1 to 25 of 99 ISO 27001 Lead Implementer Jobs in the UK

Assistant Manager – Information Security

Location
Greater London, England, United Kingdom
Maintain and continuously improve the ISO 27001:2022 Information Security Management System, including policies, standards, procedures, documentation and Statement of Applicability. Provide security and data protection assurance for new initiatives, changes and projects, embedding security-by-design and privacy-by-design. Conduct information security … strongly preferred, for example CISM, CISSP, ISO 27001 Lead Implementer / Lead Auditor. Technology-centric training and certification is an advantage. 5+ years’ experience in information and cyber security implementation, management and governance, ideally within ...

Information Security Analyst

Location
West of England, England, United Kingdom
great opportunity for an experienced InfoSec professional who enjoys the governance, risk and assurance side of security , with a particular focus on ISO 27001, ISMS governance, audit, compliance and control assurance . You’ll play an important role in maintaining and developing the organisation … security framework, working across the business to manage risk, strengthen controls and support the continued development of its ISO 27001 certification internationally. The Role You’ll take a hands‐on role across information security governance, audit and compliance, helping ensure security controls remain effective ...

Information Security Analyst

Hiring Organisation
REX Cyber Security
Location
Greater Bristol Area, United Kingdom
great opportunity for an experienced InfoSec professional who enjoys the governance, risk and assurance side of security , with a particular focus on ISO 27001, ISMS governance, audit, compliance and control assurance . You’ll play an important role in maintaining and developing the organisation … security framework, working across the business to manage risk, strengthen controls and support the continued development of its ISO 27001 certification internationally. 🔐 The Role You’ll take a hands-on role across information security governance, audit and compliance, helping ensure security controls remain effective ...

Senior Security Consultant

Location
City Of London, England, United Kingdom
Define, implement and monitor corporate information security strategies, objectives and governance frameworks. Design and implement information security management systems and security master plans. Lead risk management activities, including risk identification, assessment, treatment and reporting. Define cybersecurity action plans and oversee their execution. Ensure the protection of services … analyses and defining continuity and testing plans. Implement and maintain information security controls aligned with applicable laws, regulations, standards and best practices, including ISO 27001 / 27002, GDPR, Cyber Assessment Framework (CAF) and NIST CSF. Develop and maintain information security policies, standards and procedures ...

Lead Information Security Analyst, GRC

Hiring Organisation
Cirrus Logic
Location
Edinburgh, Midlothian, United Kingdom
Salary
£ 70 K
field, or demonstrated equivalent experience as a security professional in a globally dispersed enterprise.Hands‐on experience with ISO / IEC 27001 (ISMS lifecycle, Annex A controls, risk assessment and treatment) and related security control frameworks (e.g., NIST CSF, ISO … semiconductor environments is beneficial.Relevant certifications (e.g., ISO 27001 Lead Implementer / Lead Auditor, CISSP, CISM, CISA, CRISC) are preferred but not required.This position is based in our Edinburgh office. It is a hybrid role (minimum ...

InfoSec Analyst II (GRC) Information security London

Location
Greater London, England, United Kingdom
governance, risk, and compliance programmes. This is a role for someone who has moved beyond task execution and is ready to drive workstreams, lead compliance activities, and act as a trusted point of contact for internal teams and external assessors. You will work across Checkout's core … compliance frameworks including PCI DSS v4.0.1, ISO 27001, SOC 2, and emerging regulatory obligations such as DORA and the EU AI Act, supporting our global footprint across Europe, MENA, APAC, and the Americas. You will coordinate audit evidence activities, conduct risk assessments, improve ...

Security Engineer, Compliance Focus

Location
Greater London, England, United Kingdom
here is not a paperwork exercise at the edge of the business. It is a condition of doing business. We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure … control is actually working or only described. What You Will Be Doing Compliance Execution Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline. Operate our GRC platform ...

Senior Information Security Analyst

Hiring Organisation
Adele Carr Recruitment Limited
Location
Liverpool, Merseyside, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £65,000 per annum
management, compliance and assurance activities, rather than infrastructure management or security operations. Key Responsibilities Support the ongoing maintenance and continuous improvement of the ISO 27001 aligned Information Security Management System (ISMS). Conduct information security risk assessments and support the management of risk treatment … plans. Assist with internal and external audits, including ISO 27001 certification and surveillance audits. Develop, review and maintain information security policies, procedures and standards. Support the management of security incidents, investigations and lessons learned activities. Monitor and track remediation of vulnerabilities, audit findings ...

Security GRC Analyst

Location
West of England, England, United Kingdom
sector, Sports and law enforcement, and those customers expect us to show, not just say, that our controls work. You will administer our ISO 27001 ISMS day to day, maintain the risk register, lead customer security assurance, run the supplier assessment … Accountabilities ISMS and certification Administer the information security policy, set: review schedule, publication and acknowledgement records, with the CISO approving changes. Maintain ISO 27001:2022 certification: statement of applicability, evidence library, internal audit scheduling and external audit coordination. Work with IT to maintain security ...

