GRC Cybersecurity Consultant - SC Cleared

Roleyou
High Wycombe, UK
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Identity and Access Management Information Security Management System

Job description

We are seeking an experienced SC Cleared GRC Cyber Security Consultant to play a pivotal role in assessing cyber security capabilities, shaping strategic roadmaps, and driving meaningful improvements across complex organisations. About the RoleYou will work closely with CISOs and senior technology leaders to elevate cyber security from a technical function to a strategic business enabler. This role combines hands-on delivery, stakeholder engagement, and business development within a dynamic consulting environment. Key ResponsibilitiesPerform information security maturity assessments and develop actionable security and resilience roadmaps.Conduct information security risk assessments and Business Impact Assessments (BIA).Design and implement Information Security Management Systems (ISMS).Identify, analyse, and embed security and resilience controls (e.g., access management, incident response, continuity planning).Measure, monitor, and report on organisational security posture aligned to risk appetite and evolving threats.Support CISOs and technology leaders across operational and transformation initiatives.Ensure quality and timely delivery of client projects and deliverables.Lead post-engagement reviews to drive continuous improvement.Build and maintain strategic client relationships and external networks.Lead development of innovative client proposals, presentations, and pitches.Identify and pursue new business opportunities with minimal oversight.

Requirements

Minimum 5 years’ consulting experience (applications not meeting this criterion will not be considered).SC ClearedStrong understanding of the challenges faced by CISOs.Solid grasp of risk-based decision-making and information security risk management.Experience implementing Cyber, Privacy, and Third-Party standards and frameworks including those from National Institute of Standards and Technology (NIST), MITRE Corporation (MITRE), Information Security Forum (ISF), and International Organization for Standardization (ISO).Experience implementing against the UK CAF in telecommunications or other Operators of Essential Services (OES) is advantageous.Proven stakeholder management and communication skills.Certifications such as CISSP or CISM are advantageous for more experienced candidates.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on apply4u.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:27 min

Centralizing access with open source identity management providers

Den Prysukhin · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all