information security compliance program. Conduct internal audits, third-party risk assessments, and due diligence reviews. Ensure alignment with regulatory and industry standards including ISO27001, NIST, SOX, GDPR, SOC 2, HIPAA, CCPA, LGPD. Collaborate with cross-functional teams across multiple jurisdictions to drive compliance initiatives. Identify gaps in security controls and recommend corrective actions. Maintain and update security policies, procedures, and … compliance, risk management, and audit. Strong understanding of international regulatory frameworks and standards. Hands-on experience with: ISO27001 audits and implementation GDPR compliance NIST cybersecurity framework SOX, SOC 2, HIPAA, CCPA, LGPD Ability to interpret complex regulatory requirements and translate them into actionable controls. Excellent communication and stakeholder engagement skills. Strong analytical and problem-solving capabilities. What We Offer: Competitive More ❯
Birmingham, West Midlands, United Kingdom Hybrid / WFH Options
Hays
information security compliance program. Conduct internal audits, third-party risk assessments, and due diligence reviews. Ensure alignment with regulatory and industry standards including ISO27001, NIST, SOX, GDPR, SOC 2, HIPAA, CCPA, LGPD. Collaborate with cross-functional teams across multiple jurisdictions to drive compliance initiatives. Identify gaps in security controls and recommend corrective actions. Maintain and update security policies, procedures, and … compliance, risk management, and audit. Strong understanding of international regulatory frameworks and standards. Hands-on experience with: ISO27001 audits and implementation GDPR compliance NIST cybersecurity framework SOX, SOC 2, HIPAA, CCPA, LGPD Ability to interpret complex regulatory requirements and translate them into actionable controls. Excellent communication and stakeholder engagement skills. Strong analytical and problem-solving capabilities. What We Offer: Competitive More ❯
as NIST 800-53 r5, NIST CSF2.0, CIS, ISO27K • Designing solutions related to advisory & consulting engagements around regulatory risk & compliances such as DORA, NIS2, GDPR, SOX ITGC, PCI-DSS, HIPAA, Data Privacy, NHS, FFIEC etc. • Develop knowledge base, re-usable components for GRC advisory services. • Responsible for development and enhancements of GRC services, team and delivery capabilities. • Manage local partners … technology risk assessments. ISO 27K, NIST, AI Governance, CIS etc. • Good compliance understanding of industry domains such as BFSI – (SOX, FFIEC, PCI-DSS, BASEL, MAS etc.), Healthcare & Life-sciences – (HIPAA, Hi-Trust, FDA CFR, GxP Compliance), Telecom, Retail, Data Privacy (GDPR, CCPA) Energy & Utilities (NERC, FERC) Information Security (ISO 27000, NIST, CIS) TPRM • Business Resiliency & Cyber Recovery, ZTA • GRC Project More ❯
as NIST 800-53 r5, NIST CSF2.0, CIS, ISO27K • Designing solutions related to advisory & consulting engagements around regulatory risk & compliances such as DORA, NIS2, GDPR, SOX ITGC, PCI-DSS, HIPAA, Data Privacy, NHS, FFIEC etc. • Develop knowledge base, re-usable components for GRC advisory services. • Responsible for development and enhancements of GRC services, team and delivery capabilities. • Manage local partners … technology risk assessments. ISO 27K, NIST, AI Governance, CIS etc. • Good compliance understanding of industry domains such as BFSI – (SOX, FFIEC, PCI-DSS, BASEL, MAS etc.), Healthcare & Life-sciences – (HIPAA, Hi-Trust, FDA CFR, GxP Compliance), Telecom, Retail, Data Privacy (GDPR, CCPA) Energy & Utilities (NERC, FERC) Information Security (ISO 27000, NIST, CIS) TPRM • Business Resiliency & Cyber Recovery, ZTA • GRC Project More ❯
sensitivity labels applied. You will be responsible for ensuring the data security , including encryption and key management. The data will primarily be for the US market, so knowledge of HIPAA or HITRUST is fantastic. However, experience with GDPR and ISO 27001 is also ok. Non-Negotiables BigQuery in-depth use Data security principles and cloud compliance experience Encryption (KMS) , secrets … labelled appropriately. Configure IAM roles, Role-based access controls (RBAC). Segregation of duties to enforce secure, system-level access. Symmetric or asymmetric encryption. Enforce & maintain regulatory compliance under HIPAA compliance standards (US). Prior HIPAA experience is not required – you can read up on this. Support security audits, logging, and monitoring to provide compliance evidence. Advise on best practice More ❯
