security (AWS/Azure/GCP) and IoT or medical device environments (Desirable) Familiarity with Microsoft Intune, Sentinel , or similar endpoint management/security tools Awareness of ISO 27001, NIST CSF, NIS2 , or similar compliance frameworks Key Responsibilities Service Delivery Implement, configure, and optimise security solutions including Cylera, Horizon3.ai, Halcyon , and others Support Third-Party Risk Management and Security Assurance … NSE , or CompTIA Security+ (advantageous) Demonstrable experience delivering Cyber services in: Threat & Vulnerability Management Penetration Testing/Offensive Security SOC/MDR operations Third-Party Risk or Compliance (ISO, NIST, GDPR) Additional Information Must have the right to live and work in the UK Full UK driving licence and access to transport Willingness to travel to client sites across the More ❯
IT Security Consultant - 12 months up to £850 Per Day Inside IR35 About People’s Partnership At the heart of our not-for-profit organisation is a commitment and a motivation to make the future-saving experience a simple one More ❯
Winchester, Hampshire, United Kingdom Hybrid / WFH Options
Arqiva
risks and the ability to oversee the implementation of appropriate controls, assurance mechanisms, and reporting frameworks. Cyber Governance & Advisory - Expertise in leading the adoption of industry cyber frameworks (e.g., NIST, ISO) and providing high-level advisory to boards, executives, and stakeholders on emerging threats and compliance posture. Incident Oversight & Resilience - Executive capability to govern cyber incident response strategies, ensuring the … and regulatory alignment. Knowledge & Experience Deep understanding of enterprise risk management (ERM), governance, and control frameworks In-depth knowledge of security, information assurance, and compliance frameworks (e.g., ISO 27001, NIST CSF, COBIT). Familiarity with legal and regulatory requirements across cyber and operational domains (e.g., GDPR, NIS2, TSA, CSR). Awareness of internal audit methodology, assurance planning, and reporting mechanisms. More ❯
Cambridge, England, United Kingdom Hybrid / WFH Options
Hays
security risks. Support AI and automation initiatives to streamline GRC processes. Key Requirements Proven hands-on experience with ServiceNow IRM and risk quantification methodologies. Strong knowledge of ISO 27001, NIST CSF, andNIST SP800-53. Certifications such as CRISC, CISM, CISSP, or FAIR are desirable. Excellent stakeholder management and communication skills. Experience in third-party cyber risk management and post More ❯
cambridge, east anglia, united kingdom Hybrid / WFH Options
Hays
security risks. Support AI and automation initiatives to streamline GRC processes. Key Requirements Proven hands-on experience with ServiceNow IRM and risk quantification methodologies. Strong knowledge of ISO 27001, NIST CSF, andNIST SP800-53. Certifications such as CRISC, CISM, CISSP, or FAIR are desirable. Excellent stakeholder management and communication skills. Experience in third-party cyber risk management and post More ❯
newport, wales, united kingdom Hybrid / WFH Options
Matchtech
up. Key Responsibilities: Identify and integrate security requirements throughout the product and system development lifecycle. Lead threat modelling and risk assessments, applying frameworks such as ISO/IEC 27001, NIST 800-30/53, and ISO 31000. Advise on secure architectures and develop strategies to mitigate identified information risks. Collaborate with multi-disciplinary teams to ensure compliance with MOD and … the Defence, Aerospace, or National Security sectors. Deep understanding of HMG Security Policy Framework and MOD-specific standards. Familiarity with risk management methodologies (ISO 27001/2, ISO 27005, NIST frameworks). Strong analytical and problem-solving abilities — able to assess complex data and provide actionable insights. A collaborative communicator who can balance technical assurance with business priorities. Ability to More ❯
Greater Bristol Area, United Kingdom Hybrid / WFH Options
Matchtech
