LMAX Group is a global financial technology company and the leading independent operator of multiple institutional execution venues for FX and cryptocurrency trading. The Group's portfolio includes LMAX Exchange (institutional FX exchange and FCA regulated MTF), LMAX Global (FCA More ❯
Provide technical escalation support in the absence of a cybersecurity specialist, particularly in coordination with the Security Operations Centre (SOC). Support compliance with relevant standards (e.g. ISO 27001, NIST, UK GDPR). Review security aspects of tenders and conduct third-party/vendor risk assessments to ensure alignment with organisational security requirements. Perform additional security-related tasks as directed … cloud security. Ability to assess and communicate technical vulnerabilities in business terms. Experience working with or within a SOC environment . Familiarity with risk management frameworks (e.g. ISO 27005, NIST RMF). Excellent communication and reporting skills. Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who More ❯
Ability to lead technical conversations, influence customer decisions, and deliver trusted advisory services Existing SC clearance or eligibility to apply Desirable Skills & Certifications Familiarity with industry security frameworks (e.g., NIST, ISO 27001, CIS Controls) Cloud security experience across major hyperscalers More ❯
risk framework. Ability to communicate effectively at technical and strategic level with both engineers and directors. Ability to work independently. Knowledge of industry standardsand regulations such as ISO27001, NIST CSF Familiarity with audit preparations and compliance requirements including SSAE 18 SOC 1 and 2, DORA/NIS2. What you'll get Competitive Base Salary Company Equity for All Learning More ❯
architectures and strategies on GCP. Evaluate and recommend security tools, services and configurations to strengthen cloud security posture. Ensure compliance with security standardsand frameworks such as ISO 27001, NIST, CIS, GDPR and others. Lead threat modelling, risk assessments, and security reviews for GCP infrastructure and applications. Define and enforce Identity and Access Management (IAM) policies, including roles, permissions andMore ❯
Senior IT GRC Analyst City of London/Hybrid £Competitive + strong bonus and benefits GRC Frameworks, ISO 27001, NIST A prestigious financial services organisation in the heart of the City of London is seeking a Senior IT GRC Analyst to join its dynamic team. In this collaborative role, you will support the development and enhancement of IT Governance, Risk … security and operational risk assessments. High attention to detail, ensuring accuracy in documentation, assessments, and compliance activities. Strong understanding of information security risk management principles, frameworks (e.g., ISO 27001, NIST), and compliance practices. Exposure and understanding of IT infrastructure, business applications, and their associated risks and controls. Experience collaborating with internal and external audit teams, including supporting audit readiness andMore ❯
cyber resilience principles/practises including experience in information security, business continuity planning, business impact assessments, crisis management and cyber security. Working knowledge and/or expertise of ISO27001, NIST, CAF or other industry standards. Knowledge and general understanding of EU Digital Operational Resilience Act (DORA) and Network and Information Security (NIS2) Directive. Knowledge of EBA Outsourcing Guidelines, PRA SS2 More ❯
decision-making across engineering and leadership teams. - Support Compliance and Audit Readiness: Build and maintain solutions that automate evidence gathering and real-time compliance monitoring across frameworks such as NIST 800-53, HITRUST, PCI-DSS, and FedRAMP. - Collaborate Across Teams: Partner with cloud engineering, GRC, and program teams to align internal tooling with evolving compliance needs and operational goals. Qualifications … tools: Microsoft Sentinel, Defender XDR, Purview, Entra ID, Azure Policy. - Hands-on experience integrating or piloting AI agents or LLMs in operational workflows. - Knowledge of compliance standards such as NIST, HIPAA, FedRAMP, PCI, SOC2, or HITRUST. - Security certifications such as SC-200, GCSA, or equivalent. Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without More ❯
with a proven track record of influencing executive stakeholders and delivering secure, compliant outcomes in a complex, regulated financial services environments. You will have a strong knowledge of ISO, NIST, PCI-DSS, SOX, COBIT, GDPR, and related frameworks, expertise in IT risk, audit, and regulatory compliance and professional certifications (CISSP, CISM, or CISA) or willingness to obtain. Experience working under More ❯
e.g. GDPR, NIS Directive, EBA Guidelines). Has a comprehensive understanding of what it takes to comply with cyber security industry standardsand frameworks in practise (e.g. ISO 27001, NIST CSF, SP 800-53, NCSC CAF, Cyber Essentials). Has a thorough understanding of cyber security threat and risk with the ability to think like an attacker and design controls More ❯
privacy policies and regulations General knowledge of security technology Nice to have: Experience with PowerBI Programming skills and experience (python, java, SQL) Technical network skills Knowledge of OWASP, SANS, NIST, ISO 27001, ISF or other security-related practices Previous Banking/Financial Industry experience CISSP, CISA, CRISC, CSSLP, SABSA certifications Skills & Competencies: Vulnerability management Risk reporting Programming Data management Please More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Harvey Nash
privacy policies and regulations General knowledge of security technology Nice to have: Experience with PowerBI Programming skills and experience (python, java, SQL) Technical network skills Knowledge of OWASP, SANS, NIST, ISO 27001, ISF or other security-related practices Previous Banking/Financial Industry experience CISSP, CISA, CRISC, CSSLP, SABSA certifications Skills & Competencies: Vulnerability management Risk reporting Programming Data management Please More ❯
