About this role
Salary: £75,000 - 80,000 per year
Requirements: Current DV Clearance is required.Proven experience in Cyber Security Governance, Risk & Compliance (GRC) environments.Strong knowledge of NIST CSF, NIST 800-53, ISO 27001, and NCSC CAF.Experience conducting risk assessments and security control reviews.Ability to interpret regulatory or contractual requirements and translate them into actionable security controls.Excellent stakeholder management and communication skills.Ability to work independently and manage multiple priorities in a fast-paced environment.Desirable: CISSP, CISA, CRISC, or ISO 27001 certifications.Desirable: Exposure to ISO 22301, ISO 31000, GDPR, PCI-DSS, OWASP, and other security assurance standards. Responsibilities: Translate contractual and regulatory security requirements into practical security controls aligned with recognised frameworks.Conduct security risk assessments, control reviews, and gap analysis activities.Identify security weaknesses and recommend appropriate mitigation strategies.Deliver security assurance activities including evidence reviews, compliance validation, and control testing.Support the development and enhancement of security policies, standards, and governance processes.Collaborate with stakeholders, suppliers, and project teams to ensure security requirements are understood and met.Assist with audits, compliance activities, and reporting to technical and non-technical audiences. Technologies: SupportOWASPSecurity More:
We are looking for an experienced DV Cleared Cyber Security GRC Consultant to support a major security and compliance programme within a highly secure environment. This is an onsite role based in Salisbury, five days per week, offering a competitive salary and benefits. You will work closely with technical and business stakeholders to help align security controls, governance frameworks, and compliance obligations with recognised industry standards and contractual requirements. We offer the opportunity to contribute to a key programme focused on strengthening security posture, assurance, and continuous improvement.
last updated 29 week of 2026