up. Key Responsibilities: Identify and integrate security requirements throughout the product and system development lifecycle. Lead threat modelling and risk assessments, applying frameworks such as ISO/IEC 27001, NIST 800-30/53, and ISO 31000. Advise on secure architectures and develop strategies to mitigate identified information risks. Collaborate with multi-disciplinary teams to ensure compliance with MOD and … the Defence, Aerospace, or National Security sectors. Deep understanding of HMG Security Policy Framework and MOD-specific standards. Familiarity with risk management methodologies (ISO 27001/2, ISO 27005, NIST frameworks). Strong analytical and problem-solving abilities — able to assess complex data and provide actionable insights. A collaborative communicator who can balance technical assurance with business priorities. Ability to More ❯
bath, south west england, united kingdom Hybrid / WFH Options
Matchtech
up. Key Responsibilities: Identify and integrate security requirements throughout the product and system development lifecycle. Lead threat modelling and risk assessments, applying frameworks such as ISO/IEC 27001, NIST 800-30/53, and ISO 31000. Advise on secure architectures and develop strategies to mitigate identified information risks. Collaborate with multi-disciplinary teams to ensure compliance with MOD and … the Defence, Aerospace, or National Security sectors. Deep understanding of HMG Security Policy Framework and MOD-specific standards. Familiarity with risk management methodologies (ISO 27001/2, ISO 27005, NIST frameworks). Strong analytical and problem-solving abilities — able to assess complex data and provide actionable insights. A collaborative communicator who can balance technical assurance with business priorities. Ability to More ❯
bradley stoke, south west england, united kingdom Hybrid / WFH Options
Matchtech
up. Key Responsibilities: Identify and integrate security requirements throughout the product and system development lifecycle. Lead threat modelling and risk assessments, applying frameworks such as ISO/IEC 27001, NIST 800-30/53, and ISO 31000. Advise on secure architectures and develop strategies to mitigate identified information risks. Collaborate with multi-disciplinary teams to ensure compliance with MOD and … the Defence, Aerospace, or National Security sectors. Deep understanding of HMG Security Policy Framework and MOD-specific standards. Familiarity with risk management methodologies (ISO 27001/2, ISO 27005, NIST frameworks). Strong analytical and problem-solving abilities — able to assess complex data and provide actionable insights. A collaborative communicator who can balance technical assurance with business priorities. Ability to More ❯
Portsmouth, England, United Kingdom Hybrid / WFH Options
Franklin Fitch
and professional certification documentation. Develop and maintain customer-facing assurance materials that demonstrate a strong security posture. Regulatory & Framework Alignment Monitor changes in global cybersecurity regulations andstandards (e.g. NIST CSF , NCSC , NIS2 , GDPR ). Ensure SOC assurance aligns with evolving regulatory and industry expectations. Advise senior leadership on how emerging regulations impact assurance strategy. Continuous Improvement & Reporting Drive efficiency … . Solid understanding of SOC operations and security assurance frameworks . Experience managing customer-facing assurance activities, including audits, RFIs, and RFPs. Knowledge of regulatory and industry frameworks including NIST CSF , GDPR , and UK NCSC guidance . Comfortable working with external auditors , certification bodies , and regulators . Key Skills Strong documentation, compliance, and evidence management skills. Excellent communicator with the More ❯
Portsmouth, England, United Kingdom Hybrid / WFH Options
Cloud People
Supporting incident response and remediation activities related to cloud environments • Collaborating with SOC and Engineering teams to strengthen detection, telemetry and visibility • Providing compliance guidance aligned to ISO 27001, NIST, Cyber Essentials Plus and NHS DSPT • Mentoring junior consultants and contributing to the development of cloud security methodologies What You’ll Bring • 4 or more years of experience in cloud … IAM, networking, encryption, monitoring and incident response in cloud environments • Familiarity with Microsoft Defender for Cloud, AWS Security Hub, GuardDuty and other native tools • Experience applying frameworks such as NIST, CIS Benchmarks, ISO 27001 and CSA CCM • Excellent stakeholder engagement and communication skills with the ability to bridge technical and business needs • Experience supporting clients in regulated industries such as More ❯
