knowledge of ISO27001 and practical experience maintaining or achieving certification. A solid understanding of cloud environments (AWS preferred) and common security risks associated with SaaS platforms. Hands-on knowledge of security tooling, including endpoint protection, SIEMs, DLP, identity and access management (IAM), and SSO. A clear understanding of More ❯
adherence to best practices, international standards, and local regulations. Ideally suited to candidates who possess expert knowledge of security frameworks including NIST 800, ISO27001, and cybersecurity guidelines from PRA, FCA, and ICO. Candidates with at least 3 years' relevant experience in finance or banking, particularly … ISO27001) and GDPR regulations. Experience with network security infrastructure and SIEM tools (Splunk, SolarWinds). Proficiency in Windows / Linux system administration and virtualization technologies (VMware, Hyper-V). Previous experience within the finance or banking sector is highly advantageous. Certifications (Desirable): CISA, CISSP More ❯
adherence to best practices, international standards, and local regulations. Ideally suited to candidates who possess expert knowledge of security frameworks including NIST 800, ISO27001, and cybersecurity guidelines from PRA, FCA, and ICO. Candidates with at least 3 years' relevant experience in finance or banking, particularly … ISO27001) and GDPR regulations. Experience with network security infrastructure and SIEM tools (Splunk, SolarWinds). Proficiency in Windows / Linux system administration and virtualization technologies (VMware, Hyper-V). Previous experience within the finance or banking sector is highly advantageous. Certifications (Desirable): CISA, CISSP More ❯
Stockport, Cheshire, United Kingdom Hybrid / WFH Options
zyncgroup.io
growth. Responsibilities: In this role, you'll help clients secure their cloud infrastructure by identifying threats, implementing protective controls, and aligning solutions with ISO27001 and other compliance frameworks. You'll be hands-on with security tooling, assess vulnerabilities, and work closely with DevOps teams to … audits, and document security strategies and findings in detailed technical reports. Essential skills: Solid experience with cloud security (AWS, Azure, or GCP) and CI / CD pipelines Familiarity with compliance standards like ISO27001 or NIST Background in consulting or engineering security solutions C1-level More ❯
change. Person specification Highly motivated self-starter Strong team player Engage and share knowledge with the team working towards the same goal Good verbal / written communication Strong ownership / responsibility over workload Good organisational skills and keen attention to detail Strong focus on customer satisfaction / … knowledge of Backup as a Service (BaaS) and Infrastructure as a Service (IaaS) Experience of SIEM, monitoring, logging, and reporting tools (e.g., Site 24x7 / N-Central) Familiarity with ISO:27001 and PCI DSS and experience in improving IT systems to adhere to security guidelines … acting proactively and reactively Experience with Active Directory / Azure Active Directory management and implementation Ability to write scripts to automate processes (e.g., PowerShell, Bash etc.) Experience working in a software development environment, with knowledge of CI / CD tools and processes, IIS, and application hosting environments Experience More ❯
Manchester Area, United Kingdom Hybrid / WFH Options
Maxwell Bond
change. Person specification Highly motivated self-starter Strong team player Engage and share knowledge with the team working towards the same goal Good verbal / written communication Strong ownership / responsibility over workload Good organisational skills and keen attention to detail Strong focus on customer satisfaction / … knowledge of Backup as a Service (BaaS) and Infrastructure as a Service (IaaS) Experience of SIEM, monitoring, logging, and reporting tools (e.g., Site 24x7 / N-Central) Familiarity with ISO:27001 and PCI DSS and experience in improving IT systems to adhere to security guidelines … acting proactively and reactively Experience with Active Directory / Azure Active Directory management and implementation Ability to write scripts to automate processes (e.g., PowerShell, Bash etc.) Experience working in a software development environment, with knowledge of CI / CD tools and processes, IIS, and application hosting environments Experience More ❯
Services: Drive the delivery of services including Threat & Vulnerability Management, Privileged Access Management, IAM, DLP, Network Security, and Penetration Testing. Project Leadership: Lead IT / Cybersecurity improvement projects as an SME. Risk & Compliance: Evaluate IT changes for security risks, ensuring compliance with security policies and frameworks like ISO27001/ NIST. Security Controls: Operate and manage security controls to protect IT systems, ensuring alignment with regulatory and industry best practices. Continuous Improvement: Recommend and implement new technologies and practices to improve security posture. Required Skills & Experience: Security Expertise: Extensive experience in IT /More ❯
