implementation of IS/IT security restructure programmes, projects of both a GRC and technical nature alongside frameworks such as ISO27001/2:2005/13, DORA, NIS 2, PCI-DSS, GDPR-DPO, NIST CSF SP800-53, PSD-2, FCA/PRA, and MS Azure. Ownership of Strategic, Operational, and Tactical IT Security and Risk Management, technical and More ❯
London, England, United Kingdom Hybrid / WFH Options
FirstBank UK Limited
degree, preferably in Computer Science, Cyber Security or Cyber Security Professional Qualifications/Certifications Desirable: General understanding of IT Security principles, standards and regulations (e.g. ISO 27001, NIST, CIS, PCIDSS and GDPR) CISM/CISSP Patch Management Applications, EDR/XDR systems. Antivirus, NAC - Forescout Vulnerability Scanning Tool e. Tenable One, Qualisys Knowledge of vulnerability scoring systems More ❯
London, England, United Kingdom Hybrid / WFH Options
The Curve Group
degree, preferably in Computer Science, Cyber Security or Cyber Security Professional Qualifications/Certifications Desirable: General understanding of IT Security principles, standards and regulations (e.g. ISO 27001, NIST, CIS, PCIDSS and GDPR) CISM/CISSP Patch Management Applications, EDR/XDR systems. Antivirus, NAC - Forescout Vulnerability Scanning Tool e. Tenable One, Qualisys Knowledge of vulnerability scoring systems More ❯
ensure adequate protection of sensitive information. Translate security requirements into architectural blueprints and patterns, balancing risk, budget, and operational challenges. Ensuring compliance with regulatory standards such as GDPR and PCI DSS. Provide subject matter expertise and assess security measures, recommending improvements in collaboration with IT teams. Build and maintain relationships with technology vendors and business partners. In conjunction with More ❯
London, England, United Kingdom Hybrid / WFH Options
McCabe & Barton
Working remotely with occasional be in office in Essex. What You’ll Do Assess compliance with internal security policies and industry standards (e.g., ISO/IEC 27001/2, PCI-DSS). Conduct supplier risk assessments and third-party due diligence. Support vulnerability assessments, incident investigations, and operational resilience activities. Monitor the effectiveness of security controls to ensure … Experience first and second line support Strong analytical thinking and attention to detail. Familiarity with compliance frameworks like ISO 27001/27002, NIST Cybersecurity Framework – 2.0 ideally version 2, PCIDSS v4.0 Exceptional communication and stakeholder engagement skills. Financial services/FCA experience Desirable: Experience with Microsoft Azure Security tools (Defender for Endpoint, Sentinel, Purview). Understanding of More ❯
services include: Strategy & transformation On-demand virtual roles Data discovery and mapping Risk advisory and assurance Continuity/Resilience Data privacy and GDPR ISO 27001 & NIST CSF Supplier assurance PCI, PA & P2PE Incident response planning Card production audits Cyber security review SOC advisory & implementation XDR consulting & implementation Alongside our core services, we have a range of bespoke services to … learn new skills and disciplines. Knowledge Experience in two or more of the below: Excellent attention to detail and documentation. Industry standards such as ISO 27001 Series, GDPR, NIST, PCI DSS. Customer facing experience at senior levels. CISSP/CISM/ISO 27001 LA or LI/PCIDSS QSA would be an advantage Outputs Ability to More ❯
services include: Strategy & transformation On-demand virtual roles Data discovery and mapping Risk advisory and assurance Continuity/Resilience Data privacy and GDPR ISO 27001 & NIST CSF Supplier assurance PCI, PA & P2PE Incident response planning Card production audits Cyber security review SOC advisory & implementation XDR consulting & implementation Alongside our core services, we have a range of bespoke services to … learn new skills and disciplines. Knowledge Experience in two or more of the below: Excellent attention to detail and documentation. Industry standards such as ISO 27001 Series, GDPR, NIST, PCI DSS. Customer facing experience at senior levels. CISSP/CISM/ISO 27001 LA or LI/PCIDSS QSA would be an advantage Outputs Ability to More ❯
services include: Strategy & transformation On-demand virtual roles Data discovery and mapping Risk advisory and assurance Continuity/Resilience Data privacy and GDPR ISO 27001 & NIST CSF Supplier assurance PCI, PA & P2PE Incident response planning Card production audits Cyber security review SOC advisory & implementation XDR consulting & implementation Alongside our core services, we have a range of bespoke services to … learn new skills and disciplines. Knowledge Experience in two or more of the below: Excellent attention to detail and documentation. Industry standards such as ISO 27001 Series, GDPR, NIST, PCI DSS. Customer-facing experience at senior levels. CISSP/CISM/ISO 27001 LA or LI/PCIDSS QSA would be an advantage Outputs Ability to More ❯
