1 to 25 of 31 Remote/Hybrid ISO 27001 Lead Auditor Jobs in the UK

Senior Security Consultant

Location
City Of London, England, United Kingdom
Define, implement and monitor corporate information security strategies, objectives and governance frameworks. Design and implement information security management systems and security master plans. Lead risk management activities, including risk identification, assessment, treatment and reporting. Define cybersecurity action plans and oversee their execution. Ensure the protection of services … analyses and defining continuity and testing plans. Implement and maintain information security controls aligned with applicable laws, regulations, standards and best practices, including ISO 27001 / 27002, GDPR, Cyber Assessment Framework (CAF) and NIST CSF. Develop and maintain information security policies, standards and procedures ...

Cyber Security Controls Tester (Assurance)

Location
City Of London, England, United Kingdom
Evaluate the effectiveness of technical, procedural, and physical security controls against documented security requirements and standards. Assess security controls against recognised frameworks including ISO 27001 , NIST CSF , NIST 800-53 , and CIS Controls . Review security documentation, including High-Level Designs (HLDs), Low-Level … Required Skills & Experience Proven experience testing and assessing the effectiveness of security controls within complex enterprise environments. Strong knowledge of security frameworks including: ISO 27001 NIST Cyber Security Framework (CSF) NIST 800-53 CIS Controls Experience reviewing and testing: Network security controls Firewall configurations ...

Senior GRC Analyst

Location
Horwich, England, United Kingdom
security risk assessments across projects, systems, and technology changes, identifying risks and recommending practical controls. Support the maintenance and continuous improvement of the ISO 27001-aligned Information Security Management System (ISMS). Review and maintain information security policies, standards, procedures, and control frameworks … equivalent level. Demonstrable experience supporting regulatory, certification, or external security audit readiness, including evidence coordination and remediation management. Hands‐on experience with ISO 27001-aligned Information Security Management Systems and information security policy and control governance. Experience conducting project and technology security risk assessments ...

Principal Security Officer

Location
Reading, England, United Kingdom
delivery of the wider security strategy and improvement plan. Provide leadership, guidance and technical oversight to Information Security Officers within the team. Lead significant security projects and initiatives from assessment and design through to implementation. Own and drive improvements to the organisation's ISMS, security controls … overall cyber maturity . Lead security assessments across infrastructure, networks, endpoints, applications, cloud environments and data. Provide security input into technical architecture and design decisions. Work with technical teams to implement appropriate security controls around identity, access management, SSO and federated services . Oversee information security risk ...

ISO 27001 ISMS Consultant - Hybrid, Client-Facing

Location
England, United Kingdom
Hewett Recruitment is seeking an experienced Information Security Consultant for a Worcestershire-based client. The role focuses on ISO 27001 consultancy, implementation and audits, delivering practical recommendations to improve ISMS. You will lead consultancy assignments, manage client relationships … translate findings into clear reports. Relevant ISO 27001 Lead Auditor / Lead Implementer credentials are preferred. #J-18808-Ljbffr ...

Cyber Security Controls Tester (Contractor)

Location
Stone Cross, England, United Kingdom
supporting documentation, including High-Level Designs (HLDs), Low-Level Designs (LLDs) and Controls Catalogues. Testing controls against recognised security frameworks and standards, including ISO 27001, NIST CSF and NIST 800-53. Reviewing policies, procedures, network configurations, firewall rules, identity and access management controls … testing and evaluating the effectiveness of technical, procedural and physical security controls within complex environments. Strong working knowledge of security control frameworks including ISO 27001, NIST CSF, NIST 800-53 and CIS Controls. Experience conducting controls testing, assurance or audit activities against recognised security ...

GRC Engineer

Location
Belfast City District, Northern Ireland, United Kingdom
querying, and control automation. You'll be a key player in maintaining our compliance posture across frameworks like SOC 2, NIST CSF, and ISO 27001, while also helping modernize how we monitor and evidence controls using platforms like Anecdotes. This role suits someone … preparation for and execution of SOC 2 (Type I / II) audits, working directly with external auditors to scope, evidence, and remediate findings Lead or support NIST CSF assessments and gap analyses, translating results into actionable remediation plans Support alignment and readiness activities for ISO ...

