and threat modelling. Security Operations (SOC) : Overseeing monitoring, incident response, vulnerability management, and operational resilience. Governance, Risk & Compliance (GRC) : Leading our efforts to achieve and maintain compliance with PCI, GDPR, SOC2, and ISO27001. Vendor Security : Spearheading due diligence and monitoring of third parties, integrated with our Vendor Governance Forum. Policies & Assurance : Defining and enforcing security standards, collaborating with IT Ops … You have deep experience overseeing a Security Operations function, managing monitoring, incident response, and vulnerability management. Driving GRC : You're an expert in managing compliance frameworks such as PCI, GDPR, SOC2, and ISO 27001, and you're skilled at preparing for audits. Vendor Security : You have led vendor security analysis, including due diligence and ongoing monitoring. Collaboration & Execution : You can More ❯
GRC Analyst Permanent Southampton - Hybrid £46,000 - £56,000 DOE + Fantastic Benefits About the Role We are seeking a detail-oriented and proactive Governance, Risk, and Compliance (GRC) Analyst to join our team. In this role, you will help More ❯
Responsibilities Own and manage governance, risk, and compliance initiatives for our SaaS platforms. Monitor, review, and improve internal policies, procedures, and controls in line with ISO 27001, SOC 2, GDPR, and other regulatory frameworks. Conduct risk assessments and recommend mitigation strategies for SaaS operations and customer data protection. Collaborate with product, engineering, and IT teams to embed compliance into … related field. 2+ years of experience in GRC, risk management, or compliance (preferably within SaaS or technology companies). Strong knowledge of SaaS compliance frameworks (ISO 27001, SOC 2, GDPR, NIS2, or similar). Ability to interpret regulations and translate them into practical, business-friendly processes. Excellent written and verbal communication skills (German or English; both preferred). Strong organizational … . Experience working with SaaS platforms (AWS, Azure, Salesforce, HubSpot, etc.). Familiarity with vendor risk management and third-party security assessments. Exposure to data privacy laws beyond GDPR (CCPA, UK-GDPR, HIPAA). Role Type Permanent or Contract London-based (Hybrid) or remote About Us Discover tailored data privacy jobs and recruitment opportunities with Lex Dinamica. As More ❯
Responsibilities Own and manage governance, risk, and compliance initiatives for our SaaS platforms. Monitor, review, and improve internal policies, procedures, and controls in line with ISO 27001, SOC 2, GDPR, and other regulatory frameworks. Conduct risk assessments and recommend mitigation strategies for SaaS operations and customer data protection. Collaborate with product, engineering, and IT teams to embed compliance into … related field. 2+ years of experience in GRC, risk management, or compliance (preferably within SaaS or technology companies). Strong knowledge of SaaS compliance frameworks (ISO 27001, SOC 2, GDPR, NIS2, or similar). Ability to interpret regulations and translate them into practical, business-friendly processes. Excellent written and verbal communication skills (German or English; both preferred). Strong organizational … . Experience working with SaaS platforms (AWS, Azure, Salesforce, HubSpot, etc.). Familiarity with vendor risk management and third-party security assessments. Exposure to data privacy laws beyond GDPR (CCPA, UK-GDPR, HIPAA). Role Type Permanent or Contract London-based (Hybrid) or remote About Us Discover tailored data privacy jobs and recruitment opportunities with Lex Dinamica. As More ❯
london (harrow), south east england, united kingdom
Reflection AI
come from DeepMind, OpenAI, Google Brain, Meta, Character.AI, Anthropic and beyond. What You'll Do Develop and maintain company-wide information security policies and frameworks (US: SOC 2, NIST, GDPR; UK: ISO 27001, Cyber Essentials, GDPR) Oversee IT operations across our three offices (London, New York, San Francisco), ensuring systems, devices, and networks remain secure and reliable Lead incident response More ❯
glasgow, central scotland, united kingdom Hybrid/Remote Options
Signify Technology
time analytics pipelines using AWS services (Lambda, EventBridge, Kinesis, Glue, Athena). Security, Compliance & Governance Implement IAM, KMS encryption, VPC networking, and PrivateLink for secure connectivity. Ensure compliance with GDPR/ UK GDPR, PCI-DSS, ISO 27001, and sector-specific standards (e.g., NHS DSP Toolkit, HIPAA). Define data retention policies, PIA / DPIA frameworks, and lawful intercept / … of enterprise-scale Amazon Connect implementations with complex integrations. Expertise in AWS services: IAM, VPC, Lambda, API Gateway, EventBridge, Kinesis, CloudWatch, DynamoDB. Strong knowledge of security and compliance frameworks (GDPR, PCI-DSS, ISO 27001, NHS DSP Toolkit). Hands-on experience with IaC (CloudFormation / Terraform / CDK) and serverless development ). Accessibility Statement: Read and apply for this role More ❯
Sheffield, England, United Kingdom Hybrid/Remote Options
Vallum Associates
