Information Security Consultant
Job Description
Location: Newcastle (Hybrid)Salary: Up to £80,000 per annum + benefits
The Opportunity\nWe are seeking an experienced and proactive Information Security Consultant to join our client's team. This is a hybrid position based in Newcastle, offering the opportunity to work with a diverse portfolio of clients, helping them strengthen their security posture and manage risk in an evolving threat landscape.
\nYou will play a key role in delivering security advisory services, conducting assessments, and supporting organisations in aligning with industry standards and best practices. The role will also involve supporting clients with modern security challenges, including threat modelling, secure-by-design practices and emerging AI security considerations.
Key Responsibilities\n- \n
- \n
Provide expert guidance on information security strategies, frameworks and best practices.
\n - \n
Conduct security risk assessments, gap analyses and audits.
\n - \n
Support clients in achieving and maintaining compliance with standards and regulations such as ISO 27001, NIST and GDPR.
\n - \n
Develop and review security policies, procedures and documentation.
\n - \n
Perform vulnerability assessments and coordinate remediation efforts.
\n - \n
Deliver threat modelling workshops and support secure solution design activities.
\n - \n
Deliver security awareness training and workshops.
\n - \n
Assist with incident response planning and post-incident reviews.
\n - \n
Collaborate with technical and non-technical stakeholders to embed security into business processes.
\n
- \n
- \n
Proven experience working as an Information Security Consultant or in a similar role.
\n - \n
Strong understanding of security frameworks including ISO 27001, NIST and CIS Controls.
\n - \n
Experience conducting threat modelling exercises and risk-based security assessments.
\n - \n
Strong client-facing and stakeholder management skills.
\n - \n
Experience working within a consultancy or advisory environment.
\n
- \n
- \n
Professional certifications such as CISSP, CISM, CRISC or ISO 27001 Lead Implementer/Auditor.
\n - \n
Experience in consultancy or client-facing roles.
\n - \n
Exposure to penetration testing or security engineering.
\n - \n
Knowledge of secure software development practices and DevSecOps.
\n - \n
Understanding of emerging security challenges, including AI security.
\n
