Information Security Consultant

Cognisys

South Africa

On-site

ZAR 450,000 - 650,000

Full time

25 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Annual Leave: 25 days + 12 SA holidays
Health & Wellbeing plan
Professional Development budget (£2,0)
Referral Bonus (£2,000)

Job summary

Cognisys is seeking an Information Security Consultant to join our GRC Consulting team in South Africa. This client-facing, delivery-focused role translates regulatory requirements into practical, business-aligned solutions and works with senior consultants and client stakeholders to improve governance, risk and compliance.

The role requires 2–5 years in security, risk or GRC, experience with ISO27001, SOC 2 or NIST, strong communication, and the ability to manage multiple priorities while

Qualifications

  • 2–5 years’ experience in security, risk, compliance, or GRC roles.
  • Experience with ISO 27001, SOC 2, NIST or similar standards.
  • Experience supporting compliance or assurance initiatives (internal or client-facing).
  • Strong written and verbal communication skills.
  • Ability to manage multiple priorities in a structured and organised manner.
  • Analytical mindset with a pragmatic approach to problem solving.
  • Comfortable working with both technical and non-technical stakeholders.
  • Consulting experience is desirable but not essential.
  • Experience with GRC platforms including Vanta is desirable.

Responsibilities

  • Lead the delivery of GRC engagements across multiple clients.
  • Contribute to security posture assessments, gap analyses, and maturity reviews.
  • Assist in the design and implementation of GRC programmes aligned to ISO 27001, SOC 2, NIST.
  • Support clients through audit preparation, certification processes, and external assessments.
  • Develop remediation plans and assist clients in tracking progress against agreed actions.
  • Participate and lead in client workshops, risk assessments, and stakeholder sessions.
  • Interpret security standards and translate requirements into practical recommendations.
  • Lead in the development of policies, procedures, risk registers, control frameworks, and governance documentation.
  • Contribute to the design and documentation of security controls and operating models.
  • Help embed compliance activities into operational and technical processes.
  • Conduct risk assessments and maintain supporting documentation.

Skills

GRC experience
Client-facing
Policy development
Risk assessment
Communication skills

Tools

GRC platforms (Vanta)

Job description

Salary: R450 000 - R650 000 per annum (DOE)

About the Role

Our GRC Consulting practice helps organisations strengthen their security posture and achieve compliance through clear, structured, and practical guidance. We work with clients at different stages of maturity, from building foundational security programmes to operating mature, scalable compliance functions.

We are seeking an Information Security Consultant to join our GRC Consulting team. This is a client-facing, delivery-focused role suited to a security and compliance professional who is confident supporting engagements and contributing high-quality advisory services.

As an Information Security Consultant, you will support the delivery of GRC engagements across a range of clients and industries. You will help translate regulatory and framework requirements into practical, business-aligned solutions and work collaboratively with senior consultants and client stakeholders to drive measurable improvements in governance, risk, and compliance.

This role suits someone with strong foundational GRC knowledge, growing consulting experience, and a desire to develop into a trusted security advisor.

Key Responsibilities

Client Delivery & Support

  • Lead the delivery of GRC consulting engagements across multiple clients and sectors.
  • Contribute to security posture assessments, gap analyses, and maturity reviews.
  • Assist in the design and implementation of GRC programmes aligned to frameworks such as ISO 27001, SOC 2, NIST, and related standards.
  • Support clients through audit preparation, certification processes, and external assessments.
  • Develop remediation plans and assist clients in tracking progress against agreed actions.
  • Participate and lead in client workshops, risk assessments, and stakeholder sessions.

Advisory & Technical Contribution

  • Support the interpretation of security standards and regulations, translating requirements into practical recommendations.
  • Lead in the development of policies, procedures, risk registers, control frameworks, and governance documentation.
  • Contribute to the design and documentation of security controls and operating models.
  • Help embed compliance activities into operational and technical processes.
  • Conduct risk assessments and maintain supporting documentation.

Quality & Professional Standards

  • Produce high-quality client deliverables with clarity, accuracy, and consistency.
  • Follow established methodologies, templates, and internal quality standards.
  • Proactively identify areas for improvement within engagements.
  • Manage assigned tasks effectively to meet deadlines and scope expectations.
Requirements
  • 2–5 years’ experience in security, risk, compliance, or GRC-related roles.
  • Practical experience with at least one framework such as ISO 27001, SOC 2, NIST, or similar standards.
  • Experience supporting compliance or assurance initiatives (internal or client-facing).
  • Strong written and verbal communication skills.
  • Ability to manage multiple priorities in a structured and organised manner.
  • Analytical mindset with a pragmatic approach to problem solving.
  • Comfortable working with both technical and non-technical stakeholders.
  • Consulting experience is highly desirable but not essential.
  • Experience with GRC platforms including Vanta is desirable.
What Success Looks Like

Success in this role means becoming a trusted consultant to your clients, delivering high-quality work with increasing independence and continuing to build your expertise across information security, GRC and consulting.

