Information Security & GRC Consultant

Information Security & GRC Consultant

Full-Time On-site
C

Join a leading telecommunications company as an Information Security & GRC Consultant and play a key role in strengthening security governance, compliance, resilience, and M&A security due diligence across a complex enterprise environment.

Job Overview:

This is a hands-on opportunity for experienced security professionals who can take ownership, drive delivery, and implement practical solutions rather than simply providing recommendations. You'll support strategic initiatives spanning ISO 27001, SOC 2, business continuity, third-party risk management, and acquisition-related security assessments.

Contract Details:

  • Location: London or Bradford (hybrid - 2 days per week onsite)
  • Rate: Β£650 per day (inside IR35)
  • Contract Length: 6 months (with visibility to extend or go permanent afterwards)

Key Responsibilities

  • Conduct cyber security risk assessments and security due diligence activities for mergers and acquisitions, identifying risks, remediation requirements and integration priorities.
  • Assess, maintain and enhance security frameworks aligned to ISO 27001 and SOC 2 Type II standards.
  • Develop and maintain security policies, standards, procedures, risk registers and remediation plans.
  • Lead and support business continuity and disaster recovery activities, including Business Impact Assessments (BIAs), recovery planning and resilience testing.
  • Perform third-party and supplier security assessments, ensuring security and continuity requirements are met across the supply chain.
  • Prepare stakeholders and control owners for internal and external compliance audits, gathering evidence and driving audit readiness.
  • Deliver security awareness initiatives and provide clear, practical guidance to both technical and non-technical stakeholders.

Key Requirements

  • Proven hands-on experience implementing, managing or auditing ISO 27001 and SOC 2 compliance programmes.
  • Demonstrable experience conducting M&A security due diligence and assessing cybersecurity risks in acquisition environments.
  • Strong background in security governance, risk management, compliance and control remediation.
  • Experience building, improving or operationalising security frameworks within a complex organisation.
  • Excellent stakeholder management skills with the ability to influence, challenge and drive actions through to completion.
  • Experience with business continuity, disaster recovery or operational resilience programmes is highly desirable.

Ideal backgrounds include

Information Security Manager, Information Security Officer, Security Governance Lead, Security Compliance Manager, GRC Consultant or Security Risk Consultant.

Start Date:

ASAP

#J-18808-Ljbffr

Information Security & GRC Consultant employer: Consult

At Consult, we pride ourselves on being an exceptional employer that fosters a dynamic and inclusive work culture. Our North America team is dedicated to professional growth, offering robust training and development opportunities while working in a fast-paced, innovative environment. Join us to be part of a collaborative team that values your contributions and supports your career aspirations in the exciting MedTech sector.

C

Contact Details:

Consult Recruitment Team