Senior GRC Consultant

Senior GRC Consultant

Leeds Full-Time 34000 - 42000 £ / year (est.) No home office possible
C

At a Glance

  • Tasks: Join our GRC team to ensure clients' data is secure and compliant.
  • Company: Cognisys is a leading cybersecurity firm focused on innovation and customer service.
  • Benefits: Enjoy hybrid work, professional development budget, wellness resources, and 22-25 days holiday.
  • Why this job: Be part of a collaborative team making a real impact in cybersecurity.
  • Qualifications: Five years in GRC consultancy with strong client-facing experience required.
  • Other info: Open to diverse backgrounds; focus on ability and attitude over strict qualifications.

The predicted salary is between 34000 - 42000 £ per year.

Location: Leeds (Hybrid) / London also considered

Salary: £40 - £50K (DOE)

We have an exciting opportunity to join our GRC team as a Senior GRC Consultant at a time of rapid growth and innovation at Cognisys. Cognisys is a leading cybersecurity company specialising in Penetration Testing, GRC Consulting, and Managed Security services. We pride ourselves on our customer service, forward-thinking approach, and commitment to excellence. Our small but mighty team works with some of the best-known companies in the world, covering over 30 countries worldwide!

About the Role

At Cognisys, our Governance, Risk, and Compliance (GRC) team is central to our mission of ensuring our clients’ data is protected to the highest standards of security and compliance. Due to our continued expansion, we are excited to announce an opportunity to further build our GRC team with an experienced and driven individual. Your contribution will be essential to the future growth of this team.

Key Responsibilities

  • Ensure that our clients establish robust governance frameworks, manage risks effectively, and maintain compliance with regulatory standards.
  • Conduct thorough security audits to evaluate and improve the effectiveness of risk management, control and governance processes.
  • Independently deliver a wide range of GRC consultancy projects across client environments, including ISO 27001 implementation and maintenance, SOC 2 readiness assessments, GDPR compliance, and broader information security frameworks.
  • Conduct comprehensive internal audits, gap analysis, and maturity assessments aligned with industry standards.
  • Perform thorough risk assessments and develop actionable risk treatment plans tailored to client needs and business context.
  • Design, write, and maintain information security policies, procedures, and documentation for clients across multiple sectors.
  • Lead governance and compliance initiatives, including client-facing reporting, audit readiness support, and continual service improvement.
  • Build trusted relationships with clients through consistent, expert guidance and support across security and compliance engagements.
  • Mentor and develop junior consultants, supporting their delivery quality and professional growth.

Requirements

  • Minimum five years of experience in a GRC consultancy or lead security role with significant client-facing responsibilities.
  • Proven ability to independently deliver information security engagements across ISO 27001, SOC 2, GDPR, NIST, or similar frameworks.
  • In-depth knowledge of information security principles, compliance standards, and regulatory requirements.
  • A recognised certification in information security, audit, or compliance (e.g. ISO 27001 Lead Implementer/Auditor, CISSP, CISM).
  • Track record of managing multiple projects simultaneously and delivering high-quality work to deadlines.
  • Excellent communication skills, including the ability to convey complex security and compliance matters to technical and non-technical audiences.
  • Strong analytical and problem-solving abilities with attention to detail.
  • Commitment to mentoring and developing junior team members.

If you think you can deliver but don't match the criteria above, please don't be put off. We are very open-minded and focus on ability and attitude above skills.

What We Offer

  • A dynamic and supportive work environment where customer care and innovation drive everything we do.
  • A dedicated budget for your professional development.
  • EMI Employee Share Schemes provide the opportunity to share in the company's success.
  • Access to an Employee Wellness Hub supported by Kara Connect for health and well-being resources.
  • Frequent team social events and celebrations.
  • 22 days holiday rising to 25, plus a birthday holiday.
  • Refer a friend bonus scheme, up to £2,000!

Why Join Us?

