1 to 25 of 36 Remote/Hybrid ISO 27001 Lead Implementer Jobs

Senior Security Consultant

Location
City Of London, England, United Kingdom
Define, implement and monitor corporate information security strategies, objectives and governance frameworks. Design and implement information security management systems and security master plans. Lead risk management activities, including risk identification, assessment, treatment and reporting. Define cybersecurity action plans and oversee their execution. Ensure the protection of services … analyses and defining continuity and testing plans. Implement and maintain information security controls aligned with applicable laws, regulations, standards and best practices, including ISO 27001 / 27002, GDPR, Cyber Assessment Framework (CAF) and NIST CSF. Develop and maintain information security policies, standards and procedures ...

Senior Information Security Manager

Hiring Organisation
Ascend Consulting
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 - £65,000 per annum
Senior Information Security Manager to play a pivotal role in their Compliance team. The Reporting to the Head of Compliance, you will lead the ISO 27001-certified information security management system, strengthen processes, and help shape policy. In this role … incidents, and contributing to policy development. The key responsibilities of this role are to oversee information security standards by managing and continually improving ISO 27001-certified Information Security Management System, leading business continuity management for information and technology risks, and supporting the organisation ...

Senior GRC Analyst

Location
Horwich, England, United Kingdom
security risk assessments across projects, systems, and technology changes, identifying risks and recommending practical controls. Support the maintenance and continuous improvement of the ISO 27001-aligned Information Security Management System (ISMS). Review and maintain information security policies, standards, procedures, and control frameworks … equivalent level. Demonstrable experience supporting regulatory, certification, or external security audit readiness, including evidence coordination and remediation management. Hands‐on experience with ISO 27001-aligned Information Security Management Systems and information security policy and control governance. Experience conducting project and technology security risk assessments ...

Cyber Security Controls Tester (Assurance)

Location
City Of London, England, United Kingdom
Evaluate the effectiveness of technical, procedural, and physical security controls against documented security requirements and standards. Assess security controls against recognised frameworks including ISO 27001 , NIST CSF , NIST 800-53 , and CIS Controls . Review security documentation, including High-Level Designs (HLDs), Low-Level … Required Skills & Experience Proven experience testing and assessing the effectiveness of security controls within complex enterprise environments. Strong knowledge of security frameworks including: ISO 27001 NIST Cyber Security Framework (CSF) NIST 800-53 CIS Controls Experience reviewing and testing: Network security controls Firewall configurations ...

Cyber Security Architect & Engineering Lead

Hiring Organisation
Circle Recruitment
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £80,000 per annum
Cyber Security Architect & Engineering Lead Location: London, hybrid Salary: £70,000 - £80,000 Our client is seeking a senior, hands-on Cyber Security Architect & Engineering Lead to strengthen its security architecture and engineering capability. Reporting to the Head of Information Security, this … cloud, SaaS, data, applications and integrations. Design, implement and improve security controls, with a focus on Zero Trust, secure-by-design and automation. Lead security architecture reviews and threat modelling for major projects, technologies and high-risk integrations. Own security initiatives from problem identification and business case ...

Assistant Manager Information Security

Location
Greater London, England, United Kingdom
MAIN DUTIES Information Security & Risk Management Maintain and continuously improve the ISO 27001:2022 ISMS, including the Statement of Applicability, information security policies, standards and procedures, and the supporting documentation register, ensuring they remain current, mapped to control frameworks and audit-ready. Provide proactive … strongly preferred, for example CISM, CISSP, ISO 27001 Lead Implementer / Lead Auditor. Technology‐centric training and certification is an advantage. Experience And Skills 5+ years' experience in information and cyber security implementation, management ...

