and security baselines across multi-project/multi-subscription environments. Collaborate with compliance, risk and audit teams to team to translate regulatory requirements (e.g. SOC2, ISO 27001, HIPPA, GDPR, PCIDSS) into technical controls in the cloud. Adherence and experience of compliance frameworks (e.g. CIS Benchmarks, NIST 800-53). Building or maintaining automated continuous compliance monitoring solutions More ❯
City of London, England, United Kingdom Hybrid / WFH Options
VE3
to work independently. Preferred Qualifications AWS Certified SysOps Administrator/DevOps Engineer – Professional. Experience with hybrid cloud/on-prem environments. Exposure to compliance frameworks (e.g., ISO 27001, GDPR, PCI-DSS). Benefits Work on cutting-edge technologies and impactful projects. Opportunities for career growth and development. Collaborative and inclusive work environment. Competitive salary and benefits package. Seniority More ❯
models aligning with MITRE ATTACK/STRIDE frameworks. Recommend the best controls & mitigations to potential vulnerabilities Ensure the design comply with relevant regulations and standards, including GDPR, SOX, and PCI-DSS. Implement advanced encryption and access control mechanisms to safeguard data integrity and confidentiality. Implement Cloud Security controls through Firewalls and leverage Defender for Cloud capabilities in the Security …/knowledge/experience: Should have proven experience as a Security Architect working in a large, complex organization. Ideally, this experience would be within a financially regulated enterprise (e.g., PCI compliance). Proven experience working previously for financial organizations. Previous relevant experience in developing bespoke Threat Models leveraging frameworks like MITRE ATTACK & STRIDE. Proficiency in assessing the Identity & Access … working in UK Financial Services or similar highly regulated industry. Have a relevant professional qualification (or be working towards certification), such as CISM/CISSP. Knowledge/experience of PCI-DSS, including PCI-P qualification. Knowledge/experience of Data privacy and GDPR. Experience with regulatory compliance frameworks specific to financial organizations. Excellent interpersonal and communication skills. More ❯
Azumi collection has 41 venues worldwide across five unique brands—including Zuma, ROKA, Oblix, Inko Nito, and Etaru. What you will do: Lead our global cybersecurity strategy, aligning with PCIDSS, GDPR, ISO27001, and evolving regulatory requirements. Own incident response and risk mitigation, overseeing system security across POS, Azure, networks, and customer data platforms. Collaborate cross-functionally with … Champion a security-first culture, driving awareness, training, and the adoption of modern threat detection and prevention tools. What we look for: Strong understanding of compliance standards such as PCIDSS, GDPR, SOC2, ISO27001, Cyber Essentials Excellent verbal and written communication skills Experience with Azure At least 2 years’ experience in cybersecurity Experience with Cisco/Meraki networks More ❯
Azumi collection has 41 venues worldwide across five unique brands—including Zuma, ROKA, Oblix, Inko Nito and Etaru. What you will do: Lead our global cybersecurity strategy , aligning with PCIDSS, GDPR, ISO27001, and evolving regulatory requirements. Own incident response and risk mitigation , overseeing system security across POS, Azure, networks, and customer data platforms. Collaborate cross-functionally with … Champion a security-first culture , driving awareness, training, and the adoption of modern threat detection and prevention tools. What we look for: Strong understanding of compliance standards such as PCIDSS, GDPR, SOC2, ISO27001, Cyber Essentials Impressive verbal and written communication skills Experience with Azure CSSIP/CSIM/CompTIA+ or equivalent qualification 2 years’ experience in cyber More ❯
Azumi collection has 41 venues worldwide across five unique brands—including Zuma, ROKA, Oblix, Inko Nito and Etaru. What you will do: Lead our global cybersecurity strategy , aligning with PCIDSS, GDPR, ISO27001, and evolving regulatory requirements. Own incident response and risk mitigation , overseeing system security across POS, Azure, networks, and customer data platforms. Collaborate cross-functionally with … Champion a security-first culture , driving awareness, training, and the adoption of modern threat detection and prevention tools. What we look for: Strong understanding of compliance standards such as PCIDSS, GDPR, SOC2, ISO27001, Cyber Essentials Impressive verbal and written communication skills Experience with Azure CSSIP/CSIM/CompTIA+ or equivalent qualification 2 years’ experience in cyber More ❯
