value everybody for who they are and what they bring to the table, supporting one another as we continue to deliver for our customers. LI-KS1 Create & Maintain an informationsecuritymanagement system (ISMS) capable of demonstrating compliance against internal security requirements and external commitments including certification and regulatory requirements. Provide subject matter expertise in the … to any new or existing programme of work. Prepare and support internal and/or external compliance audit activities. Manage remediation of any audit (internal & External) non-conformities. Ensure security policies (on a risk-based approach) are produced, signed off by relevant stakeholders, published, and communicated. Also, ensure that policies are managed throughout their lifecycle and updated through yearly … or ad-hoc reviews. Produce relevant security standards documentation in consultation with Technical teams. Lead on providing information to Three UK Customers (B2B) regarding Three UK's security practices. Support proactive and effective oversight of technology and security risk management frameworks, methodologies, processes, assurance, remediation, and reporting activities across the company. Assist in designing, building More ❯
Hertfordshire, England, United Kingdom Hybrid / WFH Options
Planet Pharma
Job Title: InformationSecurity Compliance Analyst Location: Hertfordshire, UK (Hybrid) Contract: 12-Month Fixed Term (Salaried) Are you passionate about cybersecurity, compliance, and driving risk management strategies? We’re seeking an experienced InformationSecurity Compliance Analyst to join a dynamic team supporting the development and maintenance of an EMEA-wide InformationSecurityManagement … System. This role plays a critical part in maintaining ISO 27001:2022 certification, ensuring compliance with legislation including NIS 2, GDPR, and the AI Act, and promoting a strong security culture across the business. Requirements: ISO 27001 Lead Implementer or Auditor certification (essential). Demonstrated experience in an InformationSecurity or IT Governance role. Strong knowledge of … frameworks like ISO 27001/27002, NIST, GDPR, and related standards. Proven ability to manage audits, compliance reporting, and security training programs. Excellent stakeholder management, communication, and analytical skills. This is an exciting opportunity for someone who thrives in a fast-paced, regulated environment and wants to make a real impact in protecting systems, data, and operations across More ❯
Chorley, England, United Kingdom Hybrid / WFH Options
TVS Supply Chain Solutions UK & Europe
InformationSecurity & Business Continuity Coordinator Purpose: TVS are recruiting an InformationSecurity & Business Continuity (ISBC) Coordinator to develop and maintain an already established informationsecuritymanagement system certified to ISO27001 and a business continuity management system certified to ISO22301 across several UK sites. The successful candidate will have a working knowledge of … ISO standards, understand risk management and be able to communicate effectively at all levels. Main Duties & Responsibilities: Support the maintenance, development and continual improvement of ISBC Management System Coordinate and assist in internal audits to maintain ISO 27001 and ISO 22301 compliance Track and follow up on corrective and preventive actions resulting from audits or incidents Maintain documentation … records, and registers in accordance with ISO standards Assist in managing the risk assessment and treatment processes Monitor compliance with policies, procedures, and controls Support incident management and business continuity testing activities Organise and deliver awareness training and communication efforts related to compliance topics Contribute to and partake in external, regulatory and customer surveillance visits Help ensure that day More ❯
wellbeing at work for employees while protecting the planet. The IT Compliance and Risk Manager is responsible for developing, implementing and overseeing the organisation's IT compliance and risk management programmes, with a strong focus on maintaining the ISO 27001 and ISO 90001 certifications. The role ensures that IT security and operations align with global Pluxee policies & procedures … as well as regulatory, legal, GDPR and industry standards while mitigating risks and enhancing overall posture. Respond to client InformationSecurity tenders and questionnaires, establish and maintain a central repository of documentation available for Sales and Planning Team access. 🚀 Your next challenge: Lead and manage the organisation's ISO certification and surveillance audit processes. Develop and maintain policies … GDPR, NIST etc Serve as a subject-matter expert for IT compliance questions Develop and enforce IT policies and procedures that support compliance and risk objectives. Respond to client InformationSecurity tenders and questionnaires. Conduct training and awareness programmes. Accountabilities: Maintain ISO certification and promote the standards within the business. Quarterly reporting to SLT on compliance status, IT More ❯
Swindon, Wiltshire, United Kingdom Hybrid / WFH Options
