1 to 25 of 57 ISO 27001 Lead Auditor Jobs in the UK

Senior Security Consultant

Location
City Of London, England, United Kingdom
Define, implement and monitor corporate information security strategies, objectives and governance frameworks. Design and implement information security management systems and security master plans. Lead risk management activities, including risk identification, assessment, treatment and reporting. Define cybersecurity action plans and oversee their execution. Ensure the protection of services … analyses and defining continuity and testing plans. Implement and maintain information security controls aligned with applicable laws, regulations, standards and best practices, including ISO 27001 / 27002, GDPR, Cyber Assessment Framework (CAF) and NIST CSF. Develop and maintain information security policies, standards and procedures ...

Security Engineer, Compliance Focus

Location
Greater London, England, United Kingdom
here is not a paperwork exercise at the edge of the business. It is a condition of doing business. We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure … control is actually working or only described. What You Will Be Doing Compliance Execution Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline. Operate our GRC platform ...

Cyber Security Controls Tester (Assurance)

Location
City Of London, England, United Kingdom
Evaluate the effectiveness of technical, procedural, and physical security controls against documented security requirements and standards. Assess security controls against recognised frameworks including ISO 27001 , NIST CSF , NIST 800-53 , and CIS Controls . Review security documentation, including High-Level Designs (HLDs), Low-Level … Required Skills & Experience Proven experience testing and assessing the effectiveness of security controls within complex enterprise environments. Strong knowledge of security frameworks including: ISO 27001 NIST Cyber Security Framework (CSF) NIST 800-53 CIS Controls Experience reviewing and testing: Network security controls Firewall configurations ...

Supplier Assurance Lead

Hiring Organisation
Morson Edge
Location
Greater Manchester, North West, United Kingdom
Employment Type
Contract
Supplier Assurance Lead / Cyber Security Risk Manager / Third Party Cyber Risk Lead £500 per day - Outside IR35 - North West Based - Hybrid My client is looking for an experienced Supplier Assurance Lead to join their Cyber Security team, taking … lead role in identifying, assessing and managing cyber security risks across a complex supplier and third-party ecosystem. This is a senior position requiring someone who can go beyond standard supplier due diligence exercises. Youll be expected to understand the underlying cyber security risks within the supply ...

Senior GRC Analyst

Location
Horwich, England, United Kingdom
security risk assessments across projects, systems, and technology changes, identifying risks and recommending practical controls. Support the maintenance and continuous improvement of the ISO 27001-aligned Information Security Management System (ISMS). Review and maintain information security policies, standards, procedures, and control frameworks … equivalent level. Demonstrable experience supporting regulatory, certification, or external security audit readiness, including evidence coordination and remediation management. Hands‐on experience with ISO 27001-aligned Information Security Management Systems and information security policy and control governance. Experience conducting project and technology security risk assessments ...

Information Security & GRC Specialist

Location
Manchester, England, United Kingdom
ISMS), helping ensure Vix remains compliant, audit-ready and continually improving. Working across Security, Engineering, Technology and the wider business, you’ll coordinate ISO 27001 activities, prepare for internal and external audits, manage evidence and help drive remediation actions through to completion. … help get things fixed. What You’ll Be Doing Own the day-to-day coordination and continuous improvement of our ISMS. Support ISO 27001 certification, surveillance and internal audits. Coordinate audit evidence and work with stakeholders to close findings and remediation actions. Maintain security ...

Information Security Analyst

Hiring Organisation
4Square Recruitment Ltd
Location
Farnborough, Hampshire, United Kingdom
Employment Type
Full-Time
Salary
£45,000 - £55,000 per annum
recruiting for an Information Security Analyst to join a growing organisation based in Farnborough. This is a varied role combining information security, ISO 27001, data protection and hands-on technical support . You’ll work closely with internal teams and customers, helping to resolve … will be responsible for: Troubleshooting hardware, software and network-related issues Identifying, triaging and escalating potential security incidents Ensuring support activities follow ISO 27001 and data protection requirements Maintaining accurate documentation and audit trails Supporting the implementation of security controls and best practice Identifying ...

IT Security Governance, Risk & Controls Analyst

Hiring Organisation
Ricoh
Location
London, United Kingdom
Employment Type
Permanent
plans. Assess the effectiveness of security controls and identify control gaps, weaknesses and opportunities for improvement . Translate security frameworks and requirements, including ISO 27001 and NIST CSF , into practical operational controls. Support audit, assurance and compliance activities , including ISO 27001 … principles . Experience conducting or supporting technology / security risk assessments and maintaining risk registers. Good knowledge of security control frameworks such as ISO 27001 and NIST CSF . Experience assessing control design and effectiveness , identifying gaps and supporting remediation. Understanding ...

Security Manager

Location
Bradford, England, United Kingdom
technical security requirements with governance, compliance, and stakeholder engagement. Key Responsibilities Manage and maintain compliance with security standards and accreditations including PCI DSS, ISO 27001, ISO 22301, Cyber Essentials Plus and IT Health Checks. Conduct internal audits, control reviews, and risk … Security Manager or similar information security role. Strong understanding of cyber security, governance, risk, and compliance frameworks. Extensive knowledge of PCI DSS, ISO 27001, Cyber Essentials Plus, and data protection requirements. Experience with Microsoft 365, Azure, AWS, vulnerability management, and SIEM tools. Strong communication ...

