within a UK-regulated environment. Expertise in cyber, operational resilience, technology, payments, and/or third-party risk management. Knowledge of best practice and industry-mandated frameworks, such as NIST, ITIL, COBIT, ISO, SWIFT CSP, and UK domestic payment scheme rules. Proficiency working with and interpreting data using SQL, SAS, Python, or R. Knowledge of IIA standards. A desire andMore ❯
London, England, United Kingdom Hybrid / WFH Options
Bridewell Consulting Limited
the UK delivering and leading a range of data privacy projects. This could cover implementation of Data Privacy Frameworks aligned to legal requirements andstandards, such as ISO27701 andNIST Privacy Risk Assessment Methodology. With Bridewell continuing to grow, you’ll build and manage a high performing team of Senior Consultants, Consultants and Junior Consultants, and Quality Assure other consultants More ❯
London, England, United Kingdom Hybrid / WFH Options
PA Consulting
You enjoy collaborating with multiple stakeholders in a fast-paced environment Experience with enterprise architecture frameworks such as TOGAF or similar. Knowledge of security frameworks and compliance standards (ISO, NIST, etc.). Experience with Agile methodologies and working in DevOps environments. Apply today by completing our online application Additional Information Please note that the interview stages may be subject to More ❯
Farnborough, England, United Kingdom Hybrid / WFH Options
Copello Global
Security and Cyber Security skills with knowledge of: Cloud Security (AWS) Experience in Vulnerability Assessments and Incident Management, Implementation of security controls, UK Information Security standards (eg. MoD, NCSC, NIST), Excellent communication skills, Clearance UK Security Clearance is essential to start. Apply To apply, follow the instructions on this page, send an updated CV to myles@copello.co.uk referencing the role More ❯
Chantilly, Virginia, United States Hybrid / WFH Options
RogueThink Inc
and system hardening. Preferred Qualifications: • Certifications such as: CompTIA Security+, CySA+, Certified Kubernetes Administrator (CKA), AWS/Azure Security Specialty, Certified DevSecOps Professional. • Experience with Zero Trust Architecture or NIST 800-53 compliance frameworks. • Familiarity with version control systems like Git and artifact repositories (e.g., Nexus, Artifactory). • Ansible experience is a plus. Benefits: At RogueThink, we offer competitive compensation More ❯
London, England, United Kingdom Hybrid / WFH Options
Sanderson Government & Defence
endpoint protection, and incident response, within a highly secure environment. Role Overview: This is a hands-on engineering role requiring the delivery of endpoint security engineering activities aligned to NIST controls and the reduction of security vulnerabilities across infrastructure and products. You will be working as part of a dedicated security function within a government-aligned environment. Initial onboarding will … due to the nature of the initial project, cannot be dual national . What we're looking for: Strong understanding of modern endpoint security and hardening practices Familiarity with NIST security controls and vulnerability management processes Practical experience with tools such as Ivanti, Trellix, SonarQube, Nessus, or Trivvy Comfortable working within Agile or Scrum environments Excellent written and verbal communication … security policies Support the resolution of security incidents and service tickets Conduct triage and root cause analysis; assist in restoring normal service Ensure systems comply with CIS, STIG, andNIST frameworks Maintain and update group policy objects and apply security patches Change Management Conduct security triage on planned infrastructure changes Participate in planning and review meetings to ensure compliance Documentation More ❯
City Of Bristol, England, United Kingdom Hybrid / WFH Options
Matchtech
sharing across teams. What We’re Looking For Technical Experience & Knowledge Experience with risk management frameworks and methodologies such as ISO/IEC 27001/2, ISO27005/31000, NIST 800-30, NIST 800-53. Strong understanding of security standardsand frameworks including OWASP, Secure by Design principles, and MOD-specific guidelines (e.g., JSP, Def Stan 05-138/… . Familiarity with HMG security principles and assurance frameworks is advantageous. Comfortable using threat modelling tools and implementing mitigation strategies. Experience with NIST standards. (this is an absolute must) Key Competencies Strong communicator with the ability to present complex information clearly and confidently. Proactive problem solver who approaches challenges with innovation and critical thinking. Highly organised with a methodical approach More ❯
to work in the UK; willing to undergo DBS and Counter Terrorist Check. Desirable Skills: Certifications such as CISSP, or other relevant qualifications. Experience with additional frameworks (e.g., SOC2, NIST, NCSC CAF). More than 2 years' experience delivering IT or cybersecurity solutions. Benefits: 30 days annual leave + 8 bank holidays Additional day off for your birthday 3% employer More ❯
London, England, United Kingdom Hybrid / WFH Options
