1 to 25 of 145 Remote/Hybrid SOC 2 Jobs

Information Security Lead

Hiring Organisation
Hackajob Ltd
Location
Wallingford, Oxfordshire, South East, United Kingdom
Employment Type
Permanent
hackajob is partnering directly with Dexory to hire for this role. Information Security Lead/ISO27001/SOC/GRC/Location: Wallingford - Oxfordshire (Hybrid) onsite circa 3 days minimum per week Permanent At Dexory, we are transforming the warehousing and logistics industry through data intelligence. Were currently recruiting … Information Security Lead to own and drive our compliance programmes (ISO 27001, SOC 1 Type 2, SOC 2 Type 2), act as the primary responder to customer security due diligence, and build the systems and knowledge base that allow Dexory to scale securely without friction. ...

GRC Engineer

Location
Belfast City District, Northern Ireland, United Kingdom
oriented skills like API integrations, data querying, and control automation. You’ll be a key player in maintaining our compliance posture across frameworks like SOC 2, NIST CSF, and ISO 27001, while also helping modernize how we monitor and evidence controls using platforms like Anecdotes. This role suits … pull evidence out of a data pipeline. What You’ll Do Audits & Framework Management Own or co‐own preparation for and execution of SOC 2 (Type I/II) audits, working directly with external auditors to scope, evidence, and remediate findings Lead or support NIST CSF assessments and ...

Senior Security Engineer

Location
Greater London, England, United Kingdom
security design and architecture reviews, paired with the governance and process work that scales the program. You will partner on customer due‐diligence and SOC 2 evidence and turn security controls into repeatable workflows that fit how the business already works. You will apply that lens across … and DevOps to reduce risk through secure design and simplicity, not just added controls. Governance, Risk & Compliance Partner on customer due‐diligence (DDQ) and SOC 2 Type II evidence gathering, keeping compliance sustainable rather than fire‐drilled. Build repeatable security workflows that embed controls into existing engineering processes ...

Platform Security & Compliance Lead | Southwest, London | Hybrid, Permanent

Location
Greater London, England, United Kingdom
cloud-native. We need someone who is as comfortable getting hands-on with IAM, infrastructure and CI/CD as they are leading a SOC 2 programme or answering an enterprise customer’s security questions. What you’ll own: The security posture of the production AWS environment, including … and software supply-chain security, including dependencies, GitHub Actions, build provenance and container security Security monitoring, penetration testing, incident response and remediation The SOC 2 programme, including controls, evidence gathering, audits and ongoing improvements UK GDPR and PECR compliance, including DPAs, sub-processors, processing records and privacy requirements ...

Enterprise Infrastructure Engineer

Hiring Organisation
Boku
Location
London, United Kingdom
Salary
£ 80 K
decisions align with a cloud-first strategy.Partner with Security to harden the Microsoft 365 tenant and infrastructure estate against relevant compliance frameworks (ISO 27001, SOC 2, DORA).Collaboration & EscalationWork closely with senior infrastructure engineers on infrastructure design decisions, escalating complex troubleshooting and design questions as needed.Change Control & DocumentationEnsure … through Intune and Kandji are compliant, patched, and enrolled to policy.The Microsoft 365 tenant and wider SaaS estate meet relevant compliance frameworks (ISO 27001, SOC 2, DORA).Infrastructure changes are documented, tested, and follow IT change control processes without exception.Technical documentation, runbooks, and architecture records are kept current ...

Head of Security

Location
Greater London, England, United Kingdom
and close the coverage gaps where some products are today outside the standard tooling. Governance, risk and compliance and vendor management Own ISO 27001, SOC 1, SOC 2 and PCI DSS compliance, the audit calendar, the compliance automation platform and the relationship with our auditors. Work with … software or SaaS company serving regulated enterprise customers, and of facing those customers on security matters. Working knowledge of ISO 27001 and SOC 2, and experience of being accountable for audits and certifications. PCI DSS experience is an advantage. Practical understanding of cloud security on AWS and Azure ...

