Cyber Security Consultant

Anson McCade

Cardiff

On-site

GBP 61,000 - 101,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Anson McCade seeks an experienced cyber risk professional to design and implement a pragmatic cyber risk management strategy with a strong emphasis on third‑party risk. You will stand up repeatable processes, configure tooling (Risk Ledger and similar), and embed NIST SP 800-161 controls across the supplier lifecycle.

The role requires hands-on TPRM leadership in regulated environments, active SC clearance, and a proven track record of delivering supplier risk programs onsite in the UK.

Qualifications

  • Proven track record in designing and implementing cyber risk programs.
  • Hands-on experience with NIST SP 800-161 frameworks.
  • Experience with TPRM platforms such as Risk Ledger.
  • Active SC clearance (current and verifiable).

Responsibilities

  • Design and implement a pragmatic cyber risk management strategy and operating model.
  • Lead third-party cyber risk management (TPRM): supplier onboarding, due diligence, risk scoring, continuous monitoring, and remediation tracking.
  • Map and embed NIST SP 800-161 guidance into policies, controls, and assessments across organisational tiers.
  • Select, configure and roll out TPRM tooling and maintain the risk ledger.
  • Develop procedures/runbooks for risk assessments, exception handling, and incident escalation related to suppliers.
  • Produce clear reporting for senior stakeholders on supply chain risk posture, concentrations, and nth‑party dependencies.

Skills

Cyber risk management
TPRM (third-party risk)
NIST SP 800-161
Risk Ledger
Vendor risk monitoring

Tools

Risk Ledger
External rating tools

Job description

Contract

6 months (inside IR35)

Rate

Up to £550/day

Role overview

Client is seeking an experienced cyber risk professional to design and implement their cyber risk management strategy with a strong focus on third‑party/supply chain risk. You’ll stand up repeatable processes, select and configure tooling (Risk Ledger and similar), and embed NIST 800‑161-aligned controls across the supplier lifecycle.

Key responsibilities
  • Design and implement a pragmatic cyber risk management strategy and operating model.
  • Lead third‑party cyber risk management (TPRM): supplier onboarding, due diligence, risk scoring, continuous monitoring, and remediation tracking
  • Map and embed NIST SP 800‑161 (C‑SCRM) guidance into policies, controls, and assessments across organisational tiers.
  • Select, configure and roll out TPRM tooling (e.g., Risk Ledger; “Bitsight”-style external rating/monitoring tools) and maintain the risk register/ledger.
  • Develop procedures/runbooks for risk assessments, exception handling, and incident escalation related to suppliers.
  • Produce clear reporting for senior stakeholders on supply chain risk posture, concentrations, and nth‑party dependencies.
  • Proven track record designing/implementing cyber risk and TPRM programmes.
  • Hands‑on experience applying NIST 800‑161 (or equivalent C‑SCRM/TPRM frameworks).
  • Practical experience with TPRM platforms (Risk Ledger or similar) and external cyber rating/monitoring tools.
  • Experience working in regulated environments (defence, critical national infrastructure, public sector).
  • Familiarity with ISO 27001, Cyber Essentials, and supplier assurance workflows.
  • Active SC clearance (must be current and verifiable).
Commercials
  • Inside IR35, up to £550/day.
  • 6-month initial term, onsite in South Wales.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Supplier Assurance Lead
Supplier Assurance Lead

Morson Group • Manchester

Hybrid
GBP 55,000 - 92,000
Supplier Assurance Lead
Supplier Assurance Lead

Morson Human Resources Limited • Greater Manchester

Hybrid
GBP 83,000 - 101,000
Cyber Security Risk Consultant
Cyber Security Risk Consultant

Sanderson Government & Defence • United Kingdom

Remote
GBP 70,000 - 100,000
Cyber Security Consultant
Cyber Security Consultant

Xcede Recruitment Solutions • Greater London

Hybrid
GBP 70,000 - 100,000
Cyber Security Assurance Consultant - Contract
Cyber Security Assurance Consultant - Contract

SR2 REC LTD • Greater London, Manchester

Hybrid
GBP 92,000 - 97,000
Cyber Security Consultant
Cyber Security Consultant

Xcede • Slough

Hybrid
GBP 83,000 - 138,000
Cyber Security Consultant
Cyber Security Consultant

Experis • Preston, Greater London, Birmingham

Hybrid
GBP 111,000 - 116,000
Cyber Consultant (SC Cleared)
Cyber Consultant (SC Cleared)

Morson Human Resources Limited • West of England

Hybrid
GBP 140,000 - 190,000
Cyber Risk Lead
Cyber Risk Lead

CPS Group (UK) Limited • Greater London

Hybrid
GBP 81,000 - 99,000
Cyber Consultant (SC Cleared)
Cyber Consultant (SC Cleared)

Cyber UK • West of England

Hybrid
GBP 137,000 - 152,000