Cyber Security Consultant
Salary: £50,000 - £70,000 + benefits
Fully Remote | UK-based | Occasional Client Travel
About the Role
An exciting opportunity for a Cyber Security Consultant to join a growing, specialist cyber security consultancy focused on helping organisations build better, more practical security.
This isn't your traditional Big Four-style consultancy. The business works predominantly with ambitious SME and high-growth organisations, giving clients pragmatic, commercially focused security advice without unnecessary layers of process or bureaucracy.
This role sits within the Cyber Security Consulting team, working directly with clients to understand their challenges, identify and manage risk, and help them actually get things done.
The demand for cyber security consulting is growing rapidly, and the business is at an exciting stage of expansion. There is plenty of opportunity to make an impact, take ownership and help shape how the consulting practice develops.
Most importantly, personality matters. We're looking for someone who is curious, proactive and genuinely enjoys working with people. Someone who doesn't need to be told what to do at every step, is happy to roll their sleeves up and get stuck in, and wants to build something rather than simply occupy a role.
Key Responsibilities
As a Cyber Security Consultant, you will work across a range of client engagements, providing practical security advice across governance, risk, compliance and technical security.
You will have the opportunity to work at both a strategic and operational level, depending on the needs of the client, and will increasingly take ownership of engagements and client relationships.
Responsibilities will include:
- Client Delivery
- Deliver cyber security consultancy engagements across a range of clients, from growing SMEs through to larger organisations.
- Conduct cyber security maturity assessments, gap analyses and risk assessments.
- Develop practical, prioritised remediation plans and security roadmaps.
- Support clients with ISO 27001 implementation, maintenance and audit preparation.
- Advise clients against recognised frameworks including ISO 27001, NIST CSF and CIS Controls, as well as supporting SOC 2 and other compliance requirements.
- Develop and improve security policies, procedures and governance frameworks.
- Establish and maintain risk registers and support security governance forums.
- Support incident response planning, tabletop exercises and crisis management activities.
- Provide advice across areas including vulnerability management, identity and access management, cloud security, security operations and supplier assurance.
- Support Secure SDLC and broader security transformation initiatives.
- Provide vCISO / outsourced security management support where required.
- Design and facilitate client workshops, discovery sessions and stakeholder interviews.
- Translate technical security issues into clear business risks and practical recommendations.
- Produce high-quality, client-ready reports, assessments, roadmaps and presentations.
- Manage multiple client engagements and priorities simultaneously while maintaining a high standard of delivery.
- Client & Stakeholder Management
- Build strong relationships with clients and become a trusted security adviser.
- Communicate confidently with technical teams, operational stakeholders and senior management.
- Take ownership of client conversations and engagements as your experience develops.
Who We Are Looking For
- 4-6 years' experience working in information security or cyber security, with some client-facing or consultancy experience.
- A good understanding of information security governance, risk and technical controls.
- Practical experience with ISO 27001 and/or other recognised security frameworks.
- Experience conducting security assessments, gap analyses or risk assessments.
- The ability to understand a client's business and provide pragmatic, proportionate security advice.
- Strong written and verbal communication skills, with the ability to explain complex security concepts clearly to both technical and non-technical audiences.
- Experience producing professional, client-ready reports and recommendations.
Knowledge or experience in areas such as the following would be beneficial:
- ISO 27001 / ISO 27005
- NIST CSF
- CIS Controls
- SOC 2
- NIS2 / DORA
- Risk management and governance
- Security operations and monitoring
- Incident response
- Vulnerability management
- Cloud security, particularly Microsoft Azure and Microsoft 365
This is a UK-based role and applicants must have the full and permanent right to work in the UK.
"Apply Now" for immediate review!
Cyber Security Consultant, Security Consultant, Cyber Security Consultant, Cyber Security, Cyber Security Consultant, 27001, Cyber Security Consultant, SOC
Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter - @Circle_Rec and LinkedIn - Circle Recruitment.