Information Security GRC Manager | ISO27001, SOC2, Azure Security | Global Trading Platform £70–80k base + 10% bonus Hybrid in London Training budget for certifications + conference attendance Strong emphasis on professional autonomy and ethical leadership A newly created opportunity to lead and shape the GRC function of a global financial group at a pivotal time, supporting the secure … and SOC2 maturity, and mentoring an evolving InfoSec team. This is a hands-on manager-level role with real scope: oversight of policy, third-party risk, architectural reviews, and cloud compliance. You'll work closely with the Head of InfoSec to maintain audit readiness, improve security posture, and influence business-wide awareness and accountability. What you’ll bring … 5+ years in InfoSec, IT Security or Ops within a regulated environment Certification required: CISSP, CISM, CRISC, or equivalent Strong knowledge of ISO27001:2022, SOC2 Type II, NIST CSF, PCI DSS, GDPR, DORA Confident with security risk assessments, audit responses, and policy governance Hands-on cloudsecurity experience: ideally with Azure and the Shared Responsibility Model More ❯
Information Security GRC Manager | ISO27001, SOC2, Azure Security | Global Trading Platform £70–80k base + 10% bonus Hybrid in London Training budget for certifications + conference attendance Strong emphasis on professional autonomy and ethical leadership A newly created opportunity to lead and shape the GRC function of a global financial group at a pivotal time, supporting the secure … and SOC2 maturity, and mentoring an evolving InfoSec team. This is a hands-on manager-level role with real scope: oversight of policy, third-party risk, architectural reviews, and cloud compliance. You'll work closely with the Head of InfoSec to maintain audit readiness, improve security posture, and influence business-wide awareness and accountability. What you’ll bring … 5+ years in InfoSec, IT Security or Ops within a regulated environment Certification required: CISSP, CISM, CRISC, or equivalent Strong knowledge of ISO27001:2022, SOC2 Type II, NIST CSF, PCI DSS, GDPR, DORA Confident with security risk assessments, audit responses, and policy governance Hands-on cloudsecurity experience: ideally with Azure and the Shared Responsibility Model More ❯
Milan, Edinburgh and Madrid. With our focus on growth in the UK and Europe, now is the perfect time to join us on this high-speed journey. Introducing our Security Trainline is investing in the next evolution of our security program-and we're hiring a Principal Security Architect to lead our enterprise-wide architecture vision. This … hybrid role sits at the intersection of corporate IT security and cloud-native product security, shaping strategy and execution across a complex, fast-moving environment. As part of Trainline's Information Security (InfoSec) team, reporting to the CISO, the Principal Security Architect you will define our Zero Trust architecture, embed secure-by-design thinking across … engineering workflows, and partner with leaders across Platform, Engineering, Corporate Functions and GRC to uplift security maturity across both employee-facing and customer-facing systems. The Principal Security Architect will bring hands-on experience in technical design with proven ability to influence stakeholders-from IT and DevOps to Product Engineering and Compliance Teams. Joining at a key moment More ❯
Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
Halian Technology Limited
We're Hiring: Senior Cyber Security Engineer | Reading (Hybrid) Are you passionate about securing complex systems and building resilient cloud infrastructure? Join our growing team as a Senior Cyber Security Engineer , and help us protect critical platforms while enabling innovation at scale. ?? Location: Berkshire, UK (Hybrid 2-3 days onsite) About the Role As a Senior Cyber … Security Engineer, youll be a key member of our security team, responsible for designing, implementing, and maintaining robust security solutions across our cloud and on-prem environments. Youll work closely with engineering, DevOps, and compliance teams to embed security into everything we dofrom infrastructure to application design. Key Responsibilities Design and implement security controls … across cloud platforms (AWS, Azure, or GCP) Develop and maintain security tooling for threat detection, vulnerability management, and incident response Lead threat modelling and risk assessments for critical systems and services Collaborate with engineering teams to integrate security best practices into CI/CD pipelines Monitor and respond to security incidents, coordinating investigation and remediation efforts More ❯
