Cyber Security Consultant

CBS Butler Limited
London, UK
2 months ago

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Compensation
£143,000.0 - £150,800.0
Working hours
Regular working hours

Tech stack

Amazon S3 Cyber Security Software Vulnerability Management Information Security Management System

Job description

Cyber Security Consultant - Incident and Vulnerability Management

+6 months +

+1 day a week on site in London/Preston/Birmingham - 4 days WFH

+Inside IR35

+£550 - £580 a day

+SC cleared role - must have current active clearance

+Sole British nationals only due to nature of the project

Role Description:

Security Incident & Vulnerability Management Consultant (Operational Integrator/SIAM - Transition Role)

UK Sole National ONLY Security Clearance required

Role Summary The Security Incident & Vulnerability Management Consultant operates within the Operational Integrator (OI) function to support the transition to a multi-supplier (SIAM) model within a Defence environment. The role focuses on understanding, aligning and governing existing high-severity security incident management (S3/S4) and vulnerability management processes across suppliers. Ensuring a consistent, risk-based approach in line with client policy and regulatory requirements, supported by appropriate evidence. The outcome is a coherent, evidence-driven view of security risk, covering both active incidents and underlying vulnerabilities, with processes standardised and ready for BAU handover. This is a governance and coordination role, not a hands-on SOC, incident response, or vulnerability remediation function.Key Responsibilities

  • Align and standardise supplier processes for high-severity incidents (S3/S4) and vulnerability management.
  • Establish governance for incident severity, escalation, vulnerability prioritisation (CVSS, KEV, EPSS), and risk acceptance.
  • Coordinate multiple suppliers to ensure consistent delivery and compliance.
  • Govern major incident life cycle activities, including escalation, communication, reporting, and assurance.
  • Oversee vulnerability management from identification through remediation and closure.
  • Define audit-ready evidence requirements and ensure alignment with ISMS and control frameworks.
  • Deliver governance reporting and support transition to BAU operations.

Essential Skills & Experience

  • Experience in Cyber Security Governance, Incident Management, or Vulnerability Management.
  • Strong understanding of incident response and vulnerability management life cycles.
  • Experience working within multi-supplier or SIAM environments.
  • Ability to interpret and govern SOC and vulnerability management outputs.
  • Knowledge of NIST CSF, NCSC guidance, or UK Government security frameorks.
  • Experience within Defence or other highly regulated environments.
  • Exposure to ISMS, audit, assurance, and ITIL practices.

Requirements

  • Experience in Cyber Security Governance, Incident Management, or Vulnerability Management.
  • Strong understanding of incident response and vulnerability management life cycles.
  • Experience working within multi-supplier or SIAM environments.
  • Ability to interpret and govern SOC and vulnerability management outputs.
  • Knowledge of NIST CSF, NCSC guidance, or UK Government security frameorks.
  • Experience within Defence or other highly regulated environments.
  • Exposure to ISMS, audit, assurance, and ITIL practices.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on computerjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:58 min

Prioritizing security over rapid feature delivery

Jakub Andrzejewski · WWC 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:43 min

The enduring legacy of the amazon S3 storage API

Chris Heilmann +3 · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

4:25 min

The growing power and security responsibility of developers

Tino Sokic · WWC 2023

Videos

See all

Related articles

See all