Senior GRC Analyst

Location
Greater London, England, United Kingdom
Manage and continuously improve Preply's risk management framework, defining risk management approaches and overseeing the implementation of mitigation actions across the business. Lead risk assessments. Run enterprise risk assessments, surfacing both technical and non-technical risks, and track Key Risk Indicators (KRIs) and other data-driven … governance checks into everyday business operations. Drive SOC 2 and beyond. Support compliance initiatives for SOC 2 Type 2, with potential expansion to ISO 27001, ensuring controls are documented, tested, and audit-ready. Support privacy initiatives. Contribute to data retention policies and guidelines ...

Information Security Analyst

Location
Nottingham, England, United Kingdom
practitioner against their outputs. The role also requires genuine compliance capability, you will contribute to internal audit and risk assessment cycles and support ISO 27001 compliance activity. You will provide ad-hoc expert input to the IT function where security judgement is needed … programme, including coordination of internal and external penetration testing Conducting internal security audits and risk assessments, producing findings reports and tracking remediation Supporting ISO 27001 compliance activity, including contributing to control evidence and audit cycles Producing clear written outputs -- findings reports, risk registers, policy ...

Principal Security Officer

Location
Reading, England, United Kingdom
delivery of the wider security strategy and improvement plan. Provide leadership, guidance and technical oversight to Information Security Officers within the team. Lead significant security projects and initiatives from assessment and design through to implementation. Own and drive improvements to the organisation's ISMS, security controls … overall cyber maturity . Lead security assessments across infrastructure, networks, endpoints, applications, cloud environments and data. Provide security input into technical architecture and design decisions. Work with technical teams to implement appropriate security controls around identity, access management, SSO and federated services . Oversee information security risk ...

ISO 27001 ISMS Consultant - Hybrid, Client-Facing

Location
England, United Kingdom
Hewett Recruitment is seeking an experienced Information Security Consultant for a Worcestershire-based client. The role focuses on ISO 27001 consultancy, implementation and audits, delivering practical recommendations to improve ISMS. You will lead consultancy assignments, manage client relationships … translate findings into clear reports. Relevant ISO 27001 Lead Auditor / Lead Implementer credentials are preferred. #J-18808-Ljbffr ...

Cyber Security Controls Tester (Contractor)

Location
Stone Cross, England, United Kingdom
supporting documentation, including High-Level Designs (HLDs), Low-Level Designs (LLDs) and Controls Catalogues. Testing controls against recognised security frameworks and standards, including ISO 27001, NIST CSF and NIST 800-53. Reviewing policies, procedures, network configurations, firewall rules, identity and access management controls … testing and evaluating the effectiveness of technical, procedural and physical security controls within complex environments. Strong working knowledge of security control frameworks including ISO 27001, NIST CSF, NIST 800-53 and CIS Controls. Experience conducting controls testing, assurance or audit activities against recognised security ...

GRC Engineer

Location
Belfast City District, Northern Ireland, United Kingdom
querying, and control automation. You'll be a key player in maintaining our compliance posture across frameworks like SOC 2, NIST CSF, and ISO 27001, while also helping modernize how we monitor and evidence controls using platforms like Anecdotes. This role suits someone … preparation for and execution of SOC 2 (Type I / II) audits, working directly with external auditors to scope, evidence, and remediate findings Lead or support NIST CSF assessments and gap analyses, translating results into actionable remediation plans Support alignment and readiness activities for ISO ...

GRC Consultant

Hiring Organisation
Big Red Recruitment
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £70,000 per annum
responsibilities include: Supporting client engagements focused on governance, risk and compliance Advising organisations on cyber security frameworks and standards Supporting and delivering ISO 27001 aligned engagements Conducting cyber security maturity assessments Supporting clients with security governance, resilience and business continuity initiatives Working closely with … consultants and principals across multiple projects Skills & Experience Experience working in cyber security governance, risk and compliance Experience working with frameworks such as ISO 27001 and / or NIST CSF Experience working in a cyber security consultancy or advisory environment is highly desirable Experience ...

GRC Senior Analyst

Location
Greater London, England, United Kingdom
levels and influence outcomes in support of enterprise projects. You will be confident working across the major information security frameworks and standards, including ISO 27001, NIST and SOC 2, and able to shape risk, compliance and control decisions in a way that keeps both … Client Delivery: Provide security subject matter expertise across our internal technology initiatives, collaborating with project managers, business stakeholders and operational teams, and lead client GRC engagements end to end from gap assessment and framework implementation through to audit readiness and ongoing advisory. Measurement and Insight: Maintain ...