company events to enhance team engagement and morale. HR: Oversee HR-related functions, acting as the key liaison between the business and our outsourced / group HR team for all internal matters. Essential experience and skills: A minimum of 2 years' experience in a similar role / environment. … leadership, communication, and problem-solving skills. Ability to work in a fast-paced environment and adapt to challenges. Financial acumen and experience managing budgets / forecasts. Excellent organisational and decision-making abilities. Availability to commit to the full maternity cover period. Previous experience in a B2B IT-related industry. … Technical Knowledge: Familiarity with Xero, finance systems, HR management systems, ConnectWise PSA (desirable) Qualifications: Business Management / Operations Management or a related field degree Professional qualifications (desirable but not mandatory) ISO27001 knowledge (desirable) Equivalent experience and knowledge This role is suitable for someone who More ❯
least 2 years of hands-on experience in information security or IT infrastructure within an enterprise environment. Familiarity with security standards such as ISO27001, Cyber Essentials, GDPR, and Data Protection Act. Experience with Microsoft O365 Security solutions and network security operations. Understanding of security testing … Consultant, IT Security Consultant, Cybersecurity Specialist, Microsoft O365 Security, Enterprise Security Jobs, Information Security Leeds, IT Risk Management, Security Incident Response, Vulnerability Management, ISO27001, GDPR Compliance, Security Awareness, Disaster Recovery and Business Continuity. More ❯
Ely, Cambridgeshire, East Anglia, United Kingdom Hybrid / WFH Options
IT Governance Limited, a GRC Solutions Company
with clients of all merchant levels and service providers across various industries. Career Growth: Enhance your expertise with exposure to frameworks like PCI DSS, ISO27001, SWIFT CSF, and CIS18. Collaborative Culture: Join a team that values innovation, client success, and your professional development. Key Responsibilities: Conducting comprehensive security assessments, including … PCI DSS, ISO27001/ 27002, SWIFT Security, and Cloud compliance. Preparing executive and technical reports detailing findings, security gaps, and actionable recommendations. Leading PCI DSS Gap Assessments, Risk Assessments, and Reports on Compliance (ROCs) across various industries. Creating roadmaps for compliance, with prioritised remediation steps and timelines. Communicating effectively … for an experienced and proactive QSA Consultant with: Essential: PCI QSA certification, supported by one or more of the following: CISSP, CISA, CISM, or ISO27001 Lead Auditor + Lead Implementer certifications. Experience: Minimum 2 years in cybersecurity, with strong technical knowledge to conduct complex security assessments. Familiarity with technologies such More ❯
Warrington, England, United Kingdom Hybrid / WFH Options
Iron Mountain
of the Programme Management Office you will work very closely with the Operations to provide support in areas such as User Acceptance Testing, application / solution development, compliance, security and other support activities required to deliver the innovation strategy. As part of the innovation strategy, you should always be … looking out for alternate solutions (which include software and hardware / tech) for current and future projects to enhance the product offering or reduce cost. Your role in our mission: User acceptance testing of new and upgraded IT platforms and applications Service introduction support for new services, applications and … organisational, and time management skills. Awareness of data security and compliance. Understanding of continuous improvement methodologies. Reporting Experience in an operations environment and project / user testing. Experience of working in a highly controlled and secure environment Web Development Database design and maintenance System design and development Experience creating More ❯
minimum of 2 years in an infrastructure, SysOps or Security role; Active Directory management; NTFS permission & Group Policy configuration & management; Microsoft RDS Architecture (RemoteApp / RDWeb Gateway / RDS Broker); Virtual Windows 2016 DC Servers / File Server with SMB file shares; Site-to-Site VPN configuration … external PEN testing; Analytical skills in monitoring, evaluating and reporting on risk scenarios; Strong report-writing skills both for policy management and for Team / Board reporting purposes; Communication skills: confidence and clarity in giving direction on information risk issues; ability to engage across all levels of the business … interest in pursuing an Information Security specialism. Desirable: IaaS and PaaS environments; SQL; VMWare Cloud Director; SharePoint; Windows IIS security & management; Security & GDPR compliance (ISO27001/ ISO27032 / SOC 2); AWS ecosystem, especially AppStream 2.0. More ❯
