Information Security Consultant - UK (Remote)

 Posted an hour ago
     
 £35000 - £42000 per year
  
2-5 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

Deliver Governance, Risk, and Compliance consulting engagements across multiple industries, including conducting security assessments and gap analyses. Facilitate client workshops, develop remediation plans, and assist clients in achieving regulatory compliance and certification.

Location: UK (Remote)

Salary: £35 - £42k per annum (DOE)

About Cognisys

At Cognisys, we help organisations strengthen their security posture through expert Governance, Risk & Compliance (GRC) consulting, Penetration Testing and Managed Security Services.

Our consultants work alongside clients to solve complex security and compliance challenges, providing practical, business-focused advice that helps organisations build resilient security programmes and achieve regulatory compliance.

As we continue to grow our GRC Consulting practice, we're looking for an Information Security Consultant to join our expanding team.

The Opportunity

Our GRC Consulting team partners with organisations at every stage of their security journey—from building foundational governance programmes to supporting mature organisations operating within complex regulatory environments.

As an Information Security Consultant, you'll work with a diverse range of clients across multiple industries, helping them strengthen their governance, risk and compliance capabilities through practical, commercially focused security advice.

This is a client-facing consulting role where you'll deliver a variety of GRC engagements, helping clients understand regulatory requirements, improve their security posture and implement effective governance frameworks.

Working alongside experienced consultants, you'll build trusted client relationships, support complex security projects and play an important role in delivering exceptional consulting outcomes.

Whether you're conducting maturity assessments, supporting ISO 27001 implementations, facilitating risk workshops or preparing clients for certification, you'll help organisations turn compliance requirements into meaningful business improvements.

What You'll Be Doing

Client Consulting & Delivery

  • Deliver Governance, Risk & Compliance consulting engagements across multiple clients and industries.

  • Conduct security posture assessments, gap analyses and maturity reviews.

  • Support clients through audit preparation, certification activities and external assessments.

  • Develop remediation plans and assist clients in tracking agreed actions through to completion.

  • Facilitate client workshops, risk assessments and stakeholder meetings.

  • Build trusted relationships with clients by providing practical, commercially focused security advice.

  • Support multiple client engagements while ensuring projects are delivered on time and to a high standard.

Governance, Risk & Compliance

  • Assist clients in designing and implementing governance, risk and compliance programmes aligned to recognised frameworks including:

    • ISO 27001

    • SOC 2

    • NIST Cybersecurity Framework

    • Other recognised industry standards

  • Interpret security standards and regulatory requirements, translating them into practical business recommendations.

  • Develop and maintain governance documentation including:

    • Information Security Policies

    • Standards and Procedures

    • Risk Registers

    • Control Frameworks

    • Risk Assessments

    • Governance documentation

  • Support organisations in embedding governance and compliance activities into day-to-day operational processes.

  • Assist clients in developing pragmatic security controls that align with both business objectives and regulatory expectations.

Continuous Improvement

  • Produce high-quality consulting deliverables that meet Cognisys' standards for quality, consistency and professionalism.

  • Identify opportunities to improve client security programmes and internal delivery methodologies.

  • Manage multiple consulting engagements while balancing competing priorities and deadlines.

  • Collaborate closely with colleagues across consulting and technical teams to deliver exceptional client outcomes.

What Success Looks Like

Success in this role is about becoming a trusted security advisor who delivers exceptional client outcomes while helping organisations build stronger, more resilient security and compliance programmes.

You will:

  • Successfully deliver multiple GRC consulting engagements, ensuring projects are completed on time, within scope and to the high standards expected by Cognisys.

  • Build trusted relationships with clients by providing practical, commercially focused advice that helps them navigate complex governance, risk and compliance challenges.

  • Confidently support organisations through certification and compliance initiatives, including ISO 27001, SOC 2 and other recognised frameworks.

  • Produce clear, accurate and professional client deliverables, including policies, procedures, risk assessments, control frameworks and governance documentation.

  • Demonstrate strong knowledge of governance, risk and compliance frameworks by translating regulatory requirements into practical, business-focused recommendations.

  • Effectively manage multiple client engagements while maintaining exceptional communication, organisation and stakeholder management.

  • Collaborate successfully with colleagues and client stakeholders to deliver successful consulting engagements and positive client outcomes.

  • Contribute to the continuous improvement of the GRC Consulting practice by enhancing methodologies, documentation, templates and ways of working.

  • Continue developing your consulting expertise and establish yourself as a trusted Information Security Consultant within the Cognisys team.

About You

We're looking for someone who enjoys solving problems, building trusted client relationships and helping organisations strengthen their security posture.

You'll be naturally organised, proactive and comfortable managing multiple priorities while working across a variety of client engagements.

Most importantly, you'll enjoy translating complex security and compliance requirements into practical advice that creates real value for clients.

Essential Skills & Experience

  • 2–5 years' experience in Governance, Risk & Compliance (GRC), Information Security or Risk Management.

  • Practical experience working with one or more recognised security frameworks, including:

    • ISO 27001

    • SOC 2

    • NIST Cybersecurity Framework

    • Other recognised governance and compliance standards

  • Experience supporting compliance, assurance or certification activities.

  • Strong written communication skills with the ability to produce clear, professional client documentation.

  • Excellent stakeholder management and client communication skills.

  • Strong organisational skills with the ability to manage multiple client engagements simultaneously.

  • Analytical mindset with a pragmatic, solution-focused approach to problem solving.

  • Comfortable working with both technical and non-technical stakeholders.

Desirable Skills & Experience

  • Previous consulting experience within a client-facing professional services environment.

  • Experience delivering ISO 27001 implementation or certification projects.

  • Exposure to SOC 2, NIST, PCI DSS, Cyber Essentials Plus or similar security frameworks.

  • Experience conducting information security risk assessments and governance reviews.

  • Experience using GRC platforms such as Vanta or similar governance tools.

Certifications

The following certifications are highly regarded:

  • SO/IEC 27001 Lead Implementer

  • ISO/IEC 27001 Lead Auditor

  • CISSP (Certified Information Systems Security Professional)

  • CISM (Certified Information Security Manager)

  • CRISC (Certified in Risk and Information Systems Control)

  • Security+ or equivalent security certifications

Why Join Us?

At Cognisys, you will be part of a collaborative and innovative team that values your input and shares support. You'll have the opportunity to work on challenging projects that make a real impact for our clients. We'd love to hear from you if you want to challenge, lead and innovate! We're not just about the work; we're about the people. Join a team where innovation is celebrated, and your contributions are valued. We foster a collaborative environment where fresh ideas thrive, and professional growth is encouraged.

What we Offer:

  • Annual Leave: 25 days per year plus 8 English bank holidays.

  • Additional Leave: 1 day of paid leave for your Birthday.

  • Health & Wellbeing: Access to Westfield Health Care Cash Plan and an employee mental health and wellbeing platform.

  • Professional Development: £2,000 annual training budget to support your continued learning and career growth.

  • Referral Bonus: help to grow our team and earn up to £2,000 per successful referral.

Applications

We’re always happy to help with questions, but to keep our process fair for everyone, we’re unable to accept applications via email—please apply directly through the job advert page.

Please feel free to reach out to Andrea, our Talent Acquisition Lead, if you would like any further information, to discuss accessibility requirements, or if you require this information provided in an alternative format – andrea.smith@cognisys.co.uk

We welcome applications from candidates from a range of diverse backgrounds and can make various reasonable adjustments to consider individual needs.

Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Software Development

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified