mitigating security risks. Define and enforce security policies for IAM, encryption, network segmentation, and threat detection. Ensure AWS environments comply with industry regulations (e.g., GDPR, PCI-DSS, HIPAA) and integrate necessary controls. Work with DevOps and development teams to integrate security throughout the SDLC and DevOps pipelines. Use IaC tools … of AWS security best practices for IAM, encryption, and data protection. Familiarity with cloud security frameworks and regulatory standards (SOC 2, ISO 27001, GDPR, PCI-DSS). Experience with Terraform, CloudFormation, or AWS CDK for automating security and infrastructure provisioning. Hands-on experience with AWS security services (GuardDuty, Inspector More ❯
quality, integrity, and consistency. - Implement and enforce data security measures to protect sensitive information and comply with legal and regulatory requirements (e.g., GDPR, CCPA). - Work with compliance teams to ensure data practices meet regulatory standards. Data Integration: - Oversee the integration of data from multiple … Power BI) is a plus. • Deep understanding of data governance frameworks and best practices. • Knowledge of security protocols, data privacy regulations (e.g., GDPR, CCPA), and how they apply to data architecture. • Extensive experience in data architecture, database management, and data modeling. • Proven track record of More ❯
Warwick, Warwickshire, United Kingdom Hybrid / WFH Options
ICEO
efficiency, whether for personal finances, business operations, or global investments. What you will do: Drive the company's information security strategy, ensuring alignment with GDPR, ISO 27001, DORA, PSD2 / 3, and other relevant regulations Identify and address local and entity-specific security requirements to maintain rigorous standards Conduct regular … a similar role (ideally in payments or fintech), with proven Second Line of Defense responsibilities in InfoSec and IT Compliance & Frameworks : Demonstrated success meeting GDPR, EU NIS2, and familiarity with ISO 27001, NIST, and cybersecurity best practices Risk & Governance : Skilled in conducting risk assessments, defining mitigation strategies, and creating More ❯
the databases and information platforms in use across the company. · ISO27000 Compliance: Serve as an internal auditor to ensure compliance with ISO27000 standards. – ensure GDPR protocols are adhered to across all systems and platforms · Contribute to the strategic planning of team projects, identifying interdependencies across projects / functions, potential risks … FOI Protocols: Act as BI Records Manager, ensuring Freedom of Information (FOI) protocols and procedures are followed. · Ensure annual certifications across cyber security /GDPR security etc are achieved. · First Point of Contact: Act as the first point of contact for our team, including any customer networks and associated research … systems or work with external service providers for solutions. · Analyse, interpret and present data to highlight issues, risks and support decision making · Ensure GDPR compliance across all data sets and platforms · Ensure Cyber Security Certificate is achieved annually. · Provide operational support across all platforms · Policy Implementation: Support the More ❯
Department Description At Disney, we're storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt's passion was to continuously envision new ways to move audiences around the world More ❯
Empowered - Governance Risk and Compliance (GRC) Software
improvements. Drive customer adoption and engagement by developing product education materials and best practices. Regulatory & Compliance Expertise Stay informed about global regulatory frameworks (e.g., GDPR, SOX, NIST, ISO 27001, DORA) and translate them into product features. Ensure our GRC solutions provide seamless regulatory compliance management and risk mitigation. Cross-Functional … management, cybersecurity, or enterprise SaaS). Strong understanding of GRC frameworks, risk assessment methodologies, and compliance requirements. Experience working with regulatory compliance frameworks (SOX, GDPR, NIST, ISO 27001, PCI-DSS, etc.). Proven ability to translate complex compliance needs into intuitive, scalable software solutions. Familiarity with AI / ML applications More ❯
of hands-on experience in information security or IT infrastructure within an enterprise environment. Familiarity with security standards such as ISO 27001, Cyber Essentials, GDPR, and DataProtection Act. Experience with Microsoft O365 Security solutions and network security operations. Understanding of security testing principles, including vulnerability scanning, risk … IT Security Consultant, Cybersecurity Specialist, Microsoft O365 Security, Enterprise Security Jobs, Information Security Leeds, IT Risk Management, Security Incident Response, Vulnerability Management, ISO 27001, GDPR Compliance, Security Awareness, Disaster Recovery and Business Continuity. More ❯
with DevOps teams to integrate security testing tools (e.g., OWASP ZAP, Snyk) into CI / CD pipelines (Jenkins, GitLab). Ensure compliance with regulations (GDPR, PCI-DSS, HIPAA) through logging, auditing, and monitoring. Assist in security incidents, conduct root cause analysis, and implement preventative security measures. Set up monitoring and … security tools (GuardDuty, Inspector) and third-party vulnerability management tools. Proficiency in scripting (Python, Bash, PowerShell) to automate security tasks. Understanding of industry compliance (GDPR, PCI-DSS, HIPAA) and its implementation in AWS. Strong analytical skills to identify and address vulnerabilities quickly. Excellent communication skills to work effectively with cross More ❯
