Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Cyber Security Consultant - GRC image - Rise Careers
Job details

Cyber Security Consultant - GRC

Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving transformational change within our clients.  We use proven technology, specialist teams and domain expertise to build solid technical foundations across platforms, data, and business applications.  We have a passion for using technology to solve business problems, working in partnership with our clients to help in achieving their goals.

 

About the role:

  • Risk Assessment: Assist in identifying, assessing, and prioritising risks across the organisation. Conduct risk assessments to evaluate the likelihood and potential impact of risks on business operations and objectives.
  • Compliance Monitoring: Monitor regulatory developments and changes in laws, regulations, and industry standards. Assess the organisation's compliance with applicable regulations, standards, and internal policies.
  • Resilience Planning: Support the Senior Resilience BCP/DR Advisor in the Development and maintenance of IT resilience and business continuity plans to ensure the organisation's ability to respond to and recover from IT disruptions.
  • Incident Response and Management: Provide support in DR related incident response activities, including investigating IT security incidents, breaches, and disruptions.
  • Issue Identification: Identify and document control deficiencies, compliance gaps, and areas for improvement. Collaborate with stakeholders to develop actionable recommendations and corrective action plans to address identified issues.
  • Documentation and Reporting: Maintain accurate documentation of risk assessments, compliance reviews, control testing activities, and remediation efforts. Prepare regular reports for management and stakeholders on the status of risk, compliance, and control activities.
  • Policy and Procedure Development: Assist in the development and maintenance of risk management, compliance, and control-related policies, procedures, and guidelines. Ensure alignment with regulatory requirements and industry best practices in alignment with the Global IS Governance Lead.
  • Vendor Risk Management Support: Assist in assessing and managing risks associated with third-party vendors and service providers. Evaluate vendor controls and adherence to contractual obligations.
  • Continuous Improvement: Identify opportunities for enhancing risk management, compliance, and control processes. Recommend and implement improvements to strengthen the organisation's risk and control environment.
  • Project Work: Contribute to project activities as required to ensure GRC requirements are understood and addressed. Roles and Responsibilities: Areas of Accountability, Responsibility and Competence Level:
  • Works with the Global Risk & Compliance Senior Manager to support IS in the delivery of governance, compliance, and risk activities, whilst supporting the Integration project.
  • Supports the execution of the security, audit, and compliance activities
  • Supports the Global Risk & Compliance Senior Manager by ensuring the successful delivery of initiatives and projects within the Risk and Compliance environment.
  • Supports the Global Risk & Compliance Senior Manager in any required activities which support improvements in assurance, compliance, and audit activities.
  • Addresses findings from identified risks or audits
  • Ensures the ISMS contains an accurate record of risks, events, and issues
  • Supports the internal and external audit investigations
  • Ensures that the audit tests, self-certifications, and audit reviews are relevant, consistent, and conducted in accordance with professionally accepted auditing standards
  • Works with minimal supervision, using clearly defined processes and procedure.
  • Facilitates the use of performance metrics to improve output
  • May be required to provide out of hours support via an on-call rota

Here are the key skills and experience relevant to this role:

  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate compliance and risk related concepts to technical and nontechnical audiences
  • Substantial relevant experience in control management for governance, compliance, IT audits, IS assurance and risk management programmes
  • CISA, CISM or equivalent preferred
  • BSc or equivalent qualification in IT based degree preferred
  • Proven ability to communicate with technical teams to elicit information and requirements
  • Understanding of regulatory requirements, including cross-industry regulations (e.g., GDPR, Data Protection Act) and industry-specific regulations
  • Skilled in implementing compliance and control frameworks
  • Proficient in IT governance and quality standards
  • Knowledge of common information security management frameworks, such as ISO/IEC 27001, ITIL, COBIT as well as those from NIST, including 800-53 and Cybersecurity Framework
  • Excellent stakeholder management skills
  • High level of personal integrity, as well as the ability to professionally handle confidential matters and show an appropriate level of judgment and maturity
  • Knowledge of OneTrust risk management toolset or similar preferred

At Sword, our core values and culture are based on caring about our people, investing in training and career development, and building inclusive teams where we are all encouraged to contribute to achieve success.  

We offer comprehensive benefits designed to support your professional development and enhance your overall quality of life. 

In addition to a Competitive Salary, here's what you can expect as part of our benefits package: 

Personalised Career Development: We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth. 

