Senior Information Security Consultant (GRC)

Reference: mg52i6otc3h4p3ykyz2n

We are seeking a Senior Information Security Consultant (GRC) to provide expert guidance on governance, risk and compliance across a complex technology and business environment. The successful candidate will work with stakeholders at all levels to assess information security risks, strengthen control frameworks and support the continued development of effective security governance practices. This role requires a pragmatic consultant who can translate regulatory, technical and business requirements into clear, achievable improvements.

Responsibilities will include conducting information security and technology risk assessments, maintaining risk registers and developing appropriate mitigation plans. You will support the design, implementation and review of security policies, standards, procedures and control frameworks, while coordinating assurance activities, internal audits and external assessments. The role will also involve mapping controls to relevant legislation, regulations and industry standards, such as ISO 27001, NIST, COBIT or applicable data protection requirements. You will prepare clear reports and management information, track remediation actions, and provide constructive advice on control gaps and emerging risks.

You will build strong working relationships with technology, business, legal, privacy, procurement and operational teams, helping to embed security and risk management into projects, change initiatives and day-to-day processes. Experience supporting third-party risk management, security questionnaires, supplier reviews, business continuity or incident management would be valuable. Applicants should have substantial experience in information security governance, risk or compliance, with a strong understanding of security principles, control testing and regulatory expectations. Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer or Lead Auditor are desirable. Excellent communication, analytical and stakeholder management skills are essential, along with the ability to work independently, prioritise competing demands and present complex information clearly to both technical and non-technical audiences.

COMPETITIVE SALARY
Added 01/09/2026
Reference: mg52i6otc3h4p3ykyz2n

Senior Information Security Consultant (GRC)

Durham, England, United Kingdom Permanent Security Consultant

Other similar jobs

Information Security Consultant

Added 09/09/2026

We are seeking an experienced Information Security Consultant to help organisations strengthen their security posture, manage cyber risks and meet relevant regulatory and industry requirements. In this role, you will work closely with stakeholders across technology, operations and governance functions to assess information security controls, identify vulnerabilities and recommend practical improvements. You will contribute to security assessments, risk reviews, policy development and the design of effective security frameworks aligned with recognised standards such as ISO 27001, NIST or CIS. Your responsibilities will include conducting security and risk assessments, supporting audits, reviewing technical and organisational controls, and developing clear reports for...

Learn more

Executive Information Security Consultant (OT)

Added 03/09/2026

We are seeking an experienced Executive Information Security Consultant (OT) to provide strategic leadership and expert guidance across operational technology environments. In this role, you will advise senior stakeholders on the protection of industrial control systems, manufacturing technologies, critical infrastructure, and other connected operational assets. You will help shape security strategy, strengthen resilience, and ensure that cybersecurity considerations are embedded into business, engineering, and transformation initiatives. Your responsibilities will include assessing OT security risks, developing pragmatic mitigation plans, and supporting the implementation of governance, policies, standards, and operating models. You will lead or contribute to security assessments, architecture reviews, threat...

Learn more

Executive Information Security Consultant (OT)

Added 03/09/2026

We are seeking an experienced Executive Information Security Consultant (OT) to provide strategic leadership and expert guidance across operational technology environments. In this role, you will help protect critical infrastructure, industrial control systems, and connected operational platforms against evolving cyber threats. You will work closely with senior stakeholders, technology leaders, engineering teams, and business units to develop practical security strategies that support resilience, safety, compliance, and operational continuity. Your responsibilities will include assessing OT security maturity, identifying risks and vulnerabilities, and defining proportionate controls across industrial networks, control systems, remote access solutions, and associated enterprise integrations. You will lead or...

Learn more

Technical Security Consultant

Added 26/08/2026

Technical Security Consultant sought to provide expert security guidance across a range of technology, infrastructure and business initiatives. This role will work closely with technical teams, project stakeholders and business leaders to identify security requirements, assess risks and recommend practical controls that support resilient and effective solutions. The successful candidate will contribute to security-by-design principles throughout the project lifecycle, from initial planning and architecture through to implementation and operational handover. Key responsibilities will include conducting security reviews, threat modelling, risk assessments and architectural evaluations; advising on cloud, network, application, identity and infrastructure security; and producing clear, actionable recommendations for remediation....

Learn more

Technical Security Consultant

Added 26/08/2026

We are seeking a Technical Security Consultant to provide expert advice and practical support across a range of information and cyber security initiatives. This role will work closely with technical teams, project managers and business stakeholders to identify security risks, define appropriate controls and ensure that solutions are designed and implemented securely. The successful candidate will contribute to security assessments, architecture reviews, risk analysis and the development of clear, actionable recommendations. Key responsibilities will include reviewing technical designs and proposed changes, advising on security requirements, supporting vulnerability management and assisting with the investigation and resolution of security incidents. You will...

Learn more

Technical Security Consultant

Added 25/08/2026

We are seeking a Technical Security Consultant to provide expert guidance on the design, implementation and improvement of secure technology environments. You will work with stakeholders across infrastructure, cloud, applications and operations to identify security risks, recommend practical controls and support the delivery of resilient solutions. The role will involve translating business and technical requirements into clear security advice while helping teams embed secure-by-design principles throughout the technology lifecycle. Key responsibilities will include conducting security assessments, threat modelling, architecture and design reviews, vulnerability reviews and risk assessments. You will develop and maintain security standards, policies, patterns and technical documentation, and...