For Example:
  • Deliver high-quality client work — You consistently deliver accurate, practical and professional GRC and information security work that meets client expectations and Cognisys' standards.
  • Take ownership — You manage your assigned work from start to finish, keeping on top of deadlines, communicating progress and raising risks or blockers early.
  • Build strong client relationships — You communicate confidently and professionally with clients, understand their challenges and build trust through reliable, practical advice.
  • Apply your knowledge — You can confidently apply information security and GRC principles to real client situations, using frameworks such as ISO 27001, SOC 2 and NIST to develop practical solutions.
  • Solve problems, not just identify them — You look beyond gaps and findings to understand the underlying issue and help clients identify realistic ways forward.
  • Manage multiple priorities — You can balance different client engagements and deadlines while maintaining a consistently high standard of work.
  • Communicate clearly — You can explain security, risk and compliance concepts to both technical and non-technical stakeholders and produce clear, concise client documentation.
  • Continue to grow — You actively build your technical and consulting capability, seek feedback and take on increasing levels of responsibility as your experience develops.
  • Contribute to the team — You share knowledge, collaborate with colleagues and contribute to a supportive, high-performing GRC team.
  • Live the Cognisys values — You demonstrate Together, Ownership, Momentum and Excellence in how you work with clients and colleagues.
What We Offer
  • Annual Leave: 25 days per year plus 12 South African public holidays.
  • Additional Leave: 1 day of paid leave for your Birthday.
  • Health & Wellbeing: Individual healthcare insurance plan and access to an employee mental health and wellbeing platform.
  • Professional Development: £2,000 annual training budget to support your continued learning and career growth.
  • Referral Bonus: help to grow our team and earn up to £2,000 per successful referral.
Why Join Us?

At Cognisys, you will be part of a collaborative and innovative team that values your input and shares support. You'll have the opportunity to work on challenging projects that make a real impact for our clients. We'd love to hear from you if you want to challenge, lead and innovate! We're not just about the work; we're about the people. Join a team where innovation is celebrated, and your contributions are valued. We foster a collaborative environment where fresh ideas thrive, and professional growth is encouraged.

We welcome applications from candidates from a range of diverse backgrounds and can make various reasonable adjustments to consider individual needs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Senior GRC Consultant: Security & Compliance
Remote Senior GRC Consultant: Security & Compliance

Cognisys • Johannesburg

Remote
ZAR 780,000 - 900,000
Professional development budget
Employee wellness resources
25 days leave plus a birthday holiday
+1
Information Security Consultant
Information Security Consultant

Placements24 • Centurion

On-site
ZAR 700,000 - 1,100,000
Competitive salary reviews
Health insurance
Retirement plan
+2
GRC Consultant CPT
GRC Consultant CPT

Datafin • Cape Town

On-site
ZAR 60,000 - 80,000
Information Security Consultant
Information Security Consultant

Placements24 • Klerksdorp

On-site
ZAR 900,000 - 1,200,000
Competitive salary and performance‑dr­
Medical benefits
Travel opportunities
+2
Senior Information Security Consultant
Senior Information Security Consultant

Placements24 • Randburg

Hybrid
ZAR 1,000,000 - 1,300,000
Medical insurance
Dental insurance
Vision insurance
+2
Junior GRC Security Analyst
Junior GRC Security Analyst

Network Recruitment • Johannesburg

On-site
ZAR 1,000,000 - 1,600,000
Cyber GRC Manager (CPT)
Cyber GRC Manager (CPT)

Datafin • Cape Town

On-site
ZAR 600,000 - 900,000
Cybersecurity Consultant
Cybersecurity Consultant

Placements24 • Gqeberha

Hybrid
ZAR 900,000 - 1,500,000
Competitive salary
Performance-based bonus
Health and wellness benefits
+2
Information Security Manager
Information Security Manager

Parvana • Cape Town

On-site
ZAR 1,200,000 - 1,800,000
Information Security Officer
Information Security Officer

Placements24 • Pretoria

Hybrid
ZAR 600,000 - 900,000