Interim AWS Security Architect - Financial Services Robert Half is recruiting on behalf of a global consulting firm for an experienced AWS Security Architect to become an associate for a global consulting firm on a large-scale cloudsecurity programme for a major financial services organisation. The focus is on designing, building, and securing AWS applications, container … platforms, and cloud network infrastructure in direct collaboration with AWS. Key Details: Start: ASAP (c. 2-week lead time for onboarding and paperwork) Location: Remote but may need a day flexibility in City of London Duration: 1 2-month contract strong likelihood of extension Rate: £600.00 p/day via PAYE ( PLUS 12.07% accrued holiday pay ) via PAYE with … admin fees Requirements: Must have experience working in financial services, ideally banking Deep experience in designing, building, and securing applications in AWS as a core role focus (not generalist cloudsecurity) Expertise in container platform security, including EKS and use of service mesh Strong cloud network security background covering firewalling, network segmentation, VPC design , and More ❯
Principal Responsibilities • Collaborate with technical and business teams to address security flaws and implement remediation plans. • Oversee application security tasks, ensuring alignment with audit requirements and internal policies. • Support change and incident management processes, with a focus on high-priority incidents (P1 & P2). • Provide guidance to development and support teams on security-related ticket requirements and … to ensure clear communication and quality engagements. • Support governance and administrative functions, including audit preparation and policy development. • Compile and deliver regular reports, including weekly, monthly, and OSM-specific security metrics. Required Key Skills (Functional/Technical) Application Security & Vulnerability Management • Familiarity with Common Vulnerability Scoring System (CVSS) • Experience with tools like OWASP ZAP, Veracode, Rapid7 (on-prem … and Wiz.IO (cloud vulnerability management and CSPM) • Track and assist in the closure of identified vulnerabilities, working closely with IT and Development teams • Review and maintain secure configurations for systems, applications, and network devices Security Fundamentals • Working knowledge of encryption, authentication, and secure data transmission • Knowledge of network security principles and firewall configurations • Familiarity with SSO and More ❯
an exciting challenge and an opportunity to make a real difference? Are you passionate about leadership and nurturing people? Are you experienced in the world of data protection and security? At University Nottingham University Hospitals NHS Trust, we have a fantastic opportunity for you to become a Deputy to our Data Protection Officer within our exciting Information Governance team. … Data Protection and Security/Information Governance is a requirement of every UK organisation ensuring that you are entering a career in an area of continued demand and expertise. You probably know the NHS is one of the largest employers in the UK and EU and it needs you. In return this role can offer you a fantastic opportunity … Requests and Freedom of Information Requests and all types of disclosures) Data Breaches (i.e. Data incidents breaches of the Confidentiality, Integrity and Availability (CIA) triad of Information Assets) Data Security (i.e. NHS Data Security and Protection Toolkit/Regulatory compliance) About us With over 20,000 staff, we are one of the biggest employers in the city with More ❯
Home " Jobs " Markets Product Security Engineer This is an amazing opportunity to work with Information Security and Compliance Team at ION. As a Product Security Engineer, you would be the key enabler of secure and compliant products. You should have knowledge of attack paths across the technology stack, including tactics, techniques and procedures (TTPs) used by adversaries … to exploit vulnerabilities. You will be trusted advisor throughout the product development lifecycle, incorporating knowledge of emerging threats, business goals and system design to improve platform security posture. You will be responsible for aligning the Markets security strategy, security design and controls engineering to product roadmap. You will also be responsible for providing transparency to leadership on … product control performance and associated risk. Key Responsibilities: Within the Product Security Team as part of the ION Markets CISO function, you will deal with the following activities: Monitor and identify security events and emerging threats associated with the product line you are managing and any dependencies; Act as the interface between CSIRT and Product teams as part More ❯
