
Information Security Consultant
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in United States.
• Provide ongoing information security advisory services across various clients and industries.
• Offer practical advice on information security risks, security programs, and improvement priorities.
• Assist in vCISO-style advisory services and the continuous development of security programs.
• Evaluate and enhance the effectiveness, maturity, and sustainability of security initiatives.
• Prioritize security projects based on risk assessment, business goals, and resource availability.
• Support specialized information security projects and other client engagements.
• Create realistic solutions for complex security challenges.
• Aid in the development, maintenance, and enhancement of information security programs.
• Assess security risks, controls, processes, and operational practices.
• Develop and sustain security roadmaps, risk registers, remediation plans, and improvement initiatives.
• Provide advice on security governance, risk management, controls, policies, procedures, and operational processes.
• Implement relevant frameworks, standards, regulations, and industry best practices.
• Assist with security assurance and compliance efforts.
• Utilize GRC platforms and other security tools effectively.
• Cultivate trusted, long-lasting relationships with client stakeholders.
• Facilitate client meetings, workshops, and advisory sessions.
• Clearly communicate risks, recommendations, and trade-offs.
• Manage expectations and relay progress, challenges, and dependencies.
• Take ownership of specific client engagements and workstreams.
• Handle competing priorities across various clients and projects.
• Plan and organize deliverables to meet established timelines and objectives.
• Identify risks and obstacles, taking appropriate actions.
• Contribute to scoping and defining additional client projects.
• Generate clear, accurate, and commercially viable client deliverables.
• Apply Cognisys methodologies and uphold quality standards.
• Share knowledge and contribute to the broader GRC consulting team.
• 3–5 years of experience in information security, cybersecurity, security consulting, or a related field.
• Strong practical understanding of information security and cybersecurity concepts.
• Experience in an operational, technical, or industry-specific information security setting.
• Proven ability to identify and manage real-world security risks.
• Background in developing, operating, assessing, or enhancing security programs.
• Familiarity with security controls, risk management, security processes, or security operations.
• Knowledge of FedRAMP and the NIST SP 800 series is advantageous.
• Strong client-facing and consulting abilities.
• Exceptional written and verbal communication skills.
• Capability to present ideas and recommendations effectively to audiences at all levels.
• Experience collaborating with technical, operational, and senior stakeholders.
• Strong questioning, listening, and relationship-building capabilities.
• Ability to devise practical, commercially sensible solutions.
• Strong organizational skills with the ability to manage multiple clients, workstreams, and competing priorities.
• Comfortable working independently and exercising professional judgment.
• Consulting experience is highly preferred.
• Experience with vCISO, security advisory, or support for ongoing security programs is highly preferred.
• Familiarity with GRC platforms such as Vanta is desirable.
• 22 days of paid time off per year in addition to 11 American bank holidays.
• 1 day of paid leave for your birthday.
• Individual access to a healthcare and life insurance plan.
• Employee mental health and wellbeing platform.
• 2% employer contributions to the Fidelity 401k scheme as per statutory requirements.
• £2,000 annual training budget.
• Up to £2,000 for each successful referral.
EXL
Reli Group
Second Nature
ASRC Federal
Get handpicked remote jobs straight to your inbox weekly.