collaborating with technical and business teams, and supporting security and compliance initiatives within the organization. The position requires development and maintenance of security policies aligned with ISO 27001, GDPR, HIPAA, and OWASP, as well as leading risk assessments and managing the risk register. Key skills and responsibilities, Comprehensive knowledge of ISO 27001, NIST CSF, GDPR, HIPAA, SOC 2, and OWASP … Lead Auditor, and hands-on experience with GRC tools (e.g., Vanta, Drata) are highly desirable. Responsible for developing and maintaining security policies in alignment with ISO 27001, GDPR, HIPAA, and OWASP standards. Lead risk assessments and oversee the management of the organizations risk register. Support efforts to prepare for audits and maintain certification readiness. Collaborate with engineering and operations teams More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Crimson
collaborating with technical and business teams, and supporting security and compliance initiatives within the organization. The position requires development and maintenance of security policies aligned with ISO 27001, GDPR, HIPAA, and OWASP, as well as leading risk assessments and managing the risk register. Key skills and responsibilities, Comprehensive knowledge of ISO 27001, NIST CSF, GDPR, HIPAA, SOC 2, and OWASP … Lead Auditor, and hands-on experience with GRC tools (e.g., Vanta, Drata) are highly desirable. Responsible for developing and maintaining security policies in alignment with ISO 27001, GDPR, HIPAA, and OWASP standards. Lead risk assessments and oversee the management of the organization’s risk register. Support efforts to prepare for audits and maintain certification readiness. Collaborate with engineering and operations More ❯
collaborating with technical and business teams, and supporting security and compliance initiatives within the organization. The position requires development and maintenance of security policies aligned with ISO 27001, GDPR, HIPAA, and OWASP, as well as leading risk assessments and managing the risk register. Key skills and responsibilities, Comprehensive knowledge of ISO 27001, NIST CSF, GDPR, HIPAA, SOC 2, and OWASP … Lead Auditor, and hands-on experience with GRC tools (e.g., Vanta, Drata) are highly desirable. Responsible for developing and maintaining security policies in alignment with ISO 27001, GDPR, HIPAA, and OWASP standards. Lead risk assessments and oversee the management of the organization’s risk register. Support efforts to prepare for audits and maintain certification readiness. Collaborate with engineering and operations More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Crimson
collaborating with technical and business teams, and supporting security and compliance initiatives within the organization. The position requires development and maintenance of security policies aligned with ISO 27001, GDPR, HIPAA, and OWASP, as well as leading risk assessments and managing the risk register. Key skills and responsibilities, Comprehensive knowledge of ISO 27001, NIST CSF, GDPR, HIPAA, SOC 2, and OWASP … Lead Auditor, and hands-on experience with GRC tools (e.g., Vanta, Drata) are highly desirable. Responsible for developing and maintaining security policies in alignment with ISO 27001, GDPR, HIPAA, and OWASP standards. Lead risk assessments and oversee the management of the organization's risk register. Support efforts to prepare for audits and maintain certification readiness. Collaborate with engineering and operations More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Crimson
collaborating with technical and business teams, and supporting security and compliance initiatives within the organization. The position requires development and maintenance of security policies aligned with ISO 27001, GDPR, HIPAA, and OWASP, as well as leading risk assessments and managing the risk register. Key skills and responsibilities, Comprehensive knowledge of ISO 27001, NIST CSF, GDPR, HIPAA, SOC 2, and OWASP … Lead Auditor, and hands-on experience with GRC tools (e.g., Vanta, Drata) are highly desirable. Responsible for developing and maintaining security policies in alignment with ISO 27001, GDPR, HIPAA, and OWASP standards. Lead risk assessments and oversee the management of the organization's risk register. Support efforts to prepare for audits and maintain certification readiness. Collaborate with engineering and operations More ❯
the firm, including General Counsel, Information Security, and Emerging Tech Risk teams, helping to shape best practices and ensure compliance with regulations such as UK/EU GDPR, DORA, HIPAA, and EU AI Act. The role offers a dynamic mix of hands-on risk management, internal auditing, and strategic input into global processes. It’s ideal for someone with a … General Counsel on data sourcing and best practice Ideal Profile: 2–5 years’ experience in data protection, risk, or compliance Strong working knowledge of UK/EU GDPR, DORA, HIPAA, and ISO27001 Experience in professional services (law firm experience is a plus) Confident stakeholder engagement and communication skills *Visa sponsorship is not available for this position More ❯
