Overview
We are seeking an experienced Information Security GRC Consultant to join a technology-driven organization in its security accreditation efforts. The consultant will collaborate with various stakeholders to establish essential policies, controls, and a governance framework aimed at achieving compliance with Cyber Essentials Plus, ISO 27001, and SOC 2 standards. This role is focused on hands-on implementation rather than advisory services, bringing practical knowledge to ensure successful outcomes.
Responsibilities
- Support the establishment of security policies, controls, and governance frameworks.
- Lead the implementation and certification processes for ISO 27001.
- Facilitate SOC 2 readiness assessments, including Type I and Type II.
- Assist in achieving Cyber Essentials Plus accreditation.
- Conduct security gap assessments and maturity reviews.
- Compile audit preparation materials and gather evidence.
- Collaborate with external suppliers and engage with senior stakeholders.
- Provide knowledge-transfer and mentoring to internal teams.
Requirements
- Demonstrated experience in ISO 27001 implementation or certification.
- Practical knowledge of SOC 2 readiness processes.
- Proven track record supporting Cyber Essentials Plus accreditation.
- Experience with security gap assessments and maturity reviews.
- Familiarity with creating security policies, risk registers, and governance documentation.
- Strong background in audit preparation and evidence collection.
- Ability to engage effectively with external suppliers and stakeholders.
- Experience mentoring and transferring knowledge to other professionals.