Job Title: GRC Security Consultant (ISO27001 Specialist) Contract Duration: 3 Months Location: Remote IR35: Outside IR35 Role Overview We are seeking an experienced GRC Security Consultant to support a project updating the client's ISO27001 framework from the 2013 version … a comprehensive gap analysis, implement the required controls, and ensure all documentation aligns with the updated standard. This role requires deep knowledge of ISO27001 and a hands-on approach to governance, risk, and compliance. Key Responsibilities Perform a detailed gap analysis between ISO27001:2013 and ISO27001:2022. Design and implement required controls to achieve compliance with the updated standard. Update and create all necessary policies, procedures, and documentation to reflect ISO27001:2022 requirements. Ensure the Information Security Management more »
Fairfax, Virginia, United States Hybrid / WFH Options
USmax Corporation
Manager to join our corporate team. This role will report to the CFO and manage the corporate IT function, corporate Quality Management Systems (QMS /ISO/ CMMI), and other operational support. Duties and Responsibilities: Corporate IT systems management, administration, and user support, including Ensuring systems … 27001: 2013 CMMI-SVC Level 3 Leads QMS activities, including internal meetings and correspondence Maintains QMS documentation Responsible for internal QMS /ISO/ CMMI audits, and, Responsible for successful external QMS /ISO/ CMMI audits. Provide other … a related field preferred. IT certifications preferred. Quality management certifications preferred. Security Clearance Requirements: None, but U.S. citizenship required for facility access. Work Location / Schedule: Hybrid work schedule; 2 days onsite in Fairfax, VA, and 3 days remote (subject to change). Travel Requirements: None. About USmax USmax more »
sharing sessions. Champion continuous process improvement culture, embedding best practices and ways of working across the organisation. Drive efficiency through the automation of common / frequent internal processes. Ensure all work is completed within budget and aligned with business planning, while managing costs efficiently to maximize savings. Contribute to … e.g. server upgrades, network enhancements, migration to Azure.) Manage other internal IT projects as needed (e.g. technology modernisation, security, operational resilience, ISO/IEC27001 programme of work). Develop the IT service model, catalogue and the end-to-end ticketing process that … for Cybersecurity to update our systems and services to be best in class for passive and active protection, including firewalls, antivirus, threat monitoring, spam / phishing Develop and implement Information Technology and Security policies, procedures, and protocols to ensure company's IP are secured, and kept up-to-date more »
sharing sessions. Champion continuous process improvement culture, embedding best practices and ways of working across the organisation. Drive efficiency through the automation of common / frequent internal processes. Ensure all work is completed within budget and aligned with business planning, while managing costs efficiently to maximize savings. Contribute to … e.g. server upgrades, network enhancements, migration to Azure.) Manage other internal IT projects as needed (e.g. technology modernisation, security, operational resilience, ISO/IEC27001 programme of work). Develop the IT service model, catalogue and the end-to-end ticketing process that … for Cybersecurity to update our systems and services to be best in class for passive and active protection, including firewalls, antivirus, threat monitoring, spam / phishing Develop and implement Information Technology and Security policies, procedures, and protocols to ensure company’s IP are secured, and kept up-to-date more »
Ely, Cambridgeshire, East Anglia, United Kingdom Hybrid / WFH Options
GRC International Group Plc
detailing the assessment findings, including security gaps, and assisting inidentifying solutions to improve the clients security posture. Performing comprehensive audits such as PCI DSS, ISO27001/ 27002, ISO27017 / 18, CCM, and SWIFT Security for IT Governance clients. Completing PCI DSS Gap Assessments, Risk Assessments, Third Party reviews … variety of activities supporting business development / sales team by answering operational and technical questions related to areas, including PCI DSS, SWIFT CSF, ISO27001/ 27002, and Cloud compliance assessments (ISO27017 / 18, CCM). The ideal candidate will have: A minimum 2years professional experience with sufficient … Firewalls, Antivirus Solutions, encryption technologies and software development life cycles It would be desirable if you had: Experiencedelivering classroom training in PCI-DSS and / or ISO27001/ SOC2 Knowledge about PCI DSS and all applicable PCI SSC published documents. Experience conducting gap more »
detailing the assessment findings, including security gaps, and assisting inidentifying solutions to improve the clients security posture. Performing comprehensive audits such as PCI DSS, ISO27001/ 27002, ISO27017 / 18, CCM, and SWIFT Security for IT Governance clients. Completing PCI DSS Gap Assessments, Risk Assessments, Third Party reviews … variety of activities supporting business development / sales team by answering operational and technical questions related to areas, including PCI DSS, SWIFT CSF, ISO27001/ 27002, and Cloud compliance assessments (ISO27017 / 18, CCM). The ideal candidate will have: A minimum 2years professional experience with sufficient … Firewalls, Antivirus Solutions, encryption technologies and software development life cycles It would be desirable if you had: Experiencedelivering classroom training in PCI-DSS and / or ISO27001/ SOC2 Knowledge about PCI DSS and all applicable PCI SSC published documents. Experience conducting gap more »
