Cyber Security Risk Consultant

Sanderson Recruitment Plc
London, UK
20 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work

Tech stack

Control Objectives for Information and Related Technology (COBIT) Cyber Security Document Management Systems Data Logging CIS Benchmarks

Job description

The Cyber Security Consultant will support the organisation’s security risk management capability through the identification, assessment, analysis, logging and ongoing monitoring of information and cyber security risks. The role is responsible for delivering effective control assurance, validating that security control objectives are met across people, process and technology, and support the business in making well-informed, risk-based decisions.

Working collaboratively with business, technology and delivery teams, the role provides independent challenge, expert advice and pragmatic guidance to ensure security risks are understood, managed and remediated in line with organisational risk appetite and recognised best practice frameworks (e.g. ISO 27001, NIST, CIS Controls)., * Deliver security risk identification, assessment, analysis and logging activities, ensuring risks are clearly articulated, consistently scored and recorded in approved Information Security Risk Management (ISRM) tools.

  • Perform control assurance activities to validate how control objectives are being met in practice, working closely with technical delivery teams to understand design and implementation.
  • Identify and document control gaps, assess residual risk, and clearly articulate outcomes within control and assurance artefacts.
  • Support the delivery, rollout and continuous improvement of Information Security Risk Management methodologies, including the discovery, review and transformation of historic risk assessments into an updated, consistent approach.
  • Manage allocated assignments end-to-end, ensuring all control, assurance and risk outputs are delivered accurately and in a timely manner.
  • Maintain oversight of risk remediation activities, tracking actions through to implementation and ensuring ongoing risk treatment and control effectiveness.
  • Provide advice, guidance and intelligent challenge on enterprise control alignment during reviews of solution designs, security documentation and architecture artefacts.
  • Lead and facilitate collaborative control and risk workshops with business and technical stakeholders to drive shared understanding, surface key risks and agree appropriate outcomes.
  • Contribute to post-incident and remedial assurance activities, ensuring lessons learned are captured and embedded into control improvements.
  • Provide input into formal scoping, ensuring key security risks are reflected in test scope and that critical controls are robustly assessed against expected security outcomes.
  • Prepare clear, concise risk summary statements and assurance outputs for senior stakeholders and risk owners, translating technical issues into business-focused language to enable effective information risk decisions.
  • Present assurance findings and risk positions at governance forums and stakeholder meetings, representing the security assurance function with credibility.
  • Ensure effective knowledge transfer on key assignments, building capability and understanding across business and technical stakeholders.
  • Contribute to the continuous improvement of assurance practices, maintaining awareness of emerging threats, vulnerabilities and industry best practice.

Requirements

  • Proven experience in cyber / information security risk management and control assurance roles.
  • Strong analytical skills with the ability to evaluate technical, procedural and design evidence.
  • Excellent written and verbal communication skills, with experience presenting to senior and non-technical audiences.
  • Experience working collaboratively with multidisciplinary teams across business and technology functions.
  • Familiarity with recognised security frameworks and standards (ISO 27001, NIST, CIS Controls).
  • Candidates must hold government security vetting at SC level and be able to meet UK residency requirements.

Benefits & conditions

What’s in it for You

  • Flexible Working: Remote-first with travel as needed.
  • Career Development: Continuous learning and professional growth.
  • Benefits Package: Includes Private Health Care, Cash Back Plan, Buy/Sell Holiday Options, Life Assurance, and more.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all