Ideally, you'll have experience leading within a risk management role and havea good knowledge of methodologies such as IEC 62443 and ISO 27005. Knowledge ofcontrol frameworks such as NIST, IEC 62443, ISO 27001, ITIL (InformationTechnology Infrastructure Library), and SABSA is also required. You'll need to have a structured, methodical and accurate approach with theability to interpret relevant industry More ❯
Ideally, you'll have experience leading within a risk management role and havea good knowledge of methodologies such as IEC 62443 and ISO 27005. Knowledge ofcontrol frameworks such as NIST, IEC 62443, ISO 27001, ITIL (InformationTechnology Infrastructure Library), and SABSA is also required. You'll need to have a structured, methodical and accurate approach with theability to interpret relevant industry More ❯
our office in Dudley (UK), we are currently recruiting a driven Cybersecurity & Compliance Manager. Position purpose The Cybersecurity & Compliance Manager will lead Tosca’s efforts to ensure adherence to NIST CFS 2.0, ISO 27001, and other standards. This role focuses on developing security protocols, maintaining documentation, conducting risk assessments, and ensuring regulatory compliance. Responsibilities include managing security infrastructure, incident response … and promoting cybersecurity awareness. The position requires collaboration with Global IT, cross-functional teams, and third-party partners. Key qualifications include experience in cybersecurity and compliance, strong knowledge ofNISTand ISO standards, risk management expertise, and effective communication skills. This is a full-time role based in Dudley, UK, with travel up to 30% of the time. Responsibilities Implement … security protocols and manage information security programs Report performance, exceptions, and outages to all audiences transparently. Align disaster recovery with business continuity plans. Ensure compliance with ISO27001, NIST CFS 2.0, and maintain ISMS. Identify risks, develop a comprehensive security plan. Test cyber-attacks regularly to address vulnerabilities. Monitor security trends, adapt strategies. Oversee incident monitoring, detection, response via SOC andMore ❯
planning, and performance metric tracking (e.g., velocity, burn-down charts). Advanced Cryptography : Understanding of cryptographic algorithms, protocols, and key management systems. Familiarity with PQC standardsand protocols (e.g., NIST PQC). Security Architecture : Expertise in designing and implementing secure architectures for software and cloud environments. Embedded Systems : Knowledge of secure software for embedded systems and IoT security. Software Security More ❯
holding one or more of the following: Professional membership with a recognised body, supported by externally validated evidence of professional development ISO/IEC 27001 Information Security Management - Foundation NIST Cyber Security Professional (NCSP) - Foundation Certificate ISO/IEC 27001 Information Security Management - Practitioner, Lead Implementer, or Lead Auditor More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
QinetiQ Limited
of action The ability to understand how architects and designers employ technology to build systems of interest Digitally literate (including fluency in Microsoft Office tools) Able to understand relevant NIST frameworks and ISO27001 standardsand how to apply in practice Knowledge of MITRE ATT&CK Essential qualifications for the Cyber Security Risk Consultant: We value difference and we don't More ❯
Cheltenham, England, United Kingdom Hybrid / WFH Options
FR Secure
and secure-by-design principles. Familiarity with government and defence security standards such as: HMG/NCSC IA Policies and Guidelines JSP440 and other MoD IA standards Cyber Essentials NIST, NIS-D ONR SyAPs (Security Assessment Principles) Excellent stakeholder communication skills – you can clearly explain complex security concepts to both technical and non-technical audiences. Security Clearance eDV clearance is More ❯
through the delivery and operational life cycle of a system Provision of authoritative specialist security advice in Risk and threat-based mitigation to system designs Control frameworks such as NIST, ISO, CIS Protective monitoring, Authentication and authorization best practices. Develop excellent working relationships with key stakeholders, peers and subordinates. Communicating effectively verbally and in writing, demonstrated through: Effectively explain complex More ❯
projects across both banking and securities domains. Candidate profile: Strong experience delivering cybersecurity or technology projects in large-scale, regulated environments. Familiarity with security standards such as ISO 27001, NIST, PCI-DSS, FFIEC, or EBA ICT. Solid understanding of audit and risk remediation processes. Excellent stakeholder engagement and cross-functional collaboration skills. A background in managing multiple complex, high-impact More ❯
Drive innovation and thought leadership within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCI DSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll More ❯
