Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
AtkinsRéalis
the CESG IA Portfolio and MoD JSPs such as JSP440, JSP604/JSP453 (plus other standard MoD IA methods). Certifications such as ISO27000, NIST Cyber Security Professional, CISMP etc. Flexibility over UK, and potentially overseas travel. Desirable: Certified Information Systems Security Professional (CISSP)/Certified Information Security Manager (CISM … CIISEC. NCSC Certified Cyber Professional/CESG CCP (Security and Information Risk Advisor or Security Architect). Understanding of 'Secure by Design' methodology andNIST 800-37 Risk Management Framework. A keen interest in the latest technology with a focus on security technologies. Ambition to work in a challenging andMore ❯
Almondsbury, Gloucestershire, United Kingdom Hybrid / WFH Options
Frontier Resourcing
Perform security code reviews, provide guidance on secure libraries and frameworks. Standards & Compliance Ensure products meet regulatory and defence standards (ISO 27001/27005, NIST 800-30/53, JSP 440/604, Def Stan 05-series). Lead the creation and maintenance of security documentation (RMADS, Security Assurance Documents … or application security within defence, government, or security-cleared environments. Deep knowledge of risk management frameworks (ISO 27001/2/5/31000, NIST 800-series) and Defence Standards (JSPs, Def Stan 05-138/139). Hands-on experience with security testing tools and techniques (SAST, DAST, penetration More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Frontier Resourcing Ltd
Perform security code reviews, provide guidance on secure libraries and frameworks. Standards & Compliance Ensure products meet regulatory and defence standards (ISO 27001/27005, NIST 800-30/53, JSP 440/604, Def Stan 05-series). Lead the creation and maintenance of security documentation (RMADS, Security Assurance Documents … or application security within defence, government, or security-cleared environments. Deep knowledge of risk management frameworks (ISO 27001/2/5/31000, NIST 800-series) and Defence Standards (JSPs, Def Stan 05-138/139). Hands-on experience with security testing tools and techniques (SAST, DAST, penetration More ❯
Supporting incident response planning and coordination related to supply chain risk scenarios. Supporting the implementation and continual improvement of ISO 27001, Cyber Essentials, andNIST CSF compliance programs. Ensuring security risks are effectively communicated to stakeholders and appropriately documented. Key Accountabilities, Skills & Experience Proven experience in Information Security , specifically in … party risk , supply chain assurance , and governance, risk, and compliance . Strong understanding of ISO 27001 (implementation, audit, and continuous improvement), Cyber Essentials, andNIST CSF. Familiarity with reviewing SOC 2 Type II, ISO 27001 certifications, and other third-party assurance artefacts. Ability to analyse and evaluate technical and procedural More ❯
Supporting incident response planning and coordination related to supply chain risk scenarios. Supporting the implementation and continual improvement of ISO 27001, Cyber Essentials, andNIST CSF compliance programs. Ensuring security risks are effectively communicated to stakeholders and appropriately documented. Key Accountabilities, Skills & Experience Proven experience in Information Security , specifically in … party risk , supply chain assurance , and governance, risk, and compliance . Strong understanding of ISO 27001 (implementation, audit, and continuous improvement), Cyber Essentials, andNIST CSF. Familiarity with reviewing SOC 2 Type II, ISO 27001 certifications, and other third-party assurance artefacts. Ability to analyse and evaluate technical and procedural More ❯
Supporting incident response planning and coordination related to supply chain risk scenarios. Supporting the implementation and continual improvement of ISO 27001, Cyber Essentials, andNIST CSF compliance programs. Ensuring security risks are effectively communicated to stakeholders and appropriately documented. Key Accountabilities, Skills & Experience Proven experience in Information Security , specifically in … party risk , supply chain assurance , and governance, risk, and compliance . Strong understanding of ISO 27001 (implementation, audit, and continuous improvement), Cyber Essentials, andNIST CSF. Familiarity with reviewing SOC 2 Type II, ISO 27001 certifications, and other third-party assurance artefacts. Ability to analyse and evaluate technical and procedural More ❯
warrington, cheshire, north west england, united kingdom
AMS CWS
Supporting incident response planning and coordination related to supply chain risk scenarios. Supporting the implementation and continual improvement of ISO 27001, Cyber Essentials, andNIST CSF compliance programs. Ensuring security risks are effectively communicated to stakeholders and appropriately documented. Key Accountabilities, Skills & Experience Proven experience in Information Security , specifically in … party risk , supply chain assurance , and governance, risk, and compliance . Strong understanding of ISO 27001 (implementation, audit, and continuous improvement), Cyber Essentials, andNIST CSF. Familiarity with reviewing SOC 2 Type II, ISO 27001 certifications, and other third-party assurance artefacts. Ability to analyse and evaluate technical and procedural More ❯
Data Centre & Cloud Manager - Birmingham, Budapest, Dublin or Amsterdam Birmingham, United Kingdom ; , BIR, GB CRH International About CRH We are CRH, and we are committed to contributing to a more resilient and sustainable built environment. We understand the wider impact More ❯
Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert: Country: United Kingdom City: Birmingham, United Kingdom ; Amsterdam, The Netherlands ; Dublin, Ireland Req ID: 505424 About CRH We are CRH, and we More ❯
Play a key role in shaping IT security strategy! Work to develop policies, manage risks, and drive security innovation. Ideal for those with extensive experience in cyber and information security and a passion for safeguarding digital assets. Overview job description More ❯
will also play a crucial role in ensuring our organisation's compliance with information security standardsand frameworks , particularly Cyber Essentials, ISO 27001 andNIST Cybersecurity Framework. As a Risk Analyst you will be responsible for: Performing internal information security risk assessments and recommending mitigation actions/solutions. Collaborating with … reviewing security controls to assess changes in residual risk and the sufficiency of compensating controls. Maintaining certifications, such as Cyber Essentials/ISO27001/NIST CSF v2, against a backdrop of a growing firm and evolving regulations, technologyand processes. Assisting in developing control testing and assurance strategies, to ensure … security controls are meeting their objectives. Key Accountabilities, Skills & Experience: Experience in using standards such as ISO 27001 (Implementation, Compliance, Certification, and audit reviews), NIST CSF, and Cyber Essentials. Experience working in an Information Security role dealing specifically with governance, risk and compliance areas. Prior experience writing Information Security related More ❯
s new UK cybersecurity team. This role is predominantly end-client facing, advising on security best practices, vulnerability management and security standard compliance (e.g. NIST, ISO, PCI DSS etc), and leading audits and examinations. You will be reporting to the UK Head of Security and consulting global clients across the … Compliance Lead on Audits Strong Security standard knowledge and experience, consulting on a range of security policies andstandards such as GDPR, ISO, PCI, NIST Confidence when speaking with stakeholders and clients, as well as the ability to provide training and mentoring around cybersecurity Ideally, some relevant cybersecurity certifications This More ❯
s new UK cybersecurity team. This role is predominantly end-client facing, advising on security best practices, vulnerability management and security standard compliance (e.g. NIST, ISO, PCI DSS etc), and leading audits and examinations. You will be reporting to the UK Head of Security and consulting global clients across the … Compliance Lead on Audits Strong Security standard knowledge and experience, consulting on a range of security policies andstandards such as GDPR, ISO, PCI, NIST Confidence when speaking with stakeholders and clients, as well as the ability to provide training and mentoring around cybersecurity Ideally, some relevant cybersecurity certifications This More ❯
Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
Bowerford Associates
software applications demonstrably more secure and robust. Good understanding of common information security management standards, frameworks, and laws/regulations: e.g . ISO 27001 , NIST , GDPR . Experience of open-source security tools and how they could be used in an enterprise. Experience of securing Azure cloud workloads and environments. … Practice, Programming, Code, C++, C#, C, .NET Core, Java, JavaScript, Node.js, Angular, React, OWASP, Agile, Application Threat Modelling, Security Policy, Security Controls, ISO 27001, NIST, GDPR, Cloud, Azure. Please note that due to a high level of applications, we can only respond to applicants whose skills and qualifications are suitable More ❯
security awareness and help drive a risk-aware culture across the business Provide expert guidance to ensure alignment with security frameworks (e.g. ISO 27001, NIST) Support audit, regulatory compliance, and governance efforts Influence adoption of secure solutions across both strategic and operational initiatives What They Are Looking For Proven experience … stakeholder engagement skills Familiarity with cloud and hybrid security models Understanding of regulatory compliance (e.g., GDPR, PCI DSS) Knowledge of frameworks like ISO 27001, NIST, CIS, or COBIT If keen please apply More ❯
Cloud Security Engineer Kent Hybrid 12-month FTC - Competitive Salary VIQU have partnered with a leading automotive organisation seeking a Cloud Security Engineer to join their growing security function. This role has been created to help bridge the gap between More ❯
Cloud Security Engineer Kent – Hybrid 12-month FTC - Competitive Salary VIQU have partnered with a leading automotive organisation seeking a Cloud Security Engineer to join their growing security function. This role has been created to help bridge the gap between More ❯
Cloud Security Engineer Kent – Hybrid 12-month FTC - Competitive Salary VIQU have partnered with a leading automotive organisation seeking a Cloud Security Engineer to join their growing security function. This role has been created to help bridge the gap between More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
TalkTalk Telecom Group PLC
Senior Security Risk Manager Senior Security Risk Manager Apply locations Salford Quays, Manchester time type Full time posted on Posted 6 Days Ago job requisition id R Please note that this is a FTC opportunity We are PXC, the UK More ❯
Gloucester, Gloucestershire, UK Hybrid / WFH Options
