Job Description
Cyber and Information Assurance Consultant Job Title Cyber and Information Assurance Consultant
Hours Per Week 37
Reporting to
Reporting to Principal Cyber Consultant / Head of Services
Location
Location Remote-first, with attendance at Nexor's Nottingham office and customer locations as required. Regular UK travel may form part of the role. Occasional international travel may arise.
Role Purpose The Cyber and Information Assurance Consultant supports customers in identifying, assessing and managing cyber security and information assurance risks across complex digital, operational and high assurance environments. The role combines consultancy, risk assessment, security assurance, governance and stakeholder engagement. Work may span secure information exchange, cross-domain solutions, cloud services, networks, applications, data platforms and operational systems.
The postholder translates security obligations, business needs, threat information and technical evidence into clear risk based recommendations. The role suits a cyber security, risk, assurance or systems professional seeking broader customer facing responsibility across defence, government and critical national infrastructure.
Key Responsibilities Conduct cyber security and information assurance risk assessments.
Identify threats, vulnerabilities, impacts and control requirements.
Develop proportionate risk treatment recommendations.
Maintain cyber risk registers, assumptions, dependencies and residual risk positions.
Support formal risk acceptance and escalation activity.
Provide clear advice to technical and non-technical stakeholders.
Information Assurance
Support assurance of systems, services and information handling arrangements.
Assess compliance against customer, contractual and regulatory requirements.
Review security documentation, technical evidence and control implementation.
Support security case development and assurance planning.
Contribute to accreditation, authorisation and approval activity.
Maintain traceability between requirements, controls, evidence and risk decisions.
Security Governance
Support development and maintenance of:
Security policies.
Standards.
Procedures.
Governance frameworks.
Assurance plans.
Security management plans.
Additionally:
Contribute to security governance forums and assurance boards.
Track security actions, risks, decisions and evidence.
Support senior ownership and oversight of cyber security risk.
Secure by Design Support
Work with architects, engineers and delivery teams to embed security throughout the lifecycle.
Review solution designs for security, privacy, resilience and assurance implications.
Support identification of security requirements and non functional requirements.
Apply defence in depth, least privilege and Zero Trust principles.
Ensure security considerations form part of design, build, test, deployment and operation.
Threat and Vulnerability Assessment
Assess credible threat scenarios relevant to customer environments.
Review vulnerability information and technical findings.
Support interpretation of penetration test, vulnerability scan and security assessment outputs.
Evaluate exploitability, business impact and operational consequence.
Recommend remediation priorities and compensating controls.
Work with:
Customer security teams.
Solution and Security Architects.
Project and Delivery Managers.
Software and Platform Engineers.
Product Teams.
Suppliers and Technology Partners.
Additionally:
Participate in workshops, assurance reviews and customer briefings.
Explain cyber security risks and control recommendations in accessible language.
Build trusted and professional customer relationships.
Continuous Improvement and Professional Development
Maintain awareness of emerging cyber threats, regulation and assurance practice.
Contribute to internal methods, templates and guidance.
Share knowledge across Nexor communities of practice.
Support lessons identified and service improvement activity.
Work towards recognised cyber security and assurance qualifications.
Professional experience in cyber security, information assurance, risk management, systems engineering or a related discipline.
Experience contributing to security assessment or assurance activity.
Experience working within multidisciplinary technical teams.
Experience producing clear and structured security documentation.
Ability to identify and communicate cyber risks.
Ability to interpret technical evidence and control requirements.
Experience engaging with technical and non technical stakeholders.
Strong interest in defence, government, critical infrastructure or high assurance systems.
Essential Technical Knowledge Cyber Security and Assurance
Information assurance.
Security governance.
Security controls.
Threat and vulnerability assessment.
Security lifecycle principles.
Residual risk and risk acceptance.
Assurance evidence and traceability.
Frameworks and Standards
Working knowledge of some of the following:
ISO/IEC 27001.
ISO/IEC 27005.
NCSC Cyber Assessment Framework.
NIST Cybersecurity Framework.
MOD Defence Standard 05-138.
Government Security Classifications.
Defence, government or critical national infrastructure experience.
Experience within high assurance or regulated environments.
Exposure to secure information exchange or cross domain solutions.
Experience supporting accreditation or authority to operate processes.
Familiarity with MOD security and assurance practices.
Experience with cloud security assurance.
Experience supporting security architecture reviews.
Knowledge of data protection and privacy impact assessment.
Current SC clearance.
Experience supporting bids, proposals or pre sales activity.
SFIA Mapping SFIA Skill
Level
Description
Information Security (SCTY)
4
Application of security controls, risk management and assurance practice
Information Assurance (INAS)
4
Assessment of information risk and assurance evidence
4
Identification, assessment and treatment of business and cyber risks
Security Administration (SCAD)
3/4
Support to security procedures and control operation
Vulnerability Assessment (VUAS)
3/4
Assessment and interpretation of vulnerabilities
Consultancy (CNSL)
4
Provision of cyber and assurance advice within defined areas
Stakeholder Relationship Management (RLMT)
4
Productive engagement with customer and technical stakeholders
Requirements Definition and Management (REQM)
4
Definition and traceability of security requirements
Methods and Tools (METL)
4
Application of assurance methods, frameworks and tools
Compliance Audit (COAU)
4
Assessment of compliance against policies, standards and controls
Professional Qualifications A degree, degree apprenticeship or equivalent experience in a relevant discipline, including:
Cyber Security.
Information Security.
Computer Science.
Software Engineering.
Electronic Engineering.
Mathematics.
Another relevant science, technology or engineering discipline.
Progress towards, or interest in obtaining:
CISSP.
CISM.
CRISC.
NCSC Certified Cyber Professional.
Chartered Cyber Security Professional.
Risk management qualification.
Development Path The role provides progression towards:
Senior Cyber and Information Assurance Consultant.
Security Architect.
Information Assurance Lead.
Security Assurance Manager.
Head of Cyber Assurance.
Development support may include:
Mentoring from senior cyber consultants and architects.
Customer and programme exposure.
Security architecture and assurance training.
Support towards professional certification.
Opportunities to lead defined assurance work packages.
Participation in internal research and service development.
Exposure to bids, pre sales and consultancy shaping.
Access to cyber and architecture communities of practice.
Measures of Success Success within the role shall be measured through:
Quality and clarity of assurance deliverables.
Effective identification and communication of cyber risks.
Completion of assigned work against customer objectives.
Constructive participation in assurance and design reviews.
Effective management of risks, actions and evidence.
Positive customer and stakeholder feedback.
Growth in assurance and domain competence.
Contribution to successful bids and customer engagements.
Increasing ownership of cyber assurance work packages.
Progress towards relevant professional qualifications.
Reporting Line The role reports to the Head of Services and/or Principal Cyber Consultant.
. click apply for full job details