Information Security Consultant - UK (Remote)
Indexed description
Our consultants work alongside clients to solve complex security and compliance challenges, providing practical, business-focused advice that helps organisations build resilient security programmes and achieve regulatory compliance.
As we continue to grow our GRC Consulting practice, we're looking for an Information Security Consultant to join our expanding team.
The Opportunity
Our GRC Consulting team partners with organisations at every stage of their security journey—from building foundational governance programmes to supporting mature organisations operating within complex regulatory environments.
As an Information Security Consultant, you'll work with a diverse range of clients across multiple industries, helping them strengthen their governance, risk and compliance capabilities through practical, commercially focused security advice.
This is a client-facing consulting role where you'll deliver a variety of GRC engagements, helping clients understand regulatory requirements, improve their security posture and implement effective governance frameworks.
Working alongside experienced consultants, you'll build trusted client relationships, support complex security projects and play an important role in delivering exceptional consulting outcomes.
Whether you're conducting maturity assessments, supporting ISO 27001 implementations, facilitating risk workshops or preparing clients for certification, you'll help organisations turn compliance requirements into meaningful business improvements.
What You'll Be Doing
Client Consulting & Delivery
- Deliver Governance, Risk & Compliance consulting engagements across multiple clients and industries.
- Conduct security posture assessments, gap analyses and maturity reviews.
- Support clients through audit preparation, certification activities and external assessments.
- Develop remediation plans and assist clients in tracking agreed actions through to completion.
- Facilitate client workshops, risk assessments and stakeholder meetings.
- Build trusted relationships with clients by providing practical, commercially focused security advice.
- Support multiple client engagements while ensuring projects are delivered on time and to a high standard.
- Assist clients in designing and implementing governance, risk and compliance programmes aligned to recognised frameworks including:
- ISO 27001
- SOC 2
- NIST Cybersecurity Framework
- Other recognised industry standards
- Interpret security standards and regulatory requirements, translating them into practical business recommendations.
- Develop and maintain governance documentation including:
- Information Security Policies
- Standards and Procedures
- Risk Registers
- Control Frameworks
- Risk Assessments
- Governance documentation
- Support organisations in embedding governance and compliance activities into day-to-day operational processes.
- Assist clients in developing pragmatic security controls that align with both business objectives and regulatory expectations.
- Produce high-quality consulting deliverables that meet Cognisys' standards for quality, consistency and professionalism.
- Identify opportunities to improve client security programmes and internal delivery methodologies.
- Manage multiple consulting engagements while balancing competing priorities and deadlines.
- Collaborate closely with colleagues across consulting and technical teams to deliver exceptional client outcomes.
You will:
- Successfully deliver multiple GRC consulting engagements, ensuring projects are completed on time, within scope and to the high standards expected by Cognisys.
- Build trusted relationships with clients by providing practical, commercially focused advice that helps them navigate complex governance, risk and compliance challenges.
- Confidently support organisations through certification and compliance initiatives, including ISO 27001, SOC 2 and other recognised frameworks.
- Produce clear, accurate and professional client deliverables, including policies, procedures, risk assessments, control frameworks and governance documentation.
- Demonstrate strong knowledge of governance, risk and compliance frameworks by translating regulatory requirements into practical, business-focused recommendations.
- Effectively manage multiple client engagements while maintaining exceptional communication, organisation and stakeholder management.
- Collaborate successfully with colleagues and client stakeholders to deliver successful consulting engagements and positive client outcomes.
- Contribute to the continuous improvement of the GRC Consulting practice by enhancing methodologies, documentation, templates and ways of working.
- Continue developing your consulting expertise and establish yourself as a trusted Information Security Consultant within the Cognisys team.
You'll be naturally organised, proactive and comfortable managing multiple priorities while working across a variety of client engagements.
Most importantly, you'll enjoy translating complex security and compliance requirements into practical advice that creates real value for clients.
Essential Skills & Experience
- 2–5 years' experience in Governance, Risk & Compliance (GRC), Information Security or Risk Management.
- Practical experience working with one or more recognised security frameworks, including:
- ISO 27001
- SOC 2
- NIST Cybersecurity Framework
- Other recognised governance and compliance standards
- Experience supporting compliance, assurance or certification activities.
- Strong written communication skills with the ability to produce clear, professional client documentation.
- Excellent stakeholder management and client communication skills.
- Strong organisational skills with the ability to manage multiple client engagements simultaneously.
- Analytical mindset with a pragmatic, solution-focused approach to problem solving.
- Comfortable working with both technical and non-technical stakeholders.
- Previous consulting experience within a client-facing professional services environment.
- Experience delivering ISO 27001 implementation or certification projects.
- Exposure to SOC 2, NIST, PCI DSS, Cyber Essentials Plus or similar security frameworks.
- Experience conducting information security risk assessments and governance reviews.
- Experience using GRC platforms such as Vanta or similar governance tools.
- SO/IEC 27001 Lead Implementer
- ISO/IEC 27001 Lead Auditor
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- Security+ or equivalent security certifications
What we Offer:
- Annual Leave: 25 days per year plus 8 English bank holidays.
- Additional Leave: 1 day of paid leave for your Birthday.
- Health & Wellbeing: Access to Westfield Health Care Cash Plan and an employee mental health and wellbeing platform.
- Professional Development: £2,000 annual training budget to support your continued learning and career growth.
- Referral Bonus: help to grow our team and earn up to £2,000 per successful referral.
We welcome applications from candidates from a range of diverse backgrounds and can make various reasonable adjustments to consider individual needs.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search