procedures in alignment with business objectives, while considering operational needs. Direct the management and continuous improvement of the Information Security Management System (ISMS). Oversee and manage Ravelin's PCIDSS and PCI 3DS compliance program, ensuring requirements are fulfilled, maintained, and areas for enhancement are identified. Conduct routine risk assessments to determine and reduce information security … robust cyber incident response plan, including coordinating necessary responses to incidents and security investigations. Requirements Extensive practical experience implementing and maintaining an ISO 27001 compliant ISMS. Demonstrable experience with PCIDSS compliance, including preparing for and undergoing assessments. Familiarity with information security frameworks (e.g., NIST, CIS). Proficiency in risk management methodologies. Knowledge of common security technologies (e.g. More ❯
as part of our team. About the role As a DevOps Engineer, you will be responsible for designing, implementing, and managing AWS-based highload infrastructure while ensuring compliance with PCIDSSsecurity standards. You will play a crucial role in automating deployments, optimizing system performance, and maintaining reliability in a high-scale environment. The role requires expertise in … redundancy. Develop and optimize CI/CD pipelines to streamline deployments and support zero-downtime releases. Monitor system performance, troubleshoot issues, and implement security best practices in compliance with PCI DSS. We're looking for you if you have 5+ years of DevOps experience, with a focus on AWS, CI/CD, and highload environments. Experience deploying and maintaining … Docker, Kubernetes, and Infrastructure as Code (IaC). Proven track record of achieving high availability for mission-critical services. Solid knowledge of monitoring, security best practices, and compliance with PCIDSS standards. Bonus Points Experience with DORA compliance for financial service providers. What's in it for You Reveal great tech solutions Join the team of experts who More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Arc IT Recruitment
makes an impact.Your role will involve: Expanding and maintaining a serverless payment processing platform built with TypeScript, Node.js, and AWS services like Lambda, API Gateway, and DynamoDB. Ensuring continued PCIDSS compliance across the full development lifecycle, including patching, error tracing, and applying secure coding practices. Designing secure, well-documented service interfaces and abstractions over external APIs used … technologies. Working knowledge of Infrastructure-as-Code tools. Strong background in RESTful API development, secure authentication mechanisms, and API integration best practices. Experience working in regulated environments such as PCIDSS, or within other compliance-heavy systems. Familiarity with frontend frameworks like React is a bonus. If you're a backend engineer who thrives in cloud-native environments More ❯
an impact. Your role will involve: Expanding and maintaining a serverless payment processing platform built with TypeScript, Node.js, and AWS services like Lambda, API Gateway, and DynamoDB. Ensuring continued PCIDSS compliance across the full development life cycle, including patching, error tracing, and applying secure coding practices. Designing secure, well-documented service interfaces and abstractions over external APIs … technologies. Working knowledge of Infrastructure-as-Code tools. Strong background in RESTful API development, secure authentication mechanisms, and API integration best practices. Experience working in regulated environments such as PCIDSS, or within other compliance-heavy systems. Familiarity with Front End frameworks like React is a bonus. If you're a Back End engineer who thrives in cloud More ❯
such as TOGAF or SABSA Strong understanding and knowledge of Information Security risk management tools and techniques Demonstrable knowledge of cyber security frameworks, including but not limited to: ISO27001, PCI-DSS, CIS Benchmarks, Cloud Platform Well Architected Frameworks. Demonstrable experience of designing and implementing enterprise security technology controls and platforms, following industry best practices. Experience of security governance More ❯
and blueprints. What You'll Bring Prior and proven experience gained as a Security Architect or in a Technical Cyber Consultant/Engineer role. Expertise in: Security legislation (GDPR, PCIDSS, ICO) Frameworks (ISO 27001, NIST CSF, CIS Controls v8) HMG/NCSC policies and guidance Cloud security (AWS, Azure) Microservice architectures PKI, Cryptography, Privileged Access Management Certifications More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Sanderson
