Cognisys logo

Information Security Consultant - USA (Remote)

Salary
$75K–$85K
USD per year
Hiring from
United States
Work type
Remote
Posted
Sep 30, 2026
Is this job info correct?

Location: USA (Remote)

Salary: $75000 - $85000 per annum

About Cognisys

Cognisys is a cybersecurity consultancy specialising in Penetration Testing, GRC Consulting and Managed Security. We work with organisations across 30+ countries, helping them understand their security risks, strengthen their security posture and build practical, sustainable security programmes.

We are a growing team and our consultants have the opportunity to work closely with clients, take ownership of meaningful work and make a visible impact.

The Opportunity

We are looking for a mid-level Information Security Consultant who is a confident communicator to join our GRC Consulting team and work across ongoing advisory, security improvement and specialist client engagements.

This is a consulting role for someone who brings genuine information security or cybersecurity experience and can apply that knowledge to complex client environments.

Rather than focusing primarily on helping clients achieve a particular certification, you will work alongside organisations to understand their security challenges, manage risk and continuously improve their security posture.

Your work may include ongoing security advisory, vCISO-style support, maintenance of existing security programmes, security improvement initiatives and specialist or additional consulting work. You will work with clients that may already have established security programmes and will help them improve, maintain and mature those programmes over time.

This requires more than knowledge of security frameworks. You will need to understand how security works in practice, be comfortable discussing real-world security challenges and use your experience and judgement to help clients determine the right way forward.

You will also need strong consulting skills. Our consultants work closely with client stakeholders, often across different functions and levels of seniority, so the ability to listen, ask good questions, communicate clearly and build trust is essential.

This role would suit someone with hands-on or industry information security experience who is a confident, clear communicator and wants to apply that knowledge in a client-facing consulting environment.

It would also be a great fit for someone keen to learn on the job and build their experience supporting clients with frameworks like NIST SP 800, FedRAMP or CMMC.

What You'll Be Doing

Security Advisory & Consulting

  • Deliver ongoing information security advisory engagements across a range of clients and industries.

  • Provide practical guidance on information security risks, security programmes and improvement priorities.

  • Support clients with vCISO-style advisory services and ongoing security programme development.

  • Assess existing security programmes and identify opportunities to improve their effectiveness, maturity and sustainability.

  • Help clients prioritise security initiatives based on risk, business objectives and available resources.

  • Provide independent thinking and practical recommendations rather than simply applying a predefined framework or checklist.

  • Support specialist information security projects and additional client work where your expertise can add value.

  • Work with clients to understand complex security problems and develop realistic approaches to addressing them.

Security Programme & Risk Management

  • Support the development, maintenance and improvement of information security programmes.

  • Assess security risks, controls, processes and operating practices.

  • Help clients develop and maintain security roadmaps, risk registers, remediation plans and improvement programmes.

  • Advise on security governance, risk management, controls, policies, procedures and operating processes.

  • Identify weaknesses or areas of risk and help clients determine appropriate remediation approaches.

  • Apply relevant frameworks, standards, regulations and industry practices where they add value to the client's security objectives.

  • Support security assurance and compliance activities where required as part of a broader engagement.

  • Use GRC platforms and other security tooling where appropriate.

Client & Stakeholder Advisory

  • Build trusted, long-term relationships with client stakeholders.

  • Work confidently with technical teams, security professionals, operational stakeholders and senior leadership.

  • Understand different stakeholder perspectives and translate security issues into language that is meaningful to the audience.

  • Lead client meetings, workshops and advisory sessions.

  • Ask thoughtful questions, challenge assumptions and help clients think through complex security decisions.

  • Communicate risks, recommendations and trade-offs clearly.

  • Manage expectations and proactively communicate progress, challenges and dependencies.

  • Balance client needs with sound professional judgement.

Engagement Ownership

  • Take ownership of defined client engagements and workstreams.

  • Manage competing priorities across multiple clients and projects.

  • Plan and organise delivery to meet agreed timelines and outcomes.

  • Identify risks and blockers early and take appropriate action.

  • Work independently while knowing when to involve senior consultants or other specialists.

  • Contribute to scoping and shaping additional client work where appropriate.

  • Maintain a high standard of quality across all client deliverables.

Quality & Professional Standards

  • Produce clear, accurate and commercially appropriate client deliverables.

  • Apply Cognisys methodologies and quality standards consistently.

