Salary: £? – ? per year
Requirements
- Proven track record of executing security due diligence on target entities during corporate acquisitions.
- Deep, hands‑on experience implementing, auditing, or managing ISO 27001 and SOC 2 compliance programs.
- Experience designing, updating, and testing Business Continuity frameworks; experience aligning with ISO 22301 is a plus.
- Outstanding stakeholder management skills, with the ability to communicate complex security risks to business leads and M&A deal teams.
Responsibilities
- Conduct comprehensive cybersecurity risk assessments and security due diligence on target acquisition companies.
- Review target company security controls, policies, third‑party assurance reports, and historical security incident logs.
- Identify deal‑impacting risks, quantify remediation effort, and advise on onboarding security priorities.
- Identify risk areas and formulate post‑acquisition security integration roadmaps and transition plans.
- Assess, maintain, and mature security frameworks aligned with ISO/IEC 27001 and SOC 2 Type II.
- Develop and maintain information security policies, standards, and procedures aligned to business objectives.
- Run security risk assessments, update risk registers, and drive risk treatment and remediation plans.
- Identify control gaps, collaborate with internal system owners to implement remediation plans, and collect audit‑ready evidence.
- Assist in preparing the business, staff, and control owners for external surveillance and compliance audits.
- Lead the review and update of Business Continuity Plans across key business departments.
- Facilitate Business Impact Analyses to identify critical processes, evaluate dependencies, and define Recovery Time Objectives.
- Design and execute tabletop exercises and simulation tests to validate recovery strategy effectiveness.
- Perform vendor risk assessments, review security clauses, and ensure suppliers meet security and business continuity requirements.
- Manage the relationship with outsourced managed IT and information security suppliers.
- Deliver security awareness initiatives and provide advisory support to projects and teams.
- Communicate risks and recommendations clearly to leadership and non‑technical stakeholders.
Technologies
- Support
- Security
- ARM
More
We are seeking two highly skilled, hands‑on Contract Information Security & Resilience Consultants to support several critical, high‑priority strategic initiatives on a 6‑month contract inside IR35, paying up to £500 per day. This is a hybrid role with two days a week onsite, based either in London or Bradford. We provide specialist recruitment and management consultancy services across technical sectors, and we will never send your CV without your permission.
#J-18808-Ljbffr…
