25 of 25 ISO 27001 Lead Auditor Jobs in London

Senior Security Consultant

Location
City Of London, England, United Kingdom
Define, implement and monitor corporate information security strategies, objectives and governance frameworks. Design and implement information security management systems and security master plans. Lead risk management activities, including risk identification, assessment, treatment and reporting. Define cybersecurity action plans and oversee their execution. Ensure the protection of services … analyses and defining continuity and testing plans. Implement and maintain information security controls aligned with applicable laws, regulations, standards and best practices, including ISO 27001 / 27002, GDPR, Cyber Assessment Framework (CAF) and NIST CSF. Develop and maintain information security policies, standards and procedures ...

Security Engineer, Compliance Focus

Location
Greater London, England, United Kingdom
here is not a paperwork exercise at the edge of the business. It is a condition of doing business. We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure … control is actually working or only described. What You Will Be Doing Compliance Execution Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline. Operate our GRC platform ...

Cyber Security Controls Tester (Assurance)

Location
City Of London, England, United Kingdom
Evaluate the effectiveness of technical, procedural, and physical security controls against documented security requirements and standards. Assess security controls against recognised frameworks including ISO 27001 , NIST CSF , NIST 800-53 , and CIS Controls . Review security documentation, including High-Level Designs (HLDs), Low-Level … Required Skills & Experience Proven experience testing and assessing the effectiveness of security controls within complex enterprise environments. Strong knowledge of security frameworks including: ISO 27001 NIST Cyber Security Framework (CSF) NIST 800-53 CIS Controls Experience reviewing and testing: Network security controls Firewall configurations ...

IT Security Governance, Risk & Controls Analyst

Hiring Organisation
Ricoh
Location
London, United Kingdom
Employment Type
Permanent
plans. Assess the effectiveness of security controls and identify control gaps, weaknesses and opportunities for improvement . Translate security frameworks and requirements, including ISO 27001 and NIST CSF , into practical operational controls. Support audit, assurance and compliance activities , including ISO 27001 … principles . Experience conducting or supporting technology / security risk assessments and maintaining risk registers. Good knowledge of security control frameworks such as ISO 27001 and NIST CSF . Experience assessing control design and effectiveness , identifying gaps and supporting remediation. Understanding ...

Senior GRC Analyst

Location
Greater London, England, United Kingdom
Manage and continuously improve Preply's risk management framework, defining risk management approaches and overseeing the implementation of mitigation actions across the business. Lead risk assessments. Run enterprise risk assessments, surfacing both technical and non-technical risks, and track Key Risk Indicators (KRIs) and other data-driven … governance checks into everyday business operations. Drive SOC 2 and beyond. Support compliance initiatives for SOC 2 Type 2, with potential expansion to ISO 27001, ensuring controls are documented, tested, and audit-ready. Support privacy initiatives. Contribute to data retention policies and guidelines ...

GRC Consultant

Hiring Organisation
Big Red Recruitment
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £70,000 per annum
responsibilities include: Supporting client engagements focused on governance, risk and compliance Advising organisations on cyber security frameworks and standards Supporting and delivering ISO 27001 aligned engagements Conducting cyber security maturity assessments Supporting clients with security governance, resilience and business continuity initiatives Working closely with … consultants and principals across multiple projects Skills & Experience Experience working in cyber security governance, risk and compliance Experience working with frameworks such as ISO 27001 and / or NIST CSF Experience working in a cyber security consultancy or advisory environment is highly desirable Experience ...

GRC Senior Analyst

Location
Greater London, England, United Kingdom
levels and influence outcomes in support of enterprise projects. You will be confident working across the major information security frameworks and standards, including ISO 27001, NIST and SOC 2, and able to shape risk, compliance and control decisions in a way that keeps both … Client Delivery: Provide security subject matter expertise across our internal technology initiatives, collaborating with project managers, business stakeholders and operational teams, and lead client GRC engagements end to end from gap assessment and framework implementation through to audit readiness and ongoing advisory. Measurement and Insight: Maintain ...