Northampton, Northamptonshire, East Midlands, United Kingdom Hybrid / WFH Options
Novacroft
week. The main focus of this role is:- To support, design, update and lead on network design & network-related aspects of existing systems Deploy / configure / Maintain Linux estate, Ansible and associated new projects. Deploy / Configure / Maintaine Cisco switches and Cisco WAF Deploy … / Configure / Maintaine Forigate firewalls Intune Azure Networking, firewalls MFA and Entra Sync SSL Certificates DHCP & DNS Private & public Experience in Google workspace. Cyber security Working closely with the 3rd Line Server Team Leader in developing Novacrofts security stance through examining, testing and if approved, deploying leading … rota ensuring support to troubleshoot or address out-of-hours network outages that may arise. Willingness to work outside regular business hours if projects / business needs arise - remunerated This is a hybrid role, based at the Brixworth, Northampton office 2-3 days per week. Technical skills TCP /more »
IT Support / Security / Azure / Active Directory /ISO Job Description: Lead Support Engineer Location: London - Hybrid Company: Financial Services Salary: up to £65,000 Position Overview: We are seeking a highly skilled and motivated Lead Support Engineer to join our team. … provide guidance to the support team. Active Directory Administration: Lead the management of Active Directory (AD) services, including configuration, Group Policy management, and user / group administration. Ensure seamless integration of on-premises AD with Azure AD and maintain synchronization. Proactively identify and mitigate risks related to AD infrastructure. … documentation for processes, procedures, and incident resolution. Experience & Knowledge Essential: 3+ years experience in a senior operations role. Expertise in Microsoft Azure , Active Directory / Entra , Defender , Sentinel , Exchange , and Intune . Proficiency in M365 Office Suite administration and support Experience with Service Management Software Proven experience in deploying more »
Role Overview As an Azure Solutions Architect / DevOps Engineer , you will be a key player in shaping, securing, and scaling the infrastructure. You will solve complex infrastructure challenges by designing and implementing solutions that are robust, secure, and scalable . While Kubernetes on Azure (AKS) will be central … cluster management—you’ll help design systems, improve workflows, and ensure platform readiness for demanding AI-driven workloads. You will collaborate closely with ML / AI teams and Research Engineers , enabling their workflows by delivering reliable infrastructure, optimised pipelines, and secure environments. Additionally, you will play a pivotal role … IaC) : Use tools like Terraform, Bicep, or ARM templates to automate and document infrastructure deployments in a repeatable, auditable way. Build and Maintain CI / CD Pipelines : Develop and manage CI / CD workflows to support APIs, general services, and internal tools, enabling reliable and automated delivery. Collaborate more »
Greater Bristol Area, United Kingdom Hybrid / WFH Options
Procentia - Pensions Software Solutions
with the organisations business objectives. As directed by the Risk and Compliance Manager, you will be the point of contact to manage Improvement Plans / Remedial Action Plans, ensuring reviewers are aware and complete corrective action plans. With the input from Risk and Compliance Manager you guide and advise … System (ISMS) with relevant business areas. In partnership with the Risk & Compliance Manager, support or co-ordinate the ISO27001/ SOC 2 and other security audit programs and take specific ownership of actions resulting from external audit and compliance activity – facilitate interaction between the … compliance. Communicate and provide feedback to SMEs to close compliance gaps where identified. Support or co-ordinate regular ISO27001/ SOC 2 and other security internal audits to ensure adherence. Administer the company risk register and work risk owners to ensure risks are periodically more »
network telemetry technologies. Providing support to members of the wider Operations team as required. Support & maintain the company objectives of ISO 9001 / 18001 /27001 accreditation. Key Skills and Experience: 3 - 5 years of experience on a service provider network in Operations, Engineering … operational experience with carrier-class routers, console servers & switches, (experience with Juniper and Cisco required). Excellent knowledge of L2 & L3 routing protocols, (IPv4+IPv6 / BGP / ISIS / VPLS / IP VPN / MPLS / QinQ / ELINE) and good understanding of … culture. Our employees are driven and committed, with many options to connect and engage in our inclusive environment. Zayo Europe is an Equal Opportunity / Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to age, race, colour, religion, sex, sexual orientation, gender identity, national more »
