HirePortal

Information Security Consultant

About the role

Zensec provides virtual CISO (vCISO) and information security consultancy services to organisations across the Channel Islands and beyond. Our clients rely on us to own the parts of their security programme they cannot resource internally — from regulatory compliance and risk management through to board-level reporting and incident readiness.

As an Information Security Consultant you will act as the vCISO lead on a portfolio of client engagements. You will be the security voice in the room: setting direction, running the compliance and assurance cycle, presenting to boards, and building long-term relationships with client stakeholders. This is a client-facing consultancy role that combines hands-on technical assurance with strategic advisory work.

You will also help shape how Zensec delivers its services — improving methodologies, mentoring junior consultants, and contributing to scoping and proposal work.

Responsibilities

Client engagement leadership
• Act as the named vCISO lead for a portfolio of client engagements, owning delivery against the agreed Statement of Works.
• Establish and maintain regular touchpoint calls with client stakeholders (no less than monthly), tracking progress and keeping scope aligned to client objectives.
• Chair monthly service review meetings and act as first point of escalation for client queries and concerns.
• Build and maintain trusted relationships with senior stakeholders including managing directors, boards, compliance officers and IT leads.
• Support scoping and proposal work for new engagements, including discovery workshops and drafting Statements of Works.
Governance, risk and compliance
• Lead gap analyses and ongoing compliance monitoring against Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance and the GFSC Cyber Security Rules and Guidance.
• Manage annual and triennial certification submissions, including Cyber Essentials and Cyber Essentials Plus questionnaires and IASME Cyber Assurance Level 1 and Level 2 assessments.
• Develop, review and maintain client information security management systems (ISMS) — policies, procedures, asset registers and supporting documentation.
• Own the client risk management cycle: conduct and maintain information and cyber risk assessments, integrate security risk into wider organisational risk frameworks, and provide emerging threat analysis and intelligence.
• Review and maintain business continuity and disaster recovery plans and produce business impact assessments where required.
• Provide oversight of data protection and privacy requirements, including data flow mapping and review of data processing agreements.
Technical assurance and oversight
• Review and monitor client technical security controls on an ongoing basis, covering firewalls, secure configuration, user access control, malware protection and security update management.
• Provide vulnerability management oversight: interpret scan output, prioritise findings, and ensure critical and high vulnerabilities are remediated within scheme timeframes.
• Review firewall rules and firmware against agreed baselines, validate endpoint and mobile security controls, and audit administrative and user accounts.
• Test and validate email and web filtering configuration as part of Cyber Essentials Plus readiness and monitoring.
• Oversee joiner, leaver and mover processes and review identity provider configuration and access control lists.
Reporting and communication
• Produce quarterly board reports covering technical and operational control performance, risk posture, opportunities and control scorecards.
• Present findings and recommendations to boards and executive teams, translating technical risk into commercial and regulatory language.
• Maintain accurate, version-controlled engagement documentation in the shared client collaboration space.
Supply chain and third-party assurance
• Conduct vendor and supplier due diligence, including questionnaire design, response review and risk identification.
• Support clients with inbound third-party due diligence requests, compliance questionnaires and cyber insurance proposal forms, including evidence gathering.
Training and incident readiness
• Design and deliver annual security awareness training to client staff, in person and remotely, refreshing content to reflect current threats and guidance.
• Facilitate incident response tabletop exercises and workshops, identifying weaknesses in client plans and controls and driving improvements.
• Review and maintain client incident response plans, processes and post-incident reports.
Team and practice development
• Mentor and quality-assure the work of junior and mid-level consultants.
• Contribute to the continuous improvement of Zensec methodologies, templates and service delivery standards.
• Maintain current knowledge of the regulatory landscape, threat trends and relevant standards.

Requirements

Essential experience and skills

• Minimum five years' experience in information or cyber security, with at least two years in a consultancy, vCISO or senior in-house security role.
• Demonstrable experience delivering against recognised security frameworks — Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance, ISO 27001, NIST CSF or equivalent.
• Proven track record of building and maintaining an ISMS, including policy authorship and risk assessment.
• Strong working knowledge of technical security controls across firewalls, endpoint protection, identity and access management, patch and vulnerability management, and email and web security.
• Experience producing and presenting security reporting to board or executive audiences.
• Excellent written English, with the ability to produce client-ready reports and documentation to a high standard.
• Confident, credible communicator able to hold their own with senior stakeholders and explain risk without jargon.
• Highly organised, able to manage competing priorities across multiple concurrent client engagements.
• Full driving licence and willingness to travel between client sites and, where required, between islands.
• Eligible to work in Jersey or Guernsey, or able to satisfy local licensing and residency requirements.
Desirable experience and skills• Experience working with regulated financial services firms, particularly against the GFSC Cyber Security Rules and Guidance or JFSC expectations.
• Familiarity with compliance management platforms and enterprise vulnerability scanning tools (for example Qualys or comparable PCI-DSS compliant scanners).
• Experience as an IASME-licensed assessor or Cyber Essentials assessor.
• Business continuity and disaster recovery planning experience, ideally aligned to ISO 22301.
• Data protection experience, including UK GDPR and the Data Protection (Jersey) Law 2018 or the Data Protection (Bailiwick of Guernsey) Law, 2017.
• Experience delivering security awareness training or facilitating tabletop exercises.
• Managed service provider (MSP) or managed security service provider (MSSP) background.

Qualifications
Desirable — one or more of the following:
• CISSP, CISM or CISA
• ISO 27001 Lead Implementer or Lead Auditor
• CompTIA Security+ or CySA+
• NCSC Certified Cyber Professional (CCP)
• IASME Cyber Assurance or Cyber Essentials assessor qualification
• Degree in cyber security, computer science or a related discipline
Equivalent demonstrable experience will be considered in place of formal qualification.

Competencies and behaviours

Zensec's brand is built on being calm in the chaos, a trusted partner, and decisive with proven expertise. We look for people who reflect that:
• Composed under pressure — steady and clear-headed when clients are dealing with an incident or a difficult audit.
• Client-first — treats engagements as long-term relationships, not transactions.
• Commercially aware — understands that security advice must be proportionate, achievable and aligned to the client's business objectives.
• Rigorous — thorough and evidence-led; does not cut corners on assurance work.
• Collaborative — works well with client IT teams, internal delivery colleagues and third parties.
• Self-directed — comfortable owning a portfolio with autonomy, and knows when to escalate.

Success in the first 12 months
• Fully onboarded onto an assigned client portfolio, with all engagements delivering to their agreed SoW milestones.
• Compliance monitoring and certification cycles running on schedule across the portfolio, with no missed submission deadlines.
• Quarterly board reporting delivered on time and rated positively by client stakeholders.
• At least one incident response exercise and one awareness training session delivered per applicable client.
• Measurable improvement in client risk posture, evidenced through control scorecards and a reduction in outstanding critical and high vulnerabilities.
• Positive client retention and satisfaction feedback across the portfolio.

Skills

  • vCISO
  • Information Security
  • Risk Management
  • Regulatory Compliance
  • Board Reporting
  • Incident Readiness
  • Client Relationship Management

Related jobs

Zenzero Solutions LtdApply for this job