The Role
We're looking for an experienced Information Security Consultant to act as the vCISO lead across a portfolio of client engagements. You'll be a trusted advisor to senior stakeholders, driving security strategy, managing compliance programmes, overseeing risk management activities, and delivering board-level reporting.
This is a highly client-facing role that combines strategic consultancy with hands-on security assurance, offering the opportunity to make a genuine impact across a diverse range of organisations.
- Act as the lead vCISO for a portfolio of clients, owning delivery and client relationships.
- Lead security governance, risk, and compliance activities aligned to frameworks such as ISO 27001, Cyber Essentials, IASME Cyber Assurance, and NIST.
- Conduct security risk assessments, gap analyses, and compliance reviews.
- Develop and maintain client ISMS documentation, policies, and procedures.
- Deliver board and executive-level reporting, translating technical risks into business-focused recommendations.
- Provide oversight of technical security controls, vulnerability management, access control, and incident readiness.
- Facilitate security awareness training, tabletop exercises, and incident response planning.
- Support client audits, certification programmes, supplier assurance activities, and regulatory requirements.
- Mentor junior consultants and contribute to the ongoing development of Zensec's security services.
- 5+ years' experience in cyber or information security, including consultancy, vCISO, or senior security roles.
- Strong knowledge of security frameworks including ISO 27001, Cyber Essentials, IASME, NIST, or equivalent.
- Experience developing and managing ISMS, policies, risk registers, and compliance programmes.
- Solid understanding of security technologies including firewalls, endpoint security, vulnerability management, IAM, and email security.
- Confident presenting to boards, executives, and senior stakeholders.
- Excellent communication, report writing, and stakeholder management skills.
- Highly organised, self-motivated, and comfortable managing multiple client engagements.
- CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, or similar certifications.
- Experience within regulated industries, financial services, MSPs, or MSSPs.
- Knowledge of GDPR, business continuity, disaster recovery, and third-party risk management.
- Experience delivering security awareness training and incident response exercises.
Benefits
- Private Medical Insurance
- Generous holiday allowance plus your birthday off
- Flexible and hybrid working
- Enhanced pension contributions
- Ongoing training and development
- Regular company social events
- Lead meaningful security programmes as a trusted client advisor.
- Work directly with boards, executives, and business leaders.
- Genuine autonomy and ownership of client relationships.
- Ongoing professional development and certification support.
- Collaborative and supportive consultancy environment