Information Security Consultant, Senior Risk & Resilience Consultant
Information Security Consultant, Senior Risk & Resilience Consultant

Information Security Consultant, Senior Risk & Resilience Consultant

Full-Time 43200 - 72000 £ / year (est.) No home office possible
Go Premium
B

At a Glance

  • Tasks: Support clients in enhancing their security and achieving certifications like ISO/IEC 27001.
  • Company: Join a leading consultancy with a focus on risk and resilience in information security.
  • Benefits: Enjoy a competitive salary, generous holiday, and a range of employee benefits.
  • Why this job: Make a real impact by guiding organisations through critical security processes.
  • Qualifications: Experience in ISO/IEC 27001 implementation and strong communication skills required.
  • Other info: Flexible working options and excellent career development opportunities await you.

The predicted salary is between 43200 - 72000 £ per year.

We have an exciting, permanent opportunity for a Senior Risk & Resilience Consultant / Information Security Consultant to join any of our 11 UK offices (hybrid working) as we continue to grow following the Howden acquisition. We are looking for an experienced Information Security Consultant to support our clients in improving their security posture and achieving recognised certifications. This role is hands-on and client-facing.

You will guide organisations through the implementation and internal audit of ISO/IEC 27001, lead them through the Cyber Essentials certification process, and help build security awareness across the business. You will also support clients in understanding and managing third-party security risks, responding to assurance requests, and making informed decisions about risk. A key part of the role is the ability to explain information security risks in a meaningful way that relates directly to business impact, enabling stakeholders to make clear, informed decisions.

Responsibilities

  • Lead and support clients through the implementation of ISO/IEC 27001, from gap analysis to readiness for certification.
  • Plan and conduct internal audits against ISO/IEC 27001, including reporting findings and recommending improvements.
  • Guide organisations through the Cyber Essentials and Cyber Essentials Plus certification process.
  • Design, review, and improve information security policies, processes, and controls that are proportionate and practical.
  • Explain information security risks to stakeholders in clear, business-focused terms, linking technical issues to business impact such as operational disruption, financial loss, regulatory exposure, or reputational damage.
  • Deliver information security training and awareness sessions to staff at different levels of the organisation.
  • Tailor training content to suit technical and non-technical audiences.
  • Support and guide clients in the event of an information security incident, helping them understand next steps, containment, and reporting obligations.
  • Support clients with third-party security assessments, including responding to customer security questionnaires; assessing supplier security posture and risks; advising on proportionate assurance and risk treatment approaches.
  • Manage security projects, including planning, tracking progress, managing risks, and meeting deadlines.
  • Act as a trusted advisor, translating security requirements into clear business actions.
  • Facilitate workshops and meetings with stakeholders ranging from operational teams to senior leadership.
  • Produce clear, well-structured documentation and reports suitable for both technical and non-technical audiences.
  • Support continuous improvement of clients’ information security management practices.

Qualifications

  • Proven experience implementing ISO/IEC 27001 within an organisation or as a consultant and performing or supporting internal audits against ISO/IEC 27001.
  • Practical experience guiding organisations through the Cyber Essentials certification process.
  • Experience delivering information security training or awareness sessions.
  • Experience supporting or responding to third-party security assessments or questionnaires.
  • Demonstrated ability to communicate information security risks in business terms, not just technical language.
  • Excellent understanding of information security risk management and controls.
  • Experience managing projects, including timelines, dependencies, and stakeholder expectations.
  • Excellent communication skills, both written and verbal with confidence engaging with people at all levels of an organisation, including senior management.
  • Experience with data protection and privacy, such as UK GDPR or EU GDPR.
  • Experience supporting organisations during security incidents or data breaches.
  • Experience assessing supplier risk or working with vendor risk management processes.
  • Experience with supporting organisations with Business Continuity planning (ISO 22301).
  • Relevant certifications (e.g. ISO 27001 Lead Implementer, Lead Auditor, Cyber Essentials Assessor, CISM, CISSP).
  • Previous consultancy or client-facing experience.

