Cyber Security Consultant (GRC)

London

£40000 - £52000 per annum

Full time

Ref: 739374312_1788342303

GRC Consultant | £40,000-£52,000 DOE | London (Hybrid)

Are you passionate about cyber security governance, risk and compliance and enjoy helping organisations navigate complex security challenges?

We're partnering with a growing cyber security consultancy that is looking to strengthen its Governance, Risk and Compliance capability with the addition of a GRC Consultant. This is an opportunity to join a collaborative team delivering cyber security, risk management and assurance services to clients operating across complex and highly regulated environments.

You'll work closely with clients to understand their business objectives, identify and assess cyber security risks, and develop pragmatic, proportionate solutions that strengthen their security and compliance posture. The role offers exposure to a broad range of client engagements and the opportunity to develop into a trusted security and risk advisor.

What you'll be doing:

As a GRC Consultant, you'll support clients across a variety of cyber security governance, risk and compliance activities, including:

  • Conducting cyber security and information security maturity assessments

  • Identifying, analysing and managing cyber and information security risks

  • Supporting the development and implementation of security governance and risk management frameworks

  • Reviewing the effectiveness of security controls and recommending proportionate improvements

  • Assessing clients against recognised standards and frameworks, including ISO 27001, NIST and similar methodologies

  • Supporting ISO 27001 implementation, readiness and assurance activities

  • Developing risk registers, treatment plans, policies, standards and security documentation

  • Conducting risk assessments, gap analyses and security assurance reviews

  • Leading client workshops and interviews to understand business processes, risks and security requirements

  • Producing high-quality reports and presenting findings and recommendations to technical teams and senior stakeholders

  • Supporting clients in developing and maintaining effective information security management practices

  • Monitoring changes across the regulatory and cyber security landscape

  • Supporting business development activities, including contributing to proposals and client engagements

What we're looking for:

We're interested in speaking with candidates who can demonstrate:

  • Experience within cyber security GRC, information security consultancy, risk management or security assurance

  • A strong understanding of cyber security governance, risk and compliance principles

  • Practical experience working with frameworks such as ISO 27001, NIST, Cyber Essentials or similar standards

  • Experience conducting risk assessments, security assessments or compliance reviews

  • An understanding of information security policies, controls, risk registers and assurance processes

  • The ability to translate complex cyber security risks into clear and practical advice for clients

  • Excellent written and verbal communication skills

  • Strong stakeholder management and relationship-building abilities

  • Experience working within complex or regulated environments such as Financial Services, Government, Defence, Energy or Telecommunications would be advantageous

  • A consulting mindset with the ability to understand client requirements and deliver commercially pragmatic solutions

Why join?

You'll be joining a growing consultancy that places a strong emphasis on integrity, collaboration and delivering meaningful outcomes for its clients.

Working as part of a close-knit team of cyber security and GRC specialists, you'll have the opportunity to work across a varied portfolio of engagements, gain exposure to different industries and develop your career within a supportive environment that values expertise and individual contribution.

This is an excellent opportunity for someone looking to further develop their career in cyber security GRC and become a trusted advisor to a growing client base.

The role is based in London on a hybrid working basis, with occasional travel to client sites where required.

If you're looking for an opportunity to work across a broad range of cyber security governance, risk and compliance challenges while developing your consulting career, we'd be pleased to hear from you.

Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy.

To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.

Apply today.

Share job