tools (GuardDuty, CloudTrail, Config, WAF). Proficiency in CloudFormation, Terraform, and scripting languages like Python or Bash. Knowledge of compliance standards (SOC 2, ISO27001, GDPR, PCI-DSS) and experience ensuring compliance in AWS environments. Experience with security incident response, monitoring, and post-incident remediation. Ability More ❯
needed Bachelor's degree in Information Technology, Business Administration, Risk Management, or a related field. Basic understanding of GRC concepts and frameworks (e.g., ISO27001, NIST, SOX, GDPR). Strong analytical and problem-solving skills. Project management and business analyst skills. Excellent written and verbal communication More ❯
expertise. Ability to optimize operational costs while maintaining service quality. Regulatory & Compliance Expertise Knowledge of security industry regulations, standards, and best practices, including: ISO27001 (Information Security) GDPR (for data privacy in surveillance) CPNI (Centre for the Protection of National Infrastructure) guidelines Local and international security More ❯
About the Job We are seeking a Product Security Specialist with expertise in connected / IoT medical devices or healthcare products to join our team. The ideal candidate will work with clients to advise and shape the overall security strategy for products, ensure secure design, development, and deployment across … testing, threat modeling, security testing) and evaluate residual risks with compensating controls. Solid experience in applying and proving compliance with frameworks like NIST, IEC, HITRUST, HIPAA, GDPR, ISO27001, SOC 2 Type 2, as well as working with Quality Management Systems (QMS). Strong More ❯
About the Job We are seeking a Product Security Specialist with expertise in connected / IoT medical devices or healthcare products to join our team. The ideal candidate will work with clients to advise and shape the overall security strategy for products, ensure secure design, development, and deployment across … testing, threat modeling, security testing) and evaluate residual risks with compensating controls. Solid experience in applying and proving compliance with frameworks like NIST, IEC, HITRUST, HIPAA, GDPR, ISO27001, SOC 2 Type 2, as well as working with Quality Management Systems (QMS). Strong More ❯
Cambridge, England, United Kingdom Hybrid / WFH Options
Client Server
Backend Software Engineer / Developer (Java Spring API Security) Cambridge / WFH to £55k Are you a backend focussed Java technologist looking for an opportunity to progress your career whilst working on complex and interesting systems with continual learning opportunities? You could be joining a market leading software … stack. There are challenges around scalability and robustness, you'll be continually learning and progressing your career within a supportive Agile team environment. Location / WFH: There's a friendly and supportive team environment, you'll be able to work from home most of the time, meeting up with … strong knowledge of Computer Science fundamentals such as OOP, Design Patterns, Data Structures You have a good understanding of networking technologies, protocols e.g. TCP / IP, UDP, multicast and security principles You have an appreciation of security and ideally have worked in an ISO27001More ❯
cambridge, east anglia, United Kingdom Hybrid / WFH Options
Client Server
Backend Software Engineer / Developer (Java Spring API Security) Cambridge / WFH to £55k Are you a backend focussed Java technologist looking for an opportunity to progress your career whilst working on complex and interesting systems with continual learning opportunities? You could be joining a market leading software … stack. There are challenges around scalability and robustness, you'll be continually learning and progressing your career within a supportive Agile team environment. Location / WFH: There's a friendly and supportive team environment, you'll be able to work from home most of the time, meeting up with … strong knowledge of Computer Science fundamentals such as OOP, Design Patterns, Data Structures You have a good understanding of networking technologies, protocols e.g. TCP / IP, UDP, multicast and security principles You have an appreciation of security and ideally have worked in an ISO27001More ❯
Cambridge, south west england, United Kingdom Hybrid / WFH Options
Client Server
Backend Software Engineer / Developer (Java Spring API Security) Cambridge / WFH to £55k Are you a backend focussed Java technologist looking for an opportunity to progress your career whilst working on complex and interesting systems with continual learning opportunities? You could be joining a market leading software … stack. There are challenges around scalability and robustness, you'll be continually learning and progressing your career within a supportive Agile team environment. Location / WFH: There's a friendly and supportive team environment, you'll be able to work from home most of the time, meeting up with … strong knowledge of Computer Science fundamentals such as OOP, Design Patterns, Data Structures You have a good understanding of networking technologies, protocols e.g. TCP / IP, UDP, multicast and security principles You have an appreciation of security and ideally have worked in an ISO27001More ❯
IT Internal Controls Manager Permanent Based in Solihull (Hybrid with 2 / 3 days in the office and the rest at home). Will also consider London based. We are looking for an experienced IT Internal Controls Manager to join our friendly and dynamic team here at Waterstones and … and requirements. In-depth knowledge of the ICFR Standards (US SOX, UK Corporate Governance Code) Strong awareness of IT control frameworks (e.g. COBIT, ISO27001, NIST) and regulatory requirements (e.g. GDPR, ISO, ITIL). Experience with Systems transformation projects and an ability to embed More ❯
IT Internal Controls Manager Permanent Based in Solihull (Hybrid with 2 / 3 days in the office and the rest at home). Will also consider London based. We are looking for an experienced IT Internal Controls Manager to join our friendly and dynamic team here at Waterstones and … and requirements. In-depth knowledge of the ICFR Standards (US SOX, UK Corporate Governance Code) Strong awareness of IT control frameworks (e.g. COBIT, ISO27001, NIST) and regulatory requirements (e.g. GDPR, ISO, ITIL). Experience with Systems transformation projects and an ability to embed More ❯
and standardised tools that support long-term business needs. Cybersecurity Oversight: Develop and implement a cybersecurity strategy aligned with industry best practices (e.g., ISO27001, NIST). Protect company systems and data through robust policies, security tools, and continuous monitoring. Device & Endpoint Management : Oversee the full … work and global operations. IT Support & Service Delivery: Establish a scalable and responsive global IT support model, including ticketing systems, SLAs, and standardised onboarding / offboarding processes. Collaboration Tools & Intranet: Lead the implementation and management of internal collaboration tools, including the development of an intranet or SharePoint environment to More ❯
