At a Glance
- Tasks: Conduct hands-on risk assessments and engage with senior stakeholders in a dynamic environment.
- Company: Join a leading firm focused on real-world cyber security challenges.
- Benefits: Enjoy flexible remote work, ongoing professional development, and exposure to high-impact projects.
- Other info: Must hold active SC security clearance; ideal for those passionate about security governance.
- Why this job: Make a difference in cyber security while shaping risk-led decisions.
- Qualifications: Proven experience in technical cyber risk and strong analytical skills required.
The predicted salary is between 63000 - 77000 £ per year.
Location: Remote with occasional UK travel
Contract Type: Permanent with an emphasis on real world risk assessment, not theory. Success will come from strong judgement, hands-on experience and the ability to operate effectively in a clearance constrained, stakeholder heavy environment.
- Proven experience as a technical cyber risk practitioner, not purely advisory
- Strong technical background with hands-on delivery of system level risk assessments across infrastructure, applications and cloud environments
- Demonstrable experience identifying, assessing and treating risk within live systems, not just framework alignment
- Experience operating in secure and regulated environments, ideally government or defence
- Proven ability to engage senior stakeholders and influence decisions
- Ability to translate technical findings into clear, actionable risk outcomes
- Confident leading risk workshops, threat modelling and control assessments
- Experience working within Agile delivery environments
- Strong analytical capability and sound judgement
Any candidates must have an active SC level of security clearance to be considered.
Technical Knowledge
- Security frameworks including ISO 27001, NIST CSF, CIS and NCSC guidance
- Regulatory landscape including GDPR and PCI DSS
- Familiarity with HMG and NCSC standards
- Modern technology environments: Cloud platforms such as Azure, AWS and Google Cloud
- Microsoft 365
- Infrastructure and network security
- Zero Trust principles
- Understanding of security architecture concepts
Certifications
- Relevant industry certifications such as CISSP, CISM, CRISC or equivalent.
- Candidates should either hold, or be working towards, Full Membership of CIISEC and professional registration with the UK Cyber Security Council at Chartered or Principal level in Cyber Security Governance and Risk Management.
What’s in it for You
- Exposure to complex, high impact work in high trust environments
- Direct engagement with senior client stakeholders
- Opportunity to shape risk led security decisions
- Ongoing professional development
- Flexible working / Remote first
Interested? Submit your application to learn more about this exciting opportunity.
Technical Security Risk Consultant employer: Sanderson Government & Defence
As a PAM Consultant with our esteemed consulting client, you will thrive in a dynamic work culture that prioritises innovation and collaboration. The company offers robust employee growth opportunities, including continuous training in cutting-edge security practices, while fostering a diverse and inclusive environment that values every individual's contribution. Located in the UK, this role not only provides competitive benefits but also the chance to make a meaningful impact on clients' security postures through your expertise in Privileged Access Management.
Contact Details:
Sanderson Government & Defence Recruitment Team