Cyber Security Capability Consultant
If the following job requirements and experience match your skills, please ensure you apply promptly.
Contract: 6 months initially
IR35: Inside IR35
Location: Liverpool Street, London onsite initially, moving to hybrid
Start: ASAP
Were currently supporting a major global financial services organisation with an exciting Cyber Security capability and controls mapping programme.
Were looking for an experienced Cyber Security Consultant / Security Architect / GRC Consultant who can assess the organisations current security landscape, identify and catalogue security technologies, and map capabilities and controls against recognised cybersecurity frameworks.
Youll work across a complex enterprise environment, engaging with security, technology and business stakeholders to understand the organisations current security capabilities and how its technology estate supports security outcomes.
Key responsibilities will include:
Identifying and cataloguing security tools and technologies across the organisation.
Investigating IT platforms that provide security outcomes, even where security isn't their primary purpose.
Building and maintaining a central inventory of security capabilities and supporting technologies.
Mapping security technologies, capabilities and controls against frameworks including NIST CSF, NIST 800-53, CIS Critical Security Controls and CRI Profile .
Establishing a baseline security capability model.
Benchmarking current security capabilities against recognised industry frameworks and standards.
Running workshops, interviews and discovery sessions with security and technology stakeholders.
Challenging assumptions and validating information from multiple sources.
Producing clear analysis, executive reporting and progress updates.
We're looking for someone with a strong understanding of cybersecurity principles, controls and security architecture, with experience working across several security domains such as:
Identity & Access Management
Endpoint Security
Vulnerability Management
Network Security
Detection & Response
Data Protection
Cloud Security
Security Monitoring & Logging
You should also have practical experience working with one or more recognised security frameworks, ideally including:
NIST Cybersecurity Framework (CSF)
NIST 800-53
CIS Critical Security Controls
CRI Profile
Crucially, you'll have experience mapping technologies, controls or processes to security frameworks, control objectives or desired security outcomes .
Key Skills Cybersecurity / Information Security
Security Controls & Control Mapping
Security Capability Assessment
Cybersecurity Frameworks
NIST / CIS / CRI
Security Maturity Assessments
Security Architecture
GRC / Cyber Risk
Stakeholder Engagement
Workshop Facilitation
Strong analytical and investigative skills
Excellent written and verbal communication
Desirable Financial services or other regulated industry experience.
Experience developing security capability or maturity models. xiskglj
Experience working within large, complex enterprise environments.
If you have experience assessing enterprise security capabilities, mapping controls against frameworks and working with senior stakeholders, we'd be keen to hear from you.
Cyber Security Consultant employer: Xcede
As a Mobility Engineer/Consultant with us, you'll thrive in a dynamic remote work environment that champions innovation and collaboration. We offer competitive benefits, a strong focus on employee development, and the opportunity to work on cutting-edge enterprise solutions that make a real impact. Join our team and be part of a culture that values your expertise and encourages professional growth while ensuring you have the tools and support needed to excel in your role.