the firm, including General Counsel, Information Security, and Emerging Tech Risk teams, helping to shape best practices and ensure compliance with regulations such as UK/EU GDPR, DORA, HIPAA, and EU AI Act. The role offers a dynamic mix of hands-on risk management, internal auditing, and strategic input into global processes. It’s ideal for someone with a … General Counsel on data sourcing and best practice Ideal Profile: 2–5 years’ experience in data protection, risk, or compliance Strong working knowledge of UK/EU GDPR, DORA, HIPAA, and ISO27001 Experience in professional services (law firm experience is a plus) Confident stakeholder engagement and communication skills *Visa sponsorship is not available for this position More ❯
the firm, including General Counsel, Information Security, and Emerging Tech Risk teams, helping to shape best practices and ensure compliance with regulations such as UK/EU GDPR, DORA, HIPAA, and EU AI Act. The role offers a dynamic mix of hands-on risk management, internal auditing, and strategic input into global processes. It’s ideal for someone with a … General Counsel on data sourcing and best practice Ideal Profile: 2–5 years’ experience in data protection, risk, or compliance Strong working knowledge of UK/EU GDPR, DORA, HIPAA, and ISO27001 Experience in professional services (law firm experience is a plus) Confident stakeholder engagement and communication skills *Visa sponsorship is not available for this position More ❯
the firm, including General Counsel, Information Security, and Emerging Tech Risk teams, helping to shape best practices and ensure compliance with regulations such as UK/EU GDPR, DORA, HIPAA, and EU AI Act. The role offers a dynamic mix of hands-on risk management, internal auditing, and strategic input into global processes. It’s ideal for someone with a … General Counsel on data sourcing and best practice Ideal Profile: 2–5 years’ experience in data protection, risk, or compliance Strong working knowledge of UK/EU GDPR, DORA, HIPAA, and ISO27001 Experience in professional services (law firm experience is a plus) Confident stakeholder engagement and communication skills *Visa sponsorship is not available for this position More ❯
london (city of london), south east england, united kingdom
Taylor Root
the firm, including General Counsel, Information Security, and Emerging Tech Risk teams, helping to shape best practices and ensure compliance with regulations such as UK/EU GDPR, DORA, HIPAA, and EU AI Act. The role offers a dynamic mix of hands-on risk management, internal auditing, and strategic input into global processes. It’s ideal for someone with a … General Counsel on data sourcing and best practice Ideal Profile: 2–5 years’ experience in data protection, risk, or compliance Strong working knowledge of UK/EU GDPR, DORA, HIPAA, and ISO27001 Experience in professional services (law firm experience is a plus) Confident stakeholder engagement and communication skills *Visa sponsorship is not available for this position More ❯
on their timelines. Become a product expert on Vanta and how our platform can be used to improve security posture through our compliance offerings (SOC 2, ISO 27001, GDPR, HIPAA, USDP and Custom Frameworks), Trust Reports, and Risk Management solution. Provide insightful technical answers and recommend the most efficient way for customers to achieve compliance using our platform while leveraging … vision to restore trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAAand ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. Now more than ever, making security continuous-not just a point-in-time check More ❯
book of business Become a product expert on Vanta and how our platform can be used to improve security posture through our compliance offerings (SOC 2, ISO 27001, GDPR, HIPAA, USDP and Custom Frameworks), Trust Reports, and Risk Management solution. Guide implementation, configuration, and optimization of Vanta Trust Management Platform Provide professional advice on security best practices and compliance standards … vision to restore trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAAand ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged. Now more than ever, making security continuous-not just a point-in-time check More ❯
PAM Consultant - London Please Note: Due to the nature of client work you will be undertaking, you will need to be willing to go through a Security Clearance process as part of this role, which requires 5+ years UK address More ❯
