26 to 50 of 187 SOC 2 Jobs in London

Platform Engineer

Location
Greater London, England, United Kingdom
available, and optimized for both performance and cost. Key Responsibilities Architect, implement, and maintain cloud infrastructure to support rapid product growth. Prepare infrastructure for SOC 2/ISO 27001 audits, aligning with customer expectations. Build and maintain CI/CD pipelines for backend, frontend, and data services … Experience implementing reliability, security, and compliance measures ahead of scale‐up or audit readiness. History of driving cost efficiency while enabling growth. Exposure to SOC 2, ISO 27001, or GDPR compliance processes. What We Offer You will be reporting directly to the founders, who have two successful venture ...

Global Cybersecurity Manager - Client Assurance

Hiring Organisation
Boston Consulting Group
Location
London, UK
ensure consistent and compliant responses to client inquiries. Risk & Compliance Support: Support clients in understanding BCG's compliance with relevant frameworks (e.g. ISO 27001, SOC 2, GDPR, NIST) and help translate technical security concepts into business-relevant assurance responses. Quality & Continuous Improvement: Support the continuous improvement of Client … field. Experience supporting client-facing information security, assurance, audit, compliance, or advisory activities. Strong understanding of information security frameworks and standards including ISO 27001, SOC 2, NIST CSF, GDPR, and relevant regional data protection regulations. Experience responding to client security questionnaires, due diligence requests, audits, or RFPs, with ...

Security Engineer

Location
Greater London, England, United Kingdom
lasting improvement to systems and controls AI security , including prompt injection, unsafe tool execution, retrieved data and sensitive information disclosure Evidence and assurance for SOC 2, enterprise security reviews and customer due diligence, plus the reusable security patterns engineering teams adopt as standard What We’re Looking … code, and enterprise identity integrations such as OAuth, OIDC and SAML Detection engineering, SIEM or cloud security monitoring, incident response or digital forensics SOC 2, ISO 27001 or enterprise customer security reviews Penetration testing or working with external security researchers What We Offer Competitive salary with regular appraisals ...

Solutions Engineer (Upmarket, Pre-Sales) - EMEA

Location
Greater London, England, United Kingdom
demonstrations that showcase how Vanta solves the customer's specific problem, including how Vanta automates and operationalises their GRC programmes across frameworks such as SOC 2, ISO 27001, and HIPAA. Validate the feasibility of standard and semi-complex integrations and confirm alignment with customer environments, workflows, and architectures. … trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. Now more than ever, making ...

Information Security Governance Specialist

Location
Greater London, England, United Kingdom
informed decisions while supporting commercial success. You'll drive the day‐to‐day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements. You'll serve as the subject matter expert during audits and ensure our control environment remains effective … experience in information security governance, GRC, or technology risk within a SaaS or cloud environment. You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional frameworks ...

Infrastructure/DevOps Engineer

Location
Greater London, England, United Kingdom
ready and high-performing. In this senior role, you’ll lead DevOps, observability, and compliance. Tasks include architecting cloud infrastructure for growth, prepping for SOC 2/ISO 27001 audits, and setting up CI/CD pipelines for all services. You’ll also manage logging, metrics, tracing, alerts … Security best practices knowledge. Networking concepts (VPCs, DNS, load balancers, VPNs, firewalls). Database management (PostgreSQL, MySQL, NoSQL) and storage. Python or Bash skills. SOC 2, ISO 27001, or GDPR exposure. Report directly to the founders with a chance to shape their future. Got what it takes? Apply ...

platform engineer for enterprise AI

Location
Greater London, England, United Kingdom
using GitHub Actions for backend, frontend, and data services Drive product-wide observability, including logging, metrics, tracing, and on-call processes Prepare infrastructure for SOC 2 and ISO 27001 security audits and manage cloud costs Build guardrails and advanced networking solutions, including VPCs, VPNs, and firewalls, for secure … Experience provisioning and scaling production databases, including PostgreSQL, MySQL, and NoSQL, and blob storage Strong Python or Bash skills for automation Direct experience with SOC 2, ISO 27001, or GDPR processes Understanding of how infrastructure decisions impact audit evidence Условия No conditions specified #J-18808-Ljbffr ...

Head of DevOps

Location
Greater London, England, United Kingdom
same agreed standards Ensuring our infrastructure meets the security and compliance bar our clients and regulators expect, and that we can evidence it (e.g. SOC 2) Giving the business clear, reliable visibility into infrastructure cost, attributed by client and project Building a self-service platform so engineering teams … Kubernetes, CI/CD and infrastructure-as-code at scale Experience running a cloud estate that has to stand up to external audit (e.g. SOC 2) and give the business real cost visibility Clear communication — comfortable explaining architectural trade-offs to technical and non-technical stakeholders alike Familiarity ...

