Guildford, Surrey, England, United Kingdom Hybrid / WFH Options
Sanderson
security controls catalogue, policies, and procedures aligned with NIST CSF Collaborate with business units to integrate security measures into operations Support compliance activities for frameworks such as Cyber Essentials, PCIDSS, and the Group Information Security Framework Facilitate reviews and updates to ensure controls remain effective against evolving threats Essential skills: Minimum 2 year's experience in information … controls catalogue in a financial services environment (highly desirable) Proven experience in delivering security projects within a federated organisation Desirable skills: Knowledge of NIST CSF, ISO 27001, Cyber Essentials, PCIDSS, DORA Understanding of risk methodologies and data analysis for reporting Strong documentation skills (control matrices, process flows, SOPs) Excellent communication skills for both technical and non-technical More ❯
Chelmsford, Essex, South East, United Kingdom Hybrid / WFH Options
Keystream Group Limited
and assets. You will be responsible for designing and implementing the evolution of security standards, policies, and procedures to ensure ECC meets regulatory, legislative, and operational requirements (e.g., PSN, PCI-DSS, ICO, disaster recovery). Experience Needed: Strong strategic leadership experience across large scale organisations, with the ability to influence and communicate effectively at senior and political levels. … A track record of developing and implementing enterprise-wide cyber and information security strategies aligned with business goals. Extensive knowledge of relevant legal, regulatory, and technical frameworks, including PSN, PCI-DSS, GDPR, and disaster recovery. A passion for innovation, collaboration, and continuous improvement in cyber and information security. Why Join ECC? As Assistant Director Cyber Security, you'll More ❯
on time, within scope, and to a high standard. Specialist Migration Expertise: Oversee the secure migration of card credentials, encryption keys, and other sensitive financial data, ensuring compliance with PCIDSS and relevant regulatory requirements. Card Scheme Migration Processes: Manage migration activities in line with card scheme processes, procedures, and compliance standards. Liaise with scheme representatives to coordinate … reconciliation methodologies. Excellent stakeholder management skills, including board-level engagement. Strong problem-solving ability and resilience under pressure. Desirable Experience in a payments or card-issuing environment. Knowledge of PCIDSS compliance requirements. Familiarity with other card scheme migration processes (Visa, Amex). PRINCE2, PMP, or Agile project management certification. Why Apply? This is an opportunity to join More ❯
on time, within scope, and to a high standard. Specialist Migration Expertise: Oversee the secure migration of card credentials, encryption keys, and other sensitive financial data, ensuring compliance with PCIDSS and relevant regulatory requirements. Card Scheme Migration Processes: Manage migration activities in line with card scheme processes, procedures, and compliance standards. Liaise with scheme representatives to coordinate … reconciliation methodologies. Excellent stakeholder management skills, including board-level engagement. Strong problem-solving ability and resilience under pressure. Desirable Experience in a payments or card-issuing environment. Knowledge of PCIDSS compliance requirements. Familiarity with other card scheme migration processes (Visa, Amex). PRINCE2, PMP, or Agile project management certification. Why Apply? This is an opportunity to join More ❯
Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
Queen Square Recruitment Limited
Application SecurityData Protection & Encryption Kubernetes, Containers, and DevSecOps/MLOps practices SIEM, logging, and monitoring Zero Trust architectures Skilled in applying frameworks such as NIST CSF, ISO 27001, PCIDSS, CSA CCM, NIST AI RMF . Hands-on with tools for vulnerability management, secrets management, CSPM, and CWPP . Relevant certifications strongly preferred (CISSP, CCSP, TOGAF, AWS More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown
initiatives, including migration of legacy applications to cloud-native platforms and adoption of SaaS/PaaS solutions. Understanding of UK financial regulations, GDPR, and industry standards (ISO 27001, NIST, PCIDSS, etc). Experience running risk assessments, threat modelling, and security testing programmes. Ability to engage and influence senior stakeholders, balancing security with commercial and operational priorities. Strong More ❯
Employment Type: Permanent, Part Time, Work From Home
Bristol, Gloucestershire, United Kingdom Hybrid / WFH Options
Hargreaves Lansdown PLC
initiatives, including migration of legacy applications to cloud-native platforms and adoption of SaaS/PaaS solutions. Understanding of UK financial regulations, GDPR, and industry standards (ISO 27001, NIST, PCIDSS, etc). Experience running risk assessments, threat modelling, and security testing programmes. Ability to engage and influence senior stakeholders, balancing security with commercial and operational priorities. Strong More ❯