Drive innovation and thought leadership within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCI DSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll More ❯
Drive innovation and thought leadership within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCI DSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll More ❯
Drive innovation and thought leadership within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCI DSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll More ❯
Drive innovation and thought leadership within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCI DSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll More ❯
Drive innovation and thought leadership within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCI DSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll More ❯
Drive innovation and thought leadership within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCI DSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll More ❯
Drive innovation and thought leadership within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCI DSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll More ❯
Drive innovation and thought leadership within the Practice by defining standards, sharing knowledge, and mentoring peers Influence customer outcomes through expert knowledge of DevSecOps tools and compliance frameworks like NIST, CIS, SOC 2, and PCI DSS You'll travel to client sites across the UK, working directly with business and technical stakeholders to drive real business value What you'll More ❯
within a top-tier business. This role emphasizes project-related work, requiring a strong all-round cybersecurity background with experience in delivering standards such as ISO2700x, Cyber Essentials, CIS, NIST , and familiarity with emerging UK government cybersecurity initiatives. Demonstrable knowledge of cybersecurity principles, theories, practices, and techniques, including offensive security is essential. Technical proficiency with Defender, Intune, Azure, and D365 More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Adecco
areas to assess these, develop action plans, identify owners and track through to completion. Requirements: Technology Knowledge: Work towards a detailed understanding ofTechnologyand cyber risk frameworks (e.g. NIST/ISO27001/COBIT/ITIL). SSSDLC Expertise: Understanding of the Secure Software/System Development Lifecycle, including secure design, development, testing, and deployment practices. Process Documentation: Experience in More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Akkodis
Azure DevOps (CI/CD) Familiar with scripting languages like PowerShell, YAML, JSON Expertise in application security tools and DevSecOps processes Understanding of key frameworks andstandards (e.g. OWASP, NIST SSDF, ISO27001, NCSC) Experience with threat modelling, risk assessments, and secure design reviews Comfortable owning security strategy and tooling across complex, modern product landscapes Strong communicator. Able to engage confidently More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Akkodis
Azure DevOps (CI/CD) Familiar with scripting languages like PowerShell, YAML, JSON Expertise in application security tools and DevSecOps processes Understanding of key frameworks andstandards (e.g. OWASP, NIST SSDF, ISO27001, NCSC) Experience with threat modelling, risk assessments, and secure design reviews Comfortable owning security strategy and tooling across complex, modern product landscapes Strong communicator. Able to engage confidently More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Akkodis
Azure DevOps (CI/CD)- Familiar with scripting languages like PowerShell, YAML, JSON- Expertise in application security tools and DevSecOps processes- Understanding of key frameworks andstandards (e.g. OWASP, NIST SSDF, ISO27001, NCSC)- Experience with threat modelling, risk assessments, and secure design reviews- Comfortable owning security strategy and tooling across complex, modern product landscapes- Strong communicator - able to engage confidently More ❯
risk management, including risk identification, assessment, and mitigation strategies. You will be responsible for reviewing and developing policies. You will have a strong understanding of security frameworks such as NIST, COBIT, or ISO/IEC standards. You will be responsible for ensuring that regulatory obligations are met, risks are proactively identified and m ana ged, and security polic ies andMore ❯
Birmingham, West Midlands, West Midlands (County), United Kingdom
Experis
someone that has a strong all round Cyber security background with an emphasis on experience with the delivery of one or more of the following ISO2700x, Cyber Essentials, CIS, NIST , and emerging UK government cybersecurity initiatives. Demonstrable knowledge of cybersecurity principles, theories, practices, and techniques, including offensive security . Technical knowledge and proficiency (operational and security) with Defender, Intune, Azure More ❯