
Information Security Consultant – SMB
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Philippines.
• Oversee and facilitate GRC consulting projects across various clients and industries
• Contribute to evaluations of security posture, gap analyses, and maturity assessments
• Aid in the design and execution of GRC programs that align with ISO 27001, SOC 2, NIST, and similar standards
• Assist clients in audit preparation, certification procedures, and external evaluations
• Create remediation plans and monitor progress against established actions
• Engage in and lead client workshops, risk assessments, and stakeholder meetings
• Cultivate trusted relationships with clients and deliver practical, business-oriented security guidance
• Manage multiple client engagements while ensuring timely and high-quality outcomes
• Support clients in the development and implementation of governance, risk, and compliance programs
• Translate security standards and regulatory requirements into actionable recommendations
• Perform information security risk assessments and maintain relevant documentation
• Design and document security controls and operational models
• Develop governance documentation such as policies, standards, procedures, risk registers, control frameworks, and risk assessments
• Generate high-quality client deliverables adhering to Cognisys methodologies and quality standards
• Identify opportunities for enhancements within client engagements and contribute to internal methodologies, templates, and operational efficiencies
• 2–5 years of experience in security, risk, compliance, or GRC-related roles
• Hands-on experience with at least one recognized security framework, such as ISO 27001, SOC 2, or NIST
• Experience in supporting compliance, assurance, or certification initiatives
• Excellent written and verbal communication abilities
• Strong skills in stakeholder management and relationship building
• Exceptional organizational skills with the capacity to manage multiple priorities and projects
• Analytical, pragmatic, and solution-oriented approach to problem-solving
• Comfortable engaging with both technical and non-technical stakeholders
• Keen attention to detail and a commitment to delivering high-quality client outputs
• Previous consulting experience in a client-facing professional services environment is preferred
• Experience in delivering ISO 27001 implementation or certification projects is desirable
• Familiarity with SOC 2, NIST, PCI DSS, Cyber Essentials Plus, or similar frameworks is desirable
• Experience in performing information security risk assessments and governance reviews is desirable
• Familiarity with GRC platforms such as Vanta or similar tools is desirable
• Experience working with international clients or distributed teams is desirable
• Relevant certifications such as ISO/IEC 27001 Lead Implementer, ISO/IEC 27001 Lead Auditor, CISSP, CISM, CRISC, Security+, or equivalent are highly regarded
• While certifications are valued, practical experience, problem-solving capabilities, and potential for development are also taken into account
• 22 days of paid time off (PTO) annually
• 12 public holidays and 8 special Filipino holidays
• 1 day of paid leave for your birthday
• 13th Month Salary - 1/2 of monthly salary paid annually in December
• Individual healthcare insurance plan
• Access to an employee mental health and wellbeing platform
• £2,000 annual training budget
• Up to £2,000 for each successful referral
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.