or targets. Enter accurate and appropriate documentation of services within timeframe required. Maintain confidentiality of sensitive records and treatment information, client files and protected health information in compliance with HIPAA, laws, rules and regulations, and established procedures. Maintain regular and reliable physical on-site attendance. Regular attendance, dependability, and promptness are required for the scheduled work day 100% of the … of the IDD diagnosis and related conditions Ability to conduct meetings and trainings. Ability to locate the diagnostic codes that are associated with IDD and related conditions. Knowledge of HIPAAand ability to protect confidentiality. Effective multi-tasking skills. Good organizational skills. Welcoming, positive behavior. Ability to express self clearly and effectively, orally and in writing. Effective time management skills. More ❯
IP strategy, including trademarks, patents, licensing, and open-source compliance. Data Privacy Compliance: Advising on data privacy and data protection regulations across multiple jurisdictions, including the US (CCPA, CPRA, HIPAA), EU (GDPR), and other international laws. Cross-functional Collaboration: Providing legal advice to and working closely with teams across Sales, Marketing, HR, Engineering, and Product to align legal support with … terms. Skills & Experience Needed: 5+ years of in-house legal experience, preferably at a SaaS or technology company. Strong knowledge of privacy and data protection laws, including CCPA, CPRA, HIPAA, GDPR, and other international regulations. Expertise in managing commercial tech transactions, including B2B licensing, SaaS agreements, and strategic partnerships. Familiarity with open-source licensing models and compliance. A proven ability More ❯
Role - Principal Consultant Technology - Data Privacy Consulting Location - UK Business Unit - DNA Compensation - Competitive (including bonus) Infosys is seeking Consultant (Data Privacy SME) for its DNA Data Governance Unit. In this role, you will be part of an intrapreneurship andMore ❯
We are more than a health system. We are a belief system. We believe wellness and sickness are both part of a lifelong partnership, and that everyone could use an expert guide. We work hard, care deeply and reach further More ❯
change? Do you thrive at the intersection of backend and frontend development? We’re looking for a versatile Fullstack Software Engineer to help scale the core systems of our HIPAA-compliant no-code automation platform that’s transforming healthcare operations. 🛠 What You’ll Do Design and scale core systems like our workflow engine, AI Copilot, and APIs Build end-to … Enhance automation and AI-driven capabilities for complex use cases Help evolve our SDK and CLI tools for secure third-party integrations Optimize for security, fault tolerance, and performance (HIPAA-compliant) Collaborate closely with product, design, and customer-facing teams ✅ What You’ll Bring Strong coding skills (ideally in TypeScript, but we value adaptability over stack-specific experience) Proven experience More ❯
change? Do you thrive at the intersection of backend and frontend development? We re looking for a versatile Fullstack Software Engineer to help scale the core systems of our HIPAA-compliant no-code automation platform that s transforming healthcare operations. #128736; What You ll Do Design and scale core systems like our workflow engine, AI Copilot, and APIs Build end … Enhance automation and AI-driven capabilities for complex use cases Help evolve our SDK and CLI tools for secure third-party integrations Optimize for security, fault tolerance, and performance (HIPAA-compliant) Collaborate closely with product, design, and customer-facing teams What You ll Bring Strong coding skills (ideally in TypeScript, but we value adaptability over stack-specific experience) Proven experience More ❯
change? Do you thrive at the intersection of backend and frontend development? We're looking for a versatile Fullstack Software Engineer to help scale the core systems of our HIPAA-compliant no-code automation platform that's transforming healthcare operations. What You'll Do Design and scale core systems like our workflow engine, AI Copilot, and APIs Build end-to … Enhance automation and AI-driven capabilities for complex use cases Help evolve our SDK and CLI tools for secure third-party integrations Optimize for security, fault tolerance, and performance (HIPAA-compliant) Collaborate closely with product, design, and customer-facing teams What You'll Bring Strong coding skills (ideally in TypeScript, but we value adaptability over stack-specific experience) Proven experience More ❯