Manage security monitoring, logging, and alerting to ensure visibility into security events. Support compliance initiatives and audits to ensure adherence to industry standards (e.g., GDPR, PCI-DSS, HIPAA). Collaborate with teams to integrate security throughout the application lifecycle and provide security training. Required Skills & Experience : Strong experience with core … GuardDuty, CloudTrail, Config, WAF). Proficiency in CloudFormation, Terraform, and scripting languages like Python or Bash. Knowledge of compliance standards (SOC 2, ISO 27001, GDPR, PCI-DSS) and experience ensuring compliance in AWS environments. Experience with security incident response, monitoring, and post-incident remediation. Ability to assess and mitigate security More ❯
The Titan Group provides a broad range of services across the whole wealth value chain - from financial planning, investment management through to platform, trading, settlement and custody services. Its strategy is to be able to offer modular, incremental services to More ❯
Information Security Manager Application Deadline: 31 May 2025 Department: Business Operations Employment Type: Full Time Location: London Reporting To: Head of IT Description Why LBR? Join Law Business Research to enjoy an amazing market position, growth opportunities, collaboration, and a More ❯
Apply now Job no: 553837 Work type: Full time Site: Redditch Categories: IT Location: Worcestershire Salary: c.£75,000pa plus aligned Company Benefits Business Area: Halfords Support Centre The Security Architect will play a pivotal role in ensuring that security More ❯
Brighton, England, United Kingdom Hybrid / WFH Options
Membership Bespoke
the end-to-end process of fulfilling data subject requests made under the UK GeneralDataProtectionRegulation (UK GDPR), such as subject access requests and erasure requests, as well as requests for information from other organisations, such as law firms, law enforcement or government … and experience of current and upcoming UK dataprotection law, e.g. the UK GeneralDataProtectionRegulation (UK GDPR), DataProtection Act 2018, Privacy and Electronic Communication Regulations (PECR) and familiarity with guidance published by the Information Commissioner’s Office One or … more recognised dataprotection qualifications, e.g. UK GDPR Practitioner, CIPP / E, CIPM Extensive experience of fulfilling data subject requests made under the UK GDPR Experience of working in a team where providing guidance and advice about UK dataprotection law to internal and external More ❯
West Sussex, England, United Kingdom Hybrid / WFH Options
Membership Bespoke
the end-to-end process of fulfilling data subject requests made under the UK GeneralDataProtectionRegulation (UK GDPR), such as subject access requests and erasure requests, as well as requests for information from other organisations, such as law firms, law enforcement or government … and experience of current and upcoming UK dataprotection law, e.g. the UK GeneralDataProtectionRegulation (UK GDPR), DataProtection Act 2018, Privacy and Electronic Communication Regulations (PECR) and familiarity with guidance published by the Information Commissioner’s Office One or … more recognised dataprotection qualifications, e.g. UK GDPR Practitioner, CIPP / E, CIPM Extensive experience of fulfilling data subject requests made under the UK GDPR Experience of working in a team where providing guidance and advice about UK dataprotection law to internal and external More ❯
tunbridge wells, south east england, United Kingdom Hybrid / WFH Options
Membership Bespoke
the end-to-end process of fulfilling data subject requests made under the UK GeneralDataProtectionRegulation (UK GDPR), such as subject access requests and erasure requests, as well as requests for information from other organisations, such as law firms, law enforcement or government … and experience of current and upcoming UK dataprotection law, e.g. the UK GeneralDataProtectionRegulation (UK GDPR), DataProtection Act 2018, Privacy and Electronic Communication Regulations (PECR) and familiarity with guidance published by the Information Commissioner’s Office One or … more recognised dataprotection qualifications, e.g. UK GDPR Practitioner, CIPP / E, CIPM Extensive experience of fulfilling data subject requests made under the UK GDPR Experience of working in a team where providing guidance and advice about UK dataprotection law to internal and external More ❯
ideal candidate will be experienced with healthcare data standards (e.g. FHIR, OMOP), possess a strong understanding of data privacy regulations (e.g., HIPAA, GDPR), and have technical expertise to design and implement data pipelines, storage systems, and integrations. This role will continue to evolve as the business grows … MongoDB) and cloud-based data warehouses (e.g., Azure Cosmos, Azure Fabric). Maintain strict compliance with data privacy regulations such as HIPAA, GDPR, and other local healthcare policies. Work closely with the clinical team to understand data requirements and translate them into technical solutions. Collaborate with the More ❯
ERPs such as SAP S / 4 HANA and Oracle Fusion. Experience of auditing areas such as DataProtection/ Privacy (including GDPR), IT Strategy, Change Management, Business Continuity & IT Disaster Recovery, IT Infrastructure (including Databases), and IT asset management. Experience of testing of IT general (ITGCs … programmes and system implementations. Experience of using audit software and Microsoft packages. Familiarity with related regulation and frameworks such as Cyber Essentials, NIST, GDPR etc would also be helpful. Strong communication skills (both written and oral) and experience of writing IT internal audit reports will be key. Knowing we More ❯
