> Markdown version of [/jobs/ext/2107780-senior-cyber-security-consultant-perm-sc-cleared](https://www.wearedevelopers.com/jobs/ext/2107780-senior-cyber-security-consultant-perm-sc-cleared). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Security Consultant - Perm - SC Cleared - **Company:** gb Sanderson Government and Defence - **Location:** UK (Remote available) - **Experience:** Expert - **Salary:** £65,000.0 - £80,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cyber Security, Digital Technology, PCI Data Security Standards, Zero Trust Network Access, Information Technology Security Auditing, Office365, Cyber Threat Analysis, Mobile Computing - **Published:** August 19, 2026 - **Apply:** https://www.totaljobs.com/job/senior-cybersecurity-consultant/sanderson-government-and-defence-job107869970 ## About the Role * Strong analytical and problem-solving skills. Excellent communication and teamwork abilities, passion for cyber security and a desire to learn and grow within the field. Ability to adapt and thrive in a fast-paced, dynamic environment, Organisation skills and forward planning. * Possess strong hands-on experience and working knowledge of: * Security related legislation (e.g. GDPR, PCI DSS, ICO requirements). * Security Control Frameworks such as NCSC Cyber Assurance Framework, ISO 27001, NIST CSF and CIS. * HMG and NCSC security policies, standards and guidance. * Have an understanding of cyber risk management in an agile delivery environment. * Have a good understanding of modern IT technologies and services, such as Cloud Computing (Azure, M365, AWS, Google), Mobile Computing, IT Security, Infrastructure technologies, Zero Trust and demonstrate an understanding of security architecture. * Be skilled in workshop facilitation particularly with respect to risk identification and assessment. * As a team, we're always looking to raise the bar, learn new things and incorporate new technologies and you will too! You'll share your knowledge with the team, our clients and the wider Cyberfort community, contributing to Group blogs and undertaking research related to technology enhancements. * Certifications That Set You Apart: Relevant certifications, e.g., CISSP, CISM, CRISC or other. Have achieved or be working towards Full Membership of CIISEC and UK Cyber Security Council professional registration at either Chartered or Principal for Cyber Security Governance & Risk Management. ## Description As a Senior Cyber Security Consultant, you will be responsible for the identification of risks relating to Security Architecture, maintaining an awareness of published vulnerabilities and best practices across various platforms, especially cloud infrastructures. Working across the business and multiple technology platforms, you will play a key role in ensuring clients make the best use of their existing technology and make proportionate, risk-informed decisions, ensuring protection of client assets and transformation of their security architecture. This role forms part of the wider Consultancy team and will work cross functionally with the Delivery Manager and others to support and assure project delivery through all phases of the agile workflow. As a team, we're always looking to raise the bar, learn new things and incorporate new technologies and you will too! The Impact You'll Make In this role, you'll be: * Providing expert advice on cyber risk management, assessment principles and frameworks, such as ISO27005 and the NIST Risk Management Framework. * Working with multi-disciplinary teams, helping to ensure that products are delivered in a secure manner that is aligned with the wider business risk appetite. * Managing and supporting risk identification, assessment, remediation and risk treatment for digital systems, applications and infrastructure. * Identifying and validating technical, procedural, physical and personnel security controls, making recommendations to address security vulnerabilities and control weaknesses. * Facilitating cyber risk workshops and threat modelling to identify and assess risks that arise from solution architectures. * Supporting the scoping of IT Health Checks, which will identify principal security concerns for service lines. * Reviewing outcomes of the ITHC and providing advice and guidance, and where required production of an action plan for vulnerabilities identified with clear recommendations and outcomes to mitigate and address. * Producing informative and succinct reporting that clearly articulates any identified vulnerabilities, associated risks, controls and risk treatment activity. * Producing residual risk registers. * Providing accurate and pragmatic remediation/risk management guidance/advice. * Conducting Security gap analysis against security control frameworks, remediation planning and monitoring. * Evaluating third-party suppliers to provide assurance of the effective design and operation of security controls. * Producing security audit reports, checklists and briefings. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)