
Confidential
Lead Security Consultant GRC ISO 27001 PCI SOC2
Job Description
Salary: £50,000 - 60,000 per year
Requirements:- Strong experience in ISO 27001 implementation, internal audit, ISMS maintenance, and engagement with external auditors
- Solid understanding of the Data Protection Act and GDPR
- Experience in security management, including risk, incident, and ISMS management, security working groups, and monitoring and measuring maturity
- Experience working with frameworks such as NIST CSF, CIS, and NCSC CAF
- Experience in supplier management, including third-party supplier security assessments
- Experience managing risk and recommending mitigating actions
- Knowledge of Cyber Essentials and IASME Cyber Assurance standards
- Outstanding written and verbal communication skills with an emphasis on confidentiality, tact, and diplomacy
- Ability to multitask, work as part of a team, and work independently
- Formal ISO certifications such as Lead Auditor or Lead Implementer are desirable
- Formal Data Protection Officer certification is desirable
- Principal or Chartered Cyber Security Professional status in Cyber Security Audit and Assurance or Cyber Security Governance and Risk is desirable
- Certified IASME Cyber Assurance Assessor status is desirable
- Certified IASME DCC Assessor status is desirable
- Good technical skills and understanding of IT and cloud services are desirable
- Solid understanding of AI Governance and ISO 42001 is desirable
- Lead and support client ISO 27001 implementation projects from initiation to certification
- Conduct client Defence Cyber Certification (DCC) assessments and help clients gain formal certification
- Provide information security, cyber security, and data privacy/GDPR consultancy to clients
- Lead PCI and SOC2 client engagements
- Support clients with the implementation of AI governance capabilities and formal certification to ISO 42001
- Perform cyber security maturity assessments using recognised frameworks from CIS and NIST and make recommendations for improvement
- Provide vCISO and vDPO services to clients and support client security working groups
- Support sales and marketing initiatives in promoting our consultancy and managed security services
- AI
- Cloud
- Support
- Marketing
- Security
More:
We are an independent ISO and CREST certified cyber security consultancy providing security consultancy and managed security services to a wide range of clients and partners. We are hiring a Lead Security Consultant to join our team in Manchester on a hybrid basis. This full-time role offers a 40-hour working week, up to £60,000 per annum depending on skills and experience, up to 10% annual bonus, funded InfoSec training, time for self-study, 25 days holiday plus bank holidays, private health care, company pension, career development opportunities, and regular team meals and activities.
last updated 34 week of 2026
Interested in this role?
Submit your application now
How to Apply
About Confidential

Confidential
Manchester
IT
Skills & Technologies
Inferred from job description
Salary Insight
£55,000
This role
£85,000
UK median
This salary is 35% below the UK median for Lead roles (£85,000/yr).
Based on 2024–2025 UK technology sector benchmarks