76 to 100 of 332 SOC 2 Jobs in the UK

Security & Compliance Architect for Scalable SaaS

Location
Greater London, England, United Kingdom
Lantern's security programme as we scale. You will cover cloud and application security, vulnerability management, IAM, incident response, secure software delivery, SOC 2, risk management, and customer security assurance. You'll drive security findings into concrete actions with owners and deadlines, and manage SOC 2 ...

Senior Compliance Lead — SOC 2 & ISO 27001 (Remote UK)

Location
Greater London, England, United Kingdom
EnergySys is seeking a dedicated Compliance & Governance professional to own the SOC 2 Type II and ISO 27001 audits, maintain the ISMS, and drive regulatory compliance across UK, Australia, and US entities. You will configure Drata, map controls, and report to senior leadership while partnering with ...

Head of Security

Location
Greater London, England, United Kingdom
security engineering, thoughtful governance and AI-first operations to ensure our customers, employees and partners can confidently rely on Geordie as we scale. With SOC 2 Type II and ISO 27001 already in place, your mission is to build an effective AI-native security programme that keeps certifications … hands-on individual contributor while building security functions from first principles. Experience maintaining security programs aligned to frameworks such as ISO 27001 and SOC 2. Strong understanding of modern software development, cloud infrastructure and secure engineering practices. Experience partnering closely with engineering organisations to build secure-by-design systems. ...

GRC Analyst

Location
Greater London, England, United Kingdom
this role will grow with them. What You'll Do Own end-to-end project management of the compliance programme: support ISO 27001/SOC 2 audits, manage the policy lifecycle, and handle customer security questionnaires and KYC onboarding Manage data protection operations and training, with UK GDPR … work directly with Finance and Engineering/Technology leadership, not just within a compliance team Nice to Have Exposure to ISO 27001 or SOC 2 audit cycles Exposure to business continuity or major incident processes Familiarity with AI governance or emerging AI regulation Interest in health & safety, environmental ...

Senior Security & Compliance Engineer (ISO 27001 / SOC 2)

Location
Greater London, England, United Kingdom
Volta is seeking a Senior Manager, Cyber Security Engineering to lead the ISO 27001 and SOC 2 Type II program across a fast-growing, security‐minded infrastructure platform. You will own controls, evidence, and ISMS documentation while collaborating with platform engineers and external auditors. You’ll drive audit ...

Director of Architecture and IT Security

Hiring Organisation
Corecom Consulting
Location
Leeds, West Yorkshire, United Kingdom
Employment Type
Permanent
Salary
£110000 - £140000/annum
demand, enterprise requirements and future international markets. The role also carries significant responsibility for AI governance, security assurance and certification, including ISO 42001 and SOC 2. You will act as the senior authority on the technology estate, making and defending decisions, challenging where necessary and providing structure without creating … support scalability. Own the organisation's security posture, data governance, risk management and security controls. Lead the certification and compliance agenda, including ISO 42001, SOC 2 and relevant security standards. Establish a rolling penetration-testing programme covering internal and external systems. Own AI governance, including model and vendor ...

IT Administrator (Microsoft 365)

Location
City Of London, England, United Kingdom
device builds and account provisioning Write clear knowledge base articles and user guides Security, compliance and improvement Support security and compliance frameworks such as SOC 2 and Cyber Essentials Plus Keep IT asset records and documentation accurate and up to date Automate repetitive tasks with PowerShell or Microsoft … Microsoft Defender Experience with Freshservice or a similar ITSM platform Experience with compliance and security tools such as Drata, & Aikido advantageous Awareness of SOC 2, Cyber Essentials Plus or ISO 27001 Understanding of email authentication (SPF, DKIM, DMARC) Basic networking knowledge: DNS, DHCP, Wi‐Fi and VPN About ...

Employee Platform Engineer

Location
City of Edinburgh, Scotland, United Kingdom
coding agent workflows that remove manual steps, so the function scales on automation, not headcount Secure and audit-ready: the fleet stays managed and SOC 2 evidence generates itself, rather than being assembled by hand before an audit Who you might be We're not hiring a traditional … Edinburgh and hands-on with real hardware Bonus: Exposure to identity and device tooling such as Okta, Google Workspace or Jamf Experience with SOC 2 or security compliance Having run or automated onboarding, endpoints or internal tools before How we work This role is on-site in Edinburgh ...

