pace with industry standards and innovations. Skills & Experience Experience as a Security Engineer in a fintech startup. Successful delivery of secure, large-scale cloud projects. Knowledge of standards like ISO27001 and NIST. Experience with vulnerability detection tools, email security gateways, EDR solutions, and SIEM. Red teaming or pen testing experience is advantageous. Securing DevOps pipelines. Proficiency with containerization (Docker, Kubernetes … M365 and Azure tools, AWS security services. Familiarity with Cyber Essentials guidelines and verification. Strategic, innovative mindset and adaptability in fast-paced environments. Desirable Qualifications Experience with regulatory compliance (ISO27001, NIST) in an agile scale-up. Certifications like CCSP, CISSP, SSCP. Understanding of financial regulations, blockchain, security operations, and back-office systems. Interest in offensive security and PKI. Why Join More ❯
East London, London, United Kingdom Hybrid / WFH Options
A&O Shearman
services structure with mature or evolving capability across all areas of digital security and cyber defence. We align our efforts to the NIST framework and other recognised certifications including ISO27001 and SOC2 and strive to keep pace with the continually evolving threat landscape, in support of A&O Shearmans strategy to lead where global complexity creates opportunity. In addition, you More ❯
If you're ready to make an impact in Cyber Security, this role is for you! Responsibilities: Ensure protection of information assets and technologies Participate in security audits like ISO27001, ISO27701, ISO20000, NIST-CSF, and IASME Governance Conduct and document internal audits for our clients Deliver security awareness training, including public speaking engagements Manage Third-Party Risk Management (TPRM) including … services to clients Skills / Must have: Extensive experience in Information Security Governance, Risk, and Compliance (GRC) Experience contributing to an Information Security Management System (ISMS) certified to ISO27001 standards Knowledge of the Cyber Essentials Plus Scheme, GDPR, and Data Protection Act (2018) Strong communication skills and the ability to build relationships with internal and external stakeholders Hands-on … experience in ISO27001 implementation and auditing Eligibility for Security Clearance Certifications Preferred: ISO/IEC27001 Lead Implementer ISO/IEC27001 Internal Auditor CISM / CISSP Salary & Benefits: £55,000 - £65,000 base salary per annum Salary Sacrifice pension scheme Private Medical Insurance Buy More ❯
City of London, London, England, United Kingdom Hybrid / WFH Options
Skillcast
role in managing security incidents, audits, and vulnerability programs, while mentoring junior team members and helping shape the future of cybersecurity at Skillcast. Key Responsibilities: - Coordinate SOC 2, ISO27001, and Cyber Essentials audits - including documentation, evidence management, gap analysis, and communication with auditors - Administer and enhance Azure Sentinel SIEM - including data source configuration, detection rule … stakeholder coordination, and remediation tracking - Implement and manage security controls across Azure and Kubernetes environments, ensuring scalable and secure architecture - Work closely with DevOps to embed security in CI / CD pipelines and infrastructure-as-code processes - Enforce security policies, standards, and procedures aligned with frameworks like ISO27001 and NIST - Monitor and report on … You: - Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field - 5+ years of experience in cybersecurity and IT infrastructure roles - Hands-on experience with Azure, Kubernetes / Docker, and CI / CD security practices - Proficient in SIEM platforms (especially Azure Sentinel) and vulnerability management tools - Strong knowledge of incident response, infrastructure hardening, and cloud security More ❯
EC3A, Tower, Greater London, United Kingdom Hybrid / WFH Options
Skillcast
role in managing security incidents, audits, and vulnerability programs, while mentoring junior team members and helping shape the future of cybersecurity at Skillcast. Key Responsibilities: - Coordinate SOC 2, ISO27001, and Cyber Essentials audits – including documentation, evidence management, gap analysis, and communication with auditors - Administer and enhance Azure Sentinel SIEM – including data source configuration, detection rule … stakeholder coordination, and remediation tracking - Implement and manage security controls across Azure and Kubernetes environments, ensuring scalable and secure architecture - Work closely with DevOps to embed security in CI / CD pipelines and infrastructure-as-code processes - Enforce security policies, standards, and procedures aligned with frameworks like ISO27001 and NIST - Monitor and report on … You: - Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field - 5+ years of experience in cybersecurity and IT infrastructure roles - Hands-on experience with Azure, Kubernetes / Docker, and CI / CD security practices - Proficient in SIEM platforms (especially Azure Sentinel) and vulnerability management tools - Strong knowledge of incident response, infrastructure hardening, and cloud security More ❯