Antom, WorldFirst and ANEXT Bank. Role Overview: As a Lead Cyber Security Specialist, you will ensure alignment with European regulations (e.g., GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCIDSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party risk , outsourcing compliance , and identity governance to safeguard operational resilience. What … Support compliance with GDPR and complementary regulations like DORA (Digital Operational Resilience Act) , ensuring alignment in areas such as incident reporting and data protection. Translate requirements from PSD2 SCA , PCIDSS , and SWIFT CSP into technical security controls. Maintain IT security governance frameworks (ISO 27001, NIST CSF, CIS Controls). Manage and maintain Security Policies and procerdures Third … with least privilege principles and regulatory requirements. Security awareness management experience. What we are looking for: 5+ years in GRC roles ; financial services or banking. Understanding of GDPR , DORA , PCIDSS, and outsourcing/third-party risk requirements. Hands-on experience with ISO 27001 implementation and third-party risk tools . Proficiency in IAM (Identity and Access Management More ❯
Antom, WorldFirst and ANEXT Bank. Role Overview: As a Lead Cyber Security Specialist, you will ensure alignment with European regulations (e.g., GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCIDSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party risk , outsourcing compliance , and identity governance to safeguard operational resilience. What … Support compliance with GDPR and complementary regulations like DORA (Digital Operational Resilience Act) , ensuring alignment in areas such as incident reporting and data protection. Translate requirements from PSD2 SCA , PCIDSS , and SWIFT CSP into technical security controls. Maintain IT security governance frameworks (ISO 27001, NIST CSF, CIS Controls). Manage and maintain Security Policies and procerdures Third … with least privilege principles and regulatory requirements. Security awareness management experience. What we are looking for: 5+ years in GRC roles ; financial services or banking. Understanding of GDPR , DORA , PCIDSS, and outsourcing/third-party risk requirements. Hands-on experience with ISO 27001 implementation and third-party risk tools . Proficiency in IAM (Identity and Access Management More ❯
Antom, WorldFirst and ANEXT Bank. Role Overview: As a Lead Cyber Security Specialist, you will ensure alignment with European regulations (e.g., GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCIDSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party risk , outsourcing compliance , and identity governance to safeguard operational resilience. What … Support compliance with GDPR and complementary regulations like DORA (Digital Operational Resilience Act) , ensuring alignment in areas such as incident reporting and data protection. Translate requirements from PSD2 SCA , PCIDSS , and SWIFT CSP into technical security controls. Maintain IT security governance frameworks (ISO 27001, NIST CSF, CIS Controls). Manage and maintain Security Policies and procerdures Third … with least privilege principles and regulatory requirements. Security awareness management experience. What we are looking for: 5+ years in GRC roles ; financial services or banking. Understanding of GDPR , DORA , PCIDSS, and outsourcing/third-party risk requirements. Hands-on experience with ISO 27001 implementation and third-party risk tools . Proficiency in IAM (Identity and Access Management More ❯
businesses: Alipay+, Antom, WorldFirst and ANEXT Bank. Role Overview: As a GRC Lead, you will ensure alignment with European regulations (e.g., GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCIDSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party risk, outsourcing compliance, and identity governance to safeguard operational resilience. What … Support compliance with GDPR and complementary regulations like DORA (Digital Operational Resilience Act), ensuring alignment in areas such as incident reporting and data protection. Translate requirements from PSD2 SCA, PCIDSS, and SWIFT CSP into technical security controls. Maintain IT security governance frameworks (ISO 27001, NIST CSF, CIS Controls). Manage and maintain Security Policies and procedures Third … requirements. Security awareness management experience. What we are looking for: Experience: 5+ years in GRC roles; financial services or banking experience is a strong plus. Understanding of GDPR, DORA, PCIDSS, and outsourcing/third-party risk requirements. Hands-on experience with ISO 27001 implementation and third-party risk tools. Proficiency in IAM (Identity and Access Management) solutions More ❯
