ISO 27001 Consultant & Auditor – Defence Cyber Certification

Reference: jqr2tshdplqcpro8vbmt

We are seeking an experienced ISO 27001 Consultant & Auditor to support organisations operating in the defence and wider security-sensitive sectors. This role will involve helping clients establish, improve and maintain robust information security management systems (ISMS) aligned with ISO/IEC 27001 and relevant defence cyber certification requirements. You will work with stakeholders at all levels to assess current controls, identify risks and develop practical, proportionate solutions that meet regulatory, contractual and operational expectations.

Key responsibilities will include planning and delivering ISO 27001 gap assessments, internal audits, readiness reviews and certification support engagements. You will document findings, assess corrective actions and provide clear, evidence-based reports for technical and executive audiences. The role will also involve supporting risk assessments, Statement of Applicability development, security policy reviews, control implementation, audit preparation and the ongoing improvement of management systems. You may contribute to defence-focused cyber assurance activities, including interpreting applicable security frameworks, supply-chain requirements and customer-specific certification standards. Building trusted relationships with clients, managing assigned engagements and maintaining accurate project documentation will be important parts of the position.

Applicants should have substantial experience working with ISO/IEC 27001, preferably across consultancy, internal audit or certification-readiness environments. A recognised ISO 27001 Lead Auditor or Lead Implementer qualification is expected, together with a strong understanding of information security governance, risk management, control design and audit methodology. Experience within defence, government, critical national infrastructure or other regulated environments would be advantageous, as would familiarity with cyber assurance schemes and secure supply-chain requirements. You should be confident interviewing stakeholders, analysing evidence, challenging constructively and presenting recommendations clearly. Strong written and verbal communication, sound judgement, attention to detail and the ability to manage multiple priorities are essential. Applicants may be required to undergo security screening appropriate to the assignments.

COMPETITIVE SALARY
Added 14/09/2026
Reference: jqr2tshdplqcpro8vbmt

ISO 27001 Consultant & Auditor – Defence Cyber Certification

Cheltenham, England, United Kingdom Permanent Security Consultant

Other similar jobs

Certification and Assurance - Senior Security/Technology Risk Analyst

Added 20/08/2026

We are seeking a skilled and experienced Senior Security/Technology Risk Analyst to join our dynamic team. In this role, you will be responsible for identifying, assessing, and managing risks associated with technology and security across various platforms. You will conduct thorough risk assessments, ensuring compliance with regulatory requirements and internal policies. This includes evaluating the effectiveness of existing security controls and making recommendations for enhancements to safeguard our systems and data. You will also collaborate with cross-functional teams to implement security best practices and promote a culture of risk awareness within the organization. The ideal candidate will possess a deep...

Learn more

Certification and Assurance - Senior Security/Technology Risk Analyst

Added 13/08/2026

We are seeking a highly skilled Senior Security/Technology Risk Analyst to join our dynamic team. In this role, you will be responsible for assessing and mitigating security risks associated with technology and information systems. You will conduct thorough risk assessments, develop risk management strategies, and ensure compliance with industry standards and regulations. The ideal candidate will possess a deep understanding of security frameworks and have experience in implementing security controls across diverse environments. Your duties will include collaborating with cross-functional teams to identify and evaluate security vulnerabilities, conducting audits and assessments, and providing expert guidance on best practices. You will...

Learn more

Sr. Manager, Security Compliance & Certification Program

Added 31/07/2026

We are seeking a highly skilled Sr. Manager, Security Compliance & Certification Program to lead and enhance our security compliance initiatives. In this role, you will be responsible for the development, implementation, and maintenance of security compliance frameworks and certification programs. You will work closely with cross-functional teams to ensure adherence to industry standards and regulatory requirements while fostering a culture of security awareness throughout the organization. Your expertise will be instrumental in conducting risk assessments, audits, and gap analyses to identify areas for improvement and drive compliance strategies. The ideal candidate will have a strong background in security compliance,...

Learn more

Information Security Lead Auditor

Added 11/09/2026

We are seeking an experienced Information Security Lead Auditor to plan, lead and deliver independent security audits across a complex technology and business environment. This role will assess the effectiveness of information security controls, governance frameworks, risk management practices and regulatory compliance arrangements. You will work closely with stakeholders across technology, operations, risk and compliance to identify control weaknesses, evaluate their impact and support the development of practical remediation plans. Responsibilities will include developing risk-based audit plans; defining audit scope, objectives and testing strategies; conducting interviews, walkthroughs and evidence reviews; and assessing controls against recognised standards and regulations such as...

Learn more

Principal Auditor - Technology and Security

Added 30/07/2026

We are seeking a highly skilled Principal Auditor specializing in Technology and Security to join our team. In this role, you will be responsible for leading audits focused on the implementation and effectiveness of technology controls within the organization. You will assess risks associated with IT systems, evaluate security protocols, and ensure compliance with regulatory requirements. Collaborating with cross-functional teams, you will provide expert guidance on best practices in security and technology risk management, helping to identify vulnerabilities and enhance overall system integrity. The ideal candidate will possess a strong background in IT auditing, with a deep understanding of information...

Learn more

Principal Auditor - Technology and Security

Added 30/07/2026

We are seeking an experienced Principal Auditor - Technology and Security to join our dynamic team. In this pivotal role, you will be responsible for leading audit engagements focused on technology and information security, ensuring compliance with relevant regulations and internal policies. You will assess the effectiveness of controls and risk management processes, while providing insightful recommendations to enhance operational efficiencies and safeguard sensitive data. Your expertise will guide the development of audit strategies and plans that align with organizational objectives, ensuring that technology-related risks are adequately addressed. As a key member of the audit function, you will collaborate closely...

