london (city of london), south east england, united kingdom
HCLTech
frameworks such as NIST 800-53 r5, NIST CSF2.0, CIS, ISO27K • Designing solutions related to advisory & consulting engagements around regulatory risk & compliances such as DORA, NIS2, GDPR, SOX ITGC, PCI-DSS, HIPAA, Data Privacy, NHS, FFIEC etc. • Develop knowledge base, re-usable components for GRC advisory services. • Responsible for development and enhancements of GRC services, team and delivery … Technical Knowledge around information security, business continuity and technology risk assessments. ISO 27K, NIST, AI Governance, CIS etc. • Good compliance understanding of industry domains such as BFSI – (SOX, FFIEC, PCI-DSS, BASEL, MAS etc.), Healthcare & Life-sciences – (HIPAA, Hi-Trust, FDA CFR, GxP Compliance), Telecom, Retail, Data Privacy (GDPR, CCPA) Energy & Utilities (NERC, FERC) Information Security (ISO More ❯
lifecycle management, and operational workflows in collaboration with compliance, support, and operations teams Ensuring all product features and processes meet relevant regulatory and scheme compliance requirements (FCA, PSD2, AML, PCI-DSS) Collaborating with engineering, design, and third-party providers to deliver scalable, secure cardpayment solutions Defining and monitoring KPIs to track product performance, customer satisfaction, and operational … Deep understanding of tokenisation, EMVCo standards, and mobile wallet provisioning (Apple Pay, Google Pay) Strong working knowledge of card scheme requirements, issuer processor integrations, and compliance frameworks (KYC, AML, PCI-DSS, PSD2) Experience designing and implementing customer and operational product processes, including onboarding, servicing, and dispute resolution Strong analytical, problem-solving, and data-driven decision-making skills Excellent More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
s Information Security Management System remains effective in protecting HL critical information assets within risk appetite. Lead assurance activities against Information Security Compliance frameworks, including but not limited to: PCI, NIST, SWIFT, GDPR Conducting analysis of cloud-based assets pertaining to information security incidents, audits, and testing while adhering to best practices. Lead engagement of Cloud Audits and remediation … CISSP, CRISC Hands on demonstratable experience and knowledge of: Carrying out security reviews against recognised security control frameworks such as CSA Cloud Control Matrix, ISO27017/27001, NIST CSF, PCI-DSS, SWIFT, AWS CAF Atlassian, IAAC Terraform, Merge Requests, GIT Ops, Git Hub, Workflow, Wiz, Security Hub, Macie, Audit Manager, Microsoft Compliance Portal/Purview, Microsoft Information Protection More ❯
Leeds, Yorkshire, United Kingdom Hybrid / WFH Options
Stott and May
Harden DevSecOps pipelines to ensure secure software delivery. Collaborate with engineering teams to integrate security by design into products. Compliance & Risk Management Ensure regulatory compliance with GDPR, SOC2, ISO, PCI-DSS, and crypto-specific frameworks. Lead risk assessments for third-party vendors and service providers. Work with legal and compliance teams on KYC/AML security for crypto More ❯
Coventry, West Midlands, United Kingdom Hybrid / WFH Options
Infoplus Technologies UK Ltd
and proxy solutions.(e.g., F5, Palo Alto, Forcepoint, Cisco ASA) Security & Compliance Integration of security principles (Zero Trust, segmentation, NAC). Familiarity with frameworks such as ISO 27001, NIST, PCI-DSS, and data protection standards (GDPR). Cloud & Virtualisation Experience with AWS, Azure, or GCP networking services (Transit Gateway, VNet, VPC, ExpressRoute, Direct Connect). Understanding of hybrid More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Networking People (UK) Limited
e.g., network security, data protection, vulnerability management, access control). Leading disaster recovery planning, business continuity strategies, and incident response. Familiarity with compliance standards such as NIST, ISO 27001, PCI-DSS, and GDPR in the context of data centers, critical IT infrastructure, and application resilience for business survivability. Excellent communication, presentation, and client-facing skills with the ability More ❯
