At a Glance
- Tasks: Lead security incident management and ensure effective governance across multiple suppliers.
- Company: Join a leading organisation focused on security and operational excellence.
- Benefits: Competitive pay, inclusive culture, and opportunities for professional growth.
- Other info: Diverse and inclusive workplace with a commitment to equality.
- Why this job: Make a real impact in security governance and enhance your leadership skills.
- Qualifications: Experience in security incident management and strong stakeholder engagement skills.
The predicted salary is between 53085 - 64881 £ per year.
Clearance: SC Cleared
Location: Inverness or Preston | 5 days onsite
Initial Contract to 31/03/2027
Pay: £500 - £600
Status: Inside IR35
Role Description: The Senior Security Incident Management Consultant operates within the Operational Integrator (OI) function and provides governance, leadership, assurance, and strategic oversight of security incident management across a complex multi-supplier environment. The role is responsible for ensuring suppliers manage security incidents consistently, effectively, and in accordance with client policy, regulatory obligations, and operational risk requirements. Acting as the primary OI lead for incident governance, the consultant provides a consolidated view of incident risk, drives supplier accountability, and supports continual improvement across the incident management lifecycle.
Key Responsibilities:
- Security Incident Governance
- Own and govern the security incident management framework across suppliers
- Define and maintain incident classification criteria, escalation models, and reporting standards
- Major incident governance processes
- Ensure alignment to client policies, regulatory obligations, and security controls
- Supplier Governance & Performance Management
- Act as the primary OI lead for security incident governance
- Challenge, validate, and assure supplier incident management processes
- Drive consistency in reporting, escalation, communications, and evidence standards
- Manage escalations relating to significant or recurring incidents
- Incident Risk & Executive Oversight
- Maintain visibility of security incident exposure across all suppliers
- Ensure major incidents receive appropriate governance attention
- Support risk-based decision making through accurate incident reporting
- Provide oversight of supplier corrective and preventative actions
- Reporting & Executive Visibility
- Produce consolidated security incident reporting across suppliers
- Provide insight into incident trends, response performance, SLA adherence, and recurring root causes
- Support governance boards, service review meetings, and client security leadership
- Assurance & Evidence Management
- Define incident management evidence requirements
- Ensure traceability across detection, escalation, investigation outcomes, recovery activities, and closure decisions
- Support audits, assurance reviews, and regulatory inspections
- Post-Incident Review & Continuous Improvement
- Coordinate governance of Post Incident Reviews (PIRs)
- Ensure suppliers provide root cause analysis, corrective actions, and improvement activities
- Identify opportunities to improve incident governance, reporting, and operational effectiveness
Your skills and experience:
- Essential
- Significant experience in Security Incident Management, Cyber Governance, Service Management, or GRC roles
- Strong understanding of security incident lifecycles, major incident management, and security reporting and governance
- Experience working within complex multi-supplier environments
- Strong stakeholder engagement and supplier management skills
- Experience presenting incident risk information to senior stakeholders
- Desirable
- Knowledge of NIST Cyber Security Framework (CSF), NCSC guidance, ITIL, Major Incident Management, and ISO 27001
- Experience supporting security assurance and audit activities
- Experience in Defence, Government, or highly regulated sectors
Key Deliverables:
- Security Incident Management Framework
- Consolidated supplier incident reporting
- Executive incident dashboards
- Governance and assurance reporting packs
- Post Incident Review governance outputs
- Continuous improvement roadmap
Role Definition: The role governs and assures security incident management across suppliers, ensuring incidents are consistently escalated, evidenced, reviewed, and reported to the client through a controlled and audit-ready process, without performing operational security response activities.
Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.
Security Operations Lead - in London employer: Sanderson Government and Defence
Join a forward-thinking organisation that values user-centred design and offers a collaborative work environment in the heart of London. With a strong commitment to diversity and inclusion, we provide our employees with opportunities for professional growth while working on impactful government projects that shape digital services. Enjoy a flexible working model that balances on-site collaboration with remote work, ensuring a rewarding and meaningful career path.
Contact Details:
Sanderson Government and Defence Recruitment Team