Cybersecurity, advanced metering infrastructure (AMI). Relevant professional certifications (e.g., ITIL, CISSP, CISM, PMP, CMP) or similar credentials are considered an asset. Expertise in Cybersecurity regulatory frameworks (e.g., OEB, NIST, NERC CIP, Privacy by Design). Experience in a regulated industry, preferably the electricity/energy/utilities sector. Previous experience with SAP S/4HANA ERP/customer service More ❯
Cybersecurity, advanced metering infrastructure (AMI). Relevant professional certifications (e.g., ITIL, CISSP, CISM, PMP, CMP) or similar credentials are considered an asset. Expertise in Cybersecurity regulatory frameworks (e.g., OEB, NIST, NERC CIP, Privacy by Design). Experience in a regulated industry, preferably the electricity/energy/utilities sector. Previous experience with SAP S/4HANA ERP/customer service More ❯
Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
LA International Computer Consultants Ltd
ensure proper actions are taken to block further attacks. 5. Compliance and Risk Management: o Ensure all incident response activities align with industry standards, regulations, and best practices (e.g., NIST, ISO 27001, GDPR, HIPAA). o Work with legal and compliance teams to manage incidents within the scope of data privacy laws and regulations. Key Skills & Experience: o Proficient in More ❯
Boston, Massachusetts, United States Hybrid / WFH Options
Digital Prospectors
models and remediation strategies. • Deliver clear and actionable assessments of vulnerabilities and threats, with recommendations to mitigate operational and reputational risks. • Ensure alignment with security compliance frameworks such as NIST 800-171 through assessments, testing, and regular reviews. • Participate in the development of security controls, processes, and documentation to support enterprise cyber operations. Qualifications: • Bachelor's degree in Cybersecurity, Computer More ❯
North Lanarkshire, Scotland, United Kingdom Hybrid / WFH Options
Net Talent
Security Operations—is key to aligning local and global security standards. You'll also drive cyber awareness and training initiatives for commercial teams, support regulatory compliance (e.g., ISO 27001, NIST SP 800-53, GDPR), and handle incident response, triage, and escalations per internal policies. You'll contribute to investigations, the annual NIST CSF 2.0 maturity assessment, and resolution of Information … Security issues. 🧠 Skills & Experience Required You're a proactive, analytical security professional with a strong technical background and excellent communication skills. You bring: Proven experience with ISO 27001, NIST CSF/SP 800-53, GDPR compliance, and risk management Strong technical expertise in implementing security controls aligned with ISMS Ability to create clear, audience-tailored documentation and reports Effective problem More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Sanderson
complex organisations Strong understanding of cyber risk, threat management, and technical security controls Excellent stakeholder management and communication skills Experience with governance, risk, and compliance frameworks (e.g., ISO 27001, NIST, GDPR) PRINCE2, PMP, or similar project management certification desirable Knowledge of cloud security (Azure/AWS) a plus Reasonable Adjustments: Respect and equality are core values to us. We are More ❯
City Of London, England, United Kingdom Hybrid / WFH Options
Sanderson
changes, and industry best practices. Required Skills & Experience: Proven experience in Information Security, Cybersecurity, and/or Information Privacy. Deep understanding of regulatory frameworks: GDPR, DPA 2018, ISO 27001, NIST , and FCA guidelines. Strong knowledge of security controls, data lifecycle management, and access control models. Experience within the banking or financial services sector is essential. Demonstrated ability to engage with More ❯
always in search of the best people to join our ever-growing talented team. Responsibilities: Design and maintain a robust technology control testingframework aligned with risk management standards (e.g.,NIST, ISO 27001, COBIT, ITIL). Develop and update testing methodologies, ensuring theyaddress key risks related to IT infrastructure, cybersecurity,cloud services, and software development. Establish and maintain control testing policies More ❯
M5, Salford, Greater Manchester, United Kingdom Hybrid / WFH Options
AJ Bell Business Solutions Limited
andtechnology teams to ensure security is embedded across the organisation Competence, knowledge, and skills Competence Experience working within recognised Information Security frameworks and best practices such as ISO27001, NIST etc. 5 years’ experience in an Information Security role gained in a financial services or e-commerce environment is preferred Knowledge & Technical Skills: Demonstrable experience of implementing enterprise security platforms … Security risk management tools and techniques Experience of security governance and compliance, ideally gained in financial services organisations Demonstrable understanding of Information Security control standardsand frameworks e.g. ISO27001, NIST, PCI DSS Awareness and understanding of the Information Security threat landscape Deep understanding of Information Security solutions and controls Experience of Cloud security solutions andstandards is highly advantageous Attained More ❯
Manchester, Lancashire, England, United Kingdom Hybrid / WFH Options
AJ Bell
