teams to ensure a coordinated incident management approach. Who You Are Experienced in security incident management, including leading responses, developing processes, and automation. Knowledgeable of incident response frameworks like NISTand SANS. Passionate about automation and skilled in building tools that combine automated responses with human judgment. Capable of developing automation tools, with a broad understanding of cloud and endpoint More ❯
/continuous deployment (CI/CD) tools, and leveraging automation platforms such as Ansible or Azure Functions Understanding of Federal Government application, server, and network security requirements such as NIST, FedRAMP, and FISMA Ability to work effectively within a distributed technical team, aided by strong written and verbal communication skills Familiarity with the Atlassian suite, including Jira and Confluence Current More ❯
Oxford, England, United Kingdom Hybrid / WFH Options
University of Oxford
responsible for safeguarding the university's digital assets while enabling its strategic objectives. Within this structure, the Operations team focuses on the Protect, Detect, and Respond functions of the NIST Cybersecurity Framework. What We Offer Working at the University of Oxford offers several exclusive benefits, such as: 38 days of annual leave (inclusive of public holidays) to support your wellbeing More ❯
London, England, United Kingdom Hybrid / WFH Options
Vantage Data Centers
people manager role. Strong understanding of cybersecurity frameworks for ICS/OT environments Strong understanding of OT network communication protocols and industrial networking topologies. Familiarity with NIST (NationalInstituteofStandardsandTechnology) Special Publication 800-61 Revision 2, Computer Security Incident Handling Guide. Familiarity with NIST (NationalInstituteofStandardsandTechnology) Special Publication 800-82 Comprehensive knowledge of … MITRE ATT&CKS for ICS or NERC CIP (North American Electric Reliability Corporation Critical Infrastructure Plan) frameworks Understanding of general cybersecurity frameworks (ISO IEC 27001/27002, ISO 15408, NIST Cybersecurity Framework (CSF), NIST SP800-53), and Guide to Industrial Control Systems (ICS) Security (NIST SP800-82) A working knowledge of industrial control systems (e.g., Distributed Control System (DCS), Programmable More ❯
andstandards such as NIS, GDPR, PCI DSS etc. • Knowledge of topic-specific framework & methodologies in areas such as Risk Management (ISO 31000) IT management (e.g. COBIT) Information Security (NIST, ISF, ISO 27001), Service Delivery (e.g. ITIL) etc. What we can offer you Business Area Primary Location More ❯
London, England, United Kingdom Hybrid / WFH Options
Babcock
and appreciation/familiarity of common OT control frameworks. In-depth knowledge and experience applying control framework(s) in an OT context, which may include some or all of: NIST SP 800-53/82, ISO/IEC 62443, Cyber Assessment Framework (CAF), ISO/IEC 27001, NIST Cyber Security Framework. Understanding of the differences between IT and OT operating More ❯
London, England, United Kingdom Hybrid / WFH Options
55 Redefined Ltd
in IT/OT cybersecurity. Certifications such as GICSP or 62443. Required Skills and Experience Basic understanding of OT control frameworks. Experience applying control frameworks in OT, such as NIST SP 800-53/82, ISO/IEC 62443, CAF, ISO/IEC 27001, NIST Cybersecurity Framework. Understanding of differences between IT and OT environments. Experience identifying security risks. Knowledge More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Apache Associates
hands-on experience with Okta's FedRAMP offerings. Experience with identity governance, SSO, MFA, RBAC, and federated identity systems. Familiarity with security best practices and compliance frameworks (e.g., FedRAMP, NIST) ** Outside IR35 role ** 6 month duration - 100% Remote Due to the number of applications, we can only respond that those who match these requirements. More ❯
London, England, United Kingdom Hybrid / WFH Options
Uphold
are a strong advantage. Knowledge of blockchain, digital assets, or Web3 technologies and the associated data risks. Understanding of control and compliance frameworks such as ISO 27001, SOC 2, NIST, or COBIT. What we have to offer you An amazing work environment in a company that continues to grow, driven by extraordinary and passionate people who keep up innovating andMore ❯
London, England, United Kingdom Hybrid / WFH Options
Oliver James
and design of the security infrastructure including WAF, Proxy, Email Gateway, Logging, Endpoint, IDS, IDP, etc. Strong understanding of cyber security principles, frameworks, and regulatory standards (e.g. ISO 27001, NIST, GDPR) Experience working with security transformation initiatives Knowledge of Azure and native cloud tools Good knowledge of ITIL processes Understanding of network/directory/security technologies Understanding of secure More ❯
Easter Howgate, Midlothian, United Kingdom Hybrid / WFH Options
Leonardo UK Ltd
