> Markdown version of [/jobs/ext/1215025-senior-information-security-consultant](https://www.wearedevelopers.com/jobs/ext/1215025-senior-information-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Consultant - **Company:** CYBERFORT LIMITED - **Location:** UK (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Microsoft Windows, Artificial Intelligence, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, PCI Data Security Standards, Microsoft PowerPoint, RSA Archer Platform, Gsuite, Servicenow - **Published:** July 9, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=ec7f9bf21aae014e ## About the Role * Highly organised with strong project and engagement management capabilities. * Proven ability to manage multiple workstreams simultaneously. * Accountable for delivery quality, timelines, and outcomes. * Comfortable operating independently in complex and ambiguous environments. Technical & Security Expertise * Strong working knowledge of recognised security frameworks and standards, including ISO 27001, NIST CSF, CAF, Cyber Essentials, CSA CCM, and ISO 42001. * Deep understanding of information security governance, risk management, control design, and assurance principles. * Experience leading security assessments, audit programmes, certification initiatives, and compliance engagements. * Good understanding of cloud and SaaS security, particularly Microsoft 365 and Google Workspace environments. * Knowledge of emerging areas such as AI governance, AI risk management, and regulatory compliance. Client & Consulting Skills * Excellent stakeholder management and relationship-building skills. * Trusted advisor mindset with the ability to influence and challenge constructively. * Strong facilitation, presentation, and communication skills. * Ability to translate complex security concepts into practical business language. * Commercial awareness and the ability to identify opportunities to expand client value. Leadership & Professionalism * Demonstrates leadership through coaching, and knowledge sharing. * Maintains high professional and ethical standards. * Proactive, adaptable, and solutions-focused. * Committed to continuous professional development and industry awareness., * Experience delivering information security, risk, governance, compliance, or assurance engagements. * Experience leading client-facing consulting projects and managing stakeholder relationships. * Strong understanding of information security frameworks, standards, and risk management methodologies. * Demonstrable experience delivering assessments, audits, gap analyses, and security improvement programmes. * Experience producing and reviewing senior-level reports and recommendations. * Strong Microsoft 365 skills, particularly Word, Excel, and PowerPoint. Desirable * Experience leading ISO 27001 implementation, certification, or surveillance programmes. * Experience with NIST CSF, CAF, Cyber Essentials, PCI DSS, DSPT CSA CCM, ISO 42001, or similar frameworks. * Experience using GRC platforms such as Vanta, One Trust, ServiceNow GRC, or equivalent. * Familiarity with Microsoft Azure, Microsoft 365, Google Workspace, and cloud security governance. * Experience with Technical implementation of security tooling * Experience supporting AI governance and AI risk management initiatives. * Project management experience within consulting or professional services environments., Professional certifications are strongly preferred and will be viewed favourably alongside practical consulting experience. Relevant certifications such as ISO 27001 Auditor/Implementer, ISC2 certifications (e.g. CC, CISSP, CGRC), ISACA certifications (e.g. CISM, CRISC), Cyber Essentials Assessor, PCIDSS QSA, ISO 42001, or equivalent. Equivalent experience and demonstrable capability will also be considered. ## Description As a Senior Information Security Consultant, you will act as a trusted advisor to clients, leading complex engagements, managing project delivery, and providing operational and strategic security guidance across governance, risk, compliance, and security improvement initiatives. You will work with stakeholders at all levels, from operational teams to senior leadership, helping organisations make informed, risk-based decisions that align security with business objectives. In addition to delivery, you will contribute to business improvement through quality engagements, account development, supporting consultants, and continuously improving methodologies and services., Project & Engagement Leadership * Lead the delivery of information security consulting engagements across frameworks such as ISO 27001, NIST, CAF, Cyber Essentials, CSA CCM, ISO 42001 and related standards. * Manage projects from initiation through to completion, ensuring delivery against agreed scope, timelines, budgets, and quality expectations. * Lead security assessments, gap analyses, risk reviews, audit readiness activities, and compliance improvement programmes. * Oversee project plans, resource allocation, risk management, and stakeholder communications throughout engagements. * Produce and review high-quality client deliverables, ensuring outputs are commercially relevant, technically accurate, and actionable. Client Advisory & Stakeholder Management * Act as a trusted advisor to clients, providing strategic, operational and practical security guidance. * Build and maintain strong client relationships, developing a deep understanding of business objectives, risks, and operating environments. * Facilitate workshops, executive briefings, and stakeholder meetings. * Present findings, recommendations, and remediation roadmaps to senior management and executive audiences. * Manage client expectations, engagement risks, issues, and escalation points effectively. Governance, Risk & Compliance * Lead the design, implementation, and improvement of security governance, risk management, and compliance programmes. * Conduct and oversee risk assessments using recognised methodologies including ISO 27005, NIST or equivalent approaches. * Support clients in developing and maintaining security policies, standards, procedures, risk registers, and compliance frameworks. * Provide guidance on security metrics, assurance activities, certification readiness, and regulatory obligations. * Maintain awareness of emerging security, regulatory, and AI governance requirements Continuous Improvement * Identify opportunities to provide additional value and support the growth of client accounts. * Recognise follow-on engagement opportunities and work collaboratively with account managers and leadership teams. * Support the development of new service offerings, consulting methodologies, and reusable delivery assets. * Share knowledge, lessons learned, and industry best practice across the consulting practice. * Drive continuous improvement of delivery standards, templates, methodologies, and internal processes., Senior Cyber Security Consultant Locations Remote Remote status Fully Remote ## Related Videos - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)