Overview
In this role you will act as the cyber security SME across complex IT and OT environments, translating high-level guidance into practical security outcomes. You will collaborate with client security leaders, architects and delivery teams to strengthen security and embed secure-by-design across projects. You’ll work on meaningful challenges in regulated sectors and critical national infrastructure, shaping risk-based controls and assurance activities. You’ll grow in a collaborative, learning-focused community with opportunities for certifications and specialist development.
Pay / Benefits
- private healthcare for you and family
- 25 days annual leave (+ half-day Christmas Eve)
- generous pension
- annual performance-based bonus
- PA share ownership
- tax efficient benefits (cycle to work, give as you earn)
Responsibilities
- Serve as cyber security authority on projects, technology releases and product implementations
- Embed into client teams to provide authoritative security design, implementation and operations guidance
- Translate frameworks (NCSC CAF, NIST CSF, ISO 27001, IEC 62443) into practical requirements
- Support security assurance, risk assessment and control implementation across client programs
- Enable regulatory compliance through pragmatic interpretation and implementation (NIS/NIS2, NCSC CAF)
- Build relationships with senior stakeholders and third parties to drive secure outcomes
- Develop reusable tools, playbooks and guidance to standardize delivery
- Coach and mentor consultants within the cyber community and contribute to capability building
- Own an assigned business area/product/technology as a trusted partner within client delivery teams
- Capture lessons learned and codify best practices to improve delivery efficiency
- Contribute to cross-functional, knowledge-sharing activities across the team
Key requirements
- Experience delivering cyber security assurance or secure-by-design work across IT and/or OT environments
- Ability to manage multiple engagements with high quality
- Strong stakeholder management with senior security leaders and technical teams
- Experience with threat and risk assessments and practical controls
- Familiarity with frameworks such as NIST CSF, ISO 27001, IEC 62443, NCSC CAF, GDPR, PCI DSS or NIS
- Knowledge in cloud security, OT/IoT security, network/infrastructure security, security architecture or digital security
- Consultative communication style to influence decisions at senior levels
- Stakeholder management
- Clear communication of complex topics
- Collaborative mindset
- NIST CSF
- ISO 27001
- IEC 62443
…
