Birmingham, England, United Kingdom Hybrid / WFH Options
Turnitin
Responsibilities: Maintain compliance tracking capabilities to help ensure adherence with Turnitin’s security program and industry standards such as NIST CSF, NIST 800-53, SOC 2, TX-RAMP and PCI DSS. Conduct risk and compliance assessments, audits, and risk evaluations to identify potential risk and compliance gaps. Lead preparation and audit activities required to maintain our SOC 2 Type … Compliance. Professional certification such as CCSK, AWS Cloud Practitioner, or other related industry certification. Familiarity with cybersecurity frameworks and regulatory standards such as NIST, SOC 2, TX-RAMP, and PCI DSS. Familiarity of risk management and security best practices. Experience with assessing security controls, risk mitigation strategies, and audit procedures. Understanding of concepts related to AWS Cloud Infrastructure and More ❯
Newcastle upon Tyne, England, United Kingdom Hybrid / WFH Options
Turnitin
Responsibilities: Maintain compliance tracking capabilities to help ensure adherence with Turnitin’s security program and industry standards such as NIST CSF, NIST 800-53, SOC 2, TX-RAMP and PCI DSS. Conduct risk and compliance assessments, audits, and risk evaluations to identify potential risk and compliance gaps. Lead preparation and audit activities required to maintain our SOC 2 Type … Compliance. Professional certification such as CCSK, AWS Cloud Practitioner, or other related industry certification. Familiarity with cybersecurity frameworks and regulatory standards such as NIST, SOC 2, TX-RAMP, and PCI DSS. Familiarity of risk management and security best practices. Experience with assessing security controls, risk mitigation strategies, and audit procedures. Understanding of concepts related to AWS Cloud Infrastructure and More ❯
Leeds, England, United Kingdom Hybrid / WFH Options
Turnitin
Responsibilities: Maintain compliance tracking capabilities to help ensure adherence with Turnitin’s security program and industry standards such as NIST CSF, NIST 800-53, SOC 2, TX-RAMP and PCI DSS. Conduct risk and compliance assessments, audits, and risk evaluations to identify potential risk and compliance gaps. Lead preparation and audit activities required to maintain our SOC 2 Type … Compliance. Professional certification such as CCSK, AWS Cloud Practitioner, or other related industry certification. Familiarity with cybersecurity frameworks and regulatory standards such as NIST, SOC 2, TX-RAMP, and PCI DSS. Familiarity of risk management and security best practices. Experience with assessing security controls, risk mitigation strategies, and audit procedures. Understanding of concepts related to AWS Cloud Infrastructure and More ❯
business case to scale and insource CIRT capabilities Driving continuous improvement through post-incident reviews and threat landscape analysis Ensuring compliance with regulatory requirements and frameworks (e.g. GDPR, NIST, PCI-DSS, MITRE ATT&CK) Requirements 5–10 years of experience in Security Operations, CIRT, or senior SOC roles Strong leadership capability or experience managing incident response teams Deep More ❯
London, England, United Kingdom Hybrid / WFH Options
Post Office
Python, Bash). • Experience with a modern programming language, e.g. C#, Java, C++, Go, Rust etc (We use Go + Typescript) • Familiarity with security compliance frameworks (e.g. ISO 27001, PCIDSS, GDPR). • Excellent communication and collaboration skills. About us Post Office is a community staple. We’re trusted. We’re relatable. We’re reliable. We’re steeped More ❯
Manchester, North West, United Kingdom Hybrid / WFH Options
N Brown Group
escalating as required would be beneficial. Experience with SIEM Platforms (ideally Splunk), including working with logs and creating correlation searches and dashboards is a plus. Experience of working within PCIDSS, or other compliance frameworks. Software and Technology SIEM (ideally Splunk) & IaaS (AWS, Azure, GCP) Endpoint Detection and Response (EDR) tools such as MS Defender APT. Network and More ❯
London, England, United Kingdom Hybrid / WFH Options
AtlasEdge
European environment. This requirement will include successfully managing an interesting mix of requirements including client audit activity, coordinating and running operational audits including but not limited to Security (E.G. PCI-DSS, ISAE 3402, ISO/IEC 27001, ENS for Spain), Business Continuity (E.G. ISO 22301, KRITIS) and ESG/Sustainability (E.G. ISO 14001, EcoVadis). The ideal candidate … The ability to develop recommendations that enhance an organisation’s controls and processes Knowledge of Standards : Familiarity with principles and standards necessary for compliance. For example to Security (E.G. PCI-DSS, ISAE 3402, ISO/IEC 27001, ENS for Spain), Business Continuity (E.G. ISO 22301, KRITIS) and ESG/Sustainability (E.G. ISO 14001, EcoVadis). IT Proficiency: excellent More ❯
and access management). Deep understanding of enterprise IT infrastructure (servers, networks, storage, cloud platforms such as AWS, Azure, GCP, etc.). Strong knowledge of regulatory environments (e.g., GDPR, PCI-DSS, SOX, ISO 27001) and operational risk frameworks. Demonstrated experience managing third-party vendors, system integrators, and outsourced service providers. Expertise in programme governance and budgeting, with ability More ❯
