Salary: Β£50,000 - 60,000 per year
Requirements:
- Strong experience in ISO 27001 implementation, internal audit, ISMS maintenance, and engagement with external auditors
- Solid understanding of the Data Protection Act and GDPR
- Experience in security management, including risk, incident, and ISMS management, security working groups, and monitoring and measuring maturity
- Experience working with frameworks such as NIST CSF, CIS, and NCSC CAF
- Experience in supplier management, including third-party supplier security assessments
- Experience managing risk and recommending mitigating actions
- Knowledge of Cyber Essentials and IASME Cyber Assurance standards
- Outstanding written and verbal communication skills with an emphasis on confidentiality, tact, and diplomacy
- Ability to multitask, work as part of a team, and work independently
- Formal ISO certifications such as Lead Auditor or Lead Implementer are desirable
- Formal Data Protection Officer certification is desirable
- Principal or Chartered Cyber Security Professional status in Cyber Security Audit and Assurance or Cyber Security Governance and Risk is desirable
- Certified IASME Cyber Assurance Assessor status is desirable
- Certified IASME DCC Assessor status is desirable
- Good technical skills and understanding of IT and cloud services are desirable
- Solid understanding of AI Governance and ISO 42001 is desirable
Responsibilities:
- Lead and support client ISO 27001 implementation projects from initiation to certification
- Conduct client Defence Cyber Certification (DCC) assessments and help clients gain formal certification
- Provide information security, cyber security, and data privacy/GDPR consultancy to clients
- Lead PCI and SOC2 client engagements
- Support clients with the implementation of AI governance capabilities and formal certification to ISO 42001
- Perform cyber security maturity assessments using recognised frameworks from CIS and NIST and make recommendations for improvement
- Provide vCISO and vDPO services to clients and support client security working groups
- Support sales and marketing initiatives in promoting our consultancy and managed security services
Technologies:
- AI
- Cloud
- Support
- Marketing
- Security
More:
We are an independent ISO and CREST certified cyber security consultancy providing security consultancy and managed security services to a wide range of clients and partners. We are hiring a Lead Security Consultant to join our team in Manchester on a hybrid basis. This full-time role offers a 40-hour working week, up to Β£60,000 per annum depending on skills and experience, up to 10% annual bonus, funded InfoSec training, time for self-study, 25 days holiday plus bank holidays, private health care, company pension, career development opportunities, and regular team meals and activities.
last updated 36 week of 2026
#J-18808-Ljbffr
Lead Security Consultant GRC ISO 27001 PCI SOC2 in Manchester employer: Confidential
As a leading employer in the data centre operations sector, we offer an exceptional work environment that prioritises employee growth and development. Our collaborative culture fosters innovation and accountability, while our commitment to safety and operational excellence ensures that you will be part of a team that values your contributions. With opportunities for international travel and the chance to lead critical operations across the EMEA region, this role provides a unique platform for impactful leadership and career advancement.