support new software and hardware such as PCs, laptops, tablets, and other mobile devices, ensuring the Asset Register is kept accurate. • Maintain existing hardware / software, including installation and deployment of updates. • Offer training and advice to staff on the use of Feedback Medical's IT systems (e.g., Microsoft … knowledge base articles. • Adhere to GDPR requirements and ensure compliance with patient confidentiality requirements, such as the NHS Data Security and Protection Toolkit. Experience / Requirements Technical Skills: • 5+ years in a similar role with a strong track record. • Extensive experience with Microsoft 365 and Entra ID, including configuration … skills (e.g., HTML, SQL, PowerShell, JSON). • Familiarity with server virtualisation technologies (e.g., VMware, Hyper-V). • Strong understanding of networking concepts (e.g., TCP / IP, DNS, DHCP). • Advanced end-user support for common hardware, including PCs, laptops, tablets, and mobile devices (e.g., Android, iOS). • Experience with more »
City of London, London, Finsbury Square, United Kingdom Hybrid / WFH Options
ARM
GRC consultant Location: London / Hybrid Salary: Up to £85,000 DOE We're looking for a GRC consultant to come aboard and use your background in Governance, Risk & Compliance, you will help, Governance : Direct, oversee, design, implement, or operate within the set of multi-disciplinary structures, policies, procedures … and Procedure Management : Direct, develop, or maintain organisational cyber and information security policies, standards, and processes, using recognised standards (e.g., the ISO/IEC 27000 family, NIST CSF) where appropriate. Apply recognised cyber and information security standards and controls within an organisation, programme, project, or … following fields of expertise: Strong understanding of security governance, risk, and compliance frameworks such as ISO27001, NIST 800-53 / CSF, NIS / NIS2, DORA, UK CNI / OT / IIOT compliance. Hands-on experience building credibility with external stakeholders, including more »
what is possible for the role. Role Responsibility Analyze and deliver solutions and ensure integration requirements align with best practice and policies for projects / BAU works involving IT systems. Hands-on skill to help deliver Design, Build, Test and also to lead / review the works delivered … integration-related topics, information, and knowledge of the integration technologies, platforms, and architecture. Own and manage integration architecture-related artefacts (integration inventory, integration architecture / design, guidelines, integration patterns). Closely work with support / service team, 3rd parties to monitor integration-related issues and lead resolution in … audit, and regulatory initiatives. Reinforce security rules and escalate where risky activity is detected. Manage the schedule & timeline of the activities across multiple systems / regions, assess and avoid conflicts, streamline the work efforts, and communicate with relevant parties. Document processes, procedures, and plans, including changes, upgrades, and new more »
Holly Springs, North Carolina, United States Hybrid / WFH Options
Amgen
or contribute to business cases and presentations on information security technologies of interest to Amgen, continuously improving information security technologies, processes, and services. Lead / support Incident response on security incidents, including contributing to mock security incident exercises. What we expect of you We are all different, yet we … professional we seek is a type of person with these qualifications. Basic Qualifications: Doctorate degree, OR Masters degree and 2+ years of Information Security / Technology and / or Engineering experience OR Bachelors degree and 4+ years of Information Security / Technology and / or Engineering … experience OR Associates degree and 8+ years of Information Security / Technology and / or Engineering experience OR High school diploma / GED and 10+ years of Information Security / Technology and / or Engineering experience Preferred Qualifications: Strong knowledge of Fortinet UTM /more »
Billingham, County Durham, North East, United Kingdom Hybrid / WFH Options
Exposed Solutions
operational security, and environmental sustainability. Key Responsibilities: Develop, implement, and maintain quality assurance policies and systems. Ensure compliance with relevant quality standards (e.g., ISO 9001, Six Sigma). Oversee the development and enforcement of security policies, including data security and physical security measures. Ensure compliance with relevant security … frameworks (e.g., ISO27001, GDPR, etc.). Develop and manage the environmental management system (EMS) in line with relevant standards (e.g., ISO 14001). Ensure compliance with environmental regulations, permits, and reporting requirements. ABOUT YOU Skills and Competencies A strong understanding of integrated management … systems (IMS) and relevant regulatory frameworks (ISO 9001, ISO27001, ISO 14001). Experience conducting internal and external audits for quality, security, and environmental compliance. Education: A higher education course at UK level 4 or above in any related field such as more »
Cardiff, Wales, United Kingdom Hybrid / WFH Options
Hays Technology
IT operations align with regulatory standards and organisational goals. Key areas will include strategic planning, incident response and integrating compliance frameworks (e.g. GDPR, ISO27001) to protect critical systems. Your new role You will be responsible for developing risk management processes, crisis plans and vendor oversight … overseeing security measures, incident responses and network security enhancements, including Fortinet solutions. What you'll need to succeed Certifications; CRISC, CISA, CISM, CISSP, ISO27001 Lead Auditor, ISO Risk Manager or equivalent Strong knowledge of regulatory requirements (e.g. GDPR, ISO27001 … days annual leave + bank holidays -Flexible hybrid working model after first 6 months -Industry leading training -Employee Assistance Program - free 24 / 7 confidential helpline (domestic, financial, legal, health support etc) -High street retail discount scheme -Staff benefits, wellbeing and recognition platform -Free on site parking -Friendly and more »