Security risk management tools and techniques Experience of security governance and compliance, ideally gained in financial services organisations Demonstrable understanding of Information Security control standardsand frameworks e.g. ISO27001, NIST, PCI DSS Awareness and understanding of the Information Security threat landscape Deep understanding of Information Security solutions and controls Experience of Cloud security solutions andstandards is highly advantageous Competence … knowledge, and skills Competence Experience working within recognised Information Security frameworks and best practices such as ISO27001, NIST etc. 5 years’ experience in an Information Security role gained in a financial services or e-commerce environment is preferred Knowledge & Skills Excellent communicator, able to translate complex topics to all areas of the business Well versed in IT security capabilities, framework More ❯
skills, working closely with business and technical teams to ensure security controls are implemented and effective Assist in preparing for and responding to regulatory audits and compliance reviews (e.g., NIST CSF, ISO 27001, DORA, GDPR. ITGC) Maintain and update the information security risk register with appropriate scenarios and control frameworks Conduct regular control testing, evaluation and reporting findings to stakeholders … awareness training and internal compliance communications Job Requirements Previous progressive experience in information security risk management, risk management, or compliance Strong understanding of information security frameworks (e.g., ISO 27001, NIST) Experience with GRC tools/platforms Excellent organisational, communication, and documentation skills Ability to work independently and cross-functionally in a fast-paced environment Industry certifications such as CISA, CRISC More ❯
City of London, London, England, United Kingdom Hybrid / WFH Options
Skillcast
closely with DevOps to embed security in CI/CD pipelines and infrastructure-as-code processes - Enforce security policies, standards, and procedures aligned with frameworks like ISO 27001 andNIST - Monitor and report on risk posture, incident trends, and compliance status to inform leadership decisions - Guide and support junior cybersecurity professionals and interns through technical coaching and feedback You: - Bachelor … SIEM platforms (especially Azure Sentinel) and vulnerability management tools - Strong knowledge of incident response, infrastructure hardening, and cloud security controls - Familiarity with SOC 2, ISO 27001, Cyber Essentials, andNIST frameworks - Experience with core security technologies: firewalls, EDR, IAM, DLP, encryption - Strong communication, documentation, and stakeholder engagement skills Benefits: - Join a growing business in a thriving and innovative sector - Join More ❯
London, Tower, United Kingdom Hybrid / WFH Options
Skillcast
closely with DevOps to embed security in CI/CD pipelines and infrastructure-as-code processes - Enforce security policies, standards, and procedures aligned with frameworks like ISO 27001 andNIST - Monitor and report on risk posture, incident trends, and compliance status to inform leadership decisions - Guide and support junior cybersecurity professionals and interns through technical coaching and feedback You: - Bachelor … SIEM platforms (especially Azure Sentinel) and vulnerability management tools - Strong knowledge of incident response, infrastructure hardening, and cloud security controls - Familiarity with SOC 2, ISO 27001, Cyber Essentials, andNIST frameworks - Experience with core security technologies: firewalls, EDR, IAM, DLP, encryption - Strong communication, documentation, and stakeholder engagement skills Benefits: - Join a growing business in a thriving and innovative sector - Join More ❯
technologies and design pragmatic security solutions for the bank Effective collaboration with internal and external SMEs/partner organizations Experience with frameworks such as ISO 27001/2, SOC, NIST, or COBIT About You Skills Recognized leading security qualification or working towards one (e.g., CiSP, CompTIA) Ideally Microsoft Azure certifications such as AZ-500 or MS-500 Experience working in More ❯
Luton, Bedfordshire, United Kingdom Hybrid / WFH Options
Leonardo UK Ltd
and maintain clear, concise reports, metrics, and documentation related to security incidents, risks, and controls. What we need from you; Practical experience of ISO27001/27004/27005 andNIST Risk Management Framework (RMF) Demonstrable experience of writing IA Technical Risk Assessments and the management of these Assessments Good understanding and appreciation of the Engineering development lifecycles and how the More ❯
Laurel, Maryland, United States Hybrid / WFH Options
TEKsystems c/o Allegis Group
multi-task and self-assign work in a fast-paced environment. • Ability to work well/collaborate with people from many different disciplines with varying degrees of technical experience. • NIST RMF Assessment and Authorization (A&A) experience. • Experience with operating IT security tools, such as ACAS, HBSS, DISA STIGs • Prior experience working Cybersecurity in accordance with US Government (USG), Department More ❯