businesses: Alipay+, Antom, WorldFirst, and ANEXT Bank. Role Overview: As a GRC Lead , you will ensure alignment with European regulations (e.g., GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCIDSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party risk , outsourcing compliance , and identity governance to safeguard operational resilience. What … Support compliance with GDPR and complementary regulations like DORA (Digital Operational Resilience Act) , ensuring alignment in areas such as incident reporting and data protection. Translate requirements from PSD2 SCA , PCIDSS , and SWIFT CSP into technical security controls. Maintain IT security governance frameworks (ISO 27001, NIST CSF, CIS Controls). Manage and maintain Security Policies and procedures. Third … management experience. What we are looking for: Experience: 5+ years in GRC roles; financial services or banking experience is a strong plus . Regulatory Knowledge: Understanding of GDPR , DORA , PCIDSS, and outsourcing/third-party risk requirements. Technical Skills: Hands-on experience with ISO 27001 implementation and third-party risk tools . Proficiency in IAM (Identity and More ❯
businesses: Alipay+, Antom, WorldFirst and ANEXT Bank. Role Overview: As a GRC Lead , you will ensure alignment with European regulations (e.g., GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCIDSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party risk , outsourcing compliance , and identity governance to safeguard operational resilience. What … Support compliance with GDPR and complementary regulations like DORA (Digital Operational Resilience Act) , ensuring alignment in areas such as incident reporting and data protection. Translate requirements from PSD2 SCA , PCIDSS , and SWIFT CSP into technical security controls. Maintain IT security governance frameworks (ISO 27001, NIST CSF, CIS Controls). Manage and maintain Security Policies and procerdures Third … with least privilege principles and regulatory requirements. Security awareness management experience. What we are looking for: 5+ years in GRC roles ; financial services or banking. Understanding of GDPR , DORA , PCIDSS, and outsourcing/third-party risk requirements. Hands-on experience with ISO 27001 implementation and third-party risk tools . Proficiency in IAM (Identity and Access Management More ❯
businesses: Alipay+, Antom, WorldFirst and ANEXT Bank. Role Overview: As a GRC Lead, you will ensure alignment with European regulations (e.g., GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCIDSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party risk, outsourcing compliance, and identity governance to safeguard operational resilience. What … Support compliance with GDPR and complementary regulations like DORA (Digital Operational Resilience Act), ensuring alignment in areas such as incident reporting and data protection. Translate requirements from PSD2 SCA, PCIDSS, and SWIFT CSP into technical security controls. Maintain IT security governance frameworks (ISO 27001, NIST CSF, CIS Controls). Manage and maintain Security Policies and procedures Third … requirements. Security awareness management experience. What we are looking for: Experience: 5+ years in GRC roles; financial services or banking experience is a strong plus. Understanding of GDPR, DORA, PCIDSS, and outsourcing/third-party risk requirements. Hands-on experience with ISO 27001 implementation and third-party risk tools. Proficiency in IAM (Identity and Access Management) solutions More ❯
Azumi collection has 41 venues worldwide across five unique brands—including Zuma, ROKA, Oblix, Inko Nito and Etaru. What you will do: Lead our global cybersecurity strategy , aligning with PCIDSS, GDPR, ISO27001, and evolving regulatory requirements. Own incident response and risk mitigation , overseeing system security across POS, Azure, networks, and customer data platforms. Collaborate cross-functionally with … Champion a security-first culture , driving awareness, training, and the adoption of modern threat detection and prevention tools. What we look for: Strong understanding of compliance standards such as PCIDSS, GDPR, SOC2, ISO27001, Cyber Essentials Impressive verbal and written communication skills Experience with Azure 2 years’ experience in cyber security Experience with Cisco/Meraki network, Oracle More ❯
