Maidenhead, Royal Borough of Windsor and Maidenhead, Berkshire, United Kingdom
Kensington Mortgages
Lambda, Elastic Search, Kibana and Kinesis. AWS certification. Knowledge of AWS Workforce Management tools including Quality Monitoring scorin Experience with working in a regulated financial services environment including ISO27001, PCI-DSS and Sarbanes Oxley. Experience with Microsoft technologies including Microsoft Teams direct routing, Microsoft 365 and Azure Entra ID. Experience with Avaya Aura solutions/Verint WFM Applications More ❯
teams, embedded in the delivery model. Experience with Kubernetes, Openshift, Service Mesh. Experience with clouds (AWS, Azure, GCP). Experience with getting or maintaining certified standards (i.e. ISO 27001, PCIDSS, MIL-SPEC). Example technologies: IAM: Key Cloak, ForgeRock, Okta, Azure Active Directory B2C, x509 Mutual TLS (OpenId Connect/OIDC/SAML). Secrets: AWS KMS More ❯
and security baselines across multi-project/multi-subscription environments. Collaborate with compliance, risk and audit teams to team to translate regulatory requirements (e.g. SOC2, ISO 27001, HIPPA, GDPR, PCIDSS) into technical controls in the cloud. Adherence and experience of compliance frameworks (e.g. CIS Benchmarks, NIST 800-53). Building or maintaining automated continuous compliance monitoring solutions More ❯
Security Architect - NIST, ISO27001, PCI-DSS, Cloud Up to £640 per day (Outside IR35) London/Primarily Remote 6 months My client is an International Consultancy who require a Security Architect to lead security design, engineering, testing and implementation for a major, complex programme. Key Requirements: Proven expertise in Security Architecture Strong working knowledge of cloud security architecture … including authentication, authorisation, encryption, network security, and application security Previous experience of designing and implementing security solutions with a strong understanding of security frameworks including CIS, NIST, ISO27001 and PCIDSS Excellent communication skills with the ability to communicate technical terms to non-technical audiences Nice to have: Immediate availability Working knowledge of GIS/ESRI products Previous More ❯
and develop effective mitigation strategies Experience in handling datasecurity incidents involving data loss or breaches Knowledge of data protection regulations and standards, such as GDPR, CCPA, HIPAA, and PCI-DSS. Strong analytical and problem-solving skills with a keen attention to detail in identifying and addressing datasecurity issues Excellent verbal and written communication skills, with the ability More ❯
London, England, United Kingdom Hybrid / WFH Options
Help Me Settle Ltd
a 24/7 offshore Cyber Security Operations Centre (SOC). Managing budgets for cyber and data TFA accounts and G&A compliance. Ensuring compliance with IT SOX and PCIDSS audits for the UK&I market. Sponsoring key cyber, data, and risk projects. Maintaining project governance and building vendor relationships to explore innovation and manage third-party More ❯
of security controls and identify weaknesses. Security Compliance: Ensure that applications comply with relevant security standards, regulations, and industry best practices, such as OWASP Top 10, OWASP ASVS, MAVS, PCIDSS, and GDPR. Security Architecture: Assist in designing and implementing secure application architectures, including authentication mechanisms, access controls, encryption, and secure communication protocols. Incident Response: Collaborate with incident … effectively collaborate with cross-functional teams and communicate technical concepts to non-technical stakeholders. Desirable Skills and Experience Knowledge of relevant regulatory requirements and compliance standards, such as GDPR, PCIDSS, and ISO 27001. What’s in it for you? The chance to make a real impact in a growing start-up on a mission to change the More ❯
Newbury, Berkshire, United Kingdom Hybrid / WFH Options
Vodafone Group Plc
ISO/IEC 27001, SOC 2, SOX, ITIL, COBIT, and NIST. Knowledge of legal, regulatory and privacy requirements, such as Personally Identifiable Information (PII) Protection and PaymentCardIndustry (PCI)/DataSecurityStandard An ability to think strategically and drive change A deep understanding of Tech Security risks and mitigating solutions A diverse security background with knowledge in More ❯
layers Ability to effectively detect, investigate, and respond to security incidents in line with incident response frameworks and methodologies Understanding of security frameworks, standards, and regulations (e.g., ISO 27001, PCIDSS, NIST, GDPR) Understanding of secure coding practices and web application vulnerabilities Understanding of security policy development and implementation Proactive approach, ability to analyse complex security issues and More ❯
