> Markdown version of [/jobs/ext/3032278-security-consultant](https://www.wearedevelopers.com/jobs/ext/3032278-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Consultant - **Company:** BAE Systems - **Location:** UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security - **Published:** September 23, 2026 - **Apply:** https://www.cybersecurityjobsite.com/logon?PipelinedPage=%2Feditprofile%3FPipelinedPage%3D%252Fjob%252F5561260%252Fsenior-security-consultant%253FAction%253DContinueJobApplication%2523application-form ## About the Role You are dedicated, skilled and knowledgeable. You are passionate about what you do and working with your team to get things done and support the national cyber mission. You should hold a Positive Vetting security clearance., * Must hold a Positive Vetting security clearance. * Ideally hold at least one relevant industry certification, such as SANS ICS515, SANS ICS410, CISA, CRISC, GICSP, or CompTIA Security + (or demonstrate on track to achieving) * Supports interviews or investigations, including on-site visits and stakeholder workshops * Communicates and works with our customers to assist them in effectively managing cyber security risk * Familiar with information security standards, such as the Australian Government Information Security Manual (ISM) and 27001 * Familiar with information security frameworks, such as NIST Cybersecurity Framework * Measures effectiveness of controls in place * Measures business impact associated with systems or processes, via document review or structured questionnaires Business expertise and interpersonal skills * Possess strong written and verbal communication skills * Have demonstrated stakeholder management experience * Demonstrate attention to detail, be proactive and organised * Be able to respond to setbacks in an agile and resilient manner ## Description * Develops security policies, procedures and plans, to ensure effective governance * Acts as a subject matter expert, providing insights and knowledge to our customers * Reviews effectiveness of controls (in relation to known controls frameworks as appropriate) and proposing proportionate security improvements. * Analyses and research security technologies to support the development of innovative solutions. * Assesses risk at the technical or system process level, delivered through the assessment of systems for compliance against defined security control frameworks * Drafts high-quality risk assessments and reports detailing security issues, technical and governance control improvements, and recommendations to address identified security risks * Provides an accurate categorisation of threats, threat actors and vulnerabilities, delivered through the completion of security threat and risk assessments of ICT and/or OT systems * Supervises and mentors junior consultants to support their growth and development * Collaborates with peers across the Digital Intelligence business, both in Australia and overseas, to look for ways to continuously add value to the business, build your professional network, and share experiences * Understands business and information risk context (typical business drivers, cyber security threats and implementation challenges) of our customers * Judges risk at a technical and business process level and clearly articulate both verbally and in writing to key stakeholders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Building Security Champions](https://www.wearedevelopers.com/videos/360-building-security-champions) - [Outsmarting the System: What Game Cheaters Can Teach Us About Cyber Security](https://www.wearedevelopers.com/videos/1396-outsmarting-the-system-what-game-cheaters-can-teach-us-about-cyber-security) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)