Cyber Security Consultant

Experis

Whitehall

Hybrid

GBP 150,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Experis in the United Kingdom seeks a governance-focused consultant to align and oversee security incident and vulnerability management across multiple suppliers. You will drive ISMS-aligned processes, manage escalation, and ensure audit-ready evidence in a Defence context.

The role focuses on governance and coordination rather than hands-on SOC activities, with a hybrid work pattern and contract through November 2026.

Qualifications

  • Experience in security incident or vulnerability governance roles.
  • Strong incident management lifecycle knowledge: detect, respond, and recover.
  • Strong vulnerability lifecycle understanding: identify, prioritise, remediate, and validate.
  • Experience in multi-supplier or SIAM environments.
  • Ability to interpret outputs from SOC and vulnerability tooling without ownership.
  • Familiarity with NIST CSF, NCSC, or UK security guidance preferred.
  • Defence sector or highly regulated environments preferred.
  • Exposure to audit, assurance, or ISMS processes preferred.
  • ITIL alignment preferred.
  • MOD clearance and sole UK nationality required.

Responsibilities

  • Review and align existing supplier processes for high-severity incident management and vulnerability management.
  • Ensure processes are consistent across suppliers and aligned to client policy and regulatory requirements.
  • Establish and govern incident severity classification, escalation thresholds, vulnerability prioritisation approaches, and exception and risk acceptance processes.
  • Coordinate multiple suppliers to ensure consistent handling of incidents and vulnerabilities.
  • Act as the integration point across suppliers, aligning outputs without redesigning underlying processes into a common model.
  • Identify and manage gaps in process maturity, coverage, data quality, and compliance with standards.
  • Govern the lifecycle of high-severity incidents, including escalation, coordination, communication, and reporting.
  • Ensure suppliers detect and escalate incidents appropriately, meet escalation and communication expectations, and maintain structured incident records.
  • Define and agree the required level of visibility from SOC outputs without requiring direct tooling access.
  • Oversee the vulnerability lifecycle from identification through to closure.
  • Ensure vulnerabilities are prioritised consistently using agreed client approaches and tracked through remediation or formal risk acceptance.
  • Validate, track, and monitor remediation timelines, SLA adherence, and handling of high-risk vulnerabilities, exceptions, and waivers.
  • Identify risks relating to incomplete asset coverage and obsolescent, legacy, or non-patchable systems.
  • Define and align evidence requirements for incident and vulnerability management.
  • Ensure outputs are consistent across suppliers, traceable to risks and controls, and audit ready.
  • Provide assurance that both domains align with ISMS and control requirements.
  • Support reporting for major incidents and vulnerability risk and remediation status.
  • Support governance forums with clear, evidence-based reporting.
  • Establish a transition baseline that enables a clean handover of processes to BAU without redesign.

Skills

Security incident management
Vulnerability management
Cyber governance
Multi-supplier/SIAM experience
SOC outputs interpretation
NIST CSF/NCSC/UK guidance familiarity
Defence sector experience
ISMS exposure
ITIL alignment
MOD clearance / UK nationality