Senior Information Security Manager page is loaded Senior Information Security Manager Apply locations Great Britain - London time type Full time posted on Posted Yesterday job requisition id R5807 Job Description: Senior Information Security Manager Position Overview: We are seeking aSenior Cyber Security Posture and Exposure Managerto lead and enhance our organization's security posture and … manage cyber exposure risks. This role will oversee a small team of highly skilled Security Engineers and will be responsible for developing, implementing, and maintaining strategies to identify, assess, and mitigate security vulnerabilities across the enterprise. The ideal candidate will have a strong technical background, leadership experience, and a proactive approach to managing cyber risks in a dynamic … technology environment. What You'll Do: Leadership and Team Management: Lead, mentor, and manage a team of Security Engineers, fostering a culture of collaboration, innovation, and continuous improvement. Define team goals, assign responsibilities, and ensure the successful execution of security initiatives. Conduct regular performance reviews and provide professional development opportunities for team members. Ability to work across the More ❯
Position Available: Security & Identity Consultant Location: London (Hybrid, 2 days a week in office) Salary: £75,000 - £85,000 (DoE) + Bonus Experience needed: We are seeking a senior-level IAM and security professional with experience designing and implementing IAM frameworks, managing access governance, and improving security posture in large-scale environments. You'll combine hands-on … technical skills with strategic leadership, working closely with senior security stakeholders. Experience with IAM tools (Saviynt preferred), authentication protocols, cloudsecurity, and frameworks like RBAC and least privilege is highly desirable. About the role: We're seeking a senior-level Identity & Access Management (IAM) and Security specialist to take ownership of a global security roadmap … and design IAM frameworks that protect operations across multiple countries. This is not a generic IT security position, you'll act as the strategic bridge between senior security leadership and global technology teams, turning high-level security objectives into practical, scalable solutions. Key Responsibilities: Own and deliver the Global Technology Operations security roadmap Design & implement IAM More ❯
Hybrid - Cloud Architect - Azure AWS Google Cloud Locations : Manchester, Birmingham, Swindon, Bristol About Our Client The Government Property Agency is the largest property holder in government, with more than £2.1 billion in property assets and over 55% of the government's office estate. They are transforming the way the Civil Service works by creating great places to work … shape future direction. Job Description The GovPass Programme within the GPA is modernising Access Control Systems across HMG. Delivering a new UK government standard for card encryption improving building security and enabling greater interoperability through its innovative technology. GovPass is operating across the UK in HMG Estate and in some of the most iconic buildings and departments, with an … ambition to expand this further over the coming years. The Cloud Architect is a critical role in the GovPass Product Team and will be responsible for designing and implementing cloud solutions that align with the Government's digital strategy and secure standards. This role involves collaboration with various stakeholders to develop, maintain, and enhance cloud architectures that More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
The Boeing Company
professional growth. Find your future with us. Boeing delivers leading-edge platforms, technology, services, and capabilities to bring the best value to the Ministry of Defence and UK national security services. Employing more than 1,800 people, Boeing Defence UK provides long-term support for more than 120 Boeing military rotary-wing and fixed-wing aircrafts in the UK. … UK, and blending our local expertise with our 'One Boeing' global approach, Boeing Defence UK is well positioned to support the UK with its current and future defence and security challenges. The Role As the Lead DevOps Engineer, you will be responsible for designing, implementing, and managing our MoDCloud Azure infrastructure using Infrastructure as Code (IaC) and automation practices. … You will lead a team of engineers, collaborate with cross-functional teams, and ensure the reliability, scalability, and security of our cloud environments, particularly in classified settings. Please note: this role is subject to successful Contract Award. This is an on-site role, with flexibility for occasional remote working at the discretion of the management team. Primary Responsibilities More ❯