Bury St Edmunds, England, United Kingdom Hybrid / WFH Options
Hamilton Barnes 🌳
findings into clear business language for various stakeholders. Produce and present high-quality technical and non-technical reports. Support clients in achieving and maintaining certifications (e.g., Cyber Essentials, ISO27001). Stay informed on cybersecurity … trends and tools, and continuously build your expertise. Collaborate across delivery, project management, and sales teams to deliver outcomes. Mentor junior consultants and contribute to internal improvement initiatives. Skills / Must Have: 2+ years of hands-on Information Security or IT Administration experience. Strong communication skills (written and verbal), with stakeholder management ability. Working knowledge of both offensive and … working model Cycle to Work and IT Purchase Schemes (subject to T&Cs) Salary: Competitive – dependent on experience and certifications. Additional Information: Employment Type: Permanent, Full-Time (36.25 hours / week) Location: Hybrid – Bury St Edmunds Office More ❯
Ensure and improve the security of Loftwares existing applications by driving forward our existing SAST and DAST setups. Establish and maintain compliance with relevant frameworks (e.g., SOC 2, ISO27001, GDPR) in partnership with internal stakeholders. Support customer, partner, and auditor interactions related to security posture and assurance. Key Qualifications: 5+ years of experience in information … and customer-facing teams. Preferred Qualifications: Prior experience building or significantly maturing a security program from early stages. Relevant certifications (e.g., CISSP, CISM, CCSP, ISO Lead Implementer / Auditor). Experience in environments with rapid product development cycles and complex data flows. Comfortable interfacing with customer security teams and fielding security questionnaires or due diligence efforts. Why … US, UK, Germany, Slovenia, China, and Singapore making us a trusted partner for companies in automotive, chemicals, clinical trials, consumer products, electronics, food & beverage, manufacturing, medical devices, pharmaceuticals, retail / apparel, and more. More about us: #Makeyourmark with Loftware and apply today! #J-18808-Ljbffr More ❯
applicable laws, particularly within cybersecurity, data protection, and operational risk. What you will do: Lead and support the implementation of key compliance and cybersecurity frameworks (e.g. UK GDPR, ISO27001, Cyber Essentials), while developing regulatory risk frameworks that track and operationalise emerging obligations. Conduct and coordinate risk assessments, internal reviews, audits, and control testing to ensure … functional teams, including Engineering, Product, and Legal. A self-starter mindset, who is proactive, curious, and resilient, with the discipline to manage your learning and growth. Desirable Qualifications and / or knowledge (any of the following): Certifications or practical experience as / in CISMP, CompTIA Security+, ISO27001 Lead Implementer, CISM, CISSP, or PCI … for milestone anniversaries! Knowledge Sharing: Lunch & Learns, Monthly Speaker Series (bringing you perspective and insights from an array of wonderful people) Team workshops and offsites. ️ Keep healthy with 24 / 7 GP, Mental Health Support & Gym Discounts. Cycle to work and Tech schemes saving you money and spreading the cost. Our Values: Get Onside: We recognise that we're More ❯
strategy development Lead efforts to assess and mature security practices across the enterprise Stay abreast of industry trends, frameworks, and regulations (e.g., GDPR, ISO27001/ 2, SANS Top 20 Critical Security Controls, NIST CSF, SP 800-53, PFMI, CPMI ISOCO and FFIEC handbook, SABSA) to ensure the organization is proactive in addressing emerging security … their day,’ we run a range of initiatives that support employees’ sense of belonging and physical, emotional and mental well-being. Our extensive benefits for employees typically include: Vacation / annual leave: 25 days in UK / Asia + 3 life days, 23 in US + 3 life days Private medical and dental cover and life insurance Generous … the US ‘Locate for your day’ hybrid working – 2 days a week in office. Access to Discover – our learning platform with 1000+ courses from LinkedIn Learning. Paid parental leave / Coaching and support services ‘Heads down days’ with no meetings on the last Friday of every month Diversity Council / Affinity groups (Women’s Forum, Black Employee Network More ❯
trends and escalate risks promptly. Ensure compliance with relevant industry regulations and standards (e.g., GDPR, ISO27001). Manage security systems, including firewalls, intrusion detection / prevention systems, and antivirus software, in collaboration with GT. Develop and test incident response plans and coordinate responses to security incidents and breaches. Raise cybersecurity awareness among bank employees … through annual training / workshops. Other Duties Maintain professional and technical knowledge by attending workshops, reading publications, and benchmarking practices. Collaborate with stakeholders to handle backlogs and new requirements, resolve conflicts, and monitor deliverables. Serve as the point of contact for external communications and facilitate internal collaboration on IT matters. Ensure compliance with policies and regulatory requirements. Maintain quality … service by establishing and enforcing standards. Act as second / third level support with GT for support issues. Comply with FCA / PRA conduct rules and mandatory training requirements. Technical / Functional Skills Proficient in Windows 10, Windows Server 2018+, Redhat Linux OS. Experience with VMWare v6.7+, Veeam Backup, Symantec Endpoint Protection, ManageEngine Patch Manager, Microsoft Office More ❯
