As one of the world's largest networks of audit, tax and consulting firms, RSM delivers big ideas and premium service to help middle-market businesses thrive. We are a fast-growing firm with big ambitions - we have a clear goal to become the premium adviser to the middle market, globally. This vision touches everything we do, motivating and inspiring us to become better every day. If you are looking for a firm where you can build a future and make an impact, then RSM is the place for you.
Make an Impact at RSM UK
As one of the world's largest networks of Audit, Tax and Consulting firms, RSM delivers big ideas and premium service to help businesses thrive. We are fast-growing with big ambitions. If you are looking for a firm where you can build a future and make an impact, then this is the place for you.
Our Consulting business brings together diverse advisory experts to deliver six core solutions: Business Transformation, Forensic, Deal Services, Restructuring, Finance Function Support and Risk and Governance.
With a bold and ambitious strategy for the next phase of growth, Consulting is investing in enhancing its governance, assurance and information security capabilities. A key part of this strategy is achieving ISO 27001 certification for defined areas of the Consulting business, whilst ensuring the foundations are established to maintain certification and support continual improvement of the Information Security Management System (ISMS).
This role will play a critical leadership and delivery role in defining the scope, shaping the roadmap and driving the activities required to achieve certification.
Reporting into Consulting Operations leadership, the Consulting ISO 27001 Programme Lead will work closely with Consulting leadership, service line representatives, risk and quality teams, National Technology (NT), central Information Security, Privacy and Legal functions.
The role combines programme leadership, information security governance and hands-on delivery, requiring someone who is equally comfortable facilitating stakeholder discussions, interpreting standards, documenting controls and preparing teams for audit.
You'll make an impact by:
ISO 27001 Strategy & Certification
-
Support the development and delivery of Consulting's ISO 27001 certification strategy and roadmap..
-
Help define certification scope, priorities and implementation plans
-
Advise stakeholders on certification requirements, risks and dependencies.
-
Translate ISO 27001 requirements into practical business outcomes and delivery plans.
-
Provide expert guidance to support certification planning and decision-making.
ISMS Implementation & Alignment
-
Partner with National Technology and Information Security teams to align certification activities with the firm's ISMS.
-
Support the adoption of security policies, controls and governance processes across Consulting.
-
Identify control gaps and recommend pragmatic remediation actions.
-
Ensure security controls are effective, auditable and embedded into day-to-day operations.
-
Act as a key link between Consulting, Technology and Information Security teams.
Stakeholder Engagement & Business Partnering
-
Build strong relationships across Consulting, Technology, Information Security, Privacy and Legal teams.
-
Facilitate workshops, assessments and stakeholder discussions.
-
Provide trusted advice on ISO 27001 requirements and implementation approaches.
-
Support evidence gathering, control ownership and audit readiness activities.
Audit Readiness & Certification Delivery
-
Conduct ISO 27001 gap assessments and develop remediation plans.
-
Coordinate evidence collection and control implementation activities.
-
Prepare teams for internal and external audits.
-
Manage engagement with certification bodies and audit partners.
-
Support successful certification through to audit completion and accreditation.
Governance, Risk & Continuous Improvement
-
Support the ongoing governance and maintenance of ISO 27001 certification.
-
Assist with surveillance audits, recertification and risk management activities.
-
Develop reporting and metrics to demonstrate compliance.
-
Identify opportunities to strengthen controls and improve processes.
-
Help establish a sustainable, long-term approach to information security and certification.
What we are looking for:
Are you someone who thrives on variety, loves learning new things, and enjoys connecting with people? If you can spot inefficiencies in everyday life and are passionate about making improvements, this role is perfect for you!
We value diverse experiences and perspectives. Here’s what we’re looking for in our ideal candidate:
-
Significant experience leading organisations through ISO 27001 certification programmes.
-
Demonstrable experience defining certification scope within large, complex or matrix organisations.
-
Strong practical knowledge of ISO 27001 and associated ISMS requirements.
-
Experience designing, implementing and operating Information Security Management Systems.
-
Experience conducting gap assessments, remediation planning and audit preparation activities.
-
Strong understanding of information security governance, risk management and control frameworks.
-
Experience working with senior leadership teams and influencing stakeholders across multiple business functions.
-
Ability to translate technical, governance and compliance requirements into practical business actions.
-
Strong documentation, facilitation and communication skills.
-
Proven ability to manage competing priorities and deliver outcomes within fixed timescales.
What we can offer you:
We recognise that our people are our most important assets. That’s why we offer a flexible reward and benefits package that will help you have fulfilling experience, both in and out of work.
-
27 Days Holiday (with the option of purchasing additional days).
-
Hybrid and Flexible working
-
Lifestyle, Health, and Wellbeing including financial wellbeing benefits such as financial tools, electric car scheme and access to a virtual GP.
-
Access to a suite of 300+ courses on demand developed by our inhouse Talent Development team.
style="color: #FFFFFF">#LI-LC1
Diversity and Inclusion at RSM
At RSM, we want to create a strong sense of belonging so that people of all identities, backgrounds, and cultures feel they can bring their true self to work. Our clients come from all walks of life. We aim to achieve that same diversity of background, experience and perspective in our own teams, so that we can genuinely understand our client's needs. Diverse teams bring a broader range of ideas and insights to work. That's why we're working together to ensure our firm's principles and processes support a firm culture that embraces difference and strengthens inclusion.