
Information Security Consultant – SMB
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in South Africa.
• Oversee the execution of GRC consulting projects across various clients and industries
• Participate in security posture evaluations, gap assessments, and maturity evaluations
• Aid in the creation and implementation of GRC programs that align with frameworks such as ISO 27001, SOC 2, NIST, and other relevant standards
• Assist clients during audit preparations, certification procedures, and external evaluations
• Formulate remediation strategies and help clients monitor their progress against established actions
• Engage and lead client workshops, risk assessments, and stakeholder meetings
• Facilitate the interpretation of security standards and regulations, converting requirements into actionable recommendations
• Spearhead the creation of policies, procedures, risk registers, control frameworks, and governance documentation
• Contribute to the design and documentation of security controls and operational models
• Support the integration of compliance activities into operational and technical workflows
• Conduct risk assessments and manage related documentation
• Deliver high-quality outputs for clients with clarity, precision, and consistency
• Adhere to established methodologies, templates, and internal quality benchmarks
• Actively seek opportunities for enhancement within projects
• Effectively manage assigned responsibilities to meet deadlines and fulfill scope expectations
• 2–5 years of experience in security, risk management, compliance, or GRC-related positions
• Hands-on experience with at least one framework like ISO 27001, SOC 2, NIST, or similar standards
• Experience in supporting compliance or assurance initiatives, whether internal or client-facing
• Excellent written and verbal communication abilities
• Capability to handle multiple priorities in an organized and systematic way
• Analytical thinker with a practical approach to resolving issues
• Comfortable collaborating with both technical and non-technical stakeholders
• Consulting experience is highly advantageous but not mandatory
• Familiarity with GRC platforms, including Vanta, is a plus
• 25 days of annual leave in addition to 12 public holidays in South Africa
• 1 day of paid leave for your birthday
• Individual healthcare insurance plan
• Access to an employee mental health and wellbeing platform
• £2,000 annual training budget
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.