hold processes, tracking and releases are properly managed in accordance with audit / regulatory requirements. Define and enforce data retention and disposal policies aligned with regulatory obligations (e.g., GDPR, FCA, PRA) and internal governance mandates. Identify data-related risks across systems, drive mitigation strategies, and maintain a risk-register for data governance activities. Create and maintain project … retention. Experience managing Legal Holds, data retention / disposal frameworks and records management in a regulated environment. Solid understanding of banking / finance regulations impacting data (e.g., GDPR, FCA, PRA, AML / CTF data obligations). Excellent stakeholder engagement, strong communication skills and ability to operate in cross-functional governance teams. Strong analytical, organisational and problem-solving More ❯
Knutsford, Cheshire, United Kingdom Hybrid/Remote Options
Applause IT Recruitment Ltd
environments (Azure / AWS preferred). Lead incident response processes and investigations, coordinating remediation actions. Support compliance programmes - ISO 27001, SOC 2 Type II, and data-protection (GDPR). Deliver regular security reporting and KPI tracking for senior leadership. Drive security awareness training and best practice across the wider team. What You'll Bring 5+ years' experience in … Type II. Hands-on experience with security tools and controls - SIEM, IAM / PAM, endpoint protection, vulnerability management. Working knowledge of data-protection and privacy standards (GDPR, HIPAA). Excellent communication skills - able to collaborate across technical and non-technical teams. Relevant certifications welcomed - CISSP, CISM, CISA, ISO 27001 Lead Implementer or Auditor. Why Apply? Join a More ❯
Newcastle upon Tyne, United Kingdom Hybrid/Remote Options
NHS Business Services Authority
data migration activities. You'll work across multiple migration waves, ensuring readiness, compliance, and successful delivery. Your responsibilities will include: Assuring data migration strategies and plans, including GDPR compliance and data quality, including migrating data from Oracle's Enterprise Business Suite to Oracle's Human Capital Management (HCM) platforms, and from 3rd party applications to HCM. … until 2030. In this role, you are accountable for 1. Providing input into, and assurance of the Suppliers: a. overall data migration strategy, including ensuring compliance with UK GDPRdataprotection laws and other relevant legislation; and b. strategies for individual migration events, or waves, from the start to conclusion of each event; and c. remediation plans More ❯
Payments, core banking, or lending domain expertise. Production experience with Kubernetes, IaC (Terraform), service meshes, and GitOps (Argo CD / Flux). Navigated PCI DSS, SOC 2, ISO 27001, GDPR; partnered with Risk / Compliance and auditors and delivered audit-ready evidence. Privacy engineering (GDPR, data residency) Experience leading across multiple geographies / time zones. Key success indicators DORA More ❯
Job: HR Data Analyst Location: Tunbridge Wells / Hybrid Employment type: Permanent Salary: £34,200 + Excellent bens Are you passionate about using data to drive positive change in HR? Unique opportunity for an analytical and proactive HR More ❯
assets. Contribute to the development of new cyber technologies, strategies, and roadmaps aligned to firm-wide IT goals. Manage vendor relationships and support supplier selection. Ensure compliance with ISO27001, GDPR, Cyber Essentials Plus, and other regulatory frameworks. What Were Looking For Proven experience in Cyber Security, Threat Intelligence, or SOC environments. Hands-on experience with Azure Security Center, Microsoft Sentinel … cyber security and a drive to stay ahead in this constantly evolving space. Qualifications Degree in Cyber Security or a related discipline (desirable) Relevant certifications (ISO27001, Cyber Essentials Plus, GDPR) are advantageous. More ❯
enjoy simplifying regulatory challenges, designing pragmatic governance models, and influencing security strategy at scale this could be your next move. Key Responsibilities Translate international standards (NIST CSF, ISO 27001, GDPR, SOC 2, PCI DSS, CSA CCM) into actionable policies and controls. Design and implement unified compliance frameworks across cloud, hybrid, and enterprise systems. Lead internal and external audits, certification readiness … dashboards. Mentor junior consultants and collaborate closely with cross-functional teams. What We’re Looking For 6–8+ years’ experience in cybersecurity governance, risk, and compliance. Strong background in GDPR and dataprotection frameworks (European experience preferred). Hands-on experience with major cloud environments (AWS, Azure, or GCP). Strong knowledge of compliance automation tools (ServiceNow GRC … or similar). Excellent communication and stakeholder management skills, including C-level engagement. Preferred Certifications CISM, CISA, CRISC, CISSP, ISO 27001 Lead Implementer / Auditor, CCSK, AWS Security Specialty, GDPR Practitioner. If you’re a cybersecurity professional passionate about compliance and looking to take on a new challenge, Apply Now More ❯