Platform Engineering Manager with us. Responsibilities include: Platform Strategy & Governance Define and implement a self-service infrastructure approach for software development teams. Oversee CI / CD governance, ensuring reliable, automated software deployments while reducing operational overhead. Set standards for Infrastructure as Code (IaC) governance, ensuring consistency and compliance. Cloud … operations. Provide strategic direction for hybrid, multi-cloud architecture (AWS, Azure, on-premises). Security, Compliance & Risk Management Ensure platform security aligns with ISO27001, NIST, and GDPR compliance. Embed security-first principles into platform governance and DevOps processes. Leadership, Collaboration & Stakeholder Management Lead and mentor … that empower engineering teams. Essential Skills Bachelor's or Master's degree in Computer Science, Engineering, or a related field. Azure Solutions Architect Expert / AWS Certified Solutions Architect (Professional) Desirable. Certified Kubernetes Administrator (CKA) or equivalent (Desirable). ITIL, CISSP, or ISO27001 Lead More ❯
Kemsing, Kent, United Kingdom Hybrid / WFH Options
Bowerford Associates
We are searching for a detail-oriented and experienced part-time Compliance Officer to support and maintain compliance frameworks across ISO 9001 (Quality Management), ISO 14001 (Environmental Management) and ISO27001 (Information Security Management). The role is critical in ensuring our … remote position with office visits circa 2 or 3 times per month and during audit periods. Key Responsibilities: Monitor and maintain compliance with ISO 9001, 14001 and 27001 standards … Conduct internal audits and support external audit preparations Maintain documentation, records, and procedures as per ISO requirements Support risk assessments and corrective / preventive actions (CAPA) Collaborate with teams to ensure ongoing adherence to environmental, quality, and information security policies Assist in staff training and awareness programs More ❯
technical experience in infrastructure design, build, and deployment, including private and public cloud, networking, connectivity, storage, and virtualization Strong technical experience of the Microsoft / Azure ecosystem (Networking / solutions, Monitor, Licensing / Cost Management, IaaS / PaaS services) and Infrastructure as Code Experience working with … Azure technologies such as virtual machines, Cloud Services, web apps, function apps, Azure Active Directory, Virtual Networks, etc. Creating and managing CI / CD pipelines using tools such as Azure DevOps, Octopus Deploy, and Terraform to deploy both infrastructure and applications Experience in managing both project and operational change … including estimating, resource allocation, status reporting, and cost management Experience in modernizing / migrating existing systems to cloud-based serverless architecture Well-versed in Windows Operating Systems and Active Directory domain services Experienced in the use of Azure platform services, PowerShell / Azure PowerShell, and the Azure Portal More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
Ignite Digital Search Limited
vital role in safeguarding our cloud infrastructure and applications. - If you have expertise in AWS security, a strong understanding of security frameworks like ISO or NIST, and the ability to drive secure coding practices, we want to hear from you! The role. As an Application Security Engineer, you … such as ISO27001, NIST, and CIS benchmarks. Collaborate with development teams to enhance secure coding practices and strengthen CI / CD pipeline security. Oversee and improve cloud security in AWS, leveraging tools such as AWS Security Hub, AWS Shield, and AWS IAM. Manage the … Familiarity with OWASP Top 10, CWE, and secure coding practices. Proficiency in using security tools such as static and dynamic analysis tools. Basic coding / scripting skills in Python, JavaScript, or similar. Strong communication skills with the ability to engage technical and non-technical stakeholders. Desirable Skills: Experience working More ❯
assurance, and oversight Ability to influence stakeholders and communicate effectively at all levels, including non-technical audiences Knowledge of security frameworks such as ISO27001, NIST, or similar Experience identifying control gaps and working across functions to address them Comfortable working in a collaborative, solutions-focused … environment Sector background is flexible – consulting, commercial, or industry experience welcome Relevant certifications (CISM, CISSP, CRISC, ISO27001 Lead Auditor) are a plus, but not required This role it's a great fit for someone who understands information security frameworks, knows how to translate technical risks More ❯
assurance, and oversight Ability to influence stakeholders and communicate effectively at all levels, including non-technical audiences Knowledge of security frameworks such as ISO27001, NIST, or similar Experience identifying control gaps and working across functions to address them Comfortable working in a collaborative, solutions-focused … environment Sector background is flexible – consulting, commercial, or industry experience welcome Relevant certifications (CISM, CISSP, CRISC, ISO27001 Lead Auditor) are a plus, but not required This role it's a great fit for someone who understands information security frameworks, knows how to translate technical risks More ❯