Role This is a unique and exciting opportunity for a seasoned PCIDSS expert to take ownership of and drive the growth of the PaymentCardIndustry (PCI) service line. This role is a perfect blend of deep technical consulting, strategic client advisory, and sophisticated business development. You will act as the lead subject matter expert, guiding … mid-market clients through the complexities of achieving and maintaining PCIDSS compliance. You will also contribute and share in the rewards for the commercial success of the practice, identifying and winning new business with both existing and prospective customers by acting as a trusted, credible advisor. Key Responsibilities Consulting & Delivery (approx. 80%) Lead and deliver a range … of PCIDSS compliance services, including Gap Analyses, Scoping Workshops, Remediation Advisory, and formal assessments (Report on Compliance (RoC) and Self-Assessment Questionnaires (SAQ)). Act as a virtual CISO or trusted security advisor to key clients, providing ongoing strategic guidance on their compliance programmes. Translate complex technical PCIDSS requirements and security findings into clear More ❯
london, south east england, united kingdom Hybrid/Remote Options
PCI Pal
WELCOME TO PCI PAL PCI Pal is a leading provider of SaaS solutions that empower companies to take payments securely, adhere to strict industry governance, and remove their business from the significant risks posed by non-compliance and data loss. We are integrated and resold by some of the world's leading business communications vendors, as well as … major payment service providers. We are currently looking for a GRC & Audit Lead to join our UK team. THE OPPORTUNITY: PCI Pal's Information Security team requires a dynamic and proactive individual to lead all Governance, Risk and Compliance (GRC), audit requirements for our team and the company. We are an agile and innovative team and are responsible for … that GRC and audit requirements are suitably managed, maintained and matured. YOU WILL BE RESPONSIBLE FOR: Managing, maintaining, and maturing the already established audit lifecycles for the following frameworks: PCIDSS v4.0, ISO 27001:2022, ISO 9001:2015, ISO 14001:2015, Cyber Essentials, Cyber Essentials Plus, SOC2 Type 1 – 3 & HIPAA Working in close collaboration with other team More ❯
Liverpool, England, United Kingdom Hybrid/Remote Options
Love2shop
examples of working in a service critical environment are advantageous. As a DevOps Engineer you will be responsible for ensuring all deployment processes and automation meet regulatory requirements, namely PCIDSS, ISO27001, and Cyber Security Essentials. This will include the introduction of standards to ensure conformity within the PayPoint development and deployment workflows. This role is Hybrid with … and firewall management • Certification in Azure, AWS, or DevOps methodologies • Experience with chaos engineering and resilience testing • Familiarity with service mesh technologies (Istio, Linkerd, cilium) Really Nice to Have: • PCI-DSS compliance experience • Experience in financial services or regulated industries • Knowledge of ITIL or similar service management frameworks • Experience with automated testing frameworks and test automation • Understanding of More ❯
Welwyn Garden City, England, United Kingdom Hybrid/Remote Options
PayPoint plc
examples of working in a service critical environment are advantageous. As a DevOps Engineer you will be responsible for ensuring all deployment processes and automation meet regulatory requirements, namely PCIDSS, ISO27001, and Cyber Security Essentials. This will include the introduction of standards to ensure conformity within the PayPoint development and deployment workflows. This role is Hybrid with … and firewall management • Certification in Azure, AWS, or DevOps methodologies • Experience with chaos engineering and resilience testing • Familiarity with service mesh technologies (Istio, Linkerd, cilium) Really Nice to Have: • PCI-DSS compliance experience • Experience in financial services or regulated industries • Knowledge of ITIL or similar service management frameworks • Experience with automated testing frameworks and test automation • Understanding of More ❯
80k base + £5k car allowance and other benefits. What You'll Do Assess compliance with internal security policies and industry standards (eg, ISO/IEC 27001/2, PCI-DSS). Conduct supplier risk assessments and third-party due diligence. Support vulnerability assessments, incident investigations, and operational resilience activities. Monitor the effectiveness of security controls to ensure … analysis. A knowledge of the data protection act (UK GDPR) and how it applies to information and cyber security A knowledge of cardpayment system security as defined in PCI-DSS V4.0 Qualifications A security certification such as CISM, CISMP, CISSP or equivalent would be desirable. A relevant IT or security-based degree or equivalent practical experience. More ❯
