At a Glance
- Tasks: Lead and deliver complex cyber security consulting projects while shaping the practice's future.
- Company: Join a unique consultancy focused on making cyber security accessible and impactful.
- Benefits: Enjoy flexible remote work, meaningful leave, healthcare support, and professional development opportunities.
- Other info: Be part of a diverse team committed to improving representation in the industry.
- Why this job: Combine hands-on consulting with leadership to influence and grow a thriving practice.
- Qualifications: Significant experience in cyber security consultancy and strong commercial understanding required.
The predicted salary is between 63000 - 77000 £ per year.
Cyber Chain Alliance was founded from a desire to do consultancy differently. Not louder. Not bigger. Just better. We believe cyber should be accessible. That organisations deserve advice that fits their reality. And that consultants deserve autonomy, progression and the chance to influence the direction of the business they’re part of.
We’re entering a new stage of growth and we’re looking for a Lead Cyber Security Consultant who wants to play a key role in what comes next.
The role in real terms:
- This is a senior, hands-on consulting role – but with broader responsibility for helping us run and develop our Consulting Practice.
- You’ll continue to lead and personally deliver complex client engagements across areas such as CAF, ISO 27001 (including full end-to-end implementation), ISO 42001, NIST CSF and Cyber Incident Exercising, advising clients on governance, risk and assurance challenges.
- You’ll take ownership of engagements from scoping through to completion. You’ll assess controls, identify risks, design practical improvements and work closely with senior stakeholders to turn complex requirements into clear, actionable outcomes.
- Working closely with our Practice Director, you’ll act as a key deputy across the Consulting Practice. You’ll provide day-to-day support and direction to the consulting team, maintain visibility of delivery and resourcing, help resolve issues and ensure we continue to deliver consistently high-quality work for our clients.
- You’ll also bring a strong understanding of the commercial mechanics of consultancy. You’ll contribute to P&L performance, forecasting, utilisation and capacity planning. You’ll scope and price work, review Statements of Work and understand the relationship between what we sell, what it costs us to deliver and the margin we achieve.
We’re looking for someone who has done this before. Someone who understands not only how to deliver great consulting work, but what it takes to run a successful consulting practice. You’ll still be close to clients. You’ll still deliver. But you’ll also have a much wider view of the practice and a meaningful role in how we operate, perform and grow.
What makes this different:
- This isn't a move away from consulting into management. It’s an opportunity to combine the two.
- You’ll remain hands-on and client-facing while taking on genuine leadership and commercial responsibility. You’ll be close to the decisions around our people, our clients, our pipeline and how we grow the practice.
- You won’t sit several layers removed from decision-making. You’ll work directly with the Practice Director, with the autonomy and trust to make things happen.
We are remote-first and genuinely flexible. We care about outcomes, not presenteeism. Autonomy isn’t a perk here, it’s part of how we work.
Built for real life:
We’ve designed our approach to benefits and flexibility with our people in mind, recognising that life doesn’t look the same for everyone. Some of our team are building families. Some are caring for others. Some are deepening their expertise. Some are exploring leadership. What works at one stage of life may not work at another, and we try to reflect that in how we support our people. That includes meaningful leave, strong family support, healthcare and wellbeing provision, income protection, pension contribution, professional development investment and space to step back when needed. More importantly, it includes a culture where those things are genuinely usable without explanation or apology. People stay because they feel supported. Because there’s balance. Because it feels sustainable.
Who we’re looking for:
- You’ll bring significant experience within cyber security consultancy, with the credibility and capability to personally lead complex client engagements.
- You’ll have strong hands-on experience across governance, risk and assurance frameworks, with particular depth across areas such as CAF, ISO 27001 and NIST, and the ability to take clients through complex programmes from assessment through to implementation and improvement.
- But technical and delivery experience alone won't be enough. You’ll also have proven experience of the commercial and operational side of consulting. You’ll understand P&L, forecasting, utilisation, capacity and engagement profitability, and you’ll have experience scoping and pricing consulting work and developing or reviewing Statements of Work.
- You’ll have experience supporting or leading consulting teams and be comfortable providing direction, coaching and constructive challenge when needed.
- You’ll be credible with clients at all levels and equally comfortable discussing delivery with a consultant, commercial performance with a Practice Director or an emerging challenge with a senior client stakeholder.
- Relevant certifications such as CISSP, CISM, ISO 27001 Lead Implementer or Lead Auditor are expected, or you’ll be working towards an equivalent.
- Most of all, you’ll be aligned with our values. Curious. Accountable. Relationship-focused. Commercially aware. Willing to take ownership and help build something, not just deliver against it.
If you’re an experienced cyber consultant who enjoys delivery but wants greater influence over how a consulting practice operates, develops and grows, this could be the next step. We’re building a sustainable, high-performing consultancy that does great work and gives good people room to make an impact. And we’d love you to be part of it.
About CCACCA is a specialist cyber consultancy built on the idea that security doesn’t need to be intimidating to be effective. We help organisations strengthen governance, manage risk and build maturity in a way that fits their context. We’re proud of the diversity of thought within our team. Different professional backgrounds, different routes into cyber, different ways of approaching problems. That mix is intentional. It challenges assumptions and improves outcomes for our clients. As co-founders of community initiatives such as Cyber House Party, we’re also committed to improving representation and creating opportunities within the industry. We’re not trying to be the biggest organisation in the room. We’re focused on building a sustainable, high-performing consultancy that does good work and gives people room to grow.
Please Note: This is a UK-based role. While we operate as a remote-first business, you will be expected to travel to client sites across the UK when required as part of your role. For this reason, applicants must be based in the UK and have the right to work in the UK. We are unable to consider applications from candidates based outside the UK.
Lead Cyber Security Consultant | Lead Delivery. Help Shape the Practice in Norwich employer: Cyber Chain Alliance
At Cyber Chain Alliance, we pride ourselves on being an exceptional employer that values innovation and collaboration. As an Executive Assistant to the CEO, you'll play a pivotal role in shaping our fast-growing consultancy, with opportunities for personal and professional growth while working alongside a dynamic leadership team. Our remote-first culture encourages regular in-person engagement across the UK, fostering a supportive environment where your contributions truly make a difference.