Senior Cyber Security Consultant - Perm - SC Cleared
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
As a Senior Cyber Security Consultant, you will be responsible for the identification of risks relating to Security Architecture, maintaining an awareness of published vulnerabilities and best practices across various platforms, especially cloud infrastructures. Working across the business and multiple technology platforms, you will play a key role in ensuring clients make the best use of their existing technology and make proportionate, risk-informed decisions, ensuring protection of client assets and transformation of their security architecture.
This role forms part of the wider Consultancy team and will work cross functionally with the Delivery Manager and others to support and assure project delivery through all phases of the agile workflow. As a team, we’re always looking to raise the bar, learn new things and incorporate new technologies and you will too!
The Impact You’ll Make
In this role, you’ll be:
- Providing expert advice on cyber risk management, assessment principles and frameworks, such as ISO27005 and the NIST Risk Management Framework.
- Working with multi-disciplinary teams, helping to ensure that products are delivered in a secure manner that is aligned with the wider business risk appetite.
- Managing and supporting risk identification, assessment, remediation and risk treatment for digital systems, applications and infrastructure.
- Identifying and validating technical, procedural, physical and personnel security controls, making recommendations to address security vulnerabilities and control weaknesses.
-
Facilitating cyber risk workshops and threat modelling to identify and assess risks that arise from solution architectures.
- Supporting the scoping of IT Health Checks, which will identify principal security concerns for service lines.
-
Reviewing outcomes of the ITHC and providing advice and guidance, and where required production of an action plan for vulnerabilities identified with clear recommendations and outcomes to mitigate and address.
- Producing informative and succinct reporting that clearly articulates any identified vulnerabilities, associated risks, controls and risk treatment activity.
- Producing residual risk registers.
- Providing accurate and pragmatic remediation/risk management guidance/advice.
- Conducting Security gap analysis against security control frameworks, remediation planning and monitoring.
- Evaluating third-party suppliers to provide assurance of the effective design and operation of security controls.
- Producing security audit reports, checklists and briefings.
Requirements
- Strong analytical and problem-solving skills. Excellent communication and teamwork abilities, passion for cyber security and a desire to learn and grow within the field. Ability to adapt and thrive in a fast-paced, dynamic environment, Organisation skills and forward planning.
-
Possess strong hands-on experience and working knowledge of:
- Security related legislation (e.g. GDPR, PCI DSS, ICO requirements).
- Security Control Frameworks such as NCSC Cyber Assurance Framework, ISO 27001, NIST CSF and CIS.
-
HMG and NCSC security policies, standards and guidance.
- Have an understanding of cyber risk management in an agile delivery environment.
- Have a good understanding of modern IT technologies and services, such as Cloud Computing (Azure, M365, AWS, Google), Mobile Computing, IT Security, Infrastructure technologies, Zero Trust and demonstrate an understanding of security architecture.
- Be skilled in workshop facilitation particularly with respect to risk identification and assessment.
-
As a team, we’re always looking to raise the bar, learn new things and incorporate new technologies and you will too! You’ll share your knowledge with the team, our clients and the wider Cyberfort community, contributing to Group blogs and undertaking research related to technology enhancements.
- Certifications That Set You Apart: Relevant certifications, e.g., CISSP, CISM, CRISC or other. Have achieved or be working towards Full Membership of CIISEC and UK Cyber Security Council professional registration at either Chartered or Principal for Cyber Security Governance & Risk Management.
Benefits & conditions
You’ll enjoy:
- Flexibility First: Work-life balance through hybrid/remote working options.
- Your Growth Journey: Continuous learning opportunities and professional development.
- Perks with a Purpose: Comprehensive benefits package to support your wellbeing, health, family and future, from Private Health Care, Cash Back Plan, Buy and Sell Holiday Options, Life Assurance….
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
IT Salaries in UK
Best Companies to work for in London: Top 25 Companies in 2023
Data Analyst Salary in the UK