Hamilton Barnes Associates Limited
to work in the UK; willing to undergo DBS and Counter Terrorist Check. Desirable Skills: Certifications such as CISSP, or other relevant qualifications. Experience with additional frameworks (e.g., SOC2, NIST, NCSC CAF). More than 2 years’ experience delivering IT or cybersecurity solutions. Benefits: 30 days annual leave + 8 bank holidays Additional day off for your birthday 3% employer More ❯
Scott Air Force Base, Illinois, United States Hybrid / WFH Options
CEdge Software Consultants
tools including ACAS and eMASS Experience reviewing and applying STIGs Experience using security scanning tools including Fortify and Nessus Experience using log analysis tools such as Splunk Understanding ofNIST RMF monitoring and controls Understanding of system ATO artifacts Data and mathematical analysis skills Vulnerability and risk analysis experience Remedy ticketing system Active Secret Clearance is required An Interim Secret More ❯
London, England, United Kingdom Hybrid / WFH Options
Bruin Financial
closure with relevant stakeholders. Requirements: Minimum of 5 years in IT Audit, preferably within Financial Services. A relevant Professional qualification in Audit or Cyber Security Knowledge of cybersecurity frameworks (NIST CSF/ISO 27001) and cloud security best practices (AWS, Azure, etc.). Excellent communication skills, both written and verbally, with a diverse range of stakeholders. Strong time management andMore ❯
Crawley, England, United Kingdom Hybrid / WFH Options
Virgin holidays
Job Details Salary: Competitive per annum Hours: Full Time, 37.5 hours Location: VHQ, Crawley, hybrid 3 days a week in the office Contract: Permanent Closing Date: 3rd July 2025 At Virgin Atlantic Airways, we believe that everyone can take on More ❯
London, England, United Kingdom Hybrid / WFH Options
Daintta
security controls within cloud-based infrastructure (e.g Azure, AWS, GCP). This may include design, configuration, or protective monitoring. You have experience working with security control frameworks e.g. ISO27001, NIST, CAF or others. You have demonstrable continuous personal development with relevant certifications and accreditations. You have strong interpersonal skills You have UK security clearance at SC or above or are More ❯
Burton Latimer, Northamptonshire, United Kingdom Hybrid / WFH Options
Weetabix Food Company
OT) environments Experience with the following products and technologies: Microsoft Sentinel or similar SIEM and SOAR tools, KQL, Next-gen email defense platforms Knowledge of security frameworks such as NIST, ISO 27001 Your Bowl of Perks (Benefits) Competitive salary & Annual Flexible benefits We offer a competitive salary and a comprehensive benefits package designed to support your wellbeing, career, and life More ❯
Kettering, Northamptonshire, East Midlands, United Kingdom Hybrid / WFH Options
WEETABIX LIMITED
OT) environments Experience with the following products and technologies: Microsoft Sentinel or similar SIEM and SOAR tools, KQL, Next-gen email defense platforms Knowledge of security frameworks such as NIST, ISO 27001 Your Bowl of Perks (Benefits) Competitive salary & Annual Flexible benefits We offer a competitive salary and a comprehensive benefits package designed to support your wellbeing, career, and life More ❯
London, England, United Kingdom Hybrid / WFH Options
Bridewell Consulting Limited
ll be doing Work would include the delivery of client engagements to a high level, implementing Data Privacy frameworks aligned to legal requirements andstandards, such as ISO27701 andNIST Privacy Risk Assessment Methodology. You’ll work with the leadership and sales team to respond to tenders and provide pre-sales support, whilst also quality assuring other consultants' work andMore ❯
Leeds, West Yorkshire, Yorkshire, United Kingdom Hybrid / WFH Options
4it Recruitment Limited
Security Lead - Leeds (Hybrid, 2 days per month in the office) Overview: Are you an experienced Risk & Security professional with a solid understanding of security frameworks such as ISO27001, NIST, and risk assurance? We are looking for a pragmatic and proactive Risk & Security Lead to join a forward-thinking organisation based in Leeds. In this key role, you will be … be in the office 2 separate days per month. Key Responsibilities: Lead and enhance the organisation's risk and security framework, ensuring alignment with best practices such as ISO27001, NIST, and other relevant standards. Provide risk assurance by identifying, assessing, and mitigating security risks across the business. Develop and implement effective risk management strategies, ensuring a balance of robust controls … guidance and training on risk and security best practices to stakeholders across the business. Key Requirements: Proven experience in a Risk & Security role with hands-on knowledge of ISO27001, NIST, and other security frameworks. Strong understanding of risk management principles and the ability to apply them pragmatically within an organisation. Experience in supporting and managing external audits, ensuring compliance andMore ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Goodman Masson
