London
£40000 - £52000 per annum
Full time
Ref: 739374312_1788342303
GRC Consultant | £40,000-£52,000 DOE | London (Hybrid)
Are you passionate about cyber security governance, risk and compliance and enjoy helping organisations navigate complex security challenges?
We're partnering with a growing cyber security consultancy that is looking to strengthen its Governance, Risk and Compliance capability with the addition of a GRC Consultant. This is an opportunity to join a collaborative team delivering cyber security, risk management and assurance services to clients operating across complex and highly regulated environments.
You'll work closely with clients to understand their business objectives, identify and assess cyber security risks, and develop pragmatic, proportionate solutions that strengthen their security and compliance posture. The role offers exposure to a broad range of client engagements and the opportunity to develop into a trusted security and risk advisor.
What you'll be doing:
As a GRC Consultant, you'll support clients across a variety of cyber security governance, risk and compliance activities, including:
Conducting cyber security and information security maturity assessments
Identifying, analysing and managing cyber and information security risks
Supporting the development and implementation of security governance and risk management frameworks
Reviewing the effectiveness of security controls and recommending proportionate improvements
Assessing clients against recognised standards and frameworks, including ISO 27001, NIST and similar methodologies
Supporting ISO 27001 implementation, readiness and assurance activities
Developing risk registers, treatment plans, policies, standards and security documentation
Conducting risk assessments, gap analyses and security assurance reviews
Leading client workshops and interviews to understand business processes, risks and security requirements
Producing high-quality reports and presenting findings and recommendations to technical teams and senior stakeholders
Supporting clients in developing and maintaining effective information security management practices
Monitoring changes across the regulatory and cyber security landscape
Supporting business development activities, including contributing to proposals and client engagements
What we're looking for:
We're interested in speaking with candidates who can demonstrate:
Experience within cyber security GRC, information security consultancy, risk management or security assurance
A strong understanding of cyber security governance, risk and compliance principles
Practical experience working with frameworks such as ISO 27001, NIST, Cyber Essentials or similar standards
Experience conducting risk assessments, security assessments or compliance reviews
An understanding of information security policies, controls, risk registers and assurance processes
The ability to translate complex cyber security risks into clear and practical advice for clients
Excellent written and verbal communication skills
Strong stakeholder management and relationship-building abilities
Experience working within complex or regulated environments such as Financial Services, Government, Defence, Energy or Telecommunications would be advantageous
A consulting mindset with the ability to understand client requirements and deliver commercially pragmatic solutions
Why join?
You'll be joining a growing consultancy that places a strong emphasis on integrity, collaboration and delivering meaningful outcomes for its clients.
Working as part of a close-knit team of cyber security and GRC specialists, you'll have the opportunity to work across a varied portfolio of engagements, gain exposure to different industries and develop your career within a supportive environment that values expertise and individual contribution.
This is an excellent opportunity for someone looking to further develop their career in cyber security GRC and become a trusted advisor to a growing client base.
The role is based in London on a hybrid working basis, with occasional travel to client sites where required.
If you're looking for an opportunity to work across a broad range of cyber security governance, risk and compliance challenges while developing your consulting career, we'd be pleased to hear from you.
Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy.
To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.
Resource Consultant
Share job