
Senior Information Security Consultant - QSA
- Cambridge
- Permanent
- Full-time
- Deliver high-quality PCI DSS assessments, including Report on Compliance (RoC) production for Merchants and Service Providers
- Lead and deliver a variety of consultancy engagements including ISO 27001 audits and implementations, GDPR assessments, risk assessments, policy development, and vCISO support.
- Act as a trusted advisor to clients, ensuring pragmatic and tailored guidance aligned with regulatory requirements and business needs.
- Mentor junior consultants, providing technical oversight, guidance, and quality assurance on engagements.
- Contribute to the development and delivery of internal training materials and client-facing information security training courses.
- Support the Leadership Team in identifying and developing new business opportunities.
- Lead on the scoping and conversion of new client engagements, contributing to bid writing and client proposals.
- Provide escalation support for complex security queries and technical decision-making.
- Maintain and enhance knowledge of PCI-related standards (e.g., PCI P2PE, PCI PIN) and other emerging areas such as cyber resilience, digital forensics, and incident response.
- Current PCI QSA (Qualified Security Assessor) certification.
- A minimum of 5 years’ experience in an information security consultancy role, including significant experience with PCI DSS and ISO 27001.
- Demonstrable experience in producing high-quality RoC documentation and conducting complex PCI DSS assessments.
- Strong understanding of broader security standards and frameworks, including Cyber Essentials, DPA 2018, GDPR, NIST, and SOX.
- ISO 27001 Lead Auditor or Implementor certification.
- Excellent communication and stakeholder engagement skills with a client-focused approach.
- Proven ability to manage multiple concurrent engagements and operate autonomously.
- Full UK working rights and flexibility to travel both nationally and internationally as required.
- CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) certification.
- Experience with Cyber Essentials Plus assessments, vulnerability assessments, or Cyber Advisor schemes.
- Familiarity or interest in adjacent domains such as PCI P2PE, PCI PIN, automotive security, digital forensics, and penetration testing.
- Training – All team members are offered a number of options in terms of personal development, whether it is technical led, business acumen or methodologies. We want you to grow with us and to help us achieve more
- Private medical cover for you and your spouse/partner, offered via Vitality
- Discretionary bonus based on a blend of personal and company performance
- Holiday – You will receive 25 Days holiday, plus 1 day for Birthday and 1 day for your work anniversary in addition to UK bank holidays
- Electric Vehicle leasing with salary sacrifice
- Contributed Pension Scheme
- Death in service cover
We are sorry but this recruiter does not accept applications from abroad.