to join our team, wed love to hear from you so please apply as soon as you can. To find out more about HCRG Care Group, please visit https: // www.hcrgcaregroup.com / about-us-2 Job description Job responsibilities Strong understanding of information and cyber security principles, including access controls, network security, encryption, endpoint protection, and … Data Security Standards, GDPR, DSP roles). Experience participating in security incident response, post-incident reviews, and technical root cause analysis. Knowledge of identity and access management, security logging / monitoring, and asset / information classification. Strong documentation skills able to produce policies, procedures, risk registers, and audit evidence clearly and accurately. Experience collaborating with Infrastructure, Digital Transformation … external auditors, suppliers, and governance bodies to represent the organisations security posture. Desirable: Exposure to private cloud environments and related security tooling. Experience in security toolsets such as antivirus / EDR, vulnerability scanners, SIEM, or MDM solutions. Relevant industry qualifications (e.g. CompTIA Security+, SSCP, CISSP Associate, ISO27001 Lead Implementer). Knowledge of backup and More ❯
i.e., control frameworks, incident management, operations and application of security best-practices. * Strong understanding and knowledge of cyber security technologies (e.g., firewalls, Microsoft enterprise cloud services, VPNs, ZTNA, IDS / IPS, SIEM, Juniper MIST, encryption). * Experience with security standards and frameworks such as ISO27001, NIST, and GDPR. Head of Cyber Security In accordance More ❯
Determining requirements by evaluating business strategies and requirements, implementing information security standards, conducting system and vulnerability analyses and risk assessments, recommending secure architecture aligned to business architecture, and identifying / driving remediation of integration issues. Providing expert knowledge of solution / application architecture for related capabilities as well as methodologies in the software development life cycle. Maintaining security … issues and risks timely. Completing market assessments on vendor products, packages, and services; guiding tests and implementation of products solving enterprise information security requirements. Suggesting and implementing alternative mitigations / compensating controls to allow for business to continue while protecting BCG's assets. Partnering with cross-functional teams to ensure compliance to industry and company standards including ISO … participating in professional organizations. Vendor escalations and Major Incident Management support for business-critical services. Able to provide L3 operational support for Secrets Management tooling and oversight of L1 / L2 operations issues. Create and track health, security, and adoption metrics. What You'll Bring Nice Haves Bachelor’s degree (or equivalent related experience) 7+ years’ experience working with More ❯
Implement network observability and predictive analytics to proactively prevent outages. Security, Compliance & Risk Management: Drive zero-trust security frameworks, ensuring secure and resilient network access. Ensure adherence to ISO27001, NIST, SOC 2, GDPR, and industry best practices. Collaborate with cybersecurity teams to enhance network threat detection and mitigation. Implement automated security policy enforcement, reducing human … networking, predictive analytics, and network telemetry. Strong understanding of zero-trust networking, compliance frameworks, and security policies. Excellent leadership, communication, and stakeholder management skills. Preferred Qualifications: Certifications: CCIE, AWS / Azure / GCP Networking, CISSP, or equivalent. Experience with Kubernetes networking, Terraform, Ansible, and SDN. Strong problem-solving abilities, with a data-driven approach to network optimization. Who … scalability. Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in More ❯
