ensure control design adequacy and effectiveness. The role supports RCSA processes and leads evidence-based evaluations. Key Responsibilities: Evaluate and test security controls against NIST 800-53 requirements Execute scheduled control testing, document results, and analyse weaknesses Review and capture control evidence for audit and compliance purposes Collaborate with control More ❯
ensure control design adequacy and effectiveness. The role supports RCSA processes and leads evidence-based evaluations. Key Responsibilities: Evaluate and test security controls against NIST 800-53 requirements Execute scheduled control testing, document results, and analyse weaknesses Review and capture control evidence for audit and compliance purposes Collaborate with control More ❯
ensure control design adequacy and effectiveness. The role supports RCSA processes and leads evidence-based evaluations. Key Responsibilities: Evaluate and test security controls against NIST 800-53 requirements Execute scheduled control testing, document results, and analyse weaknesses Review and capture control evidence for audit and compliance purposes Collaborate with control More ❯
ensure control design adequacy and effectiveness. The role supports RCSA processes and leads evidence-based evaluations. Key Responsibilities: Evaluate and test security controls against NIST 800-53 requirements Execute scheduled control testing, document results, and analyse weaknesses Review and capture control evidence for audit and compliance purposes Collaborate with control More ❯
Central London, London, United Kingdom Hybrid / WFH Options
Police Digital Services
etc.), supporting cloud architecture design, implementation, operations, and automation in Azure AWS and GCP. Strong knowledge and ability to demonstrate the use of the NIST Cyber Security Framework, mapping and translating NIST Cyber Security Controls to other frameworks such as ISO27001 and CIS Top 20 controls, including understanding of the More ❯
and technical teams to ensure security controls are implemented and effective Assist in preparing for and responding to regulatory audits and compliance reviews (e.g., NIST CSF, ISO 27001, DORA, GDPR. ITGC) Maintain and update the information security risk register with appropriate scenarios and control frameworks Conduct regular control testing, evaluation … communications Job Requirements Previous progressive experience in information security risk management, risk management, or compliance Strong understanding of information security frameworks (e.g., ISO 27001, NIST) Experience with GRC tools/platforms Excellent organisational, communication, and documentation skills Ability to work independently and cross-functionally in a fast-paced environment Industry More ❯
Management: directs, develops or maintains organisational cyber and information security policies, standardsand processes, using recognised standards (e.g. the ISO/IEC 27000 family, NIST CSF) where appropriate. Applies recognised cyber and information security standardsand controls within an organisation, programme, project or operation. Applies relevant security classification. Risk Management … data protection, risk management, enterprise IT, legal or (relevant) compliance roles. Strong understanding of security governance, risk, and compliance frameworks such as ISO 27001, NIST 800-53/CSF, NIS/NIS2, DORA, UK CNI/OT/IIOT compliance. Hands-on experience building credibility with external stakeholders, including enterprise More ❯
cyber security audits, ensuring compliance with regulatory and industry standards. Develop and maintain risk management frameworks, aligning with best practices such as ISO 27001, NIST, and GDPR . Collaborate with stakeholders to identify and mitigate cyber risks across digital and operational infrastructures. Provide expert guidance on cyber risk governance , resilience … Other essential skills: Proven experience in cyber security risk management and audit , ideally within regulated industries Strong knowledge of security frameworks, including ISO 27001, NIST, CIS Controls, and GDPR compliance Ability to conduct security assessments, risk analyses, and internal audits Familiarity with security tooling and governance platforms (e.g., SIEM, GRC More ❯
complex third-party audits. Key Responsibilities Cybersecurity Program Evaluation Lead cyber assurance engagements, assessing client cybersecurity programs for compliance with industry standards such as NIST, ISO 27001, and other relevant frameworks. Act as a trusted advisor, ensuring client cybersecurity postures are resilient, compliant, and in line with regulatory requirements. Vulnerability … compliance audits. Proven track record of leading cyber assurance engagements and guiding clients through risk management and compliance processes based on industry frameworks (e.g., NIST, ISO 27001). Expertise in managing third-party audits and ensuring regulatory compliance across audit lifecycles. In-depth understanding of regulatory frameworks, with hands-on More ❯
A leading bank is seeking a skilled Security Operations Manager to strengthen its IT Security team. This role involves optimizing security controls, frameworks, and processes while supporting the integration of new technologies to enhance the bank's security posture. You More ❯
Overview: We’re seeking a proactive and detail-oriented Information Security Analyst to join a London based Banks growing security function. Reporting to the Cyber Security Manager , you will support the daily operational security activities across the business. This role More ❯
Overview: We’re seeking a proactive and detail-oriented Information Security Analyst to join a London based Banks growing security function. Reporting to the Cyber Security Manager , you will support the daily operational security activities across the business. This role More ❯
Overview: We’re seeking a proactive and detail-oriented Information Security Analyst to join a London based Banks growing security function. Reporting to the Cyber Security Manager , you will support the daily operational security activities across the business. This role More ❯
