> Markdown version of [/jobs/ext/46696-information-security-consultant](https://www.wearedevelopers.com/jobs/ext/46696-information-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Consultant - **Company:** OmniCyber Security Services Ltd - **Location:** UK (Remote available) - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Security Management System, CIS Benchmarks - **Published:** May 15, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=b511862c764112e9 ## About the Role Do you have experience in NIST standards?, Technical & Framework Expertise * Strong working knowledge of ISO/IEC 27001:2022 (essential). * Practical experience with NIST CSF assessments or implementation. * Solid understanding of GDPR principles, data protection impact assessments, and privacy governance. * Familiarity with supplementary frameworks or regulations (e.g. CIS Controls, DORA, NIS2, SOC 2, ISO 22301) is highly desirable. Consultancy Skills * Demonstrable experience in client-facing roles within security, audit or GRC. * Ability to produce concise, clear and well-structured documentation suitable for senior stakeholders. * Strong analytical and problem-solving capabilities. * Comfortable working independently and able to "hit the ground running". Industry Certifications (desirable but not mandatory) * ISO 27001 Lead Implementer / Lead Auditor * CISM, CISSP, CRISC, CISA ## Description Governance, Risk and Compliance * Lead or support the implementation, maintenance and internal auditing of Information Security Management Systems (ISMS) aligned to ISO/IEC 27001:2022. * Assist clients in developing security policies, standards and procedures covering all core domains. * Conduct maturity assessments against ISO 27001, NIST CSF, CIS Controls, DSPT, and other recognised frameworks. * Deliver GDPR compliance assessments, support DPIAs, ROPAs, and advise on privacy-related control gaps. Risk Management * Facilitate risk assessments, threat identification, and risk treatment planning, including development of security risk registers. * Advise on appropriate control selection aligned to business context, risk tolerance and regulatory obligations. * Support clients in establishing ongoing risk governance, including risk committees, management reporting and oversight processes. Audit, Assurance and Certification * Prepare organisations for external certification audits (ISO 27001, ISO 22301, DSPT). * Perform internal audits and readiness assessments, identifying non-conformities, observations and improvement actions. * Produce well-structured audit reports, dashboards and action plans for senior management. Incident Management & Business Continuity * Support clients in tabletop exercises, and resilience planning activities. * Advise on alignment to ISO 22301, DORA, NIS2, and sector-specific resilience requirements. Client Delivery & Consultancy * Act as a trusted advisor to client leadership, translating technical issues into clear, business-focused recommendations. * Produce professional documentation, including policies, roadmaps, risk reports, and board-level updates. * Manage multiple engagements concurrently, ensuring high-quality outputs and strong client satisfaction. * Contribute to the continued development of Omni's methodologies, templates, and best-practice guidance. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Communicate efficiently with Software Architecture Diagrams](https://www.wearedevelopers.com/videos/379-communicate-efficiently-with-software-architecture-diagrams) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)