Information Security Manager - Fintech - Hybrid

Location
City Of London, England, United Kingdom
Programme Maintain and continuously improve the Information Security Management System, firmwide information security programme, security policies, certifications and control framework, aligned to ISO 27001, SOC 2, DORA‐related customer obligations, applicable financial services expectations and Crédit Agricole Group requirements. Partner with Product, Engineering … such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer / Lead Auditor or equivalent experience. Degree in cybersecurity, computer science, risk management or a related discipline, or equivalent practical experience. We believe we offer ...

Principal Security Officer

Location
Reading, England, United Kingdom
delivery of the wider security strategy and improvement plan. Provide leadership, guidance and technical oversight to Information Security Officers within the team. Lead significant security projects and initiatives from assessment and design through to implementation. Own and drive improvements to the organisation's ISMS, security controls … overall cyber maturity . Lead security assessments across infrastructure, networks, endpoints, applications, cloud environments and data. Provide security input into technical architecture and design decisions. Work with technical teams to implement appropriate security controls around identity, access management, SSO and federated services . Oversee information security risk ...

Information Security Officer

Location
Reading, England, United Kingdom
continually improve the organisation's Information Security Management System (ISMS) , including policies, procedures and controls. Support the implementation and ongoing management of ISO 27001, Cyber Essentials Plus, PCI-DSS, NIST / CIS Controls and other relevant security requirements. Conduct security assessments across infrastructure, networks … endpoints, applications and data. Identify, assess and manage information security risks, including maintaining risk registers and tracking remediation. Lead and support internal and external security audits , including evidence gathering, control testing and remediation of findings. Manage technical security risks within Data Protection Impact Assessments and policy exceptions. ...

GRC Engineer

Location
Belfast City District, Northern Ireland, United Kingdom
querying, and control automation. You’ll be a key player in maintaining our compliance posture across frameworks like SOC 2, NIST CSF, and ISO 27001, while also helping modernize how we monitor and evidence controls using platforms like Anecdotes. This role suits someone … preparation for and execution of SOC 2 (Type I / II) audits, working directly with external auditors to scope, evidence, and remediate findings Lead or support NIST CSF assessments and gap analyses, translating results into actionable remediation plans Support alignment and readiness activities for ISO ...

Operational Resilience & Technology Risk Business Partner

Hiring Organisation
Leeds Building Society
Location
Leeds, West Yorkshire, Yorkshire, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£55,000
Resilience framework, assessing whether our approach is practical, evidence-based and aligned with regulatory expectations and the needs of the business. You'll lead thematic and targeted assurance reviews across operational resilience, technology resilience, IT risk and information security. You'll assess the design and effectiveness … facilitation skills, with the curiosity to deepen your expertise across operational resilience, technology resilience and assurance. A relevant qualification such as CISA, ISO 27001 Lead Auditor or ISO 27001 Lead Implementer ...

Senior GRC Content Engineer

Location
Greater London, England, United Kingdom
Security & Compliance Consultant Mandatory GRC skills — you must be able to demonstrate: Practical, implementation‐level experience with ISO / IEC 27001 (2022 control set): scoping, risk assessment and treatment, Statement of Applicability, running or facing internal and certification audits — not just framework literacy … CISA, CRISC, CGRC, ISO / IEC 27001 Lead Implementer / Lead Auditor, CIPP / E are appreciated — practical experience matters more Benefits & Perks 100% Remote – In a fully digital world, work from anywhere ...

Cyber Security Manager

Hiring Organisation
Amtis Professional Ltd
Location
Birmingham, West Midlands (County), United Kingdom
Employment Type
Permanent
Salary
£75000 - £85000/annum 30% Bonus, Private Medical, Company
looking for an experienced Cyber Security Manager to join it's technology function. Reporting to the Head of Information Security, you'll lead the organisation's day-to-day cyber defence and information security capability. You'll protect critical systems, customer data and business operations across … communications and recovery Leading security investigations and overseeing remediation after incidents or identified risks Driving compliance with security policies, standards and regulations, including ISO 27001, Cyber Essentials and PCI-DSS Managing security audits, risk assessments and improvement plans Delivering security reporting, metrics and risk ...