Zurich 56 Company Ltd
June The opportunity: This is an opportunity to join the UK IT and Operations team, reporting to the Head of IT Service Delivery, where you will collaborate with the management team, bursting with ideas on how to move our UK business forward. You will be asked to drive change and improve on a set of already well-established IT … Controls and an IT Risk Management Framework to allow senior IT management, business functions and 3rd party service providers to demonstrate they are managing and safeguarding company assets, data, and operations. Your ideas will be heard. You will collaborate and influence IT management, the IT Governance and Controls Manager and other governance colleagues to gather data and … collate, aggregate and interpret information to provide the Boards of Directors, Business Executives and other interested parties with an assessment of the UK IT Risk and Controls landscape. You will also manage multiple demands for IT risk-based information within Zurich, ensuring all reporting commitments are met. You will work alongside local and regional Group IT functions, Service More ❯
Ripponden, Yorkshire, United Kingdom Hybrid / WFH Options
JLA Limited
and The Netherlands. Ensure compliance with data protection laws (eg GDPR, PECR) and internal privacy standards Provide expert advice and guidance on data protection impact assessments (DPIAs) and risk management Conduct regular audits to monitor compliance and address potential privacy issues Deliver training and awareness programs to employees on data protection best practices Collaborate with Legal, IT and HR … in emerging technologies (eg AI, IoT) In-depth knowledge of direct marketing laws as they relate to data privacy, such as the Privacy and Electronic Communications Regulations Strong project management skills Knowledge of data protection laws in Ireland and the Netherlands is helpful but not essential Knowledge of cybersecurity best practices and technologies Knowledge of data protection social norms … subject access requests and other requests from data subjects regarding their personal data Experience in delivering training and awareness programs to employees on data protection best practices Familiarity with informationsecuritymanagement systems and data governance frameworks Experience in a legal, audit or risk management role Personal qualities (the way you think and act) An ability More ❯
We are seeking an experienced Network and InformationSecurity Engineer to join our team. In this role, you will be responsible for managing and configuration of network equipment (Cisco, Juniper,etc.) , and ensuring the smooth operation of our ZSTACK cloud environment. Key Responsibilities: (1) Strictly abide by the local laws, regulations and company rules and regulations of the … country or region to do the relative network maintenance or informationsecurity jobs; 1-3 years of experience in network maintenance, configuration, cyber security and information; Hardworking and quick learning. (2) Experience with the details and practical application of current data protection legislation, and possess an in-depth understanding of the GDPR. (3) Following the guidance … of CTG HQ network and informationsecurity department to do the relative jobs, reports, support internal and external networks, including VPN setup, DNS management, AP management, firewall configuration, WAF (e.g. Akaimai),SIEM(e.g. IBM QRada),etc. (4) Familiar with IP network, familiar with Cisco and Juniper, etc. equipment’s maintenance and configuration. (5) Experience with the More ❯
We are seeking an experienced Network and InformationSecurity Engineer to join our team. In this role, you will be responsible for managing and configuration of network equipment (Cisco, Juniper,etc.) , and ensuring the smooth operation of our ZSTACK cloud environment. Key Responsibilities: (1) Strictly abide by the local laws, regulations and company rules and regulations of the … country or region to do the relative network maintenance or informationsecurity jobs; 1-3 years of experience in network maintenance, configuration, cyber security and information; Hardworking and quick learning. (2) Experience with the details and practical application of current data protection legislation, and possess an in-depth understanding of the GDPR. (3) Following the guidance … of CTG HQ network and informationsecurity department to do the relative jobs, reports, support internal and external networks, including VPN setup, DNS management, AP management, firewall configuration, WAF (e.g. Akaimai),SIEM(e.g. IBM QRada),etc. (4) Familiar with IP network, familiar with Cisco and Juniper, etc. equipment’s maintenance and configuration. (5) Experience with the More ❯