threat detection, malware prevention, and device compliance. Build and operate scalable data protection solutions, including data loss prevention (DLP), secrets management, encryption, and classification. Integrate security controls into CI / CD pipelines, cloud-native services, and on-prem platforms to enforce security-by-design principles. Deliver security capabilities that support modern work scenarios, remote access, zero-trust networking, and … AI / ML workloads. Leverage automation frameworks and IaC to improve scalability and reduce manual intervention. Operational Security, SRE & Assurance: Ensure security platforms are resilient, continuously monitored, and designed for 24x7 support and incident response readiness. Embed security telemetry and observability to enable proactive threat detection and automated response. Apply SRE principles to improve reliability, performance, and maintainability of … security controls, implementing zero-trust models, and supporting 24x7 security operations. Strong understanding of compliance frameworks and risk management strategies. Preferred Qualifications: Certifications such as CISSP, CCSP, CISM, AWS / Azure Security Specialty, or equivalent. Experience with tools like Okta, Azure AD, CrowdStrike, Tanium, Zscaler, Vault, and other modern security platforms. Familiarity with DevSecOps principles, Infrastructure as Code, and More ❯
Bexhill-On-Sea, East Sussex, South East, United Kingdom Hybrid / WFH Options
Hastings Direct
You will define and enforce rigorous security configuration standards, baselines, and hardening guides for Azure resources, collaborating closely with DevOps and Engineering teams to integrate security seamlessly into CI / CD pipelines (DevSecOps). Conducting thorough risk assessments and gap analyses will be part of your remit, as will developing comprehensive remediation strategies. Your responsibilities will include maintaining detailed … scheduled, that's why we have a range of support to help you keep yourself well. We have the thrive mental health app, our colleague assistance programme available 24 / 7, our own, in-house mental health first aiders, support groups and a dedicated team to make sure we are covering your needs There's more! - 27 days annual … is an equal opportunities employer which means we treat people fairly. We welcome applications from all suitably skilled persons regardless of their gender, age, race, disability, ethnic background, religion / belief, sexual orientation, gender reassignment or marital / family status. Please also note that we have a thorough referencing process, which includes credit and criminal record checks. At More ❯
Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
Queen Square Recruitment Limited
data platforms. Perform threat modelling, architecture reviews, and propose mitigation strategies. Ensure alignment with European regulatory standards (e.g., GDPR, PSD2, DORA, NIS2). Embed DevSecOps into SDLC and CI / CD pipelines using IaC and automation tools. Drive adoption of Zero Trust principles, secure APIs, container security, and logging strategies. What Were Looking For 15+ years in Information Security … years of hands-on cloud security experience (AWS, Azure, or GCP multi-cloud preferred). In-depth understanding of financial services compliance requirements and frameworks (e.g., NIST CSF, ISO27001, CSA CCM, PCI DSS). Expert-level knowledge of IAM, network security, encryption, API and application security, container security, and SIEM strategies. Proven leadership in DevSecOps More ❯
You will define and enforce rigorous security configuration standards, baselines, and hardening guides for Azure resources, collaborating closely with DevOps and Engineering teams to integrate security seamlessly into CI / CD pipelines (DevSecOps). Conducting thorough risk assessments and gap analyses will be part of your remit, as will developing comprehensive remediation strategies. Your responsibilities will include maintaining detailed … scheduled, that’s why we have a range of support to help you keep yourself well. We have the thrive mental health app, our colleague assistance programme available 24 / 7, our own, in-house mental health first aiders, support groups and a dedicated team to make sure we are covering your needs There's more! – 27 days annual … is an equal opportunities employer which means we treat people fairly. We welcome applications from all suitably skilled persons regardless of their gender, age, race, disability, ethnic background, religion / belief, sexual orientation, gender reassignment or marital / family status. Please also note that we have a thorough referencing process, which includes credit and criminal record checks. At More ❯
processes and activities Support the Head of Security and Infrastructure across all functional areas within the security department Liaise with with our Privacy, Governance, Infrastructure, IT Operations, and Product / Engineering teams on all security matters Ensure tools are running correctly Ensure the integrity of our data Investigate Events of Interest (EoIs) Act upon alerts Continuous learning development Documentation … demonstrate knowledge and commitment to cybersecurity: CompTIA Security+ Certified Ethical Hacker (CEH) CompTIA Network+ ISO27001 Foundation or Practitioner AWS Certified Security Familiarity with TCP / IP, DNS, firewalls, VPNs, and VLANs. Basic experience with SIEMs and security logs Understanding of vulnerability management practices Understanding of penetration testing, Threat Hunting, Red Teaming methodologies Familiarity with More ❯