AI-Native Software Engineer

Location
Greater London, England, United Kingdom
These are broad, senior engineering roles, not single-language specialist posts. This is a regulated payments environment governed by frameworks including DORA, PCI DSS, SOC 2, EMI regulations and GDPR. These frameworks shape our SDLC itself, from change control and approvals to testing evidence and audit trails. Delivery … propose efficiency improvements that keep compliance intact. Familiarity with, or the ability to rapidly get to grips with, frameworks such as DORA, PCI DSS, SOC 2, EMI regulations and GDPR. You understand that the SDLC is constrained by these frameworks and can still deliver efficiently within it, using ...

Security Engineering Lead — IAM, ISO 27001 & SOC 2

Location
Greater London, England, United Kingdom
while steering the security programme and acting as the security expert across teams. You will protect leadership from targeted attacks, drive ISO 27001 and SOC 2 efforts, and partner with DevOps to secure our cloud environment while keeping pace with a fast-growing startup. #J-18808-Ljbffr ...

Global Compliance Lead — SOC 1/2 & PCI for FinTech

Location
Greater London, England, United Kingdom
financial software company in London is seeking a Global Compliance Manager to oversee compliance execution. You'll manage audits for SOC 1, SOC 2, and PCI programs, ensuring robust control implementation and corporate compliance. Ideal candidates will have 3-7 years in compliance, strong engineering collaboration skills ...

Product Security Specialist for Medical Devices (Cyber Security)

Location
Greater London, England, United Kingdom
align with what you want to do. Hybrid working - our approach is to be in the office or on client site a minimum of 2 days per week. Work on a broad variety of projects and tech stacks for clients across seven sectors - no project is ever the same … residual risk after applying compensating security controls Experience implementing and demonstrating compliance to security frameworks such as NIST, IEC, HITRUST, HIPAA, GDPR, ISO 27001, SOC 2 Type 2 and familiarity working with Quality Management Systems Experience working with teams in a structured software development lifecycle process Excellent ...

Product Security Specialist for Medical Devices (Cyber Security)

Hiring Organisation
PA Consulting
Location
Pimlico, Hertfordshire, UK
Employment Type
Full-time
align with what you want to do. Hybrid working - our approach is to be in the office or on client site a minimum of 2 days per week. Work on a broad variety of projects and tech stacks for clients across seven sectors - no project is ever the same … residual risk after applying compensating security controls Experience implementing and demonstrating compliance to security frameworks such as NIST, IEC, HITRUST, HIPAA, GDPR, ISO 27001, SOC 2 Type 2 and familiarity working with Quality Management Systems Experience working with teams in a structured software development lifecycle process Excellent ...

Head of Platform / Senior Platform Manager

Location
Greater London, England, United Kingdom
Experience designing for air-gapped, disconnected, sovereign or similarly restricted production environments. Experience leading a substantial high-assurance audit or compliance programme, such as SOC 2 Type 2, PCI DSS, DEFSTAN 05-138 or FedRAMP. Strong Linux, Kubernetes, infrastructure automation and troubleshooting expertise. The ability to write ...

Principal Security Engineer, Product & Infrastructure

Location
Greater London, England, United Kingdom
.NET Core, TypeScript, React, Python, Go Datadog (SIEM), CloudFlare ZTNA, Falco, Wiz, Riot, HackerOne, TruffleHog Google Workspace, Jumpcloud, Vanta, Hibob, Slack GitHub, CircleCI, ArgoCD SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001 Who you are You have at least 8 years of experience ...

Head Of Engineering

Location
Greater London, England, United Kingdom
team. About Descrial Descrial is a startup inside a twenty-year-old company TresVista has run the analytical work behind private capital since 2006. 2,000 people, 400+ clients including some of the biggest names in the industry, no outside capital and no outside board. That was the first … platform holding confidential investment data, you own identity, token architecture, permissions, tenant isolation and an audit trail of agent actions. TresVista holds SOC 2 Type 2 and ISO 27001:2022 certification. With TresVista's compliance team, you lead Descrial's readiness for both and prepare ...

