Salary: £50,000 – 60,000 per year
Requirements:
- Strong experience in ISO 27001 implementation, internal audit, ISMS maintenance, and engagement with external auditors
- Solid understanding of the Data Protection Act and GDPR
- Experience in security management, including risk, incident, and ISMS management, security working groups, and monitoring and measuring maturity
- Experience working with frameworks such as NIST CSF, CIS, and NCSC CAF
- Experience in supplier management, including third-party supplier security assessments
- Experience managing risk and recommending mitigating actions
- Knowledge of Cyber Essentials and IASME Cyber Assurance standards
- Outstanding written and verbal communication skills with an emphasis on confidentiality, tact, and diplomacy
- Ability to multitask, work as part of a team, and work independently
- Formal ISO certifications such as Lead Auditor or Lead Implementer are desirable
- Formal Data Protection Officer certification is desirable
- Principal or Chartered Cyber Security Professional status in Cyber Security Audit and Assurance or Cyber Security Governance and Risk is desirable
- Certified IASME Cyber Assurance Assessor status is desirable
- Certified IASME DCC Assessor status is desirable
- Good technical skills and understanding of IT and cloud services are desirable
- Solid understanding of AI Governance and ISO 42001 is desirable
Responsibilities:
- Lead and support client ISO 27001 implementation projects from initiation to certification
- Conduct client Defence Cyber Certification (DCC) assessments and help clients gain formal certification
- Provide information security, cyber security, and data privacy/GDPR consultancy to clients
- Lead PCI and SOC2 client engagements
- Support clients with the implementation of AI governance capabilities and formal certification to ISO 42001
- Perform cyber security maturity assessments using recognised frameworks from CIS and NIST and make recommendations for improvement
- Provide vCISO and vDPO services to clients and support client security working groups
- Support sales and marketing initiatives in promoting our consultancy and managed security services
Technologies:
- AI
- Cloud
- Support
- Marketing
- Security
More:
We are an independent ISO and CREST certified cyber security consultancy providing security consultancy and managed security services to a wide range of clients and partners. We are hiring a Lead Security Consultant to join our team in Manchester on a hybrid basis. This full-time role offers a 40-hour working week, up to £60,000 per annum depending on skills and experience, up to 10% annual bonus, funded InfoSec training, time for self-study, 25 days holiday plus bank holidays, private health care, company pension, career development opportunities, and regular team meals and activities.
last updated 36 week of 2026
#J-18808-Ljbffr…
