Guildford, Surrey, England, United Kingdom Hybrid / WFH Options
Sanderson
security controls catalogue, policies, and procedures aligned with NIST CSF Collaborate with business units to integrate security measures into operations Support compliance activities for frameworks such as Cyber Essentials, PCIDSS, and the Group Information Security Framework Facilitate reviews and updates to ensure controls remain effective against evolving threats Essential skills: Minimum 2 year's experience in information … controls catalogue in a financial services environment (highly desirable) Proven experience in delivering security projects within a federated organisation Desirable skills: Knowledge of NIST CSF, ISO 27001, Cyber Essentials, PCIDSS, DORA Understanding of risk methodologies and data analysis for reporting Strong documentation skills (control matrices, process flows, SOPs) Excellent communication skills for both technical and non-technical More ❯
optimise payment processes, ensuring transactions run smoothly and reliably. Share your expertise with the team through code reviews, documentation, and knowledge-sharing sessions. Implement industry-standardsecurity practices, including PCIDSS considerations, fraud prevention, and rate limiting. Integrate with third-party payment gateways and APIs while ensuring compliance with local and international regulations. Partner with product managers to … issues for non-technical audiences. Collaborative mindset with openness to feedback and new ideas. Strong problem-solving skills with both critical and creative thinking. Familiarity with compliance frameworks (GDPR, PCIDSS, PSD2). Experience handling multiple currencies, sales tax, 3D Secure, tokenization, fraud prevention, and disputes/chargebacks. Bonus Points Experience with brewing PHP fixes while fending off More ❯
on time, within scope, and to a high standard. Specialist Migration Expertise: Oversee the secure migration of card credentials, encryption keys, and other sensitive financial data, ensuring compliance with PCIDSS and relevant regulatory requirements. Card Scheme Migration Processes: Manage migration activities in line with card scheme processes, procedures, and compliance standards. Liaise with scheme representatives to coordinate … reconciliation methodologies. Excellent stakeholder management skills, including board-level engagement. Strong problem-solving ability and resilience under pressure. Desirable Experience in a payments or card-issuing environment. Knowledge of PCIDSS compliance requirements. Familiarity with other card scheme migration processes (Visa, Amex). PRINCE2, PMP, or Agile project management certification. Why Apply? This is an opportunity to join More ❯
on time, within scope, and to a high standard. Specialist Migration Expertise: Oversee the secure migration of card credentials, encryption keys, and other sensitive financial data, ensuring compliance with PCIDSS and relevant regulatory requirements. Card Scheme Migration Processes: Manage migration activities in line with card scheme processes, procedures, and compliance standards. Liaise with scheme representatives to coordinate … reconciliation methodologies. Excellent stakeholder management skills, including board-level engagement. Strong problem-solving ability and resilience under pressure. Desirable Experience in a payments or card-issuing environment. Knowledge of PCIDSS compliance requirements. Familiarity with other card scheme migration processes (Visa, Amex). PRINCE2, PMP, or Agile project management certification. Why Apply? This is an opportunity to join More ❯
Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
Queen Square Recruitment Limited
Application SecurityData Protection & Encryption Kubernetes, Containers, and DevSecOps/MLOps practices SIEM, logging, and monitoring Zero Trust architectures Skilled in applying frameworks such as NIST CSF, ISO 27001, PCIDSS, CSA CCM, NIST AI RMF . Hands-on with tools for vulnerability management, secrets management, CSPM, and CWPP . Relevant certifications strongly preferred (CISSP, CCSP, TOGAF, AWS More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
initiatives, including migration of legacy applications to cloud-native platforms and adoption of SaaS/PaaS solutions. Understanding of UK financial regulations, GDPR, and industry standards (ISO 27001, NIST, PCIDSS, etc). Experience running risk assessments, threat modelling, and security testing programmes. Ability to engage and influence senior stakeholders, balancing security with commercial and operational priorities. Strong More ❯
Employment Type: Permanent, Part Time, Work From Home
London, South East, England, United Kingdom Hybrid / WFH Options
Sanderson
artefacts including standards and blueprints. What You'll Bring Prior and proven experience gained as a Security Architect or in a technical cyber role. Expertise in: Security legislation (GDPR, PCIDSS, ICO) Frameworks (ISO 27001, NIST CSF, CIS Controls v8) HMG/NCSC policies and guidance Cloud security (AWS, Azure) Microservice architectures PKI, Cryptography, Privileged Access Management Certifications More ❯
Leeds, Yorkshire, United Kingdom Hybrid / WFH Options
William Hill PLC
