Luton, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
Working remotely with occasional be in office in Essex. What You’ll Do Assess compliance with internal security policies and industry standards (e.g., ISO/IEC 27001/2, PCI-DSS). Conduct supplier risk assessments and third-party due diligence. Support vulnerability assessments, incident investigations, and operational resilience activities. Monitor the effectiveness of security controls to ensure … Experience first and second line support Strong analytical thinking and attention to detail. Familiarity with compliance frameworks like ISO 27001/27002, NIST Cybersecurity Framework – 2.0 ideally version 2, PCIDSS v4.0 Exceptional communication and stakeholder engagement skills. Experience with Microsoft Azure Security tools (Defender for Endpoint, Sentinel, Purview). Understanding of ITIL, data protection laws (UK GDPR More ❯
Warrington, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
Working remotely with occasional be in office in Essex. What You’ll Do Assess compliance with internal security policies and industry standards (e.g., ISO/IEC 27001/2, PCI-DSS). Conduct supplier risk assessments and third-party due diligence. Support vulnerability assessments, incident investigations, and operational resilience activities. Monitor the effectiveness of security controls to ensure … Experience first and second line support Strong analytical thinking and attention to detail. Familiarity with compliance frameworks like ISO 27001/27002, NIST Cybersecurity Framework – 2.0 ideally version 2, PCIDSS v4.0 Exceptional communication and stakeholder engagement skills. Experience with Microsoft Azure Security tools (Defender for Endpoint, Sentinel, Purview). Understanding of ITIL, data protection laws (UK GDPR More ❯
Belfast, Northern Ireland, United Kingdom Hybrid / WFH Options
JR United Kingdom
Working remotely with occasional be in office in Essex. What You’ll Do Assess compliance with internal security policies and industry standards (e.g., ISO/IEC 27001/2, PCI-DSS). Conduct supplier risk assessments and third-party due diligence. Support vulnerability assessments, incident investigations, and operational resilience activities. Monitor the effectiveness of security controls to ensure … Experience first and second line support Strong analytical thinking and attention to detail. Familiarity with compliance frameworks like ISO 27001/27002, NIST Cybersecurity Framework – 2.0 ideally version 2, PCIDSS v4.0 Exceptional communication and stakeholder engagement skills. Experience with Microsoft Azure Security tools (Defender for Endpoint, Sentinel, Purview). Understanding of ITIL, data protection laws (UK GDPR More ❯
Edinburgh, Scotland, United Kingdom Hybrid / WFH Options
JR United Kingdom
remotely with occasional presence in the office in Essex. What You’ll Do Assess compliance with internal security policies and industry standards (e.g., ISO/IEC 27001/2, PCI-DSS). Conduct supplier risk assessments and third-party due diligence. Support vulnerability assessments, incident investigations, and operational resilience activities. Monitor the effectiveness of security controls to ensure … in first and second line support. Strong analytical thinking and attention to detail. Familiarity with compliance frameworks like ISO 27001/27002, NIST Cybersecurity Framework – 2.0 (preferably version 2), PCIDSS v4.0. Exceptional communication and stakeholder engagement skills. Experience with Microsoft Azure Security tools (Defender for Endpoint, Sentinel, Purview). Understanding of ITIL, data protection laws (UK GDPR More ❯
Hounslow, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
Working remotely with occasional be in office in Essex. What You’ll Do Assess compliance with internal security policies and industry standards (e.g., ISO/IEC 27001/2, PCI-DSS). Conduct supplier risk assessments and third-party due diligence. Support vulnerability assessments, incident investigations, and operational resilience activities. Monitor the effectiveness of security controls to ensure … Experience first and second line support Strong analytical thinking and attention to detail. Familiarity with compliance frameworks like ISO 27001/27002, NIST Cybersecurity Framework – 2.0 ideally version 2, PCIDSS v4.0 Exceptional communication and stakeholder engagement skills. Experience with Microsoft Azure Security tools (Defender for Endpoint, Sentinel, Purview). Understanding of ITIL, data protection laws (UK GDPR More ❯