For: Experience in IT security or within a SOC/NOC environment Strong knowledge of Microsoft Defender, EDR, and network architecture Understanding of security frameworks (e.g., MITRE ATT&CK, NIST, ISO 27001) Excellent communication and teamwork skills Relevant certifications (e.g., Sec+, OSCP, CISA) are a plus More ❯
London, England, United Kingdom Hybrid / WFH Options
Sanderson Government & Defence
government-backed financial services environment. This includes the creation of a fit-for-purpose Information Security Management System (ISMS) aligned with ISO27001, while also integrating requirements and controls from NIST, PRISMA, and COBIT. Responsibilities:ISMS Development:Multi-Framework IntegrationControl Mapping & HarmonisationStakeholder EngagementAudit & Assurance Key Requirements:Strong experience in designing and implementing ISO27001-compliant ISMS, ideally in greenfield or transformation environments.Proven … ability to integrate multiple assurance frameworks (ISO27001, NIST, COBIT, PRISMA) in a coherent and auditable manner.Experience working within or delivering into UK public sector, financial services, or other high-assurance environments.Excellent documentation and communication skills, capable of translating security requirements for technical and non-technical audiences. Eligibility:To be considered for the role, you must have active SC Clearance OR More ❯
London, England, United Kingdom Hybrid / WFH Options
McNally Recruitment Ltd
of processing, storing, or transmitting information to reduce or eliminate impact, integrity, or availability of information and information systems. Experience conducting security and risk assessments using security frameworks (e.g., NIST, RMF, Common Criteria). Excellent communication skills , both written and verbal, with the ability to communicate complex security concepts to technical and non-technical audiences. Ability to adapt to changing … the latest security trends and best practices. Preferred Skills and Experience Past experience in assisting stakeholders in quantifying risks and developing mitigation and remediation strategies. Understanding and application ofNIST Control Framework, Critical Security Controls, and other related regulatory and compliance frameworks. Experience with cloud security, cyber resiliency/incident management, Zero Trust, network/EDGE security, and emerging technologies More ❯
London, England, United Kingdom Hybrid / WFH Options
Spotify
significant experience and a strong interest in effective security incident management, including leading response efforts, process development and automation. You have a shown understanding of incident response frameworks (e.g. NIST, SANS) and standard processes. You have a passion for automation, and the ability to effectively build tooling that combines automated response actions with human judgement You have the skills to More ❯
teams to ensure a coordinated incident management approach. Who You Are Experienced in security incident management, including leading responses, developing processes, and automation. Knowledgeable of incident response frameworks like NISTand SANS. Passionate about automation and skilled in building tools that combine automated responses with human judgment. Capable of developing automation tools, with a broad understanding of cloud and endpoint More ❯
/continuous deployment (CI/CD) tools, and leveraging automation platforms such as Ansible or Azure Functions Understanding of Federal Government application, server, and network security requirements such as NIST, FedRAMP, and FISMA Ability to work effectively within a distributed technical team, aided by strong written and verbal communication skills Familiarity with the Atlassian suite, including Jira and Confluence Current More ❯
Oxford, England, United Kingdom Hybrid / WFH Options
University of Oxford
responsible for safeguarding the university's digital assets while enabling its strategic objectives. Within this structure, the Operations team focuses on the Protect, Detect, and Respond functions of the NIST Cybersecurity Framework. What We Offer Working at the University of Oxford offers several exclusive benefits, such as: 38 days of annual leave (inclusive of public holidays) to support your wellbeing More ❯
London, England, United Kingdom Hybrid / WFH Options
Vantage Data Centers
people manager role. Strong understanding of cybersecurity frameworks for ICS/OT environments Strong understanding of OT network communication protocols and industrial networking topologies. Familiarity with NIST (NationalInstituteofStandardsandTechnology) Special Publication 800-61 Revision 2, Computer Security Incident Handling Guide. Familiarity with NIST (NationalInstituteofStandardsandTechnology) Special Publication 800-82 Comprehensive knowledge of … MITRE ATT&CKS for ICS or NERC CIP (North American Electric Reliability Corporation Critical Infrastructure Plan) frameworks Understanding of general cybersecurity frameworks (ISO IEC 27001/27002, ISO 15408, NIST Cybersecurity Framework (CSF), NIST SP800-53), and Guide to Industrial Control Systems (ICS) Security (NIST SP800-82) A working knowledge of industrial control systems (e.g., Distributed Control System (DCS), Programmable More ❯