happy business? We are an innovative, agile, and continuously growing modern tech company on a path to improving the work lives of millions around the world. We develop workforce management solutions - software that makes scheduling and time reporting more smooth and more flexible for almost a million users worldwide! We value passion, quality, innovation, trust, and collaboration . You … and thrive. We have a hybrid working set up and therefore you will be required to attend our Stockholm office minimum twice per week. About the role A Chief Information Officer (CIO) is the senior-level executive within an organization responsible for establishing and maintaining the enterprise vision , strategy , and program to ensure information assets and technologies are … adequately protected. The role is broken into three key areas of responsibility: Informationsecurity IT, infrastructure and networks Internal data and reporting As CIO you will be responsible for developing integrated strategies and programs of work covering all three areas listed above delivering maximum value to the business, as well as acting as a chief informationsecurityMore ❯
About this Role Writer is seeking a highly skilled and experienced Security Engineer to join our dynamic and innovative team. The Security Engineer will play a crucial role in enhancing our informationsecurity and privacy posture by engaging with engineering and operations teams to perform security reviews, threat modeling, and other critical security activities. … This role requires a deep understanding of informationsecurity principles, a strong technical background, and the ability to collaborate effectively across various teams. The Security Engineer will report to the Head of InformationSecurity & Compliance, and will work closely with the InformationSecurityManagement Leadership, the Engineering, Product, and Design Team, and … other relevant stakeholders. Location(s): London; New York, Austin, Chicago, San Francisco, Remote ️ Your Responsibilities Design and implement robust security architectures that align with industry standards and best practices; ensure that security controls are integrated into the design and implementation of new systems and applications. Provide technical guidance and recommendations to engineering and operations teams to enhance the More ❯
providing the right trading infrastructure, smart logistical solutions and the benefits of freeport status to our customers. An excellent opportunity has opened within CNS IT Operations for a IT Security Manager . Reporting to the Head of IT our ideal candidate will have hands on leadership background where you’ll shape the future of our security posture, influence … and ensure our systems, people and processes are secure, compliant and resilient. Location: Southampton Training Hours: 37.5 Hours How you will contribute: Lead and manage a small team of InformationSecurity Analysts, providing direction, support and development. Own and maintain our ISO 27001 InformationSecurityManagement System (ISMS), ensuring compliance and continuous improvement. Drive the … implementation of Cyber Essentials Plus and other key security standards. Develop and update security policies, procedures and controls to protect our systems and data. Conduct regular risk assessments and manage mitigation plans to reduce vulnerabilities. Respond to security incidents, lead investigations and coordinate recovery efforts. Produce monthly reports on security performance, risks and incidents for senior More ❯
Worthing, Sussex, United Kingdom Hybrid / WFH Options
NHS
moves and changes Acting as the lead engineer for networks on new projects and moves and working in agreement with standards set out by the Technical Lead - network and security Main duties of the job Working as part of the wider networks team, the post-holder will provide comprehensive technical expertise and support to maintain and expand the Trust … a lead engineer on the build, configuration, documentation and integration of new IT network service components as part of the Trusts on going technology expansion alongside the capital programme Management of Installation of new structured cabling including WAN and Distribution connections alongside client side, BMS, IOT and WAP connections Providing quotations of networking components to project team Installation and … performance and address potential risks Operational response of escalated Network issues Monitoring of reporting and proactive response to network errors and performance issues Provide and maintain evidence to support informationsecurity reviews and best practice including the information governance toolkit and the ISO27001 InformationSecurityManagement System Communication Required to explain complex IT issues More ❯
Brighton, Sussex, United Kingdom Hybrid / WFH Options
NHS
moves and changes Acting as the lead engineer for networks on new projects and moves and working in agreement with standards set out by the Technical Lead - network and security Main duties of the job Working as part of the wider networks team, the post-holder will provide comprehensive technical expertise and support to maintain and expand the Trust … a lead engineer on the build, configuration, documentation and integration of new IT network service components as part of the Trusts on going technology expansion alongside the capital programme Management of Installation of new structured cabling including WAN and Distribution connections alongside client side, BMS, IOT and WAP connections Providing quotations of networking components to project team Installation and … performance and address potential risks Operational response of escalated Network issues Monitoring of reporting and proactive response to network errors and performance issues Provide and maintain evidence to support informationsecurity reviews and best practice including the information governance toolkit and the ISO27001 InformationSecurityManagement System Communication Required to explain complex IT issues More ❯