and blueprints. What You'll Bring Prior and proven experience gained as a Security Architect or in a Technical Cyber Consultant/Engineer role. Expertise in: Security legislation (GDPR, PCIDSS, ICO) Frameworks (ISO 27001, NIST CSF, CIS Controls v8) HMG/NCSC policies and guidance Cloud security (AWS, Azure) Microservice architectures PKI, Cryptography, Privileged Access Management Certifications More ❯
Bristol, Avon, England, United Kingdom Hybrid / WFH Options
Sanderson
Lead roles JSP440, JSP604/453 & JSP490 Working with system secure design MOD/GDS Secure by Design Principles Supplier Chain Assurance and Risks. Security related legislation (e.g. GDPR, PCIDSS, ICO requirements). Security Control Frameworks such as ISO 27001, NIST CSF and CIS Controls v8. HMG, NPSA and NCSC security policies, standards and guidance. Have experience More ❯
Salford, Greater Manchester, North West, United Kingdom Hybrid / WFH Options
AJ BELL BUSINESS SOLUTIONS LIMITED
risk management tools and techniques Experience of security governance and compliance, ideally gained in financial services organisations Demonstrable understanding of Information Security control standards and frameworks e.g. ISO27001, NIST, PCIDSS Awareness and understanding of the Information Security threat landscape Deep understanding of Information Security solutions and controls Experience of Cloud security solutions and standards is highly advantageous More ❯
Bristol, Avon, South West, United Kingdom Hybrid / WFH Options
Sanderson Government and Defence
Lead roles JSP440, JSP604/453 & JSP490 Working with system secure design MOD/GDS Secure by Design Principles Supplier Chain Assurance and Risks. Security related legislation (e.g. GDPR, PCIDSS, ICO requirements). Security Control Frameworks such as ISO 27001, NIST CSF and CIS Controls v8. HMG, NPSA and NCSC security policies, standards and guidance. Have experience More ❯
Croydon, London, United Kingdom Hybrid / WFH Options
Gold Group Limited
to ensure security is embedded in all new and existing applications, systems, and network infrastructure Risk Management & Compliance: Ensure compliance with industry regulations and data protection laws (e.g. GDPR, PCI-DSS) Continuous Improvement: Stay informed of the latest cybersecurity threats, trends, and technologies, recommending and implementing improvements to enhance security defences Change Management: Establish and lead a Change More ❯
Hull, North Humberside, England, United Kingdom Hybrid / WFH Options
Heron Foods
incident response, containment, and recovery activities. Oversee vulnerability management: assessing risks, tracking remediation, and validating fixes. Support forensic investigations and evidence handling when needed. Contribute to compliance activities including PCIDSS evidence gathering and audit readiness. Deliver security awareness training, phishing simulations, and staff engagement campaigns. Provide local insights to the Group Information Security team to strengthen overall … experience: Experience working in security operations, SOC, or incident response. Knowledge of SIEM tools, vulnerability management, and log analysis. Understanding of security frameworks such as ISO 27001, NIST, or PCI DSS. Strong communication skills to engage with IT teams, business stakeholders, and non-technical staff. Ability to work independently at Heron Foods while remaining aligned to Group Information Security. More ❯
North Ferriby, North Humberside, North East, United Kingdom Hybrid / WFH Options
Heron Foods
incident response, containment, and recovery activities. Oversee vulnerability management: assessing risks, tracking remediation, and validating fixes. Support forensic investigations and evidence handling when needed. Contribute to compliance activities including PCIDSS evidence gathering and audit readiness. Deliver security awareness training, phishing simulations, and staff engagement campaigns. Provide local insights to the Group Information Security team to strengthen overall … experience: Experience working in security operations, SOC, or incident response. Knowledge of SIEM tools, vulnerability management, and log analysis. Understanding of security frameworks such as ISO 27001, NIST, or PCI DSS. Strong communication skills to engage with IT teams, business stakeholders, and non-technical staff. Ability to work independently at Heron Foods while remaining aligned to Group Information Security. More ❯
Borehamwood, Hertfordshire, England, United Kingdom Hybrid / WFH Options
Elysium Healthcare
informed on evolving frameworks, regulatory changes, and best practice in information security. It would be great if you also bring: Familiarity with broader regulatory frameworks such as ISO 27001, PCIDSS, or ICO guidance. Experience embedding compliance into projects, change programmes, and supplier contracts. This is a remote-based role, offering flexibility while ensuring close collaboration with colleagues More ❯
Excellent presentation, communication and collaboration skills - able to build trust with engineers and business stakeholders Preferred requirements AWS Certification (e.g., Solutions Architect Associate) Experience with ISO27001 and/or PCI-DSS compliance Exposure to hybrid cloud/migration from on-prem to cloud environments Familiarity with observability strategy or platform standardization projects Guidelines for Hybrid/Home Office More ❯
