Hybrid Managing Information Security Consultant, GRC

Posted 15 hours ago

Apply now

About the role

  • Managing Consultant delivering information security consultancy specializing in GRC for LRQA clients. Driving client engagements with a focus on governance, risk, and compliance standards.

Responsibilities

  • Deliver information security consultancy to LRQA clients, specialising in governance, risk and compliance (GRC).
  • Drive engagements whilst supporting other members of the team with the ultimate aim of achieving excellent client satisfaction results.
  • Provision of client support to achieve compliance/certification against recognised standards such as ISO 27001, the GDPR, NIST CSF and PCI DSS.
  • Independently conducted ISO/IEC 27001:2022 audit activities.
  • Provision of expert advice to clients on governance structures.
  • Facilitation of information asset discovery workshops and engagements.
  • Facilitation of risk assessment workshops and engagements.
  • Delivery of business continuity scenario tabletop exercises.
  • Delivery of external stakeholder training and awareness presentations.
  • Mentor, coach, and guide team members to enhance their technical and consulting capabilities.
  • Develop and deliver training programs on GRC, risk management, and information assurance best practices.
  • Establish thought leadership by contributing to white papers, webinars, and conferences in the GRC space.

Requirements

  • Degree level qualification in Computer Science, Computer Engineering, IT, Cyber Security, or a related field or 5 years experience working within an information security role.
  • Minimum 2 years experience in delivering consultative engagements using well-known risk management and data security frameworks, standards, and methodologies.
  • ISO 27001 Lead Auditor or Lead Implementer qualification.
  • CISSP/CISM (or equivalent) certification preferable.
  • Experience in ISO 27001/NIST CSF implementation and use of relevant standards to build control frameworks.
  • Demonstrable experience communicating complex information security concepts to top level (C suite) management.
  • Experience in cyber resilience planning, security operations, and managing security professionals.
  • Strong communication skills and the ability to build rapport with key stakeholders.
  • Experience in some or all of the following areas of information security: GDPR regulation, PCI DSS, CMMC, SOC 2, DORA, NIS 2 Directive, HIPAA / NHS DSPT / Healthcare regulation, Business Continuity, Supplier Management, Incident Management, Physical Security.

Benefits

  • We are a people-focused, high-performing, high-trust professional services team.
  • Opportunities to make a difference.
  • Encourage all employees to challenge norms and empower them to get involved.
  • Enjoy blogging or public speaking.
  • Commit to getting involved in industry discussions.
  • Time to attend conferences and get involved in the infosec community.
  • Opportunities for professional development.

Job title

Managing Information Security Consultant, GRC

Job type

Experience level

JuniorMid level

Salary

Not specified

Degree requirement

Bachelor's Degree

Tech skills

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job