Darkshield is an expert cybersecurity agency based in York, UK. We help organisations navigate an increasingly complex digital landscape by providing expert services in penetration testing, vulnerability assessment, managed security, and more. Our mission is to protect businesses by delivering tailored, cutting-edge cybersecurity solutions that keep them resilient and ahead of cyber threats. The Role We are looking … for a skilled and motivated Cybersecurity Engineer to join our team. You will play a key role in designing, implementing, and maintaining security solutions that protect our clients from evolving threats. This role requires a strong technical background in cybersecurity, problem-solving skills, and the ability to work collaboratively with clients and internal teams. Key Responsibilities Design, implement, and … maintain security solutions to protect networks, applications, and data. Conduct security assessments, penetration testing, and vulnerability management. Monitor and respond to security incidents, ensuring swift mitigation and resolution. Develop and enforce security policies, procedures, and best practices. Perform security audits and risk assessments to identify potential vulnerabilities. Work closely with clients to provide expert advice More ❯
Security Support Engineer, Vulnerability Management and Remediation Operations Job ID: Amazon UK Services Ltd. Embark on a Mission to Fortify Amazon's Defenses as a Support Engineer with the Vulnerability Management & Remediation Operations team! Amazon Security is seeking an experienced and innovative Support Engineer specialising in cybersecurity to join our Vulnerability Management and Remediation Operations (VMRO) team in … Support vulnerability detection campaigns by working closely with Campaign Owners to launch and continuously improve the quality of campaigns across Amazon. - Assess and negotiate with customers to drive down security risk by engaging with teams to remediate critical security vulnerabilities in their environments. - Collaborate with builder teams to implement security fixes and improvements. - Understand technical details of … peers. - Participate in an on-call rotation to support continuous monitoring and remediation of vulnerabilities. If you're excited about the opportunity to make a significant impact on the security of one of the world's largest and most complex technology ecosystems from our London office, we'd love to hear from you! About the team Why Amazon SecurityMore ❯
want a real Swiss Army Knife. You must have vast high level design experience across a range of disciplines, being comfortable in a range of potential situations, from endpoint security through to web app Firewalls and everything in between. It is important to note that they are NOT looking for an Enterprise Architect, but more of an infrastructure focused … Security Architect. There is no specific list of tools for this one as they are looking for the right person to come in, rather than someone who just ticks a checklist of tech. With that being said, experience with AWS security architecture is required, albeit not as an out-and-out AWS Security Architect or CloudSecurity Architect. Key experience that will need to be demonstrated: Solid endpoint detection and response deployment (EDR deployment) experience. Zscaler knowledge/experience. Broad AWS Infrastructure Security experience. Ability to deal with issues/tasks outside of the specific cloud domain. Broad use of security technologies in SaaS environments. Extensive Endpoint security work. Ability More ❯
Security Support Engineer (Level.3/Zscaler) Xalient United Kingdom ProfessionalServices-Deployment Remote working Company Description Xalient specializes in the convergence and holistic management of identity, cybersecurity, and networking to deliver secure connectivity within a zero-trust framework.Offering world-class Identity solutions and services including IGA, PAM, customer identity, access enforcement and IAM solutions, Xalient also delivers transformative software-defined … Xalient was named among Europe's Fastest Growing Companies in 2024 by Financial Times and Statista for the third consecutive year. Position We are seeking an experienced Level 3 Security Support Engineer to join our Zscaler Managed Services team. This role is responsible for advanced troubleshooting, implementation, and optimization of Zscaler security solutions. As a key escalation point … you will work closely with clients, internal teams, and vendors to ensure seamless security operations. What you'll be doing Provide Level 3 support for Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) solutions. Troubleshoot complex issues related to connectivity, policy enforcement, authentication, and performance. Lead root cause analysis and resolution of critical incidents. Implement and optimize Zscaler More ❯