is remote with occasional in-office presence in Essex. What You’ll Do Assess compliance with internal security policies and industry standards (e.g., ISO/IEC 27001/2, PCI-DSS). Conduct supplier risk assessments and third-party due diligence. Support vulnerability assessments, incident investigations, and operational resilience activities. Monitor the effectiveness of security controls to ensure … with first and second line support. Strong analytical thinking and attention to detail. Familiarity with compliance frameworks like ISO 27001/27002, NIST Cybersecurity Framework – 2.0 (preferably version 2), PCIDSS v4.0. Exceptional communication and stakeholder engagement skills. Experience with Microsoft Azure Security tools (Defender for Endpoint, Sentinel, Purview). Understanding of ITIL, data protection laws (UK GDPR More ❯
Doncaster, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
Remote work with occasional in-office presence in Essex. What You’ll Do Assess compliance with internal security policies and industry standards (e.g., ISO/IEC 27001/2, PCI-DSS). Conduct supplier risk assessments and third-party due diligence. Support vulnerability assessments, incident investigations, and operational resilience activities. Monitor security controls to ensure confidentiality, integrity, and … with first and second line support. Strong analytical thinking and attention to detail. Familiarity with compliance frameworks like ISO 27001/27002, NIST Cybersecurity Framework 2.0 (preferably version 2), PCIDSS v4.0. Exceptional communication and stakeholder engagement skills. Experience with Microsoft Azure Security tools (Defender for Endpoint, Sentinel, Purview). Understanding of ITIL, UK GDPR, and paymentcardMore ❯
services include: Strategy & transformation On-demand virtual roles Data discovery and mapping Risk advisory and assurance Continuity/Resilience Data privacy and GDPR ISO 27001 & NIST CSF Supplier assurance PCI, PA & P2PE Incident response planning Card production audits Cyber security review SOC advisory & implementation XDR consulting & implementation Alongside our core services, we have a range of bespoke services to … learn new skills and disciplines. Knowledge Experience in two or more of the below: Excellent attention to detail and documentation. Industry standards such as ISO 27001 Series, GDPR, NIST, PCI DSS. Customer facing experience at senior levels. CISSP/CISM/ISO 27001 LA or LI/PCIDSS QSA would be an advantage Outputs Ability to More ❯
services include: Strategy & transformation On-demand virtual roles Data discovery and mapping Risk advisory and assurance Continuity/Resilience Data privacy and GDPR ISO 27001 & NIST CSF Supplier assurance PCI, PA & P2PE Incident response planning Card production audits Cyber security review SOC advisory & implementation XDR consulting & implementation Alongside our core services, we have a range of bespoke services to … learn new skills and disciplines. Knowledge Experience in two or more of the below: Excellent attention to detail and documentation. Industry standards such as ISO 27001 Series, GDPR, NIST, PCI DSS. Customer facing experience at senior levels. CISSP/CISM/ISO 27001 LA or LI/PCIDSS QSA would be an advantage Outputs Ability to More ❯
services include: Strategy & transformation On-demand virtual roles Data discovery and mapping Risk advisory and assurance Continuity/Resilience Data privacy and GDPR ISO 27001 & NIST CSF Supplier assurance PCI, PA & P2PE Incident response planning Card production audits Cyber security review SOC advisory & implementation XDR consulting & implementation Alongside our core services, we have a range of bespoke services to … learn new skills and disciplines. Knowledge Experience in two or more of the below: Excellent attention to detail and documentation. Industry standards such as ISO 27001 Series, GDPR, NIST, PCI DSS. Customer-facing experience at senior levels. CISSP/CISM/ISO 27001 LA or LI/PCIDSS QSA would be an advantage Outputs Ability to More ❯