What’s in it for you

  • Competitive discretionary annual bonus.
  • Core benefits paid for by BW including life assurance, group income protection, private medical cover and 25 days holiday per year with holiday trading.
  • A generous pension scheme where we contribute 8% of your salary from day one of your employment.
  • Employee Assistance Programme to support you and your family through any concerns or challenges you may experience.
  • A comprehensive range of voluntary benefits to suit you (and your family) including an electric car leasing scheme, tech scheme, cycle to work scheme, dental cover, healthcare cash plan, health assessments, critical illness cover, extension of private medical cover or life assurance to family members, Sports Allowance – we pay up to 50% of your gym/sports membership (up to £50 pm), travel insurance, paid volunteering, and a broad range of discounts at hundreds of retailers including supermarkets, fitness centres, travel and leisure companies.

We are a Disability Confident Employer. If you reasonable adjustments could support you, or if you would like more information on accessibility, please click here.

Information Security Consultant, Senior Risk & Resilience Consultant employer: Barnett Waddingham

At Barnett Waddingham, we pride ourselves on being an exceptional employer, offering a dynamic work environment that fosters professional growth and collaboration. With competitive benefits including a generous pension scheme, private medical cover, and a range of voluntary perks, we ensure our employees feel valued and supported. Our commitment to flexible working and a culture of inclusivity makes our 11 UK offices an ideal place for experienced Information Security Consultants to thrive while making a meaningful impact on clients' security postures.
B

Contact Detail:

Barnett Waddingham Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Consultant, Senior Risk & Resilience Consultant

✨Tip Number 1

Network like a pro! Reach out to your connections in the industry, attend relevant events, and engage with professionals on LinkedIn. We can’t stress enough how important it is to make those personal connections that could lead to job opportunities.

✨Tip Number 2

Prepare for interviews by practising common questions and scenarios related to information security. We recommend role-playing with a friend or using mock interview platforms to boost your confidence and refine your responses.

✨Tip Number 3

Showcase your expertise! Create a portfolio or case studies of your past projects, especially those involving ISO/IEC 27001 or Cyber Essentials. This will help you stand out and demonstrate your hands-on experience to potential employers.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are genuinely interested in joining our team and contributing to our mission.

We think you need these skills to ace Information Security Consultant, Senior Risk & Resilience Consultant

ISO/IEC 27001 Implementation
Internal Auditing
Cyber Essentials Certification
Information Security Policy Design
Risk Management
Stakeholder Communication
Information Security Training Delivery
Third-Party Security Assessment
Project Management
Data Protection and Privacy (UK GDPR, EU GDPR)
Incident Response
Business Continuity Planning (ISO 22301)
Client-Facing Experience
Clear Documentation and Reporting

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights your experience with ISO/IEC 27001 and Cyber Essentials. We want to see how you've helped clients improve their security posture, so be specific about your achievements!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're the perfect fit for this role. Share your passion for information security and how you can help our clients make informed decisions about risk.

Showcase Your Communication Skills: Since you'll be explaining complex security risks to stakeholders, it's crucial to demonstrate your ability to communicate clearly. Use straightforward language in your application to show us you can bridge the gap between technical and business terms.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates during the process!

How to prepare for a job interview at Barnett Waddingham

✨Know Your Standards

Make sure you’re well-versed in ISO/IEC 27001 and Cyber Essentials. Brush up on the key principles and be ready to discuss how you've implemented these standards in past roles. This will show your expertise and readiness for the hands-on nature of the job.

✨Speak Their Language

Practice explaining complex information security risks in simple, business-focused terms. Use examples that relate directly to potential impacts like financial loss or operational disruption. This will demonstrate your ability to communicate effectively with stakeholders at all levels.

✨Showcase Your Training Skills

Prepare to discuss your experience in delivering information security training. Think of specific examples where you tailored content for different audiences. Highlighting your ability to engage both technical and non-technical staff will set you apart.

✨Project Management Prowess

Be ready to talk about your project management experience, especially in relation to security projects. Discuss how you’ve managed timelines, tracked progress, and met deadlines. This will illustrate your organisational skills and ability to handle multiple responsibilities.

Information Security Consultant, Senior Risk & Resilience Consultant
Barnett Waddingham
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

B
  • Information Security Consultant, Senior Risk & Resilience Consultant

    Full-Time
    43200 - 72000 £ / year (est.)
  • B

    Barnett Waddingham

    500-1000
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>