Cyber Security Assurance Consultant - Contract

SR2
Manchester, UK
1 day ago
Apply on find.jobs
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Cloud Computing Security Cyber Security Identity and Access Management Secure Coding Software Vulnerability Management Data Lineage Data Analytics

Job description

The role sits between cyber security, risk, controls and data, ensuring security metrics and technical evidence provide an accurate and defensible view of control effectiveness and residual risk., You’ll work with security, risk, data and technology teams to:

  • Assess the design and operating effectiveness of cyber controls
  • Review security metrics, KRIs/KPIs and underlying evidence
  • Translate technical findings into clear residual risk assessments
  • Validate security reporting against source data, risk registers, audit findings and incidents
  • Identify gaps across controls, data quality and security reporting
  • Review data lineage, security telemetry and integrations to challenge data completeness
  • Define acceptance criteria and support testing/UAT
  • Produce concise assurance findings and recommendations
  • Facilitate workshops and challenge technical and senior stakeholders constructively

Requirements

  • Cyber Security Risk & Assurance / GRC
  • Security controls testing and assurance
  • Assessing control effectiveness and residual risk
  • Cyber metrics, KRIs/KPIs and risk reporting
  • Data-driven security assurance
  • Investigating conflicting technical evidence
  • Working knowledge across several security domains such as vulnerability management, cloud security, IAM, endpoint security, secure development, third-party risk or incident management
  • Understanding structured data, APIs, data lineage and security telemetry
  • Defining acceptance criteria and supporting testing/UAT
  • Strong stakeholder management and workshop facilitation
  • Producing clear, defensible assurance and governance reporting

Relevant certifications such as CISSP, CISM, CRISC, CISA or ISO 27001 would be beneficial but aren’t essential.

This would suit a hands-on Cyber Risk, Security Assurance, Technology Risk or GRC specialist who can interrogate technical evidence, challenge assumptions and clearly explain what the findings mean from a risk perspective.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on find.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

9:51 min

Live demonstration of dynamic data redaction plugins

Tom Kaltofen Tom Kaltofen +1 · Europe 2026 Virtual

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all