BS32, Bradley Stoke, South Gloucestershire, Almondsbury, Gloucestershire, United Kingdom Hybrid / WFH Options
Emponics
on your own initiative as a self-starter Desirable Skills • Understanding of how to build resilient multi-site architectures • Experience and knowledge of cloud security and relevant ISO and PCI compliance requirements • Knowledge of Azure and other cloud providers • Experience of Windows and Linux operating systems • Experience of using Terraform to build, change and version infrastructure. • Experience of container More ❯
Employment Type: Permanent
Salary: £65000 - £75000/annum health, pension, life , hybrid home
London, England, United Kingdom Hybrid / WFH Options
Oracle
data rules and data flows. Collaborate with Technical Leads and internal teams to implement best practices for compliance, data privacy, and protection, against relevant security standards (NIST, ISO-27001, PCI-DSS, HIPAA, FedRAMP) Help with creating tools to help engineering teams identify security-related weaknesses. Monitor the platform & tools for compliance threats and reporting. Create reports for stakeholders. More ❯
Umbrella Company for this role. Key Requirements: - As a QSA you will be responsible for conducting formal assessments of organizations' compliance with the PaymentCardIndustryDataSecurityStandard (PCIDSS). - You will evaluate security controls, identify gaps, and provide guidance to help organizations achieve and maintain compliance. - This role requires deep technical knowledge, strong communication skills … and a commitment to upholding the integrity of the PCIDSS program. Key Responsibilities: - Conduct PCIDSS assessments for merchants and service providers. - Review and validate security controls, policies, and procedures. - Perform onsite inspections, interviews, and technical testing. - Document findings and prepare detailed Reports on Compliance (RoC) and Attestations of Compliance (AoC). - Provide remediation guidance … GIAC). - Minimum of 5 years of experience in IT security, audit, or compliance. - Completed ISA training and certification through PCI SSC. - Strong understanding of internal security controls and PCIDSS requirements. Certifications (Preferred): - CISSP, CISA, CISM, CRISC, CEH, OSCP, or similar. - PCIDSS QSA/ISA certification (mandatory for role). All of our More ❯
external partners, including banks, card issuers and processors, payment processors to gather intelligence on evolving fraud trends. • Regulatory and Compliance Adherence: o Ensure compliance with UK regulations, including GDPR, PCIDSS, and industry best practices related to card fraud prevention. o Keep up to date with relevant legislation, ensuring that fraud detection activities are aligned with legal requirements. … external partners, including banks, card issuers and processors, payment processors to gather intelligence on evolving fraud trends. • Regulatory and Compliance Adherence: o Ensure compliance with UK regulations, including GDPR, PCIDSS, and industry best practices related to card fraud prevention. o Keep up to date with relevant legislation, ensuring that fraud detection activities are aligned with legal requirements. More ❯
London, England, United Kingdom Hybrid / WFH Options
PAYTER
internal IT systems Foster DevSecOps culture and embed security principles across all solutions and IT services Design secure cloud architecture and internal IT infrastructure adhering to paymentindustry standards (PCI-DSS, PCI-PIN, PCI-P2PE) Security Implementation & Operations Provide security requirements and oversight for software, cloud infrastructure, and internal IT projects Harden cloud environments and internal … security risk register for cloud and internal IT with appropriate escalation protocols Develop, document and enforce security policies and procedures compliant with industry regulations for all systems Guide annual PCI audits with external QSAs ensuring coverage of all applicable systems Monitor evolving regulations and maintain compliance roadmap for payment and IT environments Incident Response & Business Continuity Lead full-cycle … Risk Management • Experience implementing security controls for multiple compliance frameworks simultaneously • Knowledge of payment technologies and standards • Experience with security risk quantification methodologies • Understanding of data privacy regulations beyond PCI (e.g., GDPR, CCPA) Incident Response & Forensics • Experience with digital forensics and incident response frameworks • Knowledge of threat hunting techniques and tools • Experience with security automation and orchestration platforms • Understanding More ❯
Maidstone, England, United Kingdom Hybrid / WFH Options
Payter B.V
internal IT systems Foster DevSecOps culture and embed security principles across all solutions and IT services Design secure cloud architecture and internal IT infrastructure adhering to paymentindustry standards (PCI-DSS, PCI-PIN, PCI-P2PE) Security Implementation & Operations Provide security requirements and oversight for software, cloud infrastructure, and internal IT projects Harden cloud environments and internal … security risk register for cloud and internal IT with appropriate escalation protocols Develop, document and enforce security policies and procedures compliant with industry regulations for all systems Guide annual PCI audits with external QSAs ensuring coverage of all applicable systems Monitor evolving regulations and maintain compliance roadmap for payment and IT environments Incident Response & Business Continuity Lead full-cycle … Risk Management ● Experience implementing security controls for multiple compliance frameworks simultaneously ● Knowledge of payment technologies and standards ● Experience with security risk quantification methodologies ● Understanding of data privacy regulations beyond PCI (e.g., GDPR, CCPA) Incident Response & Forensics ● Experience with digital forensics and incident response frameworks ● Knowledge of threat hunting techniques and tools ● Experience with security automation and orchestration platforms ● Understanding More ❯
