Information Security Consultant – SMB

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Cognisys

Cognisys

51 - 200 employees

Founded 2017

🔒 Cybersecurity

📋 Compliance

💼 Consulting

💰 Debt financing on 2023-04

Cybersecurity • Compliance • Consulting

Cognisys is a cybersecurity and compliance consultancy that provides governance, risk and compliance (GRC) services, CREST-accredited penetration testing, and vulnerability management. They act as a security and compliance partner (including vCISO engagements), and are a leading global service partner for Vanta, helping clients accelerate compliance like SOC 2 and ISO 27001. Cognisys operates internationally with multiple regional teams and offices, offers remote and hybrid roles, and emphasizes agile, client-focused delivery for organisations ranging from startups to large enterprises.

📋 Description

• Lead and support GRC consulting engagements across multiple clients and sectors • Contribute to security posture assessments, gap analyses and maturity reviews • Assist in designing and implementing GRC programmes aligned with ISO 27001, SOC 2, NIST and related standards • Support clients through audit preparation, certification processes and external assessments • Develop remediation plans and track progress against agreed actions • Participate in and lead client workshops, risk assessments and stakeholder sessions • Build trusted client relationships and provide practical, business-focused security advice • Manage multiple client engagements and ensure timely, high-quality delivery • Help clients develop and implement governance, risk and compliance programmes • Interpret security standards and regulatory requirements into practical recommendations • Conduct information security risk assessments and maintain documentation • Design and document security controls and operating models • Develop governance documentation including policies, standards, procedures, risk registers, control frameworks and risk assessments • Produce high-quality client deliverables and follow Cognisys methodologies and quality standards • Identify improvements within client engagements and contribute to internal methodologies, templates and ways of working

🎯 Requirements

• 2–5 years’ experience in security, risk, compliance or GRC-related roles • Practical experience with at least one recognised security framework, such as ISO 27001, SOC 2 or NIST • Experience supporting compliance, assurance or certification initiatives • Strong written and verbal communication skills • Excellent stakeholder management and relationship-building skills • Strong organisational skills and ability to manage multiple priorities and engagements • Analytical, pragmatic and solution-focused approach to problem solving • Comfortable working with technical and non-technical stakeholders • Strong attention to detail and commitment to high-quality client deliverables • Previous consulting experience in a client-facing professional services environment preferred • Experience delivering ISO 27001 implementation or certification projects desirable • Exposure to SOC 2, NIST, PCI DSS, Cyber Essentials Plus or similar frameworks desirable • Experience conducting information security risk assessments and governance reviews desirable • Experience using GRC platforms such as Vanta or similar tools desirable • Experience working with international clients or distributed teams desirable • Certifications highly regarded: ISO/IEC 27001 Lead Implementer, ISO/IEC 27001 Lead Auditor, CISSP, CISM, CRISC, Security+ or equivalent security certifications • Certifications are valued, but practical experience, problem-solving ability and development potential are also considered

🏖️ Benefits

• 22 days PTO per year • 12 public and 8 special Filipino holidays • 1 day of paid leave for your Birthday • 13th Month Salary - 1/2 of monthly salary paid annually in December • Individual healthcare insurance plan • Access to an employee mental health and wellbeing platform • £2,000 annual training budget • Up to £2,000 per successful referral

Apply Now

Similar Jobs

🕒 July 21

Workstreet

11 - 50

🔒 Cybersecurity

📋 Compliance

🤝 B2B

Cloud Security Engineer at Workstreet designing and implementing security for clients across AWS, GCP, Azure, and Oracle Cloud Infrastructure. Collaborating with teams to enhance cloud security posture and compliance.

AWS

Azure

Cloud

Google Cloud Platform

Oracle

Python

Terraform

🕒 July 15

Atturra

501 - 1000

💼 Consulting

🏥 Healthcare

📦 Logistics

Information Security Officer responsible for governance and compliance of information assets at Atturra. Collaborating across the business to maintain information security controls and protect sensitive data.

AWS

Azure

Cloud

Cyber Security

🕒 May 28

CallTek

5001 - 10000

💼 Consulting

🏥 Healthcare

🏨 Hospitality

Pentest/Retest Operator performing network, web, API, and infrastructure penetration testing. Requires knowledge of multiple tools and methodologies within security standards.

Linux

🕒 May 11

Pear Tree.

1 - 10

💼 Consulting

📦 Logistics

📣 Marketing

AI Security Expert focusing on securing the AI lifecycle, protecting systems from emerging threats. Collaborating on projects that require compliance and resilience against AI-specific risks.

AWS

Azure

Cloud

Cyber Security

Docker

Google Cloud Platform

Kubernetes

PyTorch

Tensorflow

🕒 May 8

Minutes to Seconds

11 - 50

🤝 B2B

👥 HR Tech

☁️ SaaS

Business Development Manager selling cybersecurity consulting and managed services for Australian organisations. Generating opportunities, managing proposals, and closing contracts remotely from the Philippines.

Cloud

Cyber Security