> Markdown version of [/jobs/ext/66954-cyber-assurance-lead-consulting](https://www.wearedevelopers.com/jobs/ext/66954-cyber-assurance-lead-consulting). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Assurance Lead, Consulting - **Company:** Cognizant (nasdaq:ctsh) - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Supervisory Control and Data Acquisition (SCADA), Sherwood Applied Business Security Architecture, Information Technology - **Published:** May 28, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/x/37781700/ ## About the Role Previous CISO experience, or extensive advisory / Deputy CISO experience at an equivalent level within a CNI organisation. Demonstrable track record of developing and delivering cyber maturity strategies and roadmaps in complex, regulated environments. Deep expertise in cyber security frameworks: NIST CSF, NCSC CAF, ISO 27001/27002, IEC 62443. Strong understanding of the UK CNI regulatory landscape: NIS Regulations, OFWAT security requirements, NCSC guidance, and emerging NIS2-aligned obligations. Experience designing and overseeing Cyber Assurance Frameworks including GRC, third-party risk, policy governance, and audit management. Proven ability to communicate cyber risk in business terms at Board and Executive level. Knowledge of both IT and OT security environments, appreciating the distinct risk profiles of operational technology in water or utilities. Experience managing and developing high-performing cyber security teams. Strong interpersonal, leadership, and influencing skills across technical and non-technical stakeholders. Desirable Experience CISO experience specifically within the UK water sector or equivalent regulated utility. Experience leading or responding to NCSC CAF assessments or formal NIS regulatory audits. Exposure to OT/SCADA cyber security assurance in water treatment or distribution environments. Non-executive advisory or board-level cyber governance experience. Published thought leadership or active participation in water sector cyber security forums (e.g. Water Industry Cyber Security). CISSP, CISM, SABSA (CSA), or equivalent senior security certifications., Degree in Cyber Security, Information Security, Computer Science, or equivalent (Masters preferred). CISSP, CISM, or SABSA Chartered Security Architect certification strongly preferred. SC / DV security clearance required or eligible. ## Description We are seeking an exceptional Cyber Assurance Lead who brings CISO-level expertise and deep CNI sector experience to guide our organisation through a comprehensive cyber maturity transformation. This senior role is accountable for defining and driving the cyber assurance strategy, overseeing the cyber maturity roadmap, and providing best-practice leadership across the full spectrum of cyber security governance, risk, and compliance (GRC). The successful candidate will have either served as a CISO or worked extensively at CISO advisory level within CNI environments, with the credibility and authority to influence at Board and Executive Committee level whilst translating strategy into operational delivery., Lead the design and delivery of an enterprise-wide Cyber Maturity Assessment, benchmarking the organisation against NIST CSF, NCSC CAF, ISO 27001, and IEC 62443. Develop and own a multi-year Cyber Maturity Roadmap, prioritising investments and improvements based on risk appetite, regulatory obligations, and operational impact. Define and implement a comprehensive Cyber Assurance Framework covering governance, policy, risk management, third-party assurance, and technical control validation. Act as the principal cyber security advisor to the CISO, Executive Committee, and Board, providing clear, risk-informed reporting and strategic recommendations. Oversee second-line cyber assurance activities: control effectiveness testing, penetration testing governance, audit management, and exception handling. Lead engagement with regulators including the NCSC, OFWAT, and Defra on cyber resilience obligations, CAF submissions, and improvement plans. Drive the development and embedding of cyber security best practices across IT, OT, and supply chain domains. Establish cyber security KPIs and metrics, developing dashboards and reporting mechanisms for Board, CISO, and operational audiences. Manage and develop the cyber assurance team, fostering a culture of continuous improvement and learning. Support procurement and contract assurance, ensuring cyber security requirements are embedded in vendor and supply chain arrangements. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)