as part of a team Ability to travel to meet business needs Preferred competencies: Relevant cyber security or other qualifications, certifications such as CSX-P, CDPSE, SSCP, CAP, OWASP, PCIDSSSecurity Cleared with potential to gain enhanced clearances Experience implementing privacy solutions based on the requirements of the EU GDPR and UK Data Protection Act 2018 Good More ❯
ソフトウェアエンジニアリングのベストプラクティス(ソースコードレビュー、ソースコード管理、ビルドプロセス、テスト、リリースおよび変更管理、自動化)に関する最新情報 - ソフトウェア開発ライフサイクル(SLDC)とアジャイル/反復方法論に関する実務知識 - CISSP、CISA、CISM、CCSPなどの業界認定を取得している - 次世代ファイアウォール、ウェブアプリケーションファイアウォール、侵入検知/防止、インシデント対応、セキュリティ情報およびイベント管理(SIEM)、識別およびアクセス管理(IAM)コントロールの1つ以上での実装経験 - NIST、PCI-DSS、ISO/IEC 27001、ISO/IEC 27017、FISCなどのコンプライアンスフレームワークに関する実装経験 - コードとしてのインフラストラクチャ、またはCloudFormation、Terraform、Ansible、Chef、Puppetなどの構成管理テクノロジーに関する知識または経験 - スクリプトスキル、すなわち PowerShell、Python、Node.js、Javascript、Bash、Ruby、Perl など - 英語で流暢にコミュニケーションをとり、プレゼンテーションを行う能力 … Application Firewalls, Intrusion Detection/Prevention, Incident Response, and Security Information and Event Management (SIEM), Identify and Access Management (IAM) controls. - Implementation experience with compliance frameworks such as NIST, PCI-DSS, ISO/IEC 27001, ISO/IEC 27017, FISC, etc. - Knowledge or experience in Infrastructure as Code or Configuration Management technologies such as CloudFormation, Terraform, Ansible, Chef More ❯
London, England, United Kingdom Hybrid / WFH Options
Smart Communications group
Engineer with designing, innovating, deploying, and maintaining security measures to safeguard our information assets. We operate in a highly secure global SaaS organization that has multiple certifications such as PCI-DSS, ISO/IEC 27001, SOC & HIPAA & IRAP standards to adhere to, as well as a large, federated customer base that we strive to embed improvements for. You … on a variety of challenging projects, with multiple security tools. Have a proven track record of successes. Knowledge of security compliance standards relevant to the SaaS industry, such as PCI, GDPR, ISO 27001, SOC2, NIST. An understanding of application security principles, best practices, OWASP/related standards. Some knowledge/experience in scoping/undertaking internal pen testing and More ❯
Broad knowledge of cyber security concepts including cryptography, authentication and authorization, access control, secure architectures, threat modeling, vulnerabilities and software security. Strong knowledge of regulatory requirements (e.g. GDPR, ISO27001, PCI-DSS) and experience in regulatory reporting. 3-5 years of experience in GRC, risk management, or compliance. A bachelor's degree in computer science, Cyber Security or similar More ❯
London, England, United Kingdom Hybrid / WFH Options
Hastings Direct
with Infrastructure-as-Code (e.g., Bicep, ARM templates, Terraform). Hands-on experience with SIEM tools, ideally Azure Sentinel. Understanding of regulatory and compliance frameworks (e.g., CIS Benchmarks, HIPAA, PCI-DSS). Excellent problem-solving skills, communication, and the ability to explain technical concepts to non-technical stakeholders. Desirable: Relevant certifications such as AZ-500, SC-100, or More ❯
Liverpool, Lancashire, United Kingdom Hybrid / WFH Options
Techwaka
practices Provide specialist security support to IT teams, including infrastructure, development, and database teams Work with stakeholders to maintain compliance with industry standards such as ISO27001, Cyber Essentials Plus, PCI/DSS Stay ahead of cyber threats, maintaining and improving security monitoring and risk management processes Support vulnerability management, penetration testing, and incident response Requirements for this role More ❯
Liverpool, England, United Kingdom Hybrid / WFH Options
Techwaka
practices Provide specialist security support to IT teams, including infrastructure, development, and database teams Work with stakeholders to maintain compliance with industry standards such as ISO27001, Cyber Essentials Plus, PCI/DSS Stay ahead of cyber threats, maintaining and improving security monitoring and risk management processes Support vulnerability management, penetration testing, and incident response Requirements for this role More ❯
controls e.g. encryption, masking and pseudonymisation. Detailed understanding of the information lifecycle and the self assurance framework for Records Management. Experience of implementing datasecurity standards such as ISO27001, PCIDSS, NIST CSF, CAA CAF etc. Ability to effectively manage cyber security risks and can clearly communicate with key stakeholders to minimise the risk to easyJet. DESIRABLE SKILLS More ❯
