> Markdown version of [/jobs/ext/1392387-cyber-security-risk-consultant](https://www.wearedevelopers.com/jobs/ext/1392387-cyber-security-risk-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Risk Consultant - **Company:** Sanderson Recruitment Plc - **Location:** London, UK (Remote available) - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Document Management Systems, Data Logging, CIS Benchmarks - **Published:** July 23, 2026 - **Apply:** https://www.totaljobs.com/job/cyber-security-risk-consultant/sanderson-government-and-defence-job107733694 ## About the Role * Proven experience in cyber / information security risk management and control assurance roles. * Strong analytical skills with the ability to evaluate technical, procedural and design evidence. * Excellent written and verbal communication skills, with experience presenting to senior and non-technical audiences. * Experience working collaboratively with multidisciplinary teams across business and technology functions. * Familiarity with recognised security frameworks and standards (ISO 27001, NIST, CIS Controls). * Candidates must hold government security vetting at SC level and be able to meet UK residency requirements. ## Description The Cyber Security Consultant will support the organisation's security risk management capability through the identification, assessment, analysis, logging and ongoing monitoring of information and cyber security risks. The role is responsible for delivering effective control assurance, validating that security control objectives are met across people, process and technology, and support the business in making well-informed, risk-based decisions. Working collaboratively with business, technology and delivery teams, the role provides independent challenge, expert advice and pragmatic guidance to ensure security risks are understood, managed and remediated in line with organisational risk appetite and recognised best practice frameworks (e.g. ISO 27001, NIST, CIS Controls)., * Deliver security risk identification, assessment, analysis and logging activities, ensuring risks are clearly articulated, consistently scored and recorded in approved Information Security Risk Management (ISRM) tools. * Perform control assurance activities to validate how control objectives are being met in practice, working closely with technical delivery teams to understand design and implementation. * Identify and document control gaps, assess residual risk, and clearly articulate outcomes within control and assurance artefacts. * Support the delivery, rollout and continuous improvement of Information Security Risk Management methodologies, including the discovery, review and transformation of historic risk assessments into an updated, consistent approach. * Manage allocated assignments end-to-end, ensuring all control, assurance and risk outputs are delivered accurately and in a timely manner. * Maintain oversight of risk remediation activities, tracking actions through to implementation and ensuring ongoing risk treatment and control effectiveness. * Provide advice, guidance and intelligent challenge on enterprise control alignment during reviews of solution designs, security documentation and architecture artefacts. * Lead and facilitate collaborative control and risk workshops with business and technical stakeholders to drive shared understanding, surface key risks and agree appropriate outcomes. * Contribute to post-incident and remedial assurance activities, ensuring lessons learned are captured and embedded into control improvements. * Provide input into formal scoping, ensuring key security risks are reflected in test scope and that critical controls are robustly assessed against expected security outcomes. * Prepare clear, concise risk summary statements and assurance outputs for senior stakeholders and risk owners, translating technical issues into business-focused language to enable effective information risk decisions. * Present assurance findings and risk positions at governance forums and stakeholder meetings, representing the security assurance function with credibility. * Ensure effective knowledge transfer on key assignments, building capability and understanding across business and technical stakeholders. * Contribute to the continuous improvement of assurance practices, maintaining awareness of emerging threats, vulnerabilities and industry best practice. ## Related Videos - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)