City of London, London, United Kingdom Hybrid/Remote Options
McCabe & Barton
80k base + £5k car allowance and other benefits. What You'll Do Assess compliance with internal security policies and industry standards (eg, ISO/IEC 27001/2, PCI-DSS). Conduct supplier risk assessments and third-party due diligence. Support vulnerability assessments, incident investigations, and operational resilience activities. Monitor the effectiveness of security controls to ensure … analysis. A knowledge of the data protection act (UK GDPR) and how it applies to information and cyber security A knowledge of cardpayment system security as defined in PCI-DSS V4.0 Qualifications A security certification such as CISM, CISMP, CISSP or equivalent would be desirable. A relevant IT or security-based degree or equivalent practical experience. More ❯
Manchester, England, United Kingdom Hybrid/Remote Options
Gravitas Recruitment Group (Global) Ltd
strengthen the organisation’s security and compliance posture. Key Responsibilities Lead and enhance governance, risk, and compliance frameworks. Manage internal/external audits and risk assessments. Ensure compliance with PCIDSS, ISO 27001, GDPR, and NIST. Develop and improve policies, procedures, and vendor risk management. Support incident response and promote a culture of security awareness. Experience & Skills Proven … leadership in GRC or Information Security. Strong knowledge of ISO 27001, PCIDSS, GDPR, NIST. Experience managing audits and compliance programmes. Excellent communication and stakeholder management. Hands-on technical understanding of security controls. Desirable: Certifications: CISM, CRISC, ISO 27001 Lead Auditor (or equivalent). Experience with cloud security (AWS/Azure) and enterprise-scale environments. Benefits Salary up More ❯
Poole, Dorset, England, United Kingdom Hybrid/Remote Options
Mexa Solutions LTD
make a real impact What you’ll be doing: Leading vulnerability assessments and coordinating regular penetration testing across systems and products Owning risk remediation actions, from security audits to PCI scans and compliance reporting Working across cloud (AWS), infrastructure, and software environments to ensure security best practices are embedded throughout Supporting the secure design of products and infrastructure, providing … tools Writing clear, actionable reports for both technical and executive audiences, including regular updates on the security landscape Aligning with frameworks such as ISO 27001, Cyber Essentials+, GDPR, and PCI-DSS Collaborating with compliance, IT, and engineering to deliver secure, scalable solutions What you’ll bring to the table: Proven experience in a security-focused role (ideally … grasp of access controls, identity management, and cloud security (especially AWS) Familiarity with secure software development practices and working alongside dev teams Understanding of key frameworks like ISO 27001, PCI-DSS, and GDPR Bonus points for scripting/automation experience (PowerShell, Python, etc.) or exposure to tools like Keeper, Keycloak, or IAM A proactive mindset and excellent communication More ❯
Cheshire, England, United Kingdom Hybrid/Remote Options
Morgan Law
of disaster recovery and business continuity plans. Produce reports and metrics for senior IT and governance stakeholders Stay updated with the latest threats, trends, and compliance requirements (e.g., GDPR, PCIDSS, Cyber Essentials) Person Specification Essential: Demonstrable experience in a related role Excellent problem-solving, analytical, and communication skills An appetite for keeping up to date with the … UK Desirable: Industry certifications (e.g., CompTIA Security+, SSCP) Experience in the charity or non-profit sector Familiarity with Microsoft Azure cloud platforms and identity management Experience with compliance frameworks (PCIDSS, Cyber Essentials) Experience with auditing and compliance Experience of BCP/DR More ❯
Portsmouth, England, United Kingdom Hybrid/Remote Options
Franklin Fitch
and maintaining key certifications such as ISO/IEC 27001 , SOC 2 Type II , Cyber Essentials Plus , and CREST SOC accreditation , as well as supporting sector-specific frameworks including PCIDSS and NCSC CIR/CHECK . The ideal candidate will have a strong background in cybersecurity assurance , experience engaging with external auditors and customers , and a proactive … ongoing maintenance of SOC-related certifications including SOC 2 Type II , SOC 3 , ISO/IEC 27001 , Cyber Essentials Plus , and CREST . Manage sector-specific compliance such as PCIDSS and NCSC CIR/CHECK . Ensure timely renewals and proactively address compliance gaps. Security Assurance for SOC Operations Integrate certification and assurance requirements into SOC governance More ❯