Compliance Officer

Location
Greater London, England, United Kingdom
space and trust to do the job the way they believe is best. This role is perfect for someone who wants to lead and build, not just follow a playbook. Why this role exists As the business scales, the need for structured governance, process integrity, and accountability … culture where compliance is practical, proportionate, and understood across the organisation. What we’re looking for Hands‐on SOC 2 and / or ISO 27001 experience: evidence management, direct auditor engagement. GRC platform experience (Drata, Vanta, or similar). Cloud literacy: comfortable navigating ...

IT Risks & Control Manager

Location
Eastleigh, England, United Kingdom
Risks & Control Manager Lead IT risk and control assessments using recognised frameworks such as ISO / IEC 27001 and NIST-aligned controls. Own and maintain the IT risk register, ensuring risks, controls and treatment plans are accurate … risk management, technology risk or information security risk. Good knowledge of IT control frameworks, particularly ISO / IEC 27001 and NIST-aligned controls. Experience maintaining IT risk registers and working with GRC tools. Confidence facilitating senior stakeholder discussions and governance meetings. Ability ...

IT Risks & Control Manager

Location
Chandler's Ford, England, United Kingdom
teams. Main Responsibilities: Lead IT risk and control assessments using recognised frameworks such as ISO / IEC 27001 and NIST-aligned controls. Own and maintain the IT risk register, ensuring risks, controls and treatment plans are accurate … risk management, technology risk or information security risk. Good knowledge of IT control frameworks, particularly ISO / IEC 27001 and NIST-aligned controls. Experience maintaining IT risk registers and working with GRC tools. Confidence facilitating senior stakeholder discussions and governance meetings. Ability ...

Senior Security Consultant

Hiring Organisation
Akkodis
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
Cyber Security Consultant, Information Security Strong client-facing and stakeholder management skills Experience working with recognised security frameworks and standards, including: ISO 27001, NISTCyber Security Framework (CSF), CIS Controls, Cloud Security Controls, Secure by Design principles The ability to balance security best practice with … commercial realities Someone who is naturally curious, proactive and enjoys solving problems Desirable Certifications CISSP CISM CCSP ISO 27001 Lead Implementer or Lead Auditor Please note that applicants must have the right to work ...

AI Security Consultant

Location
Manchester, England, United Kingdom
assurance. Familiarity with frameworks and guidance such as NIST AI RMF, OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, MITRE ATLAS, ISO 27001, NIST CSF, CIS Controls or cloud security frameworks. Experience with SOC operations, SIEM / SOAR platforms, detection engineering, threat … autonomous systems, including least privilege, approval workflows, action limits, logging, monitoring and rollback mechanisms. Relevant certifications such as CISSP, CISM, CCSP, GIAC, ISO 27001 Lead Implementer / Auditor, cloud security certifications or AI / security-focused training. Please ...

AI Security Consultant

Location
City of Westminster, England, United Kingdom
assurance. Familiarity with frameworks and guidance such as NIST AI RMF, OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, MITRE ATLAS, ISO 27001, NIST CSF, CIS Controls or cloud security frameworks. Experience with SOC operations, SIEM / SOAR platforms, detection engineering, threat … autonomous systems, including least privilege, approval workflows, action limits, logging, monitoring and rollback mechanisms. Relevant certifications such as CISSP, CISM, CCSP, GIAC, ISO 27001 Lead Implementer / Auditor, cloud security certifications or AI / security-focused training. Please ...

AI Security Consultant

Hiring Organisation
PA Consulting
Location
Pimlico, Hertfordshire, UK
Employment Type
Full-time
assurance. Familiarity with frameworks and guidance such as NIST AI RMF, OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, MITRE ATLAS, ISO 27001, NIST CSF, CIS Controls or cloud security frameworks. Experience with SOC operations, SIEM / SOAR platforms, detection engineering, threat … autonomous systems, including least privilege, approval workflows, action limits, logging, monitoring and rollback mechanisms. Relevant certifications such as CISSP, CISM, CCSP, GIAC, ISO 27001 Lead Implementer / Auditor, cloud security certifications or AI / security-focused training. Please ...

