/cyber security projects and challenges, preferably over a number of industry domains Strong understanding of leading cybersecurity frameworks and standards such as ISO27001, NIST, Cyber Essentials+, CAF, CIS, SOC2, etc. Up-to-date knowledge of cyber/information security, concepts, risk, controls, and industry trends Experience of working on e.g., security governance models and frameworks, policies More ❯
/cyber security projects and challenges, preferably over a number of industry domains Strong understanding of leading cybersecurity frameworks and standards such as ISO27001, NIST, Cyber Essentials+, CAF, CIS, SOC2, etc. Up-to-date knowledge of cyber/information security, concepts, risk, controls, and industry trends Experience of working on e.g., security governance models and frameworks, policies More ❯
e.g. CISSP, CISM, ISO27001 Lead Auditor/Implementer, Cloud Security Practitioner ). Strong working knowledge of key frameworks and standards including ISO27001, Cyber Essentials, CIS Critical Controls, NIST CSF, SOC2 , and Data Protection requirements ( DPA/GDPR ). Outstanding communication and relationship-building skills — able to influence, challenge constructively, and engage with both technical teams and senior leadership. More ❯
e.g. CISSP, CISM, ISO27001 Lead Auditor/Implementer, Cloud Security Practitioner ). Strong working knowledge of key frameworks and standards including ISO27001, Cyber Essentials, CIS Critical Controls, NIST CSF, SOC2 , and Data Protection requirements ( DPA/GDPR ). Outstanding communication and relationship-building skills — able to influence, challenge constructively, and engage with both technical teams and senior leadership. More ❯
s Information Security function and maintain/improve its security posture Take the lead in responding to customer security questionnaires or audit follow ups Oversee our regular ISO27001 andSOC2 Type II audits Research and choose technical tools to proactively detect and respond to weaknesses, threats and potential compromises Lead the development, implementation, and continuous improvement of More ❯
Oxford, Oxfordshire, United Kingdom Hybrid/Remote Options
La Fosse Associates
Senior DevSecOps Engineer - Global Health Data Platform Location: Oxford or London (hybrid: 3 office/2 WFH) Join a world-class research and technology organisation using data and AI to tackle global challenges - from health and food security to climate and clean energy. They're now hiring a Senior DevSecOps Engineer to help build and secure this cloud-first … Develop CI/CD pipelines (e.g., GitHub Actions) with built-in security testing. Support data scientists and engineers in deploying secure, automated workflows. Implement monitoring and compliance (ISO 27001, SOC2, GDPR). Mentor engineers on DevSecOps best practices. What you'll bring Strong cloud experience (ideally OCI ). Industry experience in the pharma space Hands-on with More ❯
logging tools. Lead incident detection and response, including root-cause analysis and remediation tracking. Maintain Humanoid’s information security risk register and control library. Drive readiness for ISO 27001, SOC2, and GDPR compliance. Deliver staff security-awareness and phishing-simulation programmes. Partner with Engineering to align product and corporate security practices. Networking & Connectivity Manage office and lab … efficiencies through the deployment of AI solutions Knowledge of ITIL or other IT service management frameworks, particularly incident/change management. Exposure to compliance frameworks such as ISO 27001, SOC2, or NIST. Prior experience scaling IT teams from small core functions into mature multi-discipline organisations. What We Offer Competitive salary plus participation in our Stock Option Plan. Paid vacations. More ❯
City of London, London, United Kingdom Hybrid/Remote Options
Humanoid
logging tools. Lead incident detection and response, including root-cause analysis and remediation tracking. Maintain Humanoid’s information security risk register and control library. Drive readiness for ISO 27001, SOC2, and GDPR compliance. Deliver staff security-awareness and phishing-simulation programmes. Partner with Engineering to align product and corporate security practices. Networking & Connectivity Manage office and lab … efficiencies through the deployment of AI solutions Knowledge of ITIL or other IT service management frameworks, particularly incident/change management. Exposure to compliance frameworks such as ISO 27001, SOC2, or NIST. Prior experience scaling IT teams from small core functions into mature multi-discipline organisations. What We Offer Competitive salary plus participation in our Stock Option Plan. Paid vacations. More ❯
Newcastle Upon Tyne, Tyne and Wear, England, United Kingdom
Opus Recruitment Solutions Ltd
am looking for an infrastructure engineer to join a 6 month contracting within the public sector.Inside IR35Till 13th March 2026Onsite aspect in Newcastle £466 per day Tech stack Minimum 2 years of professional experience in cloud security, specifically within AWS environments, demonstrating a track record of implementing and managing comprehensive security strategies. Experience leading projects with a focus on … at rest and in transit. Experience with AWS Key Management Service (KMS) and AWS Certificate Manager (ACM). Knowledge of compliance requirements that impact cloud security (e.g., GDPR, HIPAA, SOC2) and experience in implementing controls to meet these requirements. Ability to design and execute incident response strategies within the AWS cloud, including the use of AWS CloudWatch More ❯
trust and accountability. Shape how the team works together, setting the cadence, communication flow, and rituals that make execution smooth and transparent. 4. Governance, Compliance & Risk Maintain Trudenty's SOC2and ISO 27001 frameworks, keeping our compliance and security posture strong as we scale. Manage the compliance calendar, coordinate audits, and ensure cross functional accountability for controls … the founder , helping translate vision into execution and shaping how the company scales in its next phase of growth. Our offer: Cash: £80 100k (depending on experience) Equity : 1 2%, on a standard vesting schedule Impact & exposure : Lead from the front, driving delivery and execution of high impact pilots and operational initiatives that shape how Trudenty scales Growth : Scope More ❯
