Head of Consultancy & Compliance
Head of Consultancy and Compliance
Acumen Cyber | Hybrid in Glasgow with travel | Reporting to the Director of Security Operations
Salary: £75k-£90k plus Private Healthcare, Pension and other benefits
We're a 24/7 CREST-accredited managed SOC and MXDR provider headquartered in Glasgow, working with mid-market, education and public sector organisations across the UK. Our philosophy is evidence over assurance: security you can prove, not security you're asked to trust.
We're growing fast and we're ambitious. Our customers stay with us because we're good at what we do, and the business is at the stage where there's real room to build. This is a chance to create a consultancy practice rather than inherit one.
The consultancy and advisory work has grown up inside our managed service, and it's ready to stand on its own as a proper practice with its own offerings. That's the job.
What you'll own
- The consultancy and compliance practice end to end: the offerings, the delivery quality, the team and the commercials.
- Hands-on billable delivery. This is a leadership role, but you'll still carry an engagement load (vCISO, ISO 27001 implementation, CAF assessments, gap analysis, security roadmaps).
- Developing and productising our offerings: pricing them, positioning them and supporting sales and bids to win the work.
- Leading, growing and mentoring a team of consultants, including capacity planning and utilisation.
- A smaller but important strand: keeping our own house in order across our growing accreditation list ISO 27001,14001, 9001, CREST SOC and Cyber Essentials Plus.
What we're looking for
- A track record delivering consultancy and advisory work in a client-facing setting, ideally within an MSSP or consultancy.
- Strong across compliance frameworks including ISO 27001, NIST CSF, NCSC CAF and CIS Controls.
- Experience with the Vanta platform is highly advantageous.
- Commercial instinct: you understand scoping, pricing, utilisation and how a practice generates revenue.
- Credibility in both directions: you can hold a technical conversation with our engineers and a risk conversation with a customer's board.
- Relevant certifications welcome (CISSP, CISM, ISO 27001 Lead Auditor or Lead Implementer, CISA, CRISC).
Location
We're open-minded on location and remote-friendly. You'll need to be willing to travel to our Glasgow HQ and out to customer sites across the UK and Ireland.
What this isn't
A back-office role. You won't be tucked away writing policies. You'll be in front of customers, carrying delivery, and building something. If you want to lead a growing practice rather than maintain a finished one, this is for you.