About The Position

Cognisys is a leading Cyber Security company specialising in Penetration Testing, GRC Consulting, and Managed Security services. We pride ourselves on our customer service, forward-thinking approach and commitment to excellence. Our small but mighty team works with some of the best-known companies in the world, covering over 30 different countries across the globe! Our GRC Consulting practice helps organisations strengthen their security posture and achieve compliance through clear, structured, and practical guidance. We work with clients at different stages of maturity, from building foundational security programmes to operating mature, scalable compliance functions. We are seeking an Information Security Consultant to join our GRC Consulting team. This is a client-facing, delivery-focused role suited to a security and compliance professional who is confident supporting engagements and contributing high-quality advisory services. As an Information Security Consultant, you will support the delivery of GRC engagements across a range of clients and industries. You will help translate regulatory and framework requirements into practical, business-aligned solutions and work collaboratively with senior consultants and client stakeholders to drive measurable improvements in governance, risk, and compliance. This role suits someone with strong foundational GRC knowledge, growing consulting experience, and a desire to develop into a trusted security advisor.

Requirements

  • 2–5 years’ experience in security, risk, compliance, or GRC-related roles.
  • Must be fluent in French and ideally German.
  • Practical experience with at least one framework such as ISO 27001, SOC 2, NIST, or similar standards.
  • Experience supporting compliance or assurance initiatives (internal or client-facing).
  • Strong written and verbal communication skills.
  • Ability to manage multiple priorities in a structured and organised manner.
  • Analytical mindset with a pragmatic approach to problem solving.
  • Comfortable working with both technical and non-technical stakeholders.

Nice To Haves

  • Consulting experience is highly desirable but not essential.
  • Experience with GRC platforms including Vanta is desirable.

Responsibilities

  • Lead the delivery of GRC consulting engagements across multiple clients and sectors.
  • Contribute to security posture assessments, gap analyses, and maturity reviews.
  • Assist in the design and implementation of GRC programmes aligned to frameworks such as ISO 27001, SOC 2, NIST, and related standards.
  • Support clients through audit preparation, certification processes, and external assessments.
  • Develop remediation plans and assist clients in tracking progress against agreed actions.
  • Participate and lead in client workshops, risk assessments, and stakeholder sessions.
  • Contribute to the design and documentation of security controls and operating models.
  • Help embed compliance activities into operational and technical processes.
  • Conduct risk assessments and maintain supporting documentation.
  • Produce high-quality client deliverables with clarity, accuracy, and consistency.
  • Follow established methodologies, templates, and internal quality standards.
  • Proactively identify areas for improvement within engagements.
  • Manage assigned tasks effectively to meet deadlines and scope expectations.
  • Support the interpretation of security standards and regulations, translating requirements into practical recommendations.
  • Lead in the development of policies, procedures, risk registers, control frameworks, and governance documentation.

Benefits

  • A dynamic and supportive work environment where customer care and innovation drive everything we do.
  • A dedicated budget for your professional development
  • Access to an Employee Wellness Hub supported by Kara Connect for health and well-being resources.
  • Frequent team social events and celebrations.
  • 25 days holiday, plus a birthday holiday.
  • Refer a friend bonus scheme, up to £2,000!
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service