Search 512 Live Jobs

Love Mondays again!

Senior Information Security Consultant

Our client offers virtual Chief Information Security Officer (vCISO) and consultancy services to organisations across the Channel Islands and beyond. This is a permanent full-time position based in Jersey. As an Information Security Consultant, you will lead a portfolio of client engagements, acting as the vCISO and being the primary voice on security matters. You will set strategic direction, manage compliance processes, present to boards, and cultivate long-term relationships with key stakeholders. In this client-facing consultancy role, you will blend hands-on technical assurance with strategic advisory responsibilities, enhancing service delivery methodologies and mentoring junior consultants along the way. You will actively contribute to scoping and proposal efforts as part of your role.

JOB DUTIES:

  • Act as the named vCISO lead for a portfolio of client engagements, owning delivery against the agreed Statement of Works.
  • Establish and maintain regular touchpoint calls with client stakeholders (no less than monthly), tracking progress and keeping scope aligned to client objectives.
  • Chair monthly service review meetings and act as first point of escalation for client queries and concerns.
  • Build and maintain trusted relationships with senior stakeholders including managing directors, boards, compliance officers, and IT leads.
  • Support scoping and proposal work for new engagements, including discovery workshops and drafting Statements of Works.
  • Lead gap analyses and ongoing compliance monitoring against major security frameworks and regulatory guidelines.
  • Manage annual and triennial certification submissions, including necessary assessments and documentation.
  • Develop, review and maintain client information security management systems, including policies, procedures, and supporting documentation.
  • Own the client risk management cycle: conduct and maintain information and cyber risk assessments, integrating security risk into wider organisational frameworks.
  • Provide oversight of data protection and privacy requirements, including data flow mapping and review of data processing agreements.
  • Review and monitor client technical security controls, ensuring adherence to agreed baselines and remediation of critical vulnerabilities.
  • Produce quarterly board reports covering technical and operational control performance and presenting findings to executive audiences.
  • Conduct vendor and supplier due diligence, supporting clients with compliance questionnaires and cyber insurance proposals.
  • Design and deliver annual security awareness training to client staff, refreshing content to reflect current threats.
  • Mentor and quality-assure the work of junior consultants while contributing to continuous improvement of service delivery standards.
  • Maintain knowledge of the regulatory landscape, threat trends, and relevant standards.

JOB REQUIREMENTS:

  • A minimum of five years' experience in information or cyber security, with at least two years in a consultancy, vCISO, or senior in-house security role.
  • Demonstrable experience delivering against recognised security frameworks — such as Cyber Essentials, ISO 27001, or equivalent.
  • Proven track record of building and maintaining an Information Security Management System (ISMS), including policy authorship and risk assessment.
  • Strong working knowledge of technical security controls, including firewalls, identity management, and patch management.
  • Experience producing and presenting security reports to board or executive audiences.
  • Excellent written communication skills, including the ability to produce client-ready documentation.
  • Confident communicator capable of engaging senior stakeholders and explaining complex risks clearly.
  • Highly organised with the ability to manage competing priorities across multiple concurrent client engagements.
  • Full driving licence and willingness to travel between client sites as necessary.
  • Eligible to work in Jersey or Guernsey, or able to satisfy local licensing and residency requirements.
  • Experience in regulated financial services is preferred, particularly against local cybersecurity rules.
  • Familiarity with compliance management platforms and vulnerability scanning tools is advantageous.
  • Knowledge of data protection laws, such as UK GDPR, is desirable.

WHAT YOU’LL LOVE:

​​​​​​​This role offers an opportunity to make a significant impact by shaping how services are delivered, developing security strategies, and working closely with clients to enhance their security posture. You will be part of a supportive environment that fosters professional growth, encourages collaboration, and places a strong emphasis on maintaining long-term relationships. The role also provides exposure to a range of client engagements, allowing for diverse experiences within cybersecurity.

Could this be your next move? Submit your CV confidentially to our friendly and dedicated recruitment team by clicking here

Job Alerts
  • Personalised updates
  • Insight and support
  • Regular contact and motivation
Sign Up for Job Alerts