At a Glance
- Tasks: Lead Cyber Assessment Framework engagements and produce actionable reports for central government clients.
- Company: A dynamic startup in cyber security with a disciplined, mission-focused culture.
- Benefits: Competitive salary, remote work flexibility, and professional development opportunities.
- Other info: Join a small, capable team where your contributions truly matter.
- Why this job: Make a real impact in shaping a growing consultancy and influence its future direction.
- Qualifications: 3-5 years of cyber security experience and hands-on NCSC CAF assessment skills.
The predicted salary is between 57000 - 63000 Β£ per year.
Hybrid working (Mainly remote, with UK client visits when required)
Salary - Circa Β£60k
Start Date ASAP - Looking for candidates ideally with a 1-month maximum notice period
Our client is a new kind of cyber security consultancy β built from the ground up by practitioners with military and defence backgrounds, with a culture that reflects it. Disciplined, direct, mission-focused and deeply competent. We are a startup, which means the team is small, the work is real, and the people who join now will help define what we become. If you want a role where you can see the impact of your work, have a genuine say in how things are done, and build something alongside people who take both quality and each other seriously β this is worth reading on.
The role:
- Four days a week you will be leading and supporting Cyber Assessment Framework (CAF) engagements across central government β working remotely with clients the majority of the time, with occasional travel to UK client sites as required.
- You will assess compliance against NCSC CAF objectives and indicators of good practice, identify and characterise gaps, and produce clear, actionable reports and remediation roadmaps.
- The fifth day is structured time for business development or wider delivery work β contributing to bids, supporting pre-sales conversations, or flexing into other cyber advisory work as the practice grows.
- Because we are a startup, you will also have the chance to help shape our methodology, sharpen our tooling and build the foundations of something lasting.
What you will be doing:
- Conducting end-to-end CAF assessments across central government clients, covering all four CAF objectives and associated indicators of good practice β primarily remote, with occasional on-site visits.
- Engaging with senior stakeholders β SROs, CISOs and technical leads β to gather evidence, validate findings and present outcomes clearly.
- Writing high-quality assessment reports, gap analyses and prioritised improvement plans that clients can actually use.
- Contributing to business development β writing proposal content, attending client conversations and helping win new work alongside senior colleagues.
- Helping build the practice β refining internal methodologies, templates and tooling as we grow and scale.
- Flexing into broader delivery on your BD/delivery day β drawing on skills across risk, governance, architecture or assurance depending on where we need you.
What we are looking for:
Essential:- Hands-on experience conducting NCSC CAF assessments β you have done this for real, not just studied the framework.
- 3-5 years Cyber Security experience.
- Public Sector/Government experience.
- Solid grasp of the CAF objectives, indicators of good practice and the broader UK government cyber security landscape.
- Comfortable working independently and remotely β self-directed, organised and reliable without needing close oversight.
- Willing to be flexible β a startup means occasional shifting priorities, and the right person sees that as opportunity, not disruption.
- Current or eligible for SC clearance (active clearance strongly preferred).
- Strong written communication β producing reports that are accurate, structured and genuinely useful.
- Relevant certifications β CISSP, CISM, CCP (Lead Assessor or equivalent) or other NCSC-recognised qualifications.
- Background in or exposure to military, defence or government security β you will fit right in.
- Broader assurance or risk experience across ISO 27001, NIST, GovAssure or similar frameworks.
- Experience in a consulting or early-stage business β you know what it means to help build something, not just execute inside it.
What you can expect from the client:
- A small, capable team that operates with high standards, low ego and genuine mutual respect.
- Primarily remote working with the flexibility that brings β and infrequent, predictable UK travel when clients need you on site.
- Real influence β you will not be employee number 500. What you build here, and how you build it, will matter.
- Ongoing professional development and certification support.
Information Security Consultant (CAF Assessments) - SC Cleared employer: Sectech Solutions
Join a pioneering cyber security consultancy that values discipline, directness, and mission-focused teamwork. With a primarily remote working environment and the opportunity to shape methodologies from the ground up, you will have a real impact on our growth while enjoying ongoing professional development and a culture of mutual respect. This is an ideal role for those looking to contribute meaningfully in a startup atmosphere where your expertise will be recognised and valued.
StudySmarter Expert Adviceπ€«
We think this is how you could land Information Security Consultant (CAF Assessments) - SC Cleared
β¨Tip Number 1
Network like a pro! Reach out to your connections in the cyber security field, especially those with military or government backgrounds. A friendly chat can lead to opportunities that arenβt even advertised yet.
β¨Tip Number 2
Show off your expertise! Prepare a portfolio of your past CAF assessments and any relevant reports you've written. This will not only demonstrate your skills but also give you something tangible to discuss during interviews.
β¨Tip Number 3
Be ready for a dynamic environment! Startups thrive on flexibility, so be prepared to discuss how you can adapt to changing priorities and contribute to building the practice. Highlight your experience in similar settings.
β¨Tip Number 4
Apply through our website! Weβre looking for passionate individuals who want to make a real impact. Your application will stand out if you show genuine interest in shaping our methodologies and contributing to our growth.
We think you need these skills to ace Information Security Consultant (CAF Assessments) - SC Cleared
Some tips for your application π«‘
Show Off Your Experience:Make sure to highlight your hands-on experience with NCSC CAF assessments. We want to see that you've been in the trenches, not just reading about it. Use specific examples to demonstrate your skills and how they relate to the role.
Tailor Your Application:Donβt just send a generic CV and cover letter. Tailor your application to reflect the job description. Mention your public sector experience and how it aligns with our mission-focused culture. We love seeing candidates who understand what weβre all about!
Keep It Clear and Concise:When writing your reports or application materials, clarity is key. We appreciate structured and actionable content. Make it easy for us to see your thought process and how you can contribute to our team.
Apply Through Our Website:We encourage you to apply directly through our website. Itβs the best way for us to receive your application and ensures you donβt miss out on any important updates. Plus, it shows youβre keen to join our team!
How to prepare for a job interview at Sectech Solutions
β¨Know Your CAF Inside Out
Make sure you have a solid understanding of the Cyber Assessment Framework (CAF) objectives and indicators of good practice. Brush up on your hands-on experience conducting assessments, as you'll need to demonstrate your practical knowledge during the interview.
β¨Engage with Stakeholders
Prepare to discuss how you've engaged with senior stakeholders in previous roles. Think about specific examples where you've gathered evidence, validated findings, and presented outcomes clearly. This will show that you can communicate effectively with SROs, CISOs, and technical leads.
β¨Showcase Your Writing Skills
Since producing high-quality assessment reports is key for this role, be ready to talk about your writing process. Bring examples of reports or gap analyses you've created in the past, and explain how they were structured to be genuinely useful for clients.
β¨Embrace the Startup Mindset
Demonstrate your flexibility and willingness to adapt in a startup environment. Share experiences where you've successfully navigated shifting priorities or contributed to building methodologies and tools. This will highlight your ability to thrive in a dynamic setting.