Cyber Security Consultant - PERMANENT - HYBRID (Permanent)
Sanderson Government and Defence
Cambridge, Cambridgeshire
Job type
permanent
Location
Cambridge, Cambridgeshire, Cambridgeshire; East of England; England
Job Description Cyber Security GRC Consultant (DV Cleared)
Cambridgeshire / London, Hybrid - c. Contract Type: Permanent & Full-time
As a Cyber Security Consultant, you will play a pivotal role in delivering Secure by Design risk and security assurance services within MOD and Public Sector environments. You'll collaborate with multi-disciplinary teams to define and implement security risk assessments and best practice solutions, ensuring alignment with business risk appetites and transformation goals. You'll be part of a knowledge-sharing culture, working alongside expert peers in Secure Architecture and Risk Planning.
Deliver Secure by Design risk and security assurance functions within MOD/Public Sector.
Lead and advise on risk management frameworks, ISMS, and Enterprise Security Risk Management.
Facilitate security and risk workshops with Authority departments.
Produce clear reporting on vulnerabilities, risks, controls, and treatment activities.
Provide pragmatic remediation and risk management guidance.
Contribute to blogs and research within the business community. The successful candidate will possess proven experience in cybersecurity, security architecture, threat modelling, or related fields within Public Sector and MOD and will have achieved or be working towards Full Membership of CIISEC and UK Cyber Security Council professional registration at either Chartered or Principal for Risk Management.
~ Supplier Chain Assurance and Risks.
HMG, NPSA and NCSC security policies, standards and guidance.
Have experience building and implementing secure by design principals within the software development lifecycle (SDLC).
Threat Modelling - Kill Chain - Attack tree analysis. Cloud security including Azure, Amazon Web Service, Key Management Systems, Containerisation, Network Security Groups, Host based firewalls, Web Application Firewalls
Physical Network Infrastructure, Anti-Patterns, Network Firewalls, IDS/IPS, DMZs
AI use cases, secure configuration (ISO42001 knowledge preferable),
HLD and LLD reviews and analysis. Working knowledge and experience of tooling relating to cloud security posture management offerings, cloud native security (AWS/Azure) and endpoint security.
Proficient in Public Key Infrastructure, Data at Rest/inTransit, Cryptography, Privileged User Access Management, Zero Trust, Cross Domain Solutions and Role-based Access Controls.
Thrives on tackling challenges with creative solutions, challenging the normal. Hybrid Working: c. 3 days onsite per week.
Career Development: Continuous learning and professional growth. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.
← Back to job search