your existing skills while developing new ones, contributing to the strategic security objectives of the Company and ensuring adherence to critical accreditations, including ISO 27001, GDPR, Cyber Essentials, and PCI DSS. The successful candidate will demonstrate: Strong analytical skills with a meticulous approach to identifying and resolving security issues. Excellent verbal and written communication abilities, with a knack for … expertise in information security. Happy to travel occasionally to other sites as required. Desirable Experience: Demonstrable expertise in external audit, compliance, and security processes (ISO27001, GDPR, Cyber Essentials and PCIDSS). Microsoft accreditation or other recognised certifications (e.g. Microsoft Learning, CISA, CISM, CRISC, CCSP) would be very beneficial. Benefits: £25,000 - £35,000 salary depending on experience. More ❯
Information Security Analyst in cybersecurity and GRC, ideally in a high-growth tech environment. Strong knowledge of cloud (AWS), application, infrastructure, and network security. Familiarity with paymentsecurity standards (PCIDSS) and threat landscapes. Excellent problem-solving, attention to detail, and communication skills. A self-starter who thrives in a fast-paced environment. Even if you do not More ❯
to apply for the Senior Cyber Security Analyst - AWS - Manchester role at Circle Group . Overview We are seeking a Senior Cyber Security Analyst with a strong background in PCIDSS and AWS cloud environments to join our UK cybersecurity team. This role involves advising on security best practices, managing vulnerabilities, ensuring compliance with security standards such as … NIST, ISO, and PCIDSS, and leading audits. The position reports to the UK Head of Security and involves consulting with global clients across the Americas and EMEA regions. Skills & Experience Minimum 4 years of experience in Cyber Security within an AWS cloud environment Experience with CrowdStrike is a plus Proven experience with PCIDSS compliance … Vulnerability management and compliance expertise Leadership in audit processes Knowledge of security standards including GDPR, ISO, PCI, NIST Excellent stakeholder communication and training skills Relevant cybersecurity certifications are desirable Location & Work Environment This role is primarily onsite at our Central Manchester office, requiring attendance 3-4 days per week. The office is a vibrant space with forward-thinking professionals. More ❯
Birmingham, England, United Kingdom Hybrid / WFH Options
Kerv Digital for Digital Transformation
for customer-readiness SQL Azure, Synapse Analytics (dataflows, Jupyter notebooks, on-demand SQL), Databricks, ADF Power BI, DAX, data flows SSIS Appreciation of information security standards such as ISO27001, PCI-DSS or Cyber Essentials BPSS clearance will be required on start Desirable experience: At least 3 years of public sector experience Azure data certifications (DP-203, DP More ❯
diligence and data related functions. Risk Management & Governance: Support the implementation and management of regional third-party risk management activities, which includes performing third-party risk assessments. Experience with PCI compliance. Manage, lead, and conduct PCI assessment for the different countries in scope partnering with app owners and payment gateway solutions. Help build the regional data loss prevention … security, IT risk management, or a similar role, with demonstrated experience in business partnering or liaison functions. Experience with cybersecurity principles, risk management frameworks (e.g., NIST CSF, CIS v8, PCI , etc.), and security technologies. Familiarity with AI concepts, AI-specific security risks, and AI governance frameworks (e.g., NIST AI RMF, EU AI Act principles). Experience with AI securityMore ❯
