Information Security Consultant (SMB) - Philippines
Location: Philippines (Remote)
Salary: ₱1,450,000.00 - ₱1,650,000.00 (DOE)
About Cognisys
At Cognisys, we help organisations strengthen their security posture through expert Governance, Risk & Compliance (GRC) consulting, Penetration Testing and Managed Security Services.
Our consultants work alongside clients to solve complex security and compliance challenges, providing practical, business-focused advice that helps organisations build resilient security programmes and achieve regulatory compliance.
As we continue to grow our GRC Consulting practice, we're looking for an Information Security Consultant to join our expanding team.
The Opportunity
Our GRC Consulting team partners with organisations at every stage of their security journey — from building foundational security programmes to operating mature, scalable compliance functions.
As an Information Security Consultant, you'll work with a diverse range of clients and industries, helping them strengthen their governance, risk and compliance capabilities through practical, commercially focused security advice.
This is a client-facing, delivery-focused role suited to a security and compliance professional who is confident supporting consulting engagements and contributing high-quality advisory services.
You'll help translate regulatory and framework requirements into practical, business-aligned solutions and work collaboratively with senior consultants and client stakeholders to drive measurable improvements in governance, risk and compliance.
This role is ideal for someone with strong foundational GRC knowledge, growing consulting experience and a desire to develop into a trusted security advisor.
What You'll Be Doing
Client Consulting & Delivery
Lead and support the delivery of GRC consulting engagements across multiple clients and sectors.
Contribute to security posture assessments, gap analyses and maturity reviews.
Assist in the design and implementation of GRC programmes aligned to frameworks such as ISO 27001, SOC 2, NIST and related standards.
Support clients through audit preparation, certification processes and external assessments.
Develop remediation plans and assist clients in tracking progress against agreed actions.
Participate in and lead client workshops, risk assessments and stakeholder sessions.
Build trusted relationships with clients and provide practical, business-focused security advice.
Manage multiple client engagements while ensuring projects are delivered on time and to a high standard.
Governance, Risk & Compliance
Support clients in developing and implementing governance, risk and compliance programmes.
Interpret security standards and regulatory requirements and translate them into practical recommendations.
Conduct information security risk assessments and maintain supporting documentation.
Contribute to the design and documentation of security controls and operating models.
Help clients embed compliance activities into their operational and technical processes.
Develop and maintain governance documentation, including:
Information Security Policies
Standards and Procedures
Risk Registers
Control Frameworks
Risk Assessments
Governance documentation
Advisory & Technical Contribution
Provide practical advice on security and compliance requirements.
Support the development and implementation of security controls aligned to business and regulatory requirements.
Work collaboratively with senior consultants to deliver high-quality client outcomes.
Help clients understand how security and compliance requirements can be applied effectively within their organisation.
Quality & Continuous Improvement
Produce high-quality client deliverables with clarity, accuracy and consistency.
Follow established Cognisys methodologies, templates and internal quality standards.
Proactively identify areas for improvement within client engagements.
Contribute to the development and improvement of internal methodologies, templates and ways of working.
Manage assigned tasks effectively to meet deadlines and scope expectations.
What Success Looks Like
Success in this role is about developing into a trusted security advisor who delivers high-quality consulting engagements and creates meaningful improvements for our clients.
You will:
Successfully contribute to and deliver multiple GRC consulting engagements across a range of clients and industries.
Build strong and trusted relationships with clients by providing practical, commercially focused security and compliance advice.
Demonstrate confidence working across recognised frameworks such as ISO 27001, SOC 2 and NIST.
Produce clear, accurate and professional client deliverables, including policies, procedures, risk assessments, control frameworks and governance documentation.
Successfully support clients through assessments, audits, certification activities and remediation programmes.
Effectively manage multiple client engagements and competing priorities while maintaining strong communication, organisation and attention to detail.
Demonstrate the ability to translate complex security and compliance requirements into practical recommendations that clients can implement.
Work collaboratively with senior consultants and internal teams to deliver excellent client outcomes.
Contribute ideas and improvements to Cognisys' GRC methodologies, processes and ways of working.
Continue developing your consulting expertise and establish yourself as a trusted Information Security Consultant within the Cognisys team.
About You
We're looking for someone who enjoys solving problems, building trusted client relationships and helping organisations strengthen their security posture.
You'll be naturally organised, proactive and comfortable managing multiple priorities while working across a variety of client engagements.
Most importantly, you'll enjoy translating complex security and compliance requirements into practical advice that creates real value for clients.
Essential Skills & Experience
2–5 years' experience in security, risk, compliance or GRC-related roles.
Practical experience working with at least one recognised security framework, such as:
ISO 27001
SOC 2
NIST
Or a similar recognised framework.
Experience supporting compliance, assurance or certification initiatives, either internally or in a client-facing environment.
Strong written and verbal communication skills.
Excellent stakeholder management and relationship-building skills.
Strong organisational skills with the ability to manage multiple priorities and engagements.
Analytical mindset with a pragmatic, solution-focused approach to problem solving.
Comfortable working with both technical and non-technical stakeholders.
Strong attention to detail and commitment to producing high-quality client deliverables.
Desirable Skills & Experience
Previous consulting experience within a client-facing professional services environment.
Experience delivering ISO 27001 implementation or certification projects.
Exposure to SOC 2, NIST, PCI DSS, Cyber Essentials Plus or similar security frameworks.
Experience conducting information security risk assessments and governance reviews.
Experience using GRC platforms such as Vanta or similar tools.
Experience working with international clients or distributed teams.
Certifications
The following certifications are highly regarded:
SO/IEC 27001 Lead Implementer
ISO/IEC 27001 Lead Auditor
CISSP
CISM
CRISC
Security+ or equivalent security certifications
Certifications are valued, but we're equally interested in practical experience, problem-solving ability and the potential to develop.
Why Join Us?
At Cognisys, you will be part of a collaborative and innovative team that values your input and shares support. You'll have the opportunity to work on challenging projects that make a real impact for our clients. We'd love to hear from you if you want to challenge, lead and innovate! We're not just about the work; we're about the people. Join a team where innovation is celebrated, and your contributions are valued. We foster a collaborative environment where fresh ideas thrive, and professional growth is encouraged.
What we Offer:
Annual Leave: 22 days PTO per year plus 12 public and 8 special Filipino holidays.
Additional Leave: 1 day of paid leave for your Birthday.
Additional Compensation: 13th Month Salary - 1/2 of monthly salary paid annually in December.
Health & Wellbeing: Individual healthcare insurance plan and access to an employee mental health and wellbeing platform.
Professional Development: £2,000 annual training budget to support your continued learning and career growth.
Referral Bonus: help to grow our team and earn up to £2,000 per successful referral.
Applications
We’re always happy to help with questions, but to keep our process fair for everyone, we’re unable to accept applications via email—please apply directly through the job advert page.
Please feel free to reach out to Andrea, our Talent Acquisition Lead, if you would like any further information, to discuss accessibility requirements, or if you require this information provided in an alternative format – andrea.smith@cognisys.co.uk
We welcome applications from candidates from a range of diverse backgrounds and can make various reasonable adjustments to consider individual needs.
- Department
- Governance, Risk and Compliance (GRC)
- Locations
- Philippines (remote)
- Remote status
- Fully Remote