Permanent | Hybrid (2 days per week in office)
Bestman Solutions is supporting a large and highly regarded organisation undertaking a significant programme of technology modernisation, cyber resilience, and operational transformation.
As part of its continued investment in information security, the organisation is seeking an experienced Information Security Consultant to help strengthen security governance, risk management, and secure-by-design practices across a complex technology estate.
This is a highly visible role that combines security consultancy, risk assessment, stakeholder engagement, and technical advisory responsibilities. You will work closely with technology, project, and business teams to ensure security is embedded effectively across strategic initiatives and day-to-day operations.
The role would suit someone who enjoys balancing technical understanding with practical security advice and is looking to influence security outcomes within a mature and evolving environment.
Key Responsibilities
- Conduct information security risk assessments across technology platforms, projects, and business initiatives
- Provide security consultancy and guidance to technical and non-technical stakeholders
- Review solution designs and architecture to ensure alignment with security requirements and best practice
- Support the development, implementation, and continuous improvement of security policies, standards, and control frameworks
- Identify security gaps and provide pragmatic recommendations to reduce organisational risk
- Assess security controls across cloud, infrastructure, and enterprise technology environments
- Support vulnerability management and remediation programmes
- Assist with audit, compliance, and regulatory activities
- Promote secure-by-design principles across projects and change initiatives
- Build strong relationships across the business to enhance security awareness and resilience
Required Experience
- Experience working as an Information Security Consultant, Security Advisor, Security Analyst, or similar cyber security professional
- Strong understanding of information security governance, risk management, and security controls
- Experience conducting security reviews, risk assessments, and control evaluations
- Good understanding of infrastructure, network, cloud, and application security concepts
- Familiarity with vulnerability management and remediation processes
- Knowledge of recognised security frameworks and standards, including:
- ISO 27001
- NIST Cyber Security Framework
- CIS Controls
- Ability to communicate complex security concepts clearly to a range of stakeholders
- Strong stakeholder management and consultancy skills
- Exposure to cloud platforms such as Azure, AWS, or GCP
- Security certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or equivalent
- Experience working within regulated or complex enterprise environments
What’s on Offer
- Opportunity to influence security strategy and resilience across a large-scale organisation
- Exposure to a broad range of security, technology, and transformation initiatives
- Hybrid working environment
- Ongoing professional development and career progression opportunities
#J-18808-Ljbffr…