and standardised tools that support long-term business needs. Cybersecurity Oversight: Develop and implement a cybersecurity strategy aligned with industry best practices (e.g., ISO27001, NIST). Protect company systems and data through robust policies, security tools, and continuous monitoring. Device & Endpoint Management : Oversee the full … work and global operations. IT Support & Service Delivery: Establish a scalable and responsive global IT support model, including ticketing systems, SLAs, and standardised onboarding / offboarding processes. Collaboration Tools & Intranet: Lead the implementation and management of internal collaboration tools, including the development of an intranet or SharePoint environment to More ❯
london, south east england, United Kingdom Hybrid / WFH Options
Quinbrook Infrastructure Partners
and standardised tools that support long-term business needs. Cybersecurity Oversight: Develop and implement a cybersecurity strategy aligned with industry best practices (e.g., ISO27001, NIST). Protect company systems and data through robust policies, security tools, and continuous monitoring. Device & Endpoint Management : Oversee the full … work and global operations. IT Support & Service Delivery: Establish a scalable and responsive global IT support model, including ticketing systems, SLAs, and standardised onboarding / offboarding processes. Collaboration Tools & Intranet: Lead the implementation and management of internal collaboration tools, including the development of an intranet or SharePoint environment to More ❯
have knowledge of security standards and processes such as ISO27001 standards, (NCSC) CAF, Cyber Essentials, NIST, and Cyber Essentials / Plus. We'll also look for your experience in: Developing cyber policy and procedures Data protection and privacy Security change management Understanding business continuity More ❯
periodic reviews (musters) and conduct spot checks of classified assets Maintain company security documents, asset registers, risk registers, and reports Protectively Marked Material Management / Mustering (PPM) and secure disposal of assets Logging in / out of assets, movement / transport plans, liaising with the authority Maintain … management Advising management on the interpretation and implementation of contractual and legislative security controls. Conduct and administrate internal security audits and address observations and / or non-conformances relating to protective security following an audit Conduct and administrate supply chain security audits and address observations and / or … non-conformances relating to protective security following an audit Update and maintain the ISO27001 ISMS and other security accreditation documents Update and maintain the site risk register Identify new risks, determine mitigations and implement suitable controls and measures Arranging for appropriate security education and awareness More ❯
ideally in financial services or highly regulated environments. Proven capability in third-party risk management, client due diligence, and compliance framework s (NIST, ISO27001, DORA, etc.). Experience in managing audits and regulatory engagements across multiple jurisdictions. Excellent communication skills – able to translate complex technical … managed across a major financial institution. If you would like to discuss this role in confidence reach out to Javed Hussain 0208 142 3930 / javed.hussain@marlinselection.com More ❯
ideally in financial services or highly regulated environments. Proven capability in third-party risk management, client due diligence, and compliance framework s (NIST, ISO27001, DORA, etc.). Experience in managing audits and regulatory engagements across multiple jurisdictions. Excellent communication skills – able to translate complex technical … managed across a major financial institution. If you would like to discuss this role in confidence reach out to Javed Hussain 0208 142 3930 / javed.hussain@marlinselection.com More ❯
ideally in financial services or highly regulated environments. Proven capability in third-party risk management, client due diligence, and compliance framework s (NIST, ISO27001, DORA, etc.). Experience in managing audits and regulatory engagements across multiple jurisdictions. Excellent communication skills – able to translate complex technical … managed across a major financial institution. If you would like to discuss this role in confidence reach out to Javed Hussain 0208 142 3930 / javed.hussain@marlinselection.com More ❯
principles and the unique challenges posed by AI technologies. What you'll be doing: AI Security Architecture: Design and implement secure architectures for AI / ML models, data pipelines, and related infrastructure. Develop security policies and procedures specific to AI systems. Evaluate and select security tools and technologies for … Communicate security risks and recommendations effectively to both technical and non-technical audiences. What experience you'll bring: 7+ Years experience in a Cyber / Information Security Role. Hold a current and relevant Security Certifications (e.g., CISSP, CISM). Extensive knowledge of security best practices, frameworks, and standards (e.g. … ISO27001). Proven experience as a Security Architect, with a strong focus on AI security. Deep understanding of AI / ML concepts, including model development, data pipelines, and deployment. Strong understanding of ethical AI principles and practices. Experience with AI security tools and technologies. More ❯
frameworks and their integration with threat intelligence. Hands-on experience with cloud security reviews (AWS, Azure, GCP) considering cloud-specific threats. Familiarity with ISO27001 audits and threat-informed compliance practices. Additional certifications such as CISM, CISSP, ECSA, CREST CCT are advantageous. Who we are: We More ❯
and presenting findings to Senior Stakeholders Hold recognised Cyber Security qualification (CISA, CISMP, CISM or equivalent). Knowledge of industry related frameworks such as ISO27001, PCI DSS This role is based in Northampton and is a hybrid position with on average 2 days a week on-site. The salary is More ❯
Python, Bash, or Perl * Excellent data visualisation and reporting skills * Solid understanding of cybersecurity principles and threat landscapes * Familiarity with compliance frameworks (e.g., GDPR, ISO27001, NIST, Cyber Essentials) * Analytical mindset with attention to detail * Strong communication and documentation skills * Ability to work independently and as part of a team * Passion More ❯