1 to 25 of 128 SOC 2 Jobs in the UK

Information Security Analyst II (GRC)

Hiring Organisation
Checkout.com
Location
London, United Kingdom
Salary
£ 80 K
trusted point of contact for internal teams and external assessors.You will work across Checkout's core compliance frameworks including PCI DSS v4.0.1, ISO 27001, SOC 2, and emerging regulatory obligations such as DORA and the EU AI Act, supporting our global footprint across Europe, MENA, APAC, and … audit, or a closely related function, ideally within payments, financial services, or fintech.Practical working knowledge of PCI DSS (v4.0.1 preferred), ISO 27001, and SOC 2. Familiarity with DORA, NIST CSF, or the EU AI Act is a plus.Experience supporting or directly managing external audits and assessments, including evidence collation ...

GRC Analyst II

Hiring Organisation
Payscale
Location
United Kingdom
Salary
£ 70 K
classification and ownership inventory, partnering with teams to ensure systems are properly classified, attributed, and reviewed on a defined cadenceSupport audit coordination activities for SOC 2 and other compliance frameworks.Conduct vendor security assessments reviews.Manage the policy management lifecycle, including drafting new policies and standards, tracking review cycles, coordinating … experience in GRC, information security, or a related field within a commercial SaaS or software companyWorking knowledge of information security control frameworks such as SOC 2, ISO 27001, NIST 800-53, or CISDemonstrated experience with data classification frameworks and data governance conceptsExperience conducting vendor security assessments and managing ...

Director, Compliance Audit – iLottery & Interactive

Hiring Organisation
Aristocrat Technologies
Location
London, United Kingdom
Salary
£ 80 K
operational, security, technology, and service delivery controls.Coordinate and lead all aspects of external audits and certifications supporting lottery customers, including but not limited to SOC 1, SOC 2, ISO 27001, WLA-SCS, PCI-DSS, and jurisdiction-specific requirements.Maintain audit readiness throughout all iLottery regions by conducting proactive … executive leadership and customer collaborators.Strong understanding of audit methodologies, internal controls, risk management, and governance frameworks.Experience with recognized industry benchmarks and certifications such as SOC 1, SOC 2, ISO 27001, PCI-DSS, WLA-SCS, NIST, COBIT, or comparable frameworks.Strong analytical, problem-solving, and decision-making capabilities.Excellent communication ...

Head of Information Security

Hiring Organisation
Duco
Location
London, United Kingdom
Salary
£ 100 K
Define and own the GRC programme, including the ISMS, policy framework, risk registers, and audit readiness– Implement and maintain compliance with ISO 27001, SOC 1, SOC 2, NIST CSF, GDPR, and relevant financial services regulations– Understand the GRC landscape, implement appropriate controls, and adapt as the threat … progressive experience in information security, with at least 3 years in a senior or leadership role- Hands-on experience owning ISO 27001 and SOC 1 and SOC 2 programmes, not just supporting them- Demonstrated experience managing security incidents end-to-end, including client and regulatory communications- Strong ...

Global Risk and Compliance Manager

Hiring Organisation
Elixirr International
Location
London, United Kingdom
Salary
£ 80 K
including horizon scanning across jurisdictions.Reduce cyber risk exposure and strengthen cybersecurity governance in partnership with the CISO, aligning to global standards e.g. ISO 27001, SOC 2.Contribute to Board, Audit Committee and Annual Report risk disclosures.Risk & Compliance OperationsLead the Group’s risk and compliance programme, ensuring controls are well-designed … operational and scalable, particularly for SOC 2 Type 2 and ISO 27001.Maintain a centralised, audit-ready evidence repository and coordinate internal/external audits, client reviews and due diligence.Oversee remediation plans and ensure continuous evidence collection.Develop consistent, lightweight playbooks for vendor intake, audit readiness and control testing ...

Senior Trust Security Analyst

Hiring Organisation
NICE Systems
Location
London, United Kingdom
Salary
£ 80 K
track remediation activities across engineering and security teams, ensuring alignment with agreed timelines and compliance requirements.AuditAudit Interpretation: Read and interpret third-party audit reports (SOC 2 Type II, ISO 27001, penetration test summaries) and represent findings to customers in questionnaires and security responses.Communication & Stakeholder ManagementInformation Translation: Gather detailed … Hands-on experience responding to SIG, CAIQ, VSA, and bespoke enterprise/government security questionnaires.Compliance Knowledge: Working knowledge of Cyber Essentials Plus, ISO 27001, SOC 2 Type II, and at least one of PCI DSS, GDPR/UK GDPR, HIPAA, or FedRAMP.Technical Expertise: Strong technical understanding of security ...

Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

Hiring Organisation
X
Location
London, United Kingdom
Salary
£ 80 K
improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e.g., ISO 27001, SOC 2) where they overlap.Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.BASIC QUALIFICATIONS:Bachelor's degree … logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations.Familiar with GDPR concepts that commonly intersect with information security (e.g., security of processing, breach notification timelines ...

Information Security Manager

Hiring Organisation
Ronald James
Location
Newcastle Upon Tyne, Tyne and Wear, England, United Kingdom
Employment Type
Full-Time
Salary
£55,000 - £75,000 per annum
emerging areas such as AI governance and sustainability. Key Responsibilities Governance, Assurance & Compliance Own major certification and assurance programmes including ISO 27001, ISO 9001, SOC 2 and other recognised frameworks. Lead audit planning and execution across multiple standards. Manage cyber insurance, regulatory compliance and third-party assurance activities. … including: Security Strong understanding of cloud and SaaS security models. Experience managing security incidents and post-incident governance. Practical implementation of ISO 27001 and SOC 2 within engineering environments. Deep understanding of UK GDPR, EU GDPR and wider privacy regulations. Knowledge of AI governance, ethics and regulatory considerations. ...

Information Security & Compliance Lead (GRC)

Hiring Organisation
Tank Recruitment
Location
Oxfordshire, United Kingdom
Employment Type
Permanent
Salary
£45000 - £55000/annum
Information Security & Compliance Lead (GRC) Job Title: Information Security & Compliance Lead Location: Oxfordshire - Hybrid 2 days per week on site Industry: Enterprise SaaS/Technology Solutions About the Role We are partnering with a fast-growing, globally active software and data solutions enterprise looking to appoint an experienced Lead … . In this position, you will drive the operational security initiatives necessary to achieve and maintain formal security frameworks and attestation standards (including SOC 2 Type I/II lifecycles). You will translate complex trust criteria into practical, sustainable controls, bridge operational gaps, coordinate external audits, and ...

GRC Analyst

Hiring Organisation
Rise Technical
Location
London, United Kingdom
Salary
£ 50 K
practices across modern cloud environments.The ideal candidate will have experience across governance, risk and compliance activities, strong knowledge of frameworks such as ISO 27001, SOC 2, GDPR and DORA, and a solid understanding of cloud platforms including AWS, Azure and GCP. Strong communication skills and a customer-focused … directly with clients to improve security programmes and regulatory complianceThe Person:Good years of experience within cybersecurity, technology or GRCStrong understanding of ISO 27001, SOC 2, GDPR, DORA and related frameworksExperience with AWS, Azure and/or GCP environmentsDegree qualified in Cyber Security, IT or a related discipline ...

GRC Analyst

Hiring Organisation
Rise Technical
Location
United Kingdom
across modern cloud environments. The ideal candidate will have experience across governance, risk and compliance activities, strong knowledge of frameworks such as ISO 27001, SOC 2, GDPR and DORA, and a solid understanding of cloud platforms including AWS, Azure and GCP. Strong communication skills and a customer-focused … clients to improve security programmes and regulatory compliance The Person: Good years of experience within cybersecurity, technology or GRC Strong understanding of ISO 27001, SOC 2, GDPR, DORA and related frameworks Experience with AWS, Azure and/or GCP environments Degree qualified in Cyber Security ...

GRC Analyst

Hiring Organisation
Rise Technical Recruitment
Location
London, United Kingdom
Employment Type
Permanent
Salary
£45000 - £55000/annum
across modern cloud environments. The ideal candidate will have experience across governance, risk and compliance activities, strong knowledge of frameworks such as ISO 27001, SOC 2, GDPR and DORA, and a solid understanding of cloud platforms including AWS, Azure and GCP. Strong communication skills and a customer-focused … clients to improve security programmes and regulatory compliance The Person: Good years of experience within cybersecurity, technology or GRC Strong understanding of ISO 27001, SOC 2, GDPR, DORA and related frameworks Experience with AWS, Azure and/or GCP environments Degree qualified in Cyber Security ...

Security GRC Analyst

Hiring Organisation
Lendable
Location
London, United Kingdom
Salary
£ 80 K
organisation.What You’ll Be DoingFramework & Regulatory Alignment: Help maintain, improve, and scale our security compliance programmes, ensuring ongoing alignment with standards such as SOC 2, ISO 27001, and PCI-DSS, as well as regulator expectations and UK GDPR.Risk & Mitigation: Collaborate on identifying security risks across the business - including … Expertise: A strong, foundational understanding of security risk management principles and hands-on experience working with compliance frameworks (e.g. ISO 27001, PCI-DSS, or SOC 2).Risk-First & Pragmatic Mindset: A natural tendency to start with the "why" (the risk) rather than the checklist. You possess the ability ...