and blueprints. What You'll Bring Prior and proven experience gained as a Security Architect or in a Technical Cyber Consultant/Engineer role. Expertise in: Security legislation (GDPR, PCIDSS, ICO) Frameworks (ISO 27001, NIST CSF, CIS Controls v8) HMG/NCSC policies and guidance Cloud security (AWS, Azure) Microservice architectures PKI, Cryptography, Privileged Access Management Certifications More ❯
for breaches. Known for crafting innovative and cost-effective Information Security Management Systems (ISMS), the consultancy enables quantifiable compliance with key information security legislation, regulations, and industry standards, including PCIDSS, the UK Data Protection Act 2018 (DPA 2018), GDPR, and ISO/IEC 27001. If you would like to learn more about this opportunity, feel free to More ❯
City of London, London, England, United Kingdom Hybrid / WFH Options
Michael Page Technology
improve, maintain and regularly test incident management policy and procedures. Ensuring security operations controls and processes adhere to relevant laws and standards including GDPR, Data Protection Act, Cyber Essentials, PCI DSS. Identify, assess and clearly communicate risks in the domains of operational security Profile A successful Security Operations Manager should have: Applicable security certification, such as CISSP, ISSMP, MSc More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Become
collaboration skills Desirable Attributes Exposure to service mesh technologies (e.g., Istio, Linkerd) Experience with secrets management and security tooling (e.g., Vault, Snyk) Familiarity with compliance frameworks (e.g., ISO 27001, PCI-DSS) Prior consulting experience or experience in client-facing roles Engagement Model Outside IR35 12-month initial contract with potential for extension or permanent employment Hybrid working model More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Addition
one. Advising on risks, vulnerabilities and mitigation strategies across the tech estate. Shaping and maintaining internal security standards and governance frameworks. Ensuring compliance with ISO 27001, GDPR, SOC 2, PCI-DSS and similar regulations. Collaborating with IT, business stakeholders, and third parties to drive secure delivery. Supporting incident response and proactively planning for emerging threats. Translating complex risks … Strong background in security architecture and designing enterprise-level solutions. Deep familiarity with frameworks like ISO 27001, NIST, TOGAF or SABSA. Significant experience in Financial Services or Insurance, including PCI-compliant environments. Expert knowledge of network and cloud security using Azure, Hands-on experience with application security, data protection, and threat modelling. Confident communicator, able to influence across technical More ❯
high growth and fast paced tech environment Sales experience is NOT required Nice to Have Understanding of common compliance frameworks such as SOX, COBIT, SOC, COSO, ISO 27001, HIPAA, PCIDSS, HITRUST and industry recognized guidance such as NIST Our Company Values Customer obsession: Apply relentless focus on listening to and understanding customers as the core of everything More ❯
Croydon, London, United Kingdom Hybrid / WFH Options
Gold Group
to ensure security is embedded in all new and existing applications, systems, and network infrastructure * Risk Management & Compliance: Ensure compliance with industry regulations and data protection laws (e.g. GDPR, PCI-DSS) * Continuous Improvement: Stay informed of the latest cybersecurity threats, trends, and technologies, recommending and implementing improvements to enhance security defences * Change Management: Establish and lead a Change More ❯
South Croydon, Surrey, England, United Kingdom Hybrid / WFH Options
Gold Group Ltd
to ensure security is embedded in all new and existing applications, systems, and network infrastructure* Risk Management & Compliance: Ensure compliance with industry regulations and data protection laws (e.g. GDPR, PCI-DSS)* Continuous Improvement: Stay informed of the latest cybersecurity threats, trends, and technologies, recommending and implementing improvements to enhance security defences* Change Management: Establish and lead a Change More ❯
roles-especially in settings that integrate governance tightly into data platform design. Familiarity with privacy-by-design , data minimization , and regulatory standards including GDPR, ISO 27001, SOC 2, and PCI DSS. Strong analytical and communication skills - capable of translating technical, regulatory, and business requirements into actionable solutions across teams. What We Offer: Fully remote and flexible working schedule, with More ❯