design and implementation of security solutions Proficient in security modelling, frameworks, and tools (e.g., SparxEA, Archi) with deep knowledge of security principles, methodologies, and industry standards (NIST, ISO 27001, PCI-DSS, GDPR) Skilled in threat and risk modelling, governance, and aligning security controls with business strategy, regulation, and technical constraints Stakeholder engagement and communication skills, with experience in More ❯
Salford, Greater Manchester, North West, United Kingdom Hybrid / WFH Options
AJ BELL BUSINESS SOLUTIONS LIMITED
risk management tools and techniques Experience of security governance and compliance, ideally gained in financial services organisations Demonstrable understanding of Information Security control standards and frameworks e.g. ISO27001, NIST, PCIDSS Awareness and understanding of the Information Security threat landscape Deep understanding of Information Security solutions and controls Experience of Cloud security solutions and standards is highly advantageous More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Sanderson Government and Defence
Lead roles JSP440, JSP604/453 & JSP490 Working with system secure design MOD/GDS Secure by Design Principles Supplier Chain Assurance and Risks. Security related legislation (e.g. GDPR, PCIDSS, ICO requirements). Security Control Frameworks such as ISO 27001, NIST CSF and CIS Controls v8. HMG, NPSA and NCSC security policies, standards and guidance. Have experience More ❯
newport, midlands, united kingdom Hybrid / WFH Options
Intellectual Property Office
team at the Intellectual Property Office. Playing a key part in an established team, the individual is responsible for ensuring the continued compliance with key security standards, such as PCI, ISO27001, secure by design, GovAssure etc. It is essential that this role ensures that security architecture alongside compliance are understood and therefore the role will include championing security by … but are not limited to: Ensure security architecture aligns with wider Gov security policies and frameworks, legal frameworks, industry regulations and best practise (e.g ISO 27001, NCSC Standards, GDPR, PCIDSS, GovAssure, Secure by Design). Support the secure by design champion in building awareness and understanding of secure by design framework across DDaT. Manage the security architecture More ❯
Hull, North Humberside, England, United Kingdom Hybrid / WFH Options
Heron Foods
incident response, containment, and recovery activities. Oversee vulnerability management: assessing risks, tracking remediation, and validating fixes. Support forensic investigations and evidence handling when needed. Contribute to compliance activities including PCIDSS evidence gathering and audit readiness. Deliver security awareness training, phishing simulations, and staff engagement campaigns. Provide local insights to the Group Information Security team to strengthen overall … experience: Experience working in security operations, SOC, or incident response. Knowledge of SIEM tools, vulnerability management, and log analysis. Understanding of security frameworks such as ISO 27001, NIST, or PCI DSS. Strong communication skills to engage with IT teams, business stakeholders, and non-technical staff. Ability to work independently at Heron Foods while remaining aligned to Group Information Security. More ❯
North Ferriby, North Humberside, North East, United Kingdom Hybrid / WFH Options
Heron Foods
incident response, containment, and recovery activities. Oversee vulnerability management: assessing risks, tracking remediation, and validating fixes. Support forensic investigations and evidence handling when needed. Contribute to compliance activities including PCIDSS evidence gathering and audit readiness. Deliver security awareness training, phishing simulations, and staff engagement campaigns. Provide local insights to the Group Information Security team to strengthen overall … experience: Experience working in security operations, SOC, or incident response. Knowledge of SIEM tools, vulnerability management, and log analysis. Understanding of security frameworks such as ISO 27001, NIST, or PCI DSS. Strong communication skills to engage with IT teams, business stakeholders, and non-technical staff. Ability to work independently at Heron Foods while remaining aligned to Group Information Security. More ❯
incident response, containment, and recovery activities. Oversee vulnerability management: assessing risks, tracking remediation, and validating fixes. Support forensic investigations and evidence handling when needed. Contribute to compliance activities including PCIDSS evidence gathering and audit readiness. Deliver security awareness training, phishing simulations, and staff engagement campaigns. Provide local insights to the Group Information Security team to strengthen overall … experience: Experience working in security operations, SOC, or incident response. Knowledge of SIEM tools, vulnerability management, and log analysis. Understanding of security frameworks such as ISO 27001, NIST, or PCI DSS. Strong communication skills to engage with IT teams, business stakeholders, and non-technical staff. Ability to work independently at Heron Foods while remaining aligned to Group Information Security. More ❯
Basingstoke, Hampshire, England, United Kingdom Hybrid / WFH Options
Oliver James
and integrations with modern platforms (Azure, Data Lake, Fabric). Manage BAU operations: patching, security updates, backups and incident resolution. Partner with teams and providers to ensure governance, GDPR, PCI-DSS compliance and operational excellence. Support new change deployments and contribute to the cloud and automation journey. What we're looking for Deep expertise in Microsoft SQL Server More ❯