uk7 UTC
testing, behavioural analysis, and environmental factors Develop and present comprehensive risk assessment reports, including clear recommendations for mitigation and investment Apply frameworks such as NIST 800-53, ISO/IEC 27001, and NCSC CAF to assess current controls and identify improvement opportunities Contribute to the development of organisational threat models … You can apply critical thinking to complex and ambiguous environments, making informed decisions under pressure You have strong knowledge of cyber risk frameworks (e.g. NIST, ISO27001, NCSC CAF) and experience in applying them You're experienced in one or more of: counterintelligence, human intelligence and security, physical security assessments, operational More ❯
compliance, and policy. You will be responsible for developing and implementing internal control frameworks and defining policies in line with industry standards such as NISTand ISO 27001. Collaboration with various business units will be key to reducing risk and ensuring compliance with regulations. Key Responsibilities: Focus on risk management … and compliance, including policy andstandards development. Map internal controls to industry standards such as NISTand ISO 27001. Build and define security policies, ensuring alignment with organizational goals. Develop and manage compliance frameworks using Microsoft tools such as SharePoint, Power BI, Power Automate, and Risk Automate. Work closely with … various regions. Identify and deliver service/control improvements and contribute lessons learned to future projects. Desired Skills and Qualifications: Certifications: CISA, CISM, CRISC, NIST, ISO 27001. Experience with building compliance frameworks and policies using Microsoft tools. Please apply if interested More ❯
Greater Bristol Area, United Kingdom Hybrid / WFH Options
Matchtech
mitigation strategies. Conducting security code reviews and offering guidance to ensure a secure-by-design approach. Ensuring products meet key regulatory standards (ISO 27001, NIST 800 series, JSPs, Def Stans). Authoring vital security documentation, including RMADS and Security Assurance Documents. Performing penetration testing and coordinating remediation efforts. What You … Bring: A solid understanding of security frameworks such as ISO 27001/2, ISO 31000, NIST 800-30/37/53. Hands-on experience with Defence Standards (JSPs, HMG, Def Stan 05-138/139). Strong knowledge of security testing tools and techniques. Excellent communication skills — able to … explain complex risks and solutions clearly. A proactive, problem-solving mindset with a high level of personal integrity and professional ethics. Experience with NIST standards. (this is an absolute must) You'll Succeed Here If You: Thrive on solving complex problems with innovative, practical solutions. Communicate clearly, confidently, and with More ❯
bristol, south west england, united kingdom Hybrid / WFH Options
AtkinsRéalis
the CESG IA Portfolio and MoD JSPs such as JSP440, JSP604/JSP453 (plus other standard MoD IA methods). Certifications such as ISO27000, NIST Cyber Security Professional, CISMP etc. Flexibility over UK, and potentially overseas travel. Experience with IT Computer Systems and interconnecting systems and networks. Desirable- Certified Information … of recognised security professional body such as the Instituteof Information Security Professionals (IISP), IS2, BCS and Understanding of 'Secure by Design' methodology andNIST 800-37 Risk Management Framework. A keen interest in the latest technology with a focus on security technologies. Ambition to work in a challenging andMore ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
AtkinsRéalis
JSP604/JSP453 (plus other standard MoD IA methods). Experience with IT Computer Systems and interconnecting systems and networks. Certifications such as ISO27000, NIST Cyber Security Professional, CISMP etc. Flexibility over UK, and potentially overseas travel. Desirable: Certified Information Security Manager Principles (CISMP) or equivalent. Associate/Full Membership … of recognised security professional body such as the Instituteof Information Security Professionals (IISP), IS2, BCS. Understanding of 'Secure by Design' methodology andNIST 800-37 Risk Management Framework. A keen interest in the latest technology with a focus on security technologies. Ambition to work in a challenging and rewarding More ❯
This individual will provide architectural leadership across IT Infrastructure, Applications, and Cyber Security domains, with a strong emphasis on Secure by Design principles andNIST Risk Management Framework compliance. The role requires effective communication with senior client stakeholders and the ability to influence technical decisions through sound governance and evidence … strategies. · Cyber Security & Secure by Design o Embed Secure by Design principles throughout the product lifecycle. o Ensure architecture and solution designs comply with NIST controls, regulatory requirements, and internal cyber security policies. o Collaborate with Information Architecture, Security, Risk, and Compliance teams to assess architectural risk and apply appropriate … architecture (e.g. integration, APIs, data), and cyber security architecture (e.g. identity & access management, threat modelling, security controls). · Strong working knowledge and application ofNIST Risk Management Framework, Secure by Design, and architecture standards. · Proven experience leading architecture governance in large-scale transformation programmes. · Demonstrated ability to engage and influence More ❯