At a Glance
- Tasks: Lead GRC consulting engagements and help clients improve their security posture.
- Company: Cognisys, a leading Cyber Security company with a focus on innovation.
- Benefits: Dynamic work environment, professional development budget, healthcare cover, and generous holiday allowance.
- Other info: Supportive culture that values creativity and encourages professional growth.
- Why this job: Join a collaborative team and make a real impact on global clients' security.
- Qualifications: 2-5 years in security or compliance roles, with knowledge of frameworks like ISO 27001.
The predicted salary is between 36000 - 60000 £ per year.
Location: UK (Leeds)
Cognisys is a leading Cyber Security company specialising in Penetration Testing, GRC Consulting, and Managed Security services. We pride ourselves on our customer service, forward-thinking approach, and commitment to excellence. Our small but mighty team works with some of the best-known companies in the world, covering over 30 countries worldwide!
About the Role
Our GRC Consulting practice helps organisations strengthen their security posture and achieve compliance through clear, structured, and practical guidance. We work with clients at different stages of maturity, from building foundational security programmes to operating mature, scalable compliance functions. We are seeking an Information Security Consultant to join our GRC Consulting team. This is a client-facing, delivery-focused role suited to a security and compliance professional who is confident supporting engagements and contributing high-quality advisory services.
As an Information Security Consultant, you will support the delivery of GRC engagements across a range of clients and industries. You will help translate regulatory and framework requirements into practical, business-aligned solutions and work collaboratively with senior consultants and client stakeholders to drive measurable improvements in governance, risk, and compliance. This role suits someone with strong foundational GRC knowledge, growing consulting experience, and a desire to develop into a trusted security advisor.
Key Responsibilities
- Lead the delivery of GRC consulting engagements across multiple clients and sectors.
- Contribute to security posture assessments, gap analyses, and maturity reviews.
- Assist in the design and implementation of GRC programmes aligned to frameworks such as ISO 27001, SOC 2, NIST, and related standards.
- Support clients through audit preparation, certification processes, and external assessments.
- Develop remediation plans and assist clients in tracking progress against agreed actions.
- Participate and lead in client workshops, risk assessments, and stakeholder sessions.
Advisory & Technical Contribution
- Support the interpretation of security standards and regulations, translating requirements into practical recommendations.
- Lead in the development of policies, procedures, risk registers, control frameworks, and governance documentation.
- Contribute to the design and documentation of security controls and operating models.
- Help embed compliance activities into operational and technical processes.
- Conduct risk assessments and maintain supporting documentation.
Quality & Professional Standards
- Produce high-quality client deliverables with clarity, accuracy, and consistency.
- Follow established methodologies, templates, and internal quality standards.
- Proactively identify areas for improvement within engagements.
- Manage assigned tasks effectively to meet deadlines and scope expectations.
Requirements
- 2–5 years’ experience in security, risk, compliance, or GRC-related roles.
- Practical experience with at least one framework such as ISO 27001, SOC 2, NIST, or similar standards.
- Experience supporting compliance or assurance initiatives (internal or client-facing).
- Strong written and verbal communication skills.
- Ability to manage multiple priorities in a structured and organised manner.
- Analytical mindset with a pragmatic approach to problem solving.
- Comfortable working with both technical and non-technical stakeholders.
- Consulting experience is highly desirable but not essential.
- Experience with GRC platforms including Vanta is desirable.
What We Offer
- A dynamic and supportive work environment where customer care and innovation drive everything we do.
- A dedicated budget for your professional development.
- Access to individual healthcare cover.
- 25 days holiday per annum, plus 8 UK bank holidays and a day off for your birthday.
- Refer a friend bonus scheme, up to £2,000!
Why Join Us?
At Cognisys, you’ll be part of a collaborative and innovative team that values your input and shares support. You will have the opportunity to work on challenging projects that make a real impact on our clients. We would love to hear from you if you want to join a high performing team! We are not just about the work; we are about the people. Join a team where creativity is celebrated and your contributions are valued. We foster a supportive environment where fresh ideas thrive and professional growth is encouraged.
Applications
Please feel free to reach out to Andrea, our Senior Recruiter, if you would like any further information, to discuss accessibility requirements, or if you require this information provided in an alternative format – andrea.smith@cognisys.group
We welcome applications from candidates from diverse backgrounds and will make reasonable adjustments as required to accommodate individual needs.
Information Security Consultant in Leeds employer: Cognisys
Contact Detail:
Cognisys Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Consultant in Leeds
✨Tip Number 1
Network like a pro! Reach out to your connections in the cyber security field, especially those who work at Cognisys or similar companies. A friendly chat can lead to insider info about job openings and even referrals.
✨Tip Number 2
Prepare for interviews by brushing up on your GRC knowledge. Make sure you can confidently discuss frameworks like ISO 27001 and SOC 2. We want to see you shine as a trusted advisor during those client-facing scenarios!
✨Tip Number 3
Showcase your problem-solving skills! Be ready to share examples of how you've tackled compliance challenges in the past. We love candidates who can think on their feet and provide practical solutions.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows us you’re genuinely interested in joining our awesome team at Cognisys.
We think you need these skills to ace Information Security Consultant in Leeds
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Information Security Consultant role. Highlight your experience with GRC frameworks like ISO 27001 or NIST, and show us how your skills align with our needs.
Showcase Your Communication Skills: Since this is a client-facing role, it’s crucial to demonstrate your strong written and verbal communication skills. Use clear and concise language in your application to reflect your ability to convey complex information effectively.
Highlight Relevant Experience: Don’t forget to mention any practical experience you have in security, risk, or compliance roles. If you've supported compliance initiatives or worked with GRC platforms, let us know – we want to see what you bring to the table!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows us you’re keen on joining our team!
How to prepare for a job interview at Cognisys
✨Know Your Frameworks
Make sure you brush up on key frameworks like ISO 27001, SOC 2, and NIST. Be ready to discuss how you've applied these in past roles or how you would approach implementing them in a new environment.
✨Showcase Your Client Engagement Skills
Since this role is client-facing, prepare examples of how you've successfully managed client relationships. Think about times when you led workshops or contributed to stakeholder sessions, and be ready to share those stories.
✨Demonstrate Your Problem-Solving Mindset
Be prepared to discuss specific challenges you've faced in security or compliance roles and how you tackled them. Highlight your analytical skills and pragmatic approach to problem-solving, as these are crucial for the position.
✨Prepare Quality Deliverables
Familiarise yourself with producing high-quality documentation. Bring examples of your work that demonstrate clarity, accuracy, and consistency. This will show that you understand the importance of quality standards in GRC consulting.