
Information Security Consultant
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in United Kingdom.
• Execute Governance, Risk & Compliance consulting projects across various clients and sectors.
• Perform security posture evaluations, gap analyses, and maturity assessments.
• Assist clients in preparing for audits, certification processes, and external evaluations.
• Create remediation strategies and support clients in tracking agreed-upon actions until completion.
• Lead client workshops, risk evaluations, and stakeholder discussions.
• Establish trusted relationships with clients by providing practical and commercially-oriented security guidance.
• Oversee multiple client projects, ensuring timely delivery and high-quality outcomes.
• Aid in the design and implementation of governance, risk, and compliance programs in alignment with ISO 27001, SOC 2, NIST Cybersecurity Framework, and other recognized standards.
• Translate security standards and regulatory requirements into actionable business recommendations.
• Create and maintain information security policies, standards, procedures, risk registers, control frameworks, risk assessments, and governance documentation.
• Help clients integrate governance and compliance initiatives into their operational practices.
• Produce high-quality consulting outputs.
• Enhance client security programs and internal delivery methodologies.
• Collaborate with consulting and technical teams to achieve successful outcomes for clients.
• Contribute to the enhancement of methodologies, documentation, templates, and operational practices.
• 2–5 years of experience in Governance, Risk & Compliance (GRC), Information Security, or Risk Management.
• Practical knowledge of one or more recognized security frameworks, including ISO 27001, SOC 2, and NIST Cybersecurity Framework.
• Experience in supporting compliance, assurance, or certification processes.
• Strong written communication abilities for creating clear and professional client documentation.
• Excellent skills in stakeholder management and client communication.
• Strong organizational capabilities with the ability to handle multiple client engagements simultaneously.
• Analytical mindset with a pragmatic, solution-oriented approach to problem-solving.
• Ability to engage with both technical and non-technical stakeholders.
• Previous consulting experience in a client-facing professional services setting is preferred.
• Experience in delivering ISO 27001 implementation or certification projects is desirable.
• Familiarity with SOC 2, NIST, PCI DSS, Cyber Essentials Plus, or similar frameworks is a plus.
• Experience in conducting information security risk assessments and governance reviews is preferred.
• Familiarity with GRC platforms such as Vanta or similar tools is desirable.
• Highly regarded certifications include ISO/IEC 27001 Lead Implementer, ISO/IEC 27001 Lead Auditor, CISSP, CISM, CRISC, Security+, or equivalent security certifications.
• 25 days of annual leave per year in addition to 8 English bank holidays.
• 1 day of paid leave for your Birthday.
• Access to the Westfield Health Care Cash Plan.
• Employee mental health and wellbeing platform.
• £2,000 annual training budget.
• Referral bonus of up to £2,000 for each successful referral.
• Collaborative and innovative team environment.
• Engaging projects that make a real impact for clients.
• Encouragement of professional growth.
• Reasonable adjustments and accessibility support available.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.