GRC Cyber Consultant

Company: Accenture UK & Ireland
Apply for the GRC Cyber Consultant
Location: London
Job Description:

Role: GRC Cyber Consultant

Location: Any Accenture UK location

Career Level: Level 9 – Specialist

Please Note: Any offer of employment is subject to satisfactory BPSS and SC security clearance which typically requires 5 years continuous UK address history and declaration of being a British passport holder with no dual nationality at the point of application.

Role Summary

We are seeking experienced Information Security Consultants specialising in Governance, Risk and Compliance (GRC) to support large‑scale, complex and cutting‑edge technology transformation programmes and to provide specialist GRC and assurance expertise to external clients. This is a consultancy‑focused role requiring professionals who can operate confidently in client environments, embed security into delivery from the outset, and provide pragmatic, risk‑based advice that enables transformation rather than constraining it. The role is suited to individuals comfortable acting as a trusted advisor, supporting clients to design, govern and assure modern digital, cloud and data‑driven services in line with regulatory, contractual and organisational requirements.

Key Responsibilities

Governance, Risk & Assurance Specialist

  • Design, implement and operate information security governance frameworks aligned to client programme and regulatory context.
  • Provide independent information security assurance across programmes, platforms and services.
  • Lead or support technology and information security risk assessments, including cloud and SaaS environments, enterprise platforms and data services, and third‑party and supply‑chain arrangements.
  • Maintain and present risk positions clearly to senior stakeholders, boards and assurance forums, supporting formal risk owners and governance bodies.

Compliance & Regulatory Advisory

  • Advise clients on meeting industry standards and regulatory expectations, which may include ISO/IEC 27001, NCSC guidance, CAF, UK regulatory frameworks and sector‑specific assurance requirements.
  • Translate regulatory and policy requirements into practical, implementable security controls.
  • Support audits, assurance reviews and regulatory assessments, acting as the information security subject matter expert.

Secure by Design & Transformation Support

  • Embed Secure by Design principles into technology and digital transformation programmes from concept through to live service.
  • Provide security input during architecture design, solution selection and delivery planning, ensuring risks are addressed early.
  • Support clients in aligning information security design with business objectives, user needs and regulatory expectations.
  • Support assurance activities across the delivery lifecycle, including design assurance, go‑live readiness and operational assurance.
  • Challenge designs constructively to ensure security controls are proportionate, effective and risk‑based.

Client Engagement & Consultancy Delivery

  • Work directly with external clients, either embedded within delivery teams or providing advisory support.
  • Build trusted relationships with client stakeholders, including technical leads, delivery managers and senior leadership.
  • Produce clear, high quality client deliverables, such as risk assessments and assurance reports, governance artefacts and information security strategies, and Secure by Design recommendations.
  • Adapt quickly to different organisational cultures, risk appetites and delivery models.

Continuous Improvement & Capability Building

  • Contribute to the development of consulting methods, templates, playbooks and best practice.
  • Contribute to shaping work packages, estimates and delivery approaches within defined engagements.
  • Provide informal mentoring and knowledge sharing to more junior colleagues, supporting capability uplift within delivery teams.
  • Remain current with emerging threats, regulatory change and modern technology patterns.

Essential Skills And Experience

  • Proven experience in information security governance, risk and compliance (GRC), including working within at least one of the more common standards or certifications (ISO27001, NIST, NIS, CAF etc).
  • Experience conducting technology and security risk assessments in complex environments.
  • Strong understanding of modern technology risks, including cloud, identity, data and third‑party services.
  • Excellent communication skills, with the ability to explain risk and information security concepts to non‑technical stakeholders.
  • Demonstrable experience applying Secure by Design principles within technology or digital delivery.
  • Experience working in client‑facing, consulting or advisory roles, or equivalent environments.

Qualifications And Professional Development

Essential / Strongly Preferred

  • One or more industry recognised information security certifications, such as CISSP, CISM or risk‑focused certifications (e.g. CRISC or equivalent).

Ongoing Development

  • A clear commitment to continuous learning and professional development.
  • Willingness to work towards CIISec Full membership and UK Cyber Security Council (UK CSC) Principal or Chartered professional registration.

Personal Attributes

  • Strong consulting mindset with a pragmatic, outcomes‑focused approach.
  • Comfortable balancing security, delivery at pace and business needs.
  • Professional, trusted and ethical when handling sensitive information.
  • Confident working independently or as part of multi‑disciplinary client teams.
  • Curious, adaptable and motivated to work with emerging technologies and new delivery models.

What We Offer

  • Opportunity to work on high‑profile, innovative and nationally significant client engagements.
  • Exposure to a wide range of sectors, technologies and regulatory environments.
  • Clear pathways for career progression, extensive training opportunities, professional recognition and certification support.
  • A culture that values individuals, teamwork, quality consultancy and continuous improvement.

Closing date 30/06/2026

#J-18808-Ljbffr…

Posted: May 30th, 2026