Cyber and Information Assurance Consultant
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The Cyber and Information Assurance Consultant supports customers in identifying, assessing and managing cyber security and information assurance risks across complex digital, operational and high-assurance environments. The role combines consultancy, risk assessment, security assurance, governance and stakeholder engagement. Work may span secure information exchange, cross-domain solutions, cloud services, networks, applications, data platforms and operational systems., Cyber Risk Assessment
- Conduct cyber security and information assurance risk assessments.
- Identify threats, vulnerabilities, impacts and control requirements.
- Develop proportionate risk treatment recommendations.
- Maintain cyber risk registers, assumptions, dependencies and residual risk positions.
- Support formal risk acceptance and escalation activity.
- Provide clear advice to technical and non-technical stakeholders.
Information Assurance
- Support assurance of systems, services and information-handling arrangements.
- Assess compliance against customer, contractual and regulatory requirements.
- Review security documentation, technical evidence and control implementation.
- Support security case development and assurance planning.
- Contribute to accreditation, authorisation and approval activity.
- Maintain traceability between requirements, controls, evidence and risk decisions.
Security Governance
Support development and maintenance of:
- Security policies.
- Standards.
- Procedures.
- Governance frameworks.
- Assurance plans.
- Security management plans.
Additionally:
- Contribute to security governance forums and assurance boards.
- Track security actions, risks, decisions and evidence.
- Support senior ownership and oversight of cyber security risk.
Secure-by-Design Support
- Work with architects, engineers and delivery teams to embed security throughout the lifecycle.
- Review solution designs for security, privacy, resilience and assurance implications.
- Support identification of security requirements and non-functional requirements.
- Apply defence-in-depth, least-privilege and Zero Trust principles.
- Ensure security considerations form part of design, build, test, deployment and operation.
Threat and Vulnerability Assessment
- Assess credible threat scenarios relevant to customer environments.
- Review vulnerability information and technical findings.
- Support interpretation of penetration test, vulnerability scan and security assessment outputs.
- Evaluate exploitability, business impact and operational consequence.
- Recommend remediation priorities and compensating controls.
Customer Engagement
Work with:
- Customer security teams.
- Senior risk owners.
- Solution and Security Architects.
- Systems Engineers.
- Project and Delivery Managers.
- Software and Platform Engineers.
- Product Teams.
- Suppliers and Technology Partners.
Additionally:
- Participate in workshops, assurance reviews and customer briefings.
- Explain cyber security risks and control recommendations in accessible language.
- Build trusted and professional customer relationships.
Continuous Improvement and Professional Development
Maintain awareness of emerging cyber threats, regulation and assurance practice.
- Contribute to internal methods, templates and guidance.
- Share knowledge across Nexor communities of practice.
- Support lessons identified and service improvement activity.
- Work towards recognised cyber security and assurance qualifications., * Principal Cyber Consultant.
- Security Architect.
- Cyber Risk Lead.
- Information Assurance Lead.
- Security Assurance Manager.
- Head of Cyber Assurance.
Development support may include:
- Mentoring from senior cyber consultants and architects.
- Customer and programme exposure.
- Security architecture and assurance training.
- Support towards professional certification.
- Opportunities to lead defined assurance work packages.
- Participation in internal research and service development.
- Exposure to bids, pre-sales and consultancy shaping.
- Access to cyber and architecture communities of practice.
Measures of Success
Success within the role shall be measured through:
- Quality and clarity of assurance deliverables.
- Effective identification and communication of cyber risks.
- Completion of assigned work against customer objectives.
- Constructive participation in assurance and design reviews.
- Effective management of risks, actions and evidence.
- Positive customer and stakeholder feedback.
- Growth in assurance and domain competence.
- Contribution to successful bids and customer engagements.
- Increasing ownership of cyber assurance work packages.
- Progress towards relevant professional qualifications.
Reporting Line
The role reports to the Head of Services and/or Principal Cyber Consultant.
Day-to-day direction may also come from a Security Architect, Programme Security Lead or Project/Delivery Manager.
Requirements
- Professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline.
- Experience contributing to security assessment or assurance activity.
- Experience working within multidisciplinary technical teams.
- Experience producing clear and structured security documentation.
- Ability to identify and communicate cyber risks.
- Ability to interpret technical evidence and control requirements.
- Experience engaging with technical and non-technical stakeholders.
- Strong interest in defence, government, critical infrastructure or high-assurance systems.
Essential Technical Knowledge
Cyber Security and Assurance
- Cyber risk management.
- Information assurance.
- Security governance.
- Security controls.
- Threat and vulnerability assessment.
- Security lifecycle principles.
- Residual risk and risk acceptance.
- Assurance evidence and traceability., * NIST Cybersecurity Framework.
- MOD Defence Standard 05-138.
- Government Security Classifications.
- Secure-by-Design principles., * Defence, government or critical national infrastructure experience.
- Experience within high-assurance or regulated environments.
- Exposure to secure information exchange or cross-domain solutions.
- Experience supporting accreditation or authority-to-operate processes.
- Familiarity with MOD security and assurance practices.
- Experience with cloud security assurance.
- Experience supporting security architecture reviews.
- Knowledge of data protection and privacy impact assessment.
- Current SC clearance.
- Experience supporting bids, proposals or pre-sales activity., Productive engagement with customer and technical stakeholders
Requirements Definition and Management (REQM)
4
Definition and traceability of security requirements
Methods and Tools (METL)
4
Application of assurance methods, frameworks and tools
Compliance Audit (COAU)
4
Assessment of compliance against policies, standards and controls, A degree, degree apprenticeship or equivalent experience in a relevant discipline, including:
- Cyber Security.
- Information Security.
- Computer Science.
- Systems Engineering.
- Software Engineering.
- Electronic Engineering.
- Risk Management.
- Mathematics.
- Another relevant science, technology or engineering discipline.
Desirable
Progress towards, or interest in obtaining:
- CISSP.
- CISM.
- CRISC.
- ISO/IEC 27001 Lead Implementer.
- ISO/IEC 27001 Lead Auditor.
- NCSC Certified Cyber Professional.
- Chartered Cyber Security Professional.
- Risk management qualification., Typically suited to candidates with sufficient delivery experience to take ownership of defined cyber risk and assurance activities under senior professional guidance.
Security and Compliance Requirements
Eligibility for UK Security Check clearance.
Compliance with customer and Nexor information-handling requirements.
Compliance with Nexor security, quality and engineering procedures.
Appropriate handling of customer, partner and programme information.
Willingness to work within secure environments where required.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What’s the Difference between a Junior, Mid, and Senior Developer?
The Most Popular IT Jobs on the Market
IT Salaries in UK
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.