At a Glance
- Tasks: Lead GRC consulting engagements and help clients improve their security posture.
- Company: Join Cognisys, a collaborative and innovative tech company.
- Benefits: 25 days annual leave, birthday off, and £2000 training budget.
- Other info: Supportive environment with clear career progression and diverse team.
- Why this job: Make a real impact on clients while developing your security expertise.
- Qualifications: 2-5 years in security or compliance roles; strong communication skills.
The predicted salary is between 40000 - 50000 £ per year.
About The Role
Our GRC Consulting practice helps organisations strengthen their security posture and achieve compliance through clear, structured, and practical guidance. We work with clients at different stages of maturity, from building foundational security programmes to operating mature, scalable compliance functions.
Location: Leeds (Remote)
We are seeking an Information Security Consultant to join our GRC Consulting team. This is a client-facing, delivery-focused role suited to a security and compliance professional who is confident supporting engagements and contributing high-quality advisory services. As an Information Security Consultant, you will support the delivery of GRC engagements across a range of clients and industries. You will help translate regulatory and framework requirements into practical, business-aligned solutions and work collaboratively with senior consultants and client stakeholders to drive measurable improvements in governance, risk, and compliance. This role suits someone with strong foundational GRC knowledge, growing consulting experience, and a desire to develop into a trusted security advisor.
Key Responsibilities
- Client Delivery & Support
- Lead the delivery of GRC consulting engagements across multiple clients and sectors.
- Contribute to security posture assessments, gap analyses, and maturity reviews.
- Assist in the design and implementation of GRC programmes aligned to frameworks such as ISO 27001, SOC 2, NIST, and related standards.
- Support clients through audit preparation, certification processes, and external assessments.
- Develop remediation plans and assist clients in tracking progress against agreed actions.
- Participate and lead in client workshops, risk assessments, and stakeholder sessions.
- Support the interpretation of security standards and regulations, translating requirements into practical recommendations.
- Lead in the development of policies, procedures, risk registers, control frameworks, and governance documentation.
- Contribute to the design and documentation of security controls and operating models.
- Help embed compliance activities into operational and technical processes.
- Conduct risk assessments and maintain supporting documentation.
- Produce high-quality client deliverables with clarity, accuracy, and consistency.
- Follow established methodologies, templates, and internal quality standards.
- Proactively identify areas for improvement within engagements.
- Manage assigned tasks effectively to meet deadlines and scope expectations.
Requirements
- 2–5 years’ experience in security, risk, compliance, or GRC-related roles.
- Practical experience with at least one framework such as ISO 27001, SOC 2, NIST, or similar standards.
- Experience supporting compliance or assurance initiatives (internal or client-facing).
- Strong written and verbal communication skills.
- Ability to manage multiple priorities in a structured and organised manner.
- Analytical mindset with a pragmatic approach to problem solving.
- Comfortable working with both technical and non-technical stakeholders.
- Consulting experience is highly desirable but not essential.
- Experience with GRC platforms including Vanta is desirable.
What We Offer
- 25 days of annual leave plus bank holidays
- Your birthday off
- £2000 Annual personal training and development budget
- A high-trust, supportive environment with clear career progression
- Refer-a-friend bonus scheme (up to £2000)
Why Join Us?
At Cognisys, you will be part of a collaborative and innovative team that values your input and shares support. You will have the opportunity to work on challenging projects that make a real impact on our clients. We welcome applications from diverse backgrounds and can make various reasonable adjustments to accommodate individual needs.
Applications
We’re always happy to help with questions, but to keep our process fair for everyone, we’re unable to accept applications via email—please apply directly through the job advert page. If you would like any further information, to discuss accessibility requirements, or to request this information in an alternative format, please contact Andrea, our Senior Recruiter, at andrea.smith@cognisys.group. NO RECRUITMENT AGENCIES, PLEASE.
Information Security Consultant - UK (SMB) in Leeds employer: Cognisys
Contact Detail:
Cognisys Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Information Security Consultant - UK (SMB) in Leeds
✨Tip Number 1
Network like a pro! Reach out to your connections in the security and compliance field. Attend industry events or webinars, and don’t be shy about introducing yourself. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Showcase your expertise! Create a portfolio of your past projects and achievements related to GRC. This can be a game-changer during interviews, as it gives potential employers a tangible sense of what you bring to the table.
✨Tip Number 3
Prepare for those interviews! Research the company and its clients, and think about how your skills align with their needs. Practise common interview questions, especially around frameworks like ISO 27001 and NIST, so you can speak confidently about your experience.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who take the initiative to engage directly with us. So, get that application in and let’s make it happen!
We think you need these skills to ace Information Security Consultant - UK (SMB) in Leeds
Some tips for your application 🫡
Tailor Your CV: Make sure your CV reflects the skills and experiences that align with the Information Security Consultant role. Highlight your GRC knowledge and any relevant frameworks you've worked with, like ISO 27001 or NIST.
Craft a Compelling Cover Letter: Use your cover letter to tell us why you're passionate about security and compliance. Share specific examples of how you've contributed to client engagements or improved security postures in previous roles.
Showcase Your Communication Skills: Since this is a client-facing role, it's crucial to demonstrate your strong written and verbal communication skills. Make sure your application materials are clear, concise, and free of jargon.
Apply Through Our Website: Remember, we can only accept applications through our job advert page. So, make sure to submit your application there to ensure it gets into our hands!
How to prepare for a job interview at Cognisys
✨Know Your Frameworks
Make sure you brush up on key frameworks like ISO 27001, SOC 2, and NIST. Be ready to discuss how you've applied these in past roles or how you would approach them in a consulting context. This shows you're not just familiar with the terms but can actually translate them into practical solutions.
✨Showcase Your Client Engagement Skills
Since this role is client-facing, prepare examples of how you've successfully managed client relationships in the past. Think about specific situations where you led workshops or contributed to risk assessments, and be ready to share how you navigated challenges and delivered value.
✨Demonstrate Your Problem-Solving Approach
Employers love candidates who can think critically. Prepare to discuss a time when you faced a complex security issue and how you approached solving it. Highlight your analytical mindset and how you balance technical requirements with business needs.
✨Prepare Quality Deliverables
Since producing high-quality client deliverables is crucial, think about how you ensure clarity and accuracy in your work. Bring examples of documentation or reports you've created that align with established methodologies, and be ready to explain your process for maintaining quality standards.