Flexible working: Flexible work arrangements to support your work-life balance.  We can’t promise to always be able to meet every request, however, are keen to discuss your individual preferences to make it work where we can. 

A Fantastic Benefits Package: This includes generous annual leave allowance, enhanced family friendly benefits, pension scheme, access to private health, well-being, and insurance schemes.

At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don’t tick all the boxes but feel you have some of the relevant skills and experience we’re looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex, or sexual orientation. Your perspective and potential are important to us. 

If we can do anything to help make the hiring process more accessible, please let our talent acquisition team know when you apply so we can support any adjustments. 

Average salary estimate

$80000 / YEARLY (est.)
min
max
$70000K
$90000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cyber Security Consultant - GRC, Sword Group

Join Sword as a Cyber Security Consultant - GRC and be part of a leading provider of business technology solutions across diverse sectors including Energy, Public, and Finance. At Sword, we’re passionate about using technology to tackle business challenges and drive transformative changes. In this role, you’ll help identify and prioritize risks across the organization, ensuring compliance with regulatory standards while collaborating with various stakeholders. You'll also play a pivotal role in documenting and monitoring compliance gaps and developing actionable recommendations to improve our risk management frameworks. With a focus on resilience planning and incident management, you'll assist our Senior Resilience BCP/DR Advisor in vital business continuity initiatives. Additionally, contributing to the development of policies and procedures that align with industry best practices will be part of your day-to-day. We actively encourage an environment of continuous improvement, making this an exciting role for those who are eager to enhance their skills in cyber security. By working closely with the Global Risk & Compliance Senior Manager, you will support governance, compliance, and risk activities while engaging in various project work. Sword values personal and professional growth, offering a comprehensive benefits package and a culture that prioritizes flexibility, inclusivity, and career development. Come be a part of our team, where your expertise will make a real difference in the confidence of our clients' business operations.

Frequently Asked Questions (FAQs) for Cyber Security Consultant - GRC Role at Sword Group
What are the main responsibilities of a Cyber Security Consultant - GRC at Sword?

As a Cyber Security Consultant - GRC at Sword, your key responsibilities include conducting risk assessments to identify and prioritize risks, monitoring compliance with regulations and internal policies, and supporting business continuity planning. You’ll investigate IT security incidents and breaches while drafting documentation for compliance reviews and providing actionable recommendations to address control deficiencies.

Join Rise to see the full answer
What qualifications are required to become a Cyber Security Consultant - GRC at Sword?

To qualify for the Cyber Security Consultant - GRC role at Sword, candidates should have substantial experience in control management, IT audits, and risk management programs. A preferred qualification would be a BSc in an IT-based degree, alongside certifications such as CISA or CISM. Familiarity with regulations like GDPR and knowledge of information security management frameworks, such as ISO/IEC 27001, is also highly valued.

Join Rise to see the full answer
What skills are essential for a Cyber Security Consultant - GRC at Sword?

Essential skills for the Cyber Security Consultant - GRC position at Sword include excellent written and verbal communication abilities, strong interpersonal skills, and a comprehensive understanding of compliance and risk management principles. Stakeholder management and the ability to communicate complex concepts to both technical and non-technical audiences are also crucial for success in this role.

Join Rise to see the full answer
How does Sword support the career development of a Cyber Security Consultant - GRC?

Sword is committed to the professional growth of its Cyber Security Consultant - GRC employees by creating personalized career development plans aligned with individual goals. The company provides a range of learning and development opportunities in a culture that encourages growth through flexible working arrangements and a fantastic benefits package.

Join Rise to see the full answer
What is the work culture like for a Cyber Security Consultant - GRC at Sword?

Sword fosters a diverse and inclusive workplace, encouraging collaboration and contribution from all team members. The culture is built on caring about people and supporting work-life balance. Cyber Security Consultants - GRC at Sword can expect to work in an environment that values personal integrity and professionalism while providing opportunities for continuous improvement.

Join Rise to see the full answer
Common Interview Questions for Cyber Security Consultant - GRC
Can you explain how you would conduct a risk assessment?

When preparing for an interview for the Cyber Security Consultant - GRC role, you should outline a systematic approach. Start by identifying the assets that need protection, assessing potential threats and vulnerabilities, and evaluating the risks’ impact on the organization. Describe how you prioritize these risks and collaborate with stakeholders to develop mitigation strategies.

Join Rise to see the full answer
How do you stay updated on cybersecurity regulations?