projects may include: Software selection, procurement, and implementation. Implementation of standard Mace software solutions. Office infrastructure setup and office moves. Whole IT strategy delivery for a project or programme. Informationsecurity projects including implementation of an InformationSecurityManagement System (ISMS) and certification to ISO27001. Disaster recovery and business continuity planning. Selection of outsourced and … promise Integrity - Always do the right thing Create opportunity - For our people to excel The Business Analyst will lead in analyzing and resolving client business problems by critically assessing information gathered through various elicitation techniques, driving business process improvements, and articulating the rationale for change. Through interviews and workshops, the Business Analyst will define, prioritize, and document requirements into … training materials, and post-implementation documents. Building professional relationships with stakeholders at all levels to manage expectations around scope, delivery, and timelines. Collaborating with project teams to understand data management and reporting practices. Contributing to standard practices and processes for the business analysis centre of excellence. Supporting the development of resources and materials for the business analysis toolkit. Establishing More ❯
InformationSecurity Lead - create the security strategy for a SaaS startup - £60,000 - £75,000 + 10% Bonus A dynamic and rapidly expanding technology company focused on revolutionizing learning and upskilling is seeking its first dedicated InformationSecurity Lead. This is a crucial role for a fast-growing SaaS platform that empowers individuals to learn … what they need, when they need it, and is already trusted by major organizations. This is an exciting opportunity for an experienced InformationSecurity professional to be the subject matter expert and build the security function from the ground up. You will take ownership of identifying, assessing, and mitigating informationsecurity risks across the business … as well as establishing and maintaining robust security processes and controls to support commercial, engineering, and product teams. The ideal InformationSecurity Lead will be responsible for: Owning and leading the informationsecurity function, working collaboratively across all departments. Maintaining and evolving ISO 27001 certification and managing the InformationSecurityManagement System More ❯
Havant, Hampshire, United Kingdom Hybrid / WFH Options
Reed Technology
Cyber Security Specialist Location: Havant Job Type: Full-time, Hybrid (3-4 days per week), 12-month FTC (with likely extension to permanent) Salary: 50 - 53K plus benefits We are seeking a Cyber Security Specialist to lead the implementation of a new InformationSecurityManagement System (ISMS) and ensure compliance with security standards. This … role is crucial in driving security improvements, managing risks, and maintaining regulatory compliance within a dynamic IT environment of circa 500 IT users. Key Accountabilities: * Lead the implementation of a new ISMS, ensuring alignment with industry security standards. * Develop and maintain cyber security policies, procedures, and risk management frameworks. * Manage compliance with cyber security regulations … standards, and frameworks (ISO27001, CAF/eCAF, Cyber Essentials Plus). * Implement and manage security monitoring tools to detect and respond to security events. * Identify and assess security risks and vulnerabilities, developing mitigation strategies. * Support regular audits and assessments to ensure adherence to security policies. * Provide reporting on security incidents, compliance status, and risk assessments. More ❯
Havant, Hampshire, South East, United Kingdom Hybrid / WFH Options
Reed Technology
Cyber Security Specialist Location: Havant Job Type: Full-time, Hybrid (3-4 days per week), 12-month FTC (with likely extension to permanent) Salary: 50 - 53K plus benefits We are seeking a Cyber Security Specialist to lead the implementation of a new InformationSecurityManagement System (ISMS) and ensure compliance with security standards. This … role is crucial in driving security improvements, managing risks, and maintaining regulatory compliance within a dynamic IT environment of circa 500 IT users. Key Accountabilities: * Lead the implementation of a new ISMS, ensuring alignment with industry security standards. * Develop and maintain cyber security policies, procedures, and risk management frameworks. * Manage compliance with cyber security regulations … standards, and frameworks (ISO27001, CAF/eCAF, Cyber Essentials Plus). * Implement and manage security monitoring tools to detect and respond to security events. * Identify and assess security risks and vulnerabilities, developing mitigation strategies. * Support regular audits and assessments to ensure adherence to security policies. * Provide reporting on security incidents, compliance status, and risk assessments. More ❯
