This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The GRC Security Consultant role is central to delivering complex Governance, Risk, and Compliance (GRC) engagements independently for Critical National Infrastructure (CNI) clients. As part of NTT DATA UK's Cyber Security Consulting team, this mid-level position empowers individuals to make a tangible impact by leveraging their expertise in UK regulatory frameworks such as the NCSC Cyber Assessment Framework (CAF), ISO 27001, and NIS Regulations. Ideal candidates will excel in client-facing leadership, technical execution, and mentorship roles, advancing both organizational objectives and their personal professional growth.
Job Responsibility:
Lead end-to-end execution of GRC consulting engagements, including compliance assessments, risk reviews, and policy framework development
Provide strategic advisory services and manage day-to-day client relationships, acting as a trusted partner in matters of GRC
Conduct independent evaluations of compliance aligned with NCSC CAF, ISO 27001, NIS Regulations, and other sector-specific security frameworks
Design and implement robust governance frameworks, risk management programs, and compliance tracking systems tailored to client needs
Facilitate workshops with client teams (5-20 stakeholders) to address risk assessments, control frameworks, and strategic planning
Develop high-quality deliverables such as risk registers, compliance roadmaps, remediation plans, and board presentations
Serve as mentor to junior consultants (P1 level), supporting skill development and conducting technical reviews of their work
Contribute to business development initiatives, including crafting client proposals, leading pitches, and promoting thought leadership
Maintain professional certifications and stay abreast of regulatory changes impacting CNI industries
Requirements:
3-5 years of proven experience in GRC consulting, information security, or cyber risk-related roles
Substantial expertise in UK regulatory standards including NCSC CAF, NIS Regulations, ISO 27001, with tangible examples of their application
Bachelor's degree in cybersecurity, information assurance, computer science, or related fields
Certifications such as CISSP, CRISC, CISM, ISO 27001 Lead Auditor/Implementer, or equivalent professional credentials
Demonstrated ability to manage client relationships, deliver advisory services, and oversee workstreams independently
Nice to have:
Experience working within the Critical National Infrastructure sectors (energy, telecommunications, public utilities)
Background in independently designing and implementing governance programs for enterprise organizations
An advanced skill set in risk management methodologies, such as NIST RMF or ISO 31000, used to support client scenarios
Master's degree is advantageous
What we offer:
Professional certification reimbursements
Health coverage
Industry-leading benefits programs
Flexible work options
Learning and development opportunities
Tailored benefits that support physical, emotional, and financial wellbeing