Proven experience in cybersecurity leadership; prior CISO/CSO experience is a strong plus. Deep knowledge of security frameworks (e.g., NIST, ISO 27001) and compliance standards (e.g., GDPR, HIPAA, PCI-DSS). Strong expertise in secure SDLC, and application security tooling (SAST, DAST, SCA). Excellent communication skills with the ability to influence executive and technical stakeholders. Experience More ❯
experience to define and implement security architectures and solutions. Requirements: 5+ year's working in a Security Architect/technical role Recent MOD experience Security related legislation (eg GDPR, PCIDSS, ICO requirements) Security Control Frameworks such as ISO 27001, NIST CSF and CIS Controls v8 HMG and NCSC security policies, standards and guidance Cloud security including Amazon More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Sanderson
experience to define and implement security architectures and solutions. Requirements: 5+ year's working in a Security Architect/technical role Recent MOD experience Security related legislation (e.g. GDPR, PCIDSS, ICO requirements) Security Control Frameworks such as ISO 27001, NIST CSF and CIS Controls v8 HMG and NCSC security policies, standards and guidance Cloud security including Amazon More ❯
capability for integrations, data quality, reporting, and performance optimisation Compliance & Data Protection Act as the lead on GDPR and data protection compliance Ensure adherence to security standards such as PCIDSS Team Management & Training Manage the Systems Administrator and IT Assistant Support staff onboarding and ongoing training on IT systems Oversee documentation and guides to ensure smooth IT More ❯
capability for integrations, data quality, reporting, and performance optimisation Compliance & Data Protection Act as the lead on GDPR and data protection compliance Ensure adherence to security standards such as PCIDSS Team Management & Training Manage the Systems Administrator and IT Assistant Support staff onboarding and ongoing training on IT systems Oversee documentation and guides to ensure smooth IT More ❯
data dictionaries for all payment and collections data processes to ensure consistency and knowledge transfer. Compliance & Risk Management • Ensure that all data-handling processes adhere to relevant regulations (e.g., PCIDSS for card Payments, GDPR for personal data in collections). • Work with Compliance and Risk teams to analyse data for potential risks • Maintain audit-ready documentation, providing More ❯
communicate effectively with internal stakeholders and customers to understand their needs and translate them into product requirements. Understanding of financial datasecurity and privacy regulations, such as GDPR or PCI-DSS. Familiarity with risk management principles and methodologies, specifically related to product operations. Understanding of sanctions screening processes and familiarity with industry-standard sanction lists. Knowledge of data privacy More ❯
of OWASP standards (Top 10, ASVS, SAMM, MASVS) Understanding of cryptographic principles and secure implementations Experience with threat modeling methodologies Knowledge of authentication standards (OAuth2, OIDC, WebAuthn) Familiarity with PCI-DSS, PSD2, and Strong Customer Authentication requirements Understanding of cloud-native security patterns Ability to identify security vulnerabilities through manual code review Experience with static and dynamic analysis More ❯
providers. Support and evolve the Group's data strategy. Ensure platform reliability, performance, and scalability. Partner with Security, Compliance, and Infrastructure teams to meet regulatory and certification standards (eg, PCIDSS, TISAX, ISO 27001), and embed security into development workflows. Collaborate cross-functionally with Product, Partner Operations, and Business Development. Take ownership of growth strategy and team development More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Arc IT Recruitment
providers. Support and evolve the Group’s data strategy. Ensure platform reliability, performance, and scalability. Partner with Security, Compliance, and Infrastructure teams to meet regulatory and certification standards (e.g., PCIDSS, TISAX, ISO 27001), and embed security into development workflows. Collaborate cross-functionally with Product, Partner Operations, and Business Development. Take ownership of growth strategy and team development More ❯