Learn more

Principal Auditor - Technology and Security

Added 30/07/2026

We are seeking a highly skilled Principal Auditor - Technology and Security to join our dynamic team. In this role, you will be responsible for leading audits focused on technology and security processes, ensuring compliance with internal policies and regulatory requirements. You will evaluate and enhance the effectiveness of risk management, control, and governance processes within the organization. Your expertise will be vital in identifying potential vulnerabilities and recommending actionable improvements to mitigate risks associated with information technology and cybersecurity. The ideal candidate will possess a deep understanding of auditing principles and practices, particularly in relation to IT systems and...

Learn more

Lead Auditor - Information Security

Added 27/07/2026

We are seeking a highly skilled Lead Auditor specializing in Information Security to join our team. In this role, you will be responsible for planning, executing, and overseeing comprehensive audits of the organization's information security management systems. You will assess current security protocols, identify vulnerabilities, and recommend improvements to enhance the overall security posture. Your expertise will ensure compliance with industry standards and regulations, such as ISO 27001, NIST, and GDPR, while also driving a culture of security awareness throughout the organization. As the Lead Auditor, you will collaborate closely with cross-functional teams to evaluate risks, develop audit strategies, and...

Learn more

Senior Consultant or Manager, Identity & Access Management Engineer - Cyber - Defence & Security GPS

Added 02/09/2026

We are seeking an experienced Senior Consultant or Manager to join a specialist Identity and Access Management (IAM) engineering team supporting complex cyber security and national security programmes. This role will suit a delivery-focused professional who can combine strong technical capability with stakeholder management, leadership and strategic thinking. You will help clients design, implement and improve secure identity services across enterprise, cloud and hybrid environments, ensuring that access is appropriately governed, monitored and aligned with business and security requirements. Your responsibilities will include leading IAM engagements from discovery and requirements gathering through to architecture, implementation and operational transition. You will...

Learn more

Senior Consultant or Manager, Identity & Access Management Engineer - Cyber - Defence & Security GPS

Added 03/08/2026

Are you ready to take the next step in your cybersecurity career? We are seeking a Senior Consultant or Manager, Identity & Access Management Engineer to join our Cyber Defence & Security team, specialising in Government and Public Sector (GPS) projects. In this role, you will design, implement, and manage complex Identity and Access Management (IAM) solutions that safeguard critical systems and sensitive information. You will collaborate with cross-functional teams to develop IAM strategies, conduct risk assessments, and advise clients on best practices for access controls, authentication, and authorization frameworks. Your responsibilities will include leading the deployment and integration of...

Learn more

Cyber Analyst in CYBER DEFENCE CENTRE

Added 01/09/2026

We are seeking a Cyber Analyst to support the monitoring, detection and investigation of cyber threats across a complex technology environment. Working as part of a collaborative security operations team, you will help protect critical systems, networks and information by identifying suspicious activity, assessing potential risks and coordinating appropriate responses. This role is suited to an analytical and proactive professional who can work effectively in a fast-paced environment and communicate clearly with both technical and non-technical stakeholders. Your responsibilities will include monitoring security alerts and event data from a range of tools, investigating suspected incidents and conducting initial triage to...

Learn more

Cyber Defence Manager

Added 08/09/2026

We are seeking an experienced Cyber Defence Manager to lead the development, operation and continuous improvement of cyber defence capabilities within a complex and evolving environment. The successful candidate will provide strategic direction and hands-on leadership across security monitoring, incident response, threat intelligence, vulnerability management and cyber resilience. You will work closely with technology, risk, compliance and business stakeholders to reduce exposure to cyber threats and strengthen organisational readiness. Key responsibilities will include managing and developing a specialist cyber defence team; overseeing security operations and the effective use of monitoring, detection and response technologies; coordinating the investigation, containment and remediation...

Learn more

Cyber Defence Manager

Added 08/09/2026

We are seeking an experienced Cyber Defence Manager to lead the development and delivery of effective cyber security defence capabilities. This role will be responsible for protecting critical systems, networks and information assets against evolving threats, while ensuring that security operations support organisational priorities and regulatory obligations. You will provide technical leadership across cyber defence, incident response, threat intelligence, vulnerability management and security monitoring. Key responsibilities will include managing and continually improving security operations processes, controls and technologies; overseeing the identification, investigation and response to cyber incidents; and coordinating containment, recovery and post-incident improvement activities. You will lead the assessment...

Learn more

Head of Cyber Defence Centre

Added 02/09/2026

We are seeking an experienced Head of Cyber Defence Centre to lead the organisation’s cyber defence capability and strengthen its ability to prevent, detect, investigate and respond to increasingly sophisticated threats. This is a senior leadership role with responsibility for setting the strategic direction of security operations, ensuring effective protection of critical systems, data and services, and building a resilient, intelligence-led defence function. You will lead security monitoring, threat detection, incident response, digital forensics, threat intelligence, vulnerability coordination and security operations processes. Working closely with technology, risk, compliance and business stakeholders, you will establish clear operating models, standards, performance measures...

Learn more

Head of Cyber Defence Centre

Added 02/09/2026

We are seeking an experienced Head of Cyber Defence Centre to lead and develop a high-performing function responsible for protecting critical systems, data and services against an evolving threat landscape. This is a strategic leadership role combining operational oversight, technical expertise and people management. You will define and implement the cyber defence strategy, ensure effective security monitoring and incident response, and provide clear direction during high-severity events. Your responsibilities will include leading security operations, threat intelligence, vulnerability management, detection engineering and digital forensics activities. You will oversee the identification, investigation and containment of cyber threats, ensuring that incidents are managed...

Learn more
At least 8 characters, 1 uppercase, 1 lowercase and 1 special character or number
Your file must be a doc, docx or pdf. No larger than 5MB.