enjoy simplifying regulatory challenges, designing pragmatic governance models, and influencing security strategy at scale this could be your next move. Key Responsibilities Translate international standards (NIST CSF, ISO 27001, GDPR, SOC 2, PCI DSS, CSA CCM) into actionable policies and controls. Design and implement unified compliance frameworks across cloud, hybrid, and enterprise systems. Lead internal and external audits, certification readiness … dashboards. Mentor junior consultants and collaborate closely with cross-functional teams. What We’re Looking For 6–8+ years’ experience in cybersecurity governance, risk, and compliance. Strong background in GDPR and dataprotection frameworks (European experience preferred). Hands-on experience with major cloud environments (AWS, Azure, or GCP). Strong knowledge of compliance automation tools (ServiceNow GRC … or similar). Excellent communication and stakeholder management skills, including C-level engagement. Preferred Certifications CISM, CISA, CRISC, CISSP, ISO 27001 Lead Implementer / Auditor, CCSK, AWS Security Specialty, GDPR Practitioner. If you’re a cybersecurity professional passionate about compliance and looking to take on a new challenge, Apply Now More ❯
West Malling, Kent, United Kingdom Hybrid/Remote Options
Lumina Energy
mitigation in collaboration with technical and operational teams Provide assurance over incident response capabilities and governance, ensuring effective escalation procedures Ensure compliance with all relevant regulatory requirements such as GDPR, NIS and the UK DataProtection Act Act as the accountable officer for information security across CSG Report regularly to the Executive Board and Audit & Risk Committee on … CISA Hands on experience managing ISMS and compliance with frameworks such as ISO 27001, NIST, CIS-20CSC and Cyber Essentials Strong understanding of security legislation and regulatory requirements, including GDPR and PCIDSS Confident presenting to Executive Boards, Audit Committees and external stakeholders A collaborative and credible leader, able to influence technical and non technical audiences Experience working at a senior More ❯
Exchange, Teams, SharePoint, OneDrive, Azure AD) Developing and maintaining SQL databases and business reports to support decision-making Leading cybersecurity and compliance initiatives aligned to ISO27001, Cyber Essentials, and GDPR Managing data backups, disaster recovery testing, and IT documentation Providing hands-on technical support and guidance to users across the business Leading, mentoring, and developing a small IT team … ESXi, Microsoft Servers, Microsoft 365, and Fortinet / Cisco networking infrastructure Experience working with SQL databases and generating reports using relevant tools A sound understanding of IT security frameworks, GDPR, and audit compliance Excellent problem-solving skills with a proactive, hands-on approach Strong communication and leadership skills, with the ability to collaborate effectively across teams A self-motivated, organised More ❯
Kettering, Northamptonshire, East Midlands, United Kingdom
Ashdown Group
Exchange, Teams, SharePoint, OneDrive, Azure AD) Developing and maintaining SQL databases and business reports to support decision-making Leading cybersecurity and compliance initiatives aligned to ISO27001, Cyber Essentials, and GDPR Managing data backups, disaster recovery testing, and IT documentation Providing hands-on technical support and guidance to users across the business Leading, mentoring, and developing a small IT team … ESXi, Microsoft Servers, Microsoft 365, and Fortinet / Cisco networking infrastructure Experience working with SQL databases and generating reports using relevant tools A sound understanding of IT security frameworks, GDPR, and audit compliance Excellent problem-solving skills with a proactive, hands-on approach Strong communication and leadership skills, with the ability to collaborate effectively across teams A self-motivated, organised More ❯
Exchange, Teams, SharePoint, OneDrive, Azure AD) Developing and maintaining SQL databases and business reports to support decision-making Leading cybersecurity and compliance initiatives aligned to ISO27001, Cyber Essentials, and GDPR Managing data backups, disaster recovery testing, and IT documentation Providing hands-on technical support and guidance to users across the business Leading, mentoring, and developing a small IT team … ESXi, Microsoft Servers, Microsoft 365, and Fortinet / Cisco networking infrastructure Experience working with SQL databases and generating reports using relevant tools A sound understanding of IT security frameworks, GDPR, and audit compliance Excellent problem-solving skills with a proactive, hands-on approach Strong communication and leadership skills, with the ability to collaborate effectively across teams A self-motivated, organised More ❯
Crawley, England, United Kingdom Hybrid/Remote Options
People's Partnership
and other relevant standards. Ensure ongoing compliance with industry regulations and internal governance requirements. Threat Intelligence And Vulnerability Management Stay current on new threats, vulnerabilities, and regulatory changes (e.g., GDPR, ISO 27001). Conduct threat modelling assessments for new interconnected technologies. What We’re Looking For Strong ability to identify, assess, and prioritise security risks across systems, applications, and third … party vendors. CISSP qualification Strong understanding of ISO 27001, CIS Controls, GDPR and familiarity with NIST. Experience with securing Azure cloud environments including configuration best practices. Strong analytical skills to assess threats, investigate incidents, and recommend effective solutions. Commitment to staying current with emerging threats, vulnerabilities, and evolving security technologies. Disability Statement People's Partnership is an equal opportunities employer. More ❯