Senior Trust Security Analyst

Location
Greater London, England, United Kingdom
teams, ensuring alignment with agreed timelines and compliance requirements. Audit Audit Interpretation: Read and interpret third-party audit reports (SOC 2 Type II, ISO 27001, penetration test summaries) and represent findings to customers in questionnaires and security responses. Communication & Stakeholder Management Information Translation: Gather … Hands-on experience responding to SIG, CAIQ, VSA, and bespoke enterprise / government security questionnaires. Compliance Knowledge: Working knowledge of Cyber Essentials Plus, ISO 27001, SOC 2 Type II, and at least one of PCI DSS, GDPR / UK GDPR, HIPAA, or FedRAMP. Technical ...

IT Security Compliance & Reporting Analyst

Hiring Organisation
Ricoh
Location
London, United Kingdom
Employment Type
Permanent
security and technology risk assessments , working with technical teams to identify appropriate and practical mitigation plans. Support audit, assurance and compliance activities , including ISO 27001, Cyber Essentials and internal control programmes. Translate security frameworks and regulatory requirements into practical, operational standards and controls . … Security Compliance . Experience developing and maintaining security policies, standards, controls and governance documentation . A strong understanding of security frameworks such as ISO 27001 and NIST CSF . Experience producing security compliance reporting, MI or dashboards , ideally using Power BI. Experience managing ...

GRC Assurance Manager

Location
Greater London, England, United Kingdom
design and operate the processes, methodologies, and relationships that enable continuous validation of our security controls, supporting certifications such as TISAX and ISO 21434, meeting customer contractual commitments, and strengthening trust across the organisation. This is an opportunity to build a security assurance capability from the ground … strong governance with the realities of a fast-moving engineering-led organisation. Desirable Experience supporting security assurance programmes for frameworks such as TISAX, ISO 21434, ISO 27001, SOC 2, or similar. Experience helping organisations evolve from periodic assurance towards continuous assurance. ...

GRC Assurance Manager

Location
Greater London, England, United Kingdom
design and operate the processes, methodologies, and relationships that enable continuous validation of our security controls, supporting certifications such as TISAX and ISO 21434, meeting customer contractual commitments, and strengthening trust across the organisation. This is an opportunity to build a security assurance capability from the ground … strong governance with the realities of a fast-moving engineering-led organisation. Desirable Experience supporting security assurance programmes for frameworks such as TISAX, ISO 21434, ISO 27001, SOC 2, or similar. Experience helping organisations evolve from periodic assurance towards continuous assurance. ...

CLOUD SECURITY ARCHITECT

Location
Greater London, England, United Kingdom
reference architectures and reusable solution patterns Define and author enterprise‐level security policies, controls frameworks, and governance documentation aligned to industry standards Lead risk assessments, threat modelling exercises, and security posture evaluations for cloud platforms and SaaS products, utilising methodologies such as FAIR Drive compliance programmes covering … ISO 27001, Cyber Essentials Plus, PCI DSS, and other relevant regulatory frameworks Support DevSecOps adoption and integrate security tooling and controls into CI / CD pipelines across client delivery teams Engage senior stakeholders and executive teams with clear security risk reporting, remediation guidance ...

Third Party Cyber Risk Lead

Hiring Organisation
Hays Technology
Location
City of London, London, Cheap, United Kingdom
Employment Type
Permanent
Salary
£80000 - £90000/annum Up to 90k, plus bonus
Third Party Cyber Risk Lead Please read carefully and contact Lorenz Pasch at Hays on (phone number removed) or if you are from the Insurance or Financial Services sector only, and are interested in the position. London | Hybrid£90,000 + Benefits We are seeking a Third … Party Cyber Risk Lead to take ownership of cybersecurity risk across its supplier and vendor ecosystem. This is a key role within the Business Information Security Office, responsible for ensuring third-party cyber risks are identified, assessed, managed and reported effectively across a complex and regulated insurance ...