Compliance Officer

Hiring Organisation
Spectrum IT Recruitment
Location
Milton Keynes, Buckinghamshire, United Kingdom
Employment Type
Permanent
Salary
£45000 - £50000/annum Benefits
Compliance Officer (ISO 27001, SOC2, GDPR) Fully Remote (Visit to the Milton Keynes Office once a month) £45,000 - £50,000 + Bonus & Benefits Are you a hands-on compliance professional who thrives on variety and ownership? Do you have experience delivering ISO, SOC & GDPR audit & compliance projects? Join … and governance is critical. You'll manage and maintain ISO 27001, ISO 9001 and ISO 22301 certifications, lead GDPR and data protection compliance, oversee SOC 2 - Type II controls, coordinate business continuity and disaster recovery activities, and support customer audits and due diligence requests. You'll also play ...

Senior Information Security Specialist

Hiring Organisation
Deliveroo
Location
London, United Kingdom
Salary
£ 80 K
mature DoorDash’s risk register, compliance reporting, dashboards, metrics and executive-level risk communications.Support control mapping and harmonization across frameworks such as ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR, UK GDPR, NIS2, DORA, and emerging AI governance requirements.Promote a risk-based, pragmatic compliance culture that enables … workshops, control self-assessments and remediation planning with cross-functional stakeholders.You have strong working knowledge of security and privacy frameworks such as ISO 27001, SOC 2, GDPR or CCPA, and you can quickly assess applicability of new frameworks or regulatory requirements.You understand how security and privacy controls operate ...

Senior DevOps Engineer (AWS)

Hiring Organisation
Duetto
Location
United Kingdom
Salary
£ 50 K
metrics and response playbooks that get ahead of incidents before they happen.Lead security-first practices across the infrastructure estate — proactively addressing vulnerabilities and driving SOC 2 compliance.Partner with engineering teams to integrate operational requirements into the development lifecycle and align on architecture decisions.Champion AI adoption within DevOps andand a track record of leading root cause analyses and implementing durable fixes.Proficiency reading Java, Ruby, Bash/Zsh, HCL, Python, and JavaScript.Experience with SOC 2 compliance and security-first infrastructure practices.Comfort with a weekly on-call rotation.Strong candidates may also have:Experience with container and orchestration technologies ...

Information Security Governance Specialist

Hiring Organisation
Frontify
Location
London, United Kingdom
Salary
£ 80 K
make informed decisions while supporting commercial success.You'll drive the day-to-day operation and continuous improvement of our compliance programs, including ISO 27001, SOC 2, TISAX, and emerging regulatory requirements.You'll serve as the subject matter expert during audits and ensure our control environment remains effective and … years of experience in information security governance, GRC, or technology risk within a SaaS or cloud environment.You've been the subject matter expert in SOC 2 and/or ISO 27001 audits — not just supporting them, but working directly on controls and partnering with auditors. Experience with additional ...

Information Security Analyst ( ISO 27001 and ISO 27018 )

Hiring Organisation
Alfa Financial Software
Location
London, United Kingdom
Salary
£ 80 K
and procedures sharp and our compliance with ISO 27001 and ISO 27018 on point. You'll get involved in SSAE 18/ISAE 3402 SOC 1 Type 2 and SSAE 18 SOC 2 Type 2 assurance audits, spot opportunities to improve our security controls and … organisational skills. You write clear documentation and reports, and you can translate complex requirements for stakeholders at every level. You'll have at least 2 years' experience in a related role. Experience in a regulated industry, familiarity with other information security frameworks and assurance reports, and exposure to Jira ...

Head of Information Security

Hiring Organisation
MOO
Location
London, United Kingdom
Salary
£ 80 K
after-action reviews.Plan, facilitate and participate directly in tabletop cyber exercises and live cyber simulations at least quarterly.For any incident classified Severity 1 or 2, act as deputy incident decision-maker, holding delegated authority from the CFO to make time-critical operational decisions.Data Privacy & RegulatoryPartner with Legal … data.Embed Privacy by Design and data minimisation into discovery, design and delivery processes.Own the roadmap towards enterprise assurance frameworks, including UK Cyber Essentials and SOC 2 readiness.Prepare for external audits and assessments and ensure customer security questionnaire responses reflect actual control status.Third-Party & Cloud SecurityEstablish and ...