Information Security Officer

Location
Reading, England, United Kingdom
continually improve the organisation's Information Security Management System (ISMS) , including policies, procedures and controls. Support the implementation and ongoing management of ISO 27001, Cyber Essentials Plus, PCI-DSS, NIST / CIS Controls and other relevant security requirements. Conduct security assessments across infrastructure, networks … endpoints, applications and data. Identify, assess and manage information security risks, including maintaining risk registers and tracking remediation. Lead and support internal and external security audits , including evidence gathering, control testing and remediation of findings. Manage technical security risks within Data Protection Impact Assessments and policy exceptions. ...

Cyber Security Manager

Hiring Organisation
Amtis Professional Ltd
Location
Birmingham, West Midlands (County), United Kingdom
Employment Type
Permanent
Salary
£75000 - £85000/annum 30% Bonus, Private Medical, Company
looking for an experienced Cyber Security Manager to join it's technology function. Reporting to the Head of Information Security, you'll lead the organisation's day-to-day cyber defence and information security capability. You'll protect critical systems, customer data and business operations across … communications and recovery Leading security investigations and overseeing remediation after incidents or identified risks Driving compliance with security policies, standards and regulations, including ISO 27001, Cyber Essentials and PCI-DSS Managing security audits, risk assessments and improvement plans Delivering security reporting, metrics and risk ...

GRC Controls & Oversight Lead

Hiring Organisation
Experis
Location
Warwickshire, United Kingdom
Employment Type
Contract
Contract Rate
£400 - £460/day
Role Title: GRC Controls & Oversight Lead Location: Warwick - Hybrid 50 / 50 Duration: 21 / 03 / 2027 Rate: £(Apply online only) per day - Umbrella only Candidates must hold active SC clearance Description: We are seeking an experienced GRC Controls & Oversight Lead to support … individual who can work independently, manage competing priorities, and bring structure to large volumes of assurance, compliance, and remediation activities. Key Responsibilities Lead and coordinate controls assurance and testing activities across IT and OT environments. Review, assess, and validate control effectiveness against defined policies, standards, and regulatory ...

Compliance Enablement Technical Program Manager

Location
Oxford, England, United Kingdom
Strong program and project management skills, with a track record of delivering across multiple teams. Solid knowledge of cybersecurity frameworks (NIST 800-53, ISO 27001, SOC 2, and / or FedRAMP) and hands‐on audit experience. Enough technical depth to be the team … APIs, and data flows, and interpreting technical work with AI assistance, even if you do not write code. Proven ability to lead technical discussions with engineers and subject‐matter experts and ask the right questions to understand how controls and systems work. Hands‐on experience with ...

IT Risks & Control Manager

Location
Eastleigh, England, United Kingdom
experienced IT Risk and Controls Manager to join our Information Security Governance, Risk and Compliance team. In this senior specialist role, you’ll lead the identification, assessment, management and reporting of IT risks across Ageas, helping ensure technology risks are clearly understood, documented and managed in line … with our risk appetite. Reporting to the Governance, Risk and Compliance Lead, you’ll own the IT risk register, facilitate senior IT risk discussions and provide clear, high-quality reporting for governance forums and second-line risk teams. Main Responsibilities as IT Risks & Control Manager Lead ...

IT Risks & Control Manager

Location
Chandler's Ford, England, United Kingdom
experienced IT Risk and Controls Manager to join our Information Security Governance, Risk and Compliance team. In this senior specialist role, you'll lead the identification, assessment, management and reporting of IT risks across Ageas, helping ensure technology risks are clearly understood, documented and managed in line … with our risk appetite. Reporting to the Governance, Risk and Compliance Lead, you'll own the IT risk register, facilitate senior IT risk discussions and provide clear, high-quality reporting for governance forums and second-line risk teams. Main Responsibilities: Lead IT risk ...

