Lead Security Consultant
We are an independent ISO and CREST certified Cyber Security Consultancy providing Security Consultancy and Managed Security services to a wide range of Clients and Partners.
We are looking to recruit a Lead Security Consultant who specialises in GRC, ISO 27001, PCI DSS and Data Protection consultancy to join our team!
Responsibilities
- Lead and Support Client ISO 27001 implementation projects from initiation to certification
- Conduct Client Defence Cyber Certification (DCC) Assessments and help Clients to gain formal certification
- Provide Information Security, Cyber Security and Data Privacy/GDPR consultancy to Clients
- Lead on PCI and SOC2 client engagements
- Support Client with the implementation of AI Governance capabilities and formal certification to ISO 42001
- Perform Cyber Security Maturity Assessments using recognised frameworks from CIS and NIST to understand the level of Security that is in place and make recommendations for improvement
- Provide vCISO and vDPO services to our Clients and support Client Security Working Groups ensuring that all stakeholders are aware of their risks/threats/vulnerability management position.
- Support sales and marketing initiatives in the promotion of the Company’s consultancy and managed security services
Key Skills and Experience:
- Strong experience of ISO 27001 implementation, internal audit, ISMS maintenance and engagement with external auditors
- Solid understanding of the Data Protection Act and GDPR
- Experience of Security Management – risk/incident/ISMS management, Security Working Groups, Monitoring and Measuring maturity
- Experience of working with frameworks such as NIST CSF, CIS, NCSC CAF
- Experience in supplier management including the undertaking of third-party supplier security assessments
- Experience of managing risk and recommendation of mitigating actions
- Knowledge of Cyber Essentials & IASME Cyber Assurance standards
- Outstanding written and verbal communication skills with an emphasis on confidentiality, tact, and diplomacy
- Ability to multi-task, work as part of a team, and work independently
Nice to have Skills:
- Formal ISO certifications e.g. Lead Auditor, Lead Implementer
- Formal Data Protection Officer certification
- A Principal or Chartered Cyber Security Professional in the Cyber Security Audit and Assurance or Cyber Security Governance and Risk
- (as recognised by the UK Cyber Security Council)
- Certified IASME Cyber Assurance Assessor
- Certified IASME DCC Assessor
- Good technical skills and understanding of IT and Cloud services
- Solid understanding of AI Governance and ISO 42001
Package
- Up to £60k per annum dependant on skills and experience
- Up to 10% annual bonus if targets met
- Funded InfoSec training and time allocated for self-study
- 40 hour working weeks
- Flexible working policy
- Hybrid working – Company HQ in Manchester
- 25 days holiday plus bank holidays
- Company Sickness Policy
- Company Pension (can opt out)
- Company Expense Policy
- Private Health Care
- Career development opportunities
- Regular team meals and activities
Job Type: Full-time
Pay: Up to £60,000.00 per year
Work Location: Hybrid remote in Manchester