At a Glance
- Tasks: Deliver high-impact consultancy and conduct audits for top clients in cybersecurity.
- Company: Join Assure Technical, a trusted family-run cybersecurity firm with a stellar reputation.
- Benefits: Enjoy flexible working, competitive salary, healthcare cover, and professional development opportunities.
- Other info: Work in a dynamic environment with excellent career growth and a supportive team culture.
- Why this job: Make a real difference in cybersecurity while working with innovative technologies and expert teams.
- Qualifications: 3+ years in compliance or audit roles; ISO 27001 Lead Auditor certification preferred.
The predicted salary is between 63000 - 77000 £ per year.
Contract: 30+ hours per week
Reports To: Chief Technology Officer
Role Summary
Are you an experienced Information Security and Compliance professional looking to deliver high-impact consultancy for the UK’s most trusted cyber security partner? We are seeking a knowledgeable, client-focused Information Governance Consultant to join our core technical delivery team. In this client-facing role, you will act as a trusted strategic advisor to our external customers while serving as an internal Subject Matter Expert to support internal information governance and security matters as needed.
Success Metrics
- Client Delivery Excellence: Consistent delivery of high-quality consultancy, ISO 27001 implementations, and external audit projects within agreed client timelines and Scope of Work SLAs.
- Audit & Assessment Integrity: Flawless execution of external client assessments and audits, maintaining rigorous compliance with IASME, DCC, and ISO standard requirements.
- Subject Matter Support: Providing effective, high-level subject matter expertise to support the business with internal compliance standards when required.
- Quality Thresholds & Client Satisfaction: Contribution to maintaining our 5.0* Trustpilot rating through clear, accurate report writing and actionable, client-first advice.
- Professional Standards: Successful achievement and maintenance of required assessor accreditations (IASME Cyber Assurance and Defence Cyber Certification).
Key Responsibilities
- Client Consulting & Audit Delivery
- Framework Implementation: Guide clients on best practices for designing, building, and embedding Information Security Management Systems (ISMS) tailored to their business needs.
- Auditing & Assessment: Conduct independent internal audits for clients against ISO 27001 standards and act as an official Assessor for IASME Cyber Assurance and Defence Cyber Certification (DCC).
- Data Protection & Governance: Provide expert advice and practical guidance on data protection compliance, risk assessments, and information governance controls.
- Technical Security Alignment: Bridge the gap between technical security controls and strategic governance to ensure holistic security postures for client organisations.
- Expert Advisory & Knowledge Leadership
- Internal Subject Matter Expertise: Provide expert advice, guidance, and technical analysis in-house, supporting the Office Manager and wider business with subject matter expertise on internal compliance standards as required.
- Framework Expertise: Maintain deep, up-to-date knowledge of evolving standards, including ISO 27001, IASME Cyber Assurance, Defence Cyber Certification (DCC), and NCSC Cyber Assessment Framework (CAF).
- Team Awareness: Aid in increasing internal awareness of information governance, providing guidance and advice to team members across other business functions.
- Continuous Improvement: Keep abreast of emerging cyber threats, regulatory changes, and industry trends, continually improving skills in line with company objectives.
Qualifications, Skills & Attributes Required
- Experience: Minimum 3 years’ hands‑on experience in a compliance, audit, or information governance-focused role (consultancy or in‑house).
- Key Accreditation: Certified ISO 27001 Lead Auditor (substantial, verifiable auditing experience will be considered in lieu of certification).
- Framework Knowledge: Solid understanding of ISO 27001, IASME Cyber Assurance, Cyber Assessment Framework (CAF), and UK GDPR.
- Auditing & Reporting: Strong, accurate report writing skills with high attention to detail and the ability to articulate complex security concepts clearly.
- Stakeholder Management: Proven track record of managing internal and external stakeholders, building trust with C‑suite executives and technical teams alike.
- Personal Traits: Self‑motivated, capable of working independently or collaboratively, with a flexible mindset and an alignment with our core values.
- Qualified IASME Cyber Assurance Assessor and/or Defence Cyber Certification (DCC) Assessor (full training will be offered to achieve these qualifications if not already held).
- ISO 9001 Lead Auditor / Internal Auditor certification.
- Experience working within an NCSC‑aligned or defence‑sector accredited cybersecurity consultancy environment.
- Full UK Driving Licence and willingness to travel to customer sites across the UK and internationally as required.
- UK Cyber Security Council (UKCSC) professional title at Principal / Chartered level.
About Assure Technical
Assure Technical is an award‑winning, family‑run cybersecurity company based in the Malvern Hills, Worcestershire. We are technical security experts who pride ourselves on making security simple for our expanding B2B client base, ranging from progressive SMEs to corporates. With over 350 genuine 5‑star Trustpilot customer reviews and an overall rating of 5.0*, we are the most trusted cyber partner in the UK. We pride ourselves on offering market‑leading solutions and are guided by our core values: We Deliver Excellence, We Do the Right Thing, We Work as One.
Competitive Salary: Market-aligned salary package reflecting your consulting experience and technical accreditations.
Flexible Working: Office‑based in Malvern with periodic remote/WFH options and structured client travel.
Bonus & Pension: Annual performance‑related bonus and enhanced employer pension contributions.
Professional Development: Fully funded training pathways (including IASME Cyber Assurance and Defence Cyber Certification Assessor qualifications).
Workplace Perks: Healthcare cover, tailored personal development plan, 25 days holiday plus Bank Holidays, and a day off for your birthday.
Incredible Location & Facilities: Air‑conditioned offices in the Malvern Hills featuring an on‑site restaurant, free parking, kitchen, and shower facilities.
Relocation Package: Available for outstanding candidates relocating to the region.
Assure Technical is an equal opportunity employer. All applicants must have the right to work in the UK and be eligible for UK Security Clearance (SC) if required. No agencies, please.
Information Governance Consultant (Lead Auditor) employer: Assure Technical
Assure Technical is an exceptional employer, offering a supportive and collaborative work culture in the picturesque Malvern Hills. With a strong focus on professional development, employees benefit from fully funded training pathways and flexible working arrangements, ensuring a healthy work-life balance. The company’s commitment to excellence is reflected in its impressive 5.0* Trustpilot rating, making it a rewarding place for those passionate about cybersecurity to thrive.