Senior Cyber Security Consultant - Perm - SC Cleared

gb Sanderson Government and Defence
UK
15 days ago
Apply on www.totaljobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£65,000.0 - £80,000.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Cyber Security Digital Technology PCI Data Security Standards Zero Trust Network Access Information Technology Security Auditing Office365 Cyber Threat Analysis Mobile Computing

Job description

As a Senior Cyber Security Consultant, you will be responsible for the identification of risks relating to Security Architecture, maintaining an awareness of published vulnerabilities and best practices across various platforms, especially cloud infrastructures. Working across the business and multiple technology platforms, you will play a key role in ensuring clients make the best use of their existing technology and make proportionate, risk-informed decisions, ensuring protection of client assets and transformation of their security architecture.

This role forms part of the wider Consultancy team and will work cross functionally with the Delivery Manager and others to support and assure project delivery through all phases of the agile workflow. As a team, we’re always looking to raise the bar, learn new things and incorporate new technologies and you will too!

The Impact You’ll Make

In this role, you’ll be:

  • Providing expert advice on cyber risk management, assessment principles and frameworks, such as ISO27005 and the NIST Risk Management Framework.
  • Working with multi-disciplinary teams, helping to ensure that products are delivered in a secure manner that is aligned with the wider business risk appetite.
  • Managing and supporting risk identification, assessment, remediation and risk treatment for digital systems, applications and infrastructure.
  • Identifying and validating technical, procedural, physical and personnel security controls, making recommendations to address security vulnerabilities and control weaknesses.
  • Facilitating cyber risk workshops and threat modelling to identify and assess risks that arise from solution architectures.

  • Supporting the scoping of IT Health Checks, which will identify principal security concerns for service lines.
  • Reviewing outcomes of the ITHC and providing advice and guidance, and where required production of an action plan for vulnerabilities identified with clear recommendations and outcomes to mitigate and address.

  • Producing informative and succinct reporting that clearly articulates any identified vulnerabilities, associated risks, controls and risk treatment activity.
  • Producing residual risk registers.
  • Providing accurate and pragmatic remediation/risk management guidance/advice.
  • Conducting Security gap analysis against security control frameworks, remediation planning and monitoring.
  • Evaluating third-party suppliers to provide assurance of the effective design and operation of security controls.
  • Producing security audit reports, checklists and briefings.

Requirements

  • Strong analytical and problem-solving skills. Excellent communication and teamwork abilities, passion for cyber security and a desire to learn and grow within the field. Ability to adapt and thrive in a fast-paced, dynamic environment, Organisation skills and forward planning.
  • Possess strong hands-on experience and working knowledge of:

  • Security related legislation (e.g. GDPR, PCI DSS, ICO requirements).
  • Security Control Frameworks such as NCSC Cyber Assurance Framework, ISO 27001, NIST CSF and CIS.
  • HMG and NCSC security policies, standards and guidance.

  • Have an understanding of cyber risk management in an agile delivery environment.
  • Have a good understanding of modern IT technologies and services, such as Cloud Computing (Azure, M365, AWS, Google), Mobile Computing, IT Security, Infrastructure technologies, Zero Trust and demonstrate an understanding of security architecture.
  • Be skilled in workshop facilitation particularly with respect to risk identification and assessment.
  • As a team, we’re always looking to raise the bar, learn new things and incorporate new technologies and you will too! You’ll share your knowledge with the team, our clients and the wider Cyberfort community, contributing to Group blogs and undertaking research related to technology enhancements.

  • Certifications That Set You Apart: Relevant certifications, e.g., CISSP, CISM, CRISC or other. Have achieved or be working towards Full Membership of CIISEC and UK Cyber Security Council professional registration at either Chartered or Principal for Cyber Security Governance & Risk Management.

Benefits & conditions

You’ll enjoy:

  • Flexibility First: Work-life balance through hybrid/remote working options.
  • Your Growth Journey: Continuous learning opportunities and professional development.
  • Perks with a Purpose: Comprehensive benefits package to support your wellbeing, health, family and future, from Private Health Care, Cash Back Plan, Buy and Sell Holiday Options, Life Assurance….

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · World Congress 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all