join one of our Global Insurance Clients on a 6 month contract. Please note the role is Inside IR35. Experience Required: Strong knowledge of risk and control frameworks (e.g., NIST, ISO 27001, COBIT). Deep understanding of IT general controls, cyber security principles, andtechnology risk domains. Experience in control ownership, control testing, and remediation planning. Familiarity with GRC platforms More ❯
enhancement of risk data models and reporting frameworks. Ensure alignment of analytics and reporting outputs with enterprise risk management and control frameworks. Strong knowledge of risk management frameworks (e.g., NIST, ISO 27001, COBIT) and control environments. Deep understanding of IT general controls, cyber security principles, andtechnology risk domains. Proven experience in risk analytics, data visualization, and reporting (e.g., using More ❯
Rochester, Kent, South East, United Kingdom Hybrid / WFH Options
Technical Placements
that comprehensively describe the product design and functionality. Certification Experience in designing products for a regulatory controlled market and ensuring compliance with those standards including ISO9001 and ISO27001/NIST or other relevant security frameworks. This is an excellent opportunity to become part of the key engineering team within a developing business with its culture shaped by core values ofMore ❯
Greater Bristol Area, United Kingdom Hybrid / WFH Options
Logiq
Architecture, Secure Systems, Network & Cloud Security, System Hardening, Cryptographic Controls (PKI, Data at Rest/In Transit), Protective Monitoring, and Security Auditing. Strong understanding of the ISO 27000 series, NIST Cyber Security & Risk Management Frameworks, NCSC CAF, and other industry standards. Familiarity with NCSC guidance and legacy Information Assurance (IA) standards. Experience with MOD security frameworks including JSP 604, JSP More ❯
scaling DevSecOps or Secure SDLC programmes within enterprise environments Strong technical and commercial acumen - able to engage with both CTOs and procurement teams Experience with regulated environments and frameworks (NIST, OWASP, ISO 27001) Hands-on experience with secure engineering practices, security toolchains, and automation strategy Excellent stakeholder management, crisis leadership, and communication skills Relevant certifications (e.g. CISSP, CSSLP, CISM) Eligibility More ❯
Ability to lead technical conversations, influence customer decisions, and deliver trusted advisory services Existing SC clearance or eligibility to apply Desirable Skills & Certifications Familiarity with industry security frameworks (e.g., NIST, ISO 27001, CIS Controls) Cloud security experience across major hyperscalers More ❯
Ability to lead technical conversations, influence customer decisions, and deliver trusted advisory services Existing SC clearance or eligibility to apply Desirable Skills & Certifications Familiarity with industry security frameworks (e.g., NIST, ISO 27001, CIS Controls) Cloud security experience across major hyperscalers More ❯
Ability to lead technical conversations, influence customer decisions, and deliver trusted advisory services Existing SC clearance or eligibility to apply Desirable Skills & Certifications Familiarity with industry security frameworks (e.g., NIST, ISO 27001, CIS Controls) Cloud security experience across major hyperscalers More ❯
Ability to lead technical conversations, influence customer decisions, and deliver trusted advisory services Existing SC clearance or eligibility to apply Desirable Skills & Certifications Familiarity with industry security frameworks (e.g., NIST, ISO 27001, CIS Controls) Cloud security experience across major hyperscalers More ❯
clear communication skills across technical and non-technical audiences. Proven ability to work across architecture and engineering teams - balancing governance with delivery. Familiarity with relevant frameworks (e.g., ISO 27001, NIST, CISSP-ISSAP) and enterprise architecture methods (e.g., TOGAF). Why this role? Strategic visibility - You'll be embedded into high-priority programmes with access to senior leadership and real influence More ❯
Accountabilities: Lead and manage a team of three security professionals , supporting their development and day-to-day delivery. Ensure ongoing ISO27001 accreditation and alignment with broader assurance frameworks (e.g. NIST CSF, Cyber Essentials). Shape and implement the company's information security strategy , including policy, tooling, and training. Conduct risk assessments, oversee remediation plans, and guide secure-by-design approaches More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
Reed Technology
Accountabilities: Lead and manage a team of three security professionals , supporting their development and day-to-day delivery. Ensure ongoing ISO27001 accreditation and alignment with broader assurance frameworks (e.g. NIST CSF, Cyber Essentials). Shape and implement the company's information security strategy , including policy, tooling, and training. Conduct risk assessments, oversee remediation plans, and guide secure-by-design approaches More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Reed Technology
Accountabilities: Lead and manage a team of three security professionals , supporting their development and day-to-day delivery. Ensure ongoing ISO27001 accreditation and alignment with broader assurance frameworks (e.g. NIST CSF, Cyber Essentials). Shape and implement the company's information security strategy , including policy, tooling, and training. Conduct risk assessments, oversee remediation plans, and guide secure-by-design approaches More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Opus Recruitment Solutions Ltd