Milton Keynes, Buckinghamshire, United Kingdom Hybrid / WFH Options
Allica Bank
of local communities - representing over a third of our economy - yet have been largely neglected both by traditional high street banks and modern fintech providers. Department Description Allica's security team plays a crucial role in maintaining the integrity and security of the company's information systems. They ensure that the ISMS (InformationSecurityManagement … date but also effectively embedded across all departments. This requires a proactive approach and close collaboration with various teams, such as Engineering, Platform, Risk, and Compliance, to address any security concerns and implement necessary measures. Role Description We are looking for an experienced and dynamic Lead Security Engineer to join our security team. The role will be … pivotal in building, leading and enhancing our security posture. You will lead a team of security engineers, drive security initiatives and play a key role in ensuring the security of our rapidly expanding platform. Principal Accountabilities Lead the development and deployment of endpoint monitoring strategies ensuring that all devices within the organisation are continuously monitored for More ❯
Security Risk & Compliance Specialist Department: 61-543 - Technology Operations - Technology Governance Employment Type: Fixed Term Contract Location: UK - Leeds Reporting To: Finlay Stannard Description Are you ready to take the challenge to educate all employees in a young and ambitious organisation about their role in making informationsecurity a core part of their modus operandi and conduct … of Risk & Compliance to join their Technology Governance team as a Fixed Term 14-month maternity cover role. Leading a team role overseeing the global strategic implementation of DAZN informationsecuritymanagement system (ISMS), the chosen candidate will be responsible for delivering annual workstream activities that form the ISMS programme to ensure continued conformity with standards such … as ISO27001 and PCI DSS. What you'll be doing: Leading the implementation and continued maintenance of DAZN's informationsecuritymanagement system (ISMS) in conformity with ISO27001. Managing and delivering annual workstreams for the successful completion of audits against ISO27001 and PCI DSS. Providing subject matter expertise within the area of informationsecurity risk More ❯
remote). Manage end-user computer estate (laptops, mobile devices – Windows & macOS) using tools like Manage Engine/Intune. Process joiners, movers, and leavers including equipment provisioning and access management Push to Automate processes where applicable. Support and manage various software tools (Jira, ServiceNow, Microsoft Office, Teams, Salesforce, Miro, Moorepay HR, and finance systems). Administer and troubleshoot office … equipment including video conferencing tools, networking equipment, and printers. Conduct quarterly software access reviews and scheduled informationsecurity checks (e.g., antivirus, updates, access control). Maintain and manage the IT Asset Register and ITOPs third-party supplier register Liaise with third party suppliers for procurement of IT equipment. Assist with audits (internal/external) and GDPR data access … approval authority. Support ISO27001 ISMS compliance including documentation, checks, and reporting. Contribute to the development of Service Desk standards, processes, and KPIs. Provide flexible support to CMS, infrastructure, and informationsecurity teams within capability and bandwidth. Collaborate with third-party vendors for efficient resolution of issues. Create and maintain up-to-date procedural and process documentation. Support mkodo More ❯
City of London, Greater London, UK Hybrid / WFH Options
mkodo
remote). Manage end-user computer estate (laptops, mobile devices – Windows & macOS) using tools like Manage Engine/Intune. Process joiners, movers, and leavers including equipment provisioning and access management Push to Automate processes where applicable. Support and manage various software tools (Jira, ServiceNow, Microsoft Office, Teams, Salesforce, Miro, Moorepay HR, and finance systems). Administer and troubleshoot office … equipment including video conferencing tools, networking equipment, and printers. Conduct quarterly software access reviews and scheduled informationsecurity checks (e.g., antivirus, updates, access control). Maintain and manage the IT Asset Register and ITOPs third-party supplier register Liaise with third party suppliers for procurement of IT equipment. Assist with audits (internal/external) and GDPR data access … approval authority. Support ISO27001 ISMS compliance including documentation, checks, and reporting. Contribute to the development of Service Desk standards, processes, and KPIs. Provide flexible support to CMS, infrastructure, and informationsecurity teams within capability and bandwidth. Collaborate with third-party vendors for efficient resolution of issues. Create and maintain up-to-date procedural and process documentation. Support mkodo More ❯
