ISO 27001 Consultant & Auditor – Defence Cyber Certification
Full DCC Assessor Training Provided
Location: Hybrid working, Cheltenham, Gloucestershire
Job type: Full\-time
Work authorisation: United Kingdom required
Build on your ISO 27001 experience and become a Defence Cyber Certification specialist
Are you an experienced ISO 27001 Lead Auditor or Lead Implementer looking to broaden your expertise and move into defence cyber security assurance?
KEYSIGMA is looking for an experienced cyber security consultant or auditor to join our growing Defence Cyber Certification (DCC) team.
You do not need to be a qualified DCC assessor or have previous DCC experience to apply.
Defence Cyber Certification is a new scheme, and we recognise that there are currently relatively few experienced professionals who already hold the relevant DCC assessor qualifications.
Instead, we are looking for someone with a strong foundation in ISO 27001, at least three years’ relevant experience in cyber security consultancy, implementation and/or auditing, and the professional judgement and enthusiasm to develop into a specialist DCC consultant and assessor.
KEYSIGMA will fund your DCC assessor training and support you through the qualification process.
For the right person, this is an opportunity to take an established ISO 27001 skill set and apply it to a developing area of defence cyber assurance, building specialist knowledge while working alongside experienced cyber security professionals.
About KEYSIGMA
KEYSIGMA is a specialist cyber security consultancy and certification body based in Cheltenham.
We are proud to be one of the first Defence Cyber Certification (DCC) Level 3 Certification Bodies, placing us at the forefront of this new and important assurance scheme.
Defence Cyber Certification is a major strategic focus for KEYSIGMA. We have ambitious plans to build one of the strongest DCC teams in the market, with the long\-term aim of becoming the largest DCC Certification Body in the UK.
We support organisations across both DCC implementation consultancy and independent certification, helping clients understand their obligations, identify gaps, implement proportionate controls and demonstrate compliance through robust, evidence\-based assessment.
You will join a growing specialist team and be led by our Head of Department, a Chartered Cyber Security Professional, working alongside experienced cyber security consultants and DCC assessors.
We are looking for an experienced professional who can bring strong ISO 27001, audit and consultancy experience to the team while developing the specialist DCC knowledge needed to become a highly capable DCC consultant and assessor.
This is an opportunity to join the business at an early stage in the growth of the DCC scheme and play a meaningful role in shaping our delivery approach, developing our capability and helping build a market\-leading Defence Cyber Certification practice.
The Role
This is a combined consultancy and assurance role.
You will work with clients that need help understanding and implementing the requirements of Defence Cyber Certification, as well as developing the capability to undertake independent DCC assessments once you have completed the required training and qualification.
Your work will therefore span two complementary areas:
DCC Implementation Consultancy
You will help organisations understand what is required of them and put appropriate controls, processes and evidence in place.
This will include:
· DCC gap assessments and readiness reviews.
· Identifying gaps and developing proportionate remediation plans.
· Supporting implementation of controls, policies and evidence.
· Supporting risk, governance and resilience activities.
· Running client workshops and preparing organisations for assessment.
DCC Audit and Certification
Following DCC assessor training and qualification, you will also undertake independent assessments, including:
· Planning and delivering DCC assessments.
· Reviewing scope, controls and supporting evidence.
· Assessing compliance and documenting findings.
· Producing clear assessment reports.
· Managing assessments impartially and supporting certification decisions.
About You
We are looking for an experienced cyber security professional with a strong background in ISO 27001 consultancy, implementation or auditing.
You may currently work as an:
· ISO 27001 Consultant
· ISO 27001 Lead Auditor
· ISO 27001 Lead Implementer
· Cyber Security Consultant
· GRC Consultant
· Information Security Consultant
· Cyber Assurance Consultant
What matters is that you already have a strong professional foundation that can be developed into DCC expertise.
Essential Experience and Qualifications
You will need:
· An ISO 27001 Lead Auditor or ISO 27001 Lead Implementer qualification.