AI Security Consultant

Location
Greater London, England, United Kingdom
assurance. Familiarity with frameworks and guidance such as NIST AI RMF, OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, MITRE ATLAS, ISO 27001, NIST CSF, CIS Controls or cloud security frameworks. Experience with SOC operations, SIEM / SOAR platforms, detection engineering, threat … autonomous systems, including least privilege, approval workflows, action limits, logging, monitoring and rollback mechanisms. Relevant certifications such as CISSP, CISM, CCSP, GIAC, ISO 27001 Lead Implementer / Auditor, cloud security certifications or AI / security-focused training. Please ...

AI Security Consultant

Location
Manchester, England, United Kingdom
assurance. Familiarity with frameworks and guidance such as NIST AI RMF, OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, MITRE ATLAS, ISO 27001, NIST CSF, CIS Controls or cloud security frameworks. Experience with SOC operations, SIEM / SOAR platforms, detection engineering, threat … autonomous systems, including least privilege, approval workflows, action limits, logging, monitoring and rollback mechanisms. Relevant certifications such as CISSP, CISM, CCSP, GIAC, ISO 27001 Lead Implementer / Auditor, cloud security certifications or AI / security-focused training. Please ...

Cyber Security Risk & Assurance

Hiring Organisation
Robert Walters
Location
Manchester, Lancashire, United Kingdom
Employment Type
Full-Time
Salary
£600.00 - £700.00 per day
range of bespoke services and solutions. Due to several projects, they are keen to appoint a Cyber Security Risk & Assurance SME to lead a number of Data Driven and Cyber Data Assurance projects. Cyber Security Risk & Assurance SME: Duties Provide cyber risk and assurance input across … Lead Auditor / Implementer or equivalent experience. Knowledge of NIST CSF, ISO / IEC 27001, COBIT, CIS Controls or enterprise risk frameworks. Experience with SQL, JSON / CSV, APIs, Power BI or data quality controls. Experience with ...

Cyber Data Engineer

Hiring Organisation
Robert Walters
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Full-Time
Salary
£600.00 - £700.00 per day
range of bespoke services and solutions. Due to several projects, they are keen to appoint a Cyber Security Risk & Assurance SME to lead a number of Data Driven and Cyber Data Assurance projects. Cyber Security Risk & Assurance SME: Duties Provide cyber risk and assurance input across … Lead Auditor / Implementer or equivalent experience. Knowledge of NIST CSF, ISO / IEC 27001, COBIT, CIS Controls or enterprise risk frameworks. Experience with SQL, JSON / CSV, APIs, Power BI or data quality controls. Experience with ...

Cyber Data Engineer

Hiring Organisation
Robert Walters
Location
Manchester, North West, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
£600 - £700 per day + Outside IR35
range of bespoke services and solutions. Due to several projects, they are keen to appoint a Cyber Security Risk & Assurance SME to lead a number of Data Driven and Cyber Data Assurance projects. Cyber Security Risk & Assurance SME: Duties Provide cyber risk and assurance input across … Lead Auditor / Implementer or equivalent experience. Knowledge of NIST CSF, ISO / IEC 27001, COBIT, CIS Controls or enterprise risk frameworks. Experience with SQL, JSON / CSV, APIs, Power BI or data quality controls. Experience with ...

Senior Cyber Security Consultant (Defence)

Location
United Kingdom
remediation strategies and residual risks to stakeholders. Supporting governance, risk and compliance activities within secure and regulated environments. Depending on experience, you may: Lead consultancy engagements and workstreams. Mentor and support the development of colleagues. Act as a trusted adviser to senior client stakeholders. Contribute to business … controls. Understanding of Defence procurement and capability delivery programmes. Beneficial Knowledge Government and industry security frameworks such as HMG Security Policy Framework (SPF), ISO 27001 and NIST. Risk management methodologies and security assurance frameworks. Enterprise and security architecture approaches including TOGAF and SABSA. Cloud ...

