Information Security & GRC Consultant

Consult

Greater London

Hybrid

GBP 102,000 - 138,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Consult in London or Bradford is seeking an Information Security & GRC Consultant to lead security governance, risk, and M&A due diligence across a complex enterprise.

The role is hybrid (2 days on-site) with a day rate of £650 inside IR35 for an initial 6-month contract, with potential extension or permanent conversion. You will implement ISO 27001 and SOC 2 programs and drive remediation and audit readiness.

Qualifications

  • Proven hands-on experience implementing ISO 27001 and SOC 2.
  • Experience conducting M&A security due diligence.
  • Strong governance, risk management and compliance background.
  • Experience building or operating security frameworks in complex organisations.
  • Excellent stakeholder management and ability to drive actions to completion.
  • Desirable: business continuity or disaster recovery programs.

Responsibilities

  • Conduct cyber security risk assessments and due diligence for M&A.
  • Maintain and enhance ISO 27001 and SOC 2 controls.
  • Develop security policies, standards, and risk registers.
  • Lead business continuity and disaster recovery activities.
  • Perform third-party security assessments across the supply chain.
  • Prepare for audits and gather evidence for audit readiness.
  • Deliver security awareness to technical and non-technical stakeholders.

Skills

ISO 27001
SOC 2
GRC governance
Risk management
M&A due diligence
Third-party risk
Security policies
Audit readiness

Job description

Join a leading telecommunications company as an Information Security & GRC Consultant and play a key role in strengthening security governance, compliance, resilience, and M&A security due diligence across a complex enterprise environment.

Job Overview:

This is a hands-on opportunity for experienced security professionals who can take ownership, drive delivery, and implement practical solutions rather than simply providing recommendations. You'll support strategic initiatives spanning ISO 27001, SOC 2, business continuity, third-party risk management, and acquisition-related security assessments.

Contract Details:
  • Location: London or Bradford (hybrid - 2 days per week onsite)
  • Rate: £650 per day (inside IR35)
  • Contract Length: 6 months (with visibility to extend or go permanent afterwards)
Key Responsibilities
  • Conduct cyber security risk assessments and security due diligence activities for mergers and acquisitions, identifying risks, remediation requirements and integration priorities.
  • Assess, maintain and enhance security frameworks aligned to ISO 27001 and SOC 2 Type II standards.
  • Develop and maintain security policies, standards, procedures, risk registers and remediation plans.
  • Lead and support business continuity and disaster recovery activities, including Business Impact Assessments (BIAs), recovery planning and resilience testing.
  • Perform third-party and supplier security assessments, ensuring security and continuity requirements are met across the supply chain.
  • Prepare stakeholders and control owners for internal and external compliance audits, gathering evidence and driving audit readiness.
  • Deliver security awareness initiatives and provide clear, practical guidance to both technical and non-technical stakeholders.
Key Requirements
  • Proven hands-on experience implementing, managing or auditing ISO 27001 and SOC 2 compliance programmes.
  • Demonstrable experience conducting M&A security due diligence and assessing cybersecurity risks in acquisition environments.
  • Strong background in security governance, risk management, compliance and control remediation.
  • Experience building, improving or operationalising security frameworks within a complex organisation.
  • Excellent stakeholder management skills with the ability to influence, challenge and drive actions through to completion.
  • Experience with business continuity, disaster recovery or operational resilience programmes is highly desirable.
Ideal backgrounds include

Information Security Manager, Information Security Officer, Security Governance Lead, Security Compliance Manager, GRC Consultant or Security Risk Consultant.

Start Date:

ASAP

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Manager/GRC Consultant - Telecoms
Information Security Manager/GRC Consultant - Telecoms

NTT DATA • Birmingham

On-site
GBP 70,000 - 90,000
Information Security Lead (GRC)
Information Security Lead (GRC)

Enorth Resourcing Limited • Bedford

Hybrid
GBP 60,000 - 70,000
Information Security Specialist (GRC)
Information Security Specialist (GRC)

La Fosse Associates • Greater London

On-site
GBP 81,000 - 99,000
Pension
Information Security Manager/GRC Consultant
Information Security Manager/GRC Consultant

The Nippon Telegraph and Telephone Corporation (NTT) • Birmingham

Hybrid
GBP 60,000 - 90,000
GRC Consultant
GRC Consultant

Big Red Recruitment • Stratford-upon-Avon

Hybrid
GBP 42,000 - 70,000
Bonus
Benefits
Hands-on ISO 27001 & SOC 2 GRC Consultant
Hands-on ISO 27001 & SOC 2 GRC Consultant

Consult • Greater London

Hybrid
GBP 102,000 - 138,000
Lead GRC Consultant
Lead GRC Consultant

Cathcart Technology • City of Edinburgh

Hybrid
GBP 90,000 - 130,000
Bonus
Share scheme
Cyber Compliance Manager
Cyber Compliance Manager

Harvey Nash Group • Manchester

On-site
GBP 70,000 - 90,000
GRC Consultant
GRC Consultant

Big Red Recruitment • City Of London

Hybrid
GBP 59,000 - 72,000
Bonus & Benefits
Hybrid work (1 day per week in Central
IT Information Security Analyst - Compliance
IT Information Security Analyst - Compliance

Adecco • West Midlands

On-site
GBP 45,000 - 55,000