Information Security Officer

Location
Reading, England, United Kingdom
continually improve the organisation's Information Security Management System (ISMS) , including policies, procedures and controls. Support the implementation and ongoing management of ISO 27001, Cyber Essentials Plus, PCI-DSS, NIST / CIS Controls and other relevant security requirements. Conduct security assessments across infrastructure, networks … endpoints, applications and data. Identify, assess and manage information security risks, including maintaining risk registers and tracking remediation. Lead and support internal and external security audits , including evidence gathering, control testing and remediation of findings. Manage technical security risks within Data Protection Impact Assessments and policy exceptions. ...

Information Security Manager

Hiring Organisation
Reed Technology
Location
Cambridge, Cambridgeshire, East Anglia, United Kingdom
Employment Type
Permanent
health organisation that develops market-leading healthcare technology used by people across international markets. We are seeking an experienced Information & Cybersecurity Manager to lead information security, product cybersecurity and cyber risk management across a growing, highly regulated technology environment. This is a unique opportunity to become … cybersecurity throughout the software and product development lifecycle. Key Responsibilities Maintain and improve the Information Security Management System (ISMS), policies, procedures and controls. Lead cybersecurity risk assessments, threat modelling and security reviews. Oversee penetration testing, vulnerability management and remediation activities. Advise on secure design, cloud security, mobile ...

Senior Trust Security Analyst

Location
Greater London, England, United Kingdom
teams, ensuring alignment with agreed timelines and compliance requirements. Audit Audit Interpretation: Read and interpret third-party audit reports (SOC 2 Type II, ISO 27001, penetration test summaries) and represent findings to customers in questionnaires and security responses. Communication & Stakeholder Management Information Translation: Gather … Hands-on experience responding to SIG, CAIQ, VSA, and bespoke enterprise / government security questionnaires. Compliance Knowledge: Working knowledge of Cyber Essentials Plus, ISO 27001, SOC 2 Type II, and at least one of PCI DSS, GDPR / UK GDPR, HIPAA, or FedRAMP. Technical ...

IT Security Compliance & Reporting Analyst

Hiring Organisation
Ricoh
Location
London, United Kingdom
Employment Type
Permanent
security and technology risk assessments , working with technical teams to identify appropriate and practical mitigation plans. Support audit, assurance and compliance activities , including ISO 27001, Cyber Essentials and internal control programmes. Translate security frameworks and regulatory requirements into practical, operational standards and controls . … Security Compliance . Experience developing and maintaining security policies, standards, controls and governance documentation . A strong understanding of security frameworks such as ISO 27001 and NIST CSF . Experience producing security compliance reporting, MI or dashboards , ideally using Power BI. Experience managing ...

GRC Assurance Manager

Location
Greater London, England, United Kingdom
design and operate the processes, methodologies, and relationships that enable continuous validation of our security controls, supporting certifications such as TISAX and ISO 21434, meeting customer contractual commitments, and strengthening trust across the organisation. This is an opportunity to build a security assurance capability from the ground … strong governance with the realities of a fast-moving engineering-led organisation. Desirable Experience supporting security assurance programmes for frameworks such as TISAX, ISO 21434, ISO 27001, SOC 2, or similar. Experience helping organisations evolve from periodic assurance towards continuous assurance. ...

GRC Assurance Manager

Location
Greater London, England, United Kingdom
design and operate the processes, methodologies, and relationships that enable continuous validation of our security controls, supporting certifications such as TISAX and ISO 21434, meeting customer contractual commitments, and strengthening trust across the organisation. This is an opportunity to build a security assurance capability from the ground … strong governance with the realities of a fast-moving engineering-led organisation. Desirable Experience supporting security assurance programmes for frameworks such as TISAX, ISO 21434, ISO 27001, SOC 2, or similar. Experience helping organisations evolve from periodic assurance towards continuous assurance. ...

CLOUD SECURITY ARCHITECT

Location
Greater London, England, United Kingdom
reference architectures and reusable solution patterns Define and author enterprise‐level security policies, controls frameworks, and governance documentation aligned to industry standards Lead risk assessments, threat modelling exercises, and security posture evaluations for cloud platforms and SaaS products, utilising methodologies such as FAIR Drive compliance programmes covering … ISO 27001, Cyber Essentials Plus, PCI DSS, and other relevant regulatory frameworks Support DevSecOps adoption and integrate security tooling and controls into CI / CD pipelines across client delivery teams Engage senior stakeholders and executive teams with clear security risk reporting, remediation guidance ...

Third Party Cyber Risk Lead

Hiring Organisation
Hays Technology
Location
City of London, London, Cheap, United Kingdom
Employment Type
Permanent
Salary
£80000 - £90000/annum Up to 90k, plus bonus
Third Party Cyber Risk Lead Please read carefully and contact Lorenz Pasch at Hays on (phone number removed) or if you are from the Insurance or Financial Services sector only, and are interested in the position. London | Hybrid£90,000 + Benefits We are seeking a Third … Party Cyber Risk Lead to take ownership of cybersecurity risk across its supplier and vendor ecosystem. This is a key role within the Business Information Security Office, responsible for ensuring third-party cyber risks are identified, assessed, managed and reported effectively across a complex and regulated insurance ...