London, South East, England, United Kingdom Hybrid/Remote Options
Robert Half
practice is a part of our overall Technology Consulting Division. The Cyber Security practice includes coverage of focused domains such as Technical Security Assessments, Assessment against cyber security frameworks, PCIDSS assessments, Cloud Security Reviews, Cyber Security Audits, Cyber Security Strategy and Advisory work. Cyber Security is a high-growth area for Protiviti globally. You will be part … other clients. Do Your Talents Include the Following? In-depth knowledge and understanding of industry cyber security frameworks such as ISO 27001, NIST CSF, NIS 2 and/or PCI DSS. Hands-on experience in implementing or assessing against these frameworks is a must-have requirement. Demonstrated ability to lead, manage and develop teams and deliver cybersecurity engagements to … experience, preferably in consulting and/or professional services. Demonstrable track record of continual growth across various roles. Relevant industry certifications such as CISSP, CISM, CISA, ISO 27001 LA, PCIDSS QSA are strongly preferred Offices - The Shard, London - Hybrid/Remote Working £100k-126k, Annual performance bonus & benefits Robert Half Ltd acts as an employment business for More ❯
their main base of operations here, in the UK, as an experienced GRC IT Security Analyst ? Do you have experience in the GRC IT Security space with audits, ISO27001, PCIDSS, SOC2, NIST & current compliance regulations? (Some, or all is fine!) If so & you are looking to expand your IT Security career, meet new team members, embrace new … you’ll already know what the role will entail, but see below for things we’ll need to see in order to be considered: - Knowledge and experience of ISO27001, PCIDSS, SOC2, NIST and CIS benchmarking - Knowledge and experience achieving and maintaining compliance with relevant legislation, such as DPA, GDPR - Knowledge of cloud environments (AWS, Azure) & Windows, &/ More ❯
Central London, London, England, United Kingdom Hybrid/Remote Options
hireful
their main base of operations here, in the UK, as an experienced GRC IT Security Analyst Do you have experience in the GRC IT Security space with audits, ISO27001, PCIDSS, SOC2, NIST & current compliance regulations? (Some, or all is fine!) If so & you are looking to expand your IT Security career, meet new team members, embrace new … you’ll already know what the role will entail, but see below for things we’ll need to see in order to be considered: - Knowledge and experience of ISO27001, PCIDSS, SOC2, NIST and CIS benchmarking - Knowledge and experience achieving and maintaining compliance with relevant legislation, such as DPA, GDPR - Knowledge of cloud environments (AWS, Azure) & Windows, &/ More ❯
with their main base of operations here, in the UK, as an experienced GRC Security Analyst ? Do you have experience in the GRC Security space with audits, auditors, ISO27001, PCIDSS, SOC2, NIST & current compliance regulations? (Some, or all is fine!) If so & you are looking to expand your IT Security career, meet new team members, embrace new … you’ll already know what the role will entail, but see below for things we’ll need to see in order to be considered: - Knowledge and experience of ISO27001, PCIDSS, SOC2, NIST and CIS benchmarking - Knowledge and experience achieving and maintaining compliance with relevant legislation, such as DPA, GDPR - Knowledge of cloud environments (AWS, Azure) & Windows, &/ More ❯
Central London, London, England, United Kingdom Hybrid/Remote Options
hireful
with their main base of operations here, in the UK, as an experienced GRC Security Analyst Do you have experience in the GRC Security space with audits, auditors, ISO27001, PCIDSS, SOC2, NIST & current compliance regulations? (Some, or all is fine!) If so & you are looking to expand your IT Security career, meet new team members, embrace new … you’ll already know what the role will entail, but see below for things we’ll need to see in order to be considered: - Knowledge and experience of ISO27001, PCIDSS, SOC2, NIST and CIS benchmarking - Knowledge and experience achieving and maintaining compliance with relevant legislation, such as DPA, GDPR - Knowledge of cloud environments (AWS, Azure) & Windows, &/ More ❯
City Of London, England, United Kingdom Hybrid/Remote Options
Hamilton Barnes 🌳