Cyber/Engineering Role. Involvement in MOD accreditation and secure by design processes (ISN2023/09), associated policies and practices across the lifecycle. Knowledge or application ofstandards including NIST Special Publications (e.g. SP 800-30, 37 & 53). Managing risks and services in accordance with customer, regulatory and legislative expectations. Experience outside of traditional enterprise IT scenarios extending to More ❯
Stafford, Staffordshire, West Midlands, United Kingdom Hybrid / WFH Options
Quest Global Engineering Limited
detection systems, and access controls. Familiarity with network segmentation techniques and security architectures for OT systems. Experience with Industrial communication network and system security IEC 62443 standards. Knowledge ofNIST Cybersecurity Framework, NIS2, and CRA regulations. Strong understanding of cybersecurity principles, risk management, and compliance frameworks. Cybersecurity certifications (e.g., SSCP, CISSP, CISM, IEC 62443) are a plus. Develop and implement More ❯
Birmingham, England, United Kingdom Hybrid / WFH Options
Jacobs
a working knowledge and understanding of networking technologies Experience of implementing standards & frameworks including EU NIS Directive, ISA/IEC 62443 Series/ISO 27000 Series, MITRE ATT&CK, NIST Cyber Security Framework (CSF), Technical Assessment Guides and supplementary guidance Our culture Our values stand on a foundation of safety, integrity, inclusion and diversity. We put people at the heart More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Uneek Global
ops teams to deliver secure changes in a 24/7 production environment Supporting incident response and root cause analysis Ensuring remediation plans align with industry standards (ISO 27001, NIST, GDPR, etc.) What They're Looking For: Strong background in cyber security operations, especially remediation and patching Comfortable working across Operational Technology (OT) as well as traditional IT systems Hands … on experience with Windows/Linux patching and secure config changes Understanding of change management in live environments Familiar with relevant frameworks: ISO 27001, NIST, NCSC Guidance Contract Length: 6 months FTC Location: London (Hybrid) Salary: Up to £75k Please get in touch for further details and a discussion about this opportunity. Uneek is a professional organisation, and we gladly More ❯
London, England, United Kingdom Hybrid / WFH Options
William Blake Group
thematic risk assessments and integrated audits. Key Requirements: At least 3 years of experience in IT audit, ideally within financial services. Sound knowledge of IT control frameworks such as NIST, ISO 27001, and COBIT. Familiar with FCA/PRA regulatory standardsand data protection laws. Exposure to cloud technologies, network security, and third-party risk oversight. Experience of conducting end More ❯
London, England, United Kingdom Hybrid / WFH Options
Datavant
research, recommendation and implementing solutions. A technical source of knowledge to continuously review, evaluate and improve systems/processes Expert knowledge of IAM compliance and audit. Knowledge of SOC2, NIST, ISO27001, and other IT security standards. Expertise relating to the design and development of information technology architectures across the organization Show expert-level troubleshooting capabilities. Ability to identify root causes More ❯
Almondsbury, Gloucestershire, United Kingdom Hybrid / WFH Options
Frontier Resourcing
modelling, secure-by-design). Perform security code reviews, provide guidance on secure libraries and frameworks. Standards & Compliance Ensure products meet regulatory and defence standards (ISO 27001/27005, NIST 800-30/53, JSP 440/604, Def Stan 05-series). Lead the creation and maintenance of security documentation (RMADS, Security Assurance Documents, Security Management Plans). Testing … experience (5+ years) in product or application security within defence, government, or security-cleared environments. Deep knowledge of risk management frameworks (ISO 27001/2/5/31000, NIST 800-series) and Defence Standards (JSPs, Def Stan 05-138/139). Hands-on experience with security testing tools and techniques (SAST, DAST, penetration testing). Eligible for UK More ❯
ops teams to deliver secure changes in a 24/7 production environment Supporting incident response and root cause analysis Ensuring remediation plans align with industry standards (ISO 27001, NIST, GDPR, etc.) What They're Looking For: Strong background in cyber security operations, especially remediation and patching Comfortable working across Operational Technology (OT) as well as traditional IT systems Hands … on experience with Windows/Linux patching and secure config changes Understanding of change management in live environments Familiar with relevant frameworks: ISO 27001, NIST, NCSC Guidance Contract Length: 6 months FTC Location: London (Hybrid) Salary: Up to £75k Please get in touch for further details and a discussion about this opportunity. Uneek is a professional organisation, and we gladly More ❯
London, England, United Kingdom Hybrid / WFH Options
Premier Inn
Mobile environments. Experience of working in a digital/Application development environment, with knowledge of development principles and best practices. Knowledge of security frameworks andstandards (ISF SoGP, ISO27000, NIST, CIS, OWAP etc.). Experience with cloud security (AWS, Azure, 365, Oracle). Able to work and collaborate at all levels. Budget and supplier/vendor management experience. Hands-on More ❯
London, England, United Kingdom Hybrid / WFH Options
DELIVEROO
to drive higher maturity. What You'll Be Doing: Develop and implement information security policies, standards, and guidance in collaboration with stakeholders. Ensure compliance with industry standards such as NIST CSF, PCI-DSS, ISO 27001, and SOC 2. Coordinate responses to internal and external audits and liaise with key stakeholders. Develop and deliver security policy awareness and training programs. Assess … in information security, ideally in a public tech company or regulated industry. Experience in developing and implementing information security policies, standards, and procedures. Familiarity with security standards such as NIST CSF, PCI-DSS, ISO 27001, and SOC2. Strong skills in security metrics and reporting. Ability to engage collaboratively with technical and non-technical stakeholders. Excellent written and verbal communication skills. More ❯
Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
Bowerford Associates
techniques that can make our software applications demonstrably more secure and robust. Good understanding of common information security management standards, frameworks, and laws/regulations: e.g . ISO 27001 , NIST , GDPR . Experience of open-source security tools and how they could be used in an enterprise. Experience of securing Azure cloud workloads and environments. Please note, to be considered … InfoSec, Security, Security Strategy, Best Practice, Programming, Code, C++, C#, C, .NET Core, Java, JavaScript, Node.js, Angular, React, OWASP, Agile, Application Threat Modelling, Security Policy, Security Controls, ISO 27001, NIST, GDPR, Cloud, Azure. Please note that due to a high level of applications, we can only respond to applicants whose skills and qualifications are suitable for this position. No terminology More ❯
Analyst if your background includes: 5-7+ years of experience in vendor risk management, third-party risk, or related fields Experience with vendor assessment methodologies and frameworks (e.g., NIST, ISO, SIG) Experience with vendor risk assessment tools and databases Contract review and negotiation experience Strong communication skills for interacting with vendors and internal stakeholders Industry certifications such as CTPRP More ❯
London, England, United Kingdom Hybrid / WFH Options
F5 Consultants
to join their growing team, with ideal candidates having good knowledge/understanding of Governance Risk & Compliance (GRC), specifically around HMG/MOD frameworks such as Secure by Design, NIST, and ISO 27001. Because of the nature of the work and customers you could end up supporting, this role would suit a service leaver/ex-military professional. This company … MoD cyber policies, standards (e.g. JSP440), and processes Experience with Secure by Design implementation and related tooling Knowledge of NCSC Cyber Assurance Framework (CAF) and GovAssure audits Understanding ofNIST Cyber Security Framework and risk assessment methods Experience with ISO/IEC 27001 audits and cyber security assurance Supplier assurance and supply chain security expertise Basic salary More ❯
London, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
network of Member Firms for compliance against our information security framework. The ideal candidate will have experience evaluating IT Infrastructure Security technologies, IT general computer controls, industry frameworks (e.g. NIST) and will bring strong information technology audit or security consulting experience to the programme. Location United Kingdom/Europe Main responsibilities The Senior Associate will support with the implementation of … experience in a similar role. Prior experience within a security compliance assurance or auditing position. Understanding of relevant regulatory requirements and assurance processes, including various auditing standards such as NISTand ISO27001 Analytical skills to collect, analyse and interpret information and/or data into useful insight Excellent communication skills, both verbal and written, with the ability to initiate andMore ❯
Hounslow, England, United Kingdom Hybrid / WFH Options
JR United Kingdom
network of Member Firms for compliance against our information security framework. The ideal candidate will have experience evaluating IT Infrastructure Security technologies, IT general computer controls, industry frameworks (e.g. NIST) and will bring strong information technology audit or security consulting experience to the programme. Location United Kingdom/Europe Main responsibilities The Senior Associate will support with the implementation of … experience in a similar role. Prior experience within a security compliance assurance or auditing position. Understanding of relevant regulatory requirements and assurance processes, including various auditing standards such as NISTand ISO27001 Analytical skills to collect, analyse and interpret information and/or data into useful insight Excellent communication skills, both verbal and written, with the ability to initiate andMore ❯