At Cognisys, you will be part of a collaborative and innovative team that values your input and shares support. You'll have the opportunity to work on challenging projects that make a real impact on our clients. We'd love to hear from you if you want to challenge, lead and innovate! We're not just about the work; we're about the people. Join a team where innovation is celebrated and your contributions are valued. We foster a collaborative environment where fresh ideas thrive and professional growth is encouraged.

Applications

Please feel free to reach out to Dom, our Head of Talent Acquisition, if you would like any further information, to discuss accessibility requirements, or if you require this information provided in an alternative format – hiring@cognisys.co.uk

We welcome applications from candidates from diverse backgrounds and can make various reasonable adjustments to accommodate individual needs.

NO RECRUITMENT AGENCIES, PLEASE

Senior GRC Consultant employer: Cognisys

Cognisys is an exceptional employer that champions a dynamic and supportive work culture, where innovation and customer care are at the forefront of everything we do. With a strong commitment to employee growth, we offer dedicated budgets for professional development, EMI Employee Share Schemes, and a wellness hub to support your health and well-being. Join our collaborative team in Leeds or London, where your contributions are valued, and you can make a meaningful impact on clients across the globe.
C

Contact Detail:

Cognisys Recruiting Team

hiring@cognisys.co.uk

StudySmarter Expert Advice 🤫

We think this is how you could land Senior GRC Consultant

✨Tip Number 1

Familiarise yourself with the specific frameworks mentioned in the job description, such as ISO 27001 and SOC 2. Being able to discuss these frameworks in detail during your interview will demonstrate your expertise and readiness for the role.

✨Tip Number 2

Network with current or former employees of Cognisys on platforms like LinkedIn. Engaging with them can provide you with insider knowledge about the company culture and expectations, which can be invaluable during your application process.

✨Tip Number 3

Prepare to showcase your experience in managing multiple projects simultaneously. Think of specific examples where you successfully delivered high-quality work under tight deadlines, as this is a key requirement for the role.

✨Tip Number 4

Highlight your mentoring experience in your discussions. Since the role involves developing junior consultants, being able to articulate how you've supported others in their professional growth will set you apart from other candidates.

We think you need these skills to ace Senior GRC Consultant

Governance Framework Development
Risk Management
Compliance Standards Knowledge
ISO 27001 Implementation
SOC 2 Readiness Assessment
GDPR Compliance
Information Security Audits
Gap Analysis
Maturity Assessments
Risk Assessment and Treatment Planning
Policy and Procedure Documentation
Client Relationship Management
Project Management
Mentoring and Coaching
Excellent Communication Skills
Analytical Skills
Problem-Solving Skills
Attention to Detail

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in GRC consultancy, particularly with frameworks like ISO 27001, SOC 2, and GDPR. Use specific examples to demonstrate your expertise and achievements in these areas.

Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for cybersecurity and your understanding of the role. Mention how your skills align with Cognisys' mission and values, and express your enthusiasm for contributing to their GRC team.

Highlight Soft Skills: In addition to technical skills, emphasise your communication abilities and experience in mentoring junior consultants. This is crucial as the role involves building relationships with clients and guiding team members.

Proofread Your Application: Before submitting, carefully proofread your application materials for any spelling or grammatical errors. A polished application reflects your attention to detail, which is essential for a Senior GRC Consultant.

How to prepare for a job interview at Cognisys

✨Showcase Your GRC Expertise

Make sure to highlight your experience with frameworks like ISO 27001, SOC 2, and GDPR during the interview. Be prepared to discuss specific projects you've worked on and how you contributed to their success.

✨Demonstrate Strong Communication Skills

Since you'll be conveying complex security concepts to both technical and non-technical audiences, practice explaining these topics clearly and concisely. Use examples from your past experiences to illustrate your points.

✨Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving abilities in real-world situations. Think of scenarios where you've had to conduct risk assessments or manage compliance issues, and be ready to explain your thought process and outcomes.

✨Emphasise Mentorship Experience

Cognisys values mentorship, so be sure to discuss any experience you have in developing junior consultants. Share specific examples of how you've supported their growth and improved team performance.

Senior GRC Consultant
Cognisys
C
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>