as part of a team Ability to travel to meet business needs Preferred competencies: Relevant cyber security or other qualifications, certifications such as CSX-P, CDPSE, SSCP, CAP, OWASP, PCIDSSSecurity Cleared with potential to gain enhanced clearances Experience implementing privacy solutions based on the requirements of the EU GDPR and UK Data Protection Act 2018 Good More ❯
core consulting and implementation services include: On-demand virtual roles Data discovery and mapping Risk advisory and assurance Continuity/Resilience Data privacy and GDPR ISO 27001 & NIST CSF PCI, PA & P2PE Cyber security review SOC advisory & implementation XDR consulting & implementation Alongside our core services, we have a range of bespoke services to help organisations protect their systems and … learn new skills and disciplines. Knowledge Experience in two or more of the below: Excellent attention to detail and documentation. Industry standards such as ISO 27001 Series, GDPR, NIST, PCI DSS. CISSP/CISM/ISO 27001 LA or LI/PCIDSS QSA would be an advantage Ability to successfully compile accurate reports within defined timescales. More ❯
London, England, United Kingdom Hybrid / WFH Options
Smart Communications group
Engineer with designing, innovating, deploying, and maintaining security measures to safeguard our information assets. We operate in a highly secure global SaaS organization that has multiple certifications such as PCI-DSS, ISO/IEC 27001, SOC & HIPAA & IRAP standards to adhere to, as well as a large, federated customer base that we strive to embed improvements for. You … on a variety of challenging projects, with multiple security tools. Have a proven track record of successes. Knowledge of security compliance standards relevant to the SaaS industry, such as PCI, GDPR, ISO 27001, SOC2, NIST. An understanding of application security principles, best practices, OWASP/related standards. Some knowledge/experience in scoping/undertaking internal pen testing and More ❯
Broad knowledge of cyber security concepts including cryptography, authentication and authorization, access control, secure architectures, threat modeling, vulnerabilities and software security. Strong knowledge of regulatory requirements (e.g. GDPR, ISO27001, PCI-DSS) and experience in regulatory reporting. 3-5 years of experience in GRC, risk management, or compliance. A bachelor's degree in computer science, Cyber Security or similar More ❯
nice to have. SKILLS: Working knowledge of cloud security architecture, specifically within Azure (or other Cloud platforms). Familiarity with security frameworks and compliance standards such as NIST, GDPR, PCI-DSS, DESC ISR. Strong problem-solving skills, with the ability to think creatively to solve complex security challenges. BENEFITS: Competitive Salary: Base salary commensurate with experience, plus performance More ❯
nice to have. SKILLS: Working knowledge of cloud security architecture, specifically within Azure (or other Cloud platforms). Familiarity with security frameworks and compliance standards such as NIST, GDPR, PCI-DSS, DESC ISR. Strong problem-solving skills, with the ability to think creatively to solve complex security challenges. BENEFITS: Competitive Salary: Base salary commensurate with experience, plus performance More ❯
London, England, United Kingdom Hybrid / WFH Options
Hastings Direct
with Infrastructure-as-Code (e.g., Bicep, ARM templates, Terraform). Hands-on experience with SIEM tools, ideally Azure Sentinel. Understanding of regulatory and compliance frameworks (e.g., CIS Benchmarks, HIPAA, PCI-DSS). Excellent problem-solving skills, communication, and the ability to explain technical concepts to non-technical stakeholders. Desirable: Relevant certifications such as AZ-500, SC-100, or More ❯
Bexhill, England, United Kingdom Hybrid / WFH Options
Vxplore
with Infrastructure-as-Code (e.g., Bicep, ARM templates, Terraform). Hands-on experience with SIEM tools, ideally Azure Sentinel. Understanding of regulatory and compliance frameworks (e.g., CIS Benchmarks, HIPAA, PCI-DSS). Excellent problem-solving skills, communication, and the ability to explain technical concepts to non-technical stakeholders. Desirable: Relevant certifications such as AZ-500, SC-100, or More ❯
Liverpool, Lancashire, United Kingdom Hybrid / WFH Options
Techwaka
practices Provide specialist security support to IT teams, including infrastructure, development, and database teams Work with stakeholders to maintain compliance with industry standards such as ISO27001, Cyber Essentials Plus, PCI/DSS Stay ahead of cyber threats, maintaining and improving security monitoring and risk management processes Support vulnerability management, penetration testing, and incident response Requirements for this role More ❯