Security Consultant – London, United Kingdom 🚀 Be the Defender of Tomorrow’s Digital World with Kyndryl Are you ready to step into a role where your decisions protect organizations, empower innovation, and define the future of cybersecurity? At Kyndryl , our Security Consultants aren’t just experts—they’re strategic advisors, problem-solvers, and the first line of defense in … a fast-evolving threat landscape. Here’s what the role looks like: 🔍 What You’ll Do Analyze, assess, and implement end-to-end security controls and policies Lead risk assessments , security audits, and design secure architectures Collaborate with clients to develop and enforce robust, real-world security frameworks Get hands-on with firewalls, IDS/IPS, encryption … and access control tech Stay ahead of threats and apply cutting-edge security practices —Zero Trust, CloudSecurity, IoT, AI, and more Influence system design to be secure by default , not by patch. 🧠 You Should Have: ✔️ 8+ years in security consulting or implementation ✔️ Expertise in frameworks like NIST, RMF, Common Criteria ✔️ Strong grasp of risk management More ❯
Security Consultant – London, United Kingdom 🚀 Be the Defender of Tomorrow’s Digital World with Kyndryl Are you ready to step into a role where your decisions protect organizations, empower innovation, and define the future of cybersecurity? At Kyndryl , our Security Consultants aren’t just experts—they’re strategic advisors, problem-solvers, and the first line of defense in … a fast-evolving threat landscape. Here’s what the role looks like: 🔍 What You’ll Do Analyze, assess, and implement end-to-end security controls and policies Lead risk assessments , security audits, and design secure architectures Collaborate with clients to develop and enforce robust, real-world security frameworks Get hands-on with firewalls, IDS/IPS, encryption … and access control tech Stay ahead of threats and apply cutting-edge security practices —Zero Trust, CloudSecurity, IoT, AI, and more Influence system design to be secure by default , not by patch. 🧠 You Should Have: ✔️ 8+ years in security consulting or implementation ✔️ Expertise in frameworks like NIST, RMF, Common Criteria ✔️ Strong grasp of risk management More ❯
East London, London, United Kingdom Hybrid / WFH Options
A&O Shearman
ability to keep our clients data secure is a bedrock for our reputation as a trustworthy professional services partner to many of the worlds large and prestigious organisations. Information security is not an afterthought; it is core to all that we do, to protect not only our data but that of our clients, and has the unwavering support of … the Board. Led by our new CISO, the in-house Information Security team is a core part of our technology services structure with mature or evolving capability across all areas of digital security and cyber defence. We align our efforts to the NIST framework and other recognised certifications including ISO27001 and SOC2 and strive to keep pace with … have experience advising clients on hundreds of incidents. Leveraging this experience, they feedback practical lessons learned into clients cyber risk management and incident response programmes. What you will do Security Architecture Strategy & Governance Orchestrate the Security Architecture team in the development and maintenance of a comprehensive security architecture strategy across the firms platforms, including M365, legal and More ❯
to keep our clients' data secure is a bedrock for our reputation as a trustworthy professional services partner to many of the world's large and prestigious organisations. Information security is not an afterthought; it is core to all that we do, to protect not only our data but that of our clients, and has the unwavering support of … the Board. Led by our new CISO, the in-house Information Security team is a core part of our technology services structure with mature or evolving capability across all areas of digital security and cyber defence. We align our efforts to the NIST framework and other recognised certifications including ISO27001 and SOC2 and strive to keep pace with … have experience advising clients on hundreds of incidents. Leveraging this experience, they feedback practical lessons learned into clients' cyber risk management and incident response programmes. What you will do Security Architecture Strategy & Governance Orchestrate the Security Architecture team in the development and maintenance of a comprehensive security architecture strategy across the firm's platforms, including M365, legal More ❯
The Ellison Institute of Technology (EIT) tackles humanity's greatest challenges by turning science and technology into impactful global solutions. Focused on areas like health, food security, sustainable agriculture, climate change, clean energy, and robotics in an era of artificial intelligence. EIT blends groundbreaking research with practical applications to deliver lasting results. A cornerstone of EIT mission is its … Oxford. It will also host the Ellison Scholars, driving innovation for societal benefit. The Pathogen Mission highlights EIT's transformative approach, using Whole Genome Sequencing (WGS) and Oracle's cloud technology to create a global pathogen metagenomics system. This initiative aims to improve diagnostics, provide early epidemic warnings, and guide treatments by profiling antimicrobial resistance. The goal is to … engineers to deploy data pipelines and platform features, and support bioinformaticians in building and deploying their workflows. You'll be responsible for maintaining infrastructure, designing secure automation pipelines, managing cloud environments, and ensuring security and compliance. You'll collaborate with cross-functional teams, data engineers, backend, and full-stack developers, to build robust, automated deployment pipelines across our More ❯