Birmingham, West Midlands, United Kingdom Hybrid/Remote Options
Tarmac Trading Limited
control assurance and financial reporting activities, supporting key initiatives across the business. What youll be doing IT Governance & Risk Management Support control design, risk assessments, and compliance monitoring (e.g., GDPR, ISO 27001). Financial Planning & Analysis Assist in budgeting, forecasting, and ROI modelling for technology investments. Automation & Insight Generation Apply tools and techniques to streamline control testing and financial reporting. … remediation tracking. Contribute to IT risk assessments and maintain the IT risk register. Participate in assurance reviews and control maturity assessments. Monitor compliance with relevant regulatory requirements, such as GDPR and ISO 27001. Collaborate with IT, Cybersecurity, and Business Operations teams to promote awareness of control frameworks. Assist in the development of dashboards and reports for control and assurance metrics. More ❯
Manchester, Lancashire, United Kingdom Hybrid/Remote Options
Smart DCC
Cross Domain Collaboration: Drive alignment and coherence across domain architectures to ensure performance, security, and operational integrity. Compliance & Governance: Maintain adherence to regulatory and security obligations (e.g., ISO 27001, GDPR) and ensure architectural governance processes are embedded across delivery teams. Your skills that will enable us to fulfil our purpose: Extensive experience in Enterprise and Solution Architecture, ideally with TOGAF … Azure, GCP), and hybrid architecture models. Proven expertise in technology risk management, asset lifecycle governance, and configuration management. Knowledge of secure architecture design, cybersecurity frameworks, and regulatory compliance (e.g., GDPR, ISO 27001). Strong leadership, communication, and stakeholder management skills across both technical and non technical audiences. Experience integrating systems across diverse platforms using APIs, middleware, and data transformation More ❯
various levels within an organization; Experience in delivering data privacy compliance frameworks and / or programmes; In depth knowledge of data privacy laws in particular EUGDPR, UK GDPR and DataProtection Act 2018; Experience of information governance practises and information security management systems (ISO27001); Experience in digital health; Experience in emerging technologies such as More ❯
luton, bedfordshire, east anglia, united kingdom Hybrid/Remote Options
easyJet
and attention to detail to ensure the accuracy and completeness of data Technical Expertise: Deep understanding of: o Relevant dataprotection laws and regulations, such as GDPR o Data management frameworks for each of the data management capabilities (data quality, reference data management and metadata management) o Data management tools (data … data platform environment Desirable Knowledge of delivery techniques e.g. SCRUM, Agile & Waterfall Data Management principles – tagging, access management, data privacy, handling of sensitive data (e.g. GDPR) and data lineage Knowledge of the DataOps processes for the continuous deployment of UCDAs to production environments Data Science machine learning (MLOps) model lifecycle Worked with modern lakehouse More ❯
Luton, England, United Kingdom Hybrid/Remote Options
easyJet
and attention to detail to ensure the accuracy and completeness of data Technical Expertise: Deep understanding of: o Relevant dataprotection laws and regulations, such as GDPR o Data management frameworks for each of the data management capabilities (data quality, reference data management and metadata management) o Data management tools (data … data platform environment Desirable • Knowledge of delivery techniques e.g. SCRUM, Agile & Waterfall • Data Management principles – tagging, access management, data privacy, handling of sensitive data (e.g. GDPR) and data lineage • Knowledge of the DataOps processes for the continuous deployment of UCDAs to production environments • Data Science machine learning (MLOps) model lifecycle • Worked with modern lakehouse More ❯
measurable impact. Design scalable, secure data infrastructure within cloud environments (AWS, Azure, or GCP). Define and embed data governance frameworks ensuring compliance with regulations such as GDPR and CCPA. Translate data insights into actionable business recommendations for senior stakeholders and C-suite leaders. Track and report on data transformation progress, ensuring alignment with fund-wide … Azure, GCP) and modern data infrastructures. Knowledge of machine learning applications (e.g. predictive modelling, AI, analytics) and their business use cases. Expertise in data governance and compliance (GDPR, CCPA). Excellent communication and stakeholder management skills, with confidence engaging at C-level. Comfortable operating in fast-paced, ambiguous environments with multiple projects running concurrently. A degree in a More ❯