Portsmouth, yorkshire and the humber, united kingdom Hybrid / WFH Options
Cloud People
Supporting incident response and remediation activities related to cloud environments • Collaborating with SOC and Engineering teams to strengthen detection, telemetry and visibility • Providing compliance guidance aligned to ISO 27001, NIST, Cyber Essentials Plus and NHS DSPT • Mentoring junior consultants and contributing to the development of cloud security methodologies What You’ll Bring • 4 or more years of experience in cloud … IAM, networking, encryption, monitoring and incident response in cloud environments • Familiarity with Microsoft Defender for Cloud, AWS Security Hub, GuardDuty and other native tools • Experience applying frameworks such as NIST, CIS Benchmarks, ISO 27001 and CSA CCM • Excellent stakeholder engagement and communication skills with the ability to bridge technical and business needs • Experience supporting clients in regulated industries such as More ❯
Reading, Berkshire, England, United Kingdom Hybrid / WFH Options
Certain Advantage
is a hands-on consulting position delivering Governance, Risk and Compliance (GRC) projects for major enterprise clients — including risk management, cloud security governance, and compliance frameworks such as ISO27001, NIST CSF, CIS Top 18 and COBIT .You’ll play a key role in engaging with senior stakeholders, assessing cyber maturity, and driving best-practice improvements across a range of industries. … levels. Skills & Experience Required 4+ years’ experience in a professional consulting role, ideally within enterprise IT security, governance, or risk management. Proven delivery experience using frameworks such as ISO27001, NIST CSF, CIS, COBIT , or equivalent. Strong client-facing skills, with the ability to communicate technical concepts to non-technical audiences. Relevant industry certifications such as CISSP, CISA, CRISC, CISM, or More ❯
Aberdeen, City of Aberdeen, United Kingdom Hybrid / WFH Options
Orion Group
structured IT and information security risk assessments and threat modelling for new IT platforms, systems, and applications and for material changes. Provide security architecture advice (patterns, guardrails) aligned to NIST CSF/ISO 27001 and company standards. Define and agree control selection (prevent/detect/correct) proportionate to risk, including identity, data and platform controls. Conduct IT control walkthroughs … approach. Role Requirements 7+ years in information risk, security assurance or IT audit within regulated, safety-critical or industrial environments (energy/oil & gas preferred). Strong knowledge ofNIST CSF, ISO 27001, UK GDPR and supplier assurance practices; familiarity with the UK CAF is desirable. Proven experience running compliance and assurance functions, Secure-by-Design reviews, and control testing More ❯
market and enterprise clients. Design and implement security and compliance solutions across Microsoft 365 and hybrid cloud platforms. Conduct risk assessments and lead mitigation planning aligned to ISO 27001, NIST CSF, and other frameworks. Lead technical workshops and deliver board-level briefings to both technical and non-technical stakeholders. Support clients with audit readiness and regulatory alignment (e.g., GDPR, NIS2 … Experience : 7+ years in cybersecurity, including at least 3 in an advisory or architecture role within an MSP, reseller, or channel partner. Framework Fluency : Proven knowledge of ISO 27001, NIST CSF, GDPR, and other regulatory/compliance standards. Cloud & Security Architecture : Deep expertise in Microsoft security (M365, Sentinel, Defender), as well as hybrid and multi-cloud security. Communication : Excellent at More ❯