You'll have a sound understanding of cyber and information security, including frameworks like NIST and ISO IEC 27002:202. It will be great if you also know about PCI-DSS V4.0 as well. Clear Communication -You'll be able to discuss these with technical and non-technical stakeholders in a way which is accessible and understood. Threat More ❯
Newport, Gwent, Wales, United Kingdom Hybrid / WFH Options
Intellectual Property Office
team at the Intellectual Property Office. Playing a key part in an established team, the individual is responsible for ensuring the continued compliance with key security standards, such as PCI, ISO27001, secure by design, GovAssure etc. It is essential that this role ensures that security architecture alongside compliance are understood and therefore the role will include championing security by … but are not limited to: Ensure security architecture aligns with wider Gov security policies and frameworks, legal frameworks, industry regulations and best practise (e.g ISO 27001, NCSC Standards, GDPR, PCIDSS, GovAssure, Secure by Design). Support the secure by design champion in building awareness and understanding of secure by design framework across DDaT. Manage the security architecture More ❯
Salford, Greater Manchester, North West, United Kingdom Hybrid / WFH Options
Gerrard White
to business and technology audits. The role will also help provide ongoing assurance that digital systems and data are safe and secure. Key Accountabilities & Responsibilities: Be an SME for PCIDSS and contribute to and ensure compliance governance to security standards. Contribute to business and technology audits. Engagement with 3rd party partners as a SME and to ensure … in projects. Skills, Experience and Knowledge: Proven experience of IT GRC and Information/Cyber security Proven experience of risk and control management Proven experience of standards including ISO27001, PCI, GDPR/DPA & NIST Communication of complex ideas clearly in a non-technical way Strong stakeholder and 3rd party management experience Strong communication and collaboration Confident at working with More ❯
Transformation: Ensure successful delivery of network upgrades, capacity enhancements, and new connectivity services while maintaining zero disruption to production services. Governance & Compliance: Implement operational processes aligned with ISO 27001, PCIDSS, and other relevant compliance frameworks. Cost & Budget Ownership: Optimise network OPEX and vendor spend through strategic negotiations, vendor consolidation, and improved service efficiency. Automation & Monitoring: Drive adoption More ❯
Market Harborough, Leicestershire, East Midlands, United Kingdom Hybrid / WFH Options
4C Resourcing
Lead and deliver client engagements across governance, risk and compliance (GRC), including audits, assessments and improvement plans aligned to frameworks such as ISO/IEC 27001, NCSC CAF, and PCI DSS. Lead independent assurance , review and test security policies, procedures and controls; identify gaps; and recommend pragmatic remediation strategies. Develop and present security strategies that enhance resilience and reduce … near term). Significant experience in cyber security consulting or assurance, ideally within the public sector. Deep knowledge of GRC frameworks and standards ( e.g. CAF, ISO/IEC 27001, PCIDSS). Strong client-facing skills , able to communicate complex issues clearly to technical and non-technical audiences. Proven track record of delivering high-quality outputs on time More ❯
South East London, London, United Kingdom Hybrid / WFH Options
TEN10 SOLUTIONS LIMITED
Understanding of IAM, WAF, and KMS. Experience implementing best practices for securing data, ensuring compliance with industry standards and regulations. Bonus points for experience with a compliance framework (ISO27001, PCI-DSS). I nfrastructure-as-Code: Experience with Terraform, CloudFormation, CDK or equivalent tools. Scripting & Automation: Skills in Python, Ansible, Bash, Groovy, Powershell, or similar. Bonus points if More ❯
capability for integrations, data quality, reporting, and performance optimisation Compliance & Data Protection Act as the lead on GDPR and data protection compliance Ensure adherence to security standards such as PCIDSS Team Management & Training Manage the Systems Administrator and IT Assistant Support staff onboarding and ongoing training on IT systems Oversee documentation and guides to ensure smooth IT More ❯
Familiar with C#/.NET ecosystems with web and/or Blazor front-ends AI/ML deployment experience with AI infrastructure orchestration Third-party SaaS integration support experience PCIDSS Mentoring junior DevOps staff Benefits 33 days holiday (including bank holidays) Personal health cash plan - claim back the cost of things like dentist and optical check ups More ❯
for smarter ways to support our platforms. You ll work closely with DevOps to manage releases, improve helpdesk processes, and keep us aligned with security frameworks like ISO27001 and PCI-DSS. Role: Cloud Support Engineer, Cloud Engineer, Cloud Infrastructure Engineer, Cloud Operations Engineer, Cloud Systems Engineer, Platform Support Engineer Salary: £45k - £55k base + bonus Benefits: 5% pension More ❯