ISO 27001 Programme Lead

  • RSM UK
  • Brentwood, Essex
  • 27/07/2026
Full time Information Technology Telecommunications

Job Description

We are searching for an experienced ISO 27001 Programme Lead

Make an Impact at RSM UK

As one of the world's largest networks of Audit, Tax and Consulting firms, RSM delivers big ideas and premium service to help businesses thrive. We are fast-growing with big ambitions. If you are looking for a firm where you can build a future and make an impact, then this is the place for you.

Our Consulting business brings together diverse advisory experts to deliver six core solutions: Business Transformation, Forensic, Deal Services, Restructuring, Finance Function Support and Risk and Governance.

With a bold and ambitious strategy for the next phase of growth, Consulting is investing in enhancing its governance, assurance and information security capabilities. A key part of this strategy is achieving ISO 27001 certification for defined areas of the Consulting business, whilst ensuring the foundations are established to maintain certification and support continual improvement of the Information Security Management System (ISMS).

This role will play a critical leadership and delivery role in defining the scope, shaping the roadmap and driving the activities required to achieve certification.

Reporting into Consulting Operations leadership, the Consulting ISO 27001 Programme Lead will work closely with Consulting leadership, service line representatives, risk and quality teams, National Technology (NT), central Information Security, Privacy and Legal functions.

The role combines programme leadership, information security governance and hands-on delivery, requiring someone who is equally comfortable facilitating stakeholder discussions, interpreting standards, documenting controls and preparing teams for audit.

You'll make an impact by:

  • Support the development and delivery of Consulting's ISO 27001 certification strategy and roadmap
  • Help define certification scope, priorities and implementation plans
  • Advise stakeholders on certification requirements, risks and dependencies.
  • Translate ISO 27001 requirements into practical business outcomes and delivery plans.
  • Provide expert guidance to support certification planning and decision-making.

ISMS Implementation & Alignment

  • Partner with National Technology and Information Security teams to align certification activities with the firm's ISMS.
  • Support the adoption of security policies, controls and governance processes across Consulting.
  • Identify control gaps and recommend pragmatic remediation actions.
  • Ensure security controls are effective, auditable and embedded into day-to-day operations.
  • Act as a key link between Consulting, Technology and Information Security teams.
Stakeholder Engagement & Business Partnering
  • Build strong relationships across Consulting, Technology, Information Security, Privacy and Legal teams.
  • Facilitate workshops, assessments and stakeholder discussions.
  • Provide trusted advice on ISO 27001 requirements and implementation approaches.
  • Support evidence gathering, control ownership and audit readiness activities.
Audit Readiness & Certification Delivery
  • Conduct ISO 27001 gap assessments and develop remediation plans.
  • Coordinate evidence collection and control implementation activities.
  • Prepare teams for internal and external audits.
  • Manage engagement with certification bodies and audit partners.
  • Support successful certification through to audit completion and accreditation.
Governance, Risk & Continuous Improvement
  • Support the ongoing governance and maintenance of ISO 27001 certification.
  • Assist with surveillance audits, recertification and risk management activities.
  • Develop reporting and metrics to demonstrate compliance.
  • Identify opportunities to strengthen controls and improve processes.
  • Help establish a sustainable, long-term approach to information security and certification.
What we are looking for:

Are you someone who thrives on variety, loves learning new things, and enjoys connecting with people? If you can spot inefficiencies in everyday life and are passionate about making improvements, this role is perfect for you!

We value diverse experiences and perspectives. Here's what we're looking for in our ideal candidate:

  • Significant experience leading organisations through ISO 27001 certification programmes.
  • Demonstrable experience defining certification scope within large, complex or matrix organisations.
  • Strong practical knowledge of ISO 27001 and associated ISMS requirements.
  • Experience designing, implementing and operating Information Security Management Systems.
  • Experience conducting gap assessments, remediation planning and audit preparation activities.
  • Strong understanding of information security governance, risk management and control frameworks.
  • Experience working with senior leadership teams and influencing stakeholders across multiple business functions.
  • Ability to translate technical, governance and compliance requirements into practical business actions.
  • Strong documentation, facilitation and communication skills.
  • Proven ability to manage competing priorities and deliver outcomes within fixed timescales.
What we can offer you:

We recognise that our people are our most important assets. That's why we offer a flexible reward and benefits package that will help you have fulfilling experience, both in and out of work.

  • 27 Days Holiday (with the option of purchasing additional days).
  • Hybrid and Flexible working
  • Lifestyle, Health, and Wellbeing including financial wellbeing benefits such as financial tools, electric car scheme and access to a virtual GP.
  • Access to a suite of 300+ courses on demand developed by our inhouse Talent Development team.

BRENTWOOD

Working here

Thousands of personalities make up RSM and we believe the power of being you, is the power of being understood. Every member of our team brings unique insights and a passion for the middle market companies we champion.

As one of the world's largest networks of audit, tax and consulting firms, we deliver the big ideas and services that help middle market organisations thrive. Our global network spans more than 120 countries, but our passion is always the same: to help our clients move forward with confidence.

At RSM, we care about our people, it's what shapes us. No two people are the same, which is why our approach is tailored to their specific needs, beyond the nine-to-five.

The UK group of companies and LLPs trading as RSM is a member of the RSM network. RSM is the trading name used by the members of the RSM network. Each member of the RSM network is an independent accounting and consulting firm which practises in its own right. The RSM network is not itself a separate legal entity in any jurisdiction. Read more