Senior Risk & amp ; Resilience Consultant , Information Security ( Associate ) - BW Career Site in Birmingham

Senior Risk & amp ; Resilience Consultant , Information Security ( Associate ) - BW Career Site in Birmingham

Birmingham Full-Time 60000 - 75000 £ / year (est.) Hybrid
B

At a Glance

  • Tasks: Lead a dynamic security team and guide clients through ISO/IEC 27001 and Cyber Essentials.
  • Company: Join a fast-growing consultancy with a collaborative culture and exciting projects.
  • Benefits: Enjoy competitive pay, generous holiday, health cover, and a range of flexible benefits.
  • Other info: Flexible working options and a supportive environment for personal growth.
  • Why this job: Make a real impact in information security while developing your leadership skills.
  • Qualifications: Experience in ISO/IEC 27001 and strong communication skills are essential.

The predicted salary is between 60000 - 75000 £ per year.

We have an exciting, permanent opportunity for a Senior Risk & Resilience Consultant / Information Security Consultant & Manager (Associate level) to join any of our 11 UK offices (hybrid working) as we continue to grow following the Howden acquisition. You’ll provide day to day leadership within a growing and fast paced consultancy environment, ensuring the security team delivers high quality, responsive services to both internal stakeholders and clients.

This role includes full line management responsibilities, such as setting clear objectives, holding regular one-to-one meetings, supporting professional development, and managing performance in a constructive and accountable manner. You will coordinate workloads across multiple concurrent client engagements, mentor team members, and foster a collaborative, solutions focused culture. You will also work closely with other areas of the organisation including data privacy, business continuity, and enterprise risk to ensure a cohesive and aligned approach to assurance.

In addition to leadership responsibilities, this position is hands on and client facing. You will guide organisations through the implementation and internal audit of ISO/IEC 27001, support them through the Cyber Essentials certification process, and help embed effective security awareness across their business. You’ll also assist clients in assessing and managing third party security risks, responding to assurance requests, and making well informed risk decisions.

A key requirement of the role is the ability to communicate information security risks clearly and meaningfully, translating technical issues into business focused impacts that enable stakeholders to make confident, informed decisions.

  • Lead and support clients through ISO/IEC 27001 implementation, from gap analysis to certification readiness
  • Plan and deliver internal ISO/IEC 27001 audits and recommend practical improvements
  • Guide organisations through Cyber Essentials and Cyber Essentials Plus certification
  • Develop and improve proportionate information security policies, processes, and controls
  • Explain information security risks in clear, business focused terms, linking technical issues to real world impact
  • Deliver tailored security training and awareness sessions for technical and non-technical audiences
  • Support clients during information security incidents, advising on containment, next steps, and reporting
  • Assist with third party security assessments, including supplier reviews, customer questionnaires, and assurance guidance
  • Manage security projects, including planning, monitoring progress, and managing risks
  • Act as a trusted advisor, translating security requirements into actionable business recommendations
  • Facilitate workshops and meetings with stakeholders at all levels
  • Produce clear, well-structured documentation and reports
  • Support ongoing improvement of clients’ information security management practices

Line Management Responsibilities

  • Provide day to day leadership to the security team in a fast-paced consultancy environment
  • Set objectives, hold regular one to ones, and manage performance and development
  • Mentor team members and provide quality assurance on deliverables
  • Allocate workloads across multiple client engagements to maintain high quality delivery
  • Foster a supportive, collaborative, practical and delivery focused team culture
  • Support recruitment, onboarding, and capability development

Proven experience:

  • Implementing ISO/IEC 27001 as a consultant
  • Conducting or supporting internal ISO/IEC 27001 audits
  • Guiding organisations through Cyber Essentials and/or Cyber Essentials Plus
  • Delivering effective information security training and awareness sessions
  • Supporting or responding to third party security assessments
  • Explaining security risks in clear, business focused terms
  • Managing projects, timelines, and stakeholder expectations
  • Engaging and influencing stakeholders at all levels, including senior leadership
  • Demonstrated line management and leadership capability, including mentoring, performance management, and team development

Experience with:

  • Data protection and privacy, such as UK GDPR or EU GDPR
  • Supporting organisations during security incidents or data breaches
  • Assessing supplier risk or working with vendor risk management processes
  • Supporting organisations with Business Continuity planning (ISO 22301)

Relevant certifications:

  • ISO 27001 Lead Implementer
  • Lead Auditor
  • Cyber Essentials Assessor
  • CISM
  • CISSP

What's in it for you:

  • Competitive discretionary annual bonus.
  • Core benefits paid for by BW including life assurance, group income protection, private medical cover and 25 days holiday per year with holiday trading.
  • A generous pension scheme where we contribute 8% of your salary from day one of your employment.
  • Employee Assistance Programme to support you and your family through any concerns or challenges you may experience.
  • A comprehensive range of voluntary benefits to suit you (and your family) including an electric car leasing scheme, tech scheme, cycle to work scheme, dental cover, healthcare cash plan, health assessments, critical illness cover, extension of private medical cover or life assurance to family members, Sports Allowance – we pay up to 50% of your gym/sports membership (up to 50 pm), travel insurance, paid volunteering, and a broad range of discounts at hundreds of retailers including supermarkets, fitness centres, travel and leisure companies.

For a full list of benefits, please click here.

Happy to talk flexible working.

Accessibility: We are a Disability Confident Employer. If you reasonable adjustments could support you, or if you would like more information on accessibility, please click here.

Not quite the right opportunity for you this time? For more about us and other Careers at BW, please click here.

We kindly ask recruitment agencies to not send speculative CVs. Should we need assistance, we will reach out. All enquiries should be directed to.

Senior Risk & amp ; Resilience Consultant , Information Security ( Associate ) - BW Career Site in Birmingham employer: Barnett Waddingham

Barnett Waddingham is an excellent employer, offering a supportive work culture that values detail-oriented professionals in the IT sector. With hybrid working options available in vibrant locations like Birmingham and Amersham, employees benefit from a competitive package that includes a generous pension and annual bonus, alongside ample opportunities for personal and professional growth within a collaborative environment.

B

Contact Details:

Barnett Waddingham Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Risk & amp ; Resilience Consultant , Information Security ( Associate ) - BW Career Site in Birmingham

✨Join Compliance Communities

Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!

✨Attend Industry Conferences

Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.

✨Leverage Your University Career Services

If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.

✨Showcase Your Knowledge Online

Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Barnett Waddingham looking for candidates who are engaged and informed.

We think you need these skills to ace Senior Risk & amp ; Resilience Consultant , Information Security ( Associate ) - BW Career Site in Birmingham

ISO/IEC 27001 Implementation
Cyber Essentials Certification
Information Security Risk Management
Internal Auditing
Project Management
Stakeholder Engagement
Communication Skills

Some tips for your application 🫡

Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!

Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.

Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!

Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Barnett Waddingham. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!

How to prepare for a job interview at Barnett Waddingham

✨Master the Regulations

Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!

✨Show Your Analytical Skills

Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!

✨Know Your Tools

Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!

✨Align with Company Culture

Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Barnett Waddingham’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!