Kellwick is looking for a Senior Information Security & GRC Consultant to support client engagements across ISO 27001, SOC 2, NIST CSF 2.0 and broader security governance.
You will work directly with organisations that need to prepare for audits, certification, customer security requirements or stronger internal security governance.
This is a hands-on consulting role. We are looking for someone who can assess an organisation, identify material gaps, recommend practical remediation, work with client teams and produce audit-ready evidence and documentation.
What You Will Do
Lead ISO/IEC 27001:2022 readiness and implementation engagements
Perform gap assessments and security maturity assessments
Build and review Information Security Management Systems
Conduct information security risk assessments
Develop risk treatment plans
Build and review Statements of Applicability
Map risks, controls, policies, processes and evidence
Support control implementation and remediation
Review security policies, standards and procedures
Prepare organisations for internal and external audits
Support internal audit and management review preparation
Review evidence and test whether controls operate in practice
Support SOC 2 readiness engagements
Map security programmes against NIST CSF 2.0
Assess supplier and third-party security controls
Work with technical teams across cloud, IAM, vulnerability management, SDLC, incident management, business continuity and security operations
Produce clear findings, remediation plans and executive-level reports
Work with Kellwick vCISO and specialist consultants where required
Required Experience
5+ years of professional experience in information security, GRC, security assurance or security consulting
3+ years of practical ISO 27001 implementation, readiness or audit experience
Experience delivering multiple ISO 27001 readiness or implementation projects
Strong knowledge of ISO/IEC 27001:2022 and ISO/IEC 27002
Practical experience with risk assessment and risk treatment
Strong understanding of Statements of Applicability
Experience preparing organisations for certification audits
Experience collecting and evaluating control evidence
Experience working directly with client stakeholders
Ability to translate security requirements into practical operational controls
Strong written documentation and report-writing skills
Professional English at C1 level or higher
Strong Plus
ISO 27001 Lead Implementer
ISO 27001 Lead Auditor
CISSP
CISM
CRISC
CISA
SOC 2 readiness experience
NIST CSF 2.0 experience
SaaS and cloud security experience
Experience with AWS, Azure or Google Cloud
Experience with Vanta, Drata, Sprinto or similar GRC/compliance platforms
Previous consulting experience with organisations of approximately 50-500 employees
Engagement Model
This is not a full-time permanent position.
Kellwick maintains a vetted network of senior specialists and matches consultants to client engagements based on expertise, jurisdiction, language and availability.
Engagements are project-based and may range from short assessments to multi-month readiness, remediation and ongoing GRC assignments.
Apply for this role
Upload your CV (required) and, optionally, a cover letter. We review every application.