Officer (CISO) is responsible for overseeing the organisation’s Information and Communications Technology (ICT) infrastructure and cybersecurity framework, ensuring alignment with the Digital Operational Resilience Act (DORA) and ISO27001 standards. The CISO safeguards the Crypto-Asset Service Provider’s (CASP) systems, including the PIL crypto platform and front-end, by conducting risk assessments, maintaining comprehensive … team to protect critical operations in a regulated fintech environment. Here's what you'll do: Oversee the ICT infrastructure and cybersecurity programme, ensuring compliance with DORA and ISO27001 standards. Develop and implement information security strategies, policies, and procedures in line with NIST CSF, NIST 800-53, CIS, and COBIT frameworks. Conduct risk assessments and … commercial correspondence. Extensive experience in IT security leadership, preferably within fintech, financial services, or crypto-asset sectors. Proven expertise in implementing information security and risk frameworks (NIST CSF, ISO27001, NIST 800-53, CIS, COBIT). In-depth knowledge of DORA requirements, and risk management for ICT assets, including crypto platforms. Strong understanding of auditing frameworks More ❯
failure. Essential Skills & Experience: At least 2 years of hands-on experience in information security or IT infrastructure within an enterprise environment. Familiarity with security standards such as ISO27001, Cyber Essentials, GDPR, and Data Protection Act. Experience with Microsoft O365 Security solutions and network security operations. Understanding of security testing principles, including vulnerability scanning, risk … apply now. Keywords: Information Security Consultant, IT Security Consultant, Cybersecurity Specialist, Microsoft O365 Security, Enterprise Security Jobs, Information Security Leeds, IT Risk Management, Security Incident Response, Vulnerability Management, ISO27001, GDPR Compliance, Security Awareness, Disaster Recovery and Business Continuity. More ❯
failure. Essential Skills & Experience: At least 2 years of hands-on experience in information security or IT infrastructure within an enterprise environment. Familiarity with security standards such as ISO27001, Cyber Essentials, GDPR, and Data Protection Act. Experience with Microsoft O365 Security solutions and network security operations. Understanding of security testing principles, including vulnerability scanning, risk … apply now. Keywords: Information Security Consultant, IT Security Consultant, Cybersecurity Specialist, Microsoft O365 Security, Enterprise Security Jobs, Information Security Leeds, IT Risk Management, Security Incident Response, Vulnerability Management, ISO27001, GDPR Compliance, Security Awareness, Disaster Recovery and Business Continuity. More ❯
Reading, Oxfordshire, United Kingdom Hybrid / WFH Options
In Technology Group
Role: Senior Cyber Security Engineer (Cyber SME) Salary : Up to 70,000 Location: Reading / Birmingham - Hybrid (1 day / week in office) Be the Cyber Security Subject Matter Expert protecting the backbone of our business. Are you a highly skilled cyber security professional ready to take ownership of security engineering and infrastructure hardening? We're looking for … re Looking For Essential: Right to work in the UK. Proven experience in cyber security engineering, including vulnerability management, SIEM, WAFs, and secure infrastructure design. Strong knowledge of TCP / IP, firewalls, routing, access controls, and threat-based security approaches. Excellent communication skills with the ability to create and maintain technical documentation. Background in infrastructure / networks and … CCNA / CCNP, or similar certifications. Familiar with ITIL-based service delivery, security hardening, and working cross-functionally. Desirable: Degree in Computer Science or equivalent experience. Understanding of ISO27001, Cyber Essentials, and AAF frameworks. What We Offer Competitive salary up to 70,000 Hybrid working - only 1 day a week in the office 25 days holiday (plus option to More ❯
Reading, Berkshire, United Kingdom Hybrid / WFH Options
In Technology Group
Role: Senior Cyber Security Engineer (Cyber SME) Salary : Up to £70,000 Location: Reading / Birmingham - Hybrid (1 day / week in office) Be the Cyber Security Subject Matter Expert protecting the backbone of our business. Are you a highly skilled cyber security professional ready to take ownership of security engineering and infrastructure hardening? We're looking for … re Looking For Essential: Right to work in the UK. Proven experience in cyber security engineering, including vulnerability management, SIEM, WAFs, and secure infrastructure design. Strong knowledge of TCP / IP, firewalls, routing, access controls, and threat-based security approaches. Excellent communication skills with the ability to create and maintain technical documentation. Background in infrastructure / networks and … CCNA / CCNP, or similar certifications. Familiar with ITIL-based service delivery, security hardening, and working cross-functionally. Desirable: Degree in Computer Science or equivalent experience. Understanding of ISO27001, Cyber Essentials, and AAF frameworks. What We Offer Competitive salary up to £70,000 Hybrid working - only 1 day a week in the office 25 days holiday (plus option to More ❯