The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written in Databricks (for Customer Use or Supporting Customer internally) to reduce the likelihood of introducing new vulnerabilities in production and minimize the count and effect of externally identified vulnerabilities on Databricks Services. You will be an individual contributor on … the product security team at Databricks, managing SDLC functions for features and products within Databricks. This would include, but is not limited to, security design reviews, threat models, manual code reviews, exploit writing and exploit chain creation. You will also support IR and VRP programs when there is a vulnerability report or a product security incident. You … Support for new product features being developed in ENG and non-ENG teams. This would include Threat Modeling, Design Review, Manual Code Review, Exploit writing, etc. Work with other security teams to provide support for Incident Response and Vulnerability Response as and when needed. Work with the results of SAST tools to help evaluate and identify false positives and More ❯
in the energy sector, based in the UK Must be able to demonstrate evidence of your skills in implementing and supporting on-premises Microsoft Windows servers, networking infrastructure and security appliances Must be able to demonstrate evidence of your skills in implementing and supporting Azure cloud environments including hybrid cloud/on-premises environments including identity Must … your skills in implementing and supporting Microsoft 365 environments including hybrid identity, Intune, MS Defender, Exchange, Teams and SharrePoint Online Desirable to have certifications in either Azure or AWS cloud platforms Experience working in consultancy is a bonus Experience working in Energy including Oil & Gas is a bonus Who We Are Hypercube Consulting is the leading technology partner for … the energy sector, specialising in cutting-edge cloud and AI solutions. We're building a world-class team of experts with deep domain knowledge in all things energy. To get a better understanding of how we think and some of the ways we work, check out our founder's blog here: First of all - we're adaptable and interested More ❯
Senior Security Engineer | Microsoft Solutions Partner | Edinburgh | Highly Competitive Pay, Performance Bonus + Exceptional Benefits Strengthen Defences. Hunt Threats. Shape the Future of Cybersecurity. Are you ready to take your cyber security expertise to the next level? Join Quorum, a leading Microsoft Solutions Partner and Tier 1 CSP based in Scotland. We're not your average IT consultancy … we're employee-owned, award-winning, and proud holders of 5 out of 6 Microsoft Designations and 3 Specialisations in CloudSecurity, Identity & Access Management, and Microsoft Teams Calling. Now, we're growing our Managed Security Services team and looking for a Senior Security Engineer with a passion for proactive threat detection, automation, and innovation. Why … budget and development pathways Award-winning family-friendly and flexible working culture A genuinely friendly, collaborative team environment with low turnover What You'll Be Doing: As a Senior Security Engineer, you'll be a key player in our mission to protect, detect, and respond to evolving cyber threats. Your day-to-day will include: Leading as an escalation More ❯
The Role in a Nutshell: You will be responsible forIntegrating security into SDLC during the design and development of digital services to ensure a holistic shift-left approach to secure by design. The Impact You'll Make Integrating AppSec security controls in a central security platform (Splunk) with service and SRO-level dashboards. Delivering service-level and … SRO dashboards in Splunk to see security posture and risk exposure for all implemented technologies and security controls. Performing deep security assessments against digital services using manual methods and tools such as Burp Suite, Metasploit, Nikto, Nessus, and ZAP. Security testing and remediating issues in APIs and infrastructure. Conducting threat modeling to identify threats and define … tangible security controls and mitigations. Supporting skills and knowledge transfer of contracted work and technical expertise. What You'll Bring to the Team and the Tools you'll need: You'll bring a comprehensive background inAppSec Engineering/DevSecOps with experience across testing, threat modeling, application development and possess a solid understanding of cyber attack methodologies. Security engineering More ❯