At a Glance
- Tasks: Lead the development of Cyber GRC practices and manage cyber risks across major projects.
- Company: Join Jacobs, a global leader in solving critical infrastructure challenges.
- Benefits: Enjoy flexible working, comprehensive health cover, and a supportive work culture.
- Other info: Hybrid working model with excellent career growth opportunities.
- Why this job: Make a real impact on cyber governance while shaping the future of infrastructure.
- Qualifications: Experience in cyber security governance and strong stakeholder engagement skills required.
The predicted salary is between 67500 - 82500 £ per year.
At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems for thriving cities, resilient environments, mission-critical outcomes, operational advancement, scientific discovery and cutting-edge manufacturing, turning abstract ideas into realities that transform the world for good.
Your impact
Join us at a pivotal moment as we strengthen cyber governance, risk and compliance across one of the UK's most significant infrastructure programmes. This is an opportunity to shape and lead a modern Cyber GRC capability from the ground up. You'll play a critical role in ensuring cyber risks are effectively understood, managed and communicated, helping senior leaders make informed decisions that support successful project delivery.
As the dedicated Cyber GRC professional supporting this team and programme, you'll have the autonomy to create meaningful change, influence stakeholders across multiple disciplines, and establish scalable approaches that could be adopted more broadly across Jacobs. For the right person, this role offers the chance to make a visible impact today while helping shape the future direction of Cyber GRC across major programmes.
What you'll do
As Lead Cyber Security GRC Consultant, you'll be responsible for developing and embedding effective governance, risk and compliance practices across a complex project environment. Working closely with cyber, IT, digital, delivery and project teams, you'll ensure cyber risks are identified, assessed and managed effectively while building stronger links between cyber risk and wider programme risk management processes. You'll lead the development and implementation of policies, standards, controls and assurance activities, helping to transform existing manual processes into streamlined, digitally enabled ways of working. You'll also provide clear, evidence-based reporting that translates technical and cyber risks into meaningful insights for senior stakeholders and decision-makers. This is a hands-on consultancy role requiring a practical approach, strong stakeholder engagement skills and the ability to drive outcomes through influence rather than direct authority.
Here's what you'll need
We're looking for an experienced Cyber GRC professional who can operate independently and confidently within a complex environment. You'll bring:
- Proven experience delivering end-to-end cyber security or IT security governance, risk and compliance activities.
- Strong experience conducting and managing cyber risk assessments, remediation activities and senior-level risk reporting.
- Experience creating and implementing cyber policies, standards, frameworks and governance processes.
- Knowledge of recognised security and risk frameworks such as ISO 27001, NIST, NCSC CAF, Government Security Standards, or equivalent.
- The ability to communicate complex cyber risks clearly to both technical and non-technical audiences.
- A proactive, delivery-focused mindset with the confidence to challenge constructively, remove barriers and work autonomously.
- Experience with Microsoft Azure, Microsoft 365, operational technology (OT) environments, government projects, or critical national infrastructure would be beneficial.
At Jacobs, we deliver solutions that matter. You'll be trusted to take ownership, encouraged to challenge constructively, and supported to create meaningful change. This is a unique opportunity to build and shape a Cyber GRC capability, work on a high-profile infrastructure programme, and influence how cyber risk is managed at scale. If you're looking for a role where you can make a lasting impact while continuing to grow your career, we'd love to hear from you.
Other key info
This is a full time, permanent role, UK based, hybrid (2-3 days/week - office/site) aligned to a local Jacobs office, with business travel to support client and business requirements. Full time employment at Jacobs is based on a 40-hour working week. We place a strong emphasis on work life balance and flexibility, and flexi-time is available. All Jacobs employees will require a BPSS check as part of the hiring and onboarding process. This role will be subject to UK Security Vetting at SC (security check) level. Applicants must be eligible and willing to undergo the appropriate security clearance process, if not already cleared. Any offer of employment will be conditional upon satisfactory completion of the relevant clearance process.
We offer an excellent and wide range of employee benefits including comprehensive Health Cover, Life Assurance, Income Protection, holiday buy/sell scheme, and a variety of wellbeing, family, parental and fertility support offerings, along with an enhanced contribution pension scheme.
Joining Jacobs not only connects you locally but globally. Our values stand on a foundation of safety, integrity, inclusion and belonging. We put people at the heart of our business, and we truly believe that by supporting one another through our culture of caring, we all succeed. We value positive mental health and a sense of belonging for all employees.
With safety and flexibility always top of mind, we’ve gone beyond traditional ways of working so you have the support, means and space to maximize your potential. You’ll uncover flexible working arrangements, benefits, and opportunities, from well-being benefits to our global giving and volunteering program, to exploring new and inventive ways to help our clients make the world a better place. No matter what drives you, you’ll discover how you can cultivate, nurture, and achieve your goals – all at a single global company.
We aim to embed inclusion and belonging in everything we do. We know that if we are inclusive, we’re more connected and creative. We accept people for who they are, and we champion the richness of different perspectives, lived experiences and backgrounds in the workplace, as a source of learning and innovation. We are committed to building vibrant communities within Jacobs, including through our Jacobs Employee Networks, Communities of Practice and our Find Your Community initiatives, allowing every employee to find connection, purpose, and belonging.
Jacobs partners with VERCIDA to help us attract and retain talent from a wide range of backgrounds. As a disability confident employer, we will interview disabled candidates who best meet the criteria. We welcome applications from candidates who are seeking flexible working and from those who may not meet all the listed requirements for a role.
We value collaboration and believe that in-person interactions are crucial for both our culture and client delivery. We empower employees with our hybrid working policy, allowing them to split their work week between Jacobs offices/projects and remote locations enabling them to deliver their best work.
Your application experience is important to us, and we’re keen to adapt to make every interaction even better. If you require further support or reasonable adjustments with regards to the recruitment process (for example, you require the application form in a different format), please contact the team via Careers Support.
Lead Cybersecurity GRC Consultant in London employer: Jacobs
At Jacobs, we pride ourselves on being an exceptional employer, offering a dynamic and inclusive work culture that prioritises safety, integrity, and collaboration. Our Glasgow office provides flexible working arrangements and a wealth of opportunities for professional growth, allowing you to contribute to innovative maritime projects while being part of a supportive team that values diverse perspectives. Join us to make a meaningful impact in the world of civil and structural engineering, all while enjoying the benefits of a global network and a commitment to employee well-being.
StudySmarter Expert Advice🤫
We think this is how you could land Lead Cybersecurity GRC Consultant in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Jacobs, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Jacobs
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Jacobs. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Lead Cybersecurity GRC Consultant in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Jacobs insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Jacobs that you’re committed to staying ahead in the game.
How to prepare for a job interview at Jacobs
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Jacobs to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Jacobs.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.