Job description

Salary: £? - ? per year

Requirements
  • We require experience in security incident management, vulnerability management, or cyber governance roles.
  • We require a strong understanding of the incident management lifecycle, including detect, respond, and recover.
  • We require a strong understanding of the vulnerability lifecycle, including identify, prioritise, remediate, and validate.
  • We require experience working in multi-supplier or SIAM environments.
  • We require the ability to interpret outputs from SOC and vulnerability tooling without direct ownership.
  • We prefer familiarity with NIST CSF, NCSC, or UK Government security guidance.
  • We prefer experience in the Defence sector or other highly regulated environments.
  • We prefer exposure to audit, assurance, or ISMS processes.
  • We prefer ITIL alignment.
  • We require MOD SC clearance and sole UK nationality.
Responsibilities
  • We review and align existing supplier processes for high-severity incident management and vulnerability management.
  • We ensure processes are consistent across suppliers and aligned to client policy and regulatory requirements.
  • We establish and govern incident severity classification, escalation thresholds, vulnerability prioritisation approaches, and exception and risk acceptance processes.
  • We coordinate multiple suppliers to ensure consistent handling of incidents and vulnerabilities.
  • We act as the integration point across suppliers, aligning outputs without redesigning underlying processes into a common model.
  • We identify and manage gaps in process maturity, coverage, data quality, and compliance with standards.
  • We govern the lifecycle of high-severity incidents, including escalation, coordination, communication, and reporting.
  • We ensure suppliers detect and escalates incidents appropriately, meet escalation and communication expectations, and maintain structured incident records.
  • We define and agree the required level of visibility from SOC outputs without requiring direct tooling access.
  • We oversee the vulnerability lifecycle from identification through to closure.
  • We ensure vulnerabilities are prioritised consistently using agreed client approaches and tracked through remediation or formal risk acceptance.
  • We validate, track, and monitor remediation timelines, SLA adherence, and handling of high-risk vulnerabilities, exceptions, and waivers.
  • We identify risks relating to incomplete asset coverage and obsolescent, legacy, or non-patchable systems.
  • We define and align evidence requirements for incident and vulnerability management.
  • We ensure outputs are consistent across suppliers, traceable to risks and controls, and audit ready.
  • We provide assurance that both domains align with ISMS and control requirements.
  • We support reporting for major incidents and vulnerability risk and remediation status.
  • We support governance forums with clear, evidence-based reporting.
  • We establish a transition baseline that enables a clean handover of processes to BAU without redesign.
Technologies
  • Incident Management
  • Support
  • ITIL
  • Security
More

We are offering a 30/11/2026 contract role paying up to £610 per day via umbrella. The position is hybrid, with locations in Preston, London, or Birmingham in the UK, and a working split of 30% office and 70% home. This is a Defence environment role within our Operational Integrator function, focused on governance and coordination rather than hands-on SOC, incident response, or vulnerability remediation. We are seeking a consultant to support the transition to a multi-supplier SIAM model, standardise incident and vulnerability management processes, and establish an evidence-driven baseline for BAU handover.

last updated 36 week of 2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Consultant
Cyber Security Consultant

Experis - ManpowerGroup • Greater London

Hybrid
GBP 68,000 - 113,000
Cyber Security Consultant - Inside IR35 - SC
Cyber Security Consultant - Inside IR35 - SC

Sanderson Government & Defence • Greater London

Hybrid
GBP 107,000 - 111,000
Cyber Security Consultant
Cyber Security Consultant

Experis • Preston, Greater London, Birmingham

Hybrid
GBP 111,000 - 116,000
Security Operations Lead
Security Operations Lead

Experis - ManpowerGroup • Preston

On-site
GBP 94,000 - 124,000
Security Operations Lead -
Security Operations Lead -

Sanderson Government & Defence • Inverness

On-site
GBP 92,000 - 111,000
Security Operations Lead
Security Operations Lead

Allscreens Nationwide Ltd • Preston

On-site
GBP 96,000 - 109,000
Security Consultant
Security Consultant

Accenture • Holywood

Hybrid
GBP 50,000 - 75,000
Private medical insurance
3 extra days of leave for charitable /
Flexible / hybrid work setup
Cyber Operations & 3rd Party Security Manager
Cyber Operations & 3rd Party Security Manager

Arbuthnot Latham • Greater London

Hybrid
GBP 36,000 - 76,000
1 day per week work from home
Private healthcare cover
Pension via market-leading provider
+2
Security Assurance Specialist
Security Assurance Specialist

Experis - ManpowerGroup • Manchester

Hybrid
GBP 92,000 - 101,000
Cyber Security Analyst - London
Cyber Security Analyst - London

Involved Solutions • Greater London

On-site
GBP 68,000 - 108,000