Senior Security Consultant (GRA)
9 days ago
Glasgow
Role Overview\n We have an exciting opportunity for a Senior Security Consultant to join our growing Governance, Risk and Assurance (GRA) team. Within this role, you will utilise your GRA and cybersecurity expertise to advise clients on information security, lead technical consulting engagements and support in the delivery of complex security programmes. \nResponsibilities\n\n • Lead cyber governance, risk and compliance engagements, applying strong knowledge of cyber threats, risks, controls and mitigations to deliver effective security outcomes.\n, • Engage with clients to understand their threat landscape and business context, conducting risk and compliance assessments against recognised frameworks (e.g. ISO 27001, NIST, SOC 2).\n, • Design, review and advise on the implementation and adoption of information security policies, standards, procedures and frameworks.\n, • Lead cyber and third‑party risk assessments, evaluate supplier security posture, and provide risk‑based recommendations for supplier selection and oversight.\n, • Identify control gaps, document findings, and track remediation activities to support assurance and audit outcomes.\n, • Produce clear, concise risk and compliance reports for executive and C‑suite stakeholders, including prioritised mitigation strategies and improvement roadmaps.\n, • Contribute to thought leadership and continuous improvement by staying current with industry developments and sharing knowledge across the cyber security community.\n, • Demonstrate strong communication, stakeholder management and mentoring skills, upholding the highest standards of integrity and professionalism.\n\nAbout you\n\n, • You have extensive experience of designing, leading and delivering cyber governance, risk and assurance outcomes, with a proven track record of successfully leading GRC and security assurance initiatives.\n, • You possess strong knowledge of recognised cyber security frameworks and standards, including ISO/IEC 27001, NIS Directives, NIST, and UK Government Functional Standards, with demonstrable experience aligning security controls to MOD requirements such as DEFSTAN 05-138, JSP 440, JSP 604 and Defence Cyber Resilience policies.\n, • You are experienced in applying UK Government security and assurance frameworks, including GovAssure, the Cyber Assessment Framework (CAF), Defence Cyber Certification (DCC), and Government Standard (GovS) 007.\n, • You are a confident stakeholder manager, able to clearly articulate cyber risk and the value of security investment to senior leaders, while mentoring and guiding teams to deliver high‑quality outcomes.\n, • You hold relevant academic or professional qualifications, such as an MSc in cyber security or related specialism, CISM, CISSP, PCIRM or ISO/IEC 27001 Lead Implementer or Lead Auditor certification.\n, • You are eligible to work in the UK and able to obtain and maintain UK security clearances.\n, • You hold, or are actively working towards, Principal or Chartered Cyber Security Professional (ChCSP) status.\n\nWhat we look for in our people\n\n, • Strong alignment with FSP values and ethos\n, • Commitment to teamwork, quality and mutual success\n, • Proactivity with an ability to operate with pace and energy\n, • Strong communication and interpersonal skills\n, • A collaborative and supportive environment in which you can grow and develop your career\n, • The tools and opportunity to do work you can be proud of\n, • A chance to work alongside some of the best people in the industry, who always seek to share their knowledge and experience\n, • Hybrid working – we empower you to make smart choices about when and where to work to achieve great results\n, • Industry leading coaching and mentoring\n