Cyber and Information Assurance Consultant in Nottingham

Cyber and Information Assurance Consultant in Nottingham

Nottingham Full-Time 63000 - 77000 £ / year (est.) Working from home possible
NEXOR LIMITED

At a Glance

  • Tasks: Support customers in managing cyber security risks and provide clear risk-based recommendations.
  • Company: Join a forward-thinking tech company focused on cyber security and information assurance.
  • Benefits: Enjoy remote work, competitive salary, and opportunities for professional development.
  • Other info: Dynamic role with excellent career progression and mentoring opportunities.
  • Why this job: Make a real impact in cyber security while working with diverse teams and technologies.
  • Qualifications: Experience in cyber security or related fields; strong communication skills are essential.

The predicted salary is between 63000 - 77000 £ per year.

The Cyber and Information Assurance Consultant supports customers in identifying, assessing and managing cyber security and information assurance risks across complex digital, operational and high‑assurance environments. The role combines consultancy, risk assessment, security assurance, governance and stakeholder engagement. Work may span secure information exchange, cross-domain solutions, cloud services, networks, applications, data platforms and operational systems. The postholder translates security obligations, business needs, threat information and technical evidence into clear risk‑based recommendations. The role suits a cyber security, risk, assurance or systems professional seeking broader customer‑facing responsibility across defence, government and critical national infrastructure.

Key Responsibilities

  • Conduct cyber security and information assurance risk assessments.
  • Identify threats, vulnerabilities, impacts and control requirements.
  • Develop proportionate risk treatment recommendations.
  • Maintain cyber risk registers, assumptions, dependencies and residual risk positions.
  • Support formal risk acceptance and escalation activity.
  • Provide clear advice to technical and non-technical stakeholders.

Information Assurance

  • Support assurance of systems, services and information‑handling arrangements.
  • Assess compliance against customer, contractual and regulatory requirements.
  • Review security documentation, technical evidence and control implementation.
  • Support security case development and assurance planning.
  • Contribute to accreditation, authorisation and approval activity.
  • Maintain traceability between requirements, controls, evidence and risk decisions.

Security Governance

  • Support development and maintenance of security policies, standards, procedures, governance frameworks, assurance plans, and security management plans.
  • Contribute to security governance forums and assurance boards.
  • Track security actions, risks, decisions and evidence.
  • Support senior ownership and oversight of cyber security risk.

Secure‑by‑Design Support

  • Work with architects, engineers and delivery teams to embed security throughout the lifecycle.
  • Review solution designs for security, privacy, resilience and assurance implications.
  • Support identification of security requirements and non‑functional requirements.
  • Apply defence‑in‑depth, least‑privilege and Zero Trust principles.
  • Ensure security considerations form part of design, build, test, deployment and operation.

Threat and Vulnerability Assessment

  • Assess credible threat scenarios relevant to customer environments.
  • Review vulnerability information and technical findings.
  • Support interpretation of penetration test, vulnerability scan and security assessment outputs.
  • Evaluate exploitability, business impact and operational consequence.
  • Recommend remediation priorities and compensating controls.
  • Work with customer security teams, solution and security architects, project and delivery managers, software and platform engineers, product teams, suppliers and technology partners.
  • Participate in workshops, assurance reviews and customer briefings.
  • Explain cyber security risks and control recommendations in accessible language.
  • Build trusted and professional customer relationships.

Continuous Improvement and Professional Development

  • Maintain awareness of emerging cyber threats, regulation and assurance practice.
  • Contribute to internal methods, templates and guidance.
  • Share knowledge across Nexor communities of practice.
  • Support lessons identified and service improvement activity.
  • Work towards recognised cyber security and assurance qualifications.

Essential Technical Knowledge

  • Cyber Security and Assurance: Information assurance, security governance, security controls, threat and vulnerability assessment, security lifecycle principles, residual risk and risk acceptance, assurance evidence and traceability.
  • Frameworks and Standards: Working knowledge of ISO/IEC 27001, ISO/IEC 27005, NCSC Cyber Assessment Framework, NIST Cybersecurity Framework, MOD Defence Standard 05-138, Government Security Classifications.
  • Experience within high‑assurance or regulated environments.
  • Exposure to secure information exchange or cross‑domain solutions.
  • Experience supporting accreditation or authority‑to‑operate processes.
  • Familiarity with MOD security and assurance practices.
  • Experience with cloud security assurance.
  • Knowledge of data protection and privacy impact assessment.
  • Current SC clearance.
  • Experience supporting bids, proposals or pre‑sales activity.

Professional Qualifications

  • A degree, degree apprenticeship or equivalent experience in a relevant discipline, including Cyber Security, Information Security, Computer Science, Software Engineering, Electronic Engineering, Mathematics, or another relevant science, technology or engineering discipline.
  • Progress towards, or interest in obtaining, CISSP, CISM, CRISC, NCSC Certified Cyber Professional, Chartered Cyber Security Professional, or a risk management qualification.

Development Path

  • The role provides progression towards Senior Cyber and Information Assurance Consultant, Security Architect, Information Assurance Lead, Security Assurance Manager, or Head of Cyber Assurance.
  • Development support may include mentoring from senior cyber consultants and architects, customer and programme exposure, security architecture and assurance training, support towards professional certification, opportunities to lead defined assurance work packages, participation in internal research and service development, and access to cyber and architecture communities of practice.

Measures of Success

  • Quality and clarity of assurance deliverables.
  • Effective identification and communication of cyber risks.
  • Completion of assigned work against customer objectives.
  • Constructive participation in assurance and design reviews.
  • Effective management of risks, actions and evidence.
  • Positive customer and stakeholder feedback.
  • Growth in assurance and domain competence.
  • Contribution to successful bids and customer engagements.
  • Increasing ownership of cyber assurance work packages.
  • Progress towards relevant professional qualifications.

Reporting Line

The role reports to the Head of Services and/or Principal Cyber Consultant. Day‑to‑day direction may also come from a Security Architect, Programme Security Lead or Project/Delivery Manager.

Eligibility for UK Security Check clearance. Compliance with customer and Nexor information‑handling requirements. Compliance with Nexor security, quality and engineering procedures. Appropriate handling of customer, partner and programme information. Willingness to work within secure environments where required.

The role holder will be expected to role model and champion the Nexor core values which are: Focus, Adaptable, Respect and Collaboration.

This job description is a guide to the work you may be required to undertake but does not form part of your contract of employment and may change from time to time to reflect changing circumstances.

Cyber and Information Assurance Consultant in Nottingham employer: NEXOR LIMITED

Nexor Limited is an exceptional employer that fosters a collaborative and innovative work culture, particularly for those in the Defence and National Security sectors. With a strong emphasis on employee growth, we offer comprehensive training and development opportunities, ensuring that our team members can thrive in their roles while contributing to meaningful projects. Located in a dynamic environment, we provide unique advantages such as flexible working arrangements and a commitment to work-life balance, making us an attractive choice for professionals seeking rewarding careers.

NEXOR LIMITED

Contact Details:

NEXOR LIMITED Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber and Information Assurance Consultant in Nottingham

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including NEXOR LIMITED, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through NEXOR LIMITED

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at NEXOR LIMITED. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cyber and Information Assurance Consultant in Nottingham

Cyber Security
Information Assurance
Risk Assessment
Threat and Vulnerability Assessment
Security Governance
Stakeholder Engagement
Security Documentation

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at NEXOR LIMITED insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to NEXOR LIMITED that you’re committed to staying ahead in the game.

How to prepare for a job interview at NEXOR LIMITED

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at NEXOR LIMITED to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at NEXOR LIMITED.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.