Senior Cyber Security Consultant (Defence)

Location
Cheltenham, England, United Kingdom
remediation strategies and residual risks to stakeholders. Supporting governance, risk and compliance activities within secure and regulated environments. Depending on experience, you may: Lead consultancy engagements and workstreams. Mentor and support the development of colleagues. Act as a trusted adviser to senior client stakeholders. Contribute to business … controls. Understanding of Defence procurement and capability delivery programmes. Beneficial Knowledge Government and industry security frameworks such as HMG Security Policy Framework (SPF), ISO 27001 and NIST. Risk management methodologies and security assurance frameworks. Enterprise and security architecture approaches including TOGAF and SABSA. Cloud ...

Senior Cyber Security Consultant

Hiring Organisation
Hackajob Ltd
Location
Guildford, Surrey, South East, United Kingdom
Employment Type
Permanent, Work From Home
remediation strategies and residual risks to stakeholders. Supporting governance, risk and compliance activities within secure and regulated environments. Depending on experience, you may: Lead consultancy engagements and workstreams. Mentor and support the development of colleagues. Act as a trusted adviser to senior client stakeholders. Contribute to business … controls. Understanding of Defence procurement and capability delivery programmes. Beneficial Knowledge Government and industry security frameworks such as HMG Security Policy Framework (SPF), ISO 27001 and NIST. Risk management methodologies and security assurance frameworks. Enterprise and security architecture approaches including TOGAF and SABSA. Cloud ...

Security Consultant – Risk & Resilience - Financial Services

Location
Greater London, England, United Kingdom
cyber risk management, operational resilience, business continuity, disaster recovery, and incident response principles. Knowledge of common security and risk frameworks such as NIST, ISO 27001, COBIT, CIS Controls, and FFIEC guidance. Familiarity with financial services regulatory requirements relating to technology risk and resilience. Experience … enabled tools to improve efficiency, insight generation, or risk management outcomes. Preferred Qualifications Professional certifications such as CISSP, CISM, CRISC, CISA, CBCI, ISO 27001 Lead Implementer / Auditor, or equivalent. Experience supporting regulatory programmes involving PRA, FCA, DORA ...

Security Consultant - Risk & Resilience - Financial Services

Hiring Organisation
Accenture
Location
London, UK
Employment Type
Full-time
cyber risk management, operational resilience, business continuity, disaster recovery, and incident response principles. Knowledge of common security and risk frameworks such as NIST, ISO 27001, COBIT, CIS Controls, and FFIEC guidance. Familiarity with financial services regulatory requirements relating to technology risk and resilience. Experience … enabled tools to improve efficiency, insight generation, or risk management outcomes. Preferred Qualifications: Professional certifications such as CISSP, CISM, CRISC, CISA, CBCI, ISO 27001 Lead Implementer / Auditor, or equivalent. Experience supporting regulatory programmes involving PRA, FCA, DORA ...

Cyber Programmes Consultant

Location
Greater London, England, United Kingdom
requirements, the cyber threat landscape and business priorities Establish effective programme governance, control, reporting, risk management and assurance to support successful delivery outcomes Lead multi-disciplinary teams across cyber security, technology, risk, operations and business functions to deliver transformational change Deliver cyber maturity assessments, security roadmaps, implementation … management skills, with experience coordinating diverse delivery teams and suppliers Relevant cyber security qualifications or certifications such as CISSP, CISM, CRISC, CCSP, SABSA, ISO 27001 Lead Implementer / Auditor, SANS, GIAC certifications or equivalent Up-to-date knowledge ...

Cyber Programmes Consultant

Hiring Organisation
PA Consulting
Location
Pimlico, Hertfordshire, UK
Employment Type
Full-time
requirements, the cyber threat landscape and business priorities Establish effective programme governance, control, reporting, risk management and assurance to support successful delivery outcomes Lead multi-disciplinary teams across cyber security, technology, risk, operations and business functions to deliver transformational change Deliver cyber maturity assessments, security roadmaps, implementation … qualifications such as MSP, PRINCE2, PMP, AgilePM, SAFe or equivalent Relevant cyber security qualifications or certifications such as CISSP, CISM, CRISC, CCSP, SABSA, ISO 27001 Lead Implementer / Auditor, SANS, GIAC certifications or equivalent Up-to-date knowledge ...