regular reviews of our current security solutions and processes, identifying opportunities for optimisation Support the business in maintaining and achieving several industry certifications, aligning where appropriate, including NIST, NIS, PCI/DSS, Cyber Essentials Plus and ISO2700 Provide expertise and support in troubleshooting, resolution, mitigation and reporting of any security incidents and root cause analysis. Qualifications, Skills And … working within a Security function Qualifications such as CCNA, CompTIA, ISC, ISACA Scripting (KQL) Experience of working with some/all industry certifications/frameworks such as NIST, NIS, PCI/DSS, Cyber Essentials Plus and ISO2700 About You About Us Over the past 30 years, Beauparc has continued to grow and acquire businesses that all share a More ❯
and data governance good practice in Banking and the established approaches to mitigating these. A deep understanding of information and data risk and control frameworks and standards, e.g. ISO27001, PCIDSS, NIST+. Strong leadership skills and proven ability to build, inspire, direct, motivate and performance-manage a multi-disciplinary team. MSc Information Security/MCIISec/CISSP/ More ❯
stakeholders, translating complex data needs into actionable plans. Mentor and lead data engineers, fostering continuous learning and technical excellence. Ensure compliance with datasecurity , privacy, and regulatory standards (e.g., PCI-DSS , GDPR ). Essential: 7+ years in Data Engineering, with 2+ years in a Principal or Lead role. Proven experience designing and delivering enterprise data strategies . Exceptional More ❯
City of London, London, United Kingdom Hybrid / WFH Options
83data
stakeholders, translating complex data needs into actionable plans. Mentor and lead data engineers, fostering continuous learning and technical excellence. Ensure compliance with datasecurity , privacy, and regulatory standards (e.g., PCI-DSS , GDPR ). Essential: 7+ years in Data Engineering, with 2+ years in a Principal or Lead role. Proven experience designing and delivering enterprise data strategies . Exceptional More ❯
stakeholders, translating complex data needs into actionable plans. Mentor and lead data engineers, fostering continuous learning and technical excellence. Ensure compliance with datasecurity , privacy, and regulatory standards (e.g., PCI-DSS , GDPR ). Essential: 7+ years in Data Engineering, with 2+ years in a Principal or Lead role. Proven experience designing and delivering enterprise data strategies . Exceptional More ❯
stakeholders, translating complex data needs into actionable plans. Mentor and lead data engineers, fostering continuous learning and technical excellence. Ensure compliance with datasecurity , privacy, and regulatory standards (e.g., PCI-DSS , GDPR ). Essential: 7+ years in Data Engineering, with 2+ years in a Principal or Lead role. Proven experience designing and delivering enterprise data strategies . Exceptional More ❯
risk assessments and mitigation plans to address identified threats. Create clear documentation and reports, including audits, assessments, and gap analyses. Oversee compliance with standards such as ISO 27001 and PCI-DSS, ensuring ongoing monitoring and delivery. Communicate effectively with stakeholders at all levels, translating complex security concepts into business terms. Stay informed on legal and regulatory requirements relevant More ❯
South East London, England, United Kingdom Hybrid / WFH Options
83data
stakeholders, translating complex data needs into actionable plans. Mentor and lead data engineers, fostering continuous learning and technical excellence. Ensure compliance with datasecurity , privacy, and regulatory standards (e.g., PCI-DSS , GDPR ). Essential: 7+ years in Data Engineering, with 2+ years in a Principal or Lead role. Proven experience designing and delivering enterprise data strategies . Exceptional More ❯
on an as needed basis. Demonstrated Experience & Attributes Min 3 years' experience in a similar Cyber Security role. Working knowledge of security frameworks, policies and standards such as ISO27001, PCIDSS, Essential Eight, NIST CSF, and MITRE ATT&CK and applying them into operational context. Experience with cloud-based services and technologies. Ability to detect and defend against More ❯
Leeds, Yorkshire, United Kingdom Hybrid / WFH Options
William Hill PLC
regulation influence cybersecurity. Skilled in stakeholder engagement, promoting information security, and working in both agile and waterfall environments, with knowledge of security standards like NIST 800, ISO 27001, and PCI-DSS What we offer Our roles offer more than just a job, you'll become part of our 888 William Hill family! We have created an environment where More ❯