Information Security Consultant
Summary
A client-facing senior consultant acting as virtual CISO for a portfolio of Channel Islands clients at Zensec — running compliance cycles (Cyber Essentials, IASME, ISO 27001, GFSC), risk assessments, board reporting, technical control reviews, and incident readiness, while mentoring junior consultants. Based in Jersey.
The Role
We're looking for an experienced Information Security Consultant to act as the vCISO lead across a portfolio of client engagements. You'll be a trusted advisor to senior stakeholders, driving security strategy, managing compliance programmes, overseeing risk management activities, and delivering board-level reporting.
This is a highly client-facing role that combines strategic consultancy with hands-on security assurance, offering the opportunity to make a genuine impact across a diverse range of organisations.
Responsibilities
- Act as the lead vCISO for a portfolio of clients, owning delivery and client relationships.
- Lead security governance, risk, and compliance activities aligned to frameworks such as ISO 27001, Cyber Essentials, IASME Cyber Assurance, and NIST.
- Conduct security risk assessments, gap analyses, and compliance reviews.
- Develop and maintain client ISMS documentation, policies, and procedures.
- Deliver board and executive-level reporting, translating technical risks into business-focused recommendations.
- Provide oversight of technical security controls, vulnerability management, access control, and incident readiness.
- Facilitate security awareness training, tabletop exercises, and incident response planning.
- Support client audits, certification programmes, supplier assurance activities, and regulatory requirements.
- Mentor junior consultants and contribute to the ongoing development of Zensec's security services.
Requirements
- 5+ years' experience in cyber or information security, including consultancy, vCISO, or senior security roles.
- Strong knowledge of security frameworks including ISO 27001, Cyber Essentials, IASME, NIST, or equivalent.
- Experience developing and managing ISMS, policies, risk registers, and compliance programmes.
- Solid understanding of security technologies including firewalls, endpoint security, vulnerability management, IAM, and email security.
- Confident presenting to boards, executives, and senior stakeholders.
- Excellent communication, report writing, and stakeholder management skills.
- Highly organised, self-motivated, and comfortable managing multiple client engagements.
- CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, or similar certifications.
- Experience within regulated industries, financial services, MSPs, or MSSPs.
- Knowledge of GDPR, business continuity, disaster recovery, and third-party risk management.
- Experience delivering security awareness training and incident response exercises.
Benefits
- Private Medical Insurance
- Generous holiday allowance plus your birthday off
- Flexible and hybrid working
- Enhanced pension contributions
- Ongoing training and development
- Regular company social events
- Lead meaningful security programmes as a trusted client advisor.
- Work directly with boards, executives, and business leaders.
- Genuine autonomy and ownership of client relationships.
- Ongoing professional development and certification support.
- Collaborative and supportive consultancy environment