Senior GRC Analyst

Location
Horwich, England, United Kingdom
security risk assessments across projects, systems, and technology changes, identifying risks and recommending practical controls. Support the maintenance and continuous improvement of the ISO 27001-aligned Information Security Management System (ISMS). Review and maintain information security policies, standards, procedures, and control frameworks … equivalent level. Demonstrable experience supporting regulatory, certification, or external security audit readiness, including evidence coordination and remediation management. Hands‐on experience with ISO 27001-aligned Information Security Management Systems and information security policy and control governance. Experience conducting project and technology security risk assessments ...

Supplier Assurance Lead

Hiring Organisation
Morson Edge
Location
Greater Manchester, North West, United Kingdom
Employment Type
Contract
Supplier Assurance Lead / Cyber Security Risk Manager / Third Party Cyber Risk Lead £500 per day - Outside IR35 - North West Based - Hybrid My client is looking for an experienced Supplier Assurance Lead to join their Cyber Security team, taking … lead role in identifying, assessing and managing cyber security risks across a complex supplier and third-party ecosystem. This is a senior position requiring someone who can go beyond standard supplier due diligence exercises. Youll be expected to understand the underlying cyber security risks within the supply ...

Security Manager

Location
North East, England, United Kingdom
billion dollar business with over 5,000 associates. About the Role As part of our growth we are looking for an ISO 14298 Site Security Manager, where you will be part of a global best in class Operations team. This is to manage the Integraf Security Printing … ISO Management Systems, ISO 27001 Lead Implementer / Lead Auditor, ASIS CPP / PSP) advantageous. Experience: Significant experience in security management within security printing, identity documents, banknote or product authentication industries ...

Supervisor, IT Security, Governance, Risk & Compliance

Location
Winnersh, England, United Kingdom
ensure cybersecurity risks are effectively identified, assessed, communicated, and managed in accordance with business objectives and risk appetite. Responsibilities Governance & Security Program Management Lead the development, implementation, and maintenance of cybersecurity governance programs, policies, standards, procedures, and guidelines. Align governance activities with business objectives, cybersecurity strategy … risk appetite. Develop and maintain KPIs, KRIs, program metrics, and executive reporting. Drive cybersecurity program maturity and continuous improvement initiatives. Cybersecurity Risk Management Lead enterprise cybersecurity risk assessments and maintain the cybersecurity risk register. Facilitate risk reviews, mitigation planning, risk acceptance, and remediation efforts. Evaluate cybersecurity risks ...

Information Security Lead

Hiring Organisation
Hackajob Ltd
Location
Wallingford, Oxfordshire, South East, United Kingdom
Employment Type
Permanent
hackajob is partnering directly with Dexory to hire for this role. Information Security Lead / ISO27001 / SOC / GRC / Location: Wallingford - Oxfordshire (Hybrid) onsite circa 3 days minimum per week Permanent At Dexory, we are transforming the warehousing and logistics industry through data intelligence. Were … currently recruiting for an Information Security Lead to own and drive our compliance programmes (ISO 27001, SOC 1 Type 2, SOC 2 Type 2), act as the primary responder to customer security due diligence, and build the systems and knowledge base ...

Director of Security & Compliance

Hiring Organisation
Oscar Associates (UK) Limited
Location
London, United Kingdom
Employment Type
Permanent
CTO. With Cyber Essentials Plus already achieved and a 24 / 7 outsourced SOC in place, the organisation is now focused on achieving ISO 27001 certification, strengthening its governance and compliance framework, and ensuring the secure adoption of a rapidly expanding enterprise AI estate. … Responsibilities: Own security monitoring, incident response and security tooling, working closely with the outsourced SOC Line manage the IT Security Engineer and lead the organisation-wide security awareness programme Define identity, access and authentication standards, including RBAC, MFA and SSO Own the IT governance framework and regulatory ...

Lead Cyber Security Consultant | Lead Delivery. Help Shape the Practice

Hiring Organisation
Cyber Chain Alliance
Location
United Kingdom
Lead Cyber Security Consultant Cyber Chain Alliance was founded from a desire to do consultancy differently. Not louder. Not bigger. Just better. We believe cyber should be accessible. That organisations deserve advice that fits their reality. And that consultants deserve autonomy, progression and the chance to influence … direction of the business they’re part of. We’re entering a new stage of growth and we’re looking for a Lead Cyber Security Consultant who wants to play a key role in what comes next. The role in real terms This is a senior, hands ...

Cyber Operations & 3rd Party Security Manager

Hiring Organisation
Arbuthnot Latham
Location
London, United Kingdom
Salary
£ 80 K
forums.Support operational resilience and outsourcing requirements relating to 3rd-party cyber security.Governance, Reporting & Continuous ImprovementDevelop and maintain operational cyber security procedures and standards.Support ISO 27001 certification, regulatory compliance activities and audit engagements.Contribute to cyber risk reporting, metrics and management information for senior management … intelligence and vulnerability management.Experience of security incident management and cyber crisis response.Experience of supplier cyber risk assessments and 3rd-party risk management.Understanding of ISO 27001, NIST CSF, FCA / PRA expectations and operational resilience requirements.Strong stakeholder management, communication and reporting skills.Qualifications:Minimum ...

