City Recruitment Associates
Assurance Consultant

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role: GRC/Assurance Consultant
Location
Fleet Street, London
Salary
£45,000 + benefits
Business Area
Governance, Risk and Compliance
Why this role exists
Our client is an NCSC Assured Service Provider, an IASME-licensed Certification Body and a Cyber Scheme Accredited Company.
Assure is the fastest-growing part of our business. This role exists to deliver it. You will be the person clients rely on when a supplier questionnaire lands, when an insurer starts asking questions, when a tender demands evidence, or when a board realises nobody actually owns information security.
What you will do
- Plan and deliver ISO/IEC 27001 internal audits, readiness reviews and gap assessments
- Support clients in building and running information security management systems — risk registers, policies, controls, evidence and corrective actions
- Deliver Cyber Essentials readiness work: assess the estate, complete the technical sections, and guide clients through submission
- Carry out supplier and third-party security due diligence, and help clients respond to assurance questionnaires
- Run recurring client assurance activity — governance reviews, risk tracking, evidence management, compliance roadmaps and management reporting
- Translate standards, contracts, procurement requirements and regulation into clear, prioritised, proportionate actions
- Write client-facing reports that explain the requirement, the risk, the gap and the recommended action, without unnecessary jargon
- Work with our technical and service teams to gather evidence, validate controls and coordinate remediation
- Build and maintain reusable templates and evidence sets, so the same control never has to be proved from scratch twice
What good looks like
- Clients trust you to discuss governance and risk with both engineers and directors, and to make the second group feel competent rather than exposed
- You can run a defined assurance engagement with limited supervision, and you recognise when something needs escalating
- Your work is evidence-led and proportionate — aimed at improving real security and resilience, not compliance for its own sake
- You are comfortable mapping common controls and evidence across different client requirements, which is how we keep assurance affordable for smaller organisations
- You understand where operational IT ends, cyber security begins and formal assurance sits — and you respect the boundaries between them
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What we need from you
- ISO/IEC 27001 Internal Auditor qualification, or demonstrable equivalent audit competence
- Practical working knowledge of ISO/IEC 27001, including participating in or conducting internal audits
- Experience with information security risk, policies, controls, evidence and remediation
- The ability to interpret a security or compliance requirement and explain what it actually means operationally
- Experience producing professional reports, findings and recommendations
- Confident client-facing communication with technical teams, managers and senior stakeholders
- Strong organisation and judgement — able to hold several engagements without losing control of the detail
- Enough technical understanding to validate evidence and ask the right questions of an engineer
Useful, but not essential
- ISO/IEC 27001 Lead Auditor or Lead Implementer training
- Cyber Essentials, IASME or wider cyber assurance experience
- NIST CSF, NCSC CAF, NIS2, supplier assurance or defence-sector security requirements
- Privacy and information governance experience, including practical DSAR support
- Experience in an MSP, MSSP or consultancy serving multiple clients
- Experience supporting regulated organisations, government suppliers or complex supply chains
Where this role can go
- You report directly to the CEO. No layers, real influence over how the Assure service develops, and visibility of the whole business rather than one corner of it
- There is a genuine path toward becoming a certification assessor. We are an IASME Certification Body and are working toward Defence Cyber Certification.
- For the right person, a training fund can be made available to support relevant professional development and qualifications
- Salary is formally reviewed at twelve months against what you are delivering
- As experience develops, the work broadens into IASME Cyber Assurance, NCSC CAF and NIS2, and defence supply-chain assurance


Get help with your application
Your very own career expert that helps elevate your application to the next level.
The person we are looking for
You do not need to know every framework on day one. We care about sound judgement, audit discipline, curiosity and the ability to learn quickly. You should be comfortable moving between evidence and controls one moment and a conversation with a client director the next. We are particularly interested in someone who enjoys making governance useful. Your instinct should be to understand the client, the risk and the intended outcome first, then apply the right level of assurance without creating unnecessary complexity.
About Client
Delivers managed IT, cyber security and assurance services through three connected disciplines: Manage, Protect and Assure. We support clients from day-to-day technology operations, through active cyber protection, to the governance and evidence needed to meet customer, regulatory and supply-chain expectations.
We are a small, established team — most of our engineers have been with us four to five years — working with clients who value practical advice, clear ownership and a service that connects technical reality with assurance requirements.
Practical points
- You must have the right to work in the UK
- The role may involve travel to client sites, predominantly in London
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills