Job Search and Career Advice Platform

Enable job alerts via email!

GRC Consultant - Inside IR35 - MOD DV

Sanderson

Farnborough

Hybrid

GBP 80,000 - 100,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading security consultancy is seeking a GRC Consultant to support risk management for the MOD. The role requires active MOD DV Clearance, a strong understanding of risk frameworks, and the ability to work collaboratively in a hybrid capacity. Candidates should be familiar with cloud security and security assurance legislation. This is a 6-month initial contract with potential for extension.

Qualifications

  • Must have Active MOD DV Clearance.
  • Experience in security assurance and risk management.
  • Ability to produce informative reporting on vulnerabilities.

Responsibilities

  • Provide risk and security assurance for MOD projects.
  • Facilitate security workshops with Authority departments.
  • Remediate and manage risk in alignment with business objectives.

Skills

Security Assurance Coordinator or Delivery Team Security Lead roles
Risk management and assessment principles
Understanding of Cloud Computing
Excellent interpersonal skills
Strong working knowledge of JSP440, JSP604/453 & JSP490
Strong knowledge of ISO 27001
Threat Modelling

Tools

Azure
Amazon Web Service
Network Security Groups
Web Application Firewalls
Job description

GRC Consultant – MOD DV

  • Location: Farnborough or Cambridgeshire
  • Type: Hybrid (3 days on–site)
  • IR Status: Inside
  • Rate: GBP500 – GBP600
  • Lenghth: Initial 6 months, scope for extension

Must have Active MOD DV Clearance

In this role, you'll be:

  • Providing the Secure by Design risk and security assurance function within MOD as part of a managed service.
  • Have an excellent understanding of risk management and assessment principles and frameworks, such as ISO27005 and the NIST Cyber Security Framework.
  • Produce informative and succinct reporting that clearly articulates any identified vulnerabilities, associated risks, controls and risk treatment activity.
  • Facilitate security and risk workshops with the various Authority departments, to align with wider customer transformational Security and risk management outcomes.
  • Provide accurate and pragmatic remediation/risk management guidance/advice in balance with Business objectives and risk appetites.
  • Have an understanding of risk assessment in an agile delivery environment.
  • Exceptional team working ethic and interpersonal skills.
  • Have a good understanding of modern IT technologies and services, such as Cloud Computing, AI (ISO42001), Mobile Computing, IT Security, Infrastructure technologies, Zero Trust, Data at Rest/In Transit Cryptography, Cross Domain Solutions and demonstrate an understanding of security architecture both physical and cloud (be able to read and understand HLDs/LLDs).
  • Strong working knowledge of:
  • Security Assurance Coordinator or Delivery Team Security Lead roles
  • JSP440, JSP604/453 & JSP490
  • MOD/GDS Secure by Design Principles
  • Supplier Chain Assurance and Risks.
  • Security related legislation (e.g. GDPR, PCI DSS, ICO requirements).
  • Security Control Frameworks such as ISO 27001, NIST CSF and CIS Controls v8.
  • HMG, NPSA and NCSC security policies, standards and guidance.
  • Have experience building and implementing secure by design principals within the software development lifecycle (SDLC).
  • Threat Modelling – Kill Chain – Attack tree analysis.
  • Working understanding of:
  • Cloud security including Azure, Amazon Web Service, Key Management Systems, Containerisation, Network Security Groups, Host based firewalls, Web Application Firewalls
  • Physical Network Infrastructure, Anti–Patterns, Network Firewalls, IDS/IPS, DMZs
  • AI use cases, secure configuration (ISO42001 knowledge preferable),
  • ITHC scoping and remediation action plans.

If you're interested in learning more – please apply or reach out to

Reasonable Adjustments:

Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.