> Markdown version of [/jobs/ext/1620008-cyber-grc-consultant-dv-cleared](https://www.wearedevelopers.com/jobs/ext/1620008-cyber-grc-consultant-dv-cleared). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber GRC Consultant (DV Cleared) - **Company:** Sanderson Recruitment Plc - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Application Firewall, Microsoft Azure, Cloud Computing Security, Cyber Security, Intrusion Detection Systems, Information Systems Security Architecture Professional, Key Management, Network Security, PCI Data Security Standards, Public Key Infrastructure, Systems Development Life Cycle, Zero Trust Network Access, Software Engineering, Information Security Management System, Cloud Platform System, Firewalls (Computer Science), Containerization, CIS Benchmarks, User Administration - **Published:** July 31, 2026 - **Apply:** https://www.totaljobs.com/job/cyber-grc-consultant/sanderson-government-and-defence-job107771373 ## About the Role The successful candidate will possess proven experience in cybersecurity, security architecture, threat modelling, or related fields within Public Sector and MOD and will have achieved or be working towards Full Membership of CIISEC and UK Cyber Security Council professional registration at either Chartered or Principal for Risk Management. * Active DV clearance required * Strong working knowledge of: + Security Assurance Coordinator or Delivery Team Security Lead roles + JSP440, JSP604/453 & JSP490 + Working with system secure design + MOD/GDS Secure by Design Principles + Supplier Chain Assurance and Risks. + Security related legislation (e.g. GDPR, PCI DSS, ICO requirements). + Security Control Frameworks such as ISO 27001, NIST CSF and CIS Controls v8. + HMG, NPSA and NCSC security policies, standards and guidance. + Have experience building and implementing secure by design principals within the software development lifecycle (SDLC). + Threat Modelling - Kill Chain - Attack tree analysis. * Working understanding of: + Cloud security including Azure, Amazon Web Service, Key Management Systems, Containerisation, Network Security Groups, Host based firewalls, Web Application Firewalls + Physical Network Infrastructure, Anti-Patterns, Network Firewalls, IDS/IPS, DMZs + AI use cases, secure configuration (ISO42001 knowledge preferable), + ITHC scoping and remediation action plans. + HLD and LLD reviews and analysis. * Working knowledge and experience of tooling relating to cloud security posture management offerings, cloud native security (AWS/Azure) and endpoint security. * Proficient in Public Key Infrastructure, Data at Rest/inTransit, Cryptography, Privileged User Access Management, Zero Trust, Cross Domain Solutions and Role-based Access Controls. * Thrives on tackling challenges with creative solutions, challenging the normal. ## Description As a Cyber Security Consultant, you will play a pivotal role in delivering Secure by Design risk and security assurance services within MOD and Public Sector environments. You'll collaborate with multi-disciplinary teams to define and implement security risk assessments and best practice solutions, ensuring alignment with business risk appetites and transformation goals. You'll be part of a knowledge-sharing culture, working alongside expert peers in Secure Architecture and Risk Planning., * Deliver Secure by Design risk and security assurance functions within MOD/Public Sector. * Lead and advise on risk management frameworks, ISMS, and Enterprise Security Risk Management. * Facilitate security and risk workshops with Authority departments. * Produce clear reporting on vulnerabilities, risks, controls, and treatment activities. * Provide pragmatic remediation and risk management guidance. * Support secure design across technology platforms including cloud infrastructures. * Contribute to blogs and research within the business community. ## Related Videos - [This Machine Ends Data Breaches](https://www.wearedevelopers.com/videos/574-this-machine-ends-data-breaches) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)