Protection Administrator, CISSP, CISM, CISA, Cisco, SANS, etc) are a plus. Preferred Skills Experience with data loss prevention (DLP) technologies and strategies. Familiarity with compliance regulations (e.g., GDPR, HIPAA) and dataprotection laws. Knowledge of cloud security concepts and technologies. Working with Us: As a Northern Trust partner, greater achievements await. You will be part of More ❯
London, England, United Kingdom Hybrid / WFH Options
ConSol Partners
incidents, when necessary. Lead information security awareness programs and provide training to employees on security best practices, regulatory compliance, and emerging threats. Ensure compliance with industry-specific regulations (e.g., GDPR, ISO 27001, industry standards) and client's internal policies. Oversee audits and inspections to verify adherence to internal security policies and ensure that compliance requirements are met. Serve as the … process manufacturing sectors, with a strong understanding of industry-specific risks and challenges. In-depth knowledge of cybersecurity frameworks, risk management practices, and regulatory requirements (e.g., NIST, ISO 27001, GDPR). Experience with industrial control systems (ICS) and operational technology (OT) security in manufacturing or production environments. Strong expertise in network security, encryption, identity and access management, and endpoint protection. More ❯
controls to manage the protection of personal data, privacy and human rights, supporting regulatory, legal, risk, environmental and operational requirements, and ensuring compliance with those requirements. (e.g. GDPR, DataProtection). Internal Controls Oversight: Establish and monitor internal controls to safeguard data and assets, conducting regular reviews and audits. Stakeholder Engagement: Serve as a liaison More ❯
monitoring, detection, and response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. Oversee endpoint security, cloud network and API security for robust protection across all … Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign-On (SSO), and Privileged Access Management (PAM). Threat Management & Incident Response More ❯
monitoring, detection, and response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. • Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). • Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. • Oversee endpoint security, cloud network and API security for robust protection across all … Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. • Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. • Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign-On (SSO), and Privileged Access Management (PAM). • Threat Management & Incident Response More ❯
Leadership Own and evolve our ISMS (Information Security Management System), ensuring it remains fit for purpose as we scale. Maintain and advance compliance across ISO 27001, SOC2, Cyber Essentials, GDPR, and any emerging frameworks (e.g. PCI DSS, AI governance), ensuring we are audit-ready. Identify, assess, and mitigate security risks across infrastructure, systems, and vendors - flagging and resolving vulnerabilities before … they become problems. Own security documentation, policies and access protocols, ensuring regular audits and updates. Lead on GDPR compliance (or arrange the appropriate support and tools) to manage data privacy obligations, including DSARs, DPIAs and risk assessments. Maintain a clear and up-to-date sub-processor list and lead on third-party risk management. Act as primary contact for … access reviews and alerting. Governance and Process Clarity Ensure security policies are clearly documented, visible, and adopted company-wide. Support the business in navigating legal and regulatory change (e.g. GDPR, international expansion, AI etc). Run awareness sessions, training and security onboarding to embed a culture of ownership and care. Partner with leadership to ensure policies align with the day More ❯
disaster recovery. Identify key risks and control weaknesses, providing practical and strategic recommendations for remediation. Evaluate compliance with internal policies, industry best practices, and regulatory requirements (e.g., FCA, PRA, GDPR, ISO 27001, PCI-DSS). Collaborate with business and IT stakeholders to understand operational processes and system architecture. Prepare detailed audit reports and present findings to senior management. Support external More ❯
Birmingham, England, United Kingdom Hybrid / WFH Options
Ampa Holdings LLP
Procedure Development: Develop, implement, and maintain security policies, standards, and procedures to protect the firm's digital assets. Compliance: Ensure compliance with relevant laws, regulations, and industry standards, including GDPR and other dataprotection regulations. This will include ensuring ongoing ISO27001 and CE+ accreditation. Incident Response: Lead the firm's response to security incidents and breaches, ensuring timely … program and any emerging threats. What you will need: Previously led teams of Information Security professionals. Depth of knowledge of Information Security standards, tools and processes. Good understanding of GDPR, COBIT, ISO27001, PCI DSS, Cyber Essentials (including Plus) and risk management frameworks. Familiarity with industry leading security products and solutions. Practical, real-life and hands-on experience of security technologies. More ❯
monitoring, detection, and response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. • Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). • Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. • Oversee endpoint security, cloud network and API security for robust protection across all … Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. • Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. • Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign-On (SSO), and Privileged Access Management (PAM). • Threat Management & Incident Response More ❯
NIS2 Review and select third-party security solutions; lead due diligence with EPC, O&M and SCADA vendors Serve as technical SME for compliance frameworks (ISO 27001, NIST CSF, GDPR, IEC 62443, CIS Controls) Collaborate with the DPO on data flow mapping, impact assessments (DPIA), breach notification readiness and audit responses Track emerging threats to the energy sector (e.g. More ❯
City of London, London, United Kingdom Hybrid / WFH Options
NextEnergy Group
NIS2 Review and select third-party security solutions; lead due diligence with EPC, O&M and SCADA vendors Serve as technical SME for compliance frameworks (ISO 27001, NIST CSF, GDPR, IEC 62443, CIS Controls) Collaborate with the DPO on data flow mapping, impact assessments (DPIA), breach notification readiness and audit responses Track emerging threats to the energy sector (e.g. More ❯