Company description: Founded and headquartered in Switzerland, Avaloq is continuously expanding its global footprint with around 2,500 colleagues in 12 countries, and more than 170 clients in 35 countries. We are an industry-leading provider of wealth management technology and services for financial institutions around the world, including private banks and wealth managers, investment managers, as well as … and risk assessment solutions It would be a real bonus if you have: Master's degree in Computer Science, Information Security, or a related field Experience or understanding of SOC2and DORA regulation What we offer: We realize that managing work life balance is a challenge we all face in our daily lives and in order to More ❯
City of London, London, United Kingdom Hybrid/Remote Options
Crimson
GDPR, HIPAA, and OWASP, as well as leading risk assessments and managing the risk register. Key skills and responsibilities, Comprehensive knowledge of ISO 27001, NIST CSF, GDPR, HIPAA, SOC2, and OWASP frameworks. Senior Security Analyst/Senior Security Engineer background Proven experience collaborating with software development teams and implementing technical controls. Skilled in articulating technical risks in More ❯
London, South East, England, United Kingdom Hybrid/Remote Options
Crimson
GDPR, HIPAA, and OWASP, as well as leading risk assessments and managing the risk register. Key skills and responsibilities, Comprehensive knowledge of ISO 27001, NIST CSF, GDPR, HIPAA, SOC2, and OWASP frameworks. Senior Security Analyst/Senior Security Engineer background Proven experience collaborating with software development teams and implementing technical controls. Skilled in articulating technical risks in More ❯
technical expertise in core cloud services (e.g. EC2, S3, RDS, Lambda, API Gateway, VPC, Route 53, IAM, CloudFormation, or Terraform). Familiarity with security and compliance frameworks (e.g. CIS, SOC2, HIPAA). Proven success in leading cloud migration projects using tools such as AWS Server Migration Service or AWS Database Migration Service. Hands-on experience with DevOps More ❯
technical expertise in core cloud services (e.g. EC2, S3, RDS, Lambda, API Gateway, VPC, Route 53, IAM, CloudFormation, or Terraform). Familiarity with security and compliance frameworks (e.g. CIS, SOC2, HIPAA). Proven success in leading cloud migration projects using tools such as AWS Server Migration Service or AWS Database Migration Service. Hands-on experience with DevOps More ❯
Woking, Surrey, England, United Kingdom Hybrid/Remote Options
Nomad Foods
across multiple entities and territories, including risk appetite and impact/likelihood calibration. Has familiarity with regulations and standards such as ISO27001, NIST CSF, NIS2, COBIT, ITIL, GDPR, andSOC2, including developing and maintaining frameworks, policies and guidance, and implementation and monitoring strategies. Some of the key skillset required for this position are: Graduate level in Cyber Security, Computer Science More ❯
Manchester, Lancashire, United Kingdom Hybrid/Remote Options
Michael Page (UK)
apply them to supplier oversight. The Successful Applicant Extensive experience in security risk management, particularly in third party and supplier contexts. Strong understanding of frameworks such as ISO27001, ISO27005, SOC2, and NIST. Holds certifications such as CISSP, CISM, or CRISC. Telecoms sector experience is a plus. Skilled in stakeholder engagement and translating technical risks into business language. What's on More ❯
Manchester, Lancashire, England, United Kingdom Hybrid/Remote Options
Michael Page Technology
standards and apply them to supplier oversight. Profile Extensive experience in security risk management, particularly in third-party and supplier contexts. Strong understanding of frameworks such as ISO27001, ISO27005, SOC2, and NIST. Holds certifications such as CISSP, CISM, or CRISC. Telecoms sector experience is a plus. Skilled in stakeholder engagement and translating technical risks into business language. Job Offer Discretionary More ❯
pipelines (GitLab or equivalent), automating builds, tests, and deployments. Implement and maintain Kubernetes clusters (AKS), Docker images, and related infrastructure components. Ensure systems meet security, performance, and compliance standards (SOC2, encryption at rest/in transit). Collaborate with software engineers to align infrastructure delivery with development requirements. Diagnose and resolve infrastructure issues, applying fixes and process improvements. Contribute to More ❯
pipelines (GitLab or equivalent), automating builds, tests, and deployments. Implement and maintain Kubernetes clusters (AKS), Docker images, and related infrastructure components. Ensure systems meet security, performance, and compliance standards (SOC2, encryption at rest/in transit). Collaborate with software engineers to align infrastructure delivery with development requirements. Diagnose and resolve infrastructure issues, applying fixes and process improvements. Contribute to More ❯
City of London, London, United Kingdom Hybrid/Remote Options
RemoteStar
Experience in cybersecurity, risk management, GRC (governance, risk & compliance) or supply-chain risk management. Familiarity with third-party/vendor risk management platforms and frameworks (e.g., NIST, ISO 27001, SOC2, supply-chain risk standards). Understanding of machine-learning/AI concepts (e.g., risk-scoring models, graph analytics, anomaly detection). Experience working with enterprise B2B customers, especially security teams More ❯
Experience in cybersecurity, risk management, GRC (governance, risk & compliance) or supply-chain risk management. Familiarity with third-party/vendor risk management platforms and frameworks (e.g., NIST, ISO 27001, SOC2, supply-chain risk standards). Understanding of machine-learning/AI concepts (e.g., risk-scoring models, graph analytics, anomaly detection). Experience working with enterprise B2B customers, especially security teams More ❯