Senior Cyber Resilience Consultant (GRA)
Role details
Job location
Tech stack
Job description
-
Lead delivery of proactive incident response preparedness activities including Incident Response Planning, maturity assessments and exercises including Tabletop (TTX), Live Play and other bespoke activities.
-
Lead cyber governance, risk and assurance engagements, applying strong knowledge of cyber threats, risks, controls and mitigations to deliver effective security outcomes for our clients.
-
Review and assess client documentation, processes and governance in relation to Cyber Incident Response, preparedness and alignment with Business Continuity and Emergency Response capabilities.
-
Design, plan and deliver a variety of exercises to meet the needs of organisations across diverse industries and sectors.
-
Engage and communicate with stakeholders from board and executive through to operational and other responders to understand their threat landscape and business context, and roles and responsibilities.
-
Deliver quality reports, with actionable information tailored to the specific needs of clients and capturing the key learnings from assessments and exercises.
-
Contribute to continuous improvement of service offerings, delivery methodologies and internal team knowledge by sharing insights and learning gained from client engagements.
-
Support the wider delivery of cyber governance risk and assurance activities and delivery working with other service and client leads and functions.
-
Contribute to thought leadership and continuous improvement by staying current with industry developments and sharing knowledge across the cyber security community.
-
Demonstrate strong communication, stakeholder management and mentoring skills, upholding the highest standards of integrity and professionalism.
Requirements
-
Extensive experience in designing, leading and delivering cyber governance, risk and assurance outcomes, with a proven track record of successfully leading cyber incident response and resilience outcomes.
-
Strong knowledge of recognised cyber security frameworks and standards, including MITRE ATT&CK, ISO/IEC 27001, NIS, NIST, and UK Government Functional Standards, with demonstrable experience applying these to relevant cyber roles and engagements.
-
Confident communicator, able to clearly articulate cyber risk and the value of security investment to senior leaders, while mentoring and guiding teams to deliver high-quality outcomes.
-
Hold relevant academic or professional qualifications, such as, an MSc in cyber security or related specialism, Cyber Essentials Assessor, Cyber Assurance Assessor, CISM, CISSP, PCIRM or ISO/IEC 27001 Lead Implementer or Lead Auditor certification.
-
Hold, or are actively working towards, a relevant cyber resilience, cyber incident response, or similar qualification or accreditation.
-
Eligible to work in the UK and able to obtain and maintain UK security clearance.
What we look for in our people
-
Strong alignment with FSP values and ethos
-
Commitment to teamwork, quality and mutual success
-
Proactivity with an ability to operate with pace and energy
-
Strong communication and interpersonal skills
-
Excellent planning and organisational skills
-
Dedication to excellence and quality