Leeds, West Yorkshire, Yorkshire, United Kingdom Hybrid / WFH Options
Stott & May Professional Search Limited
platforms (AWS, Azure, GCP). Implement DevSecOps practices, including secure CI/CD pipelines and infrastructure-as-code templates. Ensure compliance with frameworks such as NIST CSF, ISO 27001, PCIDSS, and CSA CCM. Essential Skills & Experience 15+ years in Information Security, 7-8+ years in Security Architecture. Cloud security architecture experience (AWS, Azure, GCP), multi-cloud More ❯
bradford, yorkshire and the humber, united kingdom Hybrid / WFH Options
Stott & May Professional Search Limited
platforms (AWS, Azure, GCP). Implement DevSecOps practices, including secure CI/CD pipelines and infrastructure-as-code templates. Ensure compliance with frameworks such as NIST CSF, ISO 27001, PCIDSS, and CSA CCM. Essential Skills & Experience 15+ years in Information Security, 7-8+ years in Security Architecture. Cloud security architecture experience (AWS, Azure, GCP), multi-cloud More ❯
Sentinel) Oversee security architecture, vulnerability management, incident response, and threat intelligence Lead security risk assessments and manage remediation plans for identified gaps Ensure compliance with financial regulations (e.g. GDPR, PCIDSS, SOX, FCA requirements) Establish and enforce security policies, standards, and procedures Report security posture, incidents, and key metrics to senior leadership and the board Drive security awareness More ❯
Hampshire, South East, United Kingdom Hybrid / WFH Options
Sanderson Government and Defence
Lead roles JSP440, JSP604/453 & JSP490 Working with system secure design MOD/GDS Secure by Design Principles Supplier Chain Assurance and Risks. Security related legislation (e.g. GDPR, PCIDSS, ICO requirements). Security Control Frameworks such as ISO 27001, NIST CSF and CIS Controls v8. HMG, NPSA and NCSC security policies, standards and guidance. Have experience More ❯
City of London, London, United Kingdom Hybrid / WFH Options
TDA TELECOM LIMITED
Design comprehensive security architectures across network, endpoint, identity, cloud, and data protection domains. Ensure alignment with industry frameworks such as NIST, ISO, and CIS, and compliance with regulatory standards (PCI-DSS, HIPAA, etc.). Produce proposals, Bills of Materials (BOMs), high-level designs, and Statements of Work (SOWs). Vendor & Partner Engagement Work with leading vendors (Palo Alto More ❯
goals Oversee security architecture, vulnerability management, incident response, and threat intelligence Lead security risk assessments and manage remediation plans for identified gaps Ensure compliance with financial regulations (e.g. GDPR, PCIDSS, SOX, FCA requirements) Establish and enforce security policies, standards, and procedures Report security posture, incidents, and key metrics to senior leadership and the board Drive security awareness More ❯
for occasional travel and out-of-hours support. Exposure to MxDR/SOC environments and advanced security protocols (SIEM, IDS/IPS, firewalls). Knowledge of GDPR, Cyber Essentials+, PCI-DSS, and other compliance standards. Strong grasp of data protection legislation (e.g., GDPR, Data Protection Act). Global Impact: Your leadership will help protect the digital infrastructure that More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
British Veterinary Association
occasional travel and out-of-hours support. Desirable: Exposure to MxDR/SOC environments and advanced security protocols (SIEM, IDS/IPS, firewalls). Knowledge of GDPR, Cyber Essentials+, PCI-DSS, and other compliance standards. Strong grasp of data protection legislation (e.g., GDPR, Data Protection Act). Why Join Us? Global Impact: Your leadership will help protect the More ❯
overall AV Solutions (Trend, Falcon CS), Monitoring & DEX platforms such as SolarWinds, ControlUp, Splunk, Strong Hardware proficiency (Ex: Synergy, Nimble, Brocade, Service BAU requests. Securing systems to Cyber Essentials, PCIDSS and ISO27000 standards through audits, vulnerability scanning and remediation Documentation, creation, update and keeping to date. Assist in the migration from, consolidation of and/or decommission More ❯
