Information Security Consultant

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $75k - $85k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Cognisys

Cognisys

51 - 200 employees

Founded 2017

🔒 Cybersecurity

📋 Compliance

💼 Consulting

💰 Debt financing on 2023-04

Cybersecurity • Compliance • Consulting

Cognisys is a cybersecurity and compliance consultancy that provides governance, risk and compliance (GRC) services, CREST-accredited penetration testing, and vulnerability management. They act as a security and compliance partner (including vCISO engagements), and are a leading global service partner for Vanta, helping clients accelerate compliance like SOC 2 and ISO 27001. Cognisys operates internationally with multiple regional teams and offices, offers remote and hybrid roles, and emphasizes agile, client-focused delivery for organisations ranging from startups to large enterprises.

📋 Description

• Deliver ongoing information security advisory engagements across clients and industries • Provide practical guidance on information security risks, security programmes and improvement priorities • Support vCISO-style advisory services and ongoing security programme development • Assess and improve the effectiveness, maturity and sustainability of security programmes • Prioritise security initiatives based on risk, business objectives and available resources • Support specialist information security projects and additional client work • Develop realistic approaches to complex security problems • Support the development, maintenance and improvement of information security programmes • Assess security risks, controls, processes and operating practices • Develop and maintain security roadmaps, risk registers, remediation plans and improvement programmes • Advise on security governance, risk management, controls, policies, procedures and operating processes • Apply relevant frameworks, standards, regulations and industry practices • Support security assurance and compliance activities • Use GRC platforms and other security tooling • Build trusted, long-term relationships with client stakeholders • Lead client meetings, workshops and advisory sessions • Communicate risks, recommendations and trade-offs clearly • Manage expectations and communicate progress, challenges and dependencies • Own defined client engagements and workstreams • Manage competing priorities across multiple clients and projects • Plan and organise delivery to meet agreed timelines and outcomes • Identify risks and blockers and take appropriate action • Contribute to scoping and shaping additional client work • Produce clear, accurate and commercially appropriate client deliverables • Apply Cognisys methodologies and quality standards • Share knowledge and contribute to the wider GRC consulting team

🎯 Requirements

• 3–5 years' experience in information security, cybersecurity, security consulting or a related industry role • Strong practical understanding of information security and cybersecurity principles • Experience working in an operational, technical or industry information security environment • Experience identifying and managing real-world security risks • Experience developing, operating, assessing or improving security programmes • Experience with security controls, risk management, security processes or security operations • Experience with FedRAMP and the NIST SP 800 series would be helpful • Strong client-facing and consulting skills • Excellent written and verbal communication skills • Ability to present ideas and recommendations clearly to audiences at all levels • Experience working with technical, operational and senior stakeholders • Strong questioning, listening and relationship-building skills • Ability to develop practical, commercially sensible solutions • Strong organisational skills and ability to manage multiple clients, workstreams and competing priorities • Comfortable operating independently and using professional judgement • Consulting experience is highly desirable • Experience with vCISO, security advisory or ongoing security programme support is highly desirable • Experience with GRC platforms such as Vanta is desirable

🏖️ Benefits

• 22 days PTO per year plus 11 American bank holidays • 1 day of paid leave for your Birthday • Individual access to a healthcare and life insurance plan • Employee mental health and wellbeing platform • 2% employer contributions to the Fidelity 401k scheme in accordance with statutory requirements • £2,000 annual training budget • Up to £2,000 per successful referral

Apply Now

Similar Jobs

🔥 2 hours ago

ASRC Federal

5001 - 10000

🎖️ Defense

🚀 Aerospace

🏛️ Government

Security Engineer securing DHS cloud, data-center, network, and application solutions. Integrating compliance tools and interpreting federal security requirements for ASRC NetCentric’s government program.

🔥 5 hours ago

Control Risks

1001 - 5000

📦 Logistics

📣 Marketing

✈️ Travel

Technical Data Center Security Assurance Manager overseeing security systems, risk assessments, and construction quality for Control Risks’ major technology client. Remote role requiring extensive travel across regional data center campuses.

🔥 9 hours ago

The Hello Team

1001 - 5000

🏥 Healthcare

🛡️ Insurance

📦 Logistics

Remote cybersecurity and compliance consultant leading HIPAA, NIST, and SOC 2 engagements. Strengthening regulated organizations’ security programs through assessments, remediation, and vCISO support.

🔥 10 hours ago

Anduril Industries

501 - 1000

🏭 Manufacturing

💼 Consulting

📦 Logistics

Senior Security Engineer securing Anduril’s defense technology OT and ICS environments. Designing defensive controls, threat detection, and security roadmaps for advanced factory systems.

🔥 10 hours ago

Anduril Industries

501 - 1000

🏭 Manufacturing

💼 Consulting

📦 Logistics

Senior Security Engineer designing defensive controls for Anduril Industries' military technology infrastructure. Automating detection, monitoring, and remediation across cloud, corporate, and production systems.