Senior GRC Consultant | Cyber Risk Advisory
£65,000 base - £70,000 base salary (DOE) + up to 10% bonus + benefits
Remote-first UK | Genuine flexibility | Ownership of client engagements
Take ownership of meaningful client work, with the trust and support to deliver it well.
You know how to turn complex requirements into a clear delivery plan, keep stakeholders informed and see a programme through to completion. Whether working independently or leading junior consultants, clients and colleagues can rely on you.
We’re partnering with a growing UK cyber security consultancy to appoint a Senior GRC Consultant to its collaborative advisory team.
This is a delivery-focused role, with responsibility for leading substantial GRC programmes and turning advice into practical improvements. You’ll stay hands-on, own your client commitments and coordinate support from colleagues where assignments require a wider team.
Why consider a move?
- Trust and ownership. Take the lead on sizeable client projects, with the autonomy to organise delivery and use your professional judgement.
- Genuine flexibility. Join a business with a genuinely flexible, remote-first working culture, with occasional client and office travel.
- Varied, challenging work. Deliver assessments, audits, implementation programmes and incident response tabletop exercises across different client environments.
- Supportive colleagues. Work alongside the GRC Lead and wider cyber security specialists who share knowledge, discuss challenges and contribute their expertise.
- The opportunity to lead through delivery. Guide junior consultants on engagements, helping them contribute effectively while taking responsibility for the overall outcome.
The work
You’ll lead and deliver engagements covering ISO 27001, Cyber Essentials, third-party risk and wider GRC programmes, working independently or with a team of junior consultants.
Your responsibilities will include:
- Translating client requirements into clear plans, milestones and deliverables.
- Taking ownership of large GRC assignments from initial scoping through to completion.
- Coordinating and guiding junior consultants, reviewing their contributions and maintaining delivery quality.
- Delivering assessments, audits and implementation activity, with practical recommendations that clients can act on.
- Planning and facilitating incident response tabletop exercises, helping clients test their response arrangements and identify improvements.
- Managing scope, timelines, dependencies and stakeholder expectations, addressing issues early to keep delivery on track.
- Communicating progress, findings and recommendations clearly to senior client stakeholders.
Depending on client needs, assignments may also involve CAF, NIST, DORA, NIS2 and ISO 42001.
What you’ll bring
- Three or more years’ experience in information security consulting and/or auditing.
- A track record of leading large GRC programmes, independently or with support from junior consultants.
- The organisation, judgement and accountability to take a substantial project and deliver it successfully.
- Hands-on ISO 27001 experience and practical Cyber Essentials delivery or auditing experience.
- Experience delivering incident response tabletop exercises.
- Confidence managing client relationships, communicating with senior stakeholders and balancing competing delivery priorities.
- A collaborative approach and the ability to provide clear direction and constructive feedback to colleagues.
ISO 27001 Lead Auditor or Lead Implementer qualifications, alongside CISM or CISSP, are particularly desirable.
If you enjoy taking ownership, delivering work clients can depend on and helping colleagues succeed, this is an opportunity to do that within a genuinely flexible, supportive team.