Senior Cyber Security Consultant (Defence)

Location
United Kingdom
remediation strategies and residual risks to stakeholders. Supporting governance, risk and compliance activities within secure and regulated environments. Depending on experience, you may: Lead consultancy engagements and workstreams. Mentor and support the development of colleagues. Act as a trusted adviser to senior client stakeholders. Contribute to business … controls. Understanding of Defence procurement and capability delivery programmes. Beneficial Knowledge Government and industry security frameworks such as HMG Security Policy Framework (SPF), ISO 27001 and NIST. Risk management methodologies and security assurance frameworks. Enterprise and security architecture approaches including TOGAF and SABSA. Cloud ...

Senior Cyber Security Consultant (Defence)

Location
Cheltenham, England, United Kingdom
remediation strategies and residual risks to stakeholders. Supporting governance, risk and compliance activities within secure and regulated environments. Depending on experience, you may: Lead consultancy engagements and workstreams. Mentor and support the development of colleagues. Act as a trusted adviser to senior client stakeholders. Contribute to business … controls. Understanding of Defence procurement and capability delivery programmes. Beneficial Knowledge Government and industry security frameworks such as HMG Security Policy Framework (SPF), ISO 27001 and NIST. Risk management methodologies and security assurance frameworks. Enterprise and security architecture approaches including TOGAF and SABSA. Cloud ...

Senior Cyber Security Consultant

Hiring Organisation
Hackajob Ltd
Location
Guildford, Surrey, South East, United Kingdom
Employment Type
Permanent, Work From Home
remediation strategies and residual risks to stakeholders. Supporting governance, risk and compliance activities within secure and regulated environments. Depending on experience, you may: Lead consultancy engagements and workstreams. Mentor and support the development of colleagues. Act as a trusted adviser to senior client stakeholders. Contribute to business … controls. Understanding of Defence procurement and capability delivery programmes. Beneficial Knowledge Government and industry security frameworks such as HMG Security Policy Framework (SPF), ISO 27001 and NIST. Risk management methodologies and security assurance frameworks. Enterprise and security architecture approaches including TOGAF and SABSA. Cloud ...

Security Consultant – Risk & Resilience - Financial Services

Location
Greater London, England, United Kingdom
cyber risk management, operational resilience, business continuity, disaster recovery, and incident response principles. Knowledge of common security and risk frameworks such as NIST, ISO 27001, COBIT, CIS Controls, and FFIEC guidance. Familiarity with financial services regulatory requirements relating to technology risk and resilience. Experience … enabled tools to improve efficiency, insight generation, or risk management outcomes. Preferred Qualifications Professional certifications such as CISSP, CISM, CRISC, CISA, CBCI, ISO 27001 Lead Implementer / Auditor, or equivalent. Experience supporting regulatory programmes involving PRA, FCA, DORA ...

Security Consultant - Risk & Resilience - Financial Services

Hiring Organisation
Accenture
Location
London, UK
Employment Type
Full-time
cyber risk management, operational resilience, business continuity, disaster recovery, and incident response principles. Knowledge of common security and risk frameworks such as NIST, ISO 27001, COBIT, CIS Controls, and FFIEC guidance. Familiarity with financial services regulatory requirements relating to technology risk and resilience. Experience … enabled tools to improve efficiency, insight generation, or risk management outcomes. Preferred Qualifications: Professional certifications such as CISSP, CISM, CRISC, CISA, CBCI, ISO 27001 Lead Implementer / Auditor, or equivalent. Experience supporting regulatory programmes involving PRA, FCA, DORA ...