Salary: £43,000 - 72,000 per year Requirements: Strong experience in security governance, risk, and information assurance Deep understanding of ISO 27000-series standards and security risk frameworks Familiarity with NCSC guidance and legacy IA standards Experience operating within MOD / defence-aligned security frameworks (e.g. JSP 604, JSP 440, JSP 902) Ability to clearly articulate risk and assurance outcomes to diverse stakeholders Essential qualifications: CISSP, CISM or equivalent recognised cyber security certification Desirable qualifications: Full CIISec membership, Chartered or Principal status via the UK Cyber Security Council (Risk Management), IEng or CEng registration, BCS chartership Responsibilities: Lead security governance and risk management activities Deliver information assurance support, including risk assessments, assurance reviews, and security documentation Support clients in defining business led security requirements and secure-by-design solutions Interpret and apply ISO 27001 / ISO 27002, NIST, NCSC CAF, and MOD security frameworks Engage confidently with technical and non-technical stakeholders, including senior leaders Contribute to bid support and presales activity where required Technologies: Support JSP Security More: We are seeking an experienced Security Consultant to join our high-performing Security Practice, supporting clients across governance, risk management, and information assurance within complex and regulated environments. This role offers clear progression within a growing security consultancy and flexible working options, including part-time or term-time arrangements. We provide a competitive pension and benefits package, private healthcare, an EV scheme, and maintain a strong company culture. Additionally, we offer additional paid leave for Reservists and CFAVs. If youre passionate about security governance, assurance, and risk-led decision making, we would love to hear from you. last updated 8 week of 2026