> Markdown version of [/jobs/ext/2353344-information-assurance-caf-consultant](https://www.wearedevelopers.com/jobs/ext/2353344-information-assurance-caf-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance CAF Consultant - **Company:** Sanderson Recruitment Plc - **Location:** London, UK - **Salary:** £156,000.0 - £182,000.0 - **Contract:** Temporary contract - **Skills:** Cyber Security, SC Clearance, Cloud Migration - **Published:** August 20, 2026 - **Apply:** https://www.careerboard.com/pt/en/find-jobs-in-United-Kingdom/-DF301885E3170E371D/ ## About the Role * Strong experience within Information Assurance, Governance, Risk, Compliance, or Quality Assurance environments. * Demonstrable experience working with the Cyber Assessment Framework (CAF) or comparable assurance frameworks. * Advanced knowledge of Quality Assurance principles and methodologies. * Experience conducting audits, compliance assessments, and assurance reviews. * Strong understanding of governance, risk management, and control frameworks. * Experience producing assurance reports, recommendations, and improvement plans. * Excellent communication, stakeholder engagement, and influencing skills. * Ability to work independently and provide subject matter expertise. * Active SC Clearance. Desirable * Experience supporting Business Continuity and Disaster Recovery programmes. * Knowledge of government security standards and public sector assurance frameworks. * Experience working within government, Critical National Infrastructure (CNI), or other highly regulated environments. * Familiarity with: + NCSC Cyber Assessment Framework (CAF) + ISO 27001 + NIST Cybersecurity Framework + Risk Management Frameworks + Control Assurance and Testing + Operational Resilience Programmes * Experience supporting large-scale digital transformation, cloud migration, or complex technology programmes. ## Description We are seeking an experienced Information Assurance CAF Consultant to join a growing consultancy delivering cyber security, assurance, and governance services across a portfolio of government projects. This is an excellent opportunity for an Information Assurance professional with strong experience in the Cyber Assessment Framework (CAF), Governance, Risk & Compliance (GRC), Quality Assurance, and Operational Resilience. You will work alongside client and delivery teams to strengthen security controls, enhance assurance frameworks, support compliance activities, and drive continuous improvement initiatives. As a trusted subject matter expert, you will engage with stakeholders at all levels, providing guidance on assurance, risk management, governance, and resilience while helping clients meet regulatory and security requirements within complex and highly regulated environments. Key Responsibilities Information Assurance & CAF Compliance * Support the implementation, assessment, and continuous improvement of Information Assurance frameworks aligned to the Cyber Assessment Framework (CAF). * Evaluate compliance against security, governance, risk, and resilience requirements. * Conduct assurance reviews to identify control gaps and recommend remediation actions. * Support internal and external audits, assessments, and accreditation activities. * Ensure security, quality, and assurance activities align with organisational and client standards. Quality Assurance & Governance * Develop, maintain, and enhance quality assurance frameworks, methodologies, and controls. * Monitor compliance with policies, procedures, standards, and regulatory requirements. * Assess operational effectiveness and identify opportunities for improvement. * Support governance forums by providing assurance reporting and recommendations. * Contribute to the development of quality metrics and performance indicators. Business Continuity & Operational Resilience * Support Business Continuity and Disaster Recovery (BCDR) activities. * Review resilience capabilities and identify opportunities to strengthen operational readiness. * Assist with testing, exercising, and validating continuity and recovery plans. * Ensure critical services meet resilience and availability requirements. Process Improvement & Best Practice * Lead initiatives to improve assurance, compliance, and quality management processes. * Identify trends, risks, and recurring issues that could impact delivery or compliance. * Promote continuous improvement and operational excellence across teams. * Develop and implement best practices that enhance governance and assurance outcomes. Reporting & Analysis * Analyse assurance, risk, and quality data to support decision-making. * Produce high-quality reports, dashboards, and management information. * Present findings and recommendations to senior stakeholders. * Monitor remediation activities and report progress against agreed objectives. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Convincing Product teams to Adopt Gitops in a Large Org](https://www.wearedevelopers.com/videos/1936-convincing-product-teams-to-adopt-gitops-in-a-large-org) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job)