Privacy & Data Security Engineer

Hiring Organisation
Robert Half
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
Robert Half Technology are assisting a market-leading threat intelligence organisation to recruit a Privacy & Data Security Engineer on a 2-year temporary contract basis. Hybrid working - London, 2-3 days per week. Role The Privacy & Data Security Engineer will lead the technical implementation of the organisation … secure data-sharing architectures would be beneficial. Experience producing technical control documentation, audit evidence and compliance artefacts for frameworks such as ISO 27001 and SOC 2. Relevant qualifications such as CIPT, CIPM, CISSP or CISM would be advantageous. Excellent written and verbal communication skills, with the ability to explain ...

Senior Internal Audit Manager, Financial Controls & Assurance

Location
Andover, England, United Kingdom
and continuous improvement.* ## Present audit findings and assurance reporting to senior leadership and governance committees.## ## **External Assurance Support*** ## Support external audit, SOC, ISO and regulatory assurance activities.* ## Coordinate internal testing activities to support customer assurance commitments.## Leverage internal audit findings to strengthen organisational readiness … highly regulated SaaS environment.* ## Professional qualifications such as: CIA, ACA/ACCA, CPA, CISA, CRISC* ## Experience working within organisations subject to SOC 1, SOC 2, ISO 27001 or similar assurance frameworks.* ## Experience using GRC platforms and audit management tools.## ## **About you and ...

Lead Engineer

Location
Greater London, England, United Kingdom
scale ensuring standardized onboarding patterns and controls.* Establish guardrails and RBAC/ABAC models aligned to Zero Trust and regulatory frameworks (ISO 27001, SOC 2, NIST 800-53/63).* Define and maintain technical roadmaps, standards, and reference architectures; mentor engineers and review develop/runbooks.* Lead ...

Senior Security Engineer

Location
Greater London, England, United Kingdom
information security principles and cybersecurity frameworks relevant to cloud environments: MITRE ATT&CK for Cloud, CIS Benchmarks, AWS Well‐Architected Security Pillar, NIST CSF, SOC 2, ISO 27001. Willingness and ability to participate in an on‐call rotation, including after‐hours response. Ability to produce clear, comprehensive, and ...

Sr Manager - IT Governance, Risk, and Compliance

Hiring Organisation
Plexus
Location
Livingston, West Lothian, UK
Employment Type
Full-time
Develop and maintain the Cybersecurity GRC framework, policies, standards, and procedures in alignment with regulatory requirements (e.g., ISO 27001, NIST CSF, Cyber Essentials +, SOC 2, GDPR, CMMC Level 2,3)Develop, maintain, and socialize IT and cybersecurity policies, standards, and procedures across the organization. Oversee risk ...

Platform Engineer

Location
Leeds, England, United Kingdom
Drive the adoption of cloud governance policies, security standards and architectural best practice, and help maintain continuous compliance evidence against the firm’s obligations (SOC 2, ISO 27001, GDPR, DORA). Contribute to observability and monitoring across the estate, and to incident response and on-call, including troubleshooting ...

Security & Compliance Analyst for SaaS Trust

Location
Harrogate, England, United Kingdom
report to the Head of Information Security. You will help respond to customer security questionnaires, support audits, and maintain a controls library aligned to SOC 1, SOC 2, ISO 27001, ISO 42001, and FedRAMP. This is a global role working with teams across time zones. #J ...

Director, Security Engineering

Location
City of Westminster, England, United Kingdom
tabletop/purple-team exercises and postmortem improvements. A major focus is driving AI security and internal AI governance: integrating LLMs/ML into SOC triage and anomaly detection, defending AI attack surfaces (agent activity, prompt injection, machine identities), hardening against AI-driven threats (phishing-resistant MFA, supply chain … with all three. Nice to have: securing AI product features, OWASP Top 10 for LLM Applications, the NIST AI Risk Management Framework, MITRE ATLAS, SOC 2, or ISO 27001. Education Degree in a STEM field, preferably Information Security or Computer Engineering, or equivalent practical experience. Certifications such ...

Staff Systems Administrator (R5995)

Location
Greater London, England, United Kingdom
manufacturing, or other mission-critical technical teams. Working knowledge of recognized security and compliance frameworks such as CIS Controls and Benchmarks, NIST, ISO 27001, SOC 2, Cyber Essentials, or equivalent local and contractual standards. Experience with security tooling such as SIEM, vulnerability-management platforms, privileged-access management, data ...