Information Security Consultant – SMB
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Information Security Consultant delivering GRC advisory services for Cognisys, a cybersecurity consultancy. Strengthening client governance, risk management and compliance across recognised security frameworks.
Responsibilities:
- Lead and support GRC consulting engagements across multiple clients and sectors
- Contribute to security posture assessments, gap analyses and maturity reviews
- Assist in designing and implementing GRC programmes aligned with ISO 27001, SOC 2, NIST and related standards
- Support clients through audit preparation, certification processes and external assessments
- Develop remediation plans and track progress against agreed actions
- Participate in and lead client workshops, risk assessments and stakeholder sessions
- Build trusted client relationships and provide practical, business-focused security advice
- Manage multiple client engagements and ensure timely, high-quality delivery
- Help clients develop and implement governance, risk and compliance programmes
- Interpret security standards and regulatory requirements into practical recommendations
- Conduct information security risk assessments and maintain documentation
- Design and document security controls and operating models
- Develop governance documentation including policies, standards, procedures, risk registers, control frameworks and risk assessments
- Produce high-quality client deliverables and follow Cognisys methodologies and quality standards
- Identify improvements within client engagements and contribute to internal methodologies, templates and ways of working
Requirements:
- 2–5 years’ experience in security, risk, compliance or GRC-related roles
- Practical experience with at least one recognised security framework, such as ISO 27001, SOC 2 or NIST
- Experience supporting compliance, assurance or certification initiatives
- Strong written and verbal communication skills
- Excellent stakeholder management and relationship-building skills
- Strong organisational skills and ability to manage multiple priorities and engagements
- Analytical, pragmatic and solution-focused approach to problem solving
- Comfortable working with technical and non-technical stakeholders
- Strong attention to detail and commitment to high-quality client deliverables
- Previous consulting experience in a client-facing professional services environment preferred
- Experience delivering ISO 27001 implementation or certification projects desirable
- Exposure to SOC 2, NIST, PCI DSS, Cyber Essentials Plus or similar frameworks desirable
- Experience conducting information security risk assessments and governance reviews desirable
- Experience using GRC platforms such as Vanta or similar tools desirable
- Experience working with international clients or distributed teams desirable
- Certifications highly regarded: ISO/IEC 27001 Lead Implementer, ISO/IEC 27001 Lead Auditor, CISSP, CISM, CRISC, Security+ or equivalent security certifications
- Certifications are valued, but practical experience, problem-solving ability and development potential are also considered
Benefits:
- 22 days PTO per year
- 12 public and 8 special Filipino holidays
- 1 day of paid leave for your Birthday
- 13th Month Salary - 1/2 of monthly salary paid annually in December
- Individual healthcare insurance plan
- Access to an employee mental health and wellbeing platform
- £2,000 annual training budget
- Up to £2,000 per successful referral


