Technical IT Manager/Leader

Location
Greater London, England, United Kingdom
meeting spaces, video conferencing and AV technology remain fully operational Troubleshoot network, hardware, software and endpoint issues Support IT security and compliance requirements, including SOC 2 and ISO 27001 Assist with technology projects and initiatives, including M&A integrations What we’re looking for Experience managing IT operations … managing endpoints and Mac environments Knowledge of core networking principles and troubleshooting Experience with conference room, Zoom/Teams and AV technology Experience with SOC 2 Type 2 and/or ISO 27001 compliance frameworks Strong organisational and project management skills Comfortable working with users at every ...

Senior Cloud Security Engineer (GCP) - Engine by Starling

Hiring Organisation
Starling Bank
Location
London, United Kingdom
Salary
£ 80 K
and Access Transparency, relevant to deploying per-market for different banks' regulatorsHands-on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSSExperience automating security controls and compliance checks against standards and frameworks including SOC 2 ...

Staff Cloud Security Engineer (GCP) - Engine by Starling

Location
Greater London, England, United Kingdom
Access Transparency, relevant to deploying per-market for different banks' regulators Hands-on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSS Experience automating security controls and compliance checks against standards and frameworks including SOC 2 ...

Security & Compliance Lead: ISO27001/SOC Expert – Hybrid

Location
Wallingford, England, United Kingdom
Dexory is transforming warehousing and logistics with data intelligence in the UK. We seek an Information Security Lead to own ISO 27001, SOC 1 Type 2, and SOC 2 Type 2 programmes, and to respond to customer security due diligence across engineering, product and operations. ...

SecOps Platform Engineer

Location
United Kingdom
security, including firewall rules, NSGs, WAFs, and network design. Ensure secure cloud configurations and enforce best practices using Azure-native controls and policies. Compliance & SOC 2 Readiness Lead implementation and validation of security controls aligned with SOC 2 and ISO standards. Document processes and participate … Identity & Access Management (IAM), endpoint security, and cloud-native controls. Experience with Microsoft Intune, Jamf Suite, Conditional Access, DLP, MFA, and compliance policies, including SOC2 and ISO27001. Previously used scripting tools such as PowerShell, Python, Bash, KQL, or SQL. You\'ll stand out from the crowd if you also have ...

Senior Cybersecurity Consultant

Location
Greater London, England, United Kingdom
creating operational friction. Responsibilities Lead penetration testing and vulnerability assessment engagements Design security architectures for cloud-native and hybrid environments Develop security compliance programs (SOC 2, ISO 27001, GDPR) Conduct incident response planning and tabletop exercises Advise C-level executives on security strategy and risk management Requirements 8+ … years in information security with consulting experience Deep expertise in penetration testing, vulnerability management, and threat modeling Knowledge of compliance frameworks: SOC 2, ISO 27001, GDPR, PCI-DSS Experience with cloud security (AWS Security Hub, Azure Defender, or GCP Security Command Center) CISSP, OSCP, or equivalent certification Nice ...

Head of Information Security

Location
Greater London, England, United Kingdom
assessments, and executive reporting for leadership and the board. Lead Compliance & Certifications: Own end‐to‐end audit readiness for enterprise and defense frameworks, including SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800‐53. Partner with Product & Engineering: Embed DevSecOps and secure SDLC practices into … cloud security (AWS/GCP), container isolation, cryptography, and network security. Audit & Compliance Track Record: Proven experience taking a high‐growth technology company through SOC 2 Type II or ISO 27001 certifications from start to finish. Stakeholder Management: Exceptional ability to bridge technical security requirements with business strategy ...

