Senior Risk & Resilience Consultant, Information Security (Associate)

Company: Barnett Waddingham
Apply for the Senior Risk & Resilience Consultant, Information Security (Associate)
Location:
Job Description:

Overview

In this role you drive the strategy and growth of Howden’s Information Security practice within a fast-paced consultancy. You’ll lead and mentor the security team, manage client engagements, and align services with business goals across governance, risk, and compliance. You will translate technical risk into business terms for senior stakeholders and shape offerings around ISO/IEC 27001, Cyber Essentials, and AI governance. You’ll collaborate across functions to deliver integrated, client-centric security solutions and stay ahead of evolving threats and technology trends.

Pay / Benefits

  • competitive discretionary annual bonus
  • life assurance of four times salary
  • income protection up to five years at 75% salary
  • private medical insurance
  • pension scheme: 5% employee + 10% employer
  • 25 days annual leave (27 after five years)

Responsibilities

  • Set and lead the strategic direction, performance and growth of the Information Security practice
  • Provide leadership, mentoring and day-to-day management to the Information Security team
  • Develop trusted advisor relationships with clients on governance, risk, and compliance
  • Oversee delivery of engagements across information security disciplines (ISO/IEC 27001, Cyber Essentials) and collaborate across groups
  • Support proposals, client presentations and bid activities to secure new business
  • Monitor threat landscape, regulatory changes and opportunities in AI; keep offerings relevant and innovative
  • Lead development and continuous improvement of methodologies, policies, templates and delivery standards
  • Champion thought leadership through client workshops, webinars, events and publications

Key requirements

  • Proven experience leading information security consultancy services and managing client relationships
  • Strong understanding of information security, risk management and compliance; ability to translate risks into business terms
  • Experience with ISO/IEC 27001, Cyber Essentials and information security governance
  • Experience leading and developing teams with performance management and resource planning
  • Ability to provide strategic security advice to senior stakeholders and support risk-based decisions
  • Experience managing multiple projects and budgets in a consultancy environment
  • Strategic thinking with ability to identify opportunities for growth and service development
  • Ability to deliver information security training and awareness sessions
  • Understanding of AI-related regulations, standards and governance considerations
  • Commercial awareness and client-focused mindset
  • Desirable: CISSP, CISM, CRISC or related certifications
  • Desirable: ISO 27001 Lead Implementer/Lead Auditor, Cyber Essentials Assessor
  • client-focused mindset
  • excellent communication
  • leadership and mentoring
  • ISO/IEC 27001
  • Cyber Essentials
  • information security governance

…

Posted: October 11th, 2026