Overview
As a GRC Consultant you will help clients navigate cyber security governance, risk and compliance across regulated environments. You will work with cross-functional teams to assess risks, implement governance frameworks, and improve controls and assurance. The role offers exposure to diverse engagements and opportunities to become a trusted security and risk advisor. You will contribute to proposals, deliver high-quality reports, and stay aligned with evolving regulatory landscapes.
Responsibilities
- Conduct cyber security and information security maturity assessments
- Identify and manage cyber and information security risks
- Support development and implementation of governance and risk management frameworks
- Review control effectiveness and propose proportionate improvements
- Assess against standards like ISO 27001 and NIST
- Support ISO 27001 implementation, readiness and assurance
- Develop risk registers, policies, standards and security documentation
- Perform risk assessments, gap analyses and assurance reviews
- Lead client workshops to understand processes and risks
- Produce reports and present findings to technical teams and senior stakeholders
- Support information security management practices
- Monitor regulatory and cyber security landscape changes
- Support business development, including proposals and engagements
Key requirements
- Experience in cyber security GRC, information security consultancy, risk management or security assurance
- Strong understanding of governance, risk and compliance principles
- Practical experience with ISO 27001, NIST, Cyber Essentials or similar
- Experience conducting risk assessments, security assessments or compliance reviews
- Knowledge of information security policies, controls, risk registers and assurance
- Ability to translate complex risks into practical client advice
- Excellent written and verbal communication skills
- Strong stakeholder management and relationship-building abilities
- Experience in regulated environments (e.g., Financial Services, Government, Defence, Energy, Telecommunications) preferred
- Consulting mindset with ability to deliver commercially pragmatic solutions
- excellent communication
- stakeholder management
- consulting mindset
- ISO 27001
- NIST
- Cyber Essentials
…