layers Ability to effectively detect, investigate, and respond to security incidents in line with incident response frameworks and methodologies Understanding of security frameworks, standards, and regulations (e.g., ISO 27001, PCIDSS, NIST, GDPR) Understanding of secure coding practices and web application vulnerabilities Understanding of security policy development and implementation Proactive approach, ability to analyse complex security issues and More ❯
businesses: Alipay+, Antom, WorldFirst and ANEXT Bank. Role Overview: As a GRC Lead, you will ensure alignment with European regulations (e.g., GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCIDSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party risk, outsourcing compliance, and identity governance to safeguard operational resilience. What … Support compliance with GDPR and complementary regulations like DORA (Digital Operational Resilience Act), ensuring alignment in areas such as incident reporting and data protection. Translate requirements from PSD2 SCA, PCIDSS, and SWIFT CSP into technical security controls. Maintain IT security governance frameworks (ISO 27001, NIST CSF, CIS Controls). Manage and maintain Security Policies and procedures Third … requirements. Security awareness management experience. What we are looking for: Experience: 5+ years in GRC roles; financial services or banking experience is a strong plus. Understanding of GDPR, DORA, PCIDSS, and outsourcing/third-party risk requirements. Hands-on experience with ISO 27001 implementation and third-party risk tools. Proficiency in IAM (Identity and Access Management) solutions More ❯
London, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
team: Data Protection, SOC, GRC, DevSecOps, and more. Embed security into our digital transformation: cloud platforms, customer data, loyalty, payments. Govern and assure compliance with regulatory frameworks including GDPR, PCI-DSS, NIS2, ISO 27001, and evolving UK/EU legislation. Manage strategic security vendor relationships, budgets, and toolsets to ensure capability, scalability, and cost-efficiency. What We’re More ❯
Certifications: Professional certifications such as CISSP, CISM, CISA, or equivalent are advantageous, but not essential. Regulatory Knowledge: Demonstrated experience with industry standards and frameworks such as ISO 27001, SOC, PCI-DSS, GDPR and other relevant regulations is desirable. Audit and Assessment: Proven track record of conducting or defending successful security audits, compliance assessments and risk management activities. Technical More ❯
Birmingham, England, United Kingdom Hybrid / WFH Options
Ampa Group
to senior management and the board. What you will need: Leadership experience managing Information Security teams. Deep knowledge of security standards, tools, and processes. Understanding of GDPR, COBIT, ISO27001, PCIDSS, Cyber Essentials, and risk frameworks. Hands-on experience with security technologies and products. Knowledge of Business Continuity Management and crisis response. Membership or qualification in IISP or More ❯
risks and mitigations. Maintain knowledge of security threats, vulnerabilities, and compliance standards. Lead efforts in security monitoring and incident response. Support security risk management and compliance with standards like PCI, GDPR, ISO. Perform other duties as assigned. Qualifications 10+ years of experience in information security, including vulnerability assessment, incident response, and audits. 5+ years working with business leadership and … in a complex environment. Knowledge of security technologies and concepts such as firewalls, intrusion detection, encryption, cloud security, and risk assessment. 3+ years in security compliance and audit support (PCIDSS, GDPR, etc.). Bachelor’s degree in IT or Security, with relevant certifications like CISSP, CRISC, or CISA. Additional notes Ideal candidates are self-starters with multi More ❯
that may include but not limited to; Business Leaders, IT/Security Leaders, Legal etc. Collaborate with businesses to ensure compliance with industry standards and regulations, such as ISO27001, PCI-DSS, GDPR etc. Qualifications: Degree or Diploma in Computer Science, Information Security, or a related field. At least 5 years of experience in a security engineering role. Strong … knowledge of security technologies and concepts, such as Identity Management, SIEM, Encryption, Vulnerability Management, Secure Coding Standards etc. Familiarity with compliance standards and regulations, such as ISO27001, PCI-DSS, and GDPR. Experience with security assessments, penetration testing, and incident response. Excellent communication and collaboration skills, with the ability to work effectively with stakeholders at all levels of the More ❯