Senior Vulnerability Management Engineer

Hiring Organisation
HCLTech
Location
City of London, London, United Kingdom
Data Center, Network, and Application Infrastructure domains. The role is responsible for scanner architecture and tuning, risk-based prioritisation, integration with patch management and SOC functions, automation of VM workflows, and executive reporting. The engineer acts as the primary SME for vulnerability risk decisions and drives continuous improvement … escalation for L1 analysts; mentor team members and review scan configurations and reports. • Lead or support internal VM audits and contribute to ISO 27001, SOC 2, or regulatory compliance evidence. TECHNICAL SKILLS & KNOWLEDGE • Deep expertise in enterprise VM platforms: Qualys VMDR (including TruRisk), Tenable Security Centre/Tenable.io ...

Cyber Security Consultant

Hiring Organisation
Circle Group
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£70,000
implementation, maintenance and audit preparation. Advise clients against recognised frameworks including ISO 27001, NIST CSF and CIS Controls, as well as supporting SOC 2 and other compliance requirements. Develop and improve security policies, procedures and governance frameworks. Establish and maintain risk registers and support security governance forums. Support … reports and recommendations. Knowledge or experience in areas such as the following would be beneficial: ISO 27001/ISO 27005 NIST CSF CIS Controls SOC 2 NIS2/DORA Risk management and governance Security operations and monitoring Incident response Vulnerability management Cloud security, particularly Microsoft Azure and Microsoft ...

Principal Engineer & Virtual CIO

Hiring Organisation
Advantage Microsystems
Location
Oakland, California, United States
Employment Type
Permanent
Salary
USD Annual
network refreshes, cloud migrations, and M&A integrations Own the technical standards and reference architectures our team deploys against Lead security and compliance initiatives - SOC 2, CMMC/NIST 800-171, HIPAA - including policy development, control implementation, and audit support Escalation and Technical Ownership Serve as the final … similar), PSA platforms (ConnectWise Manage, Autotask, HaloPSA, or similar), documentation systems (IT Glue, Hudu) Compliance Frameworks - working knowledge of at least one of SOC 2, CMMC/NIST 800-171, HIPAA, or PCI Scripting and Automation - PowerShell at a production level; Graph API, Power Automate, or similar ...

Cloud Operations Engineer

Hiring Organisation
Kerridge Commercial Systems
Location
Nottingham, Nottinghamshire, United Kingdom
Salary
£ 70 K
Manage secrets, credentials, and privileged access controls in line with security and governance requirements. Ensure compliance with organisational and regulatory standards, including ISO 27001, SOC 2, GDPR, and related governance requirements. Identify recurring issues, raise problem records, and implement preventative measures to improve service stability and reduce incident … Entra/IAM), patching, vulnerability remediation and safe secrets managementExperience working to service levels (SLAs/SLOs) and within compliance controls (e.g. ISO 27001, SOC 2, GDPR)Willingness to take part in a compensated on-call rota (see on-call policy)Preferred Qualifications and ExperienceAn associate-level cloud ...

Cloud Operations Engineer

Hiring Organisation
Kerridge Commercial Systems
Location
Barnsley, South Yorkshire, United Kingdom
Salary
£ 70 K
Manage secrets, credentials, and privileged access controls in line with security and governance requirements. Ensure compliance with organisational and regulatory standards, including ISO 27001, SOC 2, GDPR, and related governance requirements. Identify recurring issues, raise problem records, and implement preventative measures to improve service stability and reduce incident … Entra/IAM), patching, vulnerability remediation and safe secrets managementExperience working to service levels (SLAs/SLOs) and within compliance controls (e.g. ISO 27001, SOC 2, GDPR)Willingness to take part in a compensated on-call rota (see on-call policy)Preferred Qualifications and ExperienceAn associate-level cloud ...

GRC Pre-Sales Consultant / Solutions Engineer – EMEA

Location
Greater London, England, United Kingdom
demonstrations that showcase how Vanta solves the customer's specific problem, including how Vanta automates and operationalises their GRC programmes across frameworks such as SOC 2, ISO 27001, and HIPAA. Validate the feasibility of standard and semi‐complex integrations and confirm alignment with customer environments, workflows, and architectures. … trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. Now more than ever, making ...

