Cyber Security Risk Consultant

Sanderson Government & Defence

United Kingdom

Remote

GBP 70,000 - 100,000

Full time

35 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Sanderson Government & Defence is seeking a Senior Technical Security Risk Consultant to advise government and defence clients on risk-led security strategies, operating remotely with occasional UK travel. You will lead risk identification, threat modelling, and workshops, translating technical findings into clear risk actions for senior stakeholders, with active SC clearance.

This role demands hands-on delivery, strong judgement and experience across cloud, infrastructure, and applications

Qualifications

  • Technical cyber risk practitioner with hands-on delivery.
  • Experience in secure and regulated environments, government/defence preferred.
  • Active SC clearance is required.
  • Experience leading risk workshops and threat modelling.
  • Ability to translate technical findings into clear risk actions for senior stakeholders.

Responsibilities

  • Provide expert advice on risk management frameworks (ISO 27005, NIST RMF).
  • Lead risk identification, assessment and treatment across systems and services.
  • Facilitate risk workshops and threat modelling sessions.
  • Assess architectures to identify security risks and control gaps.
  • Produce risk and remediation reports for stakeholders.
  • Maintain risk registers and track residual risk.
  • Evaluate third-party controls and supplier risk.
  • Ensure security is embedded in delivery teams and roadmaps.

Skills

Technical cyber risk
Stakeholder engagement
Threat modelling
Risk workshops
ISO 27005/NIST RMF
Cloud security
Secure delivery

Education

CISSP
CISM
CRISC
CIISEC Full Membership
UK Cyber Security Council Chartered/Principal

Tools

Azure
AWS
GCP
Microsoft 365

Job description

Senior Technical Security Risk Consultant
Location: Remote with occasional UK travel
Contract Type: Permanent & Full-time
Security Clearance: Active SC clearance required
Salary: Competitive + Benefits
About the Role

As a Technical Cyber Risk Consultant, you will work closely with clients across government, defence and regulated sectors. You will operate as a trusted advisor, working alongside senior stakeholders and technical teams to deliver pragmatic, risk-led outcomes.

Key Responsibilities
  • Provide expert advice on cyber risk management frameworks including ISO 27005 and NIST RMF
  • Lead risk identification, assessment and treatment across applications, infrastructure and digital services
  • Facilitate structured risk workshops and threat modelling sessions
  • Assess solution architectures to identify security risks and control gaps
  • Review and interpret IT Health Check outputs and define clear remediation plans
  • Produce concise reporting on risks, vulnerabilities and treatment options
  • Maintain and manage risk registers including residual risk position
  • Conduct gap analysis against recognised security frameworks
  • Evaluate third party suppliers and assess control effectiveness
  • Produce audit reports, controls assessments and security briefings
  • Work with delivery teams to ensure security is embedded throughout
Experience Required

This role is aligned to a technically credible and delivery focused consultant / cyber risk practioner; with an emphasis on real world risk assessment, not theory. Success will come from strong judgement, hands-on experience and the ability to operate effectively in a clearance constrained, stakeholder heavy environment.

  • Proven experience as a technical cyber risk practitioner, not purely advisory
  • Strong technical background with hands-on delivery of system level risk assessments across infrastructure, applications and cloud environments
  • Demonstrable experience identifying, assessing and treating risk within live systems, not just framework alignment
  • Experience operating in secure and regulated environments, ideally government or defence
  • Proven ability to engage senior stakeholders and influence decisions
  • Ability to translate technical findings into clear, actionable risk outcomes
  • Confident leading risk workshops, threat modelling and control assessments
  • Experience working within Agile delivery environments
  • Strong analytical capability and sound judgement
  • Any candidates must have an active SC level of security clearance to be considered.
Technical Knowledge
  • Security frameworks including ISO 27001, NIST CSF, CIS and NCSC guidance
  • Regulatory landscape including GDPR and PCI DSS
  • Familiarity with HMG and NCSC standards
  • Modern technology environments:
  • Cloud platforms such as Azure, AWS and Google Cloud
  • Microsoft 365
  • Infrastructure and network security
  • Zero Trust principles
  • Understanding of security architecture concepts
Certifications

Relevant industry certifications such as CISSP, CISM, CRISC or equivalent. Candidates should either hold, or be working towards, Full Membership of CIISEC and professional registration with the UK Cyber Security Council at Chartered or Principal level in Cyber Security Governance and Risk Management.

What's in it for You
  • Exposure to complex, high impact work in high trust environments
  • Direct engagement with senior client stakeholders
  • Opportunity to shape risk led security decisions
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Consultant
Cyber Security Consultant

Gattaca • Corsham

Hybrid
GBP 70,000 - 110,000
Hybrid working
Generous annual leave entitlement
Enhanced pension scheme
+2
Cyber Security Consultant
Cyber Security Consultant

Matchtech • Gloucester

Hybrid
GBP 60,000 - 90,000
Hybrid working
Private healthcare
Competitive salary
+3
Cyber Security Consultant
Cyber Security Consultant

Investigo • England

Hybrid
GBP 60,000 - 80,000
Structured career development
Support for certifications like CISSP, ISO27001
Mentoring and regular reviews
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Control Risks • Greater London

On-site
GBP 60,000 - 80,000
Competitively positioned compensation package
Discretionary global bonus scheme
Hybrid working arrangements
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Matchtech • Corsham

Hybrid
GBP 65,000 - 90,000
Hybrid working arrangement
Generous annual leave entitlement
Enhanced pension scheme
+5
Cyber Security Consultant
Cyber Security Consultant

Matchtech • Portsmouth

Hybrid
GBP 65,000 - 90,000
Hybrid working
Annual bonus
Private healthcare
+5
Cyber Security Consultant
Cyber Security Consultant

Matchtech • Devon and Torbay

Hybrid
GBP 65,000 - 90,000
Competitive salary
Hybrid working
Annual bonus
+8
Cyber Security Consultant
Cyber Security Consultant

Matchtech • Plymouth

Hybrid
GBP 65,000 - 90,000
Private healthcare
Enhanced pension scheme
Life assurance
+1
Cyber Security Consultant
Cyber Security Consultant

Matchtech • West of England

Hybrid
GBP 60,000 - 90,000
Private healthcare
Enhanced pension scheme
Life assurance
+3
Senior Cyber Transformation Manager
Senior Cyber Transformation Manager

Anson McCade • Greater London

On-site
GBP 120,000 - 155,000