Head of Security

Location
Greater London, England, United Kingdom
management. Automate wherever possible: zero-touch deployments, IaC for security tooling, automated provisioning and deprovisioning. - Drive compliance and certification. Lead certification efforts (ISO 27001, SOC 2) as needed to meet partner requirements. Automate where needed and treat compliance as a byproduct of good security practice. - Own IT administration … people Experience building or significantly maturing a security programme Familiarity with cloud security (AWS IAM, networking, infrastructure review) Experience with compliance frameworks (ISO 27001, SOC 2) Hands-on experience with endpoint management (Kandji, Jamf, or similar) and identity/access management Experience administering Google Workspace or equivalent Interest ...

Information Security Analyst ( ISO 27001 and ISO 27018 )

Location
Greater London, England, United Kingdom
and procedures sharp and our compliance with ISO 27001 and ISO 27018 on point. You’ll get involved in SSAE 18/ISAE 3402 SOC 1 Type 2 and SSAE 18 SOC 2 Type 2 assurance audits, spot opportunities to improve our security controls and … excellent organisational skills. You write clear documentation and reports, and can translate complex requirements for stakeholders at every level You’ll have at least 2 years’ experience in a related role Experience in a regulated industry, familiarity with other information security frameworks and assurance reports, and exposure to Jira ...

Information Security Analyst ( ISO 27001 and ISO 27018 )

Location
Greater London, England, United Kingdom
and procedures sharp and our compliance with ISO 27001 and ISO 27018 on point. You'll get involved in SSAE 18/ISAE 3402 SOC 1 Type 2 and SSAE 18 SOC 2 Type 2 assurance audits, spot opportunities to improve our security controls and … organisational skills.* You write clear documentation and reports, and you can translate complex requirements for stakeholders at every level.* You'll have at least 2 years' experience in a related role.* Experience in a regulated industry, familiarity with other information security frameworks and assurance reports, and exposure to Jira ...

Information Security Analyst - ISO 27001/SOC 2, Hybrid London

Location
Greater London, England, United Kingdom
Information Security Analyst to safeguard our SaaS platform across security operations, access reviews and risk management. You will help operate ISO 27001 and SOC 2 controls while learning quickly and delivering practical security improvements across the business. Based in London with hybrid work, you will collaborate with Engineering ...

Information Security Analyst

Location
Greater London, England, United Kingdom
Information Security Management System. As an Information Security Analyst, you will help operate and improve the controls that support our ISO 27001 and SOC 2 programmes, while also getting involved in the real security work that happens across a growing SaaS business. You will not be expected … helpful, trusted partner in the way FundApps builds, buys and operates technology. Taking full, end-to-end ownership of FundApps’ ISO 27001 and SOC 2 controls operation, managing every stage from initial evidence collection and control checks through to remediation tracking and comprehensive audit preparation. Organising and chairing ...

Compliance & IT Operations Manager IT & Compliance · London Office

Location
Greater London, England, United Kingdom
management and continuous improvement of our compliance programme, information security governance and IT operations. You will lead our approach to ISO 27001, SOC 2 and UK GDPR/data protection, acting as the primary point of contact for our external Data Protection Officer (DPO), auditors, customers and internal … and IT Operations Manager at Lunio if you have experience with: Compliance Programme Ownership: Manage and continuously improve Lunio's compliance programme (ISO 27001, SOC 2, UK GDPR), acting as the single point of contact for auditors, our external DPO, and internal stakeholders. Audit Readiness: Lead certification and ...

Privacy and Compliance Analyst

Location
Greater London, England, United Kingdom
privacy notices, consent, data retention, and contractual commitments Support audits and compliance programs through evidence collection and remediation tracking Contribute to ISO 27001, SOC 2, and other compliance initiatives Support privacy, security, and third-party risk assessments and maintain risk registers Support privacy incident investigations and remediation activities … Experience with privacy assessments, documentation, supplier reviews, and customer questionnaires Understanding of cloud technology, information security principles, and frameworks such as ISO 27001 and SOC 2 Strong research, critical thinking, and problem-solving skills Clear communication skills with the ability to explain complex topics simply Organised, detail-oriented ...

Applied AI Security Architect

Location
Greater London, England, United Kingdom
architects, compliance teams, and DPOs to understand their security requirements and design solutions that meet European regulatory standards (GDPR, EU AI Act, DORA, NIS2, SOC 2, PCI-DSS, and national regulator expectations). Lead technical deep-dives on network architecture, EU data residency, data retention and Zero Data … with the EU AI Act as it applies to foundation models. Experience navigating compliance frameworks relevant to European financial services and insurance (DORA, NIS2, SOC 2, PCI-DSS, and national regulators' guidance on AI/ML such as FCA/PRA, BaFin, ACPR, FINMA). A track record ...

