Cyber & Information Assurance Consultant / Senior Consultant / Principal Consultant
Defence | National Security | Cyber Security | Information Assurance
£65,000-£120,000 + benefits | UK Remote / Hybrid | SC Clearance, with ability to obtain DVHelp secure the information, systems and capabilities that matter most.Are you a cyber security, information assurance, risk, security or systems professional looking to apply your expertise to some of the UK’s most complex Defence, Government and National Security challenges?Perhaps you’re a Service Leaver, Veteran or Defence professional with experience of secure information systems, operational communications, cyber security, risk management, assurance or working in complex and highly controlled environments.We are working with a specialist UK organisation delivering cyber-resilient systems and high-assurance digital services to Defence, Government and Critical National Infrastructure customers – environments where controlled, secure and reliable information flow is mission critical.Due to continued growth, we are seeking talented professionals across three levels – Cyber & Information Assurance Consultant, Senior Consultant and Principal Consultant.These are excellent opportunities for people who enjoy understanding complex risks, solving challenging problems, engaging with customers and helping organisations operate securely in demanding environments.
What You’ll Be Working On
Your work could span a broad range of secure and high-assurance environments, including:
- Cyber security and information assurance
- Cyber risk management
- Security governance and assurance
- Secure-by-Design
- Security architecture
- Secure information exchange
- Cross-domain solutions
- Cloud security assurance
- Networks and communications
- Applications and data platforms
- Operational and mission-critical systems
- Defence and Government digital transformation
- High-assurance and regulated environments
You will help customers understand their security risks, assess the effectiveness of controls and evidence, and make informed decisions about how those risks should be treated and managed.
Key Responsibilities
Depending on your level and experience, you could be involved in:
Cyber Risk & Assurance
- Conducting cyber security and information assurance risk assessments.
- Identifying threats, vulnerabilities, impacts and control requirements.
- Developing proportionate risk treatment recommendations.
- Maintaining cyber risk registers, assumptions, dependencies and residual risk positions.
- Supporting formal risk acceptance and escalation activity.
- Providing clear, practical advice to technical and non-technical stakeholders.
Information Assurance
- Supporting assurance of systems, services and information-handling arrangements.
- Assessing compliance against customer, contractual and regulatory requirements.
- Reviewing security documentation, technical evidence and control implementation.
- Supporting security case development and assurance planning.
- Contributing to accreditation, authorisation and approval activity.
- Maintaining traceability between security requirements, controls, evidence and risk decisions.
Security Governance & Secure-by-Design
- Supporting security policies, standards, procedures, governance frameworks and assurance plans.
- Contributing to security governance forums and assurance boards.
- Tracking security actions, risks, decisions and evidence.
- Working with architects, engineers and delivery teams to embed security throughout the lifecycle.
- Reviewing solution designs for security, privacy, resilience and assurance implications.
- Supporting identification of security and non-functional requirements.
- Applying principles including defence-in-depth, least privilege and Zero Trust.
Threat & Vulnerability Assessment
- Assessing credible threat scenarios relevant to customer environments.
- Reviewing vulnerability information and technical findings.
- Interpreting penetration testing, vulnerability scanning and security assessment outputs.
- Evaluating exploitability, business impact and operational consequence.
- Recommending remediation priorities and appropriate compensating controls.
Customer Engagement
- Customer security teams
- Senior risk owners
- Solution and Security Architects
- Systems Engineers
- Project and Delivery Managers
- Software and Platform Engineers
- Product teams
- Suppliers and technology partners
You’ll participate in workshops, assurance reviews and customer briefings, explaining cyber risks and security recommendations in language that both technical and non-technical audiences can understand.
At Senior and Principal level, you’ll increasingly take ownership of customer engagements, assurance work packages and senior stakeholder relationships.
Your Background
We are deliberately open-minded about where your experience has come from. You may have developed your expertise within Defence, Government, National Security, a Defence Prime, specialist consultancy, critical national infrastructure, technology, engineering or another secure/regulated environment. For the Consultant level, we are particularly interested in professionals with experience in cyber security, information assurance, risk management, systems engineering or a related discipline who are ready to take ownership of defined assurance activities. For Senior and Principal positions, we are looking for increasingly experienced professionals with demonstrable experience providing cyber, security, risk or information assurance advice across complex programmes and stakeholder environments. Relevant experience could include:
- Cyber Security
- Information Assurance
- Cyber Risk Management
- Security Architecture
- Security Governance
- Risk & Compliance
- Systems Engineering
- Operational Communications
- Secure Information Systems
- Defence Digital Transformation
- Security Assurance
- Technical or Cyber Consultancy
- Secure/Classified Environments
Experience with ISO 27001, ISO 27005, NCSC Cyber Assessment Framework, NIST Cybersecurity Framework, Cyber Essentials, MOD Defence Standard 05-138 or Government Security Classifications would be advantageous.
Professional qualifications such as CISSP, CISM, CRISC or relevant ISO 27001 qualifications are welcome, but equivalent Defence, operational and professional experience will be highly valued.
Service Leavers & Veterans
Your military experience could be more relevant than you think. Service Leavers and Veterans are particularly encouraged to apply. You don’t necessarily need to have held the exact civilian job title. Military careers can develop highly transferable skills in risk management, operational planning, information assurance, communications, cyber security, engineering, information management, security procedures, capability development and decision-making within complex and constrained environments. If you’ve worked in environments where security, information integrity, operational resilience and risk management really mattered, you may already have many of the foundations required to succeed in cyber and information assurance consultancy. Your experience could have come from military communications, information systems, cyber, engineering, intelligence-supporting environments, operational planning, technical security, risk management or another specialist area. The important thing is the experience underneath your job title. Whether you’re transitioning from the Armed Forces or have already moved into industry, this is an opportunity to translate that experience into a career where you can advise customers, influence security decisions and work on technology supporting UK Defence and National Security.
Why Consider These Opportunities? You’ll have the opportunity to:
- Work on meaningful Defence, Government and Critical National Infrastructure programmes.
- Help secure systems and information that are genuinely mission critical.
- Work alongside cyber specialists, architects, engineers and technical consultants.
- Engage directly with customers and senior stakeholders.
- Develop expertise across cyber risk, information assurance and security governance.
- Gain exposure to Secure-by-Design and high-assurance environments.
- Contribute to emerging technologies, research, innovation and service development.
- Work towards recognised professional qualifications and certifications.
- Progress your career towards Senior Consultant, Principal Consultant, Security Architect, Cyber Risk Lead or Information Assurance leadership roles.
- Contribute to bids, pre-sales and new customer opportunities as your experience develops.
The organisation is continuing to grow and invests in its people, technical capability and future opportunities, with a collaborative culture that values different perspectives, diversity and neurodiversity.
Security & Location
Security Clearance: SC Clearance required, with the ability to obtain DV.
Location: Remote-first, with hybrid working options and attendance at UK office/customer locations as required.
Travel: Regular UK travel may form part of the role, with occasional international travel.
#J-18808-Ljbffr
Cyber & Information Assurance Consultant / Senior Consultant / Principal Consultant employer: Cyber UK
As a leading Financial Services organisation, we pride ourselves on fostering a dynamic and inclusive work culture that prioritises employee growth and development. With a focus on cyber resilience and cloud technologies, our team enjoys competitive rates, flexible working arrangements, and the opportunity to influence strategic initiatives at the highest levels. Join us in Reading, where you will be part of a collaborative environment that values innovation and empowers you to make a meaningful impact in the fight against cyber threats.