This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Junior/Associate GRC Consultant role represents an exceptional opportunity for entry-level professionals eager to develop foundational skills in Governance, Risk, and Compliance (GRC) while contributing to the cybersecurity posture of Critical National Infrastructure (CNI) clients. Working under direct supervision, the consultant will gain exposure to UK regulatory frameworks such as NCSC Cyber Assessment Framework (CAF), NIS Regulations, and ISO 27001, while building the technical and interpersonal competencies necessary to succeed in GRC consulting.
Job Responsibility:
Conduct compliance assessments aligned with UK regulatory frameworks (NCSC CAF, NIS Regulations, and ISO 27001) under the guidance of senior team members
Assist in the development of governance documentation, including policies, procedures, and control frameworks, ensuring alignment with best practices
Perform basic gap analysis and control testing activities, documenting findings in accordance with established methodologies
Participate in facilitated risk assessment workshops, supporting documentation of risks, controls, and mitigation strategies
Contribute to high-quality deliverables, including executive summaries, compliance matrices, remediation plans, and tailored client recommendations
Maintain documentation standards, adhering to quality assurance processes
Support pre-sales activities through technical input, proposal preparation, and research contributions
Participate in internal knowledge-sharing sessions and professional development opportunities to build technical expertise
Requirements:
0-2 years of experience in cybersecurity, GRC roles, or related consulting positions
Fundamental understanding of information security principles, risk management concepts, and basic regulatory requirements
Awareness of UK regulatory frameworks such as NCSC CAF, ISO 27001, or equivalent standards
Bachelor’s degree in Computer Science, Information Security, Business, or a related field, or equivalent experience
Foundation-level certifications (e.g., Security+, CISSP Associate, ISO 27001 Foundation), or strong commitment toward obtaining relevant certifications within 12 months
Nice to have:
Entry-level hands-on experience in information security controls, compliance frameworks, or risk methodologies
Familiarity with the Critical National Infrastructure sector or comparable regulated environments
Exceptional organizational skills and attention to detail, particularly in technical writing and documentation
What we offer:
Competitive entry-level salary package, inclusive of certification reimbursement, health benefits, and access to industry events
Tailored benefits that support physical, emotional, and financial wellbeing