Information Security & Resilience Consultant
Job Description
Information Security & Resilience Consultant - M&A\n6-Month contract - Inside IR35 - up to £500 per day\nHybrid working - 2 days a week...
Job Description
Information Security & Resilience Consultant - M&A
\n6-Month contract - Inside IR35 - up to £500 per day
\nHybrid working - 2 days a week onsite - either London or Bradford based
\n\nWe are seeking two highly skilled, hands-on Contract Information Security & Resilience Consultants to support several critical, high-priority strategic initiatives.
\nIn this dual-role, you will be responsible for executing rigorous security due diligence on upcoming M&A activities, maintaining and maturing our Information Security Management System (ISMS) compliance frameworks, and driving our Business Continuity and Resilience programs.
\n\nKey Responsibilities
\n- \n
- M&A Security Due Diligence \n
Due Diligence Assessments: Conduct comprehensive cybersecurity risk assessments and security due diligence on target acquisition companies.
\nControl Evaluation: Review target company security controls, policies, third-party assurance reports (e.g., SOC 2, ISO certifications), and historical security incident logs.
\nIdentify deal-impacting risks, quantify remediation effort (cost/timeline ranges), and advise on onboarding security priorities.
\nIntegration Roadmapping: Identify risk areas and formulate actionable post-acquisition security integration roadmaps and transition plans.
\n- \n
- Information Security Standards & Compliance (ISO 27001 & SOC 2) \n
Framework Governance: Assess, maintain, and mature existing security frameworks aligned with ISO/IEC 27001 and SOC 2 Type II.
\nDevelop and maintain information security policies, standards, and procedures aligned to these standards and business objectives.
\nRun security risk assessments, update risk registers, and drive risk treatment/remediation plans.
\nRemediation & Evidence: Identify control gaps, collaborate with internal system owners to implement remediation plans, and collect audit-ready evidence.
\nExternal Audits: Assist in preparing the business, staff, and control owners for upcoming external surveillance and compliance audits.
\n- \n
- Business Continuity & Disaster Recovery \n
Plan Development: Lead the review and update of Business Continuity Plans (BCPs) across key business departments
\nImpact Analysis: Facilitate Business Impact Analyses (BIAs) to identify critical business processes, evaluate upstream/downstream dependencies, and define Recovery Time Objectives (RTOs)
\nTesting & Exercises: Design and execute tabletop exercises and simulation tests to validate recovery strategy effectiveness
\n- \n
- Third-Party & Supplier Security \n
Perform vendor risk assessments, review security clauses, and ensure suppliers meet security and business continuity requirements.
\nManage the relationship with our outsourced managed IT and information security suppliers
\n- \n
- Security Awareness & Stakeholder Management \n
Deliver security awareness initiatives and provide advisory support to projects and teams.
\nCommunicate risks and recommendations clearly to leadership and non-technical stakeholders.
\n\nRequired Skills & Experience
\n- \n
- M&A Security Expertise: Proven track record of executing security due diligence on target entities during corporate acquisitions. \n
- Compliance Mastery: Deep, hands-on experience implementing, auditing, or managing ISO 27001 and SOC 2 compliance programs. \n
- Business Continuity Planning: Experience designing, updating, and testing Business Continuity frameworks (experience aligning with ISO 22301 is a plus) \n
- Consultative Approach: Outstanding stakeholder management skills, with the ability to communicate complex security risks to business leads and M&A deal teams. \n
Disclaimer:
\nThis vacancy is being advertised by either Advanced Resource Managers Limited, Advanced Resource Managers IT Limited or Advanced Resource Managers Engineering Limited ("ARM"). ARM is a specialist talent acquisition and management consultancy. We provide technical contingency recruitment and a portfolio of more complex resource solutions. Our specialist recruitment divisions cover the entire technical arena, including some of the most economically and strategically important industries in the UK and the world today. We will never send your CV without your permission. Where the role is marked as Outside IR35 in the advertisement this is subject to receipt of a final Status Determination Statement from the end Client and may be subject to change.
Below are some other jobs we think you might be interested in.
-
Head of Security and Resilience
- Goodman Masson
- London, ENG, GB
21 Jul -
Information Security and Assurance Advisor
- Certain Advantage
- Warwick, ENG, GB
22 Jul -
Information Security and Assurance Advisor
- Certain Advantage
- Leek Wootton, ENG, GB
20 Jul -
Information Security Officer
- KennedyPearce Consulting
- London, ENG, GB
21 Jul -
Information Security & Cyber Security Manager
- Remote Recruit Services Limited
- London, ENG, GB
21 Jul -
Information Security Architect
- Technology Consulting Inc
- Frankfort, KY, US
22 Jul -
Head of Information Security & IT Risk
- Harvey Nash
- London, ENG, GB
21 Jul -
Data Resilience Technical Consultant
- Searchability (UK) Ltd
- Manchester, ENG, GB
22 Jul -
Information Security Manager
- Yolk Recruitment Limited
- Briton Ferry, WLS, GB
21 Jul -
VP Information Security
- GXO Logistics
- Northampton, ENG, GB
21 Jul -
Chief Information Security Officer
- Totara
- Greater London, ENG, GB
21 Jul -
Sr Analyst, Information Security - (Offensive Security)
- Lowe's
- Mooresville, NC, US
22 Jul -
Information Security Manager
- Base One Technology
- Arlington, VA, US
20 Jul -
Chief Information Security Officer
- Man Group
- City of London, ENG, GB
20 Jul -
Head of Information Security
- Limelight Health
- Greater London, ENG, GB
20 Jul -
Head of Information Security
- Moneybox
- Greater London, ENG, GB
20 Jul -
Engineer, Information Security (IAM/Cloud Security)
- Lowe's
- Charlotte, NC, US
22 Jul -
Chief Information Security Officer
- Uline
- Pleasant Prairie, WI, US
20 Jul -
Information System Security Engineer
- MANTECH
- Virginia Beach, VA, US
20 Jul -
Information System Security Engineer
- NAS
- Woodbridge, VA, US
20 Jul

