CareerPlanSign in

GRC Consultant

London, United Kingdom💼 Full-time🗓 2026-08-31 → 2026-09-26

Core

Design, develop, test, and evaluate information security controls throughout the lifecycle to ensure business systems operate safely and securely based on risk alignment.

Role type

GRC Consultant (Cyber Assurance / Security Operations Manager)

Builds

Information Security Management Systems, documented Security Management Plans, and risk mitigation strategies.

Domain

Cybersecurity, Governance, Risk, and Compliance (GRC)

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Security standards and accreditations expertise, Information Security Management System (ISMS) maintenance, regulatory and legal compliance integration, risk identification and quantification, risk mitigation planning, third-party supplier security verification, security KPI monitoring, continuous improvement facilitation, policy and procedure development, information risk assessment, audit and risk assurance coordination, incident response and root cause analysis, security working group leadership.

Preferred skills

Large-scale infrastructure security solution delivery, NIST CSF/NIST 800-53/NCSC CAF framework knowledge, networking (switching/routing/firewalls), modern security concepts (attack vectors/malware/analytics/threat intelligence), security testing and vulnerability management (pen testing/ITHC/CVSS/CVE), ISO 27001/27002/27017/27108 standards experience, Cloud platform security (AWS/Azure), CISSP/CISM/CCSP/CRISC certifications, Active Directory/Cryptography/IAM/PKI/Server hardening/SIEM/SOAR/virtualization, MITRE ATT&CK, ITIL.

Technologies

NIST CSF, NIST 800-53, NCSC CAF, ISO 27001, ISO 27002, ISO 27017, ISO 27108, AWS, Microsoft Azure, Active Directory, SIEM, SOAR, VMware, MITRE ATT&CK, ITIL, CVSS, CVE.

Responsibilities

Provide security expertise across standards and accreditations; derive and deliver Information Security Management Plans; identify risks and lead mitigation plans; verify partner/supplier compliance; lead GRC development aligned to policy; ensure continuous assessment and reporting for risk-based decisions; challenge processes for continuous improvement; review and verify security control documentation; develop ISMS practices for certification; propose and implement policy changes; perform focused information risk assessments; coordinate audit and risk assurance activities; chair Security Working Groups; monitor security incidents and contribute to response.

Seniority

Mid-to-Senior, hands-on IC with strategic oversight.

Sourced via workday · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.