Discuss your methods for staying informed about cybersecurity regulations. Mention resources such as industry publications, regulatory websites, professional organizations, and relevant continuing education courses. Showing that you actively engage with the cybersecurity community can also demonstrate your commitment to ongoing learning.

Join Rise to see the full answer
Describe a time you identified a compliance gap and how you handled it?

Prepare an example that illustrates your problem-solving skills. Briefly explain the context of the compliance gap, the steps you took to investigate and document it, and the recommendations you made for corrective actions. Highlight your collaboration with stakeholders to ensure the implementation of those recommendations.

Join Rise to see the full answer
What frameworks have you implemented for risk management?

In answering this question, share specific frameworks you have experience with, such as ISO/IEC 27001 or NIST Cybersecurity Framework. Discuss how you applied these frameworks in previous roles, focusing on how they improved the organization’s risk management capabilities.

Join Rise to see the full answer
How would you communicate complex IT security issues to non-technical stakeholders?

Illustrate your ability to simplify technical information by explaining concepts in layman's terms. Provide an example where you successfully conveyed complex security concerns to non-technical team members, emphasizing the importance of collaboration and clarity in communication.

Join Rise to see the full answer
What steps do you take when developing and updating policies and procedures?

Explain your systematic approach, including gathering input from relevant stakeholders, aligning with regulatory requirements, and ensuring best practices are integrated into the policies. Mention how you document changes and communicate revisions to affected parties.

Join Rise to see the full answer
What strategies do you employ for effective vendor risk management?

Discuss how you assess vendor controls, establish performance metrics, and monitor compliance with contractual obligations. Emphasize the importance of ongoing assessments and building strong communication lines with vendors to manage risks effectively.

Join Rise to see the full answer
How do you prioritize your tasks when managing multiple projects?

Share your strategies for prioritization, such as using project management tools, keeping track of deadlines, and identifying tasks based on their urgency and impact on the organization. Explain how you communicate with stakeholders to manage expectations.

Join Rise to see the full answer
Can you share your experience with incident response protocols?

When discussing this, highlight specific incidents where you've been involved in response activities. Outline your understanding of the key steps in an incident response plan, including identification, containment, mitigation, and lessons learned, while stressing the importance of a collaborative approach.

Join Rise to see the full answer
What do you believe is the biggest challenge facing cybersecurity today?

Discuss current trends such as ransomware attacks, insider threats, or the challenges posed by remote work. Explain how these challenges impact organizations and the importance of proactive risk management and constant vigilance in maintaining cybersecurity.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Sword Group Remote No location specified
Posted 11 days ago

Sword is looking for a Technical Data Architect to deliver scalable data solutions using Microsoft Fabric within diverse sectors.

Photo of the Rise User
Sword Group Remote No location specified
Posted 11 days ago

Join Sword as an IT Change Manager and lead transformative change management initiatives across multiple sectors with a focus on enhancing user adoption and process improvements.

Photo of the Rise User
Posted 13 days ago

Join National General as an IT Asset and Expense Consultant in a remote role where you can shape the future of IT asset management.

Posted 9 days ago

Join our team as an AWS Consultant specializing in API development, and contribute to creating secure and efficient solutions within the AWS ecosystem.

Photo of the Rise User
Posted 11 days ago

Join Avalon Healthcare Solutions as a Technical Integration Lead and play a pivotal role in enhancing healthcare delivery through innovative IT solutions.

Photo of the Rise User
Natixis Remote Rua de Santos Pousada, Porto, Portugal
Posted 11 days ago

Join Natixis in Portugal as a C# .NET Developer and contribute to innovative digital banking solutions in a dynamic team.

Photo of the Rise User

Join Lockheed Martin as an Info Systems Analyst to drive IT support within military Space Programs in Washington, DC.

Posted 10 days ago

Join a leading team as a Senior SQL Server Database Administrator, providing critical support and maintaining high levels of database performance and reliability.

Join Allied Consultants as an MS SQL Database Administrator to support and manage integrated database environments.

Photo of the Rise User
Posted 2 days ago

Join Silverton Mortgage as an IT Specialist, where you'll deliver top-notch tech support in a dynamic and inclusive environment.

Sword has 2,200+ (after disposal) IT/Digital & Software specialists present over 5 continents to accompany you in the growth of your organization in the digital age. As a leader in technological and digital transformation, Sword has a solid reputa...

44 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 9, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!