partners. They will actively participate in national and regional health and social care initiatives, promoting the Trust's expertise and ensuring compliance with UK GDPR, DataProtection Act (2018), and other relevant legislation. The successful candidate will establish and maintain high-quality arrangements for dataprotection … and effective administration of a document management system. Act as the DataProtection Officer fulfilling their statutory duties and responsibilities under the GDPR and the DataProtection Act 2018. Monitor the compliance of the Trust with the dataprotection legislation and reporting any issues … role in a health care organisation. Knowledge Specialist knowledge, good understanding, and experience of applications of the DataProtection Act (2018), UK GDPR, Freedom of Information Act (2000), Records Management Code of Practice (2021) and other relevant legislation. Knowledge of healthcare regulations, data privacy laws . click More ❯
and ISO 90001 certifications. The role ensures that IT security and operations align with global Pluxee policies & procedures as well as regulatory, legal, GDPR and industry standards while mitigating risks and enhancing overall posture. Respond to client Information Security tenders and questionnaires, establish and maintain a central repository of documentation … processes and projects, and take appropriate actions to drive to closure. Conduct regular risk assessments for core platforms, services and vendors. Ensure compliance with GDPR, NIST etc Serve as a subject-matter expert for IT compliance questions Develop and enforce IT policies and procedures that support compliance and risk objectives. … documentation skills. Experience and knowledge of ISO27001 (Information Security Management System) and ISO 9001 (Quality Management System), ideally to Management Representative level. Knowledge of GDPR (GeneralDataProtectionRegulation) rules and obligations. Good knowledge of Information Security Tools, techniques and processes. Good knowledge of Business Continuity More ❯
our 4 key businesses: Alipay+, Antom, WorldFirst and ANEXT Bank. Role Overview: As a GRC Lead , you will ensure alignment with European regulations (e.g., GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCI DSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party … risk , outsourcing compliance , and identity governance to safeguard operational resilience. What you will be doing: Regulatory & Technical Compliance: Support compliance with GDPR and complementary regulations like DORA (Digital Operational Resilience Act) , ensuring alignment in areas such as incident reporting and data protection. Translate requirements from PSD2 SCA , PCI DSS … experience. What we are looking for: Experience: 4+ years in GRC roles ; financial services or banking experience is a strong plus . Understanding of GDPR , DORA , PCI DSS, and outsourcing / third-party risk requirements. Hands-on experience with ISO 27001 implementation and third-party risk tools . Proficiency in More ❯
our 4 key businesses: Alipay+, Antom, WorldFirst and ANEXT Bank. Role Overview: As a GRC Lead , you will ensure alignment with European regulations (e.g., GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCI DSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party … risk , outsourcing compliance , and identity governance to safeguard operational resilience. What you will be doing: Regulatory & Technical Compliance: Support compliance with GDPR and complementary regulations like DORA (Digital Operational Resilience Act) , ensuring alignment in areas such as incident reporting and data protection. Translate requirements from PSD2 SCA , PCI DSS … experience. What we are looking for: Experience: 4+ years in GRC roles ; financial services or banking experience is a strong plus . Understanding of GDPR , DORA , PCI DSS, and outsourcing / third-party risk requirements. Hands-on experience with ISO 27001 implementation and third-party risk tools . Proficiency in More ❯
our 4 key businesses: Alipay+, Antom, WorldFirst and ANEXT Bank. Role Overview: As a GRC Lead , you will ensure alignment with European regulations (e.g., GDPR, DORA, PSD2 SCA, CSSF) and global standards (PCI DSS, SWIFT CSP). This role requires technical knowledge, strategic thinking, and expertise in managing third-party … risk , outsourcing compliance , and identity governance to safeguard operational resilience. What you will be doing: Regulatory & Technical Compliance: Support compliance with GDPR and complementary regulations like DORA (Digital Operational Resilience Act) , ensuring alignment in areas such as incident reporting and data protection. Translate requirements from PSD2 SCA , PCI DSS … we are looking for: Experience: 5+ years in GRC roles ; financial services or banking experience is a strong plus . Regulatory Knowledge: Understanding of GDPR , DORA , PCI DSS, and outsourcing / third-party risk requirements. Technical Skills: Hands-on experience with ISO 27001 implementation and third-party risk tools . More ❯
Department Description At Disney, we're storytellers. We make the impossible, possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt's passion was to continuously envision new ways to move audiences around the world More ❯
Role overview Zaizi is a software consultancy specialising in building bespoke digital solutions using open source software and cloud platforms. We predominantly work with central government agencies and adhere to the Government Digital Service standard. We take security seriously, and More ❯