focus on Microsoft Azure. Deep understanding of Azure security architecture, governance, and compliance. Hands-on experience with Azure-native security tools and services. Familiarity with security frameworks such as NIST, ISO 27001, CIS Benchmarks, and Zero Trust principles. Azure certifications such as AZ-500 (Azure Security Engineer Associate) or SC-100 (Cybersecurity Architect Expert) are highly desirable. Excellent communication andMore ❯
threats. Key Responsibilities: Conduct security audits, risk assessments, and penetration tests to evaluate and strengthen our security posture Develop and implement security policies aligned with Cyber Essentials, ISO 27001, NIST, and GDPR Configure and deploy essential tools: firewalls, IDS/IPS, endpoint protection, and encryption Overhaul Active Directory, Group Policies, and server configurations Lead incident response, forensic analysis, and threat More ❯
threats. Key Responsibilities: Conduct security audits, risk assessments, and penetration tests to evaluate and strengthen our security posture Develop and implement security policies aligned with Cyber Essentials, ISO 27001, NIST, and GDPR Configure and deploy essential tools: firewalls, IDS/IPS, endpoint protection, and encryption Overhaul Active Directory, Group Policies, and server configurations Lead incident response, forensic analysis, and threat More ❯
threats. Key Responsibilities: Conduct security audits, risk assessments, and penetration tests to evaluate and strengthen our security posture Develop and implement security policies aligned with Cyber Essentials, ISO 27001, NIST, and GDPR Configure and deploy essential tools: firewalls, IDS/IPS, endpoint protection, and encryption Overhaul Active Directory, Group Policies, and server configurations Lead incident response, forensic analysis, and threat More ❯
senior stakeholders to deliver cyber risk solutions that protect operations, support compliance, and enable strategic growth. Key Responsibilities Lead cyber strategy and maturity assessments aligned to frameworks like ISO27001, NIST CSF, GDPR, and CAF Deliver cyber risk roadmaps and business-aligned security recommendations Translate technical insights into executive-level communications Mentor junior consultants and contribute to proposal or bid work More ❯
security risks. To develop and embed best-practice security processes and knowledge into technical teams aligned to Zero Trust principles and in line with industry standardsand frameworks (e.g. NIST, PCI DSS). To identify opportunities for automation and optimization and drive maximum value from existing technologies and services to strengthen Clarks' overall security posture. DIMENSIONS Financial : No direct financial … project and architecture teams to plan and deliver remediation activities Supporting the development of relevant security roadmaps and activity plans aligned to Zero Trust principles and common industry frameworks (NIST, PCI DSS etc) Assisting in the review and development of operational processes and procedures required to maintain cyber security for I T services, including managing endpoint compliance, system hardening, host … and data protection laws and regulations and how they apply to technology environments (e.g. GDPR, PIPL etc) Knowledge of other regulatory or compliance frameworks such as ISO, PCI DSS, NIST etc Likely to hold at least one common security certification (CEH, CCSP, CISSP, OSCP) alongside other relevant IT certifications (ITIL, AMP, Prince2 etc) preferred Additional technologies/experience: Experience with More ❯
familiarity with industry standards such as ISO 27001-ideally having led certification projects-and an ability to apply structured frameworks for risk assessment across complex organisational landscapes. Exposure to NIST frameworks or certifications such as CISMP/CISSP/CISM/CRISC which would further enhance your suitability for this influential position. five years' experience in Information Security/GRC More ❯
Birmingham, West Midlands, England, United Kingdom
Robert Walters
familiarity with industry standards such as ISO 27001-ideally having led certification projects-and an ability to apply structured frameworks for risk assessment across complex organisational landscapes. Exposure to NIST frameworks or certifications such as CISMP/CISSP/CISM/CRISC which would further enhance your suitability for this influential position. five years' experience in Information Security/GRC More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
TalkTalk Telecom Group PLC
Analyse and interpret relevant and emerging compliance standardsand regulations to ensure these are understood by the business and appropriate steps are taken to achieve compliance where relevant. Support NIST control maturity assessment. Support resilience activities and audits. Oversee and lead the liaison, preparation and coordination of external compliance and regulatory audits, ensuring they are run effectively and efficiently. What More ❯
Engineering Role. Leading delivery of MOD accreditation and secure by design processes (ISN2023/09), associated policies and practices across the lifecycle. Experience in the application ofstandards including NIST Special Publications (e.g. SP 800-30, 37 & 53). Application of Defence standards including Defstan 05-138 & Defstan 05-139. Experience managing risks and services in accordance with customer More ❯
Easter Howgate, Midlothian, United Kingdom Hybrid / WFH Options
Leonardo UK Ltd
Engineering Role. Leading delivery of MOD accreditation and secure by design processes (ISN2023/09), associated policies and practices across the lifecycle. Experience in the application ofstandards including NIST Special Publications (e.g. SP 800-30, 37 & 53). Application of Defence standards including Defstan 05-138 & Defstan 05-139. Experience managing risks and services in accordance with customer More ❯