Skip to main content
Back to open positions
Cyber Security & Risk Advisory

Cyber Security Consultant

Help organisations strengthen cyber resilience through practical security assessments, risk reduction, control improvement and incident-readiness support across modern workplace, cloud and infrastructure environments.

LocationPortugal — LisbonEmploymentFull-timeWork ModelHybrid / On-Site

Who We Are

GIS360 is a global IT services and technology solutions provider delivering help desk support, managed IT services, field engineering and engineer dispatch, infrastructure and network support, cybersecurity, Microsoft Dynamics 365 and ERP expertise, wireless services, technical resourcing and compliant IT asset disposal.

We coordinate cross-country operations through our presence in Portugal—including Beja, Lisbon and Porto—with additional operational coverage in Spain through Madrid, Barcelona and Sevilla, and across the United Kingdom. This footprint enables GIS360 to combine central service coordination with responsive local delivery for organisations operating across multiple locations.

Our company expertise brings together service governance, SLA-driven operations, technical consulting, vendor coordination and qualified local engineering capability. We help customers standardise technology delivery, strengthen operational resilience and access the right specialists wherever their business requires support.

Role Overview

GIS360 is seeking a Cyber Security Consultant to support customers in identifying security risks, improving technical controls and building practical cyber resilience across their technology environments. You will work across advisory and delivery activities, translating security findings into clear, proportionate actions that customers can implement and maintain.

The role covers security assessments, vulnerability and risk management, Microsoft and cloud security, identity and access controls, security documentation, incident readiness and customer guidance. You will collaborate with managed services, infrastructure, field engineering and enterprise application teams to ensure security is considered throughout the service lifecycle.

This position is based in Portugal with a hybrid working arrangement. Customer workshops, on-site assessments and travel within EMEA may be required according to engagement needs.

Key Responsibilities

  • Conduct structured cybersecurity assessments across endpoints, networks, identities, cloud services, business applications and operational processes.
  • Identify vulnerabilities, control gaps and material risks, then present prioritised remediation recommendations in clear business language.
  • Support vulnerability-management activities, including validation, risk-based prioritisation, remediation coordination and progress reporting.
  • Review identity and access management, privileged access, multifactor authentication and account-lifecycle controls.
  • Assess Microsoft 365, Azure and other cloud configurations against recognised security practices and customer requirements.
  • Help customers develop and improve security policies, standards, procedures, risk registers and incident-response documentation.
  • Support security incident readiness through playbooks, tabletop exercises, evidence collection guidance and post-incident improvement actions.
  • Work with technical delivery teams to embed appropriate security controls into infrastructure, workplace, application and managed-service solutions.
  • Prepare professional assessment reports, executive summaries, technical findings and remediation roadmaps.
  • Facilitate customer workshops and communicate effectively with technical teams, operational stakeholders and senior decision-makers.
  • Track actions, dependencies and risks throughout engagements while maintaining accurate project and security documentation.
  • Keep current with relevant threats, technologies and recognised frameworks, and contribute to GIS360 security methods and reusable delivery standards.

Required Qualifications

  • At least four years of practical experience in cybersecurity consulting, security engineering, risk assessment or a closely related role.
  • Strong working knowledge of security principles across networks, endpoints, identity, cloud services and business applications.
  • Experience conducting security or risk assessments and documenting findings, evidence, impact and remediation priorities.
  • Practical knowledge of vulnerability management, secure configuration, access control, logging and incident-response fundamentals.
  • Experience with Microsoft 365 and Azure security capabilities or comparable enterprise cloud platforms.
  • Ability to interpret recognised security frameworks and regulatory expectations, such as ISO 27001, NIST Cybersecurity Framework, CIS Controls, GDPR and NIS2, in a practical customer context.
  • Confidence producing clear technical reports, management summaries, remediation plans and customer-facing documentation.
  • Strong analytical judgement and the ability to distinguish urgent risks from longer-term improvements.
  • Professional written and spoken English with confident workshop and stakeholder communication skills.
  • Ability to manage several workstreams, protect confidential information and work independently within agreed delivery standards.
  • Availability for hybrid work in Portugal and travel to customer locations when required.

Preferred Experience

  • Relevant security certification such as CISSP, CISM, CCSP, Security+, Microsoft Security, ISO 27001 or an equivalent practitioner credential.
  • Experience with Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID or comparable security platforms.
  • Knowledge of security monitoring, SIEM, endpoint detection and response, email security and data-protection controls.
  • Experience supporting incident-response exercises, technical investigations or security-improvement programmes.
  • Familiarity with penetration-test findings and coordination of remediation with infrastructure and application teams.
  • Experience working with managed-service providers, distributed organisations or multi-country customer environments.
  • Portuguese or another European language in addition to English.

What GIS360 Offers

  • A customer-facing role with meaningful ownership across varied cybersecurity assessments and improvement programmes.
  • A professional development path aligned with security consulting, engineering, governance and cloud-security goals.
  • Access to relevant learning resources, training and certification opportunities.
  • Collaboration with specialists across managed services, infrastructure, enterprise applications and field engineering.
  • Hybrid working arrangements aligned with customer and engagement requirements.
  • Opportunities to shape reusable security methods, assessment standards and future GIS360 service offerings.
  • A working environment that values integrity, sound judgement, accountability and respectful collaboration.

Working at GIS360

GIS360 delivers coordinated IT support, field engineering, managed services, enterprise applications and specialist technical resources across EMEA, APAC and LATAM. Our delivery model combines local technical capability with consistent operational coordination for customers working across multiple locations.

We value practical expertise, professional accountability, continuous learning and respectful collaboration. Our consultants work across varied customer environments while contributing to reliable technology outcomes and long-term service relationships. GIS360 provides equal employment opportunities and assesses applicants according to role-related experience, capability and business requirements.