information security compliance program.You will be responsible for ensuring that all corporate and subsidiary operations comply with internal security policies, regulatory requirements, and internationally recognised frameworks such as ISO27001, NIST, SOX, GDPR, CMMC, amongst others. Key Responsibilities: Support the execution and enhancement of the global information security compliance program. Conduct internal audits, third-party risk assessments, and due diligence reviews. … Ensure alignment with regulatory and industry standards including ISO27001, NIST, SOX, GDPR, SOC 2, HIPAA, CCPA, LGPD. Collaborate with cross-functional teams across multiple jurisdictions to drive compliance initiatives. Identify gaps in security controls and recommend corrective actions. Maintain and update security policies, procedures, and documentation. Monitor changes in global regulations and assess their impact on business operations. Minimum of … Required: Proven experience in information security compliance, risk management, and audit. Strong understanding of international regulatory frameworks and standards. Hands-on experience with: ISO27001 audits and implementation GDPR compliance NIST cybersecurity framework SOX, SOC 2, HIPAA, CCPA, LGPD Ability to interpret complex regulatory requirements and translate them into actionable controls. Excellent communication and stakeholder engagement skills. Strong analytical and problem More ❯
Birmingham, West Midlands, United Kingdom Hybrid / WFH Options
Hays
information security compliance program.You will be responsible for ensuring that all corporate and subsidiary operations comply with internal security policies, regulatory requirements, and internationally recognised frameworks such as ISO27001, NIST, SOX, GDPR, CMMC, amongst others. Key Responsibilities: Support the execution and enhancement of the global information security compliance program. Conduct internal audits, third-party risk assessments, and due diligence reviews. … Ensure alignment with regulatory and industry standards including ISO27001, NIST, SOX, GDPR, SOC 2, HIPAA, CCPA, LGPD. Collaborate with cross-functional teams across multiple jurisdictions to drive compliance initiatives. Identify gaps in security controls and recommend corrective actions. Maintain and update security policies, procedures, and documentation. Monitor changes in global regulations and assess their impact on business operations. Minimum of … Required: Proven experience in information security compliance, risk management, and audit. Strong understanding of international regulatory frameworks and standards. Hands-on experience with: ISO27001 audits and implementation GDPR compliance NIST cybersecurity framework SOX, SOC 2, HIPAA, CCPA, LGPD Ability to interpret complex regulatory requirements and translate them into actionable controls. Excellent communication and stakeholder engagement skills. Strong analytical and problem More ❯
remediation planning for cloud related threats Collaborating with SOC and Engineering teams to align logging, identity and detection controls Advising on compliance and regulatory frameworks such as ISO 27001, NIST, Cyber Essentials Plus and NHS DSPT Contributing to the development of advisory frameworks, templates and best practices Mentoring junior consultants and sharing knowledge across the wider cyber team What Youll … encryption, monitoring and incident response in cloud environments Familiarity with cloud native tools such as Microsoft Defender for Cloud, AWS Security Hub and GuardDuty Knowledge of security frameworks including NIST, CIS Benchmarks, ISO 27001 and CSA CCM Excellent communication, presentation and stakeholder engagement skills Experience working in regulated sectors such as Healthcare, Finance or Public Sector Strong understanding of hybrid More ❯
remediation planning for cloud related threats • Collaborating with SOC and Engineering teams to align logging, identity and detection controls • Advising on compliance and regulatory frameworks such as ISO 27001, NIST, Cyber Essentials Plus and NHS DSPT • Contributing to the development of advisory frameworks, templates and best practices • Mentoring junior consultants and sharing knowledge across the wider cyber team What You … encryption, monitoring and incident response in cloud environments • Familiarity with cloud native tools such as Microsoft Defender for Cloud, AWS Security Hub and GuardDuty • Knowledge of security frameworks including NIST, CIS Benchmarks, ISO 27001 and CSA CCM • Excellent communication, presentation and stakeholder engagement skills • Experience working in regulated sectors such as Healthcare, Finance or Public Sector • Strong understanding of hybrid More ❯
Belfast, Northern Ireland, United Kingdom Hybrid / WFH Options
Hamilton Barnes 🌳
