Apply Edge Start your job search

Assurance Consultant

City Recruitment Associates · City Of London, England, United Kingdom

Apply & track with Apply Edge
Client: IT Service providerRole: GRC/Assurance ConsultantLocation: Fleet Street, LondonSalary: £45,000 + benefitsBusiness Area: Governance, Risk and ComplianceWhy this role existsOur client is an NCSC Assured Service Provider, an IASME-licensed Certification Body and a Cyber Scheme Accredited Company. Assure is the fastest-growing part of our business. This role exists to deliver it. You will be the person clients rely on when a supplier questionnaire lands, when an insurer starts asking questions, when a tender demands evidence, or when a board realises nobody actually owns information security.What you will doPlan and deliver ISO/IEC 27001 internal audits, readiness reviews and gap assessmentsSupport clients in building and running information security management systems — risk registers, policies, controls, evidence and corrective actionsDeliver Cyber Essentials readiness work: assess the estate, complete the technical sections, and guide clients through submissionCarry out supplier and third-party security due diligence, and help clients respond to assurance questionnairesRun recurring client assurance activity — governance reviews, risk tracking, evidence management, compliance roadmaps and management reportingTranslate standards, contracts, procurement requirements and regulation into clear, prioritised, proportionate actionsWrite client-facing reports that explain the requirement, the risk, the gap and the recommended action, without unnecessary jargonWork with our technical and service teams to gather evidence, validate controls and coordinate remediationBuild and maintain reusable templates and evidence sets, so the same control never has to be proved from scratch twiceWhat good looks likeClients trust you to discuss governance and risk with both engineers and directors, and to make the second group feel competent rather than exposedYou can run a defined assurance engagement with limited supervision, and you recognise when something needs escalatingYour work is evidence-led and proportionate — aimed at improving real security and resilience, not compliance for its own sakeYou are comfortable mapping common controls and evidence across different client requirements, which is how we keep assurance affordable for smaller organisationsYou understand where operational IT ends, cyber security begins and formal assurance sits — and you respect the boundaries between themWhat we need from youISO/IEC 27001 Internal Auditor qualification, or demonstrable equivalent audit competencePractical working knowledge of ISO/IEC 27001, including participating in or conducting internal auditsExperience with information security risk, policies, controls, evidence and remediationThe ability to interpret a security or compliance requirement and explain what it actually means operationallyExperience producing professional reports, findings and recommendationsConfident client-facing communication with technical teams, managers and senior stakeholdersStrong organisation and judgement — able to hold several engagements without losing control of the detailEnough technical understanding to validate evidence and ask the right questions of an engineerUseful, but not essentialISO/IEC 27001 Lead Auditor or Lead Implementer trainingCyber Essentials, IASME or wider cyber assurance experienceNIST CSF, NCSC CAF, NIS2, supplier assurance or defence-sector security requirementsPrivacy and information governance experience, including practical DSAR supportExperience in an MSP, MSSP or consultancy serving multiple clientsExperience supporting regulated organisations, government suppliers or complex supply chainsWhere this role can goYou report directly to the CEO. No layers, real influence over how the Assure service develops, and visibility of the whole business rather than one corner of itThere is a genuine path toward becoming a certification assessor. We are an IASME Certification Body and are working toward Defence Cyber Certification.For the right person, a training fund can be made available to support relevant professional development and qualificationsSalary is formally reviewed at twelve months against what you are deliveringAs experience develops, the work broadens into IASME Cyber Assurance, NCSC CAF and NIS2, and defence supply-chain assuranceThe person we are looking forYou do not need to know every framework on day one. We care about sound judgement, audit discipline, curiosity and the ability to learn quickly. You should be comfortable moving between evidence and controls one moment and a conversation with a client director the next.We are particularly interested in someone who enjoys making governance useful. Your instinct should be to understand the client, the risk and the intended outcome first, then apply the right level of assurance without creating unnecessary complexity.About Client:Delivers managed IT, cyber security and assurance services through three connected disciplines: Manage, Protect and Assure. We support clients from day-to-day technology operations, through active cyber protection, to the governance and evidence needed to meet customer, regulatory and supply-chain expectations.We are a small, established team — most of our engineers have been with us four to five years — working with clients who value practical advice, clear ownership and a service that connects technical reality with assurance requirements.Practical pointsYou must have the right to work in the UKThe role may involve travel to client sites, predominantly in London