Cognisys
Information Security Consultant - UK (Remote)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Location: UK (Remote) Salary: £35 - £42k per annum (DOE)
About Cognisys
At Cognisys, we help organisations strengthen their security posture through expert Governance, Risk & Compliance (GRC) consulting, Penetration Testing and Managed Security Services.
Our consultants work alongside clients to solve complex security and compliance challenges, providing practical, business-focused advice that helps organisations build resilient security programmes and achieve regulatory compliance.
As we continue to grow our GRC Consulting practice, we're looking for an Information Security Consultant to join our expanding team.
The Opportunity
Our GRC Consulting team partners with organisations at every stage of their security journey—from building foundational governance programmes to supporting mature organisations operating within complex regulatory environments.
As an Information Security Consultant, you'll work with a diverse range of clients across multiple industries, helping them strengthen their governance, risk and compliance capabilities through practical, commercially focused security advice.
This is a client-facing consulting role where you'll deliver a variety of GRC engagements, helping clients understand regulatory requirements, improve their security posture and implement effective governance frameworks.
Working alongside experienced consultants, you'll build trusted client relationships, support complex security projects and play an important role in delivering exceptional consulting outcomes.
Whether you're conducting maturity assessments, supporting ISO 27001 implementations, facilitating risk workshops or preparing clients for certification, you'll help organisations turn compliance requirements into meaningful business improvements.
What You'll Be Doing
Client Consulting & Delivery
- Deliver Governance, Risk & Compliance consulting engagements across multiple clients and industries.
- Conduct security posture assessments, gap analyses and maturity reviews.
- Support clients through audit preparation, certification activities and external assessments.
- Develop remediation plans and assist clients in tracking agreed actions through to completion.
- Facilitate client workshops, risk assessments and stakeholder meetings.
- Build trusted relationships with clients by providing practical, commercially focused security advice.
- Support multiple client engagements while ensuring projects are delivered on time and to a high standard.
Governance, Risk & Compliance
- Assist clients in designing and implementing governance, risk and compliance programmes aligned to recognised frameworks including:
- ISO 27001
- SOC 2
- NIST Cybersecurity Framework
- Other recognised industry standards
- Interpret security standards and regulatory requirements, translating them into practical business recommendations.
- Develop and maintain governance documentation including:
- Information Security Policies
- Standards and Procedures
- Risk Registers
- Control Frameworks
- Risk Assessments
- Governance documentation
- Support organisations in embedding governance and compliance activities into day-to-day operational processes.
- Assist clients in developing pragmatic security controls that align with both business objectives and regulatory expectations.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Continuous Improvement
- Produce high-quality consulting deliverables that meet Cognisys' standards for quality, consistency and professionalism.
- Identify opportunities to improve client security programmes and internal delivery methodologies.
- Manage multiple consulting engagements while balancing competing priorities and deadlines.
- Collaborate closely with colleagues across consulting and technical teams to deliver exceptional client outcomes.
What Success Looks Like
Success in this role is about becoming a trusted security advisor who delivers exceptional client outcomes while helping organisations build stronger, more resilient security and compliance programmes.
You will:
- Successfully deliver multiple GRC consulting engagements, ensuring projects are completed on time, within scope and to the high standards expected by Cognisys.
- Build trusted relationships with clients by providing practical, commercially focused advice that helps them navigate complex governance, risk and compliance challenges.
- Confidently support organisations through certification and compliance initiatives, including ISO 27001, SOC 2 and other recognised frameworks.
- Produce clear, accurate and professional client deliverables, including policies, procedures, risk assessments, control frameworks and governance documentation.
- Demonstrate strong knowledge of governance, risk and compliance frameworks by translating regulatory requirements into practical, business-focused recommendations.
- Effectively manage multiple client engagements while maintaining exceptional communication, organisation and stakeholder management.
- Collaborate successfully with colleagues and client stakeholders to deliver successful consulting engagements and positive client outcomes.
- Contribute to the continuous improvement of the GRC Consulting practice by enhancing methodologies, documentation, templates and ways of working.
- Continue developing your consulting expertise and establish yourself as a trusted Information Security Consultant within the Cognisys team.
About You
We're looking for someone who enjoys solving problems, building trusted client relationships and helping organisations strengthen their security posture.
You'll be naturally organised, proactive and comfortable managing multiple priorities while working across a variety of client engagements.
Most importantly, you'll enjoy translating complex security and compliance requirements into practical advice that creates real value for clients.
Essential Skills & Experience
- 2–5 years' experience in Governance, Risk & Compliance (GRC), Information Security or Risk Management.
- Practical experience working with one or more recognised security frameworks, including:
- ISO 27001
- SOC 2
- NIST Cybersecurity Framework
- Other recognised governance and compliance standards
- Experience supporting compliance, assurance or certification activities.
- Strong written communication skills with the ability to produce clear, professional client documentation.
- Excellent stakeholder management and client communication skills.
- Strong organisational skills with the ability to manage multiple client engagements simultaneously.
- Analytical mindset with a pragmatic, solution-focused approach to problem solving.
- Comfortable working with both technical and non-technical stakeholders.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable Skills & Experience
- Previous consulting experience within a client-facing professional services environment.
- Experience delivering ISO 27001 implementation or certification projects.
- Exposure to SOC 2, NIST, PCI DSS, Cyber Essentials Plus or similar security frameworks.
- Experience conducting information security risk assessments and governance reviews.
- Experience using GRC platforms such as Vanta or similar governance tools.
Certifications
The following certifications are highly regarded:
- SO/IEC 27001 Lead Implementer
- ISO/IEC 27001 Lead Auditor
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- Security+ or equivalent security certifications
Why Join Us?
At Cognisys, you will be part of a collaborative and innovative team that values your input and shares support. You'll have the opportunity to work on challenging projects that make a real impact for our clients. We'd love to hear from you if you want to challenge, lead and innovate! We're not just about the work; we're about the people. Join a team where innovation is celebrated, and your contributions are valued. We foster a collaborative environment where fresh ideas thrive, and professional growth is encouraged.
What we Offer:
- Annual Leave: 25 days per year plus 8 English bank holidays.
- Additional Leave: 1 day of paid leave for your Birthday.
- Health & Wellbeing: Access to Westfield Health Care Cash Plan and an employee mental health and wellbeing platform.
- Professional Development: £2,000 annual training budget to support your continued learning and career growth.
- Referral Bonus: help to grow our team and earn up to £2,000 per successful referral.
Applications
We’re always happy to help with questions, but to keep our process fair for everyone, we’re unable to accept applications via email—please apply directly through the job advert page.
Please feel free to reach out to Andrea, our Talent Acquisition Lead, if you would like any further information, to discuss accessibility requirements, or if you require this information provided in an alternative format – andrea.smith@cognisys.co.uk
We welcome applications from candidates from a range of diverse backgrounds and can make various reasonable adjustments to consider individual needs.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location