Managing Consultant delivering information security consultancy specializing in GRC for LRQA clients. Driving client engagements with a focus on governance, risk, and compliance standards.
Responsibilities
Deliver information security consultancy to LRQA clients, specialising in governance, risk and compliance (GRC).
Drive engagements whilst supporting other members of the team with the ultimate aim of achieving excellent client satisfaction results.
Provision of client support to achieve compliance/certification against recognised standards such as ISO 27001, the GDPR, NIST CSF and PCI DSS.
Provision of expert advice to clients on governance structures.
Facilitation of information asset discovery workshops and engagements.
Facilitation of risk assessment workshops and engagements.
Delivery of business continuity scenario tabletop exercises.
Delivery of external stakeholder training and awareness presentations.
Mentor, coach, and guide team members to enhance their technical and consulting capabilities.
Develop and deliver training programs on GRC, risk management, and information assurance best practices.
Establish thought leadership by contributing to white papers, webinars, and conferences in the GRC space.
Requirements
Degree level qualification in Computer Science, Computer Engineering, IT, Cyber Security, or a related field or 5 years experience working within an information security role.
Minimum 2 years experience in delivering consultative engagements using well-known risk management and data security frameworks, standards, and methodologies.
ISO 27001 Lead Auditor or Lead Implementer qualification.
Experience in ISO 27001/NIST CSF implementation and use of relevant standards to build control frameworks.
Demonstrable experience communicating complex information security concepts to top level (C suite) management.
Experience in cyber resilience planning, security operations, and managing security professionals.
Strong communication skills and the ability to build rapport with key stakeholders.
Experience in some or all of the following areas of information security: GDPR regulation, PCI DSS, CMMC, SOC 2, DORA, NIS 2 Directive, HIPAA / NHS DSPT / Healthcare regulation, Business Continuity, Supplier Management, Incident Management, Physical Security.
Benefits
We are a people-focused, high-performing, high-trust professional services team.
Opportunities to make a difference.
Encourage all employees to challenge norms and empower them to get involved.
Enjoy blogging or public speaking.
Commit to getting involved in industry discussions.
Time to attend conferences and get involved in the infosec community.
DevSecOps engineer at Ford ensuring secure software development and compliance with security standards. Collaborating with teams to embed security practices and assess vulnerabilities in software delivery.
Security Officer responsible for ensuring safety and security at the Genesee Brewing Company. Monitoring premises, responding to emergencies, and providing visitor assistance during shifts.
Security Estimator creating estimates and proposals for security projects at LINX. Collaborating with engineering and sales teams for system design and client relationships.
Product Security Architect at Expedia designing secure architecture for services and APIs. Collaborating with teams to guide secure practices and integrate AI - driven solutions.
IT Security Officer overseeing information security for a specific IT sector at Desjardins. Collaborating with cross - sector teams and managing information security risks and vulnerabilities.
Associate, Information Security professional at Santander focusing on Vulnerability Management and network security exposure. Collaborating with teams to enhance security posture and manage technology risks.
IAM Security & Technology Governance person driving IAM technical program with cutting - edge technology to improve security posture at MUFG. Manage IAM requirements, standards, governance and solutions across global implementation.
Senior Analyst in Mastercard's newly created Vocalink Control Office supporting control testing across Security domains. Ensuring a strong control environment and identifying gaps for improvement.
Senior Analyst focusing on Information Security and Compliance at Cirque du Soleil. Engaging in threat analysis and improvement of security tools and processes, within a creative company culture.
Security Architect designing and implementing cybersecurity architectures for UK Defence projects. Collaborating with stakeholders to safeguard client data against cyber threats.