South East London, London, United Kingdom Hybrid / WFH Options
TEN10 SOLUTIONS LIMITED
Understanding of IAM, WAF, and KMS. Experience implementing best practices for securing data, ensuring compliance with industry standards and regulations. Bonus points for experience with a compliance framework (ISO27001, PCI-DSS). Infrastructure-as-Code: Mastery of Terraform, CloudFormation, CDK or equivalent tools. Scripting & Automation: Skills in a scripting language like Python, Ansible, Bash, Groovy, Powershell, or similar. More ❯
Understanding of IAM, WAF, and KMS. Experience implementing best practices for securing data, ensuring compliance with industry standards and regulations. Bonus points for experience with a compliance framework (ISO27001, PCI-DSS). Infrastructure-as-Code: Mastery of Terraform, CloudFormation, CDK or equivalent tools. Scripting & Automation: Skills in a scripting language like Python, Ansible, Bash, Groovy, Powershell, or similar. More ❯
ensuring that systems are highly available, auto scalable, self-healing, secure and operate with 99.99% uptime Production deployments with zero downtime & automated rollback procedures Change control procedures to meet PCI requirements 3rd line technical support for infrastructure related issues Build, deploy, and maintain our AWS infrastructure using Infrastructure-as-Code Develop, maintain & support infrastructure and application deployment pipelines logging More ❯
Market Harborough, Leicestershire, East Midlands, United Kingdom Hybrid / WFH Options
4C Resourcing
Lead and deliver client engagements across governance, risk and compliance (GRC), including audits, assessments and improvement plans aligned to frameworks such as ISO/IEC 27001, NCSC CAF, and PCI DSS. Lead independent assurance , review and test security policies, procedures and controls; identify gaps; and recommend pragmatic remediation strategies. Develop and present security strategies that enhance resilience and reduce … near term). Significant experience in cyber security consulting or assurance, ideally within the public sector. Deep knowledge of GRC frameworks and standards ( e.g. CAF, ISO/IEC 27001, PCIDSS). Strong client-facing skills , able to communicate complex issues clearly to technical and non-technical audiences. Proven track record of delivering high-quality outputs on time More ❯
Oxford, Oxfordshire, United Kingdom Hybrid / WFH Options
Nomios
assurance services, we offer an incredible opportunity to be part of an experienced team, build your skills, and grow professionally. Dionach by Nomios holds impressive certifications, including CREST, CHECK, PCI QSA, and ISO 27001. With our focus on enhancing customers' security and fostering team development, you'll be joining a company that prioritizes both your growth and the safety More ❯
Understanding of IAM, WAF, and KMS. Experience implementing best practices for securing data, ensuring compliance with industry standards and regulations. Bonus points for experience with a compliance framework (ISO27001, PCI-DSS). I nfrastructure-as-Code: Experience with Terraform, CloudFormation, CDK or equivalent tools. Scripting & Automation: Skills in Python, Ansible, Bash, Groovy, Powershell, or similar. Bonus points if More ❯
UX, QA, and business stakeholders. Champion software engineering best practice, Agile delivery, and secure development standards. Ensure system availability, performance, resilience and compliance with UK regulations including GDPR and PCI-DSS. About You: 10+ years in software development, including at least 3 years in an E-commerce software development management role. Proven experience delivering secure, high-traffic retail websites More ❯
Bradford, West Yorkshire, Yorkshire, United Kingdom Hybrid / WFH Options
Exalto Consulting ltd
UX, QA, and business stakeholders. Champion software engineering best practice, Agile delivery, and secure development standards. Ensure system availability, performance, resilience and compliance with UK regulations including GDPR and PCI-DSS. About You: 10+ years in software development, including at least 3 years in an e-commerce software development management role. Proven experience delivering secure, high-traffic retail websites More ❯
Harrogate, North Yorkshire, Yorkshire, United Kingdom Hybrid / WFH Options
WRK DIGITAL LTD
and the department, ensuring they are regularly reviewed, updated, and consistently applied to support high-quality, maintainable, and secure code. Ensure adherence to standards and regulation including to ISO27001, PCIDSS, and GDPR. Ensure quality and compliance across the development lifecycle, working closely with Test Analysts to validate solutions. Manage version control, documentation, and release processes, partnering closely More ❯
Starbeck, North Yorkshire, UK Hybrid / WFH Options
WRK DIGITAL LTD
and the department, ensuring they are regularly reviewed, updated, and consistently applied to support high-quality, maintainable, and secure code. Ensure adherence to standards and regulation including to ISO27001, PCIDSS, and GDPR. Ensure quality and compliance across the development lifecycle, working closely with Test Analysts to validate solutions. Manage version control, documentation, and release processes, partnering closely More ❯