At a Glance
- Tasks: Support customers in managing cyber security risks and provide clear risk-based recommendations.
- Company: Join a forward-thinking tech company focused on cyber security and information assurance.
- Benefits: Enjoy remote work, competitive salary, and opportunities for professional development.
- Other info: Dynamic role with excellent career progression and mentoring opportunities.
- Why this job: Make a real impact in cyber security while working with diverse teams and technologies.
- Qualifications: Experience in cyber security or related fields; strong communication skills are essential.
The predicted salary is between 63000 - 77000 £ per year.
The Cyber and Information Assurance Consultant supports customers in identifying, assessing and managing cyber security and information assurance risks across complex digital, operational and high‑assurance environments. The role combines consultancy, risk assessment, security assurance, governance and stakeholder engagement. Work may span secure information exchange, cross-domain solutions, cloud services, networks, applications, data platforms and operational systems. The postholder translates security obligations, business needs, threat information and technical evidence into clear risk‑based recommendations. The role suits a cyber security, risk, assurance or systems professional seeking broader customer‑facing responsibility across defence, government and critical national infrastructure.
Key Responsibilities
- Conduct cyber security and information assurance risk assessments.
- Identify threats, vulnerabilities, impacts and control requirements.
- Develop proportionate risk treatment recommendations.
- Maintain cyber risk registers, assumptions, dependencies and residual risk positions.
- Support formal risk acceptance and escalation activity.
- Provide clear advice to technical and non-technical stakeholders.
Information Assurance
- Support assurance of systems, services and information‑handling arrangements.
- Assess compliance against customer, contractual and regulatory requirements.
- Review security documentation, technical evidence and control implementation.
- Support security case development and assurance planning.
- Contribute to accreditation, authorisation and approval activity.
- Maintain traceability between requirements, controls, evidence and risk decisions.
Security Governance
- Support development and maintenance of security policies, standards, procedures, governance frameworks, assurance plans, and security management plans.
- Contribute to security governance forums and assurance boards.
- Track security actions, risks, decisions and evidence.
- Support senior ownership and oversight of cyber security risk.
Secure‑by‑Design Support
- Work with architects, engineers and delivery teams to embed security throughout the lifecycle.
- Review solution designs for security, privacy, resilience and assurance implications.
- Support identification of security requirements and non‑functional requirements.
- Apply defence‑in‑depth, least‑privilege and Zero Trust principles.
- Ensure security considerations form part of design, build, test, deployment and operation.
Threat and Vulnerability Assessment
- Assess credible threat scenarios relevant to customer environments.
- Review vulnerability information and technical findings.
- Support interpretation of penetration test, vulnerability scan and security assessment outputs.
- Evaluate exploitability, business impact and operational consequence.
- Recommend remediation priorities and compensating controls.
Continuous Improvement and Professional Development
- Maintain awareness of emerging cyber threats, regulation and assurance practice.
- Contribute to internal methods, templates and guidance.
- Share knowledge across Nexor communities of practice.
- Support lessons identified and service improvement activity.
- Work towards recognised cyber security and assurance qualifications.
Professional Qualifications
- A degree, degree apprenticeship or equivalent experience in a relevant discipline, including Cyber Security, Information Security, Computer Science, Software Engineering, Electronic Engineering, Mathematics, or another relevant science, technology or engineering discipline.
- Progress towards, or interest in obtaining: CISSP, CISM, CRISC, NCSC Certified Cyber Professional, Chartered Cyber Security Professional, or a risk management qualification.
Development Path
- The role provides progression towards Senior Cyber and Information Assurance Consultant, Security Architect, Information Assurance Lead, Security Assurance Manager, or Head of Cyber Assurance.
- Development support may include mentoring from senior cyber consultants and architects, customer and programme exposure, security architecture and assurance training, support towards professional certification, opportunities to lead defined assurance work packages, participation in internal research and service development, and access to cyber and architecture communities of practice.
Measures of Success
- Success within the role shall be measured through quality and clarity of assurance deliverables, effective identification and communication of cyber risks, completion of assigned work against customer objectives, constructive participation in assurance and design reviews, effective management of risks, actions and evidence, positive customer and stakeholder feedback, growth in assurance and domain competence, contribution to successful bids and customer engagements, increasing ownership of cyber assurance work packages, and progress towards relevant professional qualifications.
Reporting Line
- The role reports to the Head of Services and/or Principal Cyber Consultant. Day‑to‑day direction may also come from a Security Architect, Programme Security Lead or Project/Delivery Manager.
Security and Compliance Requirements
- Eligibility for UK Security Check clearance.
- Compliance with customer and Nexor information‑handling requirements.
- Compliance with Nexor security, quality and engineering procedures.
- Appropriate handling of customer, partner and programme information.
- Willingness to work within secure environments where required.
Nexor Values
The role holder will be expected to role model and champion the Nexor core values which are: Focus, Adaptable, Respect and Collaboration.
This job description is a guide to the work you may be required to undertake but does not form part of your contract of employment and may change from time to time to reflect changing circumstances.
Cyber and Information Assurance Consultant in Nottingham employer: NEXOR LIMITED
Nexor Limited is an exceptional employer that fosters a collaborative and innovative work culture, particularly for those in the Defence and National Security sectors. With a strong emphasis on employee growth, we offer comprehensive training and development opportunities, ensuring that our team members can thrive in their roles while contributing to meaningful projects. Located in a dynamic environment, we provide unique advantages such as flexible working arrangements and a commitment to work-life balance, making us an attractive choice for professionals seeking rewarding careers.