Overview: We’re seeking a proactive and detail-oriented Information Security Analyst to join a London based Banks growing security function. Reporting to the Cyber Security Manager , you will support the daily operational security activities across the business. This role More ❯
to join a growing team within an MSSP. Within this role you will be providing detailed risk assessments, implementing industry-standard security frameworks including NIST, NCSC, and NIS2 as well as actively managing SIEM tools such as QRadar and/or Sentinel. You’ll be working closely with end customer … through regular meetings, strategic updates and consultative insights Lead comprehensive security risk assessments inline with industry standardsand conduct environment reviews ensuring compliance with NIST Frameworks and related standards Oversee and implement SIEM/XDR deployments, custom rule development, and incident response processes acting as a point of escalation and … businesses, perform gap analyses, and create and deliver reports on findings to end customer stakeholders Skills, Experience, and Certifications: Strong understanding of cybersecurity frameworks (NIST CSF, NCSC CAF, NIS2, NIST 800-30) Confident in using risk assessment methodologies (NIST 800-30). Hands-on experience with SIEM/XDR solutions More ❯
to join a growing team within an MSSP. Within this role you will be providing detailed risk assessments, implementing industry-standard security frameworks including NIST, NCSC, and NIS2 as well as actively managing SIEM tools such as QRadar and/or Sentinel. You’ll be working closely with end customer … through regular meetings, strategic updates and consultative insights Lead comprehensive security risk assessments inline with industry standardsand conduct environment reviews ensuring compliance with NIST Frameworks and related standards Oversee and implement SIEM/XDR deployments, custom rule development, and incident response processes acting as a point of escalation and … businesses, perform gap analyses, and create and deliver reports on findings to end customer stakeholders Skills, Experience, and Certifications: Strong understanding of cybersecurity frameworks (NIST CSF, NCSC CAF, NIS2, NIST 800-30) Confident in using risk assessment methodologies (NIST 800-30). Hands-on experience with SIEM/XDR solutions More ❯
to join a growing team within an MSSP. Within this role you will be providing detailed risk assessments, implementing industry-standard security frameworks including NIST, NCSC, and NIS2 as well as actively managing SIEM tools such as QRadar and/or Sentinel. You’ll be working closely with end customer … through regular meetings, strategic updates and consultative insights Lead comprehensive security risk assessments inline with industry standardsand conduct environment reviews ensuring compliance with NIST Frameworks and related standards Oversee and implement SIEM/XDR deployments, custom rule development, and incident response processes acting as a point of escalation and … businesses, perform gap analyses, and create and deliver reports on findings to end customer stakeholders Skills, Experience, and Certifications: Strong understanding of cybersecurity frameworks (NIST CSF, NCSC CAF, NIS2, NIST 800-30) Confident in using risk assessment methodologies (NIST 800-30). Hands-on experience with SIEM/XDR solutions More ❯
to join a growing team within an MSSP. Within this role you will be providing detailed risk assessments, implementing industry-standard security frameworks including NIST, NCSC, and NIS2 as well as actively managing SIEM tools such as QRadar and/or Sentinel. You’ll be working closely with end customer … through regular meetings, strategic updates and consultative insights Lead comprehensive security risk assessments inline with industry standardsand conduct environment reviews ensuring compliance with NIST Frameworks and related standards Oversee and implement SIEM/XDR deployments, custom rule development, and incident response processes acting as a point of escalation and … businesses, perform gap analyses, and create and deliver reports on findings to end customer stakeholders Skills, Experience, and Certifications: Strong understanding of cybersecurity frameworks (NIST CSF, NCSC CAF, NIS2, NIST 800-30) Confident in using risk assessment methodologies (NIST 800-30). Hands-on experience with SIEM/XDR solutions More ❯
london, south east england, United Kingdom Hybrid / WFH Options
InfoSec People Ltd
at all levels, strong all round technical expertise, and a passion for security. Key Responsibilities: Lead detailed cybersecurity risk assessments aligned to frameworks (e.g., NIST, NIS2). Manage and grow client relationships through strategic engagement, consulting with C suite executives and external security leaders. Oversee SIEM/XDR deployments and … Provide guidance on threat detection best practices. Technical Skills & Experience: Proficient with SIEM/XDR tools (QRadar, Sentinel, Defender XDR). Strong knowledge ofNIST CSF, NCSC CAF, and cloud security (AWS, Azure, GCP). Experienced in risk methodologies (e.g., NIST 800-30). Preferred Certifications: CompTIA Security+, CySA+ (Desirable More ❯
Experience Required for the Role Mandatory experience: 5-7 years in cybersecurity or governance, risk, and compliance (GRC) roles. Experience with security frameworks like NIST CSF, NCSC CAF, CIS Controls, ISF SOGP. Preferred experience: Experience with governance or risk frameworks like ISO 27001, COBIT, NIST RMF. Knowledge of capability maturity More ❯
and data protection. Translate requirements from PSD2 SCA , PCI DSS , and SWIFT CSP into technical security controls. Maintain IT security governance frameworks (ISO 27001, NIST CSF, CIS Controls). Manage and maintain Security Policies and procedures. Third-Party Risk & Outsourcing Management: Design and implement third-party risk management programs to … IAM (Identity and Access Management) solutions and conducting user access reviews . Familiarity with cloud Technologyand IT infrastructure. Framework Expertise: Strong knowledge ofNIST frameworks (CSF, 800-53) and CIS Controls . Certifications: CRISC, CISSP, CISM, or CISA preferred (equivalent experience considered). More ❯