Cybersecurity Risk and Compliance Associate

Location
Greater London, England, United Kingdom
assessments, including control walkthroughs, evidence gathering, gap analysis and remediation tracking. Coordinate evidence and actions for external audits and compliance assessments, including ISO 27001, SOC 2 and Cyber Essentials. Maintain clear, reusable control documentation and audit evidence so assurance activity is efficient, consistent and audit-ready. Track risk … governance, compliance, audit support, third-party risk or a related field. Working knowledge of control-based assurance and common frameworks such as ISO 27001, SOC 2 or Cyber Essentials; familiarity with NIST is beneficial. Strong analytical and organisational skills, with the ability to manage evidence, actions and deadlines ...

Head of Security

Location
Greater London, England, United Kingdom
security engineering, thoughtful governance and AI-first operations to ensure our customers, employees and partners can confidently rely on Geordie as we scale. With SOC 2 Type II and ISO 27001 already in place, your mission is to build an effective AI-native security programme that keeps certifications … hands-on individual contributor while building security functions from first principles. Experience maintaining security programs aligned to frameworks such as ISO 27001 and SOC 2. Strong understanding of modern software development, cloud infrastructure and secure engineering practices. Experience partnering closely with engineering organisations to build secure-by-design systems. ...

Senior Technical Programme Manager

Location
Greater London, England, United Kingdom
platforms or ways of working across multiple teams. Experience working in regulated environments or with strict compliance requirements (e.g., GDPR, PCI‐DSS, SOC 2, DMA, and EU AI Act). Demonstrated ability to establish programme governance and operating models from scratch in ambiguous or fast‐moving environments. Experience … Communication Leadership Skills Decision‐Making Influencing Stakeholders Navigating Complexity Certifications & Qualifications PMP Agile Project Management Certification AWS Cloud Practitioner Industry Keywords GDPR PCI‐DSS SOC 2 DMA EU AI Act Tools & Technologies Jira Confluence Smartsheet Cloud‐Native Designs Microservices #J-18808-Ljbffr ...

Senior Compliance Lead — SOC 2 & ISO 27001 (Remote UK)

Location
Greater London, England, United Kingdom
EnergySys is seeking a dedicated Compliance & Governance professional to own the SOC 2 Type II and ISO 27001 audits, maintain the ISMS, and drive regulatory compliance across UK, Australia, and US entities. You will configure Drata, map controls, and report to senior leadership while partnering with ...

Senior Security & Compliance Engineer (ISO 27001 / SOC 2)

Location
Greater London, England, United Kingdom
Volta is seeking a Senior Manager, Cyber Security Engineering to lead the ISO 27001 and SOC 2 Type II program across a fast-growing, security‐minded infrastructure platform. You will own controls, evidence, and ISMS documentation while collaborating with platform engineers and external auditors. You’ll drive audit ...

AI-Native Software Engineer

Location
Greater London, England, United Kingdom
These are broad, senior engineering roles, not single-language specialist posts. This is a regulated payments environment governed by frameworks including DORA, PCI DSS, SOC 2, EMI regulations and GDPR. These frameworks shape our SDLC itself, from change control and approvals to testing evidence and audit trails. Delivery … propose efficiency improvements that keep compliance intact. Familiarity with, or the ability to rapidly get to grips with, frameworks such as DORA, PCI DSS, SOC 2, EMI regulations and GDPR. You understand that the SDLC is constrained by these frameworks and can still deliver efficiently within it, using ...

Global Compliance Lead — SOC 1/2 & PCI for FinTech

Location
Greater London, England, United Kingdom
financial software company in London is seeking a Global Compliance Manager to oversee compliance execution. You'll manage audits for SOC 1, SOC 2, and PCI programs, ensuring robust control implementation and corporate compliance. Ideal candidates will have 3-7 years in compliance, strong engineering collaboration skills ...

Principal Security Engineer, Product & Infrastructure

Location
Greater London, England, United Kingdom
.NET Core, TypeScript, React, Python, Go Datadog (SIEM), CloudFlare ZTNA, Falco, Wiz, Riot, HackerOne, TruffleHog Google Workspace, Jumpcloud, Vanta, Hibob, Slack GitHub, CircleCI, ArgoCD SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001 Who you are You have at least 8 years of experience ...

Product Security Specialist for Medical Devices (Cyber Security)

Location
Greater London, England, United Kingdom
align with what you want to do. Hybrid working - our approach is to be in the office or on client site a minimum of 2 days per week. Work on a broad variety of projects and tech stacks for clients across seven sectors - no project is ever the same … residual risk after applying compensating security controls Experience implementing and demonstrating compliance to security frameworks such as NIST, IEC, HITRUST, HIPAA, GDPR, ISO 27001, SOC 2 Type 2 and familiarity working with Quality Management Systems Experience working with teams in a structured software development lifecycle process Excellent ...