GRC Engineer

Location
Belfast City District, Northern Ireland, United Kingdom
querying, and control automation. You’ll be a key player in maintaining our compliance posture across frameworks like SOC 2, NIST CSF, and ISO 27001, while also helping modernize how we monitor and evidence controls using platforms like Anecdotes. This role suits someone … preparation for and execution of SOC 2 (Type I / II) audits, working directly with external auditors to scope, evidence, and remediate findings Lead or support NIST CSF assessments and gap analyses, translating results into actionable remediation plans Support alignment and readiness activities for ISO ...

Cyber Security Architect & Engineering Lead

Location
Greater London, England, United Kingdom
Cyber Security Architect & Engineering Lead Department: IT Infrastructure Employment Type: Permanent - Full Time Location: City, London Reporting To: Head of Information Security Compensation: £75,000 / year Description We are looking for a senior, hands-on Cyber Security Architect & Engineering Lead to help shape … applications and integration platforms. Design and implement modern security controls, with a strong focus on Zero Trust, secure-by-design principles and automation. Lead security architecture reviews and threat modelling for major projects, new products, high-risk integrations and emerging technologies. Act as the technical lead ...

Head of Cyber Security

Location
Greater London, England, United Kingdom
Purpose: To lead 7IM’s cyber security function and own the day-to-day execution of the Cyber Security strategy across the 7IM Group. The role is accountable for protecting 7IM’s clients, colleagues, data, systems and services from current and emerging cyber threats, while supporting business … clear cyber roadmap, control improvement plan and reporting cadence aligned to business priorities, regulatory expectations and risk appetite Security Operations & Threat Defence: Lead operational cyber defence across SIEM, endpoint protection, identity controls, email security, cloud security, vulnerability tooling and managed security service providers. Improve detection coverage, alert ...

Cyber Security & Compliance Lead

Location
Greater London, England, United Kingdom
CYBER SECURITY & COMPLIANCE LEAD Hours Full-time, 9:30am – 5.30pm with flexibility required to support system changes, upgrades and critical incidents where necessary. Department IT / Risk & Compliance The Role The Cyber Security & Compliance Lead is responsible for defining, delivering, and continuously improving … expectations. Technical skills and expertise Essential Significant experience in cyber security, information security, or IT risk roles. Experience operating at a senior or lead level within a professional services or regulated environment. Strong understanding of security frameworks (e.g. ISO 27001, NIST ...

Cyber Security Consultant / Security Architect

Location
Corsham, England, United Kingdom
assessments, penetration tests and supplier assurance activity, then advise on remediation and risk acceptance. Help clients align with relevant frameworks and standards, including ISO 27001, NIST, CAF, GovAssure, Secure by Design and HMG / MOD assurance expectations. Strong background in Security Architecture, Cyber Security … Strong stakeholder management skills, including the ability to advise technical teams and brief non-technical decision makers. Knowledge of security frameworks such as ISO 27001, NIST, CAF, Secure by Design, GovAssure or HMG / MOD security standards. Comfortable working 5 days per week ...

ISO Implementation Consultant

Location
London, United Kingdom
Robert Half are working with a leading payments organisation is looking for an experienced ISO Implementation Consultant to support the development and delivery of its ISO certification programme. This is an initial four-month contract, working approximately 20 hours per week, supporting a Europe … wide programme. The successful candidate will have a strong background in ISO implementation, information security, GRC, technology risk or cyber security, with practical experience advising organisations on ISO requirements and supporting them through certification or audit readiness. The role will combine hands-on ISO ...

ISO Implementation Consultant

Hiring Organisation
Robert Half Limited
Location
South East London, London, United Kingdom
Employment Type
Part Time, Work From Home
Robert Half are working with a leading payments organisation is looking for an experienced ISO Implementation Consultant to support the development and delivery of its ISO certification programme. This is an initial four-month contract, working approximately 20 hours per week, supporting a Europe … wide programme. The successful candidate will have a strong background in ISO implementation, information security, GRC, technology risk or cyber security, with practical experience advising organisations on ISO requirements and supporting them through certification or audit readiness. The role will combine hands-on ISO ...

Security Manager

Hiring Organisation
Emovis
Location
Leeds, England, United Kingdom
technical security requirements with governance, compliance, and stakeholder engagement. Key Responsibilities · Manage and maintain compliance with security standards and accreditations including PCI DSS, ISO 27001, ISO 22301, Cyber Essentials Plus and IT Health Checks. · Conduct internal audits, control reviews, and risk … Security Manager or similar information security role. · Strong understanding of cyber security, governance, risk, and compliance frameworks. · Extensive knowledge of PCI DSS, ISO 27001, Cyber Essentials Plus, and data protection requirements. · Experience with Microsoft 365, Azure, AWS, vulnerability management, and SIEM tools. · Strong communication ...