Principal Cyber Assurance Advisor (OT/Technical Arch./Supply Chain)

Hiring Organisation
IBEX RECRUITMENT LTD
Location
London, UK
recruiting on behalf of a client in the nuclear / Critical National Infrastructure (CNI) sector for a Cyber Assurance Principal Advisor to lead the delivery of second-line cyber assurance across key domains including OT, technical architecture, and supply chain. This role ensures cyber security controls … verify remediation of assurance findings and contribute to lessons learned Maintain awareness of emerging threats, technologies, and regulatory expectations to inform assurance planning Lead, mentor, and develop a team of cyber assurance advisors to build capability and consistency Promote a culture of cyber risk awareness and accountability ...

AI Security Consultant

Location
Greater London, England, United Kingdom
assurance. Familiarity with frameworks and guidance such as NIST AI RMF, OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, MITRE ATLAS, ISO 27001, NIST CSF, CIS Controls or cloud security frameworks. Experience with SOC operations, SIEM / SOAR platforms, detection engineering, threat … autonomous systems, including least privilege, approval workflows, action limits, logging, monitoring and rollback mechanisms. Relevant certifications such as CISSP, CISM, CCSP, GIAC, ISO 27001 Lead Implementer / Auditor, cloud security certifications or AI / security-focused training. Please ...

Security Consultant – Risk & Resilience - Financial Services

Location
Greater London, England, United Kingdom
cyber risk management, operational resilience, business continuity, disaster recovery, and incident response principles. Knowledge of common security and risk frameworks such as NIST, ISO 27001, COBIT, CIS Controls, and FFIEC guidance. Familiarity with financial services regulatory requirements relating to technology risk and resilience. Experience … enabled tools to improve efficiency, insight generation, or risk management outcomes. Preferred Qualifications Professional certifications such as CISSP, CISM, CRISC, CISA, CBCI, ISO 27001 Lead Implementer / Auditor, or equivalent. Experience supporting regulatory programmes involving PRA, FCA, DORA ...

Security Consultant - Risk & Resilience - Financial Services

Hiring Organisation
Accenture
Location
London, UK
Employment Type
Full-time
cyber risk management, operational resilience, business continuity, disaster recovery, and incident response principles. Knowledge of common security and risk frameworks such as NIST, ISO 27001, COBIT, CIS Controls, and FFIEC guidance. Familiarity with financial services regulatory requirements relating to technology risk and resilience. Experience … enabled tools to improve efficiency, insight generation, or risk management outcomes. Preferred Qualifications: Professional certifications such as CISSP, CISM, CRISC, CISA, CBCI, ISO 27001 Lead Implementer / Auditor, or equivalent. Experience supporting regulatory programmes involving PRA, FCA, DORA ...

Director, Technology, Cyber & Resilience Risk

Location
Greater London, England, United Kingdom
into architecture, engineering and change processes. Partner with 2LOD to ensure alignment with regulatory expectations (e.g. DORA, UK OpRes). Risk Governance & Decisioning Lead 1LoD technology risk governance forums). Provide independent first-line challenge to engineering, architecture, and product teams. Escalate and drive resolution of material … KCIs). Ensure availability of accurate, decision-ready risk data. Drive adoption of data-led risk management across engineering teams. Leadership & Operating Model Lead and develop a high-performing technology risk team. Define clear roles, responsibilities, and RACI across first and second lines. Build risk capability across ...

Director, Technology, Cyber & Resilience Risk

Hiring Organisation
London Stock Exchange Group
Location
London, UK
Employment Type
Full-time
behaviours, and delivery outcomes. Required ExperienceSenior leadership in technology risk within regulated financial services. Ownership of control frameworks aligned to recognised standards (NIST, ISO, COBIT).Strong track record in risk governance and remediation of systemic issues. Operational resilience and incident management expertise. Experience engaging with regulators … executive stakeholders. Cloud and third-party risk oversight. Qualifications & Certifications (preferred)CRISC, CISM, CISSP, ISO 27001 Lead Auditor / Implementer, ITIL Expert. Degree in Computer Science / Engineering or equivalent experience. Skills & AttributesCombines deep risk expertise with engineering ...

