Information Security Consultant
Listed on 2026-09-13
-
IT/Tech
Cybersecurity, IT Consultant, Information Security & Data Protection
About the role
Zensec provides virtual CISO (vCISO) and information security consultancy services to organisations across the Channel Islands and beyond. Our clients rely on us to own the parts of their security programme they cannot resource internally — from regulatory compliance and risk management through to board-level reporting and incident readiness.
As an Information Security Consultant you will act as the vCISO lead on a portfolio of client engagements. You will be the security voice in the room: setting direction, running the compliance and assurance cycle, presenting to boards, and building long‑term relationships with client stakeholders. This is a client‑facing consultancy role that combines hands‑on technical assurance with strategic advisory work.
You will also help shape how Zensec delivers its services — improving methodologies, mentoring junior consultants, and contributing to scoping and proposal work.
Job requirements Essential experience and skills- Minimum five years' experience in information or cyber security, with at least two years in a consultancy, vCISO or senior in‑house security role.
- Demonstrable experience delivering against recognised security frameworks — Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance, ISO 27001, NIST CSF or equivalent.
- Proven track record of building and maintaining an ISMS, including policy authorship and risk assessment.
- Strong working knowledge of technical security controls across firewalls, endpoint protection, identity and access management, patch and vulnerability management, and email and web security.
- Experience producing and presenting security reporting to board or executive audiences.
- Excellent written English, with the ability to produce client‑ready reports and documentation to a high standard.
- Confident, credible communicator able to hold their own with senior stakeholders and explain risk without jargon.
- Highly organised, able to manage competing priorities across multiple concurrent client engagements.
- Full driving licence and willingness to travel between client sites and, where required, between islands.
- Eligible to work in Jersey or Guernsey, or able to satisfy local licensing and residency requirements.
- Experience working with regulated financial services firms, particularly against the GFSC Cyber Security Rules and Guidance or JFSC expectations.
- Familiarity with compliance management platforms and enterprise vulnerability scanning tools (for example Qualys or comparable PCI‑DSS compliant scanners).
- Experience as an IASME‑licensed assessor or Cyber Essentials assessor.
- Business continuity and disaster recovery planning experience, ideally aligned to ISO 22301.
- Data protection experience, including UK GDPR and the Data Protection (Jersey) Law 2018 or the Data Protection (Bailiwick of Guernsey) Law, 2017.
- Experience delivering security awareness training or facilitating tabletop exercises.
- Managed service provider (MSP) or managed security service provider (MSSP) background.
Desirable — one or more of the following:
- CISSP, CISM or CISA
- ISO 27001 Lead Implementer or Lead Auditor
- CompTIA Security+ or CySA+
- NCSC Certified Cyber Professional (CCP)
- IASME Cyber Assurance or Cyber Essentials assessor qualification
- Degree in cyber security, computer science or a related discipline
Equivalent demonstrable experience will be considered in place of formal qualification.
Job responsibilities Client engagement leadership- Act as the named vCISO lead for a portfolio of client engagements, owning delivery against the agreed Statement of Works.
- Establish and maintain regular touchpoint calls with client stakeholders (no less than monthly), tracking progress and keeping scope aligned to client…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).