Cyber Security Governance Consultant

Nortal
UK
3 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
£63,427.0
Working hours
Regular working hours

Tech stack

Cyber Security CIS Benchmarks

Job description

As a trusted advisor in a multidisciplinary environment, you will work across functions to embed secure-by-design principles, assess cyber workforce requirements, and lead the development of governance policies and controls.

  • Design and implement effective cyber governance structures and risk management processes.
  • Develop organisational models that strengthen governance and streamline cybersecurity operations.
  • Collaborate with multi-disciplinary teams to embed cybersecurity into governance frameworks, considering people, process, and technology.
  • Propose workforce structures and SQEP (Suitably Qualified and Experienced Personnel) requirements for steady-state operations.
  • Define, monitor, and report metrics to measure the effectiveness of cyber governance.
  • Lead continuous improvement initiatives and mentor key personnel within governance functions.
  • Ensure all policies, procedures, and controls are compliant with regulatory standards (NCSC, ISO 27001, NIST, CIS Controls).
  • Identify, assess, and manage risks to project or organisational goals.
  • Build alignment with executive stakeholders, board members, and external partners to ensure accountability and clear decision-making processes.

Requirements

  • A proven track record in cybersecurity risk and governance transformations in complex or government/defence environments.
  • Deep knowledge of cybersecurity frameworks (e.g., NIST, ISO 27001, CIS Controls) and regulatory obligations.
  • Experience designing and implementing cybersecurity governance structures from the ground up.
  • Strong analytical and strategic thinking skills to assess risks and influence operational change.
  • Excellent communication and stakeholder engagement skills
  • Demonstrated ability to manage concurrent projects and priorities under tight deadlines.
  • A passion for innovation and continuous learning in cybersecurity., * Professional certifications: CISSP, CISM, CRISC (or equivalent experience).
  • Minimum 5 years’ experience in cybersecurity transformation, ideally in a defence or maritime context.
  • UK Government security clearance (DV/SC)

Benefits & conditions

  • We live by our values: commit to delivering value and results, take ownership, empower yourself and others, and own your future and growth
  • A collaborative and agile work environment working with industry experts
  • Opportunities for professional development through training and mentorship
  • An international team with a people-oriented culture, work-life balance, and flexible work arrangements.

About the company

At Nortal, we believe in thinking big-creating digital solutions with meaningful, far-reaching impact. With over 2,000 professionals across 26 locations, we’ve spent over two decades helping governments, enterprises, and healthcare institutions in Europe, North America and the Middle East build secure digital organizations, businesses and entire societies.

In the UK, we are proud to empower government and defence organisations to transform their operations, services and digital infrastructure, delivering human-centric, resilient, and secure solutions.

We provide top-tier cybersecurity services that enable organizations to operate with confidence - securing supply chains, ensuring compliance, and fortifying critical systems.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all