At a Glance
- Tasks: Support clients in implementing security risk assessments and best practices.
- Company: Dynamic cybersecurity consultancy with a focus on innovation and collaboration.
- Benefits: Flexible remote work, comprehensive benefits, and continuous learning opportunities.
- Other info: Join a diverse team committed to equality and professional growth.
- Why this job: Make a real impact in cybersecurity while growing your skills in a supportive environment.
- Qualifications: Experience in cyber security, strong analytical skills, and relevant certifications.
The predicted salary is between 65000 - 80000 £ per year.
Clearance: SC
Salary: £65k - £80k + Package
Location: Remote first with occasional travel to customer site
The Role in a Nutshell:
In this role you'll work within the Consulting team, supporting new and existing clients across various sectors to define and implement security risk assessment and best practice solutions that match their requirements. You'll work in close partnership with clients to ensure the delivery of expert services by complementing their in-house Information and Cyber Security resources, combining expertise in information security, solution architecture and business advice.
As a Senior Cyber Security Consultant, you will be responsible for the identification of risks relating to Security Architecture, maintaining an awareness of published vulnerabilities and best practices across various platforms, especially cloud infrastructures. Working across the business and multiple technology platforms, you will play a key role in ensuring clients make the best use of their existing technology and make proportionate, risk-informed decisions, ensuring protection of client assets and transformation of their security architecture. This role forms part of the wider Consultancy team and will work cross-functionally with the Delivery Manager and others to support and assure project delivery through all phases of the agile workflow.
The Impact You'll Make:
- Providing expert advice on cyber risk management, assessment principles and frameworks, such as ISO27005 and the NIST Risk Management Framework.
- Working with multi-disciplinary teams, helping to ensure that products are delivered in a secure manner that is aligned with the wider business risk appetite.
- Managing and supporting risk identification, assessment, remediation and risk treatment for digital systems, applications and infrastructure.
- Identifying and validating technical, procedural, physical and personnel security controls, making recommendations to address security vulnerabilities and control weaknesses.
- Facilitating cyber risk workshops and threat modelling to identify and assess risks that arise from solution architectures.
- Supporting the scoping of IT Health Checks, which will identify principal security concerns for service lines.
- Reviewing outcomes of the ITHC and providing advice and guidance, and where required production of an action plan for vulnerabilities identified with clear recommendations and outcomes to mitigate and address.
- Producing informative and succinct reporting that clearly articulates any identified vulnerabilities, associated risks, controls and risk treatment activity.
- Producing residual risk registers.
- Providing accurate and pragmatic remediation/risk management guidance/advice.
- Conducting Security gap analysis against security control frameworks, remediation planning and monitoring.
- Evaluating third-party suppliers to provide assurance of the effective design and operation of security controls.
- Producing security audit reports, checklists and briefings.
What You'll Bring to the Team and the Tools you'll need:
You'll bring:
- Strong analytical and problem-solving skills.
- Excellent communication and teamwork abilities, passion for cyber security and a desire to learn and grow within the field.
- Ability to adapt and thrive in a fast-paced, dynamic environment, organisation skills and forward planning.
- Possess strong hands-on experience and working knowledge of security related legislation (e.g. GDPR, PCI DSS, ICO requirements).
- Security Control Frameworks such as NCSC Cyber Assurance Framework, ISO 27001, NIST CSF and CIS.
- HMG and NCSC security policies, standards and guidance.
- Have an understanding of cyber risk management in an agile delivery environment.
- Have a good understanding of modern IT technologies and services, such as Cloud Computing (Azure, M365, AWS, Google), Mobile Computing, IT Security, Infrastructure technologies, Zero Trust and demonstrate an understanding of security architecture.
- Be skilled in workshop facilitation particularly with respect to risk identification and assessment.
You'll share your knowledge with the team, our clients and the wider Cyberfort community, contributing to Group blogs and undertaking research related to technology enhancements.
Certifications That Set You Apart:
- Relevant certifications, e.g., CISSP, CISM, CRISC or other.
- Have achieved or be working towards Full Membership of CIISEC and UK Cyber Security Council professional registration at either Chartered or Principal for Cyber Security Governance & Risk Management.
What's in it for You?
- Flexibility First: Work-life balance through hybrid/remote working options.
- Your Growth Journey: Continuous learning opportunities and professional development.
- Perks with a Purpose: Comprehensive benefits package to support your wellbeing, health, family and future, from Private Health Care, Cash Back Plan, Buy and Sell Holiday Options, Life Assurance.
- Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives.
If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.
Senior Cyber Security Consultant - Perm - SC Cleared employer: Sanderson Government and Defence
Join a forward-thinking organisation that values user-centred design and offers a collaborative work environment in the heart of London. With a strong commitment to diversity and inclusion, we provide our employees with opportunities for professional growth while working on impactful government projects that shape digital services. Enjoy a flexible working model that balances on-site collaboration with remote work, ensuring a rewarding and meaningful career path.
Contact Details:
Sanderson Government and Defence Recruitment Team