We are seeking a highly skilled Automotive Cyber Security Lead to join our Global Transport practice. This role is pivotal in strengthening and expanding our cyber security capability within the global automotive ecosystem, while also supporting cross-domain engagements in rail, maritime, and aviation as needed.The ideal candidate will bring deep knowledge of automotive cyber security, connected and software-defined vehicle technologies, operational technology (OT), embedded systems, relevant international cyber security standards and regulations (including ISO/SAE 21434, UNECE R155, UNECE R156, and ISO 26262), penetration testing methodologies, and the broader transport ecosystem. In addition to technical delivery, the individual will play a key role in supporting business development, building client trust, and elevating NCC Group's profile within the automotive sector.This is a fully remote, client-facing role requiring strong collaboration, communication, and consulting skills.Key ResponsibilitiesTechnical Delivery & Automotive Cyber Security ExpertiseAct as a subject matter expert (SME) for automotive cyber security across global engagements.Lead and deliver complex cyber security assessments across vehicle, engineering, manufacturing, operational technology (OT), and information technology (IT) environments.Apply deep knowledge of automotive-specific standards and frameworks, including: ISO/SAE 21434 (Road Vehicle Cybersecurity Engineering)UNECE R155 (Cyber Security Management System)UNECE R156 (Software Update Management System)ISO 26262 (Functional Safety)Conduct or support penetration testing, vulnerability assessments, architecture reviews, risk assessments, and Threat Analysis and Risk Assessments (TARA) for automotive clients.Provide expert interpretation of cyber security requirements for vehicle manufacturers, suppliers, technology providers, and mobility operators.Ensure security recommendations are aligned with safety, regulatory, operational, and business requirements throughout the vehicle lifecycle.Automotive Domain ExpertiseProvide expert understanding of the automotive ecosystem, including: Connected vehiclesSoftware-defined vehicles (SDVs)Electronic Control Units (ECUs)In-vehicle networks (CAN, LIN, FlexRay, Automotive Ethernet)Telematics and connected servicesElectric vehicle charging infrastructureManufacturing and production environmentsVehicle development, validation, and homologation processesTranslate complex automotive engineering and operational knowledge into training and knowledge-sharing activities for internal teams.Contribute to the development of internal automotive cyber security capabilities, methodologies, and best practices.Maintain awareness of emerging threats, vulnerabilities, regulations, and industry trends affecting the automotive sector.Business Development & Practice GrowthSupport the identification, creation, and growth of automotive cyber security opportunities globally.Help strengthen NCC Group's presence within the automotive sector through: Thought leadership activities, including white papers, webinars, and industry eventsClient engagements and pre-sales supportCollaboration with OEMs, Tier 1 suppliers, mobility providers, and industry bodiesCollaborate with engagement managers and practice leadership to support the development of automotive-focused service offerings.Contribute to bids, proposals, statements of work, and technical scoping activities for prospective customers.Cross-Domain Support (Multi-Modal Transport)Support projects across rail, maritime, and aviation domains where automotive cyber security expertise can add value.Maintain awareness of common OT, embedded, and safety-critical technologies across transport sectors.Promote knowledge sharing and collaboration across the wider Transport Cyber Security practice.Client Engagement & Delivery ExcellenceAct as a trusted advisor to clients, providing clear and actionable cyber security recommendations.Communicate complex technical concepts in a professional and client-friendly manner.Deliver high-quality outputs and maintain strong client satisfaction throughout engagements.Build and maintain positive working relationships with clients and key stakeholders.Skills, Knowledge and ExpertiseTechnical ExperienceProven experience in automotive cyber security, ideally within OEMs, Tier 1 suppliers, mobility providers, automotive technology companies, or a cyber security consultancy.Strong experience working with and applying: ISO/SAE 21434UNECE R155UNECE R156ISO 26262Strong understanding of embedded systems, vehicle electronics, automotive communications networks, connected vehicle platforms, and safety-critical environments.Practical experience conducting or supporting penetration testing and security assessment activities.Experience performing secure architecture reviews, threat modelling, TARA activities, and risk assessments within automotive or transportation environments.Familiarity with automotive development lifecycles, software delivery processes, and regulatory compliance requirements.Domain KnowledgeIn-depth understanding of the automotive ecosystem, including vehicle architectures, connected vehicle platforms, software-defined vehicles, manufacturing environments, supplier ecosystems, and automotive cyber security regulations.Direct experience working within or alongside automotive OEMs, Tier 1 suppliers, mobility service providers, or automotive cyber security programmes.Understanding of vehicle engineering, safety, validation, and homologation processes.Soft Skills & Professional AttributesExcellent communication skills in both technical and non-technical contexts.Strong client-facing and stakeholder management skills.Ability to lead workstreams and influence stakeholders at all levels.Ability to work collaboratively across geographies, teams, and disciplines.Strong consulting mindset with the ability to understand client challenges and provide pragmatic solutions.A passion for coaching, mentoring, and knowledge sharing.Desirable (Not Mandatory)Recognised cyber security certifications such as CISSP, GICSP, ISA/IEC 62443 Cyber Security Expert, OSCP, or GIAC certifications.Automotive cyber security certifications or formal training relating to ISO/SAE 21434, UNECE R155/R156, or automotive engineering disciplines.Experience contributing to industry standards, working groups, or regulatory consultations.Background in automotive engineering, systems engineering, functional safety, or vehicle development.Knowledge of EV ecosystems, charging infrastructure security, and software-defined vehicle architectures.BenefitsWhat do we offer in return? We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits: Flexible Working: Balance your work and personal life with our flexible working options. Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. Green Car Scheme: Drive green and save money with our eco-friendly car scheme. Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments. DepartmentCyber Services and CapabilitiesEmployment TypeFull TimeWorkplace typeHybrid
Transport - Managing Security Consultant in London employer: NCC Group
NCC is an exceptional employer, offering a dynamic work culture that prioritises flexibility and employee well-being in the heart of Cheltenham. With generous holiday allowances, comprehensive financial benefits, and a strong commitment to community engagement, employees are empowered to grow both personally and professionally while contributing to cutting-edge cyber threat intelligence initiatives.