to our policies and adhered to Understands and delivers best practice security standards as part of the IT Security standards delivered under ISO 27001, GDPR, Cyber Essentials Plus andNIST Work closely with the software vendor, building a strong working relationship to maximise our use of the product to the best of its ability through: Understanding the product roadmap Access More ❯
skills and experience for this role are: 6+ years experience in Information Security Risk and Compliance Knowledge of security and compliance standards across InfoSec (e.g. ISO 27001, Cyber Essentials, NIST, CMMC) Expertise in Azure, Microsoft 365 & AWS Security Compliance Experience of Supply Chain compliance 27 days of annual leave Healthy half (0.5 day leave every 6 months for wellbeing) Private More ❯
and situational awareness updates Review escalations and follow incident response plans Conduct trend analysis and develop defense signatures Desired Skills: Certifications such as GIAC, GCIH, GCIA, ITIL Familiarity with NIST frameworks, Cyber Kill Chain Experience with case management, SOAR, SIEM, EDR tools Experience with multinational organizations and automation scripting (Python) Qualifications: Bachelor's degree or equivalent in Computer Science, Cybersecurity More ❯
landscape Familiarity with AWS, Azure, or Google Cloud. Understanding of Cyber Services markets e.g. Penetration Testing, Red Team/Purple Team, Adversary Simulation, risk and compliance frameworks ISO 27001, NIST, DORA, CREST. TIBER etc.) Willingness to travel to regular F2F end user meetings Familiarity with tools andstandards such as OWASP, MITRE ATT&CK etc Self-starter with a results More ❯
security platforms and working across diverse environments (cloud, hybrid, manufacturing). - Hands-on expertise with EDR, SOAR tooling, and SASE/SSE technologies. - Deep familiarity with frameworks such as NIST, MITRE ATT&CK, and other industry standards. - Strong stakeholder management skills and the ability to influence at all levels of the business. - A pragmatic, action-oriented approach to reaching strategic More ❯
from day-to-day operations to major transformation projects. Main responsibilities: Leading security assurance, assessments, and advisory for IT and business projects (both Cloud and On-Prem), aligned to NIST 800-53 standards. Partnering with security architecture and other teams to define and embed security patterns and controls. Developing non-functional security requirements and guiding their integration into solution designs. More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Goodman Masson
For: Experience in IT security or within a SOC/NOC environment Strong knowledge of Microsoft Defender, EDR, and network architecture Understanding of security frameworks (e.g., MITRE ATT&CK, NIST, ISO 27001) Excellent communication and teamwork skills Relevant certifications (e.g., Sec+, OSCP, CISA) are a plus More ❯
in Microsoft and ideally Linux Be strong at Scripting for example with Python, Bash or PowerShell Have strong Cloud Security monitoring experience Be familiar with industry frameworks for example NIST, MITRE and ATT&CK Soc Analyst Your Background The ideal applicant for this role will Have some experience operating as a SOC L1 or Cybersecurity Analyst Have a positive attitude More ❯
strategies. Deploy, configure, and manage security tools to optimize detection, response, and reporting functions. Skills & Knowledge Solid understanding of SOC best practices, incident response, and regulatory frameworks (e.g., GDPR, NIST, ISO 27001). Hands-on experience with security technologies such as SIEM, IDS/IPS, EDR, etc. Excellent communication skills, including the ability to explain technical topics to non-technical More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Salt Search
across multiple projects and programmes Design and implement Sentinel playbooks to automate detection and response Lead on PSN audit readiness and ensure compliance with key frameworks (Cyber Essentials, ISO27001, NIST, GDPR) Conduct cyber risk assessments, maintain the risk register, and drive remediation activity Provide regular reports and updates to senior stakeholders on cyber posture, risks, and progress Support and mentor … within a Local Government environment (this is essential) Direct experience supporting or leading PSN audits and wider compliance activities Strong working knowledge of core security frameworks: ISO27001, Cyber Essentials, NIST, GDPR Excellent stakeholder management and reporting skills, with the ability to operate independently in a complex environment CISSP certification is required Please only apply if you have Local Government experience More ❯
with Microsoft 365 security features (Intune, Defender, etc.). Understanding of financial regulatory requirements. Excellent communication and documentation skills. Experience with ICE Clearing or similar regulatory processes. Familiarity with NIST, CIS Controls, or other frameworks. Can't find the job you're looking for, send us your info and we will review your options? (Permitted file size is 5Mb andMore ❯
strategies. Deploy, configure, and manage security tools to optimize detection, response, and reporting functions. Skills & Knowledge Solid understanding of SOC best practices, incident response, and regulatory frameworks (e.g., GDPR, NIST, ISO 27001). Hands-on experience with security technologies such as SIEM, IDS/IPS, EDR, etc. Excellent communication skills, including the ability to explain technical topics to non-technical More ❯
across multiple projects and programmes Design and implement Sentinel playbooks to automate detection and response Lead on PSN audit readiness and ensure compliance with key frameworks (Cyber Essentials, ISO27001, NIST, GDPR) Conduct cyber risk assessments, maintain the risk register, and drive remediation activity Provide regular reports and updates to senior stakeholders on cyber posture, risks, and progress Support and mentor … within a Local Government environment (this is essential) Direct experience supporting or leading PSN audits and wider compliance activities Strong working knowledge of core security frameworks: ISO27001, Cyber Essentials, NIST, GDPR Excellent stakeholder management and reporting skills, with the ability to operate independently in a complex environment CISSP certification is required Please only apply if you have Local Government experience More ❯