overall AV Solutions (Trend, Falcon CS), Monitoring & DEX platforms such as SolarWinds, ControlUp, Splunk, Strong Hardware proficiency (Ex: Synergy, Nimble, Brocade, Service BAU requests. Securing systems to Cyber Essentials, PCIDSS and ISO27000 standards through audits, vulnerability scanning and remediation Documentation, creation, update and keeping to date. Assist in the migration from, consolidation of and/or decommission More ❯
overall AV Solutions (Trend, Falcon CS), Monitoring & DEX platforms such as SolarWinds, ControlUp, Splunk, Strong Hardware proficiency (Ex: Synergy, Nimble, Brocade, Service BAU requests. Securing systems to Cyber Essentials, PCIDSS and ISO27000 standards through audits, vulnerability scanning and remediation Documentation, creation, update and keeping to date. Assist in the migration from, consolidation of and/or decommission More ❯
overall AV Solutions (Trend, Falcon CS), Monitoring & DEX platforms such as SolarWinds, ControlUp, Splunk, Strong Hardware proficiency (Ex: Synergy, Nimble, Brocade, Service BAU requests. Securing systems to Cyber Essentials, PCIDSS and ISO27000 standards through audits, vulnerability scanning and remediation Documentation, creation, update and keeping to date. Assist in the migration from, consolidation of and/or decommission More ❯
overall AV Solutions (Trend, Falcon CS), Monitoring & DEX platforms such as SolarWinds, ControlUp, Splunk, Strong Hardware proficiency (Ex: Synergy, Nimble, Brocade, Service BAU requests. Securing systems to Cyber Essentials, PCIDSS and ISO27000 standards through audits, vulnerability scanning and remediation Documentation, creation, update and keeping to date. Assist in the migration from, consolidation of and/or decommission More ❯
overall AV Solutions (Trend, Falcon CS), Monitoring & DEX platforms such as SolarWinds, ControlUp, Splunk, Strong Hardware proficiency (Ex: Synergy, Nimble, Brocade, Service BAU requests. Securing systems to Cyber Essentials, PCIDSS and ISO27000 standards through audits, vulnerability scanning and remediation Documentation, creation, update and keeping to date. Assist in the migration from, consolidation of and/or decommission More ❯
overall AV Solutions (Trend, Falcon CS), Monitoring & DEX platforms such as SolarWinds, ControlUp, Splunk, Strong Hardware proficiency (Ex: Synergy, Nimble, Brocade, Service BAU requests. Securing systems to Cyber Essentials, PCIDSS and ISO27000 standards through audits, vulnerability scanning and remediation Documentation, creation, update and keeping to date. Assist in the migration from, consolidation of and/or decommission More ❯
overall AV Solutions (Trend, Falcon CS), Monitoring & DEX platforms such as SolarWinds, ControlUp, Splunk, Strong Hardware proficiency (Ex: Synergy, Nimble, Brocade, Service BAU requests. Securing systems to Cyber Essentials, PCIDSS and ISO27000 standards through audits, vulnerability scanning and remediation Documentation, creation, update and keeping to date. Assist in the migration from, consolidation of and/or decommission More ❯
overall AV Solutions (Trend, Falcon CS), Monitoring & DEX platforms such as SolarWinds, ControlUp, Splunk, Strong Hardware proficiency (Ex: Synergy, Nimble, Brocade, Service BAU requests. Securing systems to Cyber Essentials, PCIDSS and ISO27000 standards through audits, vulnerability scanning and remediation Documentation, creation, update and keeping to date. Assist in the migration from, consolidation of and/or decommission More ❯
overall AV Solutions (Trend, Falcon CS), Monitoring & DEX platforms such as SolarWinds, ControlUp, Splunk, Strong Hardware proficiency (Ex: Synergy, Nimble, Brocade, Service BAU requests. Securing systems to Cyber Essentials, PCIDSS and ISO27000 standards through audits, vulnerability scanning and remediation Documentation, creation, update and keeping to date. Assist in the migration from, consolidation of and/or decommission More ❯