Liverpool, England, United Kingdom Hybrid / WFH Options
Techwaka
practices Provide specialist security support to IT teams, including infrastructure, development, and database teams Work with stakeholders to maintain compliance with industry standards such as ISO27001, Cyber Essentials Plus, PCI/DSS Stay ahead of cyber threats, maintaining and improving security monitoring and risk management processes Support vulnerability management, penetration testing, and incident response Requirements for this role More ❯
London, England, United Kingdom Hybrid / WFH Options
Barclay Simpson
Terraform, or XSOAR. Collaborate with infrastructure and DevOps teams to embed security into CI/CD pipelines, containers (GKE), and API services. Compliance & Risk Alignment Ensure operational alignment with PCI-DSS, ISO 27001, SOC 2, NIST, and GDPR requirements. Support internal and external audits with relevant security evidence and reports. Work closely with GRC teams to implement controls … response and recovery Security orchestration (SOAR), preferably Chronicle + XSOAR IAM, policy enforcement, logging, and access reviews in GCP Proven experience working in FinTech or financial services, ideally under PCI-DSS, ISO 27001, or SOC 2. Strong Scripting or automation experience (Python, Terraform, Bash). Knowledge of threat modelling and attack frameworks (MITRE ATT&CK, Kill Chain). More ❯
controls e.g. encryption, masking and pseudonymisation. Detailed understanding of the information lifecycle and the self assurance framework for Records Management. Experience of implementing datasecurity standards such as ISO27001, PCIDSS, NIST CSF, CAA CAF etc. Ability to effectively manage cyber security risks and can clearly communicate with key stakeholders to minimise the risk to easyJet. DESIRABLE SKILLS More ❯
controls e.g. encryption, masking and pseudonymisation. Detailed understanding of the information lifecycle and the self assurance framework for Records Management. Experience of implementing datasecurity standards such as ISO27001, PCIDSS, NIST CSF, CAA CAF etc. Ability to effectively manage cyber security risks and can clearly communicate with key stakeholders to minimise the risk to easyJet. DESIRABLE SKILLS More ❯
London, England, United Kingdom Hybrid / WFH Options
Starling Bank
while contributing to open-source tools so we can utilise them Experience in automating security controls and compliance checks against standards and frameworks which include SOC 2, ISO 27001, PCIDSS/3DS Thorough understanding of the incident response process (preparation, identification, containment, eradication, recovery, lessons learned) What skills are desirable: Hands on experience taking your company through … security and compliance frameworks like NIST, SOC2, ISO27001, PCI-DSS Experience with Infrastructure as Code and infrastructure provisioning tools (Cloudformation, Terraform) Expertise in Kubernetes, securing clusters and meshes (Cilium is preferable), networking best practices and RBAC implementation (CKA, CKS qualifications are a plus) Container security knowledge including container image provenance (e.g. Sigstore, Notary) with an in-depth knowledge More ❯
controls e.g. encryption, masking and pseudonymisation. · Detailed understanding of the information lifecycle and the self assurance framework for Records Management. · Experience of implementing datasecurity standards such as ISO27001, PCIDSS, NIST CSF, CAA CAF etc. · Ability to effectively manage cyber security risks and can clearly communicate with key stakeholders to minimise the risk to easyJet. DESIRABLE SKILLS More ❯
necessary ● Drive implementation of cybersecurity policies and standards across News UK. Proactively identify non-compliance and areas of potential improvement, and facilitate development and deployment of standard solutions ● Oversee PCI, SOX, and any other required legal and/or compliance requirements, support internal technology audits, as well as support Privacy on GDPR and other similar requirements ● Provide regular and … s degree in Technology, Legal, Computer Science/Engineering, Cybersecurity, a related field or experience ● Must have a strong understanding of security compliance, policy management, security frameworks (NIST, ISO27001, PCI etc) and regulations. ● Solid foundation of security architectures and cloud computing environments ● Excellent communication skills. Ability to effectively communicate, both orally and in writing, through all levels of the More ❯
AWS. Good understanding of AWS serverless security controls. Good understanding of software development processes. Experience with ISO 27001 or SOC 2 implementations and maintenance. Knowledge of paymentsecurity standards (PCIDSS). Awareness of the security threat landscape. Good attention to detail and outstanding communication skills. Self-starter and strong problem-solving abilities. Security/DevSecOps tooling experience More ❯