Security Architect - Belfast (Hybrid, Outside IR35) - £500 per day - 3 Months We are seeking an experienced Security Architect to design, implement, and maintain secure architectures across enterprise systems and networks. This role requires deep technical expertise in cybersecurity design principles More ❯
lisburn, antrim, united kingdom Hybrid / WFH Options
Hamilton Barnes 🌳
Security Architect - Belfast (Hybrid, Outside IR35) - £500 per day - 3 Months We are seeking an experienced Security Architect to design, implement, and maintain secure architectures across enterprise systems and networks. This role requires deep technical expertise in cybersecurity design principles More ❯
newtownabbey, antrim, united kingdom Hybrid / WFH Options
Hamilton Barnes 🌳
Security Architect - Belfast (Hybrid, Outside IR35) - £500 per day - 3 Months We are seeking an experienced Security Architect to design, implement, and maintain secure architectures across enterprise systems and networks. This role requires deep technical expertise in cybersecurity design principles More ❯
City of London, London, United Kingdom Hybrid / WFH Options
TalentHawk
AD, Okta, and SailPoint for OT environments. Apply Zero Trust principles and industry-standard security framework controls to IAM processes. Compliance & Security: Ensure IAM solutions adhere to CAF, eCAF, NIST, and other regulatory frameworks. Conduct access audits, identity risk assessments, and compliance reporting. Work closely with cybersecurity, risk, and compliance teams to align IAM strategies with regulatory requirements. Collaboration & Documentation … IdentityIQ – access reviews, lifecycle automation, compliance workflows, and enterprise application integration. Privileged Access Management: CyberArk – Vault administration, credential rotation, JIT access, session monitoring, compliance reporting. Security & Compliance: CAF, eCAF, NIST frameworks; IAM controls for critical infrastructure; incident response and threat detection. Preferred Certifications: Microsoft Certified: Identity and Access Administrator Associate Okta Certified Administrator/Professional SailPoint IdentityNow/IdentityIQ Engineer More ❯
london (city of london), south east england, united kingdom Hybrid / WFH Options
TalentHawk
AD, Okta, and SailPoint for OT environments. Apply Zero Trust principles and industry-standard security framework controls to IAM processes. Compliance & Security: Ensure IAM solutions adhere to CAF, eCAF, NIST, and other regulatory frameworks. Conduct access audits, identity risk assessments, and compliance reporting. Work closely with cybersecurity, risk, and compliance teams to align IAM strategies with regulatory requirements. Collaboration & Documentation … IdentityIQ – access reviews, lifecycle automation, compliance workflows, and enterprise application integration. Privileged Access Management: CyberArk – Vault administration, credential rotation, JIT access, session monitoring, compliance reporting. Security & Compliance: CAF, eCAF, NIST frameworks; IAM controls for critical infrastructure; incident response and threat detection. Preferred Certifications: Microsoft Certified: Identity and Access Administrator Associate Okta Certified Administrator/Professional SailPoint IdentityNow/IdentityIQ Engineer More ❯
AD, Okta, and SailPoint for OT environments. Apply Zero Trust principles and industry-standard security framework controls to IAM processes. Compliance & Security: Ensure IAM solutions adhere to CAF, eCAF, NIST, and other regulatory frameworks. Conduct access audits, identity risk assessments, and compliance reporting. Work closely with cybersecurity, risk, and compliance teams to align IAM strategies with regulatory requirements. Collaboration & Documentation … IdentityIQ – access reviews, lifecycle automation, compliance workflows, and enterprise application integration. Privileged Access Management: CyberArk – Vault administration, credential rotation, JIT access, session monitoring, compliance reporting. Security & Compliance: CAF, eCAF, NIST frameworks; IAM controls for critical infrastructure; incident response and threat detection. Preferred Certifications: Microsoft Certified: Identity and Access Administrator Associate Okta Certified Administrator/Professional SailPoint IdentityNow/IdentityIQ Engineer More ❯