Cambridge, England, United Kingdom Hybrid / WFH Options
Arm
findings, post incident reviews, and assessments lead to meaningful, sustained improvements. Required Skills And Experience Experience leading enterprise security risk programs—practical and scalable. Deep understanding of control frameworks (NIST, ISO 27001, SOX) and how to apply them. Experience driving third-party risk strategies and supplier oversight. Clear communicator with a strong delivery mindset—can engage technical and non-technical More ❯
Poole, England, United Kingdom Hybrid / WFH Options
General Dynamics UK
Social network you want to login/join with: General Dynamics Mission Systems engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
QinetiQ Limited
include: Creating business risk models and associated material, in support of operational cyber security and business planning across a range of different domains or sectors using established frameworks (e.g. NIST, UK Government) Undertake cyber security audit processes in support of operational and business planning activity across a range of different domains or sectors against recognised standards (e.g. ISO27001, UK Government … of organisational maturity and risk exposure to cyber security, in support of operational and business planning activity across a range of different domains or sectors using established frameworks (e.g. NIST, MITRE ATT&CK, UK Government) Identify mitigations for cyber risk in a given business or operational scenario and threat environment Support development of cyber security risk cases in a given … of the Cyber Security Risk Consultant: Digitally literate (including fluency in Microsoft Office tools) Minimum of 2-3 years of experience in security vulnerability, risk, audit & compliance Understand relevant NIST frameworks and ISO27001 standardsand how to apply in practice Knowledge of MITRE ATT&CK Essential qualifications for the Cyber Security Risk Consultant: We value difference and we don't More ❯
Bristol, England, United Kingdom Hybrid / WFH Options
QinetiQ Limited
include: Creating business risk models and associated material, in support of operational cyber security and business planning across a range of different domains or sectors using established frameworks (e.g. NIST, UK Government) Undertake cyber security audit processes in support of operational and business planning activity across a range of different domains or sectors against recognised standards (e.g. ISO27001, UK Government … of organisational maturity and risk exposure to cyber security, in support of operational and business planning activity across a range of different domains or sectors using established frameworks (e.g. NIST, MITRE ATT&CK, UK Government) Identify mitigations for cyber risk in a given business or operational scenario and threat environment Support development of cyber security risk cases in a given … of the Cyber Security Risk Consultant: Digitally literate (including fluency in Microsoft Office tools) Minimum of 2-3 years of experience in security vulnerability, risk, audit & compliance Understand relevant NIST frameworks and ISO27001 standardsand how to apply in practice Knowledge of MITRE ATT&CK Essential qualifications for the Cyber Security Risk Consultant: We value difference and we don’t More ❯
Crawley, Sussex, United Kingdom Hybrid / WFH Options
Thales Group
provide them with insight into the security solutions adapted to their needs Check compliance with applicable regulations, standards, policies and guidance on cybersecurity and information risk management (PCI DSS, NIST, ISO 27000, Privacy, etc) Support the development of appropriate and proportionate documentation to inform risk management decisions, ensuring these are expressed in terms meaningful to the business Check compliance with … applicable regulations, standards, policies and guidance on cybersecurity and information risk management (PCI DSS, NIST, ISO 27000, Privacy, etc) Support the development of appropriate and proportionate documentation to inform risk management decisions, ensuring these are expressed in terms meaningful to the business Right for this role? Ideally you'll be familiar with the main risk analysis methods (EBIOS, ISO … regulatory constraints (LPM, NIS, RGPD, II 901, IGI 1300) and security standards (ISO 27000, NIST, ANSSI, etc) You are able to identify, analyse and evaluate cybersecurity and information risks Have knowledge of Authentication and Identity management solutions Experienced in database administration (mainly Oracle, MySQL and MS SQL) You can demonstrate knowledge in programming background and experience (Java, C++, .NET, SQL More ❯
Crawley, England, United Kingdom Hybrid / WFH Options
Thales Group
provide them with insight into the security solutions adapted to their needs Check compliance with applicable regulations, standards, policies and guidance on cybersecurity and information risk management (PCI DSS, NIST, ISO 27000, Privacy, etc) Support the development of appropriate and proportionate documentation to inform risk management decisions, ensuring these are expressed in terms meaningful to the business Check compliance with … applicable regulations, standards, policies and guidance on cybersecurity and information risk management (PCI DSS, NIST, ISO 27000, Privacy, etc) Support the development of appropriate and proportionate documentation to inform risk management decisions, ensuring these are expressed in terms meaningful to the business Right for this role? Ideally you’ll be familiar with the main risk analysis methods (EBIOS, ISO … regulatory constraints (LPM, NIS, RGPD, II 901, IGI 1300) and security standards (ISO 27000, NIST, ANSSI, etc) You are able to identify, analyse and evaluate cybersecurity and information risks Have knowledge of Authentication and Identity management solutions Experienced in database administration (mainly Oracle, MySQL and MS SQL) You can demonstrate knowledge in programming background and experience (Java, C++, .NET, SQL More ❯
provide them with insight into the security solutions adapted to their needs Check compliance with applicable regulations, standards, policies and guidance on cybersecurity and information risk management (PCI DSS, NIST, ISO 27000, Privacy, etc) Support the development of appropriate and proportionate documentation to inform risk management decisions, ensuring these are expressed in terms meaningful to the business Right for this … role? Ideally you'll be familiar with the main risk analysis methods (EBIOS, ISO 27005), regulatory constraints (LPM, NIS, RGPD, II 901, IGI 1300) and security standards (ISO 27000, NIST, ANSSI, etc). You are able to identify, analyse and evaluate cybersecurity and information risks. Have knowledge of Authentication and Identity management solutions. Experienced in database administration (mainly Oracle, MySQL More ❯
London, England, United Kingdom Hybrid / WFH Options
Thales Group
provide them with insight into the security solutions adapted to their needs Check compliance with applicable regulations, standards, policies and guidance on cybersecurity and information risk management (PCI DSS, NIST, ISO 27000, Privacy, etc) Support the development of appropriate and proportionate documentation to inform risk management decisions, ensuring these are expressed in terms meaningful to the business Right for this … role? Ideally you'll be familiar with the main risk analysis methods (EBIOS, ISO 27005), regulatory constraints (LPM, NIS, RGPD, II 901, IGI 1300) and security standards (ISO 27000, NIST, ANSSI, etc). You are able to identify, analyse and evaluate cybersecurity and information risks. Have knowledge of Authentication and Identity management solutions. Experienced in database administration (mainly Oracle, MySQL More ❯
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
QinetiQ Limited
of action The ability to understand how architects and designers employ technology to build systems of interest Digitally literate (including fluency in Microsoft Office tools) Able to understand relevant NIST frameworks and ISO27001 standardsand how to apply in practice Knowledge of MITRE ATT&CK Essential qualifications for the Cyber Security Risk Consultant: We value difference and we don't More ❯
Bristol, England, United Kingdom Hybrid / WFH Options
QinetiQ Limited
of action The ability to understand how architects and designers employ technology to build systems of interest Digitally literate (including fluency in Microsoft Office tools) Able to understand relevant NIST frameworks and ISO27001 standardsand how to apply in practice Knowledge of MITRE ATT&CK Essential qualifications for the Cyber Security Risk Consultant: We value difference and we don’t More ❯
Cheltenham, England, United Kingdom Hybrid / WFH Options
FR Secure
and secure-by-design principles. Familiarity with government and defence security standards such as: HMG/NCSC IA Policies and Guidelines JSP440 and other MoD IA standards Cyber Essentials NIST, NIS-D ONR SyAPs (Security Assessment Principles) Excellent stakeholder communication skills – you can clearly explain complex security concepts to both technical and non-technical audiences. Security Clearance eDV clearance is More ❯
London, England, United Kingdom Hybrid / WFH Options
Philip Morris International
systems · Understanding of design and architecture principles, security controls, risk management and the relevant legal and regulatory requirements for Artificial Intelligence systems · Familiar with standards such as ISO 42001, NIST AI RMF and regulation such as EU Artificial Intelligence Act · Proficient in working with geographically dispersed or remote teams, demonstrating excellent technical writing proficiency and oral presentation skills · Team player More ❯
London, England, United Kingdom Hybrid / WFH Options
Promon
exploring new technologies (including AI), and challenging the status quo to create market-leading solutions. Regulatory & Compliance Knowledge – Familiarity with industry standardsand frameworks like ISO 27001, SOC 2, NIST, DORA, and the AI Act, with the ability to translate compliance needs into product improvements. In addition to the above, we are looking for a leader who is: Thriving: You More ❯
Aberdeen, Aberdeenshire, Scotland, United Kingdom Hybrid / WFH Options
Reed
of IT fundamentals, including networks (LAN/WAN), operating systems, Active Directory, authentication systems, cloud computing, and core security concepts. Familiar with industry security standardsand frameworks such as NIST, CIS, and ISO, and able to apply them in practice. Proven ability to work effectively in teams, with strong communication and presentation skills and a commitment to a positive work More ❯
Barnsley, South Yorkshire, England, United Kingdom Hybrid / WFH Options
Hays Specialist Recruitment Limited
evaluate and design solutions as required for business and customer requirements and help develop the strategic direction. You will ensure that our infrastructure is implemented securely using guidance from NIST, NCSC, CIS etc. You will ensure all systems are maintain and in support and compliant with our security certifications. You will need to have experience in a similar sized environment More ❯
London, England, United Kingdom Hybrid / WFH Options
Take-Two Interactive
understanding of IT infrastructure , cloud services, networking, and security. Demonstrated ability to lead cross-functional recovery teams across diverse lines of business. Familiarity with industry frameworks such as ISO, NIST, or COBIT. Excellent communication, planning, and documentation skills. Administration experience with tools such as Fusion Framework, AlertMedia, ServiceNow or similar platforms is a plus. Great to Have Background in gaming More ❯
Lexington, Massachusetts, United States Hybrid / WFH Options
Aquila Technology
Docker, Kubernetes, Podman) Experience with running/maintaining databases/data stores (e.g., MySQL, InfluxDB, Elasticsearch) And These Skills are a Bonus: Prior experience with IT system security compliance (NIST, PCI, HIPPA, CMMC) MacOS system administration Working knowledge of DevOps tools and pipelines Computer networking Amazon Web Services (AWS) Strong understanding of DoD RMF and STIG process Our interview process More ❯
Stevenage, England, United Kingdom Hybrid / WFH Options
Capgemini Engineering
SCADA, PLCs, industrial networks) Understanding of industrial communication protocols and network architectures Experience with data analytics and machine learning in IIoT contexts Knowledge of security standards (e.g., IEC 62443, NIST SP 800-82) Relevant certifications in IIoT, cloud, or industrial networking are a bonus Don’t meet every single requirement? We encourage you to apply anyway. We are committed to More ❯
Stevenage, England, United Kingdom Hybrid / WFH Options
Capgemini
SCADA, PLCs, industrial networks) Understanding of industrial communication protocols and network architectures Experience with data analytics and machine learning in IIoT contexts Knowledge of security standards (e.g., IEC 62443, NIST SP 800-82) Relevant certifications in IIoT, cloud, or industrial networking are a bonus Don't meet every single requirements? Studies have shown women and people of colour are less More ❯
London, England, United Kingdom Hybrid / WFH Options
Hays PLC
and implement robust security frameworks and governance structures. Provide strategic guidance on risk management and compliance. Support audit and certification processes. Requirements: Active SC Clearance. Proven understanding of ISO27001, NIST, and Prisma. Experience in GRC and audit processes. #J-18808-Ljbffr More ❯
London, England, United Kingdom Hybrid / WFH Options
Databricks Inc
demonstrated expertise as a Security Engineer with experience in Endpoint/Enduser security. Expert knowledge of physical endpoints (macOS, Windows) ideally using tools such as Osquery. Significant experience with NIST 800-53 or similar frameworks. Experience with automating security reviews is desirable. Skill and experience with Identity and Access Management (IAM) solutions such as Okta; Device Management solutions such as More ❯
Manchester, Lancashire, England, United Kingdom Hybrid / WFH Options
Oliver James
and design of the security infrastructure including WAF, Proxy, Email Gateway, Logging, Endpoint, IDS, IDP, etc. Strong understanding of cyber security principles, frameworks, and regulatory standards (e.g. ISO 27001, NIST, GDPR) Experience working with security transformation initiatives Knowledge of Azure and native cloud tools Good knowledge of ITIL processes Understanding of network/directory/security technologies Understanding of secure More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Lawrence Harvey
mature organization that will continue to embed modern security practices and methodologies About the role: Develop, maintain, and align security policies, standards, and frameworks with industry best practices (e.g., NIST CSF, 800-53). Advise stakeholders on security best practices and support cybersecurity risk management strategies. Conduct and manage risk assessments, maintain the risk register (RSA Archer), and prioritize security … audits, ensure compliance, and provide assurance through reporting, metrics, and lessons learned. What you will need: Strong experience conducting test plans and testing security controls whilst ensuring compliance to NIST CSF/NIST 800-53/ISO27001/SOC I&II Strong background working within a Security Risk team Wider experience working with different Cyber Security teams Excellent attention to More ❯
mature organization that will continue to embed modern security practices and methodologies About the role: Develop, maintain, and align security policies, standards, and frameworks with industry best practices (e.g., NIST CSF, 800-53). Advise stakeholders on security best practices and support cybersecurity risk management strategies. Conduct and manage risk assessments, maintain the risk register (RSA Archer), and prioritize security … audits, ensure compliance, and provide assurance through reporting, metrics, and lessons learned. What you will need: Strong experience conducting test plans and testing security controls whilst ensuring compliance to NIST CSF/NIST 800-53/ISO27001/SOC I&II Strong background working within a Security Risk team Wider experience working with different Cyber Security teams Excellent attention to More ❯
in Ivanti Application & Device Control or similar lockdown tools. Experience working with high-security MOD systems and secure design principles. Familiarity with security and compliance documentation (e.g. RMADS, SyOPs, NIST frameworks). Core Technologies Microsoft: Windows Server 2019/2022/2025 Active Directory, Group Policy, DNS, DHCP Exchange Server 2019, SQL Server, SharePoint 2019 VMware: VMware Cloud Foundation vSphere More ❯