Lead Cybersecurity GRC Consultant

Company: Jacobs
Apply for the Lead Cybersecurity GRC Consultant
Location: London
Job Description:

Overview

In this role you will lead the development and embedding of cyber governance, risk and compliance across a major infrastructure programme. You’ll collaborate with cyber, IT, digital and delivery teams to translate risks into actionable insights for senior decision-makers. You drive the design of policies, standards and controls and modernise processes with digital tooling. You’ll influence outcomes through collaboration and clear reporting, shaping a scalable Cyber GRC capability across projects.

Pay / Benefits

  • Health Cover
  • Life Assurance
  • Income Protection
  • holiday buy/sell
  • wellbeing support
  • parental and fertility support offerings’,’enhanced contribution pension

Responsibilities

  • Develop and embed governance, risk and compliance practices across a complex project environment
  • Identify, assess and manage cyber risks and link them to wider programme risk management
  • Lead policies, standards, controls and assurance activities
  • Transform manual processes into digitally enabled workflows
  • Provide clear, evidence-based reporting to senior stakeholders
  • Engage with cross-functional teams to drive outcomes through influence
  • Hands-on consultancy with proactive stakeholder engagement
  • Build and scale Cyber GRC capability for broader adoption across Jacobs

Key requirements

  • Proven experience delivering end-to-end cyber security governance, risk and compliance activities
  • Experience conducting cyber risk assessments, remediation activities and senior-level risk reporting
  • Experience creating and implementing cyber policies, standards, frameworks and governance processes
  • Knowledge of ISO 27001, NIST, NCSC CAF, Government Security Standards or equivalent
  • Ability to communicate complex cyber risks to technical and non-technical audiences
  • Delivery-focused mindset with autonomous work style
  • Experience with Microsoft Azure, Microsoft 365, OT environments, government projects, or critical national infrastructure (beneficial)
  • Stakeholder engagement
  • Clear communication
  • Autonomy and self-motivation
  • ISO 27001
  • NIST
  • NCSC CAF

Posted: September 14th, 2026