· At least three years’ relevant professional experience in cyber security consultancy, implementation, audit, assurance or a closely related discipline.
· The ability to identify gaps and turn findings into practical and proportionate actions.
· Strong consultancy and client\-facing skills.
· Strong written communication and report\-writing skills.
· A genuine interest in developing specialist knowledge of Defence Cyber Certification and defence cyber assurance.
You may have spent more of your career implementing ISO 27001, or you may have a stronger auditing background. We are interested in people who have the underlying knowledge, practical experience and professional capability to develop across both consultancy and assurance work.
Desirable Experience
The following would be useful but is not essential:
· Experience working within the defence or defence supply\-chain sector.
· Experience supporting organisations through external certification.
· Broader GRC, cyber assurance or compliance experience.
· Additional professional qualifications such as CISSP, CISM, CISMP or similar.
Why Join KEYSIGMA?
· Funded DCC assessor training and the opportunity to develop specialist expertise in a new and growing assurance scheme.
· Join one of the first DCC Level 3 Certification Bodies and help shape a rapidly growing area of the business.
· Work directly with experienced DCC assessors and senior cyber security professionals.
· Gain varied experience across implementation consultancy and independent assurance.
· Take meaningful ownership of client work and play a visible role in building a market\-leading DCC practice.
Benefits
· Professional development and funded training
· Hybrid working
· Flexitime
· Company pension
· Free fitness classes
· On\-site parking
· Casual dress
Equality, Diversity and Inclusion
KEYSIGMA is committed to providing an inclusive working environment and recruiting people based on their skills, experience, capability and potential.
We welcome applications from people of all backgrounds and recognise that different professional and personal experiences strengthen our team.
Disability and Accessibility
KEYSIGMA is a Disability Confident Employer and is committed to attracting, recruiting and retaining disabled people and those with long\-term health conditions.
We welcome applications from disabled candidates, neurodivergent people and those with long\-term health conditions, and are committed to providing an accessible and inclusive recruitment process.
Our recruitment process may include an initial CV review, interview, and role\-related discussion or assessment. We will consider reasonable adjustments at each stage, which may include alternative formats, additional time, adjusted interview arrangements, or other changes to help candidates demonstrate their suitability for the role.
If you would like to be considered under the Disability Confident interview commitment, please let us know when applying and ensure your CV or covering note clearly demonstrates how you meet the minimum essential criteria for the role.
If you require any other adjustments during the recruitment process, please let us know and we will work with you to understand what support would enable you to participate fully.
Armed Forces Community
KEYSIGMA is a signatory to the Armed Forces Covenant and has been recognised with a Bronze Award under the Defence Employer Recognition Scheme.
We actively welcome applications from members of the Armed Forces community, including:
· Service leavers and veterans
· Reservists
· Military spouses and partners
· Members of the wider Armed Forces community
We recognise the significant transferable skills that can come from military service, including leadership, risk management, assurance, problem solving, technical expertise and the ability to operate effectively in challenging environments.
A previous military or defence background is not required for this position.
Working Arrangements
This is a hybrid role based from our Cheltenham office.
You will have flexibility to work remotely but must be able to attend the office when required and travel to client locations where an assignment requires on\-site work.
Security Screening
Due to the nature of our work within the defence sector, the successful candidate will be expected to attain and maintain a minimum of Security Check (SC) clearance.
Applicants must therefore be willing and able to undergo the required UK security vetting. This may include checks relating to identity, employment history, residency, criminal record, financial circumstances and other relevant background information.
Appointment and continued suitability for certain duties may be dependent on obtaining and maintaining the required level of security clearance.
Work Authorisation
Applicants must already have the unrestricted right to work in the United Kingdom. Unfortunately, this vacancy is not eligible for visa sponsorship.
To Apply
Please send your CV together with a short covering note expla
This listing is from Indeed. View original listing ↗