Lead Security Consultant GRC ISO 27001 PCI SOC2

Company: Confidential
Apply for the Lead Security Consultant GRC ISO 27001 PCI SOC2
Location: Manchester
Job Description:

Salary: £50,000 – 60,000 per year


Requirements:



  • Strong experience in ISO 27001 implementation, internal audit, ISMS maintenance, and engagement with external auditors

  • Solid understanding of the Data Protection Act and GDPR

  • Experience in security management, including risk, incident, and ISMS management, security working groups, and monitoring and measuring maturity

  • Experience working with frameworks such as NIST CSF, CIS, and NCSC CAF

  • Experience in supplier management, including third-party supplier security assessments

  • Experience managing risk and recommending mitigating actions

  • Knowledge of Cyber Essentials and IASME Cyber Assurance standards

  • Outstanding written and verbal communication skills with an emphasis on confidentiality, tact, and diplomacy

  • Ability to multitask, work as part of a team, and work independently

  • Formal ISO certifications such as Lead Auditor or Lead Implementer are desirable

  • Formal Data Protection Officer certification is desirable

  • Principal or Chartered Cyber Security Professional status in Cyber Security Audit and Assurance or Cyber Security Governance and Risk is desirable

  • Certified IASME Cyber Assurance Assessor status is desirable

  • Certified IASME DCC Assessor status is desirable

  • Good technical skills and understanding of IT and cloud services are desirable

  • Solid understanding of AI Governance and ISO 42001 is desirable


Responsibilities:



  • Lead and support client ISO 27001 implementation projects from initiation to certification

  • Conduct client Defence Cyber Certification (DCC) assessments and help clients gain formal certification

  • Provide information security, cyber security, and data privacy/GDPR consultancy to clients

  • Lead PCI and SOC2 client engagements

  • Support clients with the implementation of AI governance capabilities and formal certification to ISO 42001

  • Perform cyber security maturity assessments using recognised frameworks from CIS and NIST and make recommendations for improvement
  • Provide vCISO and vDPO services to clients and support client security working groups

  • Support sales and marketing initiatives in promoting our consultancy and managed security services


Technologies:



  • AI

  • Cloud

  • Support

  • Marketing

  • Security


More:


We are an independent ISO and CREST certified cyber security consultancy providing security consultancy and managed security services to a wide range of clients and partners. We are hiring a Lead Security Consultant to join our team in Manchester on a hybrid basis. This full-time role offers a 40-hour working week, up to £60,000 per annum depending on skills and experience, up to 10% annual bonus, funded InfoSec training, time for self-study, 25 days holiday plus bank holidays, private health care, company pension, career development opportunities, and regular team meals and activities.


last updated 36 week of 2026

#J-18808-Ljbffr…

Posted: September 9th, 2026