Manchester Area, United Kingdom Hybrid / WFH Options
bet365
practical knowledge of application security, specifically focused on network infrastructure and network engineering. Strong knowledge of ITIL principles and IT security governance frameworks ISO27001, NIST, PCI DSS, CIS Controls and benchmarks. Splunk ES practical experience is essential. Complete understanding and practical security implementation experience in … applying to us you are agreeing to share your Personal Data in accordance with our Recruitment Privacy Policy which can be found at https: // content001.bet365.com / Careers / Documents / privacypolicy.pdf more »
and training investment to get your PCI QSA certification! The ideal candidate will have a broad range of cyber risk advisory skills (PCI DSS, ISO27001, GDPR, Data Privacy & Risk Assessments) and has already achieved ONE certification from List A AND ONE certification from List B to be able to sit … the PCI QSA exam. List A: Certified Information Systems Security Professionals (CISSP) Certified Information Security Manager (CISM) ISO27001 Lead Implementer List B: Certified Information Systems Auditor (CISA) ISO27001 Lead Auditor As a Senior / Managing Consultant you will be leading and delivering on a diverse range of clients across … training budget on top of your package so you can obtain the most relevant and industry-recognised Cyber Security Certifications!! Responsibilities of the Senior / Manager Security Consultant Delivery on client projects supporting from a governance, risk and compliance (GRC) perspective against regulations, standards and frameworks such as but more »
Cardiff, Wales, United Kingdom Hybrid / WFH Options
Hays
IT operations align with regulatory standards and organisational goals. Key areas will include strategic planning, incident response and integrating compliance frameworks (e.g. GDPR, ISO27001) to protect critical systems. The role responsibilities: You will act as the Information Security SME on all things GRC and InfoSec. … someone who’s currently leading in a similar role but would like a new challenge or environment. Certifications such as CRISC, CISA, CISM, ISO27001 Lead Auditor, or equivalent will be beneficial, but not essential. However, the experience of having performed a similar role will be … be fully remote, nor can the company offer sponsorship. 28 days annual leave + bank holidays. Industry leading training Employee Assistance Program - free 24 / 7 confidential helpline (domestic, financial, legal, health support etc) High street retail discount scheme Staff benefits, wellbeing and recognition platform Free on-site parking more »
methodologies such as SABSA and TOGAF Knowledge and understanding of UK government protective marking standards and industry standards, including PCI-DSS, ISO/IEC27001, NIST, CIS, etc. Awareness of common exploits and vulnerabilities and how these may be prevented Previous hands-on more »
West Midlands, United Kingdom Hybrid / WFH Options
Eviden Technology Services Limited
methodologies such as SABSA and TOGAF Knowledge and understanding of UK government protective marking standards and industry standards, including PCI-DSS, ISO/IEC27001, NIST, CIS, etc. Awareness of common exploits and vulnerabilities and how these may be prevented Previous hands-on more »
Security Analyst Manchester / Hybrid Our client is a dynamic and growing insurance organisation committed to ensuring the security of information systems and safeguarding sensitive data. As part of their ongoing efforts to enhance our security posture, we are looking for a skilled Security Analyst to join the team … The ideal candidate will have hands-on experience in security controls, day-to-day security operations, patch management, documentation, and an understanding of ISO27001 standards. You will work closely with various teams to ensure that security best practices are implemented and adhered to across the … security processes, incidents, and improvements to maintain a robust security posture and support compliance efforts. * Support the implementation and ongoing maintenance of the ISO27001 Information Security Management System (ISMS). * Conduct regular security assessments, vulnerability scans, and remediation activities. * Collaborate with cross-functional teams to more »
Washington, Washington DC, United States Hybrid / WFH Options
MAGNUS Management Group
Company Description MAGNUS Management Group LLC is a Woman Owned Small Business consulting firm located in Washington DC. We are ISO 9001, ISO27001, ISO 20000, ISO 56002 & CMMI L3 SVC + SSD certified, and we provide expert consulting services … requirements and technical requirements based upon analysis of user, policy, technology, regulatory, and resource demands; recommends cloud-specific solutions for customer requirements; directs and / or supports design of solutions for enterprise cloud environments; has specific knowledge and experience developing or engineering cloud service provider solutions; and possesses expert … Bachelor's degree in Computer Science or related field Strong communication and problem-solving skills Experience with DevOps methodology Certifications in AWS, Azure, and / or Google Cloud Platform are a plus MAGNUS Management Group offers a competitive, comprehensive benefits package, which includes: 3 Weeks Paid Time Off more »