Cyber Programmes Consultant

Location
Greater London, England, United Kingdom
requirements, the cyber threat landscape and business priorities Establish effective programme governance, control, reporting, risk management and assurance to support successful delivery outcomes Lead multi-disciplinary teams across cyber security, technology, risk, operations and business functions to deliver transformational change Deliver cyber maturity assessments, security roadmaps, implementation … management skills, with experience coordinating diverse delivery teams and suppliers Relevant cyber security qualifications or certifications such as CISSP, CISM, CRISC, CCSP, SABSA, ISO 27001 Lead Implementer / Auditor, SANS, GIAC certifications or equivalent Up-to-date knowledge ...

Interim Cyber Security Internal Auditor

Location
City Of London, England, United Kingdom
risk, control and governance services, working with clients across a variety of industries and beyond. If you’re an experienced Interim Cybersecurity Internal Auditor who’s tired of choosing between freedom and meaningful work, there’s another route. Within our Business Risk Services team … audits for client organisations in line with UK regulations. Assess compliance against UK GDPR and the Data Protection Act 2018, the NIS Regulations, ISO / IEC 27001, Cyber Essentials and Cyber Essentials Plus, and the Telecommunications (Security) Act 2021. Identify risks, provide actionable ...

Interim Cyber Security Internal Auditor

Hiring Organisation
Grant Thornton
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£550.00 - £750.00 per day
risk, control and governance services, working with clients across a variety of industries and beyond. If you’re an experienced Interim Cybersecurity Internal Auditor who’s tired of choosing between freedom and meaningful work, there’s another route. Within our Business Risk Services team … audits for client organisations in line with UK regulations. · Assess compliance against UK GDPR and the Data Protection Act 2018, the NIS Regulations, ISO / IEC 27001, Cyber Essentials and Cyber Essentials Plus, and the Telecommunications (Security) Act 2021. · Identify risks, provide actionable ...

Senior Cyber Security Consultant

Location
Greater London, England, United Kingdom
facing our clients. Role Tasks and Responsibilities Managing and delivering client projects Delivering projects (e.g., conducting asset identification exercises, cyber risk assessments against ISO and NIST CSF 2.0 standards, and demonstrating cyber audit expertise). Managing different types of client meetings and maintaining positive and respectful client … clients in Europe Undergraduate or post‐graduate degree in a field related to security, information security, intelligence, or computer science. CISSP, CISM, ISO27001 lead auditor, SANs or similar industry qualifications / certifications would be preferred Control Risks offers a competitively positioned compensation and benefits ...

Senior Cyber Security Consultant — Public Sector Impact

Location
Greater London, England, United Kingdom
Your level of experience will determine the amount or responsibility given to you, as a result you may also have the opportunity to lead assignments and be responsible for supervising direct reports whilst ensuring the overall success of the engagement. You will be given the opportunity … such as chartered or principal status with the UK Cyber Security Council, or certifications such as CompTIA, NIST, PCiIAA, CISMP, CISSP, CREST, ISO27001 Lead Implementer / Auditor, SABSA, and TOGAF. A Mentor will be on hand to provide support and guidance throughout your journey ...

Head Of Cyber

Hiring Organisation
Arbuthnot Latham
Location
London, UK
Employment Type
Full-time
that is consistent with achieving good outcomes for consumers; and to comply with the FCA and PRA's Conduct Rules. Job DescriptionKey Responsibilities: Lead and develop the cyber security function, ensuring effective delivery across governance, assurance and operational security disciplines. Deliver the cyber security strategy and roadmap … translate cyber risks into business-focused and regulatory reporting. Qualifications: Minimum of two of the below is required: CISSP CISM CRISC ISO27001 Lead Implementer / AuditorCompetencies: Problem Solving and JudgmentCustomer FocusPlanning and ReviewingPerformance FocusCommunication and ConfidenceAbout UsLife, Work and BenefitsAt Arbuthnot Latham, we seek proactive individuals ...