Our client is seeking an experienced Information Security Consultant to serve as the virtual Chief Information Security Officer (vCISO) lead across a portfolio of client engagements. This full-time position offers a unique opportunity to act as a trusted advisor to senior stakeholders, shaping security strategy, managing compliance programmes, and providing thorough board-level reporting. In this highly client-facing role, you will combine strategic consultancy with hands-on security assurance. You will have the opportunity to make a significant impact across a diverse range of organisations, leveraging your expertise in information security to enhance their resilience and compliance.
JOB DUTIES:
- Act as the lead vCISO for a portfolio of clients, owning delivery and client relationships.
- Lead security governance, risk, and compliance activities aligned to frameworks such as ISO 27001, Cyber Essentials, IASME Cyber Assurance, and NIST.
- Conduct security risk assessments, gap analyses, and compliance reviews to identify and mitigate risks.
- Develop and maintain client Information Security Management System (ISMS) documentation, policies, and procedures tailored to client needs.
- Deliver board and executive-level reporting, translating technical risks into business-focused recommendations to inform decision-making.
- Provide oversight of technical security controls, vulnerability management, access control, and incident readiness measures.
- Facilitate security awareness training, tabletop exercises, and incident response planning to bolster client preparedness.
- Support client audits, certification programmes, supplier assurance activities, and regulatory requirements to ensure compliance across all operational aspects.
- Mentor junior consultants and contribute to the ongoing development of the consultancy's security services, fostering a culture of continuous improvement.
JOB REQUIREMENTS:
- A minimum of five years’ experience in cyber or information security, including consultancy, vCISO, or senior security roles.
- Strong knowledge of security frameworks including ISO 27001, Cyber Essentials, IASME, NIST, or equivalent.
- Proven experience in developing and managing ISMS, policies, risk registers, and compliance programmes.
- Solid understanding of security technologies including firewalls, endpoint security, vulnerability management, identity and access management (IAM), and email security.
- Confidence in presenting to boards, executives, and senior stakeholders, with excellent communication and report writing skills.
- Highly organised, self-motivated, and comfortable managing multiple client engagements effectively.
- Desirable certifications include CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, or similar.
- Experience within regulated industries, financial services, Managed Service Providers (MSPs), or Managed Security Service Providers (MSSPs).
- Knowledge of GDPR, business continuity, disaster recovery, and third-party risk management principles.
- Experience delivering security awareness training and incident response exercises.
WHAT YOU’LL LOVE:
This role offers meaningful involvement in leading security programmes as a trusted advisor, providing you with direct access to boards, executives, and business leaders. You will enjoy genuine autonomy and ownership of client relationships while benefiting from ongoing professional development and certification support. The collaborative and supportive consultancy environment promotes your career progression, complemented by generous holiday allowances, enhanced pension contributions, private medical insurance, flexible and hybrid working arrangements, and regular company social events.
Could this be your next move? Submit your CV confidentially to our friendly and dedicated recruitment team by clicking here