Solutions Engineer (Upmarket, Pre-Sales) - EMEA

Location
Greater London, England, United Kingdom
demonstrations that showcase how Vanta solves the customer's specific problem, including how Vanta automates and operationalises their GRC programmes across frameworks such as SOC 2, ISO 27001, and HIPAA. Validate the feasibility of standard and semi-complex integrations and confirm alignment with customer environments, workflows, and architectures. … trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. Now more than ever, making ...

Senior Security, Trust & Compliance Lead

Location
Royal Leamington Spa, England, United Kingdom
compliance initiatives across cloud-based and regulated environments Driving audit readiness, compliance programs and evidence-based assurance across frameworks such as ISO 27001, GDPR, SOC 2 and GxP Providing leadership on risk management, governance and security strategy Partnering with customers, auditors and key stakeholders on security reviews, assurance … with experience in several of the following areas: Security leadership, governance, risk and compliance (GRC) Cloud security architecture and security strategy ISO 27001, GDPR, SOC 2, GxP, 21 CFR Part 11 or similar regulated frameworks Audit leadership, customer assurance and certification programs Healthcare technology, pharmaceutical, biotechnology or regulated ...

Senior DevOps Engineer (AWS)

Hiring Organisation
Appcast
Location
Remote, UK
metrics and response playbooks that get ahead of incidents before they happen.Lead security-first practices across the infrastructure estate — proactively addressing vulnerabilities and driving SOC 2 compliance.Partner with engineering teams to integrate operational requirements into the development lifecycle and align on architecture decisions.Champion AI adoption within DevOps andand a track record of leading root cause analyses and implementing durable fixes.Proficiency reading Java, Ruby, Bash/Zsh, HCL, Python, and JavaScript.Experience with SOC 2 compliance and security-first infrastructure practices.Comfort with a weekly on-call rotation.Strong candidates may also have:Experience with container and orchestration technologies ...

Head of Information Security

Hiring Organisation
MOO
Location
London, United Kingdom
Salary
£ 80 K
after-action reviews.Plan, facilitate and participate directly in tabletop cyber exercises and live cyber simulations at least quarterly.For any incident classified Severity 1 or 2, act as deputy incident decision-maker, holding delegated authority from the CFO to make time-critical operational decisions.Data Privacy & RegulatoryPartner with Legal … data.Embed Privacy by Design and data minimisation into discovery, design and delivery processes.Own the roadmap towards enterprise assurance frameworks, including UK Cyber Essentials and SOC 2 readiness.Prepare for external audits and assessments and ensure customer security questionnaire responses reflect actual control status.Third-Party & Cloud SecurityEstablish and ...

Information Security Analyst ( ISO 27001 and ISO 27018 )

Location
Greater London, England, United Kingdom
and procedures sharp and our compliance with ISO 27001 and ISO 27018 on point. You’ll get involved in SSAE 18/ISAE 3402 SOC 1 Type 2 and SSAE 18 SOC 2 Type 2 assurance audits, spot opportunities to improve our security controls and … excellent organisational skills. You write clear documentation and reports, and can translate complex requirements for stakeholders at every level You’ll have at least 2 years’ experience in a related role Experience in a regulated industry, familiarity with other information security frameworks and assurance reports, and exposure to Jira ...

Information Security Analyst ( ISO 27001 and ISO 27018 )

Hiring Organisation
Alfa Financial Software
Location
London, United Kingdom
Salary
£ 80 K
and procedures sharp and our compliance with ISO 27001 and ISO 27018 on point. You'll get involved in SSAE 18/ISAE 3402 SOC 1 Type 2 and SSAE 18 SOC 2 Type 2 assurance audits, spot opportunities to improve our security controls and … organisational skills. You write clear documentation and reports, and you can translate complex requirements for stakeholders at every level. You'll have at least 2 years' experience in a related role. Experience in a regulated industry, familiarity with other information security frameworks and assurance reports, and exposure to Jira ...