Information Security Management System), ensuring it remains fit for purpose as we scale. Maintain and advance compliance across ISO 27001, SOC2, Cyber Essentials, GDPR, and any emerging frameworks (e.g. PCIDSS, AI governance), ensuring we are audit-ready. Identify, assess, and mitigate security risks across infrastructure, systems, and vendors - flagging and resolving vulnerabilities before they become problems. Own … Essential Experience as an InfoSec expert - ideally within a high-growth SaaS or B2B tech environment. Strong working knowledge of compliance frameworks (e.g. ISO 27001, SOC2Cyber Essentials) and ideally PCI DSS. Working knowledge of GDPR, with experience supporting or overseeing data protection practices. Hands-on experience with security tooling and SaaS security systems. Confident in managing compliance audits, access More ❯
London, England, United Kingdom Hybrid / WFH Options
Coalfire Systems, Inc
account relationships and identifies upsell and cross sell opportunities and escalates to sales. Travel 25-50%. Ability to be successful when working remotely. What You'll Bring Current PCI-QSA certification preferred (will consider former QSA) One of the following Information Security certifications required: CISSP, CISM or ISO 27001 Lead Implementer. One of the following Audit certifications required … ISMS Auditor or higher, or ISO 27001 Lead Auditor. Bachelor's degree (four-year college or university) or equivalent combination of education and work experience. Strong knowledge of the PCI-DSSsecurity standards. 5+ years of experience in an IT Security Audit and/or Compliance role. Experience preparing and presenting Tier 1 and Tier 2 Reports on More ❯
required Strong analytical, organizational, and problem-solving skills are required Must be highly flexible and adaptable to change Experience in a highly regulated environment, specific experience with FFIEC, OSFI, PCI-DSS, SOX preferred Skills/Qualifications Proven work experience. Information Security Certification Working With Us As a Northern Trust partner, greater achievements await. You will be part of More ❯
or other cybersecurity certifications. Experience with scripting languages (Python, PowerShell, etc.). Hands-on experience in a security operations or related role. Knowledge of regulatory compliance frameworks (e.g., GDPR, PCI-DSS, CyberEssentials). A willingness to travel within the UK if required is essential when being considered for this post. Devonshire is an equal-opportunity employer, and we More ❯
Experience: Applicants should have 2-5 years experience in cyber security or technology risk management Knowledge of information security standards and frameworks (., ISO/IEC 27001/27002, PCI-DSS, NIST Cybersecurity Framework, or attestation reports (., SOC 1/2) Understanding of risk management process and principles. Proficient use of personal computers and Microsoft Office Suite More ❯
Capable of implementing SecOps/DevSecOps practices from scratch, implementing, maintaining, and scaling them out across teams and the company Familiarity with Security compliance frameworks (e.g. NIST, ISO 27001, PCIDSS, GDPR) You are collaborative, keen to learn and quick to adapt Additional information: This role may require travel from time to time for team get-togethers or More ❯
Centers, we offer a complete end-to-end security services covering our clients’ security from every angle. Our services include Managed Security, Cyber Security Testing, Incident Response, Security Integration, PCI Compliance and Cyber Risk & Assurance services. What sets Integrity360 apart is our excellent team of people that drive the business forward. The company was founded with a focus on More ❯
experience in Information Security and Risk Management within complex organisations Strong communication and stakeholder engagement skills Familiarity with cloud and hybrid security models Understanding of regulatory compliance (e.g., GDPR, PCIDSS) Knowledge of frameworks like ISO 27001, NIST, CIS, or COBIT If keen please apply! Seniority level Seniority level Mid-Senior level Employment type Employment type Full-time More ❯
Centers, we offer a complete end-to-end security services covering our clients’ security from every angle. Our services include Managed Security, Cyber Security Testing, Incident Response, Security Integration, PCI Compliance and Cyber Risk & Assurance services. What sets Integrity360 apart is our excellent team of people that drive the business forward. The company was founded with a focus on More ❯