suppliers to ensure timely delivery Produce and maintain documentation including roadmaps, risk logs, and reports Ensure all work aligns with frameworks such as Cyber Essential+, ISO 27001, GDPR, and PCIDSS Report progress and risks to senior stakeholders Champion a culture of continuous improvement and security awareness Skills/Must Haves: 5+ years’ experience managing IT or security … stakeholder management and communication skills Experience delivering projects in Agile or hybrid environments Familiarity with Jira, Confluence, or MS Project Understanding of compliance frameworks such as ISO 27001, GDPR, PCIDSS Nice to have: experience with hospitality systems (POS, PMS, or guest management) Contract Details: Duration: 6 months Determination: Inside IR35 Location: London (Hybrid/Remote More ❯
Leeds, Yorkshire, United Kingdom Hybrid/Remote Options
Stott and May
Harden DevSecOps pipelines to ensure secure software delivery. Collaborate with engineering teams to integrate security by design into products. Compliance & Risk Management Ensure regulatory compliance with GDPR, SOC2, ISO, PCI-DSS, and crypto-specific frameworks. Lead risk assessments for third-party vendors and service providers. Work with legal and compliance teams on KYC/AML security for crypto More ❯
Wokingham, Berkshire, England, United Kingdom Hybrid/Remote Options
KBC Technologies UK LTD
VPNs, and WAFs. Develop and manage firewall policies, network access controls, IAM solutions, MFA, RBAC, and privilege management . Ensure alignment of security measures with compliance standards (GDPR, HIPAA, PCIDSS). Conduct regular security audits and assessments to identify and remediate risks. Apply industry frameworks such as NIST Cybersecurity Framework, ISO 27001, CIS Controls . Oversee and More ❯
Banbury, Oxfordshire, United Kingdom Hybrid/Remote Options
Chiltern Railways
to demonstrate equivalent knowledge. Desirable Familiarity with the Microsoft security suite: Defender, InTune, Purview, EntraID, and Azure. Further certifications such as CISSP, CISM, or CRISC are advantageous Familiarity with PCI-DSS standards. Experience influencing cyber security investments and initiatives by providing expert advice to stakeholders and management. Educated to degree level or equivalent. More ❯
Hook Norton, Oxfordshire, United Kingdom Hybrid/Remote Options
Chiltern Railways
to demonstrate equivalent knowledge. Desirable Familiarity with the Microsoft security suite: Defender, InTune, Purview, EntraID, and Azure. Further certifications such as CISSP, CISM, or CRISC are advantageous Familiarity with PCI-DSS standards. Experience influencing cyber security investments and initiatives by providing expert advice to stakeholders and management. Educated to degree level or equivalent. More ❯
City of London, London, United Kingdom Hybrid/Remote Options
TDA TELECOM LIMITED
Design comprehensive security architectures across network, endpoint, identity, cloud, and data protection domains. Ensure alignment with industry frameworks such as NIST, ISO, and CIS, and compliance with regulatory standards (PCI-DSS, HIPAA, etc.). Produce proposals, Bills of Materials (BOMs), high-level designs, and Statements of Work (SOWs). Vendor & Partner Engagement Work with leading vendors (Palo Alto More ❯
Manchester, England, United Kingdom Hybrid/Remote Options
Acumin
IAM, encryption, API security, and application security. Experience performing threat modelling, security risk assessments, and control design validation. In-depth knowledge of industry standards and frameworks (ISO27001, NIST CSF, PCIDSS, CIS Controls). Minimum of 5 years’ experience in information security roles, ideally within financial services or large-scale digital environments. Professional certifications such as CISSP, SABSA More ❯
City of London, London, United Kingdom Hybrid/Remote Options
Acumin
IAM, encryption, API security, and application security. Experience performing threat modelling, security risk assessments, and control design validation. In-depth knowledge of industry standards and frameworks (ISO27001, NIST CSF, PCIDSS, CIS Controls). Minimum of 5 years’ experience in information security roles, ideally within financial services or large-scale digital environments. Professional certifications such as CISSP, SABSA More ❯
IAM, encryption, API security, and application security. Experience performing threat modelling, security risk assessments, and control design validation. In-depth knowledge of industry standards and frameworks (ISO27001, NIST CSF, PCIDSS, CIS Controls). Minimum of 5 years’ experience in information security roles, ideally within financial services or large-scale digital environments. Professional certifications such as CISSP, SABSA More ❯