controls e.g. encryption, masking and pseudonymisation. Detailed understanding of the information lifecycle and the self assurance framework for Records Management. Experience of implementing datasecurity standards such as ISO27001, PCIDSS, NIST CSF, CAA CAF etc. Ability to effectively manage cyber security risks and can clearly communicate with key stakeholders to minimise the risk to easyJet. DESIRABLE SKILLS More ❯
London, England, United Kingdom Hybrid / WFH Options
Starling Bank
while contributing to open-source tools so we can utilise them Experience in automating security controls and compliance checks against standards and frameworks which include SOC 2, ISO 27001, PCIDSS/3DS Thorough understanding of the incident response process (preparation, identification, containment, eradication, recovery, lessons learned) What skills are desirable: Hands on experience taking your company through … security and compliance frameworks like NIST, SOC2, ISO27001, PCI-DSS Experience with Infrastructure as Code and infrastructure provisioning tools (Cloudformation, Terraform) Expertise in Kubernetes, securing clusters and meshes (Cilium is preferable), networking best practices and RBAC implementation (CKA, CKS qualifications are a plus) Container security knowledge including container image provenance (e.g. Sigstore, Notary) with an in-depth knowledge More ❯
controls e.g. encryption, masking and pseudonymisation. · Detailed understanding of the information lifecycle and the self assurance framework for Records Management. · Experience of implementing datasecurity standards such as ISO27001, PCIDSS, NIST CSF, CAA CAF etc. · Ability to effectively manage cyber security risks and can clearly communicate with key stakeholders to minimise the risk to easyJet. DESIRABLE SKILLS More ❯
necessary ● Drive implementation of cybersecurity policies and standards across News UK. Proactively identify non-compliance and areas of potential improvement, and facilitate development and deployment of standard solutions ● Oversee PCI, SOX, and any other required legal and/or compliance requirements, support internal technology audits, as well as support Privacy on GDPR and other similar requirements ● Provide regular and … s degree in Technology, Legal, Computer Science/Engineering, Cybersecurity, a related field or experience ● Must have a strong understanding of security compliance, policy management, security frameworks (NIST, ISO27001, PCI etc) and regulations. ● Solid foundation of security architectures and cloud computing environments ● Excellent communication skills. Ability to effectively communicate, both orally and in writing, through all levels of the More ❯
Manchester, England, United Kingdom Hybrid / WFH Options
Jobs via eFinancialCareers
risk management tools and techniques Experience of security governance and compliance, ideally gained in financial services organisations Demonstrable understanding of Information Security control standards and frameworks e.g. ISO27001, NIST, PCIDSS Awareness and understanding of the Information Security threat landscape Deep understanding of Information Security solutions and controls Experience of Cloud security solutions and standards is highly advantageous More ❯
lifecycle Vulnerability scanning and management tools (e.g., Tenable, Qualys, Rapid7) Scripting and automation (PowerShell, Bash, Python) Ticketing and ITSM tools (e.g., Jira, ServiceNow, Remedy) Security compliance standards (e.g., NIST, PCI-DSS, ISO 27001, CIS Benchmarks) Seniority level Seniority level Mid-Senior level Employment type Employment type Contract Job function Job function Information Technology Industries Staffing and Recruiting, IT More ❯
strategies , ensuring security and performance Work with Terraform, Deployment Manager, and CloudFormation for IaC-based deployments Security and Compliance: Implement cloud security measures and ensure compliance with ISO 27001, PCIDSS, GDPR, and other industry standards Define cloud architecture standards and best practices for a secure cloud environment Performance Optimisation: Monitor and optimise cloud resources for performance, scalability More ❯