Cheltenham, Gloucestershire, United Kingdom Hybrid / WFH Options
Spirax-Sarco Engineering
working) Benefits: 27 days holiday plus Wellbeing day,Private Medical Insurance, Bonus scheme, Sharescheme, Enhanced pension plan,Life assurance, Discount scheme. Role Overview: Join a dynamic, international team of InformationSecurity and IT professionals at Spirax Group plc as a Group IT Assurance Manager . Reporting to the Group IT GRC Manager and leading a small team, you … the Group. Acting as a key ambassador for IT assurance and controls, sharing best practices and ensuring delivery of actions. Supporting the maintenance and development of the Group's InformationSecurityManagement System (ISMS). Leading compliance assessments and maintaining a central repository of security and compliance documentation. Coaching team members and colleagues on IT General … Controls and assurance practices. Your previous experience is likely to include . Proven experience leading IT assurance programmes. Substantial experience in security assessments and compliance oversight. Familiarity with ISMS and frameworks such as ISO 27001, NIST CSF, CIS Controls, or SCF. Understanding of cloud security, third-party risk, and regulatory standards (e.g., GDPR, UK DPA2018). Experience using More ❯
consistency, uphold best practices, and drive compliance efforts that align with industry standards and regulatory expectations. How Youll Spend Your Time Assistingwith the compliance program and integrated quality/informationsecuritymanagement system to maintain alignment with industry standards Facilitatingand conducting risk assessments in order to ensure risks are effectively identified and managed according to the company … compliance frameworks and industry standards such as ISO, SOC, HIPAA, and GDPR Ability to commuteto our UK office up to [insert number] days a week Sincere interestin privacy, risk management, and maintaining ethical operations across a global organization A knack for working collaborativelywithin cross-functional and international teams What you will gain: This is an excellent opportunity for you … Competencies You Will Need: Must have excellent oral and written communication skills and expertise in: UK & EU privacy legislation completing risk assessments in general, privacy assessments in particular risk management managing and completing subject access requests project management It would be desirable if you have: A deep understanding of the regulatory environment in the US, CAN, DE, SWE More ❯
Chesterfield, Derbyshire, United Kingdom Hybrid / WFH Options
Hays Technology
IT Security & Compliance Lead Chesterfield £50,000 to £55,000+ Excellent Benefits Your new company Hays Technology are recruiting for an InformationSecurity & Compliance Lead to join a large public sector organisation based in the Chesterfield area. You will be reporting to the Head of Digital, Data & Technology. This is a new role to establish and make … your own. Your new role In your new role, you will be responsible for ensuring the security and protection of the organisation's information systems, networks, and data, whilst playing a critical role in developing and implementing informationsecurity strategies, policies, and procedures to safeguard the organisation's digital assets and mitigating potential risks. You will … oversee informationsecurity, compliance, and risk management practices based on industry-accepted informationsecurity and risk management frameworks, whilst establishing and maintaining an incident response plan, including incident detection, response, investigation, and resolution, to minimise the impact of security incidents. What you'll need to succeed Demonstrable experience of implementing and maintaining informationMore ❯
Employment Type: Permanent
Salary: £50000 - £55000/annum £50,000 to £55,000+Benefits
Manchester, North West, United Kingdom Hybrid / WFH Options
Tunstall Healthcare (UK) Ltd
We are currently recruiting for a Regional InformationSecurity Officer , reporting to the Global Chief InformationSecurity Officer (CISO), to oversee the informationsecurity function across the countries and Tunstall entities in their scope. This is an incredibly exciting time to join Tunstall as we embark on an exciting period of transformation. You will … be joining a recently created and growing global InformationSecurity team within Tunstall and will be in a leadership position playing a key part in the success of this transformation. This role would be based at either our Manchester office or our Whitley site (DN14 0HR) working on a hybrid basis. We are flexible on number of days … in the office. What will you be doing in this role? As our Regional Security Officer , you will be responsible for implementing, running and overseeing the informationsecurity function across the countries and Tunstall entities in your scope, ensuring consistent and strong informationsecuritymanagement in support of our business goals and in line More ❯