Manchester, England, United Kingdom Hybrid / WFH Options
Tunstall Healthcare Group
is recoverable and secure. Security: Implement and maintain robust security measures to protect sensitive healthcare data in compliance with global dataprotection regulations (e.g., HIPAA, GDPR). Data Integration: Support ETL processes, data migrations, and integration projects with other systems and third-party applications. Database Development: Collaborate with application developers to design database schemas … organization is highly desirable. Demonstrated expertise in scaling databases to support large scale operations, including real-time data access. Proven experience in working within regulatory frameworks like HIPAA, GDPR, or HITECH. Familiarity with audit preparation and reporting for database compliance. Proven experience in managing and resolving critical database outages with minimal downtime. Knowledge of emergency response protocols for ensuring More ❯
OS . Knowledge of network perimeter security, including firewalls, WAF, anti-virus, and O365 compliance & security centre . Familiarity with NIST (CSF Framework 2.0), ISO 27001, PCI-DSS, and GDPR . Experience operating and managing SIEM solutions , vulnerability management tools, and secure configuration tooling. Ability to use PowerShell and Python scripting for security automation. Experience working in or with agile More ❯
/ Skills: Comprehensive Understanding of the Financial Services Industry : Wealth Management, Private Banking & Commercial Banking. While not essential, this knowledge is highly desirable. Familiarity with Financial Services Regulations : Including GDPR/DataProtection, Vulnerable Clients, and related compliance requirements. Experience with Fintech Systems : understanding or experience with Core Banking systems, client-facing banking platforms, investment platforms, and CRM More ❯
Certified Solutions Architect – Professional). Experience with hybrid cloud and multi-cloud data architecture strategies. Familiarity with data governance, data privacy, and regulatory compliance frameworks (., GDPR). Our Commitment to Diversity & Inclusion: Did you know that Apexon has been Certified by Great Place To Work, the global authority on workplace culture, in each of the three More ❯
London, England, United Kingdom Hybrid / WFH Options
FSP
delivering and deploying information security outcomes, solutions and services Demonstrable experience of industry frameworks and standards, including UK government, public and private sector; such as ISO27001, NIS Directives, NIST, GDPR, DORA, Cyber Essentials, PCI and UK Government Functional Standards Experienced in leading and managing successful GRC / Information Security projects Capable of effectively communicating and showcasing the strategic benefits of More ❯
Certified Solutions Architect – Professional). Experience with hybrid cloud and multi-cloud data architecture strategies. Familiarity with data governance, data privacy, and regulatory compliance frameworks (e.g., GDPR). Our Commitment to Diversity & Inclusion: Did you know that Apexon has been Certified by Great Place To Work, the global authority on workplace culture, in each of the three More ❯
Hounslow, England, United Kingdom Hybrid / WFH Options
MarkJames Search
CI / CD pipelines, and tools such as GitHub Actions, Jenkins, or cloud-native DevOps tools. Strong knowledge of cloud security features and experience ensuring compliance with standards like GDPR, HIPAA, or ISO 27001. Ability to monitor and optimize cloud resource usage and costs using tools like Cost Management dashboards. Expertise in troubleshooting and resolving complex cloud issues using monitoring More ❯
London, England, United Kingdom Hybrid / WFH Options
ZipRecruiter
leveraging services such as EC2, S3, Lambda, RDS, Aurora, EKS, and more. Develop secure cloud infrastructure aligned with regulatory and compliance requirements (e.g., PCI DSS, ISO 27001, SOC 2, GDPR). Enforce best practices for and access management, dataprotection, and incident response. Collaborate with business units, software developers, DevOps engineers, and security teams to integrate AWS solutions More ❯
, encryption, identity and access management (IAM), and security information and event management (SIEM) systems. Strong understanding of security frameworks, standards, and regulations, including ISO 27001, NIST Cybersecurity Framework, GDPR , NCSC Cyber Essentials Plus, with experience in implementing and maintaining compliance with these requirements. Excellent leadership and communication skills, with the ability to effectively communicate security-related concepts and risks More ❯
Group Technology) - Group IT Security. Stay up-to-date with the latest cybersecurity threats and trends and escalate risks promptly. Ensure compliance with relevant industry regulations and standards (e.g., GDPR and any other applicable to the IT). Evaluate GT s compliance with relevant regulatory standards (eg ISO 27001) as part of critical vendor performance assessment ensuring operational resilience is More ❯
London, England, United Kingdom Hybrid / WFH Options
NextEnergy Group
/ 27019 and NIS2 Evaluate and select third-party security solutions and conduct vendor due diligence Serve as SME for compliance frameworks such as ISO 27001, NIST CSF, GDPR, IEC 62443, and CIS Controls Collaborate on data flow mapping, impact assessments, breach response, and audit preparations Monitor emerging threats in the energy sector and update architecture strategies accordingly Skills More ❯
Cambridge, England, United Kingdom Hybrid / WFH Options
Murnen Design
loss prevention (DLP) Endpoint protection Security operations and incident response Experience in developing and implementing security policies, procedures, and standards. Understanding of legal and regulatory frameworks (e.g., GDPR, ISO 27001, NIST SP 800-171). Excellent communication, collaboration, and interpersonal skills, with the ability to effectively communicate complex technical information to both technical and non-technical audiences. Experience More ❯
About the role Please note we're open to considering both Interim and Permanent applications for this opportunity. As the Director ofManagement Information & Business Insights you'll drive the evolution of our data strategy, enabling data-driven decisions More ❯
and best practices, particularly in AWS Experience in managing security incidents and leading incident response Excellent knowledge of security frameworks, standards, and regulations, including ISO 27001, SOC 2, HIPAA, GDPR, etc. Good communication and interpersonal skills, with the ability to effectively communicate security-related questions to technical and non-technical stakeholders (employees, customers, and / or partners) Project management skills More ❯