Senior Information Security Consultant

GDS Link

Leeds

On-site

GBP 75,000 - 110,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

GDS Link in the United Kingdom is seeking a Senior Information Security Consultant to own security controls end-to-end, focusing on ISO 27001 and SOC 2 audits, while remaining hands-on in AWS-hosted environments.

You will act as the primary technical contact for auditors, drive remediation, and provide senior security expertise across IAM, monitoring, vulnerability management, SIEM, and incident response.

Qualifications

  • Senior experience in a technical information security role.
  • Direct ownership of ISO 27001 and/or SOC 2 audit controls, including auditor interaction and remediation.
  • Strong hands-on experience securing AWS-hosted environments.
  • Practical experience with vulnerability management, SIEM, and monitoring.
  • Ability to explain technical controls to auditors and engineers with sound judgement.

Responsibilities

  • Own assigned areas of ISO 27001 and/or SOC 2 audits as technical control owner.
  • Act as primary technical point of contact for auditors, leading walkthroughs and responding to queries.
  • Define, review, and approve technical audit evidence and drive remediation of findings.
  • Provide senior hands-on security expertise across AWS (IAM, logging, monitoring, network security).
  • Own or oversee vulnerability management, including prioritisation, remediation, and audit-ready reporting.
  • Provide senior input into SIEM, monitoring, and incident response.
  • Oversee endpoint and SaaS security controls (e.g. Microsoft 365).
  • Act as a senior technical authority and coach less-senior team members.

Skills

AWS security
ISO 27001
SOC 2
GRC
Vulnerability management
SIEM
Monitoring
Incident response
Endpoint security
SaaS security
Automation scripting

Tools

Microsoft 365

Job description

Role Summary

The Senior Information Security Consultant is a senior individual contributor role that spans both Cyber Security and Information Security Governance (GRC). The role owns security controls end-to-end and is directly accountable for ISO 27001 and/or SOC 2 audit outcomes, while remaining hands-on across AWS-hosted environments.

Description

Cyber & GRC / Cloud & Audit Focus

Role Summary

The Senior Information Security Consultant is a senior individual contributor role that spans both Cyber Security and Information Security Governance (GRC). The role owns security controls end-to-end and is directly accountable for ISO 27001 and/or SOC 2 audit outcomes, while remaining hands-on across AWS-hosted environments.

Key Responsibilities
  • Own assigned areas of ISO 27001 and/or SOC 2 audits as technical control owner.
  • Act as primary technical point of contact for auditors, leading walkthroughs and responding to queries.
  • Define, review, and approve technical audit evidence and drive remediation of findings.
  • Provide senior hands-on security expertise across AWS (IAM, logging, monitoring, network security).
  • Own or oversee vulnerability management, including prioritisation, remediation, and audit-ready reporting.
  • Provide senior input into SIEM, monitoring, and incident response.
  • Oversee endpoint and SaaS security controls (e.g. Microsoft 365).
  • Act as a senior technical authority and coach less-senior team members.
Requirements
Required Experience

Essential:

  • Senior experience in a technical information security role.
  • Direct ownership of ISO 27001 and/or SOC 2 audit controls, including auditor interaction and remediation.
  • Strong hands-on experience securing AWS-hosted environments.
  • Practical experience with vulnerability management, SIEM, and monitoring.
  • Strong judgement and ability to explain technical controls to auditors and engineers.
Desirable
  • SaaS or cloud-native environments.
  • Familiarity with NIST CSF or CIS Controls.
  • Automation or scripting experience.
  • Relevant certifications (ISO 27001, AWS Security, CISSP, etc.).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior InfoSec & Cloud Compliance Lead
Senior InfoSec & Cloud Compliance Lead

GDS Link • Leeds

On-site
GBP 75,000 - 110,000
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
Senior Information Security & GRC Specialist
Senior Information Security & GRC Specialist

Zachary Daniels • Greater London

Hybrid
GBP 75,000 - 85,000
Senior InfoSec GRC Specialist
Senior InfoSec GRC Specialist

Clearwater Analytics (CWAN) • England

On-site
GBP 65,000 - 85,000
Senior Cyber GRC Lead: ISO27001 & Risk Advisory
Senior Cyber GRC Lead: ISO27001 & Risk Advisory

FSP • Greater London

Hybrid
GBP 80,000 - 110,000
Hybrid working
Mentoring program
Benefits package
+1
Senior Security Consultant
Senior Security Consultant

ANS Group • Manchester

On-site
GBP 70,000 - 110,000
GRC Analyst
GRC Analyst

IMT Resourcing Solutions • Cheltenham

On-site
GBP 42,000 - 58,000
Security Consultant
Security Consultant

CyberNorth • Newcastle upon Tyne

On-site
GBP 65,000 - 100,000
Security Analyst
Security Analyst

Peaple Talent • Manchester

On-site
GBP 40,000 - 60,000
Information Security Engineer
Information Security Engineer

Selby Jennings • Greenwich

On-site
GBP 70,000 - 100,000