
Posted 5 days ago
Senior Security Consultant (GRA)
AI Summary
Senior Security Consultant leading cyber governance, risk and assurance engagements for clients, advising on information security, conducting risk and compliance assessments against frameworks such as ISO 27001 and NIST, and producing reports for executive stakeholders.
About this role
Role Overview
We have an exciting opportunity for a Senior Security Consultant to join our growing Governance, Risk and Assurance (GRA) team. Within this role, you will utilise your GRA and cyber security expertise to advise clients on information security, lead technical consulting engagements and support in the delivery of complex security programmes.
Responsibilities
- Lead cyber governance, risk and compliance engagements, applying strong knowledge of cyber threats, risks, controls and mitigations to deliver effective security outcomes.
- Engage with clients to understand their threat landscape and business context, conducting risk and compliance assessments against recognised frameworks (e.g. ISO 27001, NIST, SOC 2).
- Design, review and advise on the implementation and adoption of information security policies, standards, procedures and frameworks.
- Lead cyber and third-party risk assessments, evaluate supplier security posture, and provide risk-based recommendations for supplier selection and oversight.
- Identify control gaps, document findings, and track remediation activities to support assurance and audit outcomes.
- Produce clear, concise risk and compliance reports for executive and C-suite stakeholders, including prioritised mitigation strategies and improvement roadmaps.
- Contribute to thought leadership and continuous improvement by staying current with industry developments and sharing knowledge across the cyber security community.
- Demonstrate strong communication, stakeholder management and mentoring skills, upholding the highest standards of integrity and professionalism.
About you
- You have extensiveexperienceofdesigning, leading and delivering cyber governance,riskand assurance outcomes, with a proventrack recordof successfully leading GRC and security assurance initiatives.
- Youpossessstrong knowledge ofrecognisedcyber security frameworks and standards, including ISO/IEC 27001, NIS Directives, NIST, and UK Government Functional Standards, with demonstrable experience aligning security controls to MOD requirements such as DEFSTAN 05-138, JSP 440, JSP 604 andDefenceCyber Resilience policies.
- You are experienced in applying UK Government security and assurance frameworks, includingGovAssure, the Cyber Assessment Framework (CAF),DefenceCyber Certification (DCC)andGovernment Standard (GovS) 007.
- You are a confident stakeholder manager, able to clearly articulate cyber risk and the value of security investment to senior leaders, while mentoring and guiding teams to deliver high-quality outcomes.
- You hold relevant academic or professional qualifications, such as, an MScincyber security or related specialism,Cyber Essentials Assessor, Cyber Assurance Assessor,CISM, CISSP, PCIRMor ISO/IEC 27001 Lead Implementer or Lead Auditor certification.
- You hold, or are actively working towards,Principal orChartered Cyber Security Professional (ChCSP) status.
- You are eligible to work in the UK and able to obtain andmaintainUK security clearances.You will have the flexibility to work from home, FSP office locations or at times visit clientsites.
What we look for in our people
- Strong alignment with FSP values and ethos
- Commitment to teamwork, quality and mutual success
- Proactivity with an ability to operate with pace and energy
- Strong communication and interpersonal skills
- Excellent planning and organisational skills
- Dedication to excellence and quality
Who are FSP?
FSP is a leading consultancy specialising in Digital, Security and AI solutions. Our success is enabled by our unwavering commitment to excellence, our people centric culture alongside best-in-class operations, ensuring impactful and sustainable outcomes for our clients.
As a long standing and highly accredited Microsoft Partner, with extensive solution designations, we partner with clients across a range of commercial sectors, enabling digital transformation, innovation and robust cyber security.
We navigate the complexities of data sensitivity, confidentiality, governance and compliance. We blend strategic insight, depth of technical expertise, delivery and operational excellence to meet the specific requirements outlined.
We take a collaborative, one team approach with our clients to drive sustainable change, providing outstanding client experience and delivering exceptional results that are aligned with business priorities.
Our commitment to security and quality is reinforced by our ISO27001 and ISO9001 certifications (UKAS), as well as our CREST approved penetration testing and SOC capabilities. Additionally, we are an IASME Cyber Essentials Certification Body and Cyber Essentials Plus certified.
Find out more about our accolades here:https://fsp.co/about-fsp/
Why work for FSP?
At FSP, we are committed to providing:
- A collaborative and supportive environment in which you can grow and develop your career
- The tools and opportunity to do work you can be proud of
- A chance to work alongside some of the best people in the industry, who always seek to share their knowledge and experience
- Hybrid working – we empower you to make smart choices about when and where to work to achieve great results.
- Industry leading coaching and mentoring
- Plus the excellent benefits package we offer at FSP
Equal and Fair Opportunity
FSP is an equal opportunity employer and welcomes applications from all suitably qualified candidates. We assess applicants based on their skills, experience, and potential, without regard to age, disability, sexual orientation, gender identity, family or parental status, race, colour, nationality, ethnic or national origin, religion or belief, or any other protected characteristic.
Please note that visa sponsorship is available for some roles, subject to eligibility and business requirements.
Research indicates that individuals from underrepresented groups may be less likely to apply where they feel they do not meet every requirement, or where there is uncertainty about who a role is intended for. If you are interested in a role with us but are concerned that you may not meet all the criteria, we encourage you to apply. You may be a strong candidate for this role or for other opportunities within FSP.
We are committed to providing a fair and inclusive recruitment process. If you require any reasonable adjustments to participate fully in an interview or meeting (whether virtual or in person), please let us know.
Skills
Explore related jobs
More jobs at FSP Consulting Services Limited
Cloud .NET EngineerVadodara, Gujarat
Senior AWS Platform EngineerGlasgow or Newbury / Reading, Berkshire
Data Security EngineerGlasgow or Newbury / Reading, Berkshire
Infrastructure Security EngineerGlasgow or Newbury / Reading, Berkshire
Lead Data EngineerGlasgow or Newbury / Reading, Berkshire
Senior Cyber Risk & Compliance Consultant (GRA)Glasgow or Reading, Berkshire
Similar CISM jobs
Jobs in Glasgow
Registered Veterinary NurseAnimal Trust · Glasgow, Glasgow City
Registered Veterinary Nurse - Part TimeAnimal Trust · Glasgow, Glasgow City- Senior EcologistOrigin Environmental · Glasgow, South Lanarkshire
Seasonal Sales AdvisorRiver Island · Glasgow Braehead- Head of PeopleCitizens Advice Scotland · Edinburgh/Glasgow, Scotland
hotel night ambassadorAnother Star · UK, Glasgow
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.