Senior Information Security Consultant - South Africa (SMB)
Location: South Africa (Remote)
Salary: R780 000 - R900 000 per annum (DOE)
About Cognisys
At Cognisys, we help organisations build confidence in their cyber security, governance and compliance. Through our specialist teams, we provide Penetration Testing, Governance, Risk & Compliance (GRC) consultancy and Managed Security Services that enable our clients to operate securely and confidently.
Our people are trusted advisors who work in partnership with clients to solve real business challenges. We pride ourselves on delivering pragmatic, commercially focused advice that creates lasting value, underpinned by our values of Together, Ownership, Momentum and Excellence.
As we continue to grow, we're looking for an experienced Senior Information Security Consultant to join our expanding GRC team.
The Opportunity
This is a client-facing consultancy role where you'll lead the delivery of Governance, Risk & Compliance engagements for a diverse portfolio of organisations across multiple industries.
You'll act as a trusted advisor, helping clients strengthen their security posture, navigate complex compliance requirements and build practical security programmes that support their business objectives.
This is a fast-paced consulting environment where you'll typically manage multiple client engagements simultaneously, balancing competing priorities while ensuring every client receives an exceptional experience. No two days are the same, so we're looking for someone who enjoys variety, thrives in a customer-facing environment and is comfortable switching between multiple projects, industries and security frameworks.
Alongside delivering high-quality consultancy services, you'll mentor junior consultants, contribute to the continuous improvement of our GRC practice and support the ongoing growth of Cognisys' consulting capability.
What You'll Be Doing
Client Consulting & Delivery
Lead and deliver multiple concurrent GRC consultancy engagements across a varied client portfolio.
Act as the primary point of contact for assigned clients, building trusted relationships throughout the engagement lifecycle.
Deliver security and compliance programmes aligned to frameworks including ISO 27001, SOC 2, NIST and other recognised standards.
Conduct security maturity assessments, gap analyses and governance reviews.
Develop practical remediation roadmaps that balance security, compliance and commercial realities.
Support organisations through certification readiness, external audits and ongoing compliance programmes.
Facilitate workshops, risk assessments and stakeholder meetings with technical and non-technical audiences.
Produce high-quality reports, recommendations and client deliverables.
Security Advisory
Provide pragmatic advice on information security governance, risk management and compliance.
Translate complex regulatory and framework requirements into practical, business-focused solutions.
Design and review policies, standards, procedures, risk registers and governance documentation.
Help clients embed security and compliance into day-to-day business operations.
Provide guidance on security best practices and continuous improvement initiatives.
Managing Multiple Client Engagements
Successfully manage a portfolio of concurrent client engagements at different stages of delivery.
Balance multiple priorities while maintaining exceptional quality and customer service.
Proactively identify risks, remove blockers and keep engagements progressing.
Work collaboratively with Project Managers, Information Security Auditors and wider GRC Consultants to ensure successful delivery.
Ensure engagements are delivered on time, within scope and to Cognisys' high professional standards.
Team Development & Continuous Improvement
Mentor and support junior consultants, helping develop their consulting and technical capability.
Review work produced by junior team members, providing coaching and constructive feedback.
Contribute to improving internal playbooks, methodologies, templates and delivery processes.
Share knowledge and best practice across the wider GRC team.
Support pre-sales activities where required, including discovery sessions, solution design and proposal input.
About You
We're looking for someone who combines strong technical knowledge with excellent consultancy, stakeholder management and organisational skills.
You'll enjoy working in a fast-paced consulting environment, managing multiple client engagements while building trusted relationships and delivering exceptional outcomes.
Essential
5+ years' experience within Information Security, Governance, Risk & Compliance or Cyber Security Consulting.
Experience delivering client-facing GRC consultancy engagements.
Strong knowledge of one or more recognised frameworks such as ISO 27001, SOC 2, NIST or similar.
Experience conducting security assessments, gap analyses and compliance programmes.
Excellent stakeholder management skills with the ability to engage confidently at all organisational levels.
Strong written communication skills with experience producing high-quality client documentation.
Experience mentoring or supporting junior team members.
Excellent organisational skills with the ability to successfully manage multiple concurrent client engagements.
A pragmatic, commercially minded and solution-focused approach to consulting.
Desirable
Lead Implementer or Lead Auditor certifications.
Experience within a consultancy or professional services environment.
Knowledge of additional frameworks including ISO 42001, ISO 22301 or PCI DSS.
Experience supporting pre-sales activities and client workshops.
What Success Looks Like
Success in this role is about far more than delivering security assessments, it's about becoming a trusted advisor to your clients while helping shape the continued growth of our GRC practice.
You'll be successful if you:
Successfully manage a portfolio of multiple concurrent client engagements, consistently delivering projects on time and to a high standard.
Build trusted, long-term relationships with clients by providing pragmatic, commercially focused security advice.
Deliver high-quality consultancy engagements that help organisations strengthen their security posture and achieve their compliance objectives.
Balance competing priorities while maintaining exceptional customer service across every engagement.
Produce clear, practical and professional client deliverables that create measurable value.
Proactively identify risks, remove blockers and maintain momentum across your client portfolio.
Support and mentor junior consultants, contributing to a collaborative, high-performing team culture.
Continuously improve our delivery methodologies, playbooks and consulting practices while contributing to the ongoing growth of Cognisys' GRC capability.
What We Offer:
Annual Leave: 25 days per year plus 12 South African public holidays.
Additional Leave: 1 day of paid leave for your Birthday.
Health & Wellbeing: Individual healthcare insurance plan and access to an employee mental health and wellbeing platform.
Professional Development: £2,000 annual training budget to support your continued learning and career growth.
Referral Bonus: help to grow our team and earn up to £2,000 per successful referral.
Why Join Us?
At Cognisys, you will be part of a collaborative and innovative team that values your input and shares support. You'll have the opportunity to work on challenging projects that make a real impact for our clients. We'd love to hear from you if you want to challenge, lead and innovate! We're not just about the work; we're about the people. Join a team where innovation is celebrated, and your contributions are valued. We foster a collaborative environment where fresh ideas thrive, and professional growth is encouraged.
Applications
We’re always happy to help with questions, but to keep our process fair for everyone, we’re unable to accept applications via email—please apply directly through the job advert page.
Please feel free to reach out to Andrea, our Senior Recruiter, if you would like any further information, to discuss accessibility requirements, or if you require this information provided in an alternative format – andrea.smith@cognisys.group
We welcome applications from candidates from a range of diverse backgrounds and can make various reasonable adjustments to consider individual needs.
NO AGENCIES PLEASE
- Department
- Governance, Risk and Compliance (GRC)
- Role
- Senior Information Security Consultant
- Locations
- South Africa
- Remote status
- Fully Remote