Senior Manager – Application Security

Hiring Organisation
Miro
Location
London, United Kingdom
Salary
£ 100 K
metrics for secure development adoption, vulnerability resolution, and developer engagement.Collaborate with Privacy, Legal, and Compliance teams to ensure alignment with regulatory requirements (ISO 27001, SOC 2, GDPR, and emerging AI regulations).Foster a strong team culture based on collaboration, learning, and continuous improvement.What you’ll need10+ years … scaling developer engagement.Experience leading offensive security programs (penetration testing, red teaming, bug bounty).Practical understanding of governance and assurance frameworks such as ISO 27001, SOC 2, and OWASP SAMM.Familiarity with AI/LLM tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations) and the associated security and governance considerations.Experience ...

IT Operations Engineer

Hiring Organisation
Cloudsmith
Location
Belfast, Down, United Kingdom
Salary
£ 50 K
and service improvement.Contribute to IT disaster recovery, business continuity, and operational readiness planning with Security and Operations.Support technical control work and evidence collection for SOC 2, ISO 27001, EU CRA, and other related compliance frameworks.Track useful IT metrics such as request volume, SLA adherence, provisioning time, patch coverage … access reviews, self-service adoption, and employee satisfaction.Required Experience, Qualities & SkillsOperational DepthAround 2 to 3+ years of IT operations experience in a modern SaaS, technology, or remote-first environment.Strong hands-on experience with endpoint management, device lifecycle, MDM, patching, encryption, and secure device posture.Experience administering identity and access systems ...

HIPAA Security Engineer

Hiring Organisation
Flo Health
Location
London, United Kingdom
Salary
£ 80 K
Security Architecture team, you will lead the design and operation of our US Healthcare security controls. You will own the roadmap for HIPAA compliance and SOC2 Type II certification, partnering with Engineering and Legal to build a secure, compliant platform for millions of users.Key ResponsibilitiesCompliance Leadership: Lead annual SOC2 and HIPAA certifications, managing interfaces with external auditors and professional services.Policy & Risk: Define and maintain security policies; embed risk assessment activities within engineering processes and vendor management.Operational Excellence: Partner with control owners to automate evidence gathering and ensure controls reduce friction rather than creating it.Stakeholder Management: Serve ...

Applied AI Security Architect

Hiring Organisation
Humanloop
Location
London, United Kingdom
Salary
> £ 150 K
architects, compliance teams, and DPOs to understand their security requirements and design solutions that meet European regulatory standards (GDPR, EU AI Act, DORA, NIS2, SOC 2, PCI-DSS, and national regulator expectations).Lead technical deep-dives on network architecture, EU data residency, data retention and Zero Data Retention … familiarity with the EU AI Act as it applies to foundation models.Experience navigating compliance frameworks relevant to European financial services and insurance (DORA, NIS2, SOC 2, PCI-DSS, and national regulators' guidance on AI/ML such as FCA/PRA, BaFin, ACPR, FINMA).A track record ...

AI Security Specialist

Hiring Organisation
Deel
Location
United Kingdom
Salary
£ 80 K
confidence. You'll work closely with engineering, product, IT, and security teams to ensure AI technologies are deployed safely, in alignment with compliance requirements (SOC 2 Type II, ISO 27001), and within our security architecture.ResponsibilitiesDefine, implement, and maintain the AI security strategy across Deel's infrastructure and product … restrictions, data classification, and prompt injection mitigationsConduct security reviews of AI-related connectors, plugins, and third-party integrations using structured approval pipelinesCollaborate with the SOC and incident response teams to build AI-specific detection rules, playbooks, and response proceduresContinuously monitor the evolving AI threat landscape, track emerging attack techniques ...

IT Auditor & Controls Analyst

Hiring Organisation
DGH Recruitment
Location
City of London, London, United Kingdom
Employment Type
Permanent
Salary
£40,000
Auditor & Controls Analyst Key Experience: IT Audit, Technology Risk, ITGC, IT Application Controls, ISA 315, SOC 1, SOC 2. Required Skills/Experience: - Deliver testing over ITGCs, IT application controls, interface controls, automated controls and IPE with limited supervision. - Support ISA 315-aligned IT understanding and risk assessment … and risks arising from IT. * Prepare clear, review-ready workpapers, testing templates, issue summaries and RACMs. * Support financial statement audit-related technology controls assurance, SOC 1, SOC 2 and regulatory assurance engagements as required. Required Skills/Experience: - Experience in IT audit, technology risk, controls assurance ...