SMEs to embrace change and find new and better ways of implementing their systems? This may be your dream job. Foregenix is recruiting an experienced cybersecurity consultant with active PCIDSS certifications , solid technical experience across several cybersecurity programs & frameworks, and years of meeting the needs of demanding customers. The job requires a strong character and amazing natural … develop internal resources and deliver top quality service. Key Responsibilities Provide current and relevant cybersecurity advice and remediation support to our customers Execute other types of cybersecurity programs assessments (PCI, NIST, CMMC, etc.) across a range of industries Manage unexpected project conditions during client engagements, work with your team and escalate early Perform scoping reviews and gap assessments, support More ❯
/or workload transition. - Notable consulting experience and collaboration skills. - Experience advising customers on architectures and practices meeting industry standards/frameworks, such as PSPF, ISM, ISO 27k, SOC, PCI-DSS, NIST CSF, etc. - Familiarity with availability concepts and archive, backup/recovery and business continuity processes. - Demonstrated ability to think strategically about business, product, and technical challenges. More ❯
London, England, United Kingdom Hybrid / WFH Options
ManpowerGroup
GDPR-related activities, and handling Subject Access Requests, including providing guidance and documentation on the legal basis for each process. Ensuring compliance with legislation/standards such as GDPR, PCIDSS etc. What We Are Looking For? 5+ years in an information Security Manager Not Highly Technical: The ideal candidate is not expected to be overly technical. Instead … in the context of the UK market. Some technical competency is necessary Self-sufficient, can work autonomously without support in a standalone role. Detailed knowledge of GDPR legislation and PCIDSS framework Experience managing audits against frameworks such CIS, NIST or similar along with implementation of ISO 27001 is beneficial/advantageous. If you feel this role is More ❯
Birmingham, England, United Kingdom Hybrid / WFH Options
Turnitin
Responsibilities: Maintain compliance tracking capabilities to help ensure adherence with Turnitin’s security program and industry standards such as NIST CSF, NIST 800-53, SOC 2, TX-RAMP and PCI DSS. Conduct risk and compliance assessments, audits, and risk evaluations to identify potential risk and compliance gaps. Lead preparation and audit activities required to maintain our SOC 2 Type … Compliance. Professional certification such as CCSK, AWS Cloud Practitioner, or other related industry certification. Familiarity with cybersecurity frameworks and regulatory standards such as NIST, SOC 2, TX-RAMP, and PCI DSS. Familiarity of risk management and security best practices. Experience with assessing security controls, risk mitigation strategies, and audit procedures. Understanding of concepts related to AWS Cloud Infrastructure and More ❯
Manchester, England, United Kingdom Hybrid / WFH Options
Turnitin
Responsibilities: Maintain compliance tracking capabilities to help ensure adherence with Turnitin’s security program and industry standards such as NIST CSF, NIST 800-53, SOC 2, TX-RAMP and PCI DSS. Conduct risk and compliance assessments, audits, and risk evaluations to identify potential risk and compliance gaps. Lead preparation and audit activities required to maintain our SOC 2 Type … Compliance. Professional certification such as CCSK, AWS Cloud Practitioner, or other related industry certification. Familiarity with cybersecurity frameworks and regulatory standards such as NIST, SOC 2, TX-RAMP, and PCI DSS. Familiarity of risk management and security best practices. Experience with assessing security controls, risk mitigation strategies, and audit procedures. Understanding of concepts related to AWS Cloud Infrastructure and More ❯
Newcastle upon Tyne, England, United Kingdom Hybrid / WFH Options
Turnitin
Responsibilities: Maintain compliance tracking capabilities to help ensure adherence with Turnitin’s security program and industry standards such as NIST CSF, NIST 800-53, SOC 2, TX-RAMP and PCI DSS. Conduct risk and compliance assessments, audits, and risk evaluations to identify potential risk and compliance gaps. Lead preparation and audit activities required to maintain our SOC 2 Type … Compliance. Professional certification such as CCSK, AWS Cloud Practitioner, or other related industry certification. Familiarity with cybersecurity frameworks and regulatory standards such as NIST, SOC 2, TX-RAMP, and PCI DSS. Familiarity of risk management and security best practices. Experience with assessing security controls, risk mitigation strategies, and audit procedures. Understanding of concepts related to AWS Cloud Infrastructure and More ❯