  • Use professional judgement to ensure recommendations are practical, proportionate and aligned to the client's circumstances.

  • Continuously look for ways to improve client delivery and consulting practices.

  • Share knowledge and contribute to the development of the wider GRC consulting team.

About You

  • 3–5 years' experience in information security, cybersecurity, security consulting or a related industry role.

  • Strong practical understanding of information security and cybersecurity principles.

  • Experience working in an operational, technical or industry information security environment.

  • Experience identifying and managing real-world security risks rather than focusing solely on compliance requirements.

  • Experience developing, operating, assessing or improving security programmes.

  • Experience working with security controls, risk management, security processes or security operations.

  • Experience with FedRAMP and the NIST SP 800 series (e.g. NIST SP 800-53 and SP 800-171) would be helpful.

  • Strong client-facing and consulting skills.

  • A confident communicator, with excellent written and verbal skills and the ability to present ideas and recommendations clearly to audiences at all levels.

  • Confident working with technical, operational and senior stakeholders.

  • Strong questioning, listening and relationship-building skills.

  • Ability to understand complex problems and develop practical, commercially sensible solutions.

  • Strong organisational skills and the ability to manage multiple clients, workstreams and competing priorities.

  • Comfortable operating independently and using professional judgement.

  • Consulting experience is highly desirable.

  • Experience with vCISO, security advisory or ongoing security programme support is highly desirable.

  • Experience with GRC platforms such as Vanta is desirable.

What Success Looks Like

Success in this role means becoming a trusted security advisor to your clients, bringing practical industry experience to complex security challenges and helping organisations continuously improve their security posture.

For example:

  • Be a trusted advisor — Clients value your judgement, experience and ability to provide practical advice rather than simply documenting requirements.

  • Bring practical security experience — You understand how security works in real organisations and can connect theory with practical implementation.

  • Think beyond compliance — You understand that frameworks and certifications are only one part of an effective security programme.

  • Understand the bigger picture — You can connect technical security risks with business priorities, operational realities and organisational risk.

  • Solve problems — You don't simply identify gaps; you help clients understand their options and determine a realistic way forward.

  • Build strong relationships — You develop trusted relationships with stakeholders and become someone clients are comfortable seeking advice from.

  • Communicate with impact — You can explain complex security issues clearly to technical teams, business stakeholders and senior leadership.

  • Challenge constructively — You are comfortable questioning assumptions, raising concerns and having difficult but productive conversations with clients.

  • Take ownership — You manage your engagements proactively, anticipate issues and remain accountable for delivery.

  • Manage complexity — You can balance multiple stakeholders, priorities and workstreams while maintaining quality.

  • Use sound judgement — You understand when to act independently and when to involve additional expertise.

  • Continue to grow — You actively develop your technical, commercial and consulting capability.

  • Contribute to the team — You share industry knowledge and experience and help strengthen the wider GRC consulting function.

  • Live the Cognisys values — You demonstrate Together, Ownership, Momentum, and Excellence in how you work with clients and colleagues.

Why Join Us?

At Cognisys, you will be part of a collaborative and innovative team that values your input and shares support. You'll have the opportunity to work on challenging projects that make a real impact for our clients. We'd love to hear from you if you want to challenge, lead and innovate! We're not just about the work; we're about the people. Join a team where innovation is celebrated, and your contributions are valued. We foster a collaborative environment where fresh ideas thrive, and professional growth is encouraged.

What we Offer:

  • Annual Leave: 22 days PTO per year plus 11 American bank holidays.

  • Additional Leave: 1 day of paid leave for your Birthday.

  • Health & Wellbeing: Individual access to a healthcare and life insurance plan and an employee mental health and wellbeing platform.

  • Pension: 2% employer contributions to the Fidelity 401k scheme in accordance with statutory requirements.

  • Professional Development: £2,000 annual training budget to support your continued learning and career growth.

  • Referral Bonus: help to grow our team and earn up to £2,000 per successful referral.

Applications

We’re always happy to help with questions, but to keep our process fair for everyone, we’re unable to accept applications via email—please apply directly through the job advert page.

Please feel free to reach out to Andrea, our Talent Acquisition Lead, if you would like any further information, to discuss accessibility requirements, or if you require this information provided in an alternative format – andrea.smith@cognisys.co.uk

We welcome applications from candidates from a range of diverse backgrounds and can make various reasonable adjustments to consider individual needs.

Similar jobs

Apply for this job