26 to 50 of 521 SOC 2 Jobs in the UK

Head of Information Security

Location
Greater London, England, United Kingdom
Valarian’s Zero-Trust security roadmap, policies, risk assessments, and executive reporting for leadership and the board Own end-to-end audit readiness for SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53 Embed DevSecOps and secure SDLC practices into CI/CD pipelines … Manager, Architect, or Director stepping into a first CISO-level leadership role Experience with Zero-Trust security roadmaps, policies, and risk assessments Experience with SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53 Experience embedding DevSecOps and secure SDLC practices into CI/ ...

Third Party Assurance (TPA) Senior Managers – London- Leeds- Liverpool – Manchester – Growing Team –

Location
Leeds, England, United Kingdom
excellent opportunity for an experienced assurance professional to apply and deepen their expertise across ISAE 3000 , ISAE 3402 , ISAE 3410 , AAF 01/20 , SOC 1/SOC 2 , ISRS 4400 , and emerging frameworks. You will work with clients at varying stages of their reporting journey, overseeing … internal audit , regulatory assurance , or risk advisory . Strong knowledge of recognised assurance standards: ISAE 3000 , ISAE 3402 , ISAE 3410 , AAF 01/20 , SOC 1/SOC 2 , ISRS 4400 . Proven experience leading complex assurance engagements, including planning, risk assessment, and methodology application. Strong understanding ...

GRC Engineer

Location
Belfast City District, Northern Ireland, United Kingdom
oriented skills like API integrations, data querying, and control automation. You'll be a key player in maintaining our compliance posture across frameworks like SOC 2, NIST CSF, and ISO 27001, while also helping modernize how we monitor and evidence controls using platforms like Anecdotes. This role suits … pull evidence out of a data pipeline. What You'll Do Audits & Framework Management Own or co-own preparation for and execution of SOC 2 (Type I/II) audits, working directly with external auditors to scope, evidence, and remediate findings Lead or support NIST CSF assessments and ...

Senior Cloud Security Engineer

Hiring Organisation
Spencer Rose Ltd
Location
United Kingdom
Employment Type
Permanent
Salary
GBP 50,000 Annual
accounts, and break-glass access processes. Support access life cycle management and privileged access governance. Compliance & Customer Assurance Support compliance initiatives including: ISO 27001 SOC 2 Cyber Essentials Plus Secure by Design Assist with audits, evidence collection, risk remediation, and customer security assessments. Work directly with enterprise clients … Azure Entra ID, RBAC, PIM, and privileged access controls. Experience developing automation using Python and/or PowerShell. Working knowledge of ISO 27001, SOC 2, Cyber Essentials Plus, or similar compliance frameworks. Experience working directly with customers, auditors, suppliers, and security assessors. Excellent communication skills with the ability ...

Information Security Manager - Fintech - Hybrid

Location
City Of London, England, United Kingdom
Programme Maintain and continuously improve the Information Security Management System, firmwide information security programme, security policies, certifications and control framework, aligned to ISO 27001, SOC 2, DORA‐related customer obligations, applicable financial services expectations and Crédit Agricole Group requirements. Partner with Product, Engineering and Technology teams to embed … monitoring and exit arrangements. Own the client security assurance process, including security questionnaires, RFP/RFI responses, client audits, evidence packs, ISO 27001/SOC 2 artefacts, penetration test summaries, contractual security schedules and remediation tracking. Security Awareness & Planning Plan and maintain the annual security roadmap ...

Senior Security Engineer

Location
Greater London, England, United Kingdom
security design and architecture reviews, paired with the governance and process work that scales the program. You will partner on customer due‐diligence and SOC 2 evidence and turn security controls into repeatable workflows that fit how the business already works. You will apply that lens across … and DevOps to reduce risk through secure design and simplicity, not just added controls. Governance, Risk & Compliance Partner on customer due‐diligence (DDQ) and SOC 2 Type II evidence gathering, keeping compliance sustainable rather than fire‐drilled. Build repeatable security workflows that embed controls into existing engineering processes ...

Enterprise Infrastructure Engineer

Location
Greater London, England, United Kingdom
align with a cloud-first strategy. Partner with Security to harden the Microsoft 365 tenant and infrastructure estate against relevant compliance frameworks (ISO 27001, SOC 2, DORA). Work closely with senior infrastructure engineers on infrastructure design decisions, escalating complex troubleshooting and design questions as needed. Change Control … Intune and Kandji are compliant, patched, and enrolled to policy. The Microsoft 365 tenant and wider SaaS estate meet relevant compliance frameworks (ISO 27001, SOC 2, DORA). Infrastructure changes are documented, tested, and follow IT change control processes without exception. Technical documentation, runbooks, and architecture records ...

Member of Technical Staff (Platform Leaning)

Location
Greater London, England, United Kingdom
deploy, operate and support wherever it needs to run. We expect you to be relentlessly AI native about it: instead of triaging alerts at 2 am, you'll build or deploy the agent that does it. Instead of reacting to scaling bottlenecks, you'll create systems that spot them … agentic tooling handles a growing share of the toil, and the infrastructure work you touch is compliant by default, keeping our ISO 27001 and SOC 2 journey unblocked. What you'll do No two days will be the same at Tessl! You'll have a high level ...

Security Compliance Analyst-UK

Location
United Kingdom
Proposal Manager as applicable. Supports calls with customers to highlight security within products. Supports compliance audits and readiness initiatives (driven by frameworks such as SOC 1, SOC 2, ISO 27001, ISO 42001, FedRAMP). Monitors control remediation efforts with stakeholders across various functions in different geographies & time … Risk & Compliance (GRC) or with an IT audit background. Experience implementing or auditing information security programs based on industry frameworks such as ISO 27001, SOC 1, SOC 2, FedRAMP, or similar. Bachelor’s Degree or equivalent work experience in Computer Science, Engineering, Accounting, or related field required. ...

Lead Security Engineer

Location
Greater London, England, United Kingdom
play a key role in protecting our leadership team from targeted attacks, serve as the technical backbone of our ISO 27001 and SOC 2 programmes, and partner with our DevOps and Platform teams on cloud security. Above all, you'll help us stay safe while keeping our pace. … from targeted phishing, impersonation, business email compromise, and AI-enabled fraud such as deepfakes. Act as the technical owner of our ISO 27001 and SOC 2 controls, from policies and evidence through to auditor walkthroughs. Lead third-party and vendor risk assessments. Respond to and lead security incidents ...

Chief Information Security Officer (CISO)

Location
Greater London, England, United Kingdom
Remanence with confidence. This is a hands‐on role. What you'll work on Build our security program and lead ISO 27001 certification and SOC 2 Type II audits, expanding to additional frameworks as needed. Manage compliance requirements, including GDPR and the EU AI Act, alongside sector‐specific … business continuity, and occasionally support internal IT security, including identity, device management and employee access. Relevant frameworks and technologies Core certifications: ISO 27001 and SOC 2 Type II. You must have led at least one certification or audit end to end. Additional frameworks: Experience with AI, privacy ...

Compliance Officer

Location
Greater London, England, United Kingdom
ensuring that nothing falls through the gaps as the business grows. What you’ll be responsible for Audit & Certification You’ll own the ongoing SOC 2 Type II and ISO 27001:2022 audit lifecycle for an already‐certified organisation: surveillance and recertification audit planning, evidence readiness, auditor liaison … regulatory changes or operational changes, and advising leadership on required updates. Vendor & Third‐Party Risk Conduct and support structured vendor risk assessments, review SOC 2 reports, ISO certificates, and DPAs, maintain the vendor register, and ensure periodic reviews are completed on schedule. Infrastructure & Evidence Navigate AWS, Microsoft Entra ...

Security Engineer, Compliance Focus

Location
Greater London, England, United Kingdom
paperwork exercise at the edge of the business. It is a condition of doing business. We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure in several countries, and deploying into partner data centers. … actually working or only described. What You Will Be Doing Compliance Execution Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline. Operate our GRC platform (Vanta) day to day: configure and ...

GRC Lead

Location
City of Edinburgh, Scotland, United Kingdom
Leads own security and compliance at Wordsmith end-to-end — setting the strategy for IT and infrastructure security, running our certification program across SOC 2, ISO 27001, and ISO 42001, embedding responsible-AI practices into how we build and ship product, and making sure privacy and regulatory obligations … corporate IT and infrastructure — identity & access management, endpoint protection, and cloud/network security — and lead incident response when issues arise. Compliance & Certification Own SOC 2 Type II, ISO 27001/27017/27018, and ISO 42001 end-to-end — policies, controls, audit evidence, and the audits themselves. ...

Security Engineer

Location
Greater London, England, United Kingdom
large case files, test arguments and produce high-quality work grounded in the full matter record. Crimson is enterprise-grade by design. We are SOC 2 Type II attested, encrypt data in transit and at rest, and maintain rigorous controls across our product, infrastructure and operations. Security … continuous learning Coordinate independent penetration testing and represent Crimson's security posture in customer security reviews Maintain the controls and evidence supporting Crimson's SOC 2 Type II attestation and enterprise customer requirements Embed practical security guidance and tooling into a fast-moving engineering environment What ...

Deputy Chief Technology Officer

Location
Greater London, England, United Kingdom
group-level data capability is live with a published catalog and cross-divisional SLAs. Regulatory & Cost Control: Engineering consistently hits all MiCA, DORA, and SOC 2 milestones while managing cloud and vendor spend against clear business-unit baselines. Key Responsibilities Engineering Delivery & Cadence: Run day-to-day global … group data pipelines and governance. Cybersecurity Execution & Compliance: Own the on-the-ground execution of The Company’s security and regulatory commitments (MiCA, DORA, SOC 2). Foster a "controls-by-design" engineering culture while respecting regulated divisional information walls. Talent, Budget & Scale: Manage the global engineering budget ...

Head of Business Systems & Security

Location
Glasgow, Scotland, United Kingdom
that keeps the company working. That covers NetSuite, Salesforce, Workato and DealHub among others, the integration layer and data definitions beneath them, SOC 2 and access control, and the full device and application estate across our UK, US and Portugal teams. It is a broad, senior remit with … integrations that connect them, and the data governance underneath. Set the architecture, operating model and roadmap for how Reachdesk uses its systems. Own the SOC 2 Type II programme, the security policy set and the risk register as the accountable business owner. Own identity and access management, joiner ...

Head of Business Systems & Security New Birmingham, England, United Kingdom

Location
Birmingham, England, United Kingdom
that keeps the company working. That covers NetSuite, Salesforce, Workato and DealHub among others, the integration layer and data definitions beneath them, SOC 2 and access control, and the full device and application estate across our UK, US and Portugal teams. It is a broad, senior remit with … integrations that connect them, and the data governance underneath. Set the architecture, operating model and roadmap for how Reachdesk uses its systems. Own the SOC 2 Type II programme, the security policy set and the risk register as the accountable business owner. Own identity and access management, joiner ...

Head of Business Systems & Security New Manchester, England, United Kingdom

Location
Manchester, England, United Kingdom
that keeps the company working. That covers NetSuite, Salesforce, Workato and DealHub among others, the integration layer and data definitions beneath them, SOC 2 and access control, and the full device and application estate across our UK, US and Portugal teams. It is a broad, senior remit with … integrations that connect them, and the data governance underneath. Set the architecture, operating model and roadmap for how Reachdesk uses its systems. Own the SOC 2 Type II programme, the security policy set and the risk register as the accountable business owner. Own identity and access management, joiner ...

IT Operations Manager

Location
Greater London, England, United Kingdom
when necessary to support them. You will own the IT strategy and roadmap, service performance, vendor procurement outcomes, and the IT control environment, including SOC 2, Cyber Essentials, and GDPR-related IT controls. You will plan and manage the project portfolio, hold vendors and the team to account … outcome, the Indeed relationship, and vendor performance Security, Risk & Compliance: Own the IT control environment and security posture, including policy, access standards, SOC 2, Cyber Essentials, GDPR-related IT controls, and audit outcomes. Direct the team's evidence gathering and control maintenance, and represent IT on security and ...

Remote Associate, SOC Assessment

Location
United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...

Remote Associate, SOC Assessment

Hiring Organisation
Coalfire
Location
Dungannon, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...

Remote Associate, SOC Assessment

Hiring Organisation
Coalfire
Location
Carmarthenshire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...

Remote Associate, SOC Assessment

Location
Durham, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...

Remote Associate, SOC Assessment

Hiring Organisation
Coalfire
Location
Denbighshire, United Kingdom
team members to effectively manage project timelines and deliverables. This team focuses on assessments for hyperscale cloud providers, and has a particular expertise in SOC 1, SOC 2, C5, and DSA assessments. This role will evaluate the design and effectiveness of technology controls throughout the business cycle … technology controls throughout the business cycle What You'll Bring Introductory understanding of audit procedures and IT security especially as it relates to SOC 1 and SOC 2 or other regulatory frameworks Experience and demonstrated ability to independently research a technical topic and develop logical testing approaches ...