QSA Security Consultant - UK Wide

Job Type:
Cyber Security
Job reference:
7 months ago

GRC Consultant - QSA

The role

We are looking for a consultant to join our GRC team in the UK. This role is home-based, with travel to client sites

You'll be part of a team delivering security consultancy in a client-facing role, with a particular focus on:

  • PCI DSS consultancy and assessments
  • Security reviews against standards or guidelines such as the NCSC 10 Steps to Cyber Security and NIST CSF
  • ISO 27001 gap analyses
  • Helping our clients to implement Information Security Management Systems and achieve and maintain ISO27001 certification
  • Conducting risk assessments
  • Creating or supporting third-party risk management and audit programmes

Essential Skills:

  • Be a current QSA who has completed multiple on-site PCI DSS assessments, and be able to demonstrate a mature understanding of complex PCI DSS environments, and an ability to consult as well as assess
  • Have experience with ISO 27001, including implementing an ISMS and achieving certification
  • Have experience working with the NIST CSF
  • A good understanding of core concepts and technologies. For example, networking, Windows and Linux operating systems, and security technologies such as antimalware, IDS/IPS, etc. You do not need hands-on experience with these technologies or to have worked in an operational role
  • Be experienced working as a consultant in a client-facing role, leading delivery. You'll be friendly and approachable and able to work well with our clients
  • Ability to work in a structured and methodical manner, with support to manage your own time with a focus on quality work

Your primary role will be to deliver PCI DSS consultancy and assessment activities to our clients as part of an established and experienced team of consultants. It's not all PCI DSS, though, and you'll be involved in other areas as listed above and have opportunities to scope and deliver more bespoke engagements.


  • This role is home-based, with an expectation of travel to client sites, primarily in the UK, but with some opportunities for European and international travel; therefore, all candidates must be willing to travel
  • PCI DSS assessment activities require on-site work, but most other work is delivered at least partly from home
  • We can support working from across the UK
  • All applicants will require residence in the UK

What we offer:

We are a people-focused, high-performing, high-trust professional services team. You'll be part of a diverse and growing international group of consultants, and we go out of our way to make sure our consultants feel part of our team. We use technology to ensure we're always communicating with each other and schedule time every week to talk as a team.

The successful candidate will have opportunities to:

  • Make a difference - as clichéd as it sounds, this really is true. We encourage all consultants to challenge norms and empower them to get involved. This might be getting involved with other teams or developing a new service offering - but if you want to do something, we always try to make it happen
  • Get involved - enjoy blogging or public speaking? Our team is committed to getting involved in industry discussions. We make time to attend conferences and get involved in the infosec community
  • Develop their skills - we love learning and ensure we find time for professional development. This isn't just about collecting certifications and attending training courses - gaining and sharing knowledge in new areas is vital. These don't always have to be directly related to your "day job"; in fact, we actively encourage developing knowledge in new and exciting domains

If you're interested in finding out more please click apply for consideration and we will be in contact to discuss in more detail!

Back job search
Back to Search Results