Learn more

Senior Information Security Consultant (GRC)

Added 01/09/2026

We are seeking a Senior Information Security Consultant (GRC) to provide expert guidance on governance, risk and compliance across a complex technology and business environment. The successful candidate will help strengthen information security frameworks, support risk-informed decision-making and ensure that security practices align with regulatory obligations, industry standards and organisational objectives. This role requires a confident consultant who can engage effectively with senior stakeholders, technical teams and business leaders. Key responsibilities will include conducting information security and technology risk assessments, maintaining risk registers, developing treatment plans and advising on appropriate controls. You will lead or contribute to security governance activities,...

Learn more

Information Security Manager/GRC Consultant - Telecoms

Added 05/08/2026

We are seeking an experienced Information Security Manager/GRC Consultant with a focus on the telecoms sector to oversee and enhance our information security framework. In this role, you will be responsible for developing, implementing, and maintaining a comprehensive Governance, Risk management, and Compliance (GRC) strategy that aligns with industry best practices and regulatory requirements. You will lead risk assessments, manage security audits, and ensure adherence to applicable laws and standards while also providing guidance on security policies and procedures to safeguard sensitive information. The ideal candidate will have a strong background in information security management, with expertise in telecoms-specific challenges...

Learn more

Senior / Managing SAP GRC & IAM Consultant

Added 18/09/2026

We are seeking a Senior / Managing SAP GRC & IAM Consultant to lead the design, implementation and continuous improvement of SAP governance, risk and compliance, identity and access management solutions. You will work closely with business stakeholders, IT teams, security functions and project leadership to deliver secure, compliant and practical access models across complex SAP environments. The role offers the opportunity to provide strategic direction while remaining engaged in hands-on delivery, solution architecture and client-facing consulting. Your responsibilities will include assessing existing SAP security and access-control landscapes; designing and implementing SAP GRC Access Control, Risk Management and Process Control...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance activities. In this role, you will lead the development, implementation and continuous improvement of cybersecurity policies, standards, procedures and control frameworks. You will work closely with technology, security, legal, privacy, audit and business stakeholders to ensure that security risks are identified, assessed and managed in line with organisational objectives and regulatory expectations. Key responsibilities include leading enterprise security risk assessments, maintaining risk registers and treatment plans, and advising on appropriate mitigation strategies. You will coordinate internal and external audits, support regulatory and...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic direction and hands-on leadership across governance, risk and compliance activities. In this role, you will advise senior stakeholders on cybersecurity risk, regulatory obligations and control effectiveness, while helping to strengthen security governance and embed sustainable risk management practices across the organisation. You will lead complex engagements from assessment through to remediation, ensuring that security objectives are aligned with business priorities. Key responsibilities will include developing and maintaining cybersecurity policies, standards, frameworks and control libraries; conducting risk assessments, control reviews, maturity assessments and compliance gap analyses; and preparing clear...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking an experienced Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance initiatives. In this role, you will help strengthen the organisation’s security posture by developing and maintaining cybersecurity policies, standards, procedures and control frameworks aligned with recognised industry practices and regulatory requirements. You will work closely with technology, risk, legal, audit and business stakeholders to translate security objectives into practical, measurable and sustainable outcomes. Your responsibilities will include leading cybersecurity risk assessments, control evaluations, compliance reviews and third-party risk assessments; identifying gaps; and recommending prioritised remediation plans. You will coordinate evidence collection and...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking a Lead Cybersecurity GRC Consultant to provide strategic leadership across governance, risk, and compliance initiatives. This role will help strengthen the organisation’s cybersecurity posture by translating business objectives, regulatory obligations, and industry standards into practical security policies, controls, and improvement programmes. You will work closely with technology, risk, legal, audit, privacy, and business stakeholders to promote a consistent, risk-based approach to information security. Key responsibilities include leading cybersecurity risk assessments, control reviews, maturity assessments, and remediation planning; maintaining and improving security governance frameworks; and supporting compliance with applicable regulations, contractual requirements, and recognised standards such as ISO...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking a Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance initiatives. In this role, you will lead the development, implementation and continuous improvement of cybersecurity frameworks, policies, standards and procedures aligned with recognised industry practices and regulatory requirements. You will work closely with technology, risk, legal, compliance, audit and business stakeholders to strengthen security governance and embed effective risk management across the organisation. Key responsibilities include leading cybersecurity risk assessments, control reviews, compliance gap analyses and remediation programmes. You will advise on regulatory obligations, customer and third-party assurance requirements, and the design and...

Learn more

Lead Cybersecurity GRC Consultant

Added 14/09/2026

We are seeking a Lead Cybersecurity GRC Consultant to provide strategic guidance across governance, risk and compliance initiatives. This role will lead the development, implementation and continuous improvement of cybersecurity frameworks, policies, standards and controls aligned with recognised industry practices and applicable regulatory requirements. You will work closely with technology, privacy, legal, risk and business stakeholders to strengthen security governance and support informed risk-based decision-making. Key responsibilities include managing enterprise security risk assessments, maintaining risk registers and treatment plans, coordinating internal and external audits, and overseeing compliance activities against frameworks such as ISO 27001, NIST, SOC 2 or equivalent standards....

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.