requirements, and guiding clients through complex third-party audits. Key Responsibilities Cybersecurity Program Evaluation Lead cyber assurance engagements, assessing client cybersecurity programs for compliance with industry standards such as NIST, ISO 27001, and other relevant frameworks. Act as a trusted advisor, ensuring client cybersecurity postures are resilient, compliant, and in line with regulatory requirements. Vulnerability Assessment and Penetration Testing Management … party risk management, and regulatory compliance audits. Proven track record of leading cyber assurance engagements and guiding clients through risk management and compliance processes based on industry frameworks (e.g., NIST, ISO 27001). Expertise in managing third-party audits and ensuring regulatory compliance across audit lifecycles. In-depth understanding of regulatory frameworks, with hands-on experience delivering compliance audits for More ❯
South Kensington, England, United Kingdom Hybrid / WFH Options
Control Risks
job description and make sure to attach relevant documents. Key Responsibilities Cybersecurity Program Evaluation Lead cyber assurance engagements, assessing client cybersecurity programs for compliance with industry standards such as NIST, ISO 27001, and other relevant frameworks. Act as a trusted advisor, ensuring client cybersecurity postures are resilient, compliant, and in line with regulatory requirements. Vulnerability Assessment and Penetration Testing Management … party risk management, and regulatory compliance audits. Proven track record of leading cyber assurance engagements and guiding clients through risk management and compliance processes based on industry frameworks (e.g., NIST, ISO 27001). Expertise in managing third-party audits and ensuring regulatory compliance across audit lifecycles. In-depth understanding of regulatory frameworks, with hands-on experience delivering compliance audits for More ❯
Watford, Hertfordshire, United Kingdom Hybrid / WFH Options
Essential Employment
Provide technical escalation support in the absence of a cybersecurity specialist, particularly in coordination with the Security Operations Centre (SOC). - Support compliance with relevant standards (e.g. ISO 27001, NIST, UK GDPR). - Review security aspects of tenders and conduct third-party/vendor risk assessments to ensure alignment with organisational security requirements. - Perform additional security-related tasks as directed … and cloud security. - Ability to assess and communicate technical vulnerabilities in business terms. - Experience working with or within a SOC environment. - Familiarity with risk management frameworks?(e.g. ISO 27005, NIST RMF). - Excellent communication and reporting skills. - Relevant certifications (e.g. CISSP, CISM, CRISC, CEH). - Experience with GRC tools and risk registers. - Knowledge of regulatory requirements and data protection laws. More ❯
or Bash Familiarity with open-source diagnostic and assessment tools such as Nmap, Wireshark, and Kali Linux Solid understanding of established security frameworks and models (e.g., MITRE ATT&CK, NIST, and related methodologies) Comfortable using general productivity and communication software for remote collaboration Bachelor's degree in cybersecurity, information technology, or a related field Qualifications Strong analytical thinking and problem More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Global TechForce
attack vectors, malware, and security trends is crucial. Developing and implementing security policies, standards, and procedures: This includes creating guidelines aligned with industry best practices and regulatory requirements (e.g., NIST CSF, ISO 27001, GDPR). Designing and architecting secure IT environments: This may involve network security design, cloud security architecture (AWS, Azure, GCP), and implementing security technologies. Developing and assisting More ❯
Guildford, Surrey, United Kingdom Hybrid / WFH Options
Allianz Popular SL
Security Analyst plays a key role in supporting Allianz UK's Information Security initiatives, with a focus on executing the Governance, Risk, and Compliance (GRC) activities and implementing the NIST Cyber Security Framework (CSF) across the organisation. The NIST analyst will involve in day-to-day GRC operations, such as designing and implementing security controls, interpreting requirements from the Group … Information Security Analyst at Allianz UK, you will be pivotal in advancing the company's Information Security initiatives by executing Governance, Risk, and Compliance (GRC) activities and implementing the NIST Cyber Security Framework (CSF) organization-wide. Your role will involve daily GRC operations, including designing and implementing security controls, interpreting requirements from the Group Information Security Framework, and managing non … analysing potential risks, and monitoring progress on maturity uplifting across security functions. You will be developing and implementing an information security controls catalogue, policies, and procedures aligned with the NIST Cyber Security Framework (CSF). Collaborating with the wider organization to integrate control testing and risk management activities into the existing governance framework. Assisting cross-functional teams and business units More ❯
attack vectors, malware, and security trends is crucial. Developing and implementing security policies, standards, and procedures: This includes creating guidelines aligned with industry best practices and regulatory requirements (e.g., NIST CSF, ISO 27001, GDPR